Privacy Policy

📅 Last updated: 5 October 2026 🏭 NAVU LLC (Growth Automation)

Contents

  1. Who we are and what this policy covers
  2. Information we collect
  3. Where we get information
  4. How and why we use information
  5. AI, automated processing and profiling
  6. How we share information
  7. "Selling", "sharing" and targeted advertising (US state law)
  8. How long we keep information
  9. How we protect information
  10. Cookies and similar technologies
  11. Your choices and rights
  12. Information for specific regions
  13. International transfers
  14. Children, third-party links and Google data
  15. Contact us
  16. Changes to this policy

This policy explains how Growth Automation collects, uses, shares and protects personal information, and the choices and rights you have. It applies to:

Summary

Who we are NAVU LLC, doing business as Growth Automation: a US company, based in Wyoming, with a team that works worldwide. We provide done-for-you B2B outbound lead generation, and the Growth Automation platform (app.growthautomation.ai, including our AI assistant Dex).
Whose information (1) Our customers and their users. (2) Business professionals whose work details are in our B2B contact database, or who receive email or LinkedIn outreach we send for our customers. (3) Visitors to our websites.
Where it comes from From you, from our customers, from licensed B2B data providers and public sources, and automatically when you use our websites and platform.
Why we use it To provide our services, to help our customers find and contact relevant business prospects, to market our own services, to keep our services secure, and to comply with the law.
Selling We never sell our customers' account information. We do provide business contact information to our customers for a fee, which some US state laws call a "sale". Anyone can opt out.
AI We use AI to research companies, draft business messages, sort replies and answer questions in our platform. We don't use it to make decisions that have legal or similarly significant effects on you.
Your choices You can ask us to stop contacting you, remove you from our database, see or correct what we hold, and more. Email privacy@growthautomation.ai.

Your right to object to direct marketing. You can object at any time to our use of your information for direct marketing, including any profiling for that purpose. If you do, we will stop. Just reply to any of our messages, or email privacy@growthautomation.ai. You don't need to give a reason.

1. Who we are and what this policy covers

1.1 Who we are. "Growth Automation", "we", "us" and "our" mean NAVU LLC, a Wyoming limited liability company doing business as Growth Automation, at 1309 Coffeen Ave, STE 1200, Sheridan, WY 82801, United States. Our team works remotely from several countries. Contact details are in section 15.

1.2 What this policy covers. It covers personal information we handle through:

1.3 Our role. Privacy laws use two roles:

We act in both roles:

1.4 What this policy doesn't cover. Third-party websites and platforms (for example LinkedIn or Calendly), which have their own policies. It also doesn't cover what our customers do with information they hold independently of us.

2. Information we collect

2.1 Customers, users and prospective customers

2.2 Business professionals (the GA Database and people we contact for customers)

We collect information about people in their professional capacity. It may include:

We don't intentionally collect sensitive information about business professionals. That includes health, racial or ethnic origin, religion, sexual orientation, political opinions, union membership, precise location, government identifiers and financial account numbers. If you include sensitive information in a reply, we use it only to handle your message.

2.3 Website visitors

2.4 Visitors to our customers' websites

Some customers use our visitor identification add-on. For them, we provide a script, through partners such as RB2B and Factors.ai, that the customer places on pages of its own website.

2.5 Other people

We collect information from job applicants (CVs, interview notes, references), suppliers and partners (contact and payment details), and people who contact us, to manage those relationships.

3. Where we get information

For most people in the GA Database, the source is one or more of the licensed data providers and public sources above; some records also come from our customers. If you ask, we'll tell you the specific source of your information, as far as our records show.

