Privacy Policy

Last updated: August 2026 

About this Privacy Notice 

This Privacy Notice is meant to give you information about what personal data we collect  about you, how we use it, why we use it, and how you control the data processing. 

Table of Contents 

  1. The Basics: Who We Are, Our Role, and Definitions
  2. Personal Data We Collect, How We Use it, and Why

2.1. Site Visitors 

2.2. Physical Tasting Stand Feedback (Minisite via Barcode Scan) 

2.3. Enforcement and Legal Compliance 

  1. Our Marketing Activities
  2. Sharing the Personal Data We Collect 
  3. International Transfers
  4. Security
  5. Your Rights – How to Control Our Use of Your Personal Data 
  6. Data Retention
  7. Cookies and Similar Technologies 
  8. Third-Party Services
  9. Children
  10. Changes to the Privacy Notice
  11. The Basics 

1.1. Who We Are. This site is an informational brand website operated by Grapa and  Top Fruit (together, “we”, “us”, or “our”). The site provides information about our  brand and product. 

The controllers of your personal data under this Privacy Notice are: 

(a) Grapa – Grapa Global LLC, of 11220 Edison Highway, Bakersfield, CA, 93307,  United States of America, registration number 33-3170607 contactable at  info@grapaglobal.com ; and 

(b) Top Fruit – Top Fruit International Limited, of 3rd floor, one London Square,  cross lanes, Guildford, Surrey, United Kingdom (GU1 1UN), registration number  14141768 contactable at robm@topfruit.co.za 

If you have questions about our company or your privacy, or want to exercise your rights,  you can contact us at liza@greenhousebrandstudio.com

1.2. Our Role: Controller. Certain data protection laws, including the laws in the EU and  UK, differentiate between a party that determines why and how personal data is  processed (called a “controller“) and a party that processes personal data solely  on the controller’s behalf and according to the controller’s instructions (called a  “processor“). We are the controller in respect of the processing described in this  Privacy Notice.

Grapa and Top Fruit each act as independent controllers in respect of the  processing described in this Privacy Notice. This means that each entity separately  determines the purposes and means of processing for its own purposes and is  independently responsible and accountable for its compliance with applicable data  protection laws. We are not joint controllers: neither entity processes personal  data on behalf of, or under the instructions of, the other, and each is solely  responsible for its own data processing activities as described herein. 

1.3. Definitions and Recommendations 

1.3.1. When we refer to the “site” and “services“, we mean our informational  website – tiqigrapes.com and related feedback mini-site(s) and related  online services. 

1.3.2. When we refer to “personal data“, we mean information that is defined as  personal data under law. This includes information that identifies you  directly or indirectly, including unique identifiers like IP addresses or cookie  IDs. 

1.3.3. When we refer to “you“, we mean visitors to our site, individuals who submit  inquiries through our contact form, and provide feedback on tasting  experience. 

1.3.4. This Privacy Notice is meant to be read together with any other contractual  document you may have with us for the provision of applicable services. In  general, we recommend that you routinely review this Privacy Notice and  your preferences on our site. 

1.4. A Note on Legal Bases. Certain jurisdictions only allow the processing of personal  data where a legal basis has been established. Under the EU’s General Data  Protection Regulation (“GDPR“) and the UK’s General Data Protection Regulation  (“UK GDPR“), the possible legal bases include (but are not limited to): your  consent, the processing is necessary to perform a contract with you, the processing  is necessary to fulfill our legal obligations, or a company has a legitimate business  interest to process your personal data. Where we are a controller, we only collect  and process data where we have established a legal basis. Below you can find more  details about specific legal bases. Under Israeli law, the legal basis for processing is  consent. You are not required under law to provide us with the Personal Data  described in this Privacy Notice. However, if you do not agree to provide the same,  we will not be able to provide you with some or all of our Services. 

  1. Personal Data We Collect, How We Use It, and Why. Below is a description of the types  of personal data we collect, how we use it, and the reason why we consider each use  lawful. You have no legal obligation to provide us with personal data, but if you don’t  provide us with certain information, we may not be able to provide you with certain site  functionality or the associated services.

2.1. Site Visitors. When you visit our site, we may collect the following types of data  about you. 

2.1.1. Contact Form Information – When you send us a message through the  contact form on our site, we collect data you provide, such as your name, country, email address, and the content of your inquiry. 

How We Use this Data: To (i) respond to your inquiry, (ii) manage our  relationship with you, (iii) where applicable, to take steps at your request  prior to entering into a contract, or business relationship, and (iv) to provide  newsletters and other promotional materials. 

