Privacy Policy
We collect the minimum needed to reply to you and run the work. No data selling, no advertising cookies on this site.
Privacy Policy
What we collect and why
Cookie policy
Every cookie, named
Terms of service
How engagements work
Accessibility statement
WCAG 2.2 AA, and the gaps
Updated 28 April 2026
The short version: we collect the minimum needed to reply to you and run the work. We don't sell data, we don't run advertising cookies on this site, and every client account we touch stays owned by the client.
Who we are
Momentum Growth Ltd, registered in England & Wales (company no. 09418822), Second Floor, Bakers Yard, 18 Little Ann Street, Bristol BS2 9EB. We are the data controller for this website and for our own client records. Our ICO registration number is ZA774310.
What we collect
- Enquiry data — name, work email, company website, and anything you type into the message field.
- Analytics data — page views, referrer, approximate region, and device type, collected server-side and only after consent.
- Client engagement data — contact details of your team, contract records, and the marketing data you give us access to.
- Recruitment data — anything in an application you send us, kept for six months unless you ask us to delete it sooner.
We do not collect special category data, and we ask you not to send it. If a client dataset contains it, we agree scope and safeguards in writing before we touch it.
Why we collect it
- To reply to you — legitimate interest. You asked us a question; answering it is the obvious use.
- To deliver the contract — performance of a contract, once you're a client.
- To improve the site — consent, via the cookie banner, withdrawable at any time.
- To meet legal obligations — accounting and tax records, kept seven years.
Who we share it with
A short list, all under data processing agreements: HubSpot (CRM), Google Cloud and GA4 (analytics, EU region), Fastmail (email), Slack (client channels), Xero (accounting). We do not share enquiry data with advertising platforms, and we don't build audiences from it.
International transfers
Data is processed in the UK and EEA wherever possible. Where a processor operates in the US, transfers rely on the UK International Data Transfer Addendum and the EU-US Data Privacy Framework, and we hold a transfer risk assessment for each one — ask and we'll send it.
How long we keep it
- Enquiries that don't become clients — 24 months, then deleted.
- Client records — the engagement plus seven years for tax.
- Analytics — 14 months, then aggregated.
- Applications — six months.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict how we use it, object to processing based on legitimate interest, or take it elsewhere in a portable format. Email privacy@momentum.co and we'll action it within one month, usually inside a week. If we get it wrong, you can complain to the Information Commissioner's Office at ico.org.uk.
Security
ISO 27001 certified and Cyber Essentials Plus assessed. Two-factor authentication everywhere, least-privilege access to client accounts, and access reviewed quarterly. When someone leaves, their access is revoked the same day — we test this.
Changes
Material changes get a notice on this page for 30 days and an email to active clients. Version history is available on request.