4. How and why we use information

Purpose What this involves Main information used Legal basis (EEA/UK/Swiss law)
Providing the Services Accounts, onboarding, campaigns, dashboards, Dex, support, security Customer and user information; information about business professionals Performance of our contract with customers; our legitimate interest in serving our customers' users
Maintaining the GA Database and matching it to customer needs Sourcing, verifying, de-duplicating, updating and removing records; selecting contacts that match a customer's ideal-customer profile; providing those contacts and related insights to the customer Information about business professionals Legitimate interests (ours, and our customers', in finding relevant business contacts); see the balancing note below
Running outreach for customers Drafting personalised messages; sending email and LinkedIn messages in the customer's name; handling, sorting and forwarding replies; booking meetings; looking up phone numbers for people who replied Information about business professionals We act on the customer's instructions. The customer relies on legitimate interests, or on consent where e-marketing law requires it
Marketing our own services Emails, LinkedIn messages, events and content about Growth Automation Business contact information; website information Legitimate interests; consent where required
AI features See section 5 As described in section 5 Legitimate interests; performance of our contract with customers
Deliverability, quality and safety Checking email addresses; monitoring bounces and complaints; keeping suppression lists; preventing abuse and fraud; securing our systems All categories, as needed Legitimate interests; legal obligations
Analytics and improvement Measuring campaign and product performance; testing features; evaluating and improving our prompts, classifiers and workflows Usage and interaction information (aggregated or de-identified where possible) Legitimate interests
Billing and administration Invoicing, payments, tax and accounting records Customer and billing information Performance of contract; legal obligations
Legal and compliance Handling rights requests and complaints; enforcing our terms; establishing or defending legal claims; responding to lawful requests All categories, as needed Legal obligations; legitimate interests
Business transfers Due diligence and completion of a merger, financing or sale All categories, as needed Legitimate interests

Balancing note (legitimate interests). "Legitimate interests" is a legal basis that lets an organisation use personal information without asking permission first, as long as its reason is genuine and doesn't unfairly override the interests of the people concerned. We rely on it for business-to-business prospecting because it lets businesses find people whose roles are relevant to what they offer, and that is widely recognised as a legitimate purpose. We limit the impact on you:

You can ask for a summary of our assessment.

5. AI, automated processing and profiling

5.1 What we use AI for. We use AI models from providers such as Anthropic, OpenAI and Google, and models accessed through OpenRouter, to:

5.2 Human oversight. Customers approve campaign strategy and messaging before launch, and our team reviews replies the AI can't confidently categorise. You can ask to speak with a person at any time.

5.3 No significant automated decisions. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects, such as decisions about employment, credit, housing, insurance or access to essential services. Deciding which business professionals receive a business message, or how a reply is routed, isn't that kind of decision. So the additional disclosures that data protection law requires for such decisions don't apply; we describe our automated processing below anyway. You can object at any time (section 11).

5.4 Automated decisions. Some of our software makes, or helps make, the following decisions. It uses professional identity, role and seniority, company information, public business signals and interaction information to decide:

Some of these decisions, such as categorising a routine reply, are made by the software alone. Others, such as choosing a campaign audience, are reviewed by our team or the customer. We don't expect any of these decisions to significantly affect anyone's rights or interests, but we describe them here for transparency.

5.5 How our AI providers handle your information. We send AI providers only the information needed for the task. We use provider settings and terms under which providers don't use the information we send to train their general-purpose models. We may use information from the Services to evaluate and improve our own prompts, classifiers and features. We don't use personal information to train large language models, and we don't sell personal information for that purpose.

6. How we share information

They may use the information only to provide services to us. You can ask us for a list of them. - With platforms you interact with. Email and LinkedIn messages pass through those platforms, which handle information under their own policies. - With professional advisers, such as lawyers, accountants, auditors and insurers, under confidentiality obligations. - For legal reasons: to comply with the law or a lawful request, to enforce our agreements, or to protect the rights, safety and security of our customers, the public or us. - In a business transfer: as part of a merger, acquisition, financing or sale of assets, subject to this policy. - With your consent or at your direction.

