Privacy Policy

‍

Last updated: 18 September 2026

Growth Vault respects the privacy of the people and businesses that interact with us and takes reasonable steps to protect personal data processed through our website, sales process and business operations.

This Privacy Policy explains what personal data we may collect when you visit our website, complete the VaultScore or another form, book a call, communicate with us, become a client or otherwise interact with Growth Vault; why we process it; when we may share it; how long we may retain it; and the rights that may apply to you.

This Policy applies to personal data Growth Vault controls for its own website, marketing, sales, qualification, administration and client-relationship purposes. Personal data processed by Growth Vault strictly on a client's instructions as part of agency delivery may instead be governed by the applicable client agreement, data-processing terms and the client's own privacy obligations.

If you have any questions about this Privacy Policy or the way we process personal data, you can contact us using the contact details or contact form available on this website.

1. Who We Are

Growth Vault is an ecommerce growth agency providing services including:

For personal data collected directly through this website and Growth Vault's own sales, marketing, qualification and business operations, Growth Vault acts as the data controller unless a different role is expressly stated. Where we process data solely on behalf of a client, our role may instead be that of processor or service provider under the applicable agreement.

2. Information We Collect

The information we collect depends on how you interact with Growth Vault.

Information You Provide to Us

When you complete the VaultScore, another form, request information, book a call, communicate with us or become a client, we may collect the information you choose to provide. You are responsible for ensuring that information you submit is accurate and that you are authorised to provide personal data relating to another person.

We will normally make clear which information is required when we ask you to provide it.

Information Collected Automatically

When you visit our website, certain technical information may be collected automatically, including:

Technical information may be generated by our website infrastructure, hosting, security and form systems. Additional analytics, conversion-measurement or advertising technologies may be enabled from time to time, subject to applicable consent and disclosure requirements.

3. How We Use Your Information

We may process personal data for the following purposes:

We may also use information where reasonably necessary to verify submitted business information, prevent abuse, protect Growth Vault and its systems, maintain records, enforce or defend our rights, and comply with legal obligations. We do not use personal data for materially incompatible purposes unless permitted or required by applicable law.

4. Legal Bases for Processing

Where the General Data Protection Regulation (GDPR) or similar data-protection legislation applies, we process personal data only where we have an appropriate legal basis.

Depending on the circumstances, this may include:

Consent
Where you have actively agreed to specific processing, such as certain marketing or non-essential cookies. You may withdraw your consent at any time.

Contractual necessity
Where processing is necessary to take steps at your request before entering into an agreement or to perform an agreement with you.

Legitimate interests — where processing is reasonably necessary for Growth Vault's legitimate business interests and those interests are not overridden by applicable data-protection rights. These interests may include operating and securing our website, responding to business enquiries, qualifying prospective clients, preparing for calls, maintaining business records, improving our services and processes, preventing fraud or misuse, and conducting appropriate business-to-business marketing.

Legal obligations
Where we are required to process or retain information to comply with applicable law.

The legal basis used depends on the particular processing activity and circumstances.

5. Lead Forms, Applications and Call Bookings

When you submit a Growth Vault contact, qualification or application form, we may use the information provided to:

Submitting the VaultScore, a contact form or a booking request does not create a client relationship, guarantee a call, guarantee acceptance, reserve capacity, or oblige Growth Vault to provide services. Growth Vault may review, verify and assess submitted information and may accept, decline or request further information at its discretion, subject to applicable law.

We use third-party systems to operate parts of this process, including website/form infrastructure, workflow or CRM tools, scheduling and communication services. Those providers may process the information necessary to provide their services to Growth Vault and may be subject to their own legal and contractual obligations.

6. Email and Marketing Communications

Where we have a lawful basis to do so, we may contact prospects, clients and business contacts about Growth Vault, relevant services, insights, operational matters or commercial opportunities. Where consent is legally required, we will obtain it before sending the relevant marketing communication.

Where required by law, we will obtain consent before sending marketing communications.

You can unsubscribe from marketing emails at any time by using the unsubscribe option included in the communication or by contacting us.

Administrative, contractual or service-related messages are not treated as marketing messages and may still be sent where necessary.

7. Cookies and Similar Technologies

Our website may use cookies or similar technologies that are necessary for website functionality, security or form operation. Analytics, advertising and conversion-measurement technologies may be added or changed over time and will be handled in accordance with applicable notice and consent requirements.

Cookies may include:

Strictly necessary cookies
Required for essential website functionality, security or form operation.

Analytics cookies
Used to understand how visitors interact with the website and to improve performance.

Functional cookies
Used to remember preferences or provide enhanced website functionality.

Advertising and measurement cookies
Where enabled, these may help measure marketing performance, understand conversions or deliver more relevant advertising.

Where applicable law requires consent for non-essential cookies or tracking technologies, we will seek the required consent before activating those technologies for that visitor.

You can use your browser settings to block, delete or restrict cookies. Where Growth Vault introduces a dedicated consent or cookie-management tool, the choices available through that tool will apply to the technologies it controls.

Disabling certain cookies may affect some website functionality.

8. Analytics and Advertising Technologies

Growth Vault may use analytics, conversion measurement and advertising technologies to understand website performance, attribute enquiries or bookings, improve our acquisition process and measure marketing effectiveness. The specific tools in use may change over time.

Depending on the tools enabled on the website, these technologies may process information such as:

Where these technologies require consent under applicable law, they will only be activated after consent has been obtained.

The presence of a technology described in this Policy does not mean that every such technology is active at all times. We may update this Policy or related consent notices as our website and marketing stack changes.

