Privacy Policy
Company: Growwwth Lab Limited, a company incorporated in England and Wales under number 11873185, whose registered office is at 42 Bloom Heights, River Rise Close, London SE8 5FT, trading as Growwwth (“we,” “our,” or “us”).
Website: https://growwwth.uk
Privacy contact: hello@growwwth.uk
ICO Registration Number: ZC152000
1. About this policy
This policy explains what we do with personal data in connection with our website at growwwth.uk and with the Google review service we provide to our clients. It is written to meet the transparency requirements of Articles 12, 13 and 14 of the UK General Data Protection Regulation (“UK GDPR”), read with the Data Protection Act 2018 (“DPA 2018”) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”).
Article 12 of the UK GDPR requires this information to be given in clear and plain language, so it is written that way deliberately rather than in the style of a contract.
We are registered with the Information Commissioner’s Office under registration number ZC152000.
2. The two roles we act in
This is the most important section of this policy, because our obligations differ depending on whose data is involved.
We are the controller of personal data about the people who visit our website, enquire about our service, book a demonstration with us, are contacted by us about our own service, and work for our client businesses. We decide why and how that data is used, and this policy explains it.
We are a processor of the customer contact data our clients give us so that we can ask their customers for reviews on their behalf, and of the reviews left about them, which we read and reply to on their behalf. The client is the controller of that data. They decide who is contacted and why; we act on their documented instructions and nothing else. We do not use their customer data for our own purposes, we do not market to it, and we do not sell, rent or share it other than with the sub-processors listed in section 8.
The terms governing that processing are set out in Schedule 1 (Data Processing Agreement) to our Terms and Conditions at growwwth.uk/terms, which satisfies the requirements of Article 28(3) of the UK GDPR.
If you are a customer of one of our clients and want to know why you received a message, the business named in that message is the controller of your data and is the right place to ask. We will help them answer you, and you can also contact us directly at hello@growwwth.uk.
3. Personal data we process as controller
3.1 Website visitors
Our website is a static site. It sets no cookies, hosts no forms, embeds nothing, and runs no third-party JavaScript. Loading a page on it makes no request to any server other than growwwth.uk — the typefaces, the icon and everything else are served by us, so no other company sees that you visited. When you visit it we process:
- Server and network log data: IP address, browser and operating-system information, the date and time of the request, the pages requested, referring URL and response codes. This is generated automatically by our hosting provider and used for security and to keep the site working.
- Cookieless analytics signals: aggregated measurements of how many people visit and which pages they read, collected without setting any identifier on your device. No individual can be identified from this data.
Our Cookie Policy at growwwth.uk/cookies has the detail.
3.2 People who book a demonstration or contact us
If you book a call with us, you enter your details on a booking page operated for us by HighLevel Inc. (GoHighLevel), our customer-relationship platform. That page is not on growwwth.uk, but the data is collected for us and we are the controller of it. We process your name, business name, email address, telephone number and anything else you choose to tell us, in order to arrange the call, prepare for it, and follow up about the service you enquired about.
If you email hello@growwwth.uk, we process your email address, your name, and the content of your message, for the same purpose.
Our website tells you that by booking a call you agree to be contacted about your enquiry by email, telephone or SMS. You can stop those messages at any time by replying STOP to an SMS, using the unsubscribe link in an email, or emailing hello@growwwth.uk.
3.3 Businesses we approach about our own service
We approach UK local businesses directly to introduce our service. We do this by telephone and by email. We process the business name, a contact name where one is published, and the business telephone number, email address and postal address, obtained from publicly available sources such as Google Business Profile listings, business websites and public directories. Article 14 of the UK GDPR requires us to tell you this if we hold your data and did not get it from you.
We rely on legitimate interests: introducing a business service to a business we believe it suits. We have assessed that this is proportionate, that we use only business contact details the business has itself published, and that it is what a business would reasonably expect. You can object at any time under Article 21 of the UK GDPR, and we will stop.
Calls. Marketing calls are governed by Regulation 21 of PECR. Before we call, we screen the number against both the Telephone Preference Service and the Corporate Telephone Preference Service, and we do not call a registered number unless that business has told us it does not object. We re-screen regularly so that our checks stay current. We identify ourselves at the start of every call, give a contact address on request, and do not withhold our number.
Emails. Marketing email is governed by Regulation 22 of PECR, which protects individual subscribers. A sole trader and an ordinary partnership are individual subscribers, so we do not send marketing email to them unless they have consented. We send marketing email only to corporate subscribers — limited companies and limited liability partnerships — and we check a business’s status before we email it. Every email identifies us, gives our registered address, and carries a working unsubscribe link. We never conceal or disguise who the message is from, as Regulation 23 of PECR requires.
