GrantFlow Intelligence

Security & privacy

Your business data, handled like it matters

Businesses tell us their turnover, plans and funding needs. That deserves plain answers about where the data goes — here they are, without the legal fog.

Live database from official UK sources
Source-backed opportunity discovery
Check each scheme’s source and review date
No guarantees sold — honest indicators

Our practices

What we do — and deliberately don't do

We collect only what the product needs

Your audit answers (sector, size, location, funding goals), contact details, and — if you create an account — saved grants, drafts and monitoring preferences. No documents are required to run an audit.

Your data is not sold or shared for marketing

Audit answers are used to run your matches, generate your report and contact you about your audit. That's it. No reselling, no third-party marketing lists.

Access is controlled by design

Account data is isolated per user with database-level row security — access to saved grants, drafts and alerts is restricted to the relevant user. Admin access is restricted and credential-protected.

Infrastructure

The platform runs on established cloud providers with encryption in transit (HTTPS everywhere). The application database is configured in the UK; service providers may process data in other countries as described in our privacy policy. Full subprocessor list available on request.

Retention and deletion

Ask us about deletion and we will assess your request, including any records we must retain. Retention periods for lead records are being formalised — contact us for the current position.

Questions answered by a person

Data questions go to info@ymequity.com and are answered directly — not by an autoresponder.

Privacy notice

The formal bit, kept readable

GrantFlow Intelligence processes business and contact information you provide in order to assess grant eligibility, deliver audit reports, provide account features, and respond to enquiries. Lawful basis: performing the service you've requested, and legitimate interest in following up your enquiry. You can request access, correction or deletion of your data at any time.

Data controller: YMEQUITY LTD, trading as GrantFlow Intelligence (company no. 16550886). Contact for data questions: info@ymequity.com. If you're unhappy with how we've handled your data, you can complain to the ICO (ico.org.uk).

Website analytics

If you allow analytics, Google Analytics measures public-site visits, acquisition source, device category, page journeys and broad funnel actions (such as starting or completing a scan, successfully submitting an enquiry, creating an account, viewing pricing or selecting a contact route) so we can improve GrantFlow. The analytics tag is not loaded before you choose to allow it, advertising personalisation is disabled, and the tag is not used on authenticated dashboard or administrator routes. We do not send form answers, names, email addresses, phone numbers, company details, record IDs, report content or client activity to Google Analytics. GrantFlow's own leads, audits and service events remain separate first-party business records.

Google acts as the analytics provider and may set the first-party _ga analytics identifiers after permission is granted. You can change your preference below at any time.

Current analytics preference: not chosen

Questions

Security & privacy FAQs

Do I need to upload documents to use GrantFlow?

No. The audit runs on a questionnaire alone. If you later use application support, you choose what to share and when.

Who can see my audit results?

You, and the GrantFlow team for the purpose of preparing your report and follow-up. Nobody else.

Is my data used to train AI models?

We use AI tools internally to help prepare work, not to train our own models. Provider processing is subject to the relevant business-service terms; ask us about the tools used for your engagement.

Can I get my data deleted?

Email info@ymequity.com from the address you used. We assess deletion requests and explain any records that must be retained.

Are you ISO/Cyber Essentials certified?

We don't currently claim any certifications. If that changes, it will be verifiable here — we'd rather show nothing than badges that don't stand up.