Privacy Policy
1. Who Are We?
Welcome to the official Privacy Policy for the digital operations, networks, and platforms managed under the corporate brand Calm Growth (referred to throughout as "we", "us", "our", or "the Platform"). We operate a compliance architecture committed to safeguarding user data, ensuring absolute privacy, and maintaining rigorous administrative transparency. Registered Corporate Mailing Address: 66 Paul Street, London, EC2A 4NA. While our primary administrative headquarters, legal registration, and data controller operations are situated within the United Kingdom, our platform coordinates a highly secure, distributed network of international collaborators, academic volunteers, and service professionals.
Regardless of geographical boundaries or the location of individual users, all information passing through our operational infrastructure is governed by UK data protection standards. This ensures uniform data integrity, security, and strict professional confidentiality worldwide.
All operational data pipelines, digital registries, and communications are processed in alignment with the statutory requirements of the United Kingdom Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
For the explicit purposes of global data protection frameworks and statutory accountability, the registered and legally designated Data Controller is Corey Yu, operating as the Principal Proprietor of Calm Growth.
All operational management, strategic data directives, and risk assessments are strictly overseen by the Principal Proprietor and/or compliance support team to ensure compliance across all service delivery tracks.
2. How We Collect Information
We collect personal data strictly to facilitate safe, professional operations and to ensure compliance with the UK Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR). We collect information through the following distinct channels:
A. Direct Interactions We collect data that you explicitly provide when you interact with our platform, submit enquiries, or register for services. This includes, but is not limited to:
Identity & Contact Data: Your name, email address, telephone number, postcode, and any general information included in your enquiry.
Service Engagement Data: Information provided when you register for events, surveys, give feedback, or when applying for volunteering opportunities.
Transactional Data: Details required to process purchases, fees, or donations.
B. Special Category (Healthcare & Support) Data
When you engage our infrastructure for specialised support, such as counselling services, we collect clinical baseline data to ensure duty of care. This includes:
Basic contact and background details.
Emergency contact information and General Practitioner (GP) details.
Brief, structured summaries regarding your reasons for seeking support.
Minimal, securely archived, and pseudonymised session notes utilized solely to track progress.
C. Third-Party Interactions
We may receive information about you from external platforms where you have given your explicit consent for data sharing. This includes third-party fundraising and donation portals (such as JustGiving or equivalent verified processors) and integrated operational partners.
D. Automated Technical Data
As you navigate our website, we may collect technical data regarding your equipment, browsing actions, and patterns. This includes
Analytical Metrics: Pages visited most frequently, click-through rates from official communications, and service engagement levels.
Cookie Data: these consists of small files used to enhance website performance, security, and user experience, which are anonymized and aggregated whenever technically feasible.
Detailed information regarding these practices can be found in Section 3 (Cookies).
E. Calm Growth collects personal data directly from you:
When you first contact Calm Growth to enquire about therapy (by email, telephone, or the website contact form)
During the initial consultation and intake process
Throughout therapy sessions as part of ongoing work together
Through any emails, messages, or telephone calls between sessions
Calm Growth does not collect personal data about you from any other source unless you have given explicit consent to do so, or it is necessary for safeguarding purposes.
Important
Should you choose to move from Calm Growth to an independent counselor’s webpage or a different private practice, please be aware that their data collection practices, privacy terms, and confidentiality policies may vary significantly from those outlined here.
3. What Personal Data Will Be Collected
To provide therapy services, Calm Growth collects and processes the following types of personal data:
Contact and administrative information:
Your name, address, telephone number, and email address
Emergency contact details
GP details (where relevant to your care)
Health and therapy-related information:
Details about why you are seeking therapy (your presenting issues)
Relevant medical and mental health history
Session notes recording therapeutic work together
Risk assessments and safety planning information
Any other information shared during session
Important
Health and therapy-related information is classified as "special category data" under Article 9(1) of the UK GDPR. This type of data receives enhanced legal protection because of its sensitive nature, and Calm Growth takes additional care to keep it secure.