Legal Basis: When we use this data to respond to your inquiry or manage our  relationship with you, we do so on the basis of our legitimate interests in  operating our business and responding to communications you initiate, and,  where applicable, to take steps at your request prior to entering into a  contract. When we use this data to send you newsletters or other  promotional materials, we do so on the basis of your consent, in jurisdictions  where required by law. You can withdraw consent at any time using the  unsubscribe link or by contacting us at liza@greenhousebrandstudio.com

2.1.2. Activity and System Data (Including Cookies) – When you visit our site, we  automatically collect data about your computer or mobile device, including personal data such as your IP address, device ID, usage data, metadata, and  your activity on our site (e.g. what pages you visited, for how long, and what  links you clicked on). For more information about the Cookies we use and  how to adjust your preferences, see the Cookies and Similar Technologies 

section below.  

How We Use this Data: (a) to provide and secure the site and related services  you request; and (b) to generate aggregated analytics to maintain and  improve the site and our services, including customer retention, analyzing  usage patterns and predicting customer needs, identifying market trends.  One of the tools we use to collect and analyze this data is Google Analytics.  For more information about how Google collects information and how you  can control such use, see: www.google.com/policies/privacy/partners/

Legal Basis: Providing the site and related services you request is necessary  for the performance of a contract with you (our site terms). Improvement  and analytics activities are based on your consent for nonessential cookies (which you may withdraw at any time via our cookie banner or preference  center). 

2.2. Physical Tasting Stand Feedback (Minisite via Barcode Scan). At physical tasting  events (or otherwise), attendees may scan a barcode that directs them to a  minisite where they can leave feedback about our grape variety. The minisite does  not actively request or require any personal data from you. However, if you  voluntarily include personal data in the free-text feedback field (for example, your  name or contact details) that data will be processed for the purpose of considering  and using your feedback in connection with product development and quality  improvement. 

Legal Basis: Where you voluntarily provide personal data in your feedback, we  process that data on the basis of our legitimate interests in product development  and quality improvement, and by virtue of the fact that you have chosen to provide  that information voluntarily. 

2.3. Enforcement and Legal Compliance. In all cases, we may also process personal data  as necessary to enforce our rights and contracts, protect our assets, prevent and  respond to fraud, security, or legal incidents, and to pursue available remedies or  limit damages we may sustain. We carry out this processing on the basis of our  legitimate interests and, where applicable, to comply with legal obligations. 

  1. Our Marketing Activities. As described above, we may use personal data we collect for  marketing purposes. We try to limit the marketing material we send to a reasonable and  proportionate level. We send marketing communications on the basis of your consent.  You can withdraw your consent at any time using the unsubscribe link in our emails or by  contacting us at liza@greenhousebrandstudio.com to request to unsubscribe. We may  tailor communications based on your interests and location. We may also use engagement  metrics (e.g., opens and clicks) derived from cookies and similar technologies embedded  in marketing materials we send you; for more information, see the Cookies and Similar  Technologies section below. 
  2. Sharing the Personal Data We Collect. We share your personal data as follows: 

4.1. Affiliates. Each Grapa and Top Fruit is a controller of the personal data processed  under this Privacy Notice, regardless of which of us actually collected that data  from you. In addition, each of us may share personal data with our respective  affiliates to operate our business, and otherwise to execute the purposes  described in this Privacy Notice.  

4.2. Service Providers. Below is a list of the types of service providers we use, the  service each provides, and the types of data shared with each. All service providers  have agreed to confidentiality restrictions and have undertaken to use your  personal data solely as we direct. 

Type of Service  Description  Personal Data Shared
Productivity,  

Collaboration and  CRM Platform

Productivity and collaboration  platform providing email,  document storage/collaboration,  and CRM capabilities used to  manage inquiries received  through our contact form and our  relationship with you; device and  endpoint management; and  assistance features to increase  productivity. Name, email address,  country, and content of  inquiry, and feedback as  described above.
Email Marketing and Campaign  Management Mailing list and campaign  management service used to  send newsletters and updates to  optedin recipients and to  measure engagement for  Name and email address.

 

performance evaluation and  personalization.
Hosting, IT support,  and site development Hosting, maintenance, and  technical support services that  may involve incidental access to  systems for troubleshooting,  performance, and security. All personal data  described in this Privacy  Notice.

 

4.3. Change of Ownership. If we are looking to sell our companies, liquidate assets, or  merge with another, assign, transfer, or otherwise reorganize all or part of our  business, assets, or operations, including in connection with the establishment of  a new group company or intellectual property holding entity, we may share your  personal data with other interested parties as part of negotiations toward that  transaction. In such case, or where we do sell our companies, your personal data  shall continue to be subject to the provisions of this Privacy Notice . 

4.4. Law Enforcement Related Disclosure. We may share your personal data with  government agencies or other relevant parties, such as a law office or independent  auditor: (i) if we believe that such disclosure is appropriate to protect our rights,  property or safety (including the enforcement of site terms of service and this  Privacy Notice) or those of a third party; (ii) if required by law or court order; or (iii)  as is necessary to comply with any legal and/or regulatory obligations, such as  audit requirements.  

