Privacy Policy
Last updated: 29 July 2026
Who We Are
Business name: GrowthPains Limited
Address: Wey House, 15 Church Street, Weybridge, Surrey, KT13 8NA
Email: hello@growthpains.com
We are the data controller for personal data processed through this website and our own systems. Where we deliver messaging or operational solutions for client businesses, we act as a data processor on their behalf.
Personal Data We Collect
We may collect and process:
Name
Email address
Phone number
Business name and role
Enquiry details and messages
Booking information
Website usage data (cookies, analytics)
Marketing interaction data
Operational Health Check responses (business size, role, questionnaire answers)
Message content processed on behalf of client businesses (see WhatsApp Business Platform below)
We do not intentionally collect special category data.
How We Collect Data
Website contact and booking forms
Email and direct communication
CRM and workflow tools
Cookies and analytics technologies
Lawful Bases for Processing
We process personal data under the following lawful bases:
Contract – to provide services or respond to enquiries
Legitimate interests – to operate and improve our business
Consent – for marketing and non-essential cookies
Legal obligation – accounting and regulatory requirements
How We Use Your Data
We use personal data to:
Respond to enquiries and provide services
Manage bookings and client relationships
Send service-related communications
Send marketing communications (where consent is given)
Analyse website performance and improve marketing
Meet legal and regulatory obligations
Operational Health Check
When you complete our Operational Health Check, we collect your name, email address, business name, business type, approximate turnover, number of employees, your role, and your responses to the questionnaire. We use this information to:
Generate your personalised report
Send the report to you by email
Contact you about how we may be able to help your business
If you provide a second email address to share your report with someone else, we will send a copy of the report to that address.
Your Operational Health Check data is stored securely and retained for up to 24 months. You can request deletion of your data at any time by emailing us.
WhatsApp Business Platform
Where we implement WhatsApp messaging solutions for client businesses, we act as a data processor on behalf of that business, who remains the data controller for their customer data. We process message content only to deliver the agreed service, under a written agreement with the client. We do not use client or end-customer data to train AI models. End-customer data remains in the client's own systems.
Marketing & Advertising
We use marketing and analytics tools, including Meta Platforms, Inc. (Facebook), to measure advertising performance and improve relevance.
This includes use of the Meta (Facebook) Pixel with Automatic Advanced Matching, which may securely match hashed contact data (such as email address or phone number, where provided) with Meta user accounts.
You will only receive marketing communications if you have opted in. You can unsubscribe at any time.
Cookies & Tracking
We use cookies and similar technologies to:
Ensure the website functions correctly
Analyse traffic and usage
Measure marketing effectiveness
Non-essential cookies are only set with your consent.
See our Cookie Policy for full details.
Sharing Your Data
We may share data with trusted service providers such as:
Website hosting and analytics providers
CRM and automation platforms
Marketing platforms (e.g. Meta, Google)
Professional advisers (upon mutual agreement)
We do not sell personal data.
We may also disclose personal data where legally compelled by a public authority. We review the legality of any such request, challenge it where grounds exist, disclose only the minimum information required, and keep a record of the request and our response. Where the data concerned belongs to a client, we notify them unless legally prohibited from doing so.
International Transfers
Some providers may process data outside the UK. Where this occurs, appropriate safeguards (such as UK-approved data transfer agreements) are in place.
Data Retention
We retain personal data only as long as necessary:
Enquiry data: up to 24 months
Client data: duration of relationship plus legal retention periods
Client message content: held only for the duration of the engagement and deleted or returned on completion, unless the client instructs otherwise
Marketing data: until consent is withdrawn
Your Rights
You have the right to:
Access your personal data
Correct inaccurate data
Request erasure
Restrict or object to processing
Request data portability
Withdraw consent at any time
You may also complain to the Information Commissioner’s Office (ICO): https://www.ico.org.uk.
Data Security
We use appropriate technical and organisational measures to protect personal data from loss, misuse, or unauthorised access.