If you contact Calm Growth by emails the platform collects your name, email address, and the content of your message.
3. Why Calm Growth Will Processes Your Data
Under the UK GDPR, Calm Growth must have a lawful basis for processing personal data. For the counselling, mentoring, and tutoring services provided, the practice relies on the following legal grounds:
Article 6 Basis (Ordinary Personal Data)
Article 6(1)(b) UK GDPR: Processing is necessary for the performance of the contract between you and Calm Growth. When you engage the practice for counselling, mentoring, or tutoring services, a contract is formed. Processing your personal data is essential to fulfil the agreed services, manage scheduling, communicate regarding sessions, and maintain administrative records.
Article 9 Basis (Special Category Data - Health or Sensitive Information)
Where sensitive information (such as health data, mental health history, or safeguarding concerns) is processed:
Article 9(2)(h) UK GDPR
Processing is necessary for the provision of health or social care treatment, or for assessing the working capacity of an employee, carried out by a health professional or someone subject to an obligation of confidentiality.
The additional condition required under the Data Protection Act 2018 is Schedule 1, Part 1, paragraph 2 (health or social care purposes). This processing is carried out by qualified practitioners at Calm Growth, who are bound by professional obligations of confidentiality under relevant ethical frameworks (such as BACP for counselling, or equivalent professional bodies for mentoring and tutoring).
Safeguarding and Legal Obligations: In addition, Calm Growth may process data under:
Article 6(1)(c): Compliance with a legal obligation (e.g., safeguarding duties under UK law).
Article 9(2)(g): Reasons of substantial public interest, specifically for safeguarding children and individuals at risk, as outlined in Schedule 1, Part 2, paragraph 18 of the Data Protection Act 2018.
These bases ensure that Calm Growth can lawfully provide counselling, mentoring, and tutoring services while maintaining robust safeguarding practices and adhering to professional ethical standards.
4. ProfessionQuality Assurance & Supervision
Counselling Services For counselling, Calm Growth adheres to the mandatory ethical frameworks of professional bodies (such as the BACP, NCPS and/or UKCP). Practitioners attend regular clinical supervision to ensure safe, effective therapy.
Confidentiality: Your name and identifying details are never shared. Only anonymised case material is discussed.
Obligations: Supervisors are qualified professionals bound by strict confidentiality.
Mentoring and Tutoring Services For mentoring and tutoring, statutory clinical supervision is not a regulatory requirement. However, Calm Growth is committed to high standards:
Best Practice: Practitioners may engage in professional consultation, peer supervision, or quality assurance reviews depending on their specific accreditation and the nature of the work.
Confidentiality: Where any form of professional consultation occurs, your identity remains protected through strict anonymisation, consistent with our safeguarding policies
5. Cookies & Automated Tracking Technologies
We use cookies and similar tracking technologies to ensure our website functions correctly, to understand visitor trends, and to enhance user experience. Non-essential cookies (such as performance or personalisation cookies) are disabled by default and are only activated if you provide your explicit consent via our cookie consent banner. Cookies do not store direct identity details (such as your name), but they do record browsing patterns, device parameters, and system preferences. Cookies are small text files that websites place on your device (computer, tablet, or phone) when you visit them. They help websites remember your preferences and understand how visitors use the site. Some cookies are deleted when you close your browser, while others remain on your device for longer. For general information regarding how cookies operate, you may consult an independent resource such as All About Cookies.
We categorise our website cookies as follows:
Strictly Necessary Cookies: These are essential files required for core site functionality, including security protocols, privacy preference management, and form submissions. These cannot be deactivated within our system, but you can configure your browser to block them. Doing so may cause parts of the website to malfunction.
