This Privacy Policy explains how Growthlio OÜ ("Growthlio", "we", "us") collects, uses and shares personal data.
Growthlio OÜ, registered in Estonia under number 16945139, registered office Vanemuise tn 46-8, Nõmme linnaosa, Tallinn, Harju maakond 10911, Estonia, is the controller of the personal data described in this Policy.
Section 1Two different roles
This distinction matters, and most people reading this policy will fall into the first group.
When we act as controller. We decide how and why personal data is processed. This covers visitors to growthlio.com, people who submit our forms, subscribers, prospects we contact, clients and their personnel, partners and suppliers. This Policy describes that processing.
When we act as processor. We process personal data on behalf of a client, under that client's instructions, to deliver services to them. That includes the contacts in a client's database that we message on the client's behalf. This Policy does not govern that processing. The client is the controller, the client's own privacy notice applies, and our processing is governed by our Data Processing Agreement with that client.
If you were contacted by an automated agent and want to know why, ask the business whose name was in the message. They hold the record of your consent. If you cannot identify them, contact us at [email protected] and we will route your request to the right controller.
Section 2Personal data we collect as controller
You give us:
| Data | When |
|---|---|
| Name, email address, telephone number, company, role | Form submissions, enquiries, bookings, lead magnet downloads |
| Information about your business, revenue, goals and current systems | Qualification forms, discovery calls, questionnaires |
| Call recordings and transcripts | Calls with us, where we tell you the call is recorded |
| Payment and billing details | Becoming a client. Card details are handled by our payment processor, we do not store full card numbers |
| Correspondence | Emails, messages and support requests |
We collect automatically:
| Data | How |
|---|---|
| IP address, device type, browser, operating system | Server logs |
| Pages viewed, referrer, time on page, clicks | Analytics and advertising cookies |
| Email open and click events | Tracking pixels in our marketing emails |
| Form interaction and submission metadata, including timestamp and IP | Our forms, as evidence of consent |
We obtain from others:
| Data | Source |
|---|---|
| Business contact details, company size, industry, technology used | Business data providers and enrichment services |
| Publicly available professional information | Company websites, public professional profiles |
| Referral details | Partners and existing clients who refer you |
Section 3Why we process it, and our lawful basis
| Purpose | Lawful basis (GDPR) |
|---|---|
| Responding to your enquiry, providing information you requested | Performance of a contract, or steps at your request before entering one |
| Delivering services to clients and administering the relationship | Performance of a contract |
| Sending marketing emails and text messages | Consent, or legitimate interest in marketing to business contacts where permitted |
| Contacting business prospects by email | Legitimate interest in promoting our services to relevant businesses |
| Recording and transcribing calls for quality, training and record keeping | Consent, given at the start of the call |
| Advertising and measuring advertising, including custom audiences | Consent, for cookies and identifier based advertising |
| Analytics and improving the Site and our services | Legitimate interest, or consent where cookies require it |
| Billing, accounting and tax | Legal obligation and performance of a contract |
| Establishing, exercising or defending legal claims | Legitimate interest and legal obligation |
| Security, fraud prevention and preventing misuse | Legitimate interest |
Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights. You may object at any time. See Section 8.
Section 4Marketing communications
Email. We send marketing email to people who requested it and to business contacts where permitted by law. Every marketing email carries an unsubscribe link and our postal address. Unsubscribing takes effect immediately and always.
Text and voice. We contact by text message or telephone only where we hold the consent required by applicable law, or where an existing business relationship permits it. Where an automated or artificial intelligence system places the call or sends the message, it will identify itself as such. Reply STOP to any text message to opt out. You may also opt out by any other reasonable means, including replying in plain language, emailing [email protected], or telling us on a call. We will action it across all channels within ten (10) business days.
Message and data rates may apply. Message frequency varies. Opting out of marketing does not stop service messages relating to an active engagement.
Section 5Cookies and tracking
We use:
- Strictly necessary cookies, for the Site to function. These cannot be turned off.
- Analytics cookies, to understand how the Site is used.
- Advertising cookies and pixels, including the Meta pixel and Google tags, to measure advertising and to build audiences.
Where required by law we ask for consent before setting non-essential cookies, and you can change your choice at any time through the cookie banner or your browser settings.