Information customers give us. We use lists and information a customer gives us to provide the Services to that customer. Where our agreement with the customer allows it, we may also use business contact details from those lists to verify and keep the GA Database accurate.

De-identified and aggregated information. We may create and share statistics that don't identify anyone, such as average reply rates. We keep that information in de-identified form and don't try to re-identify it.

7. "Selling", "sharing" and targeted advertising (US state law)

8. How long we keep information

We keep personal information only as long as we need it for the purposes above, then delete or de-identify it. How long that is depends on the type of information:

Information How long we keep it
Customer account, contract and billing records For the life of the account, then as long as tax, accounting and legal-claim rules require (usually up to 7 years)
Customer campaign data (messages, replies, lead records) For the life of the customer relationship and a reasonable period afterwards, unless the customer asks us to delete it sooner or we must keep it for legal reasons. Aggregated statistics that don't identify anyone may be kept
GA Database records While the information remains accurate and useful. We remove records that bounce, or that we learn are out of date
Suppression records (people who asked not to be contacted) Indefinitely, in minimal or hashed form, so the request keeps being honoured
Website analytics Up to 14 months in Google Analytics; in Factors.ai, according to its retention settings
Platform session recordings and error reports For a limited period set in our error-monitoring provider, generally no more than 90 days
Contact form and sales correspondence Up to 3 years after our last interaction
Backups Overwritten on a rolling basis, within 30 days

9. How we protect information

We use administrative, technical and physical safeguards designed to protect personal information. They include:

No system is perfectly secure. If a data breach is likely to cause you serious harm, we'll notify you and the relevant regulators as the law requires. Customers are responsible for keeping their own login credentials secure and for managing their users' access.

10. Cookies and similar technologies

10.1 What we use on the Site.

Type Provider Purpose Examples and duration
Strictly necessary Vercel (hosting) Delivering the Site securely Server logs
Preferences Growth Automation Remembering your light or dark theme Browser storage key ga-theme, until cleared
Analytics Google Analytics 4 Understanding how the Site is used _ga, _ga_*, up to 2 years
Company identification Factors.ai Identifying which organisations visit Set by Factors.ai under its own cookie policy
Scheduling Calendly (embedded) Booking calls Set by Calendly under its own policy

10.2 On the Platform. We use strictly necessary storage to keep you signed in and secure, and error monitoring (Sentry) to find and fix problems. We don't use advertising cookies on the Platform.

10.3 Your choices. You can block or delete cookies in your browser settings, and install Google's Analytics opt-out browser add-on. Blocking analytics cookies won't stop the Site working.

10.4 Browser signals. There's no agreed standard for browsers' "Do Not Track" signals, so we don't respond to them. You can opt out of the sale of your information as described in section 7.

10.5 Emails. Our outreach emails don't use open-tracking pixels by default.

11. Your choices and rights

11.1 Stop outreach, or remove yourself from our database

11.2 Your rights

Depending on where you live, you may have the right to:

We honour these requests for everyone, wherever you live, subject to legal exceptions. For example, we may keep information we need to comply with the law or defend legal claims, or to keep a suppression record. If your request is about a message one of our customers asked us to send, see section 11.5.

11.3 How to make a request

Email privacy@growthautomation.ai, or reply to any message we sent you. You don't need an account.

We'll tell you if we need more time, and why. - Cost. Requests are free, unless they are clearly unfounded or excessive.

11.4 Appeals (US)

If we decline your request, you can appeal: reply to our decision, or email privacy@growthautomation.ai with "Appeal" in the subject line, within 60 days. We'll respond within the time your state's law allows, usually 45 or 60 days. If you're not satisfied, you can contact your state Attorney General.

11.5 Requests about customer data

If your request is about information we process for a customer (for example, messages that customer asked us to send), we'll pass it to the customer and help them respond. We also stop our own use of your information, as described in section 11.1.

11.6 Complaints

If you have a privacy concern or complaint, please contact our Privacy Officer first (section 15).

