Legal
Privacy Policy
Last updated: August 11th, 2026
Thank you for choosing to be part of our community at Growy, at https://growy.app ("we", "us", or "our"), a product of Attitude Group Ltd. We are committed to protecting your personal information and your right to privacy.
This Privacy Policy explains how we collect, use, disclose, share, store and protect your information when you visit our website, use our AI platform, and interact with related services (collectively, the "Services").
By using our Services, you agree to the terms outlined in this policy. If you have any questions or wish to exercise your data rights, contact us at [email protected].
1. Our role: controller and processor
There are two distinct relationships, and they work differently.
When you visit our website, request a demo, or hold an account with us, Attitude Group Ltd is the data controller. We decide what personal data to collect and why. This policy describes that processing.
When our clients upload documents to their Company Brain, connect their systems, or run AI Agents over their business data, the client is the data controller and Attitude Group Ltd is the data processor. We process that data only on the client's documented instructions, under a Data Processing Agreement.
If your personal data sits inside a client's Growy workspace, for example, because your employer uses Growy, that organisation is the controller and you should direct your requests to them. We assist our clients in responding.
Our full position on data protection and AI regulation is set out on our GDPR & EU AI Act page.
2. What information do we collect?
Personal information you provide to us
We collect personal information that you voluntarily provide when you:
- register for an account or join our waiting list
- book a demo or request a consultation
- contact us for support or enquiries
- subscribe to communications from us
This may include: name, email address, phone number, company name, job title, and any other information you choose to provide.
Payment data
If you subscribe to a paid plan, we collect (through card payment providers) billing address and related payment information. Payment processing is handled solely through PCI-DSS compliant providers. We do not store full payment card details on our servers.
Information collected automatically
When you access our Services we automatically collect certain technical information, including IP address, device type, browser type, operating system, pages visited, time spent on pages, referring URLs and other usage data. This is collected to enable functionality, troubleshoot issues and improve the experience.
3. How do we use your information, and on what legal basis?
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, processing registrations, maintaining your profile | Contract (Art. 6(1)(b)) |
| Providing, operating and improving the platform, including AI Assistants and AI Agents | Contract |
| Billing, invoicing and payment | Contract / legal obligation |
| Responding to enquiries and providing support | Contract / legitimate interests |
| Analytics and product improvement | Legitimate interests (Art. 6(1)(f)) |
| Security, authentication, fraud and abuse prevention | Legitimate interests |
| Marketing communications about products, features and updates | Consent (Art. 6(1)(a)) |
| Meeting legal and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we assess that interest against your rights and freedoms. You may opt out of marketing at any time, and you may object to processing based on legitimate interests as described in section 10.
4. How we handle your uploaded data
Your content belongs to you.
When you upload documents, PDFs, manuals, spreadsheets, or integrate third-party tools with Growy, this data is used exclusively to power your AI Agents and Assistants within your account.
We do not:
- use your uploaded company data to train general AI models
- share your uploaded data with other customers
- retain your data beyond what is necessary, except for technical support you have requested or to comply with legal obligations
Your uploaded data is encrypted at rest and in transit, and is logically separated from other clients. You may request deletion at any time.
5. Will your information be shared with anyone?
- With your consent: where you have given explicit permission.
- Service providers and subprocessors: third parties performing services on our behalf, contractually obliged to protect your information.
- Legal obligations: where required by law, regulation or governmental request.
- Business transfers: in the event of a merger, acquisition, sale of assets or insolvency.
- Protection of rights: where necessary to protect Growy, our users or the public.
We do not sell your personal information.
Our subprocessors fall into these categories: cloud infrastructure and hosting; large language model providers (currently Anthropic, OpenAI and Google); integration infrastructure; and operational tooling such as email delivery, analytics, support and payment processing.
Data sent to model providers is used solely to generate a response or complete a task within your account. Providers operate under terms prohibiting training on customer data.
The current named subprocessor list forms part of our Data Processing Agreement and is available at [email protected].
6. International data transfers
Your information may be transferred to and processed in countries outside the UK or the EEA, principally because some model and infrastructure providers operate in the United States.
Where that happens, transfers are made under an appropriate safeguard: Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved, or under an adequacy decision where one applies. We apply supplementary technical measures where required, principally encryption in transit and at rest.
7. How long do we keep your information?
| Data | Retention |
|---|---|
| Account data | For the duration of your account, then 12 months after closure or deletion request |
| Billing and financial records | 6 years, as required by UK tax and company law |
| Marketing data | Until you opt out |
| Analytics data | 14 months, then anonymised or deleted |
| Uploaded content | Until you delete it or close your account |
| Agent workflow and audit logs | 12 months |
If you request account deletion, we remove your personal data within 30 days, except where we are legally required to retain it for longer. Backup copies expire on our standard backup cycle.
8. Personal data breaches
Where a personal data breach is likely to result in a risk to individuals' rights and freedoms, we notify the relevant supervisory authority within 72 hours of becoming aware of it, as required by Article 33 of the GDPR.
Where the breach is likely to result in a high risk to individuals, we also notify affected individuals without undue delay, as required by Article 34.
Where we act as processor for a client, we notify that client without undue delay so they can meet their own obligations.
9. How do we keep your information safe?
- Encryption of data at rest and in transit (TLS)
- Role-based access control and least-privilege internal access
- Logically separated client environments
- Workflow and node-level audit logging
- Monitoring and security review as the platform changes
- Established cloud infrastructure providers
Despite these safeguards, no method of electronic transmission or storage is completely secure. Full detail is on our Security & Permissions page.
10. What are your privacy rights?
If you are located in the UK or the EEA, you have the following rights:
- right of access
- right to rectification
- right to erasure
- right to restrict processing
- right to data portability
- right to object
- right to withdraw consent
To exercise any of these, contact [email protected]. We respond within one month, extendable by two further months for complex requests, in which case we will tell you.
You also have the right to lodge a complaint with a supervisory authority: the Information Commissioner's Office in the UK, or your national data protection authority in the EEA.
11. Controls for Do-Not-Track features
We do not currently respond to DNT browser signals. We will update this policy if that changes. See also our AI Policy and Cookie Policy.
12. Children's privacy
Our Services are not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. Account holders must be at least 18, as set out in our Terms of Service.
13. Updates to this Privacy Policy
We may update this Privacy Policy from time to time. The current version is always indicated by the "Last updated" date at the top of this page.
14. Contact us
Email: [email protected]
Attitude Group Ltd.
2 Alderney Court, Montague Street
Reading, England, RG1 4JW
United Kingdom
