GrantFairy apps and websites (collectively “GrantFairy” in this document) refer to apps and webpages hosted on the GrantFairy.com domain and on other related domains and subdomains.
Like most website operators, GrantFairy collects non-personally-identifying information of the sort that web browsers and servers typically make available, such as the browser type, language preference, referring site, and the date and time of each visitor request. GrantFairy’s purpose in collecting non-personally identifying information is to better understand how GrantFairy’s visitors use its website. From time to time, GrantFairy may release non-personally-identifying information in the aggregate, e.g., by publishing a report on trends in the usage of its website.
GrantFairy also collects potentially personally-identifying information like Internet Protocol (IP) addresses. GrantFairy does not use such information to identify its visitors, however, and does not disclose such information, other than under the same circumstances that it uses and discloses personally-identifying information, as described below.
Gathering of Personally-Identifying Information & Data Sharing
Certain visitors to GrantFairy choose to interact with GrantFairy in ways that require GrantFairy to gather personally-identifying information. The amount and type of information that GrantFairy gathers depends on the nature of the interaction. For example, we ask visitors who use our apps to provide a username and email address. In each case, GrantFairy collects such information only insofar as is necessary or appropriate to fulfil the purpose of the visitor’s interaction with GrantFairy. GrantFairy does not disclose personally-identifying information other than as described below. And visitors can always refuse to supply personally-identifying information, with the caveat that it may prevent them from engaging in certain website-related or app-related activities.
GrantFairy may collect statistics about the behaviour of visitors to its websites. For instance, GrantFairy may reveal how many downloads a particular version got. However, GrantFairy does not disclose personally-identifying information other than as described below.
Protection of Certain Personally-Identifying Information
GrantFairy discloses potentially personally-identifying and personally-identifying information only to those of its employees, contractors, and affiliated organizations that (i) need to know that information in order to process it on GrantFairy’s behalf or to provide services available at GrantFairy, and (ii) that have agreed not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using GrantFairy, you consent to the transfer of such information to them. GrantFairy will not rent or sell potentially personally-identifying and personally-identifying information to anyone. Other than to its employees, contractors, and affiliated organizations, as described above, GrantFairy discloses potentially personally-identifying and personally-identifying information only when required to do so by law, or when GrantFairy believes in good faith that disclosure is reasonably necessary to protect the property or rights of GrantFairy, third parties, or the public at large. If you are a registered user of a GrantFairy website and have supplied your email address, GrantFairy may occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what’s going on with GrantFairy and our products. We primarily use our blog to communicate this type of information, so we expect to keep this type of email to a minimum. If you send us a request (for example via a support email or via one of our feedback mechanisms), we reserve the right to publish it in order to help us clarify or respond to your request or to help us support other users. GrantFairy takes all measures reasonably necessary to protect against the unauthorized access, use, alteration, or destruction of potentially personally-identifying and personally-identifying information.
How secure is the information on GrantFairy?
Very, very secure: we take data security very seriously. Please see below for details.
EU-only data centres
Student data is only stored and processed in EU datacentres and is secured between our servers and your browser using 256 bit SSL encryption.
Servers sit behind multiple firewalls within a VPC which is only accessable via a VPN; only ports 80 and 443 are publicly accessible. The database server is not accessible outside the VPC.
All data is stored in accordance with the General Data Protection Regulation (GDPR) 2018. Sensitive data such as passwords are hashed and salted.
Layered access security
Administrators have limited access to student data, and only when strictly necessary.
Backed up every hour
Snapshots are taken at 1 hour intervals and are retained in reducing granularity for a minimum of 3 months.
Primary servers are managed by Amazon Web Services. Only our developers can access these servers.
– – –