If you tell us not to contact you again, by any route, we stop, permanently, across both channels. We keep the minimum record needed to make certain of that, as explained in section 9.
3.4 Our clients and the people who work for them
When a business becomes a client we process the account and contract data needed to provide and bill the service: the name, email address and telephone number of the people we deal with, the business name and address, the Google Business Profile and social accounts we are given access to, billing details, records of the service we have delivered, support correspondence, and platform activity logs.
Payment card details are handled by our payment provider. We do not store full card numbers.
4. Personal data we process as a processor for our clients
Our clients give us contact data about their own customers so that we can ask those customers for a review. This is typically a first name, and an email address, a mobile number, or both, together with the date and type of the job the client carried out. The data reaches us as a file the client exports, or through a connection to the client’s own accounting, CRM or job-management software.
We use it to send review request messages in the client’s name, to follow up where no review is left, to record whether a message was delivered, opened, clicked or replied to, and to record and honour opt-outs.
We also read the client’s Google reviews, which are public, so that we can publish their new five-star reviews to their own Facebook and Instagram accounts where they have asked us to, so that we can write and publish replies to reviews in the client’s name, and so that we can report to them each month. A reply is written from what the reviewer chose to publish and nothing else, and we do not reply to every review. We do not monitor other review platforms.
We do not enrich the data, profile it, sell it, or use it for anything other than the client’s instructions. Section 9 sets out how long we keep it.
5. Why we process it, and our lawful basis
| What we process | Why | Lawful basis (UK GDPR Article 6) |
|---|---|---|
| Server and network log data | Security, fraud and abuse prevention, keeping the site available | Legitimate interests: running a secure website |
| Cookieless analytics | Understanding which pages are read, in aggregate | Legitimate interests: measuring our own marketing, with no impact on individual privacy |
| Demonstration bookings and enquiries | Arranging and holding the call, answering the enquiry, following up about the service | Steps taken at your request before entering a contract (Article 6(1)(b)); legitimate interests where the enquiry is not about a possible contract |
| Approaching businesses about our service, by telephone and email | Introducing our service to a business we think it suits | Legitimate interests: direct business-to-business marketing, subject to the Regulation 21 and Regulation 22 limits described in section 3.3 |
| Client account, contract and support data | Providing the service, supporting it, and billing for it | Performance of our contract with the client (Article 6(1)(b)) |
| Accounting and tax records | Meeting our statutory obligations | Legal obligation (Article 6(1)(c)) |
| Establishing, exercising or defending legal claims | Protecting our position in a dispute | Legitimate interests |
| Our clients’ customer contact data, and the reviews published about them | Sending review requests, and writing and publishing replies, on the client’s instructions | We are the processor; the client determines and is responsible for the lawful basis |
We do not ask for, and do not want, special category data as defined in Article 9 of the UK GDPR. If someone sends us any, we delete it unless we are required to keep it.
Where we rely on legitimate interests, we have assessed that the processing is necessary and proportionate and does not override the rights of the people concerned. You can ask us for that assessment.
6. Review request messages and the UK marketing rules
Review requests go to people who already have a customer relationship with the business named in the message, about the job that business carried out for them. Every message names that business, and every message carries a working opt-out.
We treat review requests as direct marketing for the purposes of Regulation 22 of PECR and rely on the exemption at Regulation 22(3), commonly called the soft opt-in. That exemption applies where the contact details were obtained in the course of a sale or negotiations for a sale to that person, the message concerns similar products or services, and the person was given a simple means of refusing, both when their details were collected and in every message since.
Because the client instigates the messages and we transmit them, both of us can be responsible under PECR. We divide that responsibility as follows:
- The client warrants that the contacts they give us are their own past or present customers, that the details were collected lawfully, that their own privacy notice covers this use, and that nobody on a suppression or do-not-contact list is included. This is a contractual obligation in our Terms and Conditions.
- We operate the controls. Every message carries a working opt-out. Opting out takes effect immediately and permanently, and the contact is added to that client’s suppression list, which we check before every send. We limit how often the same person is contacted and leave a reasonable interval between requests. We never gate or filter recipients by expected sentiment, and we never offer any incentive for a review.