  1. International Transfers. Some of our service providers and affiliates are located in  countries other than your own. When we transfer your personal data internationally, we  will do so safely and securely and in accordance with applicable law, including the GDPR  and, where applicable, the UK GDPR. 

5.1. If you are located in the EU or the UK, when we share your personal data with third  parties based outside of the European Economic Area (EEA) or the UK, respectively,  we ensure that such transfers are made in accordance with applicable law. To that  end, we implement one or more of the following safeguards: 

5.1.1. When we transfer your personal data to a country that the European  Commission has recognized as providing an adequate level of data  protection, we rely on that adequacy decision and, for transfers from the  UK, on the UK’s corresponding adequacy regulations recognizing that  country. 

5.1.2. When we transfer your personal data to entities in the United States that  participate in the EUUS Data Privacy Framework, we rely on the European  Commission’s adequacy decision for those certified organizations and, for  transfers from the UK, on the UK Extension to the EU-US Data Privacy  Framework (the “UK-US Data Bridge”) where the recipient participates in it. 

5.1.3. Where we transfer your personal data to other countries or to US entities  that are not DPFcertified, we use the European Commission’s Standard  Contractual Clauses (or, for transfers from the UK, the UK International Data  Transfer Agreement or the UK Addendum to the EU Standard Contractual  Clauses) and, where appropriate, additional supplementary measures.

5.1.4. Please contact us at liza@greenhousebrandstudio.com if you would like  further information on the specific mechanism used by us when transferring  your Personal Data out of the EEA or the UK. 

  1. Security. We maintain organizational and technical measures designed to protect  personal data against accidental or unlawful destruction, loss, alteration, unauthorized  disclosure, or access. Measures include rolebased access controls across our platforms,  multifactor authentication for users, device management for company endpoints, and  endpoint protection. Access to personal data is limited to personnel with a need to know  and is periodically reviewed. We also require appropriate safeguards from our service  providers. While we cannot guarantee absolute security, we work to maintain protections  aligned with the nature of our processing and industry practice. 
  2. Your Rights – How to Control Our Use of Your Personal Data. Depending on which laws  apply, you have certain legal rights over your data, including under the GDPR and, where  applicable, the UK GDPR. Below is some general information about rights that may apply  to you, but we recommend checking the law or consulting with a lawyer to understand  what applies in your specific case. To exercise your rights, please contact us at liza@greenhousebrandstudio.com. We may ask for reasonable evidence to verify your  identity before we can comply with any request. 

7.1. Right of Access. You may have a right to know what personal data we collect about  you. We may charge you with a fee to provide you with this information, if  permitted by law. If we are unable to provide you with all the information you  request, we will do our best to explain why. See Article 15 of the GDPR, or the  equivalent Article 15 of the UK GDPR, for more details, if your personal data is  subject to the GDPR or the UK GDPR. 

7.2. Right to Correct Personal Data. You may request that we update, complete, correct  or delete inaccurate, incomplete, or outdated Personal Data. See Article 16 of the  GDPR, or the equivalent Article 16 of the UK GDPR, for more details, if your  personal data is subject to the GDPR or the UK GDPR. 

7.3. Deletion of Personal Data (“Right to Be Forgotten”). If you are located in the EU or  the UK, you may have the right to request that we delete your personal data. Note  that we cannot restore information once it has been deleted. Even after you ask  us to delete your personal data, we may be allowed to keep certain data for specific  purposes under applicable law. See Article 17 of the GDPR, or the equivalent Article  17 of the UK GDPR, for more details, if your personal data is subject to the GDPR  or the UK GDPR. 

7.4. Right to Restrict Processing. If you are located in the EU or the UK, you may have  the right to ask us to stop processing your personal data. See Article 18 of the  GDPR, or the equivalent Article 18 of the UK GDPR, for more details, if your  personal data is subject to the GDPR or the UK GDPR. 

7.5. Right to Data Portability. If you are located in the EU or the UK, you may have the  right to request that we provide you with a copy of the personal data you provided  to us in a structured, commonly-used, and machine-readable format. See Article  20 of the GDPR, or the equivalent Article 20 of the UK GDPR, for more details, if 

your personal data is subject to the GDPR or the UK GDPR. 

7.6. Right to Object. If you are located in the EU or the UK, you may have the right  object to certain processing activities. See Article 21 of the GDPR, or the equivalent  Article 21 of the UK GDPR, for more details, if your personal data is subject to the  GDPR or the UK GDPR. 

7.7. Withdrawal of Consent. If we are processing your data based on your consent, you are always free to withdraw your consent, however, this won’t affect processing we have done from before you withdrew your consent. 