Please be aware that if you block Strictly Necessary Cookies also known as 'Essential Cookies' , some parts of this website may not function correctly. These cookies are necessary for the website to function properly. They enable basic features such as page navigation, access to secure areas, and remembering your cookie preferences. The website cannot function properly without these cookies, and they do not require your consent under the Data (Use and Access) Act 2025.
Strictly Necessary Cookies on this site may include: Session cookies that keep you logged in while browsing (if using a client portal); Security cookies that help protect against fraudulent activity and/or Preference cookies that remember your cookie settings.
Performance and Analytical Cookies: These allow us to monitor visitor traffic and trace referral sources. They help us analyse page popularity and user navigation pathways so we can measure and improve performance. If you deactivate these, we cannot evaluate site efficiency or user traffic trends. Calm Growth does currently use analytics or statistical cookies and you have the ability to opt out, in line with the low-risk exemptions introduced by the Data (Use and Access) Act 2025. Currently, Calm Growth does not use any advertising, marketing, or third-party tracking cookies on this website. If this changes in the future, Calm Growth will update this policy and ensure you have the ability to opt out in line with the low-risk exemptions introduced by the Data (Use and Access) Act 2025.
Personalisation Cookies: These track user interaction across our web pages to help deliver more relevant content based on historical browsing activity. Deactivating these will result in a less tailored user experience.
External Embedded Content and Third-Party Tracking: Some cookies on this website may be set by third-party services that help the site function. Calm Growth does not control these cookies, but they are limited to essential technical functions. For example, our website features embedded content and social media infrastructure, including videos from YouTube and share buttons linked to platforms such as Instagram, TikTok, and/or Meta. These embedded features connect directly to external servers. They may automatically collect your IP address, deploy their own tracking cookies, and log your interactions across the web. This data is handled entirely by the respective third-party providers (Google, Meta and/or TikTok) under their own independent privacy frameworks. We maintain no operational control over, and accept no liability for, the data processing practices of these external corporate entities.
Calm Growth website is hosted and managed using Systeme.io, which places essential cookies on your device to enable core functionalities such as session management, security, and load balancing. The Systeme.io platform has built-in capabilities for analytics and affiliate tracking. Systeme.io places essential cookies strictly necessary for core functionalities such as session management (keeping you logged in), security (fraud protection), and load balancing. These do not require consent.
The Systeme.io platform has the capability to deploy analytical and marketing tracking cookies (including for its own affiliate program). Calm Growth utilizes a cookie consent banner to manage these cookies. If you reject non-essential cookies: No analytics, marketing, or affiliate tracking cookies from Systeme.io will be set on your device. If you accept non-essential cookies: Systeme.io may set cookies to help us understand website usage and, if applicable, track affiliate referrals. You can withdraw this consent at any time via the cookie settings icon on our website.
6. Data Sharing, Disclosures, & Confidentiality
We do not sell your personal data or browsing activity to any third-party organisations for marketing activities. Your information is strictly utilized by our internal personnel, verified volunteers, and integrated operational infrastructure to deliver our services safely. We may disclose or share your data under the following limited circumstances:
A. Essential Operational Providers: We may utilize trusted third-party service providers (such as website hosts, secure database systems, and encrypted email services) to run our platform. These processors may access your data, but strictly under contractual terms that forbid them from using it for their own purposes.
B. Professional Advisors and Corporate Transition: We may share relevant data with our legal counsel or accountants to fulfil regulatory, financial, and compliance obligations. In the event of a future business sale, asset transfer, or organisational restructuring, user data may be transferred as an operational asset, provided the acquiring party maintains equivalent data protection standards.
C. Cross-Border Data Transfers: We may store and process data within the United Kingdom. If operational requirements dictate transferring data outside the UK in the future, we will ensure robust legal safeguards are deployed, such as standard contractual clauses approved by the UK Government.
