Growthlio OÜ · Legal

Privacy Policy

Last updated 20 August 2026

What personal data Growthlio collects, why, and how to have it corrected, deleted, or stop being contacted.

Contents
  1. 1Two different roles
  2. 2Personal data we collect as controller
  3. 3Why we process it, and our lawful basis
  4. 4Marketing communications
  5. 5Cookies and tracking
  6. 6Artificial intelligence
  7. 7Who we share it with
  8. 8Your rights
  9. 9How to exercise your rights
  10. 10How long we keep it
  11. 11International transfers
  12. 12Security
  13. 13Children
  14. 14Changes
  15. 15Contact

This Privacy Policy explains how Growthlio OÜ ("Growthlio", "we", "us") collects, uses and shares personal data.

Growthlio OÜ, registered in Estonia under number 16945139, registered office Vanemuise tn 46-8, Nõmme linnaosa, Tallinn, Harju maakond 10911, Estonia, is the controller of the personal data described in this Policy.

Section 1Two different roles

This distinction matters, and most people reading this policy will fall into the first group.

When we act as controller. We decide how and why personal data is processed. This covers visitors to growthlio.com, people who submit our forms, subscribers, prospects we contact, clients and their personnel, partners and suppliers. This Policy describes that processing.

When we act as processor. We process personal data on behalf of a client, under that client's instructions, to deliver services to them. That includes the contacts in a client's database that we message on the client's behalf. This Policy does not govern that processing. The client is the controller, the client's own privacy notice applies, and our processing is governed by our Data Processing Agreement with that client.

If you were contacted by an automated agent and want to know why, ask the business whose name was in the message. They hold the record of your consent. If you cannot identify them, contact us at [email protected] and we will route your request to the right controller.

Section 2Personal data we collect as controller

You give us:

DataWhen
Name, email address, telephone number, company, roleForm submissions, enquiries, bookings, lead magnet downloads
Information about your business, revenue, goals and current systemsQualification forms, discovery calls, questionnaires
Call recordings and transcriptsCalls with us, where we tell you the call is recorded
Payment and billing detailsBecoming a client. Card details are handled by our payment processor, we do not store full card numbers
CorrespondenceEmails, messages and support requests

We collect automatically:

DataHow
IP address, device type, browser, operating systemServer logs
Pages viewed, referrer, time on page, clicksAnalytics and advertising cookies
Email open and click eventsTracking pixels in our marketing emails
Form interaction and submission metadata, including timestamp and IPOur forms, as evidence of consent

We obtain from others:

DataSource
Business contact details, company size, industry, technology usedBusiness data providers and enrichment services
Publicly available professional informationCompany websites, public professional profiles
Referral detailsPartners and existing clients who refer you

Section 3Why we process it, and our lawful basis

PurposeLawful basis (GDPR)
Responding to your enquiry, providing information you requestedPerformance of a contract, or steps at your request before entering one
Delivering services to clients and administering the relationshipPerformance of a contract
Sending marketing emails and text messagesConsent, or legitimate interest in marketing to business contacts where permitted
Contacting business prospects by emailLegitimate interest in promoting our services to relevant businesses
Recording and transcribing calls for quality, training and record keepingConsent, given at the start of the call
Advertising and measuring advertising, including custom audiencesConsent, for cookies and identifier based advertising
Analytics and improving the Site and our servicesLegitimate interest, or consent where cookies require it
Billing, accounting and taxLegal obligation and performance of a contract
Establishing, exercising or defending legal claimsLegitimate interest and legal obligation
Security, fraud prevention and preventing misuseLegitimate interest

Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights. You may object at any time. See Section 8.

Section 4Marketing communications

Email. We send marketing email to people who requested it and to business contacts where permitted by law. Every marketing email carries an unsubscribe link and our postal address. Unsubscribing takes effect immediately and always.

Text and voice. We contact by text message or telephone only where we hold the consent required by applicable law, or where an existing business relationship permits it. Where an automated or artificial intelligence system places the call or sends the message, it will identify itself as such. Reply STOP to any text message to opt out. You may also opt out by any other reasonable means, including replying in plain language, emailing [email protected], or telling us on a call. We will action it across all channels within ten (10) business days.

Message and data rates may apply. Message frequency varies. Opting out of marketing does not stop service messages relating to an active engagement.

Section 5Cookies and tracking

We use:

  • Strictly necessary cookies, for the Site to function. These cannot be turned off.
  • Analytics cookies, to understand how the Site is used.
  • Advertising cookies and pixels, including the Meta pixel and Google tags, to measure advertising and to build audiences.

