GROW is committed to protecting personal data and respecting the privacy of everyone we work with, including customers, learners, Licensed Providers, Accredited Coaches and business contacts.
This policy explains how GROW collects, uses, stores and protects personal data in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Scope
This policy applies to all personal data processed by GROW in connection with its programmes, services, accreditation and certification activities.
Our Commitment
When handling personal data, GROW will:
- Process personal data lawfully, fairly and transparently
- Collect only the information needed for a legitimate purpose
- Keep personal data accurate and up to date where possible
- Store personal data securely
- Retain personal data only for as long as necessary
- Respect individuals' rights in relation to their personal data
The Information We Collect
Depending on the service being provided, GROW may collect and process:
- Names
- Postal addresses
- Email addresses
- Telephone numbers
- Payment and transaction records
- Learner records
- E-learning progress data
- Assessment records and supporting documentation
- Coaching records
- Community participation data
- Communications with GROW
In some circumstances, GROW may also collect information relating to accessibility requirements, learning support needs, disabilities or other information disclosed for the purpose of making reasonable adjustments.
How We Use Personal Data
GROW uses personal data to:
- Deliver courses, coaching and certification programmes
- Provide learner support
- Process payments
- Send workbooks, certificates and other learning materials
- Assess learner progress and achievement
- Communicate with learners, customers and partners
- Improve our programmes and services
- Meet legal and regulatory obligations
How We Store and Protect Personal Data
GROW takes reasonable technical and organisational measures to protect personal data from loss, misuse, unauthorised access, disclosure or alteration.
Personal data may be stored using trusted third-party systems, including:
- Kajabi
- Google Workspace
- Zoom
- Stripe
- ScoreApp
- Mailchimp
Access to personal data is limited to those who need it in order to carry out their role.
International Data Transfers
Some of GROW's service providers may store or process personal data outside the United Kingdom.
Where this occurs, GROW will ensure that appropriate safeguards are in place to protect personal data and comply with applicable data protection laws.
Individual Rights
Individuals have the right to:
- Request access to their personal data
- Request correction of inaccurate personal data
- Request deletion of personal data where appropriate
- Restrict or object to certain types of processing
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Information Commissioner's Office (ICO)
Requests relating to personal data should be sent to support@growformula.org.
Data Retention
GROW will only keep personal data for as long as it is needed for the purpose for which it was collected, or as required by law. GROW will securely delete or anonymise personal data when it is no longer required, unless there is a legal or legitimate business reason to retain it.
Data Protection Reviews
Where a new activity, project or process presents a significant privacy risk, GROW will assess the risks and appropriate safeguards before proceeding.
Data Breaches
Any suspected personal data breach must be reported to the Founder immediately. GROW will investigate all reported breaches and, where required by law, notify the Information Commissioner's Office (ICO) and affected individuals.
Responsibility
The Founder of GROW acts as GROW's Data Protection Lead and is responsible for overseeing compliance with this policy.
Related Policies
This policy should be read alongside the following policies:
- Accessibility and Reasonable Adjustments Policy
- Appeals Policy
- Complaints Policy