Specific Confidentiality Framework for Counselling Services: If you engage our platform for counselling or psychological support, your clinical data and personal identity are heavily protected by professional confidentiality. We will never share your personal information with external parties except under the following specific, structured exemptions:
A. Internal Service Coordination: When you submit an initial enquiry, your basic contact information, availability, and broad support needs will be securely shared with our administrative coordinator. This is done solely to match you with the most appropriate therapist within our operational network. If you fail to respond to a therapist's attempts to arrange an initial session, or fail to attend a booked appointment, our coordinator may contact you directly to offer administrative assistance.
B. Professional Clinical Supervision: In compliance with UK professional accrediting bodies (such as the BACP, UKCP, or NCPS), all practicing counsellors within our network undergo mandatory, regular clinical supervision. Aspects of your case may be discussed to ensure clinical excellence, but your full name, contact details, and identifying traits will remain entirely anonymous. All clinical supervisors are bound by equivalent, strict professional confidentiality frameworks and data laws.
C. Safeguarding and Legal Compulsion (Breaking Confidentiality): We reserve the right to bypass client consent and disclose necessary personal or clinical data to appropriate authorities (such as your GP, emergency services, or local mental health crisis teams) if we reasonably believe: Your personal safety or the physical safety of another individual is at imminent, significant risk.
We are legally compelled to do so by a court order or subpoena, information relating to statutory disclosures, including acts of terrorism, money laundering, or the ongoing abuse of a minor or vulnerable adult. Wherever clinically safe and practical, we will attempt to discuss this with you before breaking confidentiality, but we retain the legal right to act without your consent to protect human life.
7. Data Security, Storage, & Risk Management
We implement administrative, physical, and technological security measures designed to protect your personal information and clinical records from unauthorised access, alteration, disclosure, or destruction.
Data Storage Infrastructure: Your personal data and any associated session notes are retained using secure, multi-layered environments: Digital Records: Stored exclusively on password-protected and encrypted.
Physical Records: Any printed or hand-written administrative documentation is housed within locked filing cabinets situated inside secure, private facilities.
Communications: Contact details, electronic correspondence, and messaging records are maintained within encrypted, password-protected communication accounts.
Communications Security and Email Encryption Our core infrastructure utilises secure, encrypted communication protocols. However, standard internet messaging channels are not automatically end-to-end encrypted across all external networks.
Electronic records: Stored on encrypted, password-protected devices.
Access restricted to compliance@calmgrowth.org and authorized practitioners only. Regular security updates applied.
Paper records: Kept in a locked filing cabinet. Located in a secure room. Access restricted to authorised personnel only. For counselling clinical supervisors receive anonymised case material only as part of professional development and quality assurance. They do not have access to your identifying information.
To maximise confidentiality, we may offer clients the option to receive correspondence via password-protected document attachments. While we take all reasonable and appropriate technical measures to safeguard data within our system, we cannot control external digital environments.
If a recipient uses an unsecure inbox, or if a shared document password is compromised on the recipient's end, we cannot guarantee the protection of that data once it exits our secure operational environment. The transmission of information via the internet is never entirely secure.
While we deploy strict security controls to protect your data, any transmission of information to our website is executed at your own risk.
We conduct reviews of our security architecture to adapt to emerging digital risks. If you suspect that your interaction or data connection with our platform has been compromised, you must alert us immediately at our compliance contact: compliance@calmgrowth.org.
Our platform may feature links to external, third-party websites. While we endeavour to link only to reputable, high-quality services, we maintain no operational control over external platforms.
We do not accept responsibility or liability for the content, privacy policies, or security frameworks of any external website. This privacy policy ceases to apply the moment you exit our domain.
8. Data Retention and Lifecycle Management:
We retain personal data strictly for as long as is reasonably necessary to fulfil the specific operational purposes for which it was collected, including the satisfaction of any legal, accounting, tax, insurance, or statutory reporting obligations. To determine the appropriate retention periods for personal data, our administration evaluates the following criteria:
The respective statutory retention periods mandated by United Kingdom law; the duration and nature of our contractual or business relationship with you and the standard regulatory compliance, insurance requirements, and internal risk management procedures.