We may share hashed identifiers, such as a hashed email address or telephone number, with advertising platforms to build custom and lookalike audiences. Those platforms act as independent controllers for their own purposes under their own terms.
Do Not Track. Browsers send inconsistent Do Not Track signals and we do not respond to them. We do honour the Global Privacy Control signal where applicable law requires it.
Section 6Artificial intelligence
We use artificial intelligence systems to draft content, analyse conversations, and conduct automated conversations by text and voice.
- Where you interact with an automated agent operated by us, it will tell you it is an artificial intelligence system.
- Personal data submitted to our artificial intelligence providers is processed under paid API terms under which it is not used to train their models.
- Artificial intelligence output can be inaccurate. We review material output before relying on it.
- We do not make decisions producing legal or similarly significant effects about you by solely automated means.
Section 7Who we share it with
| Recipient | Purpose |
|---|---|
| Service providers and sub-processors | Hosting, database, communications, artificial intelligence, analytics, payment and email delivery. The current list is at SUB-PROCESSORS.md |
| Advertising platforms | Advertising delivery and measurement |
| Professional advisers | Lawyers, accountants and insurers, where necessary |
| Authorities | Where legally required, or to establish, exercise or defend legal claims |
| An acquirer | In connection with a merger, acquisition or sale of assets, subject to this Policy |
We do not sell personal data. We do not share personal data for cross context behavioural advertising in a way that constitutes a "sale" or "share" under the CCPA, other than the use of advertising cookies and hashed audience uploads described in Section 5, which some laws treat as "sharing". You may opt out at Section 9.
Section 8Your rights
If you are in the EEA or UK, you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict processing; object to processing based on legitimate interest, including profiling; receive your data in a portable format; withdraw consent at any time without affecting prior processing; and complain to a supervisory authority.
Our lead supervisory authority is the data protection authority of Estonia. You may also complain to the authority where you live or work.
If you are in the United States, depending on your state you may have the right to: know what personal information we collect, use and disclose; access and receive a copy of it; correct inaccuracies; delete it; opt out of sale, sharing and targeted advertising; limit use of sensitive personal information; and not be discriminated against for exercising these rights.
Everyone. You may opt out of marketing at any time. That right is absolute and does not depend on where you live.
Section 9How to exercise your rights
Email [email protected] with your request. We may need to verify your identity, and will only ask for what is necessary to do so.
We respond within thirty (30) days for GDPR requests and within forty five (45) days for US state law requests, extendable where the law permits and we tell you.
An authorised agent may submit a request on your behalf with proof of authority.
We do not charge for this. We may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, and we will explain why.
To opt out of targeted advertising and sharing: use the cookie banner, or email [email protected]. We honour the Global Privacy Control signal where required.
Section 10How long we keep it
| Data | Retention |
|---|---|
| Enquiry and prospect data where you do not become a client | 24 months from last contact |
| Client records | Term of the engagement plus 7 years, for tax and limitation purposes |
| Communication records, transcripts, consent and opt-out records | 4 years from the communication, longer where needed to defend a claim |
| Suppression and opt-out lists | Indefinitely, because we need the record to keep honouring the opt-out |
| Analytics data | 26 months |
| Backups | Until the backup expires in the ordinary cycle |
We keep opt-out records forever on purpose. Deleting a record that you asked not to be contacted would allow you to be contacted again.
Section 11International transfers
We are established in Estonia. Many of our service providers are in the United States. Where we transfer personal data out of the EEA or UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where applicable, together with additional safeguards where needed.
A copy of the relevant safeguards is available on request to [email protected].
Section 12Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role based access control, multi factor authentication on administrative accounts, logical separation of client data, audit logging and an incident response process.
No system is completely secure. We cannot guarantee absolute security.
Section 13Children
The Site and our services are for businesses. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact [email protected] and we will delete it.
Section 14Changes
We may update this Policy. The "Last updated" date shows when. Where a change is material we will take reasonable steps to notify you. Continued use after the update constitutes acceptance where consent is not otherwise required.
Section 15Contact
Growthlio OÜ Vanemuise tn 46-8, Nõmme linnaosa, Tallinn, Harju maakond 10911, Estonia Registration number: 16945139
Privacy enquiries and rights requests: [email protected] General: [email protected]