Privacy Policy

Effective date: July 2026

Data controller: Matchr Technologies Ltd, Co. No. 17228795, 7 Llysgwyn, Llangyfelach, Swansea, SA6 6BJ · ICO registration: C1944075

Contact: admin@grantmatchr.co.uk

1. What this policy covers

This Privacy Policy explains how Matchr Technologies Ltd (trading as GrantMatchr) collects, uses, stores, and protects your personal data when you use grantmatchr.com. We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003.

2. Data we collect

  • Account data: name, email address, organisation name, role.
  • Organisation profile data: sector, company size, location, trading history, R&D activity, previous grant history, and other information you provide to enable grant matching assessments.
  • Equality data (optional): where relevant to a specific grant, you may choose to provide protected-characteristic information. This is collected by self-declaration with a clear purpose notice; declining does not block general matching.
  • Usage data: pages visited, features used, assessment runs, login timestamps.
  • Business plan / document data: if you upload a document, we extract structured content to support your grant matching profile. See retention (§6).
  • Payment data: processed by Stripe once paid tiers are active. We do not store card details.
  • Communications: emails and support requests.

3. How we use your data

PurposeLegal basis
Providing the GrantMatchr serviceContract performance
Running MatchScore assessmentsContract performance
Sending service emails (account, billing)Contract performance
Improving the platformLegitimate interests
Equality/bias monitoring (where data provided)Legitimate interests / consent
Complying with legal obligationsLegal obligation
Sending marketing emailsConsent

4. Automated decision-making

GrantMatchr produces grant assessments using a deterministic rules engine. We provide a transparency notice at each assessment output, an explanation of how the result was reached, and a functional human-review route.

Our assessments are indicative. An ELIGIBLE status does not guarantee funding. You should independently verify all grant requirements directly with the relevant funder. Grant opportunity data is sourced from publicly available third-party sources — see §6 Data Sources for attribution details.

5. Third-party processors and AI

We use Claude (developed by Anthropic PBC) as our AI model for extracting and structuring information from documents you provide. Claude does not make funding decisions — all eligibility and scoring decisions are made by our deterministic rules engine. Anthropic acts as a data processor under a Data Processing Agreement with us. We have configured our use of Anthropic's services to opt out of training data use.

A full list of our subprocessors is available on request at admin@grantmatchr.co.uk.

6. Data Sources

GrantMatchr incorporates data from the following public-sector and third-party sources. Attribution is provided in accordance with each source's licence terms.

  • Companies House — Public Data API

    When you provide a Companies House registration number, we retrieve company information (including name, entity type, registered address, incorporation date, and SIC codes) from the Companies House Public Data API. This data is Crown Copyright and is licensed under the Open Government Licence v3.0 (OGL v3.0). Contains public sector information licensed under the Open Government Licence v3.0.

  • Grant opportunity data

    Grant listings displayed on the platform are sourced from publicly available funder websites, official programme notices, and other open sources. We take reasonable steps to keep this data current, but it may not reflect the most recent changes made by funders. Always verify eligibility requirements directly with the relevant funder before applying.

7. Retention

  • Uploaded documents are subject to a 90-day auto-deletion default unless you explicitly opt in to retention for an active assessment.
  • Account data is retained for the duration of your account and deleted within 30 days of account closure. Consent records are the exception — see below — and are kept even if you never held an account with us.
  • Audit logs and immutable assessment snapshots are retained per our data retention policy for traceability purposes.

Consent records (including digest unsubscribes)

When you give or withdraw consent — for example, subscribing to or unsubscribing from our weekly funding digest — we keep a record of that decision. It contains your email address, what you were told at the time, and when you gave or withdrew consent. We keep these records permanently, including after you unsubscribe, and we do not delete them in response to an erasure request.

The reason is that the record is the mechanism that keeps you unsubscribed. It is what we check against before sending any marketing, so if we deleted it we would have no way of knowing you had asked us to stop, and you would be at risk of being added back and contacted again by mistake. Keeping a suppression list of people who have opted out — rather than deleting them — is the practice the UK's Information Commissioner's Office directs organisations to follow. The record also lets us demonstrate that we had your consent before sending you marketing, which we are required to be able to do. In law we rely on Articles 17(3)(b) and 17(3)(e) of the UK GDPR.

Your other rights are unaffected. Only erasure of the consent record itself is refused. You can still ask us for a copy of it, ask us to correct it if it is wrong, and object to or restrict other processing. If you ask us to erase your data, we will erase everything else we hold about you and tell you plainly that this record has been kept and why.

We keep nothing in these records beyond what is needed for that purpose. In particular, we do not record your IP address.

8. International transfers

We use subprocessors based in the UK and Ireland (EU). Where any transfer outside the UK occurs, we ensure an adequate transfer mechanism is in place in accordance with UK GDPR Chapter V.

9. Your rights

Under UK GDPR you have rights to: access your data (Art. 15); rectify inaccuracies (Art. 16); request erasure (Art. 17); restrict processing (Art. 18); data portability (Art. 20); and object to processing (Art. 21). Where processing is based on automated decision-making, you also have the right to request human review and to contest any outcome (Art. 22).

To exercise any right, email admin@grantmatchr.co.uk. We respond within one calendar month. You may also complain to the Information Commissioner's Office (ico.org.uk).

10. Cookies

We operate a Consent Management Platform (CMP) to obtain granular, withdrawable consent for non-essential cookies before they are set. You can withdraw consent at any time, as easily as you gave it, via the cookie preferences link in the footer of every page. See our Cookie Policy for full details.

11. Security

We implement appropriate technical and organisational measures including AES-256 encryption at rest, TLS 1.3 in transit, role-based access control, and signed URLs for document storage. In the event of a personal data breach posing a risk to your rights, we will notify you and the ICO as required by UK GDPR Articles 33–34.

12. Changes to this policy

We will notify you by email of material changes at least 14 days before they take effect.

13. Contact

Data protection enquiries: admin@grantmatchr.co.uk

Matchr Technologies Ltd · 7 Llysgwyn, Llangyfelach, Swansea, SA6 6BJ

GrantMatchr Logo
Copyright © 2026 GrantMatchr
Matchr Technologies Ltd, trading as GrantMatchr
Swansea, Wales · All rights reserved

GRANTMATCHR