This policy explains how Growth Automation collects, uses, shares and protects personal information, and the choices and rights you have. It applies to:
| Who we are | NAVU LLC, doing business as Growth Automation: a US company, based in Wyoming, with a team that works worldwide. We provide done-for-you B2B outbound lead generation, and the Growth Automation platform (app.growthautomation.ai, including our AI assistant Dex). |
| Whose information | (1) Our customers and their users. (2) Business professionals whose work details are in our B2B contact database, or who receive email or LinkedIn outreach we send for our customers. (3) Visitors to our websites. |
| Where it comes from | From you, from our customers, from licensed B2B data providers and public sources, and automatically when you use our websites and platform. |
| Why we use it | To provide our services, to help our customers find and contact relevant business prospects, to market our own services, to keep our services secure, and to comply with the law. |
| Selling | We never sell our customers' account information. We do provide business contact information to our customers for a fee, which some US state laws call a "sale". Anyone can opt out. |
| AI | We use AI to research companies, draft business messages, sort replies and answer questions in our platform. We don't use it to make decisions that have legal or similarly significant effects on you. |
| Your choices | You can ask us to stop contacting you, remove you from our database, see or correct what we hold, and more. Email privacy@growthautomation.ai. |
Your right to object to direct marketing. You can object at any time to our use of your information for direct marketing, including any profiling for that purpose. If you do, we will stop. Just reply to any of our messages, or email privacy@growthautomation.ai. You don't need to give a reason.
1.1 Who we are. "Growth Automation", "we", "us" and "our" mean NAVU LLC, a Wyoming limited liability company doing business as Growth Automation, at 1309 Coffeen Ave, STE 1200, Sheridan, WY 82801, United States. Our team works remotely from several countries. Contact details are in section 15.
1.2 What this policy covers. It covers personal information we handle through:
1.3 Our role. Privacy laws use two roles:
We act in both roles:
1.4 What this policy doesn't cover. Third-party websites and platforms (for example LinkedIn or Calendly), which have their own policies. It also doesn't cover what our customers do with information they hold independently of us.
We collect information about people in their professional capacity. It may include:
We don't intentionally collect sensitive information about business professionals. That includes health, racial or ethnic origin, religion, sexual orientation, political opinions, union membership, precise location, government identifiers and financial account numbers. If you include sensitive information in a reply, we use it only to handle your message.
Some customers use our visitor identification add-on. For them, we provide a script, through partners such as RB2B and Factors.ai, that the customer places on pages of its own website.
We collect information from job applicants (CVs, interview notes, references), suppliers and partners (contact and payment details), and people who contact us, to manage those relationships.
For most people in the GA Database, the source is one or more of the licensed data providers and public sources above; some records also come from our customers. If you ask, we'll tell you the specific source of your information, as far as our records show.
| Purpose | What this involves | Main information used | Legal basis (EEA/UK/Swiss law) |
|---|---|---|---|
| Providing the Services | Accounts, onboarding, campaigns, dashboards, Dex, support, security | Customer and user information; information about business professionals | Performance of our contract with customers; our legitimate interest in serving our customers' users |
| Maintaining the GA Database and matching it to customer needs | Sourcing, verifying, de-duplicating, updating and removing records; selecting contacts that match a customer's ideal-customer profile; providing those contacts and related insights to the customer | Information about business professionals | Legitimate interests (ours, and our customers', in finding relevant business contacts); see the balancing note below |
| Running outreach for customers | Drafting personalised messages; sending email and LinkedIn messages in the customer's name; handling, sorting and forwarding replies; booking meetings; looking up phone numbers for people who replied | Information about business professionals | We act on the customer's instructions. The customer relies on legitimate interests, or on consent where e-marketing law requires it |
| Marketing our own services | Emails, LinkedIn messages, events and content about Growth Automation | Business contact information; website information | Legitimate interests; consent where required |
| AI features | See section 5 | As described in section 5 | Legitimate interests; performance of our contract with customers |
| Deliverability, quality and safety | Checking email addresses; monitoring bounces and complaints; keeping suppression lists; preventing abuse and fraud; securing our systems | All categories, as needed | Legitimate interests; legal obligations |
| Analytics and improvement | Measuring campaign and product performance; testing features; evaluating and improving our prompts, classifiers and workflows | Usage and interaction information (aggregated or de-identified where possible) | Legitimate interests |
| Billing and administration | Invoicing, payments, tax and accounting records | Customer and billing information | Performance of contract; legal obligations |
| Legal and compliance | Handling rights requests and complaints; enforcing our terms; establishing or defending legal claims; responding to lawful requests | All categories, as needed | Legal obligations; legitimate interests |
| Business transfers | Due diligence and completion of a merger, financing or sale | All categories, as needed | Legitimate interests |
Balancing note (legitimate interests). "Legitimate interests" is a legal basis that lets an organisation use personal information without asking permission first, as long as its reason is genuine and doesn't unfairly override the interests of the people concerned. We rely on it for business-to-business prospecting because it lets businesses find people whose roles are relevant to what they offer, and that is widely recognised as a legitimate purpose. We limit the impact on you:
You can ask for a summary of our assessment.