Upon the expiration of the defined retention window, all relevant information is routinely, permanently, and securely deleted or destroyed in accordance with our data lifecycle protocols, unless continuing retention is strictly required to protect our infrastructure or the rights of a third party.
Calm Growth keeps records of our work together for several important reasons:
Legal obligations: The law requires Calm Growth to keep certain records for specified periods.
Professional responsibility: As a BACP member, Calm Growth must maintain appropriate records of therapeutic work.
Insurance requirements: Professional indemnity insurance requires Calm Growth to retain records in case of future claims.
Continuity of care: Should you return to therapy, your records help Calm Growth provide consistent support.
Financial compliance: HMRC requires retention of financial records for tax purposes.
Calm Growth retains personal data only for as long as necessary to fulfil specific legal and business purposes.
For therapy records, we retain information for 7 years after your last session. This duration aligns with the Limitation Act 1980 and standard professional indemnity insurance requirements.
For financial records, we are legally required by HMRC to retain data for 6 years.
For website enquiries from non-clients, we retain data for 12 months for legitimate business purposes.
Once these retention periods expire, Calm Growth ensures all records are securely destroyed. Paper records are confidentially shredded, and electronic records are permanently deleted using secure deletion software.
To ensure operational transparency, we apply the following standardised retention timelines to our core services: a) Educational, Tutoring, and Mentoring Data any personal information associated with digital learning infrastructure, tutoring, and mentoring services is retained for the duration of service delivery and typically archived for up to 7 years following the termination of user participation, matching standard UK tax and liability limitation periods.
Adult Counselling Records: Clinical files and session notes for individuals who were adults (aged 18 or older) at the commencement of care are securely retained for 7 years following the conclusion of treatment, unless insurance or legal provisions dictate a variation.
Child and Adolescent Counselling Records: In alignment with UK frameworks, where treatment is provided to individuals under the age of 18, all associated records and session notes are securely preserved until the individual reaches the age of 25, or for 7 years following the conclusion of treatment, whichever period concludes later.
We do not maintain identifiable personal data or clinical archives indefinitely unless exceptional clinical, safeguarding, or statutory requirements compel us to do so. If you require specific information regarding the lifecycle of your data, please contact our administrative inbox.
The information Calm Growth keeps includes:
Contact details: your name, email address, phone number, and address.
Session notes: clinical notes from sessions together.
Assessment and intake forms: information gathered at the start of therapy, mentoring, or tutoring.
Correspondence: emails and other communications between us.
Payment records: invoices, receipts, and records of payments made.
Consent records: signed agreements and consent forms.
Calm Growth maintains a "Clinical Will" (or contingency plan) to ensure your records are handled appropriately and confidentially should the practice or a specific practitioner become suddenly unable to operate due to serious illness, incapacity, or death. Calm Growth maintains clinical will arrangements to ensure your records are handled appropriately and confidentially in the event that the practice or a practitioner is unexpectedly unable to continue practising. Specific details of the appointed executor are kept securely and will be communicated to clients if the need arises.
Appointed Executor: An independent, qualified professional (the "Executor") is appointed to manage this process. This person is bound by strict confidentiality obligations equivalent to those of the practitioner.
While clinical wills are a mandatory ethical requirement for our counselling services (per BACP standards), Calm Growth extends this best practice to our mentoring and tutoring services to ensure consistent safeguarding for all clients.
The Executor’s sole responsibility is to secure records, notify clients, and facilitate the transfer of care or safe disposal of data in line with legal retention periods.
Specific details of the appointed Executor are kept securely and will be communicated to clients if the need arises.
Please note that Calm Growth accepts no liability for the data practices, confidentiality policies, or safeguarding procedures of any independent counsellors, mentors, tutors, or private practices you may choose to engage with directly outside of our service, and you are advised to verify their terms independently.
