Skip to content
LEGAL

PRIVACY POLICY

What personal data Vazgro Ltd collects, our lawful bases under UK GDPR, who we share it with, and your rights.

EFFECTIVE DATE
13 August 2026
ISSUED BY
VAZGRO LTD · England & Wales no. 15902777

1. WHO WE ARE

VAZGRO LTD ("Vazgro", "we", "us", "our") is a company registered in England and Wales under company number 15902777, whose registered office is at Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, England, CO4 3ZQ. We are the data controller responsible for the personal data described in this policy. You can write to us at that address, or email hello@vazgro.com.

This policy explains how we collect, use, store, and protect personal data when you visit vazgro.com, make an enquiry, or work with us as a client under any of our LAUNCH, GROW, BUILD, or EXTEND services.

If you have any questions about this policy or how we handle your data, you can contact us at hello@vazgro.com.

2. WHAT DATA WE COLLECT

Enquiry and lead data: when you complete a contact, enquiry, or booking form, or email us, we collect details such as your name, email address, phone number, company name, and the project details and messages you provide.

Business contact data we collect ourselves: we sometimes identify businesses that may be a good fit for our services and contact them directly. Where we do, we obtain contact details from public sources — company websites and public business registers — rather than from you. We collect only what is needed to make contact: a business email address, the company name, and publicly available details about what the business does. We contact corporate subscribers only.

Account and project data: when you become a client, we collect information needed to deliver the Services, including contact and account details, project briefs, credentials and access you share with us, and communications between us.

Billing data: payments are processed by Stripe. We do not store full card numbers ourselves; we receive limited billing information (such as name, billing email, amounts, and transaction status) needed to manage invoices and Subscriptions.

Usage and technical data: our servers and security tooling necessarily receive limited technical information whenever you request a page, including your IP address, the identification string your browser sends, and the page you were referred from. In addition, we run two privacy-preserving measurement tools from our host, Vercel: Web Analytics (page views) and Speed Insights (page performance). Neither stores anything on your device, neither sets a cookie, and neither creates an identifier that could recognise you on a later visit or on another website. Our Cookie Policy sets out field by field what each one sends.

3. HOW & WHY WE USE DATA (LAWFUL BASES)

To provide and manage the Services — responding to enquiries, preparing proposals, delivering LAUNCH, GROW, BUILD, and EXTEND work, managing accounts, and providing support. Lawful basis: performance of a contract, or steps taken at your request before entering a contract.

To run and improve our business — operating and securing the Site, understanding usage, improving our services, and keeping business records. Lawful basis: our legitimate interests in running an effective and secure business, balanced against your rights.

For business-to-business outreach — contacting businesses we have identified as a potential fit, using the details described in section 2. Lawful basis: our legitimate interests in finding clients for our services, balanced against the recipient's rights; our assessment of that balance is documented and available on request. If you do not reply, we delete or anonymise your details within 24 months. You can object at any time using the unsubscribe link in any message or by emailing us — we will stop, and we will keep a record of your address for the sole purpose of not contacting you again.

For optional marketing — sending updates you have asked us to send you. Lawful basis: your consent, which you can withdraw at any time using the unsubscribe link in any message or by emailing us.

For measuring how the website performs — counting page views and recording page speed, using the two tools described in section 4. Lawful basis: our legitimate interests in understanding whether our website works and is fast enough. We do not rely on consent for this, because these tools store nothing on your device and create no identifier for you, so no consent is required; you can still object at any time under section 8.

To meet legal and regulatory duties — including accounting, tax, and fraud-prevention obligations. Lawful basis: compliance with a legal obligation. We do not sell your personal data.

4. COOKIES & ANALYTICS

We use strictly necessary cookies to make the Site work — chiefly to keep you signed in and to show prices in the right currency. We also use three referral-attribution cookies when you arrive through a referral link. Those are not strictly necessary, so we ask your permission before setting any of them, we set none of them if you say no, and nothing you see or pay changes either way. You can change that answer at any time using Cookie choices in the footer of any page, which also deletes any already set. Our Cookie Policy describes every one of them by name.

We do not use analytics cookies, and we do not use advertising or marketing cookies at all. Our two measurement tools, Vercel Web Analytics and Vercel Speed Insights, are cookieless: they store nothing on your device and read nothing from it. Because nothing is stored on or read from your equipment, regulation 6 of the Privacy and Electronic Communications Regulations is not engaged and your consent is not required for them — which is why this site shows no site-wide cookie consent banner. The one consent question we do ask is the one about the referral cookies described above, and it appears only for visitors who actually arrive through a referral link. Our Cookie Policy explains all of this in full and lists every cookie we set.

You can also control cookies through your browser settings. Blocking some cookies may affect how parts of the Site function. If we introduce new advertising or marketing cookies, we will update this policy and the relevant consent options.