5.1 What we use AI for. We use AI models from providers such as Anthropic, OpenAI and Google, and models accessed through OpenRouter, to:
5.2 Human oversight. Customers approve campaign strategy and messaging before launch, and our team reviews replies the AI can't confidently categorise. You can ask to speak with a person at any time.
5.3 No significant automated decisions. We don't make decisions about you based solely on automated processing that have legal or similarly significant effects, such as decisions about employment, credit, housing, insurance or access to essential services. Deciding which business professionals receive a business message, or how a reply is routed, isn't that kind of decision. So the additional disclosures that data protection law requires for such decisions don't apply; we describe our automated processing below anyway. You can object at any time (section 11).
5.4 Automated decisions. Some of our software makes, or helps make, the following decisions. It uses professional identity, role and seniority, company information, public business signals and interaction information to decide:
Some of these decisions, such as categorising a routine reply, are made by the software alone. Others, such as choosing a campaign audience, are reviewed by our team or the customer. We don't expect any of these decisions to significantly affect anyone's rights or interests, but we describe them here for transparency.
5.5 How our AI providers handle your information. We send AI providers only the information needed for the task. We use provider settings and terms under which providers don't use the information we send to train their general-purpose models. We may use information from the Services to evaluate and improve our own prompts, classifiers and features. We don't use personal information to train large language models, and we don't sell personal information for that purpose.
We keep personal information only as long as we need it for the purposes above, then delete or de-identify it. How long that is depends on the type of information:
| Information | How long we keep it |
|---|---|
| Customer account, contract and billing records | For the life of the account, then as long as tax, accounting and legal-claim rules require (usually up to 7 years) |
| Customer campaign data (messages, replies, lead records) | For the life of the customer relationship and a reasonable period afterwards, unless the customer asks us to delete it sooner or we must keep it for legal reasons. Aggregated statistics that don't identify anyone may be kept |
| GA Database records | While the information remains accurate and useful. We remove records that bounce, or that we learn are out of date |
| Suppression records (people who asked not to be contacted) | Indefinitely, in minimal or hashed form, so the request keeps being honoured |
| Website analytics | Up to 14 months in Google Analytics; in Factors.ai, according to its retention settings |
| Platform session recordings and error reports | For a limited period set in our error-monitoring provider, generally no more than 90 days |
| Contact form and sales correspondence | Up to 3 years after our last interaction |
| Backups | Overwritten on a rolling basis, within 30 days |
We use administrative, technical and physical safeguards designed to protect personal information. They include:
No system is perfectly secure. If a data breach is likely to cause you serious harm, we'll notify you and the relevant regulators as the law requires. Customers are responsible for keeping their own login credentials secure and for managing their users' access.
10.1 What we use on the Site.
| Type | Provider | Purpose | Examples and duration |
|---|---|---|---|
| Strictly necessary | Vercel (hosting) | Delivering the Site securely | Server logs |
| Preferences | Growth Automation | Remembering your light or dark theme | Browser storage key ga-theme, until cleared |
| Analytics | Google Analytics 4 | Understanding how the Site is used | _ga, _ga_*, up to 2 years |
| Company identification | Factors.ai | Identifying which organisations visit | Set by Factors.ai under its own cookie policy |
| Scheduling | Calendly (embedded) | Booking calls | Set by Calendly under its own policy |
10.2 On the Platform. We use strictly necessary storage to keep you signed in and secure, and error monitoring (Sentry) to find and fix problems. We don't use advertising cookies on the Platform.
10.3 Your choices. You can block or delete cookies in your browser settings, and install Google's Analytics opt-out browser add-on. Blocking analytics cookies won't stop the Site working.
10.4 Browser signals. There's no agreed standard for browsers' "Do Not Track" signals, so we don't respond to them. You can opt out of the sale of your information as described in section 7.
10.5 Emails. Our outreach emails don't use open-tracking pixels by default.
Depending on where you live, you may have the right to:
We honour these requests for everyone, wherever you live, subject to legal exceptions. For example, we may keep information we need to comply with the law or defend legal claims, or to keep a suppression record. If your request is about a message one of our customers asked us to send, see section 11.5.
Email privacy@growthautomation.ai, or reply to any message we sent you. You don't need an account.
We'll tell you if we need more time, and why. - Cost. Requests are free, unless they are clearly unfounded or excessive.
