The Grow Shop – GDPR Compliance Statement

The Grow Shop is committed to full compliance with the UK GDPR and Data Protection Act 2018.

1. Lawful Basis for Processing We process personal data under the following lawful bases:

Consent

Contract

Legal obligation

Legitimate interest

2. Data Subject Rights You have the following rights under GDPR:

Access your data

Rectify incorrect data

Erase your data (“right to be forgotten”)

Restrict processing

Data portability

Object to processing

Withdraw consent at any time

3. Data Protection Officer If required, a DPO will be appointed. Currently, data protection matters can be directed to info@thegrowshop.co.uk

4. Data Security We implement appropriate technical and organisational measures to protect data.

5. Data Breach Procedure In the event of a data breach, we will notify the ICO and affected individuals as required.