Privacy
Privacy notice
What we collect when you use this site, why we are allowed to, who else touches it, and how to make us stop.
Who we are and how to contact us
TelecomGrowth is a B2B marketing agency working with telecoms resellers, VoIP providers and MSPs in the UK. TelecomGrowth is part of OD3X and was founded by Paul Hanner.
The data controller for this website is [TO CONFIRM], registered in England and Wales under company number [TO CONFIRM]. VAT registration number [TO CONFIRM].
Post: Suite 626, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW. Email: hello@telecomgrowth.co.uk. Phone: +44 2079 234 949.
The person responsible for data protection here is [TO CONFIRM]. Send anything about your data to that person, or to the general address above and we will pass it on.
We are registered with the Information Commissioner's Office under registration number [TO CONFIRM].
What personal data we collect
The free website review form asks for your company name, your website address, your name, your email address and your phone number. Every field on it is one we need in order to look at your site and come back to you.
The contact form asks for your name, your company, your email address, your phone number and your message. Whatever you choose to put in the message field is up to you, so please do not put anything confidential in there.
Alongside a form submission we record technical detail about the visit: your IP address, your browser user agent string, the page you submitted from and its title, and the page that referred you to us.
We also record the campaign parameters that were on the link you arrived through, if there were any. Those are utm_source, utm_medium, utm_campaign, utm_term and utm_content, plus the click identifiers gclid from Google Ads and fbclid from Meta. They tell us which piece of our marketing brought you here.
We do not collect payment details on this site. We do not ask for and do not want special category data, which means anything about health, race, religion, politics, trade union membership, sex life or biometrics. There is no profiling and no automated decision-making anywhere in this.
Why we use it and our lawful basis
Answering your enquiry and delivering the free website review. Our lawful basis is legitimate interests: you asked a business a question and it is in both of our interests that the business answers. Where your enquiry is about engaging us for work, the basis is that the processing is necessary to take steps at your request before entering a contract.
Understanding which marketing brought you here, using the campaign parameters attached to your submission. Lawful basis: legitimate interests, being our interest in knowing which of our own activity works so we do not waste money on the parts that do not.
Sending you marketing email. Lawful basis: consent, or the soft opt-in. Under PECR we only send marketing email to an individual subscriber, which in the UK includes sole traders and unincorporated partnerships, where that person has consented, or where they asked us about a similar service and we gave them a plain way to opt out at that moment and in every message since. For corporate subscribers, which means limited companies, LLPs and public bodies, PECR allows us to email a work address without prior consent, and our lawful basis under UK GDPR is legitimate interests. Either way, one line back from you and we stop.
Analytics and advertising measurement. Lawful basis: consent. These tags do not load and set nothing until you accept them, and you can withdraw that at any time from the cookie notice.
Keeping the site available and defending it against abuse, which is why our hosting provider processes your IP address. Lawful basis: legitimate interests in running a secure website.
Keeping records of what we agreed and what we were paid, once you become a client. Lawful basis: legal obligation for the tax and accounting records we are required to keep, and legitimate interests for the rest of the file.
Where we rely on legitimate interests we have weighed our interest against yours. Ask us and we will send you that assessment.
Sending data outside the UK
Some of the providers above are based outside the UK or run infrastructure outside it, so some of your data is transferred internationally.
Our CRM database is hosted in the [TO CONFIRM] region.
Where the destination country is covered by UK adequacy regulations, we rely on that adequacy. Where it is not, our contract with the provider includes the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement, together with any additional safeguards the transfer risk assessment calls for.
Ask us and we will tell you which mechanism covers a specific provider.
How long we keep it
Enquiries and free website review requests held in the CRM: 24 months from our last contact with you, then deleted. If the enquiry goes nowhere sooner than that and you ask us to remove it, we remove it.
Email correspondence: 24 months from the last message in the thread, unless it belongs to a client file.
Client records, including contracts, briefs and invoices: for the length of the engagement, then six years after the end of the financial year the work falls in, which is the period HMRC requires for company records.
Marketing list membership: for as long as you are subscribed. If you unsubscribe we keep only the minimum suppression record needed to make sure we never email you again, and we keep that for as long as we send marketing at all.
Analytics data in Google Analytics: 14 months, which is the retention period set on the property.
Security and delivery logs: held by Cloudflare under its own retention schedule for a short period. We do not keep a separate copy of them.
Your rights
Under UK GDPR you have the right to ask for a copy of the personal data we hold about you, to have it corrected if it is wrong, and to have it erased.
You can also ask us to restrict what we do with it while a dispute is sorted out, ask for it in a portable machine-readable format where the processing is based on consent or a contract, and object to processing we base on legitimate interests, including any use of your data for direct marketing. An objection to direct marketing is absolute: we have to stop.
Where we rely on your consent, for example for analytics and advertising cookies or for marketing email, you can withdraw it at any time. Withdrawing does not make what we did before that unlawful, it just stops us going forward.
To use any of these rights, email hello@telecomgrowth.co.uk or write to us at Suite 626, 60 Tottenham Court Road, Fitzrovia, London W1T 2EW. Say what you want and we will do the rest. You do not need to fill in a form or use any particular wording.
We respond within one month. If a request is genuinely complex we can extend that by up to two further months, and we will tell you inside the first month if that happens and why. There is no charge.
We may ask you for enough information to be sure who you are before we hand over data, which protects you rather than us.
Complaining to the ICO
If you think we have handled your data badly, tell us first and we will try to fix it. You do not have to, and going to us first does not cost you the right to complain.
The supervisory authority for the UK is the Information Commissioner's Office. Website: ico.org.uk. Helpline: 0303 123 1113. Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
The ICO can look at your complaint whether or not you have raised it with us.
How we keep it secure
Everything on this site is served over HTTPS, so form submissions are encrypted in transit. Our database provider encrypts the data at rest.
The public site can write a form submission into the database but cannot read anything back out of it. Access to the CRM itself is limited to the people who need it to do their work, and those accounts require multi-factor authentication.
We keep the amount of data we hold small on purpose, because the safest record is the one that was never collected or has already been deleted.
No system is perfectly secure and we will not pretend otherwise. If a breach happens that is likely to risk your rights, we will report it to the ICO within 72 hours and tell you directly where the risk to you is high.
Changes to this notice
We update this notice when what we do with data changes, not on a schedule. The date below tells you which version you are reading.
If we make a change that materially affects how we use data we already hold, we will tell the people it affects rather than quietly editing the page.
This notice was last updated on 1 September 2026.