Skip to content

Data, IP and marketing

Data Protection Policy

How personal data is collected, used, shared and retained, and how to exercise your rights under UK GDPR.

GROW is committed to protecting personal data and respecting the privacy of everyone we work with, including customers, learners, Licensed Providers, Accredited Coaches and business contacts.

This policy explains how GROW collects, uses, stores and protects personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Scope

This policy applies to all personal data processed by GROW in connection with its programmes, services, accreditation and certification activities.

Our Commitment

When handling personal data, GROW will:

  • Process personal data lawfully, fairly and transparently
  • Collect only the information needed for a legitimate purpose
  • Keep personal data accurate and up to date where possible
  • Store personal data securely
  • Retain personal data only for as long as necessary
  • Respect individuals' rights in relation to their personal data

The Information We Collect

Depending on the service being provided, GROW may collect and process:

  • Names
  • Postal addresses
  • Email addresses
  • Telephone numbers
  • Payment and transaction records
  • Learner records
  • E-learning progress data
  • Assessment records and supporting documentation
  • Coaching records
  • Community participation data
  • Communications with GROW

In some circumstances, GROW may also collect information relating to accessibility requirements, learning support needs, disabilities or other information disclosed for the purpose of making reasonable adjustments.

How We Use Personal Data

GROW uses personal data to:

  • Deliver courses, coaching and certification programmes
  • Provide learner support
  • Process payments
  • Send workbooks, certificates and other learning materials
  • Assess learner progress and achievement
  • Communicate with learners, customers and partners
  • Improve our programmes and services
  • Meet legal and regulatory obligations

How We Store and Protect Personal Data

GROW takes reasonable technical and organisational measures to protect personal data from loss, misuse, unauthorised access, disclosure or alteration.

Personal data may be stored using trusted third-party systems, including:

  • Kajabi
  • Google Workspace
  • Zoom
  • Stripe
  • ScoreApp
  • Mailchimp

Access to personal data is limited to those who need it in order to carry out their role.

International Data Transfers

Some of GROW's service providers may store or process personal data outside the United Kingdom.

Where this occurs, GROW will ensure that appropriate safeguards are in place to protect personal data and comply with applicable data protection laws.

Individual Rights

Individuals have the right to:

  • Request access to their personal data
  • Request correction of inaccurate personal data
  • Request deletion of personal data where appropriate
  • Restrict or object to certain types of processing
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Information Commissioner's Office (ICO)

Requests relating to personal data should be sent to support@growformula.org.

Data Retention

GROW will only keep personal data for as long as it is needed for the purpose for which it was collected, or as required by law. GROW will securely delete or anonymise personal data when it is no longer required, unless there is a legal or legitimate business reason to retain it.

Data Protection Reviews

Where a new activity, project or process presents a significant privacy risk, GROW will assess the risks and appropriate safeguards before proceeding.

Data Breaches

Any suspected personal data breach must be reported to the Founder immediately. GROW will investigate all reported breaches and, where required by law, notify the Information Commissioner's Office (ICO) and affected individuals.

Responsibility

The Founder of GROW acts as GROW's Data Protection Lead and is responsible for overseeing compliance with this policy.

This policy should be read alongside the following policies:

  • Accessibility and Reasonable Adjustments Policy
  • Appeals Policy
  • Complaints Policy