Our commitment to General Data Protection Regulation compliance
Last Updated: July 1, 2026
Local Growth Labs AI is committed to protecting the personal data of individuals in the European Economic Area (EEA) and the United Kingdom in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the UK GDPR. This policy outlines our approach to GDPR compliance.
For the purposes of GDPR, the data controller is:
If you are located in the EEA or UK and wish to raise a GDPR-related concern, please contact us at the above email address. We aim to respond to all GDPR requests within 30 days.
We process personal data on the following legal bases under Article 6 of the GDPR:
| Legal Basis | Purpose |
|---|---|
| Contract | Providing services, managing accounts, issuing invoices |
| Legitimate Interests | Website analytics, fraud prevention, service improvement |
| Consent | Marketing emails, newsletters, optional cookies |
| Legal Obligation | Compliance with accounting, tax, and regulatory requirements |
We may process the following categories of personal data about EEA/UK individuals:
We do not knowingly process special categories of personal data (as defined in Article 9 of the GDPR).
If you are located in the EEA or UK, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you (Subject Access Request).
Request correction of inaccurate or incomplete personal data without undue delay.
Request deletion of your data (“right to be forgotten”) where applicable.
Request restriction of processing in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or for direct marketing.
Not to be subject to solely automated decision-making with significant effects.
Withdraw consent at any time where processing is based on consent.
To exercise any of these rights, please email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
As a Bangladesh-based company, any transfer of EEA/UK personal data outside the EEA/UK is conducted with appropriate safeguards in place, including:
We retain personal data only for as long as necessary for the purpose it was collected and in accordance with our legal obligations. Specifically:
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will:
We work with third-party data processors to deliver our services. All processors are assessed for GDPR compliance and bound by Data Processing Agreements. Key processors include:
For all GDPR-related enquiries, Subject Access Requests, or complaints:
📍 USA
You also have the right to contact your local data protection authority if you believe your rights have been violated.