9. Service Allocation and Clinical Governance
To ensure therapeutic competence and adherence to professional duty of care, our platform utilizes a structured intake framework for all counselling services:
Assessment and Referral: Once a client profile is initiated via our secure intake channels, our administrative infrastructure reviews the initial assessment parameters. Clients are subsequently allocated and securely referred to an appropriate practitioner within the Calm Growth clinical network.
Data Handovers: Case handovers between our administrative coordinators and allocated practitioners are executed via secure, encrypted electronic communications or protected briefings.
Advanced Support for Trainee Practitioners: Where a client case may be allocated to a qualified trainee practitioner within our network, the intake handover incorporates additional clinical oversight to ensure all support queries are resolved. Trainee practitioners are contractually mandated to evaluate the assessment within a secure clinical supervision environment prior to conducting an initial client consultation.
Collaborative Re-allocation: If a client requests a transition to an alternative practitioner, or if a practitioner evaluates that a client's specific clinical requirements sit outside their immediate professional competencies, our administration may provide support to securely transition the client to a more suitable alternative practitioner.
10. Your Statutory Data Protection Rights
Under the UK Data Protection Act 2018 and the UK GDPR, you have the right to request:
Depending on your location, you have the right to request the following rights regarding your personal data:
Right to be informed: to know how your data is being used.
Right of access: You can request a copy of the personal data I hold about you. You can request a clear summary and a digital copy of the personal data we maintain regarding you.
Right to rectification: You can request that we correct any inaccurate or incomplete personal records.
Right to erasure: You can request the deletion of your data where it is no longer required for the operational purposes for which it was gathered, or where you have withdrawn consent (please note this right may not apply if Calm Growth are required to retain records for professional or insurance purposes).
Right to restrict processing: You can request to limit how CalmGrowth uses your data in certain situations by requesting that we temporarily suspend the use of your data while an administrative or accuracy query is being resolved.
Right to data portability: You can request a digital copy of the personal contact information you provided to us in a standard, structured format, or receive your data in a structured, commonly used format. (Note: This right applies specifically to automated digital data processed by consent or contract and does not apply to standard clinical paper records or manual notes).
Right to object: You can object to our processing of your data for specific profiles, marketing activities and/or certain types of processing.
Rights related to automated decision-making: to not be subject to decisions based solely on automated processing (Calm Growth does not use automated decision-making in my practice)
To make a request to exercise your data rights, please contact us at compliance@calmgrowth.org. When you make a subject access request, Calm Growth will conduct a reasonable and proportionate search for your personal data.
We use proportionate identity checks to protect your data e.g., if we have reasonable doubts about your identity, we may require additional verification (such as answering security questions or providing account details) before releasing any information.
Important: Under UK GDPR, you have the right to request deletion of your personal data. However, this right is not absolute. Calm Growth may need to retain your records where:
Retention is required to meet professional indemnity insurance obligations (typically 7 years for therapy records).
The data is needed to comply with legal requirements (such as HMRC record-keeping for 5 years).
The information may be needed to establish, exercise, or defend legal claims.
If you request erasure and Calm Growth is unable to comply fully, we will always explain our reasons.
When your data reaches the end of its retention period:
Paper records are destroyed using a cross-cut shredder.
Electronic records are permanently deleted using secure deletion software that overwrites the data.
Calm Growth carries out regular reviews to ensure data is not kept longer than necessary.
Important: If you choose to engage directly with independent counselors, mentors, tutors, or volunteers outside of Calm Growth, or move to a different private practice, their data retention and security policies may vary. Calm Growth accepts no liability for their practices, and you are advised to verify their terms independently.
While we respect your statutory rights, the UK GDPR provides explicit legal exemptions. We reserve the right to defer or decline a request if acting upon it would compromise the privacy rights of a third party, interfere with active safeguarding protocols, conflict with ongoing academic research, or breach our statutory obligations to maintain records for insurance, tax, or professional compliance frameworks.