7.8. Right to Lodge a Complaint with Your Local Data Protection Authority. If you are  located in the EU or the UK, you have the right to submit a complaint to the  relevant data protection authority – including, if you are in the UK, the Information  Commissioner’s Office (ICO) – if you have any concerns about how we are  processing your personal data, though we ask that as a courtesy you please  attempt to resolve any issues with us first. 

7.9. Your Rights Under Israeli Law. If you are subject to Israeli law, you may request to  access any personal data you have provided to us and request that such personal  data be corrected, updated, or deleted, including in accordance with Articles 13  through 14 of the Israeli Privacy Protection Law, 1981. You may exercise such rights  by emailing us at info@grapaglobal.com. You may have the right to delete your  personal data subject to and in accordance with Article 3 of the Israeli Privacy  Protection Regulations (Provisions Regarding Information Transferred to Israel  from the European Economic Area), 2023. 

  1. Data Retention.  

8.1. We retain your personal data as long as necessary to fulfill each of the purposes  we described above. When deciding how long to store personal data, we consider  the amount, nature, and sensitivity of the personal data, the potential risk of harm  from unauthorized access, the purposes for which the personal data was collected,  as well as applicable legal requirements. Please note that we may delete  information from our systems without notifying you first. Retention by any of our  service providers or subcontractors may vary in accordance with each business’s  retention policy.  

8.2. In some circumstances, we may store your personal data even after we’re finished  using it if required to do so by law (e.g. to fulfill tax or audit requirements), or to keep accurate records of our interactions in case there is a prospect of litigation  relating to your personal data. In such cases, we will maintain the same security  measures as described above. 

  1. Cookies and Similar Technologies. 

9.1. What are Cookies? A cookie is a small piece of text that is sent to your browser by  a site you visit. This piece of text acts as a sort of tag, letting the site know that it’s  you (really, your device) that’s visiting. There are other technologies that act  similarly, like web beacons, pixel tags, and Device IDs for apps, but for simplicity’s  sake we’ll refer to them all as “cookies“.

9.2. First-Party / Third-Party Cookies. Sites can place their own cookies (called “first party cookies“) but can also place cookies from other sites (called “third-party  cookies“). If your browser holds both first and third-party cookies for a given site,  both the site and the third party are notified when you visit the site. We may place  both first and third-party cookies on our site.  

9.3. How We Use Cookies. While the specific names and types of cookies we use may  change from time to time, they generally fall into one of the categories listed  below.  

Cookie Type  Function
Necessary  These cookies allow the site to work correctly. They enable your access  to the site, move around, and access different services, features, and  tools. They also help us identify and prevent security risks, for example  by storing your session information to prevent others from changing  your password without your login information. These cookies cannot  be disabled.
Performance /Analytics These cookies and similar technologies (such as pixel tags in emails)  collect analytical information to help us understand how you use our  site and interact with our email communications, for example whether  you have viewed messages, clicked on links, and how long you spent  on each page. This helps us improve our site and marketing  communications to better suit your needs.
Advertising  These cookies and similar technologies are used to build a profile of  your interests based on your browsing activity on our site and  elsewhere, and to deliver personalized advertising and retargeting  content to you, including on third-party sites and platforms, based on  that profile – for example, showing you ads for our products after you  have visited our site. These cookies may also be used to measure the  effectiveness of our advertising campaigns and to limit the number of  times you see a given ad.

 

9.4. Third Party Cookies. In addition to our first-party cookies, we place cookies from  the third parties listed below who serve as independent data controllers of your  personal data and who process such data in accordance with their respective  privacy notices: 

  • Google LLC – Google Analytics (Performance/Analytics). For further  information, please see section 2.1.2. 

9.5. How to Adjust Your Preferences. Most web browsers are initially configured to  accept cookies, but you can change the settingsso your browser refuses all cookies or certain types of cookies. In addition, you are free to delete any existing cookies  at any time. Please note that some features of the services may not function  properly when cookies are disabled or removed. For example, if you delete cookies  that store your account information or preferences, you will be required to input  these each time you visit. 

  1. Third-Party Services. You may have access to third-party services through our services.  Please note that all use of third-party services is at your own risk and subject to such third  party’s terms and privacy policies. We do not take any responsibility for the performance  of other services.
  2. Children. We do not knowingly collect nor transfer personal data from/of children under  the age of eighteen (18). In the event that you become aware that an individual under the  age of eighteen (18) has provided data without parental permission, please advise us  immediately.  
  3. Changes to the Privacy Notice. We may update this Privacy Notice from time to time to  keep it up to date with legal requirements and the way we operate our business. We will  place any updates on this webpage. Please come back to this page every now and then to  make sure you are familiar with the latest version.