Opting out is per business. When you opt out, you are telling the business named in the message to stop contacting you, and that business is the controller of your data. We suppress you for that business, permanently. We do not apply it to other businesses we work for, because they are separate controllers with their own relationship with you — an objection you make to your plumber is not an instruction to your vet. Applying it more widely would also mean us linking your data across unrelated businesses for a purpose nobody has asked for, which we do not do.
A suppression list belongs to the client it was built for. When that client leaves us, we return their list to them so that they can keep honouring it, and we delete our copy with the rest of their data. Section 9 sets out the timing.
7. Cookies and analytics
Our website sets no cookies and uses no advertising, marketing or behavioural tracking technology. Analytics are produced by Cloudflare from the server logs it generates as it delivers the site to you. Nothing runs in your browser to measure you: no script, no identifier on your device, and no tracking of you across sites — only aggregated counts of requests and pages. Because nothing is stored on or read from your device beyond what is strictly necessary to deliver the page, the consent requirement in Regulation 6 of PECR is not engaged and we display no cookie banner.
The booking page you reach when you click a booking link is operated by HighLevel Inc. and is not part of growwwth.uk. It may set its own cookies, governed by its own notices.
If we ever introduce a cookie that requires consent, we will put a compliant consent mechanism in place first. Our Cookie Policy has the detail.
8. Who we share personal data with
We do not sell personal data and we do not share it for anyone else’s marketing. We share it only where we need to in order to run the service.
Not everyone below plays the same role, and the difference matters. Those who process personal data on our behalf and on our instructions are our processors, and each is bound by a written contract meeting Article 28 of the UK GDPR. Others decide for themselves how they use data on their own platforms, or receive it in their own right — they are independent controllers, and their own privacy notices govern what they do. The role column says which is which.
| Provider | What they do | Role | Where |
|---|---|---|---|
| HighLevel Inc. (GoHighLevel) | The platform the service runs on: contact records, campaign automation, email and SMS delivery, calendar bookings, and the automated drafting described in section 15 | Our processor | United States |
| Cloudflare, Inc. | Website hosting, content delivery, network security, and cookieless analytics | Our processor | United States and global edge network |
| Zoho Corporation B.V. | Email platform for onboarding and account correspondence | Our processor | European Union |
| Google LLC | Reading our clients’ Google reviews through the Business Profile API, and publishing replies to them in the client’s name, so that we can publish qualifying reviews, reply and report | Independent controller for its own platform | United States |
| Meta Platforms, Inc. | Publishing review posts to the client’s own Facebook and Instagram pages | Independent controller for its own platform | United States |
| Stripe, Inc. | Card payment processing for client subscriptions | Independent controller for payment processing | United States |
| Professional advisers, and law-enforcement, regulatory or judicial bodies | Legal, accounting and audit advice, and disclosures we are lawfully required to make | Independent controllers and lawful recipients, not processors | United Kingdom and others as applicable |
SMS and email messages are sent through the HighLevel platform. HighLevel uses its own sub-processors, including telecommunications carriers and email delivery providers, to deliver them. We do not contract with those providers directly, and HighLevel is answerable to us for them under our contract with it. Telephone numbers used to send messages are held by HighLevel.
The artificial intelligence described in section 15 is HighLevel’s, and runs inside that platform. We have not engaged a separate artificial intelligence provider, and no personal data is sent to one. If that changes we will add it to the table above and tell our clients at least 30 days beforehand, as Schedule 1 to our Terms and Conditions requires.
If we reorganise, merge or transfer our business, personal data may be transferred as part of it, and the recipient will be bound by this policy.
9. How long we keep it
| Data | Retention |
|---|---|
| Server and network logs | 90 days, unless needed longer to investigate a specific security incident |
| Analytics | Aggregated only, with no individual-level identifier at any stage |
| Enquiries and demonstration bookings that do not become clients | 24 months from the last contact |
| Prospect data from our own telephone and email outreach | 12 months from the last contact, unless a relationship develops |
| Client account, contract and billing records | Duration of the contract, then 6 years, to meet tax and accounting obligations and the limitation period for contract claims |
| Client’s customer contact data (processed on their behalf) | Duration of the contract, then 30 days, after which it is deleted or returned |
| Message and campaign activity, at the level of an individual (what was sent to whom, and what came back) | This is part of the client’s customer data and follows the row above: duration of the contract, then 30 days |
| Aggregated campaign statistics, with no individual identifier | Duration of the contract, then 12 months |
| Support correspondence | 3 years from the last contact |
| A client’s suppression list (people who opted out of that client’s messages) | Duration of the contract. On exit it is returned to the client, who must keep honouring it, and our copy is deleted within 30 days with the rest of their data |
| Our own do-not-contact list (businesses and people who have told us to stop contacting them about Growwwth) | Kept indefinitely. We hold the minimum data needed — a masked identifier and the date — to make certain we never contact you again. Deleting it would put us at risk of contacting someone who has told us not to |
Those two are deliberately different, because the roles are different. A suppression list built for a client is that client’s data and we hold it as their processor, so it leaves when they do. Our own do-not-contact list records a decision made about us, we are the controller of it, and the only way to honour it is to keep it.