5. SHARING & PROCESSORS

We share personal data with carefully selected service providers (processors and sub-processors) who help us operate. They are: Stripe (payment processing — card details are handled by Stripe and never reach our systems); Supabase (the database and file storage holding your account, the records we hold about you, and any files you upload); Resend (sending transactional and marketing email, which necessarily includes your email address); Vercel (hosting this website, and the Web Analytics and Speed Insights measurement described in section 4); and Sentry (error monitoring — diagnostic reports when something goes wrong, which we filter to remove personal data before they are sent).

These providers act on our instructions under contracts that require them to protect personal data and use it only for the services they provide to us. We may also disclose data where required by law, to enforce our rights, or in connection with a business reorganisation or sale.

We also work with independent partners, who introduce businesses to us and who may work an enquiry on our behalf. Where a partner takes on your enquiry, we disclose your enquiry details to them - typically your name, email address, telephone number, company and website, and the notes recorded about what you are looking for - so that they can respond to you. A partner is not one of the service providers described above: they are a separate business, acting on their own account, and they become responsible in their own right for the details we pass them. We require them by contract to use those details only to deal with your enquiry for us, not to add you to any list of their own, not to market anything else to you, not to pass you on to anyone else, and to delete what they hold when they stop working on your enquiry or when their agreement with us ends.

Our partners are based in a number of countries. Where a partner is outside the United Kingdom, and outside a country the UK recognises as offering adequate protection, we put an approved transfer safeguard in place before disclosing anything to them - the Information Commissioner's International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. If you would rather your enquiry was not passed to a partner at all, tell us at hello@vazgro.com and we will handle it ourselves.

6. INTERNATIONAL TRANSFERS

Some of our providers may process personal data outside the United Kingdom. Where this happens, we ensure appropriate safeguards are in place, such as UK adequacy regulations, the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, or equivalent legal mechanisms.

You can contact us at hello@vazgro.com for more information about the safeguards we use for international transfers.

7. DATA RETENTION

We keep personal data only for as long as necessary for the purposes set out in this policy. Enquiry and lead data that does not become a client relationship is typically kept for up to 24 months and then deleted or anonymised.

Client project records and communications are generally retained for the duration of the engagement and for up to 6 years afterwards. Billing, invoice, and tax records are kept for at least 6 years to meet UK accounting and tax requirements. Website measurement data (page views and page speed) is aggregate, contains no identifier for you, and is retained by Vercel under the retention period applicable to our plan; we hold no separate copy of it.

When data is no longer needed, we securely delete or anonymise it.

8. YOUR RIGHTS UNDER UK GDPR

Subject to certain conditions, you have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict how we process your data; receive certain data in a portable format; and object to processing based on our legitimate interests or to direct marketing.

Where we rely on consent, you have the right to withdraw that consent at any time, without affecting processing carried out before withdrawal. To exercise any of these rights, email hello@vazgro.com; we will respond within one month, as required by law.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk. We would, however, appreciate the chance to address your concerns first.

9. SECURITY

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure, including access controls, encryption in transit where appropriate, and trusted, security-conscious service providers.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please avoid sending highly sensitive information unless it is necessary and through an appropriate channel.

10. CHILDREN

Our Site and Services are intended for businesses and adults. They are not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.

11. WHEN WE PROCESS DATA ON YOUR BEHALF (PROCESSOR / DPA)

This policy describes the personal data for which Vazgro is the controller — for example your enquiry, account, and billing data. When we deliver Services, we may also handle personal data that belongs to you and your own customers or users: for instance data held in a website, platform, or system we build or operate for you, content used to train an AI assistant, or data in tools you give us access to.

For that data you are the controller and we act as your processor. We process it only on your documented instructions (including the relevant Statement of Work), keep our personnel under confidentiality, apply appropriate security measures under Article 32 UK GDPR, use sub-processors only under written terms offering equivalent protection, assist you with data-subject requests and breach handling, notify you without undue delay of any personal data breach we become aware of, and delete or return the data at the end of the engagement except where the law requires us to keep it.

These processor commitments are set out in full as a data processing agreement under Article 28 UK GDPR in Section 16 of our Terms of Service, and apply automatically to any such processing. If you need a separate or more detailed DPA, contact us at hello@vazgro.com.

12. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we do, we will publish the current version on this page and update the effective date. Where changes are significant, we will take reasonable steps to notify you.

13. HOW TO CONTACT US

To make a data request, exercise your rights, or ask any privacy question, contact VAZGRO LTD, registered in England and Wales under company number 15902777, at Innovation Centre, Knowledge Gateway, Boundary Road, Colchester, England, CO4 3ZQ, or by email at hello@vazgro.com.

If you are not satisfied with our response, you can contact the Information Commissioner's Office (ICO) at ico.org.uk.

Scoring and automated matching

Two automatic scores operate inside our own systems. Neither decides anything about you on its own, but both influence how you are dealt with, so we would rather describe them than leave you to discover them.