Where required by law we ask for consent before setting non-essential cookies, and you can change your choice at any time through the cookie banner or your browser settings.

We may share hashed identifiers, such as a hashed email address or telephone number, with advertising platforms to build custom and lookalike audiences. Those platforms act as independent controllers for their own purposes under their own terms.

Do Not Track. Browsers send inconsistent Do Not Track signals and we do not respond to them. We do honour the Global Privacy Control signal where applicable law requires it.

Section 6Artificial intelligence

We use artificial intelligence systems to draft content, analyse conversations, and conduct automated conversations by text and voice.

  • Where you interact with an automated agent operated by us, it will tell you it is an artificial intelligence system.
  • Personal data submitted to our artificial intelligence providers is processed under paid API terms under which it is not used to train their models.
  • Artificial intelligence output can be inaccurate. We review material output before relying on it.
  • We do not make decisions producing legal or similarly significant effects about you by solely automated means.

Section 7Who we share it with

RecipientPurpose
Service providers and sub-processorsHosting, database, communications, artificial intelligence, analytics, payment and email delivery. The current list is at SUB-PROCESSORS.md
Advertising platformsAdvertising delivery and measurement
Professional advisersLawyers, accountants and insurers, where necessary
AuthoritiesWhere legally required, or to establish, exercise or defend legal claims
An acquirerIn connection with a merger, acquisition or sale of assets, subject to this Policy

We do not sell personal data. We do not share personal data for cross context behavioural advertising in a way that constitutes a "sale" or "share" under the CCPA, other than the use of advertising cookies and hashed audience uploads described in Section 5, which some laws treat as "sharing". You may opt out at Section 9.

Section 8Your rights

If you are in the EEA or UK, you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict processing; object to processing based on legitimate interest, including profiling; receive your data in a portable format; withdraw consent at any time without affecting prior processing; and complain to a supervisory authority.

Our lead supervisory authority is the data protection authority of Estonia. You may also complain to the authority where you live or work.

If you are in the United States, depending on your state you may have the right to: know what personal information we collect, use and disclose; access and receive a copy of it; correct inaccuracies; delete it; opt out of sale, sharing and targeted advertising; limit use of sensitive personal information; and not be discriminated against for exercising these rights.

Everyone. You may opt out of marketing at any time. That right is absolute and does not depend on where you live.

Section 9How to exercise your rights

Email [email protected] with your request. We may need to verify your identity, and will only ask for what is necessary to do so.

We respond within thirty (30) days for GDPR requests and within forty five (45) days for US state law requests, extendable where the law permits and we tell you.

An authorised agent may submit a request on your behalf with proof of authority.

We do not charge for this. We may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive, and we will explain why.

To opt out of targeted advertising and sharing: use the cookie banner, or email [email protected]. We honour the Global Privacy Control signal where required.

Section 10How long we keep it

DataRetention
Enquiry and prospect data where you do not become a client24 months from last contact
Client recordsTerm of the engagement plus 7 years, for tax and limitation purposes
Communication records, transcripts, consent and opt-out records4 years from the communication, longer where needed to defend a claim
Suppression and opt-out listsIndefinitely, because we need the record to keep honouring the opt-out
Analytics data26 months
BackupsUntil the backup expires in the ordinary cycle

We keep opt-out records forever on purpose. Deleting a record that you asked not to be contacted would allow you to be contacted again.

Section 11International transfers

We are established in Estonia. Many of our service providers are in the United States. Where we transfer personal data out of the EEA or UK to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where applicable, together with additional safeguards where needed.

A copy of the relevant safeguards is available on request to [email protected].

Section 12Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role based access control, multi factor authentication on administrative accounts, logical separation of client data, audit logging and an incident response process.

No system is completely secure. We cannot guarantee absolute security.

Section 13Children

The Site and our services are for businesses. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact [email protected] and we will delete it.

Section 14Changes

We may update this Policy. The "Last updated" date shows when. Where a change is material we will take reasonable steps to notify you. Continued use after the update constitutes acceptance where consent is not otherwise required.

Section 15Contact

Growthlio OÜ Vanemuise tn 46-8, Nõmme linnaosa, Tallinn, Harju maakond 10911, Estonia Registration number: 16945139

Privacy enquiries and rights requests: [email protected] General: [email protected]

Growthlio OÜ, registry code 16945139, Vanemuise tn 46-8, Nõmme linnaosa, Tallinn, Harju maakond 10911, Estonia

Privacy enquiries and rights requests: [email protected]

Terms of Use Sub-processors