- Document Number
- GPC-POL-02
- Version
- 1.2
- Last Updated
- August 30, 2026.
- Effective Date
- August 23, 2026.
- Data Controller
- Growth Partners Consultancy W.L.L, Commercial Registration No. 197615-1, Kingdom of Bahrain
- Privacy and Data Protection Email
- support@growth-gcc.com
Acknowledgement and Acceptance
By purchasing through the Platform, you agree to these policies.
This Policy explains the Personal Data we collect, why we collect it, how we protect it, your rights, and how to exercise them.
1. Scope of the policy.
This policy applies to all personal data collected by Growth Partners Consultancy W.L.L. or processed through its online store and associated communication channels. This policy is formulated in accordance with the provisions of Personal Data Protection Law in the Kingdom of Bahrain promulgated by Act No. 30 of 2018 and its implementing resolutions, and with the best practices recognized in the GCC States.
Company is the Data Controller for the data referred to in this policy, and the entity that determines and assumes responsibility for the purposes and means of processing.
2. The data we collect.
We follow the principle of data minimisation and collect only the Personal Data reasonably necessary to provide the service.
Identification data.
Examples: Full name.
Collection source: Directly from you when you’re registering or purchasing.
Is it required?: Yes, to complete the order and issue the Licence.
Communication data.
Examples: E-mail, phone number.
Collection source: Directly from you.
Is it required?: Yes, to deliver the product and communicate about the order.
Licensing data.
Examples: Company name or project to be licensed.
Collection source: Directly from you when you buy.
Is it required?: Yes, for Digital Templates, because they’re the basis for determining the scope of the Licence.
Order and transaction data.
Examples: Order number, product name, transaction amount, date and time, payment status, last four digits of the card and type when supplied from Payment Gateway.
Collection source: From Payment Gateway and the store system.
Is it required?: Yes. It is generated automatically when the transaction is completed.
Technical use data.
Examples: IP address, browser type and device, access times, download log and attempts, course viewing activity.
Collection source: Automatically when you use the platform.
Is it required?: Automatically collected for security and proof of delivery.
Correspondence data.
Examples: The content of your letters to us and attachments you send with Refund requests or complaints.
Collection source: Directly from you.
Is it required?: Optional generally, but required when necessary to process your request.
Payment Data
We don’t collect or store on our servers any complete data on payment cards, such as the full card number, expiry date or verification code.
Payment Data is processed entirely by the Approved Payment Service Provider in an environment that complies with applicable payment-card security standards, including PCI DSS where applicable. We receive only the transaction result and limited identifying data that cannot be used to make a payment.
We don’t collect data of a sensitive nature, such as health, belief, race or criminal record data, and we don’t ask you to provide it, and we ask you not to include any such data in your correspondence with us.
3. Processing purposes and legal bases.
We process your data only for a specific and legitimate purpose, with a clear legal basis, as follows:
Order fulfilment and delivery of and access to Digital Product.
Data used: Definition, communication, order.
Legal basis for processing: Performance of the contract between you and Company.
Issuance of Licence and registration of Company or Authorized Project.
Data used: Definition, authorization.
Legal basis for processing: Performance of the contract and protection of legitimate interest in controlling the scope of use.
Order fulfilment and processing of payments and Refund.
Data used: Request, transaction data.
Legal basis for processing: Contract implementation and adherence to payment system rules.
Order verification, anti-fraud and protection of Platform.
Data used: Technical use, request.
Legal basis for processing: The legitimate interest of the company in the protection of its systems and rights.
Proof of delivery and defence of company against disputes and bank objections.
Data used: Request, technical use.
Legal basis for processing: Legitimate interest and exercise of the right to defence.
Answer your questions, complaints, and Refund requests.
Data used: Communication, correspondence.
Legal basis for processing: Performance of the contract and respond to your request.
Maintenance of accounting, tax and system records.
Data used: Request, transaction data.
Legal basis for processing: Obligation under law.
Sending marketing letters and offers about our products.
Data used: Communication.
Legal basis for processing: Your express, separate and optional consent, which is not a condition for the completion of the purchase, and you withdraw it at any time through a clear means of unsubscribing.
We will not process your data for any new purpose that is fundamentally different from those mentioned above until you have been notified and given your consent when necessary.
4. What we don’t do with your data.
- We don’t sell your personal data to anyone, in any way, for any purpose.
- We don’t rent your data, we don’t trade it, we don’t share it with data intermediaries.
- We don’t share your data with third parties for their own marketing purposes.
- We don’t make solely automated decisions about you that produce legal effect on you without human intervention.
- We don’t use your data to create behavioural profiles that are directed to external advertising without your consent.
5. Those with whom data may be shared.
We may share a minimum of your data with the following, and to the extent necessary only for the purpose:
Approved Payment Service Provider.
Data shared: Request and payment data required for the operation.
Purpose: Payment processing, Refund, dispute resolution and bank objections.
Hosting providers and technical structure of the platform.
Data shared: Data stored on the Platform.
Purpose: Operation of the store, data storage and security.
E-mail service provider and system messages.
Data shared: Name and e-mail.
Purpose: Order notifications and access for Buyers via My Purchases and Responses.
Our legal advisers and our auditors.
Data shared: Request and correspondence statements as required.
Purpose: Defending the rights of the company or fulfilling a professional obligation, and a subject to strict confidentiality obligations.
Competent judicial and oversight bodies.
Data shared: Only what is officially requested.
Purpose: Response to an lawful official order or request.