Enquiry scoring. Every enquiry we receive is given a score out of 100. It is calculated from how the enquiry reached us, the estimated value of the work, which services were asked about, whether a phone number, company, industry, budget and timeline were given, and how recently there has been activity on it. It measures the enquiry rather than the person who sent it — but it is stored against a record that usually names an individual, and it affects how quickly and by whom you are contacted, so we treat it as profiling and tell you about it rather than relying on that distinction. No offer, price or refusal is produced by it: it orders a queue that our people work through, and a person makes every decision that follows.

Partner matching. Where an enquiry may be worked by one of our independent partners, we rank the available partners for it using country, language, service area, skills, industry experience, a partner performance score, tier, current workload and how recently each was last given an enquiry. A member of our staff then chooses; nothing is assigned automatically. Where a partner is an individual rather than a company, that performance score is personal data about them, and the same rights apply: they can object to it, and they can ask us how it was arrived at. It is one input among several to a ranking that a person then acts on, and it never allocates anything by itself.

Your rights over this. We rely on our legitimate interests in responding to enquiries efficiently and directing them to the right people. You can object to that at any time under section 8, and you can ask us what score is held against your record and how it was reached. We do not make decisions about you by automated means alone that produce legal effects concerning you or similarly significantly affect you, so the additional rights under Article 22 of the UK GDPR are not engaged. If that ever changes we will say so here, and in that case we would also tell you the logic involved and give you the right to obtain human intervention, to express your point of view and to contest the decision.

Where your personal data is handled, and how we protect it if it leaves the UK

Where we are. Vazgro Ltd is registered in England and Wales (company number 15902777) and operates from London and Colchester. All of our own people work in the United Kingdom.

Where our suppliers are. We use third-party suppliers to host, run and support our platform, and some of them process personal data outside the United Kingdom. Where a supplier does, that transfer is covered either by United Kingdom adequacy regulations under section 17A of the Data Protection Act 2018, or by standard data protection clauses, or by another safeguard permitted by Chapter V of the UK GDPR.

Our plans for India. We intend to establish a group company in India. When it is trading, people employed by that company will work alongside our United Kingdom team across all four of our service lines, and they will need access to some of the personal data we hold in order to do that work. No personal data held by us is accessible from India at the date of this policy.

What we will put in place first. We will not make any personal data accessible from India until all of the following are in place: the India company has been incorporated and is under our common ownership and management; we and that company have signed a written transfer agreement in the form of the International Data Transfer Agreement issued by the Information Commissioner under section 119A of the Data Protection Act 2018, or another safeguard permitted by Chapter V of the UK GDPR; we have completed and recorded a written transfer risk assessment covering the laws and practices of India, including the circumstances in which public authorities there may obtain access to data; access is restricted to named individual accounts, subject to multi-factor authentication and to the minimum permissions each person needs, with every access logged; and we have given advance written notice to every client whose personal data will be affected and have dealt with any objection made in response.

The date access begins. Access to personal data from India began on: not applicable, because no such access has begun. When it does begin we will record the date in this paragraph, and the change will appear in the version history of this policy. Until a date appears here, no personal data held by us is accessible from India.

The safeguard, and how to see it. The International Data Transfer Agreement is a standard set of contractual protections issued by the Information Commissioner. It requires the receiving company to protect personal data to the standard required by United Kingdom law, and it gives the people whose data is transferred the right to enforce its main protections directly against both companies in the courts of England and Wales. Once we have signed it you may ask us for a copy, and we will provide one; we may redact commercial terms such as pricing, which do not affect your protection.

Your rights do not change. Your rights of access, rectification, erasure, restriction, portability and objection, and your right to complain, apply in exactly the same way to personal data handled from India as to personal data handled in the United Kingdom. You may complain to us and we will respond within thirty days; you may also complain to the Information Commissioner at ico.org.uk or on 0303 123 1113, or bring a claim in court, whether or not you have raised it with us first.

If you are a client. Where we handle personal data on your behalf under a Master Services Agreement or an Order Form, that agreement governs what we may do with it and this policy does not cut it down. Under that agreement we will give you advance written notice before any group company or third party begins processing your personal data, and you have a right to object.

If you would rather your data stayed in the United Kingdom, tell us. Where we can reasonably deliver your work using United Kingdom personnel only, we will tell you what that involves and what it costs, and you may choose it.

Keeping this current. We review this section at least once a year, and whenever we add a country or a supplier.

How we intend to work with India in practice. The people employed by that company are expected to work inside our clients own systems, on our clients own tools and under those clients direction, rather than inside our platform. Where that is how a person works, no personal data held by us is transferred to India at all, and the question of a transfer safeguard does not arise for us — although the client, whose systems they are using, has its own position to consider and we will help them with it. We will not give anyone in India access to our own systems, or to the personal data we hold, unless everything in the paragraph above is in place first.

STILL HAVE QUESTIONS?

Ask us directly.

If anything here is unclear, or you want to know how Vazgro handles your data, we're happy to talk it through.

hello@vazgro.com →