10. Sending data outside the United Kingdom
Several of the providers in section 8 are based in the United States or run infrastructure outside the UK. Where personal data is transferred to a country without UK adequacy regulations, we rely on:
- The International Data Transfer Agreement, or the ICO’s International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, as appropriate to the provider, issued under section 119A of the DPA 2018; and
- Supplementary measures, including encryption in transit and at rest and contractual limits on government access, informed by a transfer risk assessment for each flow.
For transfers to the United States, we rely on the UK Extension to the EU-US Data Privacy Framework where the recipient is certified under it, per the Data Protection (Adequacy) (United States of America) Regulations 2023.
11. Security
We use technical and organisational measures appropriate to the risk, as Article 32 of the UK GDPR requires. These include encryption in transit and at rest, role-based access control on the principle of least privilege, multi-factor authentication on administrative accounts, network and application protection at our hosting edge, confidentiality obligations on anyone who can access personal data, and a documented procedure for identifying, containing and reporting a personal data breach.
Where a breach is likely to result in a risk to people’s rights and freedoms, we will report it to the ICO within 72 hours and tell the people affected without undue delay. Where we are the processor, we will tell the client without undue delay so that they can meet their own obligations.
No transmission over the internet can be guaranteed secure. Please do not send us anything highly sensitive by email.
12. Your rights
Where we are the controller, you have the right to ask us to give you a copy of your personal data, correct it if it is wrong, delete it, restrict what we do with it, give it to you or another provider in a portable format, and stop processing it where we rely on legitimate interests. You can object to direct marketing at any time and we will stop. Where we rely on consent, you can withdraw it at any time without affecting what we did before.
We take no decisions about anyone that produce legal or similarly significant effects and are based solely on automated processing.
To exercise any of these rights, email hello@growwwth.uk. We will respond within one calendar month. If a request is complex, or if you make several, we may extend that by up to two further months and will tell you if we do.
If we hold your data as a processor — that is, if you are a customer of one of our clients — please contact that business, as they are the controller. If you contact us instead, we will pass your request to them promptly and help them respond. We will always action an opt-out immediately whoever it comes from.
13. Complaining to the regulator
If you are unhappy with how we have handled your personal data, please tell us first at hello@growwwth.uk so that we can put it right. You also have the right to complain to the Information Commissioner’s Office at any time:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone: 0303 123 1113
Website: https://ico.org.uk
14. Children
Our service is sold to businesses and is not directed at children. We do not knowingly collect personal data about anyone under 18. Our clients must not give us contact data for children. If we learn that we hold data about a child, we will delete it without undue delay.
15. Automated drafting and artificial intelligence
We use automated tools, which may include artificial intelligence, to draft the wording of review request messages, to decide when messages are sent, and to write the replies we publish to our clients’ Google reviews.
Review request messages are approved by our client before anything is sent to anyone, and no message content is generated from an individual’s personal data beyond using their first name.
Replies to reviews are different, and we say so plainly: our client approves the voice we reply in before we start, but each individual reply is written and published automatically, without a person reading it first. A reply is written from the review the person chose to publish and from nothing else. We hold no other information about a reviewer, we do not try to identify them, and we do not combine a review with anything else we hold.
Nothing about an individual is decided by automated means. These tools produce wording; they make no decision that has a legal or similarly significant effect on anyone.
If a reply we published concerns you and you want it corrected or removed, tell us at hello@growwwth.uk and we will ask our client, who controls the profile it appears on. Section 12 sets out your rights.
16. Changes to this policy
We may update this policy to reflect changes in what we do or in the law. The version and effective date at the top of this page always show the current version. Where a change materially affects your rights, we will give notice on the website and, for clients, by email.
17. Contact
Growwwth Lab Limited
42 Bloom Heights, River Rise Close, London SE8 5FT
Email: hello@growwwth.uk
Website: https://growwwth.uk
We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR and have not appointed one. Privacy enquiries are monitored at the address above and answered within the statutory time limits.