We commit each service provider with whom we deal, under a written agreement, to maintain confidentiality of data, not to use it for the agreed purpose, and to apply appropriate protective measures.
6. Data transfer outside Kingdom of Bahrain.
Some of your data may be stored or processed on servers located outside the Kingdom of Bahrain by the nature of cloud services. In this case, we are obliged to transfer only to a State that provides adequate protection of personal data, or after obtaining the necessary authorization from the competent authority, or based on one of the legally prescribed exceptions such as the need for the transfer to perform the contract with you or to obtain your express consent.
7. Duration of data retention.
Account, identification and contact data.
Retention period: For as long as the account, access or Licence remains active, and thereafter only for any period required by law or reasonably necessary to protect legitimate rights.
Action after the retention period: Delete or anonymise after need and statutory duration, unless some need to be retained to establish rights.
Requests, transactions, delivery records and disputes.
Retention period: Delivery and dispute records are retained for at least two (2) years. Accounting and tax records are retained for the statutory period applicable to the Company’s registration status and the requirements in force from time to time.
Action after the retention period: Delete or anonymise after expiry of the period, unless there is a legal obligation or a dispute to retain.
Licensing data and name of company or project licensed.
Retention period: For as long as the relevant Licence remains active, and thereafter for any period required by law or necessary to establish rights connected with that Licence.
Action after the retention period: Deleted or anonymised, with the Licence record maintained where necessary to establish rights.
Correspondence, Refund requests and complaints.
Retention period: At least 2 years from the date of closure of the application, or a longer period if a dispute or statutory obligation arises.
Action after the retention period: Permanently delete.
Marketing list data.
Retention period: Until your consent is withdrawn, or five years after the last interaction, whichever is closer.
Action after the retention period: Deleted from the list immediately.
If a dispute, legal claim or official investigation arises, we shall keep the relevant data until the end of the dispute and a final decision thereon, even if it exceeds the above-mentioned periods.
8. Your rights to your data.
Subject to applicable law and identity verification, you may request access to the Personal Data we process about you and receive it in a readable format; request correction, blocking or erasure where the legal conditions are met; object to certain processing and direct marketing; withdraw consent; request data portability where applicable and technically feasible; and lodge a complaint with the competent authority.
Requests are submitted through support@growth-gcc.com, and we will respond to them during the applicable statutory periods, including ten (10) working days for requests for correction, blocking or erasure when the conditions are met. We may request proof of your identity and explain the reasons for any total or partial rejection.
9. Security measures.
Depending on the nature of the data, the level of risks, possibilities and characteristics available in the systems we use, we shall apply appropriate technical and regulatory measures to protect your data from unauthorized loss, destruction, access or disclosure, including, where appropriate and available:
- The connection encryption of Platform through a secure protocol, and the encryption of sensitive data during preservation wherever possible.
- Restricting access to data to the minimum number of workers who need it to perform their functions.
- Use strong passwords and activate verification by two steps on administrative systems where the feature is available.
- Periodic data backups and refund testing, to the extent appropriate to the nature of the system.
- Periodic updating of systems, software, firewalls and malware control programs.
- Reliance on a certified payment service provider that applies the security standards of the card industry, so that we do not store full card data on our servers.
However, no electronic system can guarantee absolute safety, so we would advise you to keep your access data confidential and not share it with anyone.
10. Dealing with data breach.
In the event of a breach affecting your personal data, we commit ourselves to the following actions:
- Contain the breach immediately and assess its scope and potential impact on data holders.
- Notify the competent regulatory authority of the Kingdom of Bahrain without undue delay and within the period of time prescribed by law and executive decisions in force, when the notification is due.
- Notify you directly and without undue delay if the breach carries a high risk to your rights, indicating the nature of the breach, the affected data, the actions taken and the preventive recommendations.
- Document the incident, its causes and corrective actions, and review controls to prevent recurrence.
11. Cookies.
The Platform uses necessary Cookies to maintain login sessions, preserve shopping-cart contents and remember language preferences. These Cookies cannot be disabled without affecting the service. We may also use analytics Cookies to measure Platform performance and improve user experience; where consent is required, such Cookies are activated only with your consent.
12. The privacy of minors.
If we find out that we have collected data on a minor, we should immediately delete it and cancel the associated account. If you are a parent or guardian and believe that a minor has provided us with his data, please write to us to take the necessary action.
13. External links and websites.
Platform or its materials may contain links to sites or services managed by others. These sites are not subject to this policy, and the company has no responsibility for its data collection or use practices.
14. Policy Amendment.
We may update this policy from time to time to keep abreast of changes in our services or in statutory requirements. The amended text is posted on the Platform with an update of the date of the last update of this document. If the amendment is material and affects the scope of your data processing, we have notified you of it via your registered e-mails well in advance of its entry into force.
15. Governing Law and Jurisdiction.
This policy and any disputes arising therefrom are governed by the laws of the Kingdom of Bahrain and the jurisdiction of the competent courts of the Kingdom of Bahrain have exclusive jurisdiction without prejudice to your right to appeal to the supervisory body competent to protect the personal data.
Final Notes
- To exercise any of your rights or to enquire about this policy, email us at support@growth-gcc.com with a clear statement of your request and the order number if any.
- The Arabic text of this Policy is the authoritative version and prevails in the event of any inconsistency with a translation.
- If any of these policy items are declared invalid, the remaining provisions remain valid and enforceable.
- By purchasing through the Platform, you agree to these policies.