We confirm that our platform does not utilize automated algorithms, profiling, or automated systems to make significant or legally binding decisions regarding your care or user profile. While we respect your statutory rights, the UK GDPR provides explicit legal exemptions.
We reserve the right to defer or decline a request if acting upon it would compromise the privacy rights of a third party, interfere with active safeguarding protocols, conflict with ongoing academic research, or breach our statutory obligations to maintain records for standard regulatory compliance, insurance requirements, and internal risk management procedures.
11. Administrative Requests
To submit a formal request regarding your data, you must contact our compliance team in writing at compliance@calmgrowth.org. To safeguard user privacy and prevent data breaches, we may require you to provide verified proof of identity before processing your application.
Response Timelines: In compliance with statutory requirements, we aim to respond to all valid data requests within one calendar month of receipt. If your request is exceptionally complex, or if we receive multiple simultaneous requests from you, this window may be extended by up to two further months (making a total of three months). In such instances, we will notify you within the initial month and provide a transparent explanation for the delay.
Grievances: If you are dissatisfied with how your personal data is handled, we ask that you contact our complaints inbox first so that we can actively investigate and resolve your complaints.
Our grievances inbox contact is complaints@calmgrowth.org, if we are unable to resolve the matter to your satisfaction, you retain the statutory right to file a formal complaint with the United Kingdom regulatory authority: The Information Commissioner’s Office (ICO).
12. Communication Monitoring and Quality Control
To maintain service standards, ensure public safety, and satisfy regulatory requirements, your communications with our administration or clinical teams (including, but not limited to, telephone calls, video consultations, and electronic correspondence) may be monitored, reviewed, or recorded.
These practices are conducted for, but not limited to: volunteer training purposes; internal quality control audits; and compliance tracking to ensure our customer and clinical service standards remain optimal.
We reserve the right to defer or decline access requests if acting upon them would compromise third-party privacy, interfere with active safeguarding protocols, or breach statutory record-keeping obligations.
13. International Data Transfers
Some of the third-party services used by Calm Growth may transfer personal data outside the United Kingdom.
Proton (Meet and Drive) – Based in Switzerland.
Zoom, Microsoft Teams, and Google Meet – Based in the USA.
Switzerland is recognized by the UK as providing an adequate level of data protection, allowing for secure data transfers without additional safeguards. For services based in the USA (which does not currently have a full UK adequacy decision), Calm Growth ensures appropriate safeguards are in place. We rely on UK International Data Transfer Agreements (IDTAs) or Standard Contractual Clauses (SCCs) in accordance with UK GDPR Chapter V. You can request a copy of the relevant transfer safeguards by contacting Calm Growth at compliance@calmgrowth.org.
14. Review, Revision, and Policy Updates
We review this privacy policy at least annually, and we reserve the right to update or amend its terms at any time.
Updates are typically implemented to reflect operational changes within our infrastructure, technological advancements, or direct modifications to UK data protection regulation and legislation.
This policy undergoes a formal administrative review periodically to ensure it remains relevant, compliant, and legally effective.
We aim to notify our users of any significant modifications by publishing a prominent advisory notice on our main website interface.
We recommend that you review this page periodically to remain informed about how we safeguard your data. This privacy policy was last reviewed and updated on 11 June 2026.
15. Jurisdiction and Governing Law
This privacy policy and any dispute or claim arising out of or in connection with it or its subject matter shall be governed by, and construed strictly in accordance with, the laws of England and Wales. By utilizing our platform, you irrevocably agree that the courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim that arises.
16. Severability
If any provision or part-provision of this privacy policy is or becomes invalid, illegal, or unenforceable under UK data protection law, it shall be deemed modified to the minimum extent necessary to make it valid, legal, and enforceable. If such modification is not possible, the relevant provision or part-provision shall be deemed deleted. Any modification to or deletion of a provision under this clause shall not affect the validity and enforceability of the rest of this policy.