9. How We Share Personal Data

Growth Vault does not sell personal data as part of its ordinary business model. We may disclose personal data only where reasonably necessary for our operations, service delivery, security, professional advice, corporate transactions, or legal obligations, and subject to applicable law.

We may share personal data where necessary with trusted service providers that support our business, such as providers of:

Service providers may act as processors, service providers or independent controllers depending on the service and applicable law. Where required, we use appropriate contractual and organisational safeguards and limit access to information reasonably necessary for the provider's role.

We may also disclose information where required by law, legal process, regulators or competent authorities, or where reasonably necessary to protect our rights, users or business.

If Growth Vault is involved in a merger, acquisition, restructuring or sale of assets, relevant information may be transferred as part of that transaction subject to applicable law.

10. International Data Transfers

Some systems and service providers used by Growth Vault may process or store personal data outside the country where you are located, including outside the European Economic Area (EEA).

Where personal data is transferred internationally, we take appropriate measures where required by law to ensure that the information receives an adequate level of protection.

Depending on the circumstances, these safeguards may include adequacy decisions, approved contractual protections such as Standard Contractual Clauses, or other legally recognized transfer mechanisms.

11. Data Retention

We retain personal data for as long as reasonably necessary for the purposes described in this Policy, including sales follow-up, client relationships, operational records, security, accounting, dispute resolution, enforcement of agreements and compliance with legal or regulatory requirements.

Retention periods may differ depending on the type of information and the reason it is processed.

For example, active-client records may be kept throughout the relationship and for an appropriate period afterwards. Prospect and unsuccessful-enquiry records may be retained while a legitimate business relationship or follow-up purpose reasonably exists, unless deletion is required earlier by law or a valid rights request.

When personal data is no longer required, we may delete, anonymize or securely archive it as appropriate.

12. Data Security

We use technical and organisational measures that we consider reasonable and appropriate for the nature of the information and our operations, which may include access controls, authentication, least-privilege permissions, secure systems, role separation, monitoring and controlled handling of credentials and client information.

These measures may include access controls, authentication, restricted permissions, secure systems, monitoring and other appropriate security practices.

No website, transmission method, storage system or security measure can be guaranteed to be completely secure. To the extent permitted by law, this Policy does not create a guarantee of absolute security or uninterrupted availability.

13. Your Data Protection Rights

Where the GDPR or another applicable privacy law gives you rights in relation to personal data, those rights may include the following, subject to statutory conditions, exceptions and limitations:

Right of access
You may request information about the personal data we process about you and obtain a copy of that data.

Right to rectification
You may request that inaccurate personal data be corrected and incomplete information be completed.

Right to erasure
You may request deletion of your personal data in circumstances where the law provides this right.

Right to restriction of processing
You may request that the processing of your personal data be restricted in certain circumstances.

Right to object
You may object to certain processing, including processing based on legitimate interests and, at any time, direct marketing.

Right to data portability
Where applicable, you may request to receive certain personal data in a structured, commonly used and machine-readable format or have it transferred to another controller.

Right to withdraw consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before the withdrawal.

Rights relating to automated decision-making
Where applicable, you may have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.

To exercise your rights, contact Growth Vault through the contact information provided on this website.

We may ask for information reasonably necessary to verify identity, authority and the scope of a request before acting on it. We may also retain information that applicable law permits or requires us to keep, including records needed to establish, exercise or defend legal claims.

Certain rights are subject to legal limitations and may not apply in every situation.

14. Complaints

If you have a concern about our handling of personal data, you may contact Growth Vault so we can review it. Nothing in this Policy limits any right you may have under applicable law to contact a competent supervisory authority.

Where the GDPR applies, you also have the right to lodge a complaint with the competent data-protection supervisory authority.

If you are located in another country, you may also have the right to contact your local data-protection authority.

15. Third-Party Websites and Services

Our website may contain links to third-party websites, platforms or services.

Growth Vault does not control and is not responsible for the privacy, security, availability, terms or content of third-party websites, platforms or services. Your use of those services is subject to the relevant provider's terms and privacy practices.

We encourage you to review the privacy information of any third-party website or service before providing personal information.

16. Children's Privacy

Growth Vault's website and services are intended for businesses and adult users.

We do not knowingly collect personal data from children under the age of 16 through our website.

If you believe that a child has provided personal data to Growth Vault without appropriate authorization, please contact us so that we can investigate and, where appropriate, remove the information.

17. Automated Processing and Profiling

Growth Vault may use software, automation and qualification rules to organise enquiries, validate required fields, route submissions, identify whether a stated minimum criterion is met, prioritise follow-up and support internal sales or operational workflows.

Website qualification or routing does not itself create a contract or guarantee that Growth Vault will accept a business as a client. Unless clearly disclosed otherwise, Growth Vault does not rely solely on automated processing to make decisions about individuals that produce legal or similarly significant effects.

18. Changes to This Privacy Policy

We may update this Privacy Policy when our website, systems, service providers, marketing stack, business operations or legal obligations change. The version published on this page is the current version and takes effect from the stated 'Last updated' date, subject to any additional notice or consent required by law.

When we make material updates, the revised version will be published on this page and the Last updated date will be changed accordingly.

We encourage you to review this Privacy Policy periodically.

19. Contact Growth Vault

For privacy questions, data-protection requests or concerns about Growth Vault's handling of personal data, contact Growth Vault using the contact details or contact form provided on this website. Please provide enough information for us to identify and respond to your request.

‍

‍