Legal

Privacy Policy

Last updated: August 2026

GIZE PLC (“we”, “us”, or “our”) is committed to protecting the privacy of visitors to our website and the clients, partners, and contacts we work with. This policy explains what information we collect, why we collect it, how we use it, and the rights you have under applicable data protection laws, including the EU General Data Protection Regulation (GDPR).

1. Information We Collect

Information you provide directly: We collect information you provide to us — for example, when you fill out our contact form, request a consultation, or email us. This may include your name, email address, phone number, company, and the nature of your enquiry.

Information collected automatically (anonymous): We use a privacy-friendly analytics tool called Umami to collect aggregate, anonymized usage data — such as page views, approximate geographic region (country level), device type, and referring website. Umami is cookieless, does not store identifiable IP addresses, and does not track individuals across sessions or other websites. This data is used solely in aggregate to understand how the website is used and to improve it.

2. Legal Basis for Processing

Under the GDPR, we process personal information you provide (such as contact form submissions) on the basis of:

  • Your consent — when you voluntarily submit your details through our contact form or email us.
  • Contractual necessity — when we engage with you to provide services you have requested.
  • Legitimate interests — to respond to your enquiries, maintain security, and improve our website and services, where these interests are not overridden by your rights.
  • Legal obligation — where we are required to retain or disclose information under applicable law.

For anonymous analytics data collected via Umami, no personal data is processed (IP addresses are not stored in identifiable form, and no cookies are set), so the GDPR does not apply to this data. If you have enabled “Do Not Track” in your browser, Umami respects this signal by default.

3. How We Use Your Information

  • To respond to your enquiries and provide the services you request.
  • To send you relevant updates, quotes, or follow-up communications where you have indicated you would like to receive them.
  • To improve our website, services, and client experience using aggregate, anonymous analytics.
  • To comply with applicable legal and regulatory obligations in Ethiopia and the jurisdictions where we operate.

4. Sharing Your Information

We do not sell, rent, or trade your personal information. We may share it with trusted service providers who help us operate our business (such as the hosting provider for this website and the third-party service that forwards contact form submissions to our email), only to the extent necessary, and under appropriate confidentiality obligations. We may also disclose information where required by law. Anonymous analytics data collected via Umami is processed by Umami’s cloud service under their privacy policy, but contains no personal data.

5. International Transfers

Your information may be processed in countries outside your country of residence, including Ethiopia and the European Union. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as standard contractual clauses, or the recipient is subject to an adequacy decision. Anonymous analytics data is not personal data and is not subject to transfer restrictions.

6. Data Retention

We retain personal information only for as long as is necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Contact form submissions are retained for a period of up to 24 months, after which they are deleted unless an ongoing business relationship exists. Anonymous analytics data is aggregated and retained indefinitely, but cannot be linked back to you.

7. Your Rights Under GDPR

If you are in the European Economic Area, you have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data (“right to be forgotten”).
  • Restriction — request that we limit processing of your data.
  • Data portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdrawal of consent — withdraw consent at any time without affecting processing already carried out.

To exercise any of these rights, contact us at gize@gizeplc.com. You also have the right to lodge a complaint with your local data protection authority.

8. Security

We take reasonable technical and organisational measures to protect your information against unauthorised access, loss, or misuse. However, no method of transmission over the internet is fully secure, and we cannot guarantee absolute security.

9. Changes to This Policy

We may update this policy from time to time. Any changes will be posted on this page with a revised “last updated” date.

10. Contact

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at gize@gizeplc.com or via our contact page.