On this page
01Purpose & scope
These terms govern all processing of personal data Growlith Academy Ltd performs on behalf of a client when operating growth systems — analytics instrumentation, paid media, lifecycle CRM, web cores — under any engagement, statement of work or order form. They form part of the Terms of Engagement and apply in addition to them.
02Roles of the parties
For processing carried out under these terms, you (the client) are the controller and Growlith is the processor. Where GDPR, UK GDPR or an equivalent regime applies, each party complies with its role-specific obligations, and Growlith processes personal data only on the controller's documented instructions — which are the engagement scope, any SOW, and directions given through your pod lead.
If a third-party platform is involved (e.g. Meta Ads, Google Ads, Klaviyo), you contract with that platform directly and it acts as an independent controller or processor for its own service; we configure and operate it for you.
03Details of the processing
The specifics depend on the engines deployed, but the envelope is fixed:
Categories of data subjects
The controller's customers, prospects, website visitors, and contacts in marketing and CRM systems — not Growlith's own staff or contacts.
Categories of personal data
- Identity & contact data — name, email, phone, account identifiers.
- Behavioural data — site and app events, campaign interactions, purchase signals.
- Transactional data — orders and revenue events ingested for attribution and scoring.
- Technical data — device class, approximate geography, referrers.
We do not knowingly process special-category data. If your use case requires it, we agree explicit written terms first.
Purposes & duration
Processing happens only to deliver the engines in scope — acquisition, conversion, retention, and the reporting that measures them — and only for the term of the engagement plus a wind-down period of up to 60 days for return or deletion.
04Subprocessors
Growlith engages the following categories of subprocessor to deliver engagements. We notify clients at least 14 days before adding a new one, and you may reasonably object on data-protection grounds.
| Category | Examples | Location |
|---|---|---|
| Cloud & edge infrastructure | Cloudflare, Vercel, AWS | Global edge · US/EU regions |
| Analytics & tag management | Google Analytics 4, GTM server-side | US / EU |
| Advertising platforms | Meta, Google, TikTok, LinkedIn Ads | US / EU |
| CRM & lifecycle | Klaviyo, HubSpot, Braze | US / EU |
| Collaboration | Google Workspace, Slack | US / EU |
05Security measures
Security is the product we ship, and the same standards that keep client growth systems safe apply to the personal data inside them.
Technical measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256) across all systems.
- Server-side tagging and first-party collection endpoints — raw browser data is not sprayed to third parties.
- Least-privilege access with MFA, individual credentials, and no shared logins.
- Secrets in managed vaults — never in client repos, spreadsheets or chat.
- Monitoring and alerting on pipelines and access anomalies.
Organisational measures
- Named pod members per engagement; access granted per client and revoked on rotation.
- Confidentiality obligations in every employment and contractor agreement.
- Quarterly access reviews and an annual security walkthrough with each client on request.
06International transfers
Where personal data is transferred out of the UK or EEA — to a subprocessor or a bureau — the transfer relies on adequacy decisions or the Standard Contractual Clauses (2010/87/EU and 2021/914 modules as applicable), the UK IDTA / Addendum, and supplementary measures including encryption and pseudonymisation. We maintain a transfer map per engagement and share it on request.
07Personal data breaches
If a breach affects client personal data, Growlith notifies the controller without undue delay and within 24 hours of becoming aware, with the nature of the breach, categories and approximate number of records and data subjects affected, likely consequences, and the remediation taken or planned. We never conceal, delay or minimise a breach notification, and we assist the controller with regulator and data-subject notifications as required.
08Return & deletion
On termination, at the controller's choice, we return personal data in a machine-readable format and delete remaining copies within 60 days — except where retention is legally required (in which case we isolate and protect the data and inform you). Because we build in the client's own accounts and repos, most data is already in your possession on day one.
09Audits & assistance
We assist controllers with data-subject requests, impact assessments and regulator enquiries touching our processing. On 30 days' notice, you may audit (or commission an independent audit of) our compliance with these terms — in practice, most clients accept our annual audit report and the shared telemetry dashboards instead.
10Contact
Data-protection matters for engagements: contact@growlithacademy.com — Growlith Academy Ltd. Privacy questions about this website itself are answered in the Privacy Policy.