Skip to main content

Privacy Policy

Last Updated: March 18, 2026

1. Introduction & Controller Identity

This Privacy Policy explains how Business Growth Academy (“we”, “us”, or “our”) collects, uses, and protects your personal data when you visit our website and when you contact us about our educational programmes, memberships, events, and mentor-led clinics.

For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, the data controller is Business Growth Academy Ltd, registered address: 1 Mark Square, London, EC2A 4EG, United Kingdom. You can contact us at [email protected] or by telephone on +44 20 3761 9128.

This policy applies to information collected through our website, including our enquiry and registration-related forms. If we introduce additional features (for example, a member portal) we will update this Privacy Policy and the Cookie Policy accordingly.

2. Personal Data We Collect

We collect personal data in a few practical ways: when you fill out a form, when you communicate with us, and when your browser interacts with our site. We aim to collect only what is needed to respond to your request and to operate the site securely.

  • Identity and contact data: name, email address, telephone number, and (where provided) company or role information.
  • Form content and enquiry details: the message you submit, programme interests, operational context you share, and any other information you include in free-text fields.
  • Communications: records of emails and messages you exchange with us, including timestamps and any attachments you send.
  • Technical data: IP address, browser type and version, device identifiers, operating system, language settings, and approximate location derived from IP (city-level).
  • Usage data: pages viewed, time on page, navigation paths, referring page, and interaction events (for example, clicks on key calls-to-action).
  • Cookies and identifiers: the cookie consent choice you make, and (if enabled by you) analytics and marketing identifiers described in Section 4.
  • Conversion events: when you submit a form or complete an on-site action that indicates interest in our programmes (for attribution and site improvement where consent applies).

We do not intentionally collect special-category data (such as information about health, religious beliefs, political opinions, or biometric identifiers) through this website. We also do not request government identification numbers or financial account details via our website forms. Please do not include sensitive information in free-text form fields.

3. Why We Process Personal Data & Legal Basis

We process personal data for specific purposes and rely on the legal bases in Article 6 of the UK GDPR. Where we rely on consent, you can withdraw it at any time (see Section 5).

3.1 Responding to enquiries and admissions conversations

When you submit an enquiry, we use your contact details and message to respond, route you to the right programme or mentor clinic, and arrange a call if requested. Legal basis: Article 6(1)(b) (taking steps at your request prior to entering a contract) and Article 6(1)(a) (consent) where you provide explicit consent to be contacted via our form checkbox.

3.2 Improving the website and programme information

If you accept analytics cookies, we use aggregated usage data to understand which pages are useful, where visitors drop off, and how to improve clarity. Legal basis: Article 6(1)(a) consent.

3.3 Marketing and advertising measurement

If you accept marketing cookies, we may measure conversions and build audiences for remarketing or lookalike modelling on advertising platforms. Legal basis: Article 6(1)(a) consent.

3.4 Security, fraud prevention, and service reliability

We process limited technical data (including IP address and request metadata) to protect the site, prevent abuse, and maintain availability. Legal basis: Article 6(1)(f) legitimate interests, balanced against your rights and expectations.

3.5 Legal obligations

We may process information to comply with applicable legal obligations (for example, responding to lawful requests). Legal basis: Article 6(1)(c).

3.6 Automated decision-making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects for you within the meaning of Article 22 UK GDPR. Any routing of enquiries is based on straightforward administrative rules (for example, programme interest selected) and is reviewed by a person.

4. Cookies & Tracking Technologies

Cookies are small text files stored on your device. We also use similar technologies (such as pixel tags and server-side event forwarding) to understand usage and measure conversions, where permitted by your consent choices. You can manage preferences at any time using “Manage cookie preferences” in the footer.

4.1 Essential cookies (always active)

These are required for the site to function and for us to store your consent settings. They do not require consent. Examples include:

  • _site_session (first-party): supports session continuity and basic site functionality. Retention: session.
  • cookie_consent (first-party): stores your cookie choices. Retention: up to 12 months.
  • CSRF-related tokens (first-party): may be used to protect forms from abuse. Retention: session to short-lived.

4.2 Analytics cookies (optional)

If you consent, we may use Google Analytics 4 (“GA4”) to measure site usage. We configure analytics to focus on aggregated insights and apply IP anonymisation where available. Example cookies:

  • _ga: GA4 user identifier. Retention: 2 years.
  • _ga_XXXXXXXXXX: GA4 session state. Retention: 2 years. (The suffix varies by property.)

Analytics data retention is typically set to 14 months. If you do not consent, analytics scripts should not be activated through our consent system.

4.3 Marketing cookies (optional)

If you consent, we may use marketing cookies to measure advertising performance, attribute conversions, and build audiences for remarketing and lookalike modelling. Example cookies include:

  • _gcl_au (Google Ads): conversion linker. Retention: 90 days.
  • _fbp (Meta): browser identifier. Retention: 90 days.
  • _fbc (Meta): click identifier, set when a click ID is present. Retention: 90 days.

4.4 Beyond cookies

Some measurement technologies work without relying exclusively on cookies, including pixel tags and server-side event forwarding (for example, via a tag manager). Where we use these, we apply them consistently with the consent category you choose. Advertising partners may derive identifiers from device signals (such as IP address and user-agent) and may use hashing for matching where applicable.

5. Consent and How to Withdraw It

Users in the United Kingdom and the EEA receive a cookie consent notice under UK GDPR / GDPR requirements. Analytics and marketing cookies are activated only after explicit, informed, freely given consent (Article 6(1)(a)).

