Privacy Policy
Last updated: 31 August 2026. This policy explains what data The Growth Fix collects, why, how it is stored and how you remove it. It covers this website and The Growth Fix application.
The Growth Fix is a trading name of Romualdo Pereira da Silva, operating as a sole trader in Dublin, Ireland. Questions about this policy, or to exercise any right described in it: romualdo@thegrowthfix.io.
Because we are established in Ireland, the EU General Data Protection Regulation applies. If you believe we have handled your data improperly you may complain to the Irish Data Protection Commission at dataprotection.ie, though we would ask you to contact us first. We have not appointed a data protection officer, and are not required to do so under Article 37 GDPR.
1. Who this applies to, and our role
Our clients are businesses. Our role under data protection law differs depending on whose data is involved, and the distinction matters:
- We are the controller for your own account information — the name, email address and organisation details you give us, and records of how you use the service. This policy governs that data.
- We are a processor for the marketing and enquiry data we access from analytics and advertising accounts you connect. That data remains yours; you stay the controller and determine why and how it is processed. We handle it only on your documented instructions, for the purposes of the engagement agreed with you, and your own privacy notice governs how you use it.
We do not build profiles of individual website visitors. We do not ask for or intentionally collect special categories of personal data. Please do not include sensitive personal information in free-text pilot-registration fields, booking notes or website enquiry messages. If it is provided unexpectedly, we will restrict access to it and delete or redact it promptly unless we are legally required to keep it.
One exception, stated plainly. When you connect a website, we fetch its public pages and store their HTML for up to 30 days (section 2). Those pages may contain other people's personal data — staff names, photographs, customer reviews, contact details you have published. For that information we are a controller, not a processor, and we have no relationship with the individuals concerned. We rely on legitimate interests (Article 6(1)(f)): our interest is in analysing a site's structure and contact routes in order to advise its owner. We consider this proportionate because the data is already published by you, we keep it for the shortest period that serves the purpose, we never use it to contact anyone, we never combine it with data from any other source, and we never sell or share it. If someone objects to us holding a page that mentions them, they can contact us at romualdo@thegrowthfix.io and we will delete it.
Our legal bases. Where we act as controller, we rely on the following bases under Article 6 GDPR:
- Performance of a contract (Article 6(1)(b)) — for your account identity and the operation of the service you have asked us to provide.
- Steps requested before a potential engagement (Article 6(1)(b)) — for the initial assessment of pilot-interest registrations and for Growth Diagnostic bookings, where you ask us to assess your interest, arrange a call or consider you for a potential engagement. We do not rely on this basis for general marketing.
- Legitimate interests (Article 6(1)(f)) — for operational and security records, including standard hosting logs, synchronisation logs and audit trails. Our interest is in serving and securing the website and application, keeping the service reliable, diagnosing failures and preventing unauthorised access. We also rely on legitimate interests for the limited retention of a pilot registration after the initial requested qualification step where the registration does not progress, so that we can consider the person for a later controlled-pilot stage. We consider these uses proportionate because the data is limited, access is restricted, retention is time-limited and you can object at any time (section 9).
- Consent (Article 6(1)(a)) — for website analytics, as described in section 7. You may withdraw consent at any time, without affecting processing carried out before withdrawal.
Where we act as processor, the legal basis for the underlying processing is determined by you as controller, not by us.
Automated decision-making. The service produces findings and recommendations about marketing performance. It does not carry out automated decision-making, including profiling, that produces legal effects concerning an individual or similarly significantly affects an individual within the meaning of Article 22 GDPR.
2. What we collect
- Pilot-interest registrations — if you register interest in the Marketing Priority AI controlled pilot, we collect your email address (always) and, if you complete the profile step, your role and — if you choose to provide them — your name, company, website, how many businesses or clients you manage, and anything you tell us about what you would like help deciding. Please do not include sensitive personal information in the free-text field. We use pilot-interest information to assess and qualify registrations, contact people about a possible pilot invitation, administer pilot participation and communicate material changes to the pilot they registered for. We do not add pilot registrants to a general marketing list unless they separately opt in.
- Booking a call — when you book a Growth Diagnostic, we receive the details you enter into the scheduler, including your name, email address, selected time and anything you add to the booking notes. We use this information to arrange and hold the call and to correspond with you about it. Please do not include sensitive personal information in the booking notes.
- Account identity — name, email address and organisation membership, provided at sign-up, used to authenticate you and scope access to your own organisation's data.
- Google Analytics 4 data — sessions, conversions, revenue and traffic by channel, device and landing page, at daily granularity. Read-only, via the Google Analytics Data API, after you authorise it.
- Meta advertising data — campaigns, ad sets, ads, spend and performance metrics. Read-only, via the Meta Marketing API, after you authorise it.