12. Information for specific regions

12.1 European Economic Area, United Kingdom and Switzerland

12.2 United States

California: notice at collection and categories of information. In the past 12 months, we've collected the categories below. We use each category for the purposes in section 4. We keep it for the periods in section 8, which are set by record type. For example, business contact identifiers and professional information are kept as GA Database records, and billing records as customer account records.

Category (California law) Examples Sources Disclosed for a business purpose to Sold to
Identifiers Name, work email, phone, LinkedIn profile address, IP address, account username You; our customers; data providers; public sources; automatically Service providers; customers (for their campaigns); professional advisers; authorities where required Customers (business contact identifiers only)
Customer records (Cal. Civ. Code § 1798.80(e)) Name, employer, job title, work address and phone; billing details for customers You; our customers; data providers Service providers; customers Customers (professional details only)
Commercial information Plans purchased, billing history You; Stripe Service providers (payments, accounting) Not sold
Internet or network activity Site and Platform usage, logs, Platform session recordings, interactions with our messages; visits to customers' websites where the customer uses our visitor identification add-on Automatically; platforms; customers' websites Service providers (hosting, analytics, error monitoring); the customer whose website was visited Not sold
Geolocation (not precise) City, region and country, from IP address or professional profiles Automatically; data providers Service providers; customers Customers (work location only)
Audio or electronic information Call or meeting recordings, if any You Service providers Not sold
Professional or employment information Job title, seniority, department, employer, professional history Data providers; public sources; you Service providers; customers Customers
Inferences Relevance to an offer, likely department or seniority, reply categories, communication-style insights Created by us Service providers; customers Customers
Sensitive personal information Account login and password (users only) You Our authentication provider Not sold. Used only to sign you in and keep your account secure

Your California rights: know and access, delete, correct, opt out of sale or sharing, and non-discrimination (section 11). We don't use sensitive personal information for purposes that would give you a right to limit it. We don't offer financial incentives in exchange for personal information.

Other US states: Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states have their own privacy laws. Most of them don't cover information about people acting in a business role. We extend the rights in section 11, including appeals (section 11.4), to everyone anyway.

Nevada: you can ask us not to sell your covered information by emailing privacy@growthautomation.ai.

12.3 Australia

We handle personal information in line with the Australian Privacy Principles (APPs).

12.4 Canada (including Quebec)

12.5 New Zealand

When we collect information about you from someone else, this policy tells you:

You can complain to the Office of the Privacy Commissioner (privacy.org.nz).

12.6 Other countries

If you live in another country, including India, the Philippines, Singapore, the United Arab Emirates or Saudi Arabia, you can exercise the rights your local law gives you by contacting us (section 15). For India, our Privacy Officer also acts as our grievance officer.

13. International transfers

We are a US company, and our main databases and servers are hosted in the United States. Our team and contractors work from several countries, including the Philippines.

We're likely to disclose personal information to recipients in:

This means your information may be processed in a country with different privacy laws from yours.

When we transfer personal information out of the EEA, UK or Switzerland, we use safeguards recognised by those laws:

We aren't ourselves certified under the Data Privacy Framework. You can ask us for a copy of the relevant safeguards.

When we disclose personal information to overseas recipients, we take reasonable steps to make sure they protect it in line with the laws that apply to us, including, where they apply, the Australian Privacy Principles.

15. Contact us

Privacy Officer NAVU LLC (Growth Automation) 1309 Coffeen Ave, STE 1200 Sheridan, WY 82801, United States Email: privacy@growthautomation.ai

16. Changes to this policy

We may update this policy as our Services or the law change, and we'll post the new version with a new "Last updated" date. If we make material changes, we'll tell customers by email or in the Platform, and highlight the change on this page, before it takes effect. Where the law requires your consent to a change, we'll ask for it. Previous versions are available on request.

Questions about your data?

We take privacy seriously. Reach out and we'll get back to you promptly.

Get in Touch →