Your choices are recorded in the cookie_consent cookie (typically for 12 months). You can withdraw consent at any time by using the “Manage cookie preferences” link in the footer or by clearing cookies in your browser settings. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

6. Sharing With Advertising & Service Partners

We use reputable service providers to run the site, protect it from abuse, and (with consent) measure performance. We do not sell personal data. When we share data with partners, it is for specific purposes and under appropriate contractual terms.

  • Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): may receive cookie identifiers, usage data, conversion events, and audience signals when enabled by consent. Privacy information: https://policies.google.com/privacy.
  • Meta Platforms, Inc. (Meta Pixel, custom/lookalike audiences, conversion measurement): may receive page views, conversion events, and identifiers when enabled by consent. Privacy information: https://www.facebook.com/privacy/policy.
  • Cloudflare (content delivery and security): may process IP addresses and request metadata to provide DDoS protection and performance. Privacy information: https://www.cloudflare.com/privacypolicy/.

We do not permit these providers to use site data for their own independent commercial purposes beyond delivering services to us, subject to their own platform terms and privacy obligations.

7. International Transfers

Some of our service providers may process personal data outside the United Kingdom and the EEA, including in the United States. Where transfers occur, we rely on appropriate safeguards, which may include: the EU–US Data Privacy Framework (and the UK Extension where applicable), and Standard Contractual Clauses (EU 2021/914) or the UK International Data Transfer Agreement (IDTA) as a fallback mechanism.

We assess transfer risks pragmatically based on the nature of the data (for example, cookie identifiers and aggregated usage events) and the security measures available. Where possible, we minimise the data shared and use consent gating for optional tracking.

8. Data Retention

We keep personal data only as long as necessary for the purpose it was collected, and then delete or anonymise it. Typical retention periods include:

  • Contact submissions and admissions enquiries: up to 2 years from the last interaction, unless you become a member or request earlier deletion.
  • Email correspondence: duration of the relationship plus up to 1 year for continuity and audit, unless a longer period is required by law.
  • Analytics data: typically 14 months (subject to analytics configuration and your consent).
  • Marketing cookies: retained according to cookie lifetimes (often 90 days), subject to your consent settings.
  • Server logs and security telemetry: typically up to 90 days, unless required for investigating abuse or security incidents.
  • Cookie consent record: we may retain evidence of consent choices for up to 3 years for compliance auditing.
  • Legal and regulatory retention: where applicable, we may retain records for periods required by law (for example, 6–10 years for certain business records).

9. Your Rights (UK GDPR and GDPR)

You have rights in relation to your personal data, subject to certain exceptions. These include:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to withdraw consent at any time (Article 7(3))
  • Right to lodge a complaint with a supervisory authority (Article 77)

To exercise a right, email [email protected]. We aim to respond within 30 days. For complex requests, this may be extended by up to a further 60 days, in line with the UK GDPR.

In the United Kingdom, the supervisory authority is the Information Commissioner’s Office (ICO): https://ico.org.uk. In the EEA, information on supervisory authorities is available at the European Data Protection Board: https://edpb.europa.eu.

10. Children

This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that personal data has been collected from a child under 16 without verifiable parental consent, we will delete it promptly.

11. Do Not Track

Some browsers send “Do Not Track” (DNT) signals. This website does not respond to DNT signals. Third-party providers may have their own handling of such signals or settings within their platforms.

12. Data Deletion Requests

You may request deletion of your personal data by emailing [email protected] with the subject line “Data Deletion Request”. We may need to verify your identity before completing the request. We aim to complete deletion within 30 days of verification, except where retention is required by law or for the establishment, exercise, or defence of legal claims.

13. Business Transfers

If we enter into a merger, acquisition, asset sale, financing, insolvency, or similar transaction, personal data may be transferred to a successor entity or professional advisers involved in the transaction. If the transfer would materially change how your data is used, we will provide notice through the website.

14. California Privacy Notice (CCPA/CPRA)

This section is provided for visitors in California. Over the past 12 months, we may have collected categories of information such as identifiers (name, email, IP address, device identifiers) and internet or other electronic network activity information (pages visited, interactions) as described in Section 2.

We do not sell personal information as defined by the CCPA. We may share information for cross-context behavioural advertising when marketing cookies are enabled. California residents may opt out of such sharing via our cookie preferences panel (see Section 5).

Subject to applicable exceptions, California residents have rights to know, delete, correct, and to opt out of sale or sharing, as well as the right to non-discrimination. To submit a request, email [email protected] with the subject “California Privacy Request”. We may request additional information to verify your identity. Authorised agents may submit requests with appropriate written proof of authorisation.

15. Virginia Privacy Notice (VCDPA)

This section is provided for visitors in Virginia. Subject to applicable exceptions, Virginia residents may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. To submit a request, email [email protected] with the subject “Virginia Privacy Request”.

We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects. If we refuse to take action on a request, you may appeal by emailing us with the subject “Appeal of Refusal — Privacy Request”. We will respond to an appeal within 60 days. If your appeal is denied, you may contact the Virginia Attorney General.

16. Nevada Privacy Notice

Nevada residents may submit a verified request to opt out of the sale of certain personal information by emailing [email protected] with the subject “Nevada Do Not Sell Request”. We do not currently sell personal information as defined under Nevada Revised Statutes Chapter 603A.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will provide a prominent notice on the website at least 14 days before the change takes effect where appropriate. The “Last Updated” date at the top of this page shows when this policy was last revised.

18. Contact

If you have questions about this Privacy Policy or how we handle personal data, contact:

Business Growth Academy Ltd
1 Mark Square, London, EC2A 4EG, United Kingdom
Email: [email protected]
Phone: +44 20 3761 9128