- Google Search Console data — the search queries your site appeared for, with impressions, clicks, average position, country and device, at daily granularity. Read-only, via the Search Console API, after you authorise it. Google aggregates and anonymises this data before we receive it; individual searchers are not identifiable to us.
- Your website's own pages — we fetch the public pages of the website you connect and store their HTML for up to 30 days, so that a finding about a page can be re-checked without fetching it again. Our crawler identifies itself as
MarketingPriorityAIand obeys yourrobots.txt; any page you disallow there is never fetched. We do not crawl anyone else's website, and we do not log in, submit forms or access anything behind a password. More about our crawler. - Connection credentials — OAuth tokens for the accounts you connect, used to retrieve your data.
- Operational records — synchronisation runs, their outcomes, and an audit trail of connection changes, so you can see when data last updated and we can diagnose failures.
- Website enquiry data — where you choose to send us enquiries captured by forms on your own website, we store the source of the enquiry, any product or service referenced, and a summary of the customer's message. We do not require or ask for the customer's name, email address or telephone number, and there are no fields for them. The message summary is free text written by your customer, so it may contain personal data they chose to include; you remain the controller of it and you are responsible for telling your own customers that it is shared with us.
- Website usage — if you consent, analytics about how this website is used. See section 7.
- Standard hosting logs — like other website hosts, Netlify records technical request data such as IP address, browser user agent, requested page and request time to deliver and secure the site, diagnose faults and prevent abuse. We rely on legitimate interests (Article 6(1)(f)) for this processing. Netlify applies its operational retention periods under its service terms and data processing agreement; The Growth Fix does not use raw access logs for advertising or to build visitor profiles.
3. Google user data — specific disclosures
Marketing Priority AI, the application described in this policy, requests two Google scopes, both read-only:
analytics.readonly— reads your Google Analytics 4 reporting data. The service cannot create, modify or delete anything in your Analytics account.webmasters.readonly— reads your Google Search Console performance data: clicks, impressions, average position, and the queries and pages they relate to. The service cannot submit sitemaps, request indexing, or change anything in your Search Console property.
Both are used only to produce the findings and recommendations described in section 1. Neither is used for advertising or to train models.
The Growth Fix's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Data obtained from Google APIs is:
- used only to provide or improve user-facing features that are prominent in the requesting application's user interface;
- never sold, and never transferred to third parties except as sub-processors necessary to operate the service (section 6), where legally compelled, or as part of a merger, acquisition or sale of assets — and in that last case only after giving you notice and obtaining your explicit prior consent;
- never used for advertising, ad targeting or building advertising profiles;
- never used to train generalised artificial intelligence or machine learning models;
- never read by humans, except where you explicitly ask us to for support, where it is necessary to investigate a fault or a security concern, where required to comply with applicable law, or where the data has been aggregated and anonymised. Where we access your data to investigate a fault, we record that access.
Google user data is retained and deleted as described in section 5. Disconnecting a source deletes the stored credential for that connection immediately.
4. How your data is protected
- Credentials are encrypted at rest. OAuth tokens are encrypted with AES-256-GCM under a key held separately from the database. They are never returned by our API, never rendered in the interface and never written to logs.
- Tenant isolation is enforced at the database. Every record carries the organisation that owns it, and row-level security prevents one organisation's data being read through another's session — independently of application code.
- Access is per-user and verified. Every request resolves a verified identity and an active organisation membership before any data is returned.
5. How long we keep it
Marketing data is retained while your account is active, because historical comparison is what makes change detectable. You can disconnect any source at any time; doing so deletes the stored credential for that connection immediately and stops all further collection from it. On account closure, your organisation's data is deleted within 30 days; that deletion is carried out by us on request or on closure, and is not currently an automated process. Account identity and operational records are kept for as long as your account is open and for up to 12 months afterwards, so we can resolve any billing or security question that arises after closure, and are then deleted.
Pilot-interest registrations are reviewed monthly and deleted once 12 months have passed since registration or our last meaningful contact about the pilot, whichever is later, unless the person joins the pilot or becomes a client and the relevant information becomes part of the applicable participant or client record. This means deletion normally occurs during the first monthly review after the 12-month period ends. “Last meaningful contact” means a reply or other substantive interaction from the person about the pilot, or a communication needed to administer participation; an outbound message from The Growth Fix that receives no response does not restart the period. After the initial requested qualification step, limited retention of a registration that does not progress is based on our legitimate interests (Article 6(1)(f)), as explained in section 1. We delete the original Netlify Forms submission and relevant working copies when they are no longer required, and earlier on request unless a legal obligation requires otherwise.