If we decline your request, you can appeal: reply to our decision, or email privacy@growthautomation.ai with "Appeal" in the subject line, within 60 days. We'll respond within the time your state's law allows, usually 45 or 60 days. If you're not satisfied, you can contact your state Attorney General.
If your request is about information we process for a customer (for example, messages that customer asked us to send), we'll pass it to the customer and help them respond. We also stop our own use of your information, as described in section 11.1.
If you have a privacy concern or complaint, please contact our Privacy Officer first (section 15).
California: notice at collection and categories of information. In the past 12 months, we've collected the categories below. We use each category for the purposes in section 4. We keep it for the periods in section 8, which are set by record type. For example, business contact identifiers and professional information are kept as GA Database records, and billing records as customer account records.
| Category (California law) | Examples | Sources | Disclosed for a business purpose to | Sold to |
|---|---|---|---|---|
| Identifiers | Name, work email, phone, LinkedIn profile address, IP address, account username | You; our customers; data providers; public sources; automatically | Service providers; customers (for their campaigns); professional advisers; authorities where required | Customers (business contact identifiers only) |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Name, employer, job title, work address and phone; billing details for customers | You; our customers; data providers | Service providers; customers | Customers (professional details only) |
| Commercial information | Plans purchased, billing history | You; Stripe | Service providers (payments, accounting) | Not sold |
| Internet or network activity | Site and Platform usage, logs, Platform session recordings, interactions with our messages; visits to customers' websites where the customer uses our visitor identification add-on | Automatically; platforms; customers' websites | Service providers (hosting, analytics, error monitoring); the customer whose website was visited | Not sold |
| Geolocation (not precise) | City, region and country, from IP address or professional profiles | Automatically; data providers | Service providers; customers | Customers (work location only) |
| Audio or electronic information | Call or meeting recordings, if any | You | Service providers | Not sold |
| Professional or employment information | Job title, seniority, department, employer, professional history | Data providers; public sources; you | Service providers; customers | Customers |
| Inferences | Relevance to an offer, likely department or seniority, reply categories, communication-style insights | Created by us | Service providers; customers | Customers |
| Sensitive personal information | Account login and password (users only) | You | Our authentication provider | Not sold. Used only to sign you in and keep your account secure |
Your California rights: know and access, delete, correct, opt out of sale or sharing, and non-discrimination (section 11). We don't use sensitive personal information for purposes that would give you a right to limit it. We don't offer financial incentives in exchange for personal information.
Other US states: Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states have their own privacy laws. Most of them don't cover information about people acting in a business role. We extend the rights in section 11, including appeals (section 11.4), to everyone anyway.
Nevada: you can ask us not to sell your covered information by emailing privacy@growthautomation.ai.
We handle personal information in line with the Australian Privacy Principles (APPs).
When we collect information about you from someone else, this policy tells you:
You can complain to the Office of the Privacy Commissioner (privacy.org.nz).
If you live in another country, including India, the Philippines, Singapore, the United Arab Emirates or Saudi Arabia, you can exercise the rights your local law gives you by contacting us (section 15). For India, our Privacy Officer also acts as our grievance officer.
We are a US company, and our main databases and servers are hosted in the United States. Our team and contractors work from several countries, including the Philippines.
We're likely to disclose personal information to recipients in:
This means your information may be processed in a country with different privacy laws from yours.
When we transfer personal information out of the EEA, UK or Switzerland, we use safeguards recognised by those laws:
We aren't ourselves certified under the Data Privacy Framework. You can ask us for a copy of the relevant safeguards.
When we disclose personal information to overseas recipients, we take reasonable steps to make sure they protect it in line with the laws that apply to us, including, where they apply, the Australian Privacy Principles.
Children. Our Services are for businesses and aren't directed at children. We don't knowingly collect personal information from anyone under 16. If we learn we have, we'll delete it.
Third-party websites and platforms. Our Site and messages may link to other websites and platforms, such as LinkedIn and Calendly. Their privacy practices are their own.
Google user data. Our staff connect their Growth Automation Google Workspace accounts to the Platform, so it can read and organise work email, send forwarded leads, and access Drive files and calendars. Growth Automation's use, and transfer to any other app, of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We don't use Google user data for advertising or to train generalised AI models.
Privacy Officer NAVU LLC (Growth Automation) 1309 Coffeen Ave, STE 1200 Sheridan, WY 82801, United States Email: privacy@growthautomation.ai
We may update this policy as our Services or the law change, and we'll post the new version with a new "Last updated" date. If we make material changes, we'll tell customers by email or in the Platform, and highlight the change on this page, before it takes effect. Where the law requires your consent to a change, we'll ask for it. Previous versions are available on request.
We take privacy seriously. Reach out and we'll get back to you promptly.
Get in Touch →