Booking enquiries are reviewed monthly and deleted once 12 months have passed since the booking or our last meaningful contact about the enquiry, whichever is later. This means deletion normally occurs during the first monthly review after the 12-month period ends. Here, “last meaningful contact” means a reply or other substantive interaction from the person about the enquiry, or a communication needed to administer an agreed booking; an outbound message from The Growth Fix that receives no response does not restart the period. If the person becomes a client, relevant information may become part of the client record and follow the retention period applicable to that engagement. We delete booking information and relevant working copies earlier on request unless a legal obligation requires otherwise.
Crawled page content is deleted after 30 days, automatically, whether or not your account is still active. What remains after that is the structural summary we derived — page titles, headings, whether a page is indexable, which contact routes it offers — not the page itself.
6. Sub-processors
Sub-processors of client data — these process data belonging to your organisation, where we act as your processor:
- Supabase — database and authentication. Data hosted in Ireland (AWS
eu-west-1). Supabase Inc. is US-headquartered; see section 8. - Netlify — application hosting. Functions run in Ireland (AWS
eu-west-1). Netlify Inc. is US-headquartered; see section 8. - Amazon Web Services — the underlying infrastructure on which both of the above run, in the
eu-west-1(Ireland) region.
Tools we use on this website — these do not process your organisation's data, and we are the controller for them:
- Cookiebot (Usercentrics) — cookie consent management.
- Google Analytics — website usage analytics, subject to your consent. See section 7.
- Netlify Forms — stores pilot-interest registrations submitted on this website, as our processor/service provider. Netlify screens all form submissions for spam using Akismet, operated by Automattic Inc. Netlify Inc. and Automattic Inc. are US-headquartered; see section 8.
- Calendly — scheduling. The booking calendar loads only when you explicitly request it. Calendly processes the booking details you provide on our behalf under its data processing terms. Within the embedded booking experience, Calendly and the infrastructure and security providers needed to display and protect the scheduler also process technical data and set cookies. For cookie and similar technical data collected through the embedded service, Calendly’s data processing terms describe Calendly and The Growth Fix as separate independent controllers. See Calendly’s privacy notice, data processing addendum and current subprocessor list.
This list is complete, as at the date above, for the sub-processors of client data and the tools The Growth Fix operates itself; the embedded Calendly booking service and its providers are disclosed above and in Calendly’s own notices. We will update it, and notify affected clients, before engaging any new sub-processor that processes your data — including any provider of artificial intelligence or language-model services. Where such a provider is engaged, we will contract on terms that prohibit it from training its models on your data, consistent with section 3.
7. Cookies and this website
This website uses a consent banner provided by Cookiebot. Analytics is disabled unless you give Statistics consent. Advertising storage, ad-user-data and ad-personalisation signals remain denied in every consent state — The Growth Fix does not enable advertising tracking. You can change or withdraw your choice at any time through the Cookie settings link in the footer of every page, or through the cookie banner. Essential cookies required for security and basic functionality are always active. Cookie information detected by Cookiebot, including purpose and duration where available, is published below. The embedded Calendly service and its providers are also described in sections 2 and 6 and in Calendly’s own notices.
8. Where your data is held
Client marketing data and your account data are stored and processed in the European Union. Our database is hosted in Ireland (AWS eu-west-1) and the application that reads and writes it runs in the same region; we have verified the region on the running application, not only in its configuration.
Calendly LLC is established in the United States. Calendly’s current data processing addendum states that applicable EEA transfers rely on its EU–US Data Privacy Framework certification, with the relevant Standard Contractual Clauses applying as a fallback if that framework is unavailable.
Our hosting and database providers are US-headquartered companies whose personnel may access data for support and infrastructure purposes. Those transfers are governed by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Website analytics data described in section 7 is processed by Google and may be transferred to the United States on the same basis, where you have consented.
You may contact us at romualdo@thegrowthfix.io to request further information about the transfer safeguards that apply to your personal data, including how to obtain a copy of the relevant safeguards where available.
9. Your choices
- Disconnect a source at any time from within the application.
- Revoke access directly at Google account permissions or in Meta Business Settings. Revoking at the provider stops collection immediately.
- Request access, correction, export or deletion of your data by contacting us.
- Object to processing carried out on the basis of our legitimate interests (section 1), and request that processing be restricted while an objection or a correction request is being considered.
- Withdraw consent at any time where processing relies on it, without affecting processing carried out before withdrawal.
- Complain to the Irish Data Protection Commission, as set out at the top of this policy.
We respond to any of these within one month. Where a request is complex or you have made several, we may extend that by up to two further months, and will tell you within the first month if we do.
10. Changes
We will update this page when our practices change and revise the date above. Material changes affecting how your data is used will be notified directly.