Privacy Policy
Effective 3 September 2026.
Who we are
Growth Path Agency S.R.L. ("GrowthPath", "we", "us") is the controller of personal data processed through this website, growthpath.systems.
Legal name: Growth Path Agency S.R.L.
Registered office: Str. Drumul Putnei nr. 38-42, Et. 4, Ap. 33, Sector 3, Bucureşti, Romania.
Trade Registry No.: J2025042918007 (Oficiul Registrului Comerţului de pe lângă Tribunalul Bucureşti).
Unique Registration Code (CUI): RO51980049 (VAT-registered).
EUID: ROONRC.J2025042918007.
Share capital: 1,000 RON (fully paid).
Privacy contact: privacy@growthpath.systems.
We have not appointed a Data Protection Officer. Our processing does not meet the thresholds in Art. 37 GDPR or in Law 190/2018. For any request under this policy, email the privacy contact above.
What this policy covers
This policy explains how we collect, use, and protect personal data when you visit growthpath.systems or interact with us through the site.
It does not cover third-party sites we link to, offline conversations and introductions, or services we deliver to clients under a signed engagement. Those engagements are governed by the separate data-processing terms in the relevant Master Services Agreement.
What we collect
We keep the data we collect as small as possible. Three categories.
Server and hosting logs. Our hosting and delivery provider records technical metadata when you load a page: IP address, user-agent string, timestamps, and response status. These logs help us investigate errors and detect abuse.
Aggregate site analytics. We use Umami, which we host ourselves on our own hardware, to count page views and understand which content works. It sets no cookies and stores nothing on your device. It counts unique visitors with a salted hash of IP plus user-agent; the salt rotates monthly, and the hash is specific to this site, so you cannot be tracked anywhere else. Because we host it, no third party receives this data.
Direct communication. If you email us, reply to one of our emails, or click "Book a call" and reach us at hello@growthpath.systems, we process the email address, the content of the message, any attachments, and (when a meeting is scheduled) the calendar metadata.
We do not process special-category data (health, biometric, political opinion, religion), we do not collect the Romanian CNP (Cod Numeric Personal), and we do not target children. This is a B2B site.
Why we collect it and legal basis
We process each category of data under one of the lawful bases in GDPR Art. 6.
Server logs run on Art. 6(1)(f) — our legitimate interest in operating a secure, functional website.
Analytics aggregates run on Art. 6(1)(f) — our legitimate interest in understanding which content helps readers. No tracking, no profiling, no cross-site identifiers, and no third-party processor.
Direct communication and meeting bookings run on Art. 6(1)(b) where we are taking steps toward a possible engagement, and on Art. 6(1)(f) where we are replying to B2B inbound without a contract in view.
Deep Audit requests submitted before 7 August 2026 run on those same two bases. The form is retired and collects nothing now, but the records it created (name, email, company, company website, and the prompt submitted) are still held, so the basis for holding them is stated here rather than retired with the form. Where the sender also ticked the marketing consent checkbox, that marketing email runs on Art. 6(1)(a) like any other, and you can withdraw it the same way.
Processors and recipients
We share personal data with a small list of processors that help us run the site and communicate with you.
Vercel Inc.: website hosting and delivery through EU-region serverless infrastructure. DPA · privacy notice.
Cloudflare, Inc.: authoritative DNS and associated network security services. DPA · subprocessors.
Loops (Astrodon Corp.): temporary storage for historical waitlist and marketing-contact records collected before 3 September 2026, pending their suppression-safe migration. The site sends no new data to Loops. US-based. DPA.
Railway Corporation: backend application and database hosting in Amsterdam, Netherlands.
Google: Google services for booked calls and, if you connect it, the Search Console access described below. In scope only when you book a meeting with us or connect Search Console.
We may also disclose personal data when required by law, court order, or regulator request, or where necessary to protect our rights, investigate fraud, or respond to emergencies threatening life or physical safety.
Google Search Console data
If you connect your Google Search Console account to GrowthPath AI, we request read-only access to your Search Console data via Google's official API, limited to the read-only permission Google calls webmasters.readonly.
What we access. Search performance data for the Search Console properties you own and choose to connect: queries, clicks, impressions, average position, and indexed-page information. We never see your Google password, and we cannot modify anything in your Google account or Search Console.
What we use it for. This data appears in your GrowthPath AI dashboard and feeds the visibility analyses you request: connecting how AI assistants cite your site with how it performs in search. We do not use it for advertising, we do not sell it, we do not use it to train models, and we do not share it with third parties beyond the processors described in this policy, under the same safeguards as all other account data.
Storage and security. OAuth tokens are stored encrypted. Search Console data we retain is stored encrypted at rest in our EU-hosted database (Railway) and covered by the retention terms of this policy.
Revoking access. You can disconnect Search Console at any time in your account settings: we delete the stored tokens immediately and stop reading your data from that point on. You can also revoke GrowthPath AI's access directly at myaccount.google.com/permissions. On account deletion, connected-service tokens and imported Search Console data are removed with the rest of your data.
Limited Use. GrowthPath AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
International transfers
Historical contact data still held by Loops is a transfer to a US company under GDPR Chapter V. We rely on the Standard Contractual Clauses (Module 2) in its Data Processing Agreement until that migration completes.
Our hosting and analytics providers serve traffic primarily from EU/EEA regions. Where any operational workload touches a non-EU point-of-presence, the same SCCs apply.
Google also relies on Standard Contractual Clauses for EU-to-US transfers.
You can request a copy of the relevant transfer safeguards by emailing privacy@growthpath.systems.
How long we keep data
We keep personal data only as long as we need it for the purpose we collected it, plus any period Romanian law requires.
Server logs are retained for up to 30 days.
Analytics data is deleted after 24 months.
Historical waitlist and marketing contacts are retained until you unsubscribe, or 24 months after your last engagement with our emails, whichever comes first. They are being moved out of Loops without changing that period.
Direct communication and meeting records are retained for up to 36 months after the last exchange. Invoice-related data is retained for the period required by Romanian accounting law (Legea contabilităţii nr. 82/1991), currently 10 years.
Deep Audit requests submitted before 7 August 2026 are retained as direct communication, on the same 36-month window: they were inbound enquiries and we hold them as we hold any other. Where the sender also joined marketing email, that marketing contact is retained until they unsubscribe, or 24 months after their last engagement with our emails, whichever comes first. You can ask us to delete either at any time, at privacy@growthpath.systems.
Your rights
Under GDPR Arts. 15-22, you have the following rights against us.
Access: you can ask us to confirm what data we hold about you and to receive a copy.
Rectification: you can ask us to correct inaccurate or incomplete data.
Erasure: you can ask us to delete your data (the "right to be forgotten"), subject to any legal retention duties that override it (for example, Romanian fiscal law may require us to keep invoice records for 10 years).
Restriction: you can ask us to pause processing in certain circumstances, such as while we verify a correction request.
Objection: you can object to processing based on our legitimate interests. We will stop unless we demonstrate compelling grounds that override your interests.
Portability: where we process your data under consent or contract, you can receive it in a common machine-readable format.
Withdraw consent: at any time, without affecting the lawfulness of processing carried out before you withdrew.
Automated decisions: you have the right not to be subject to decisions based solely on automated processing that have legal or similarly significant effects. We do not make such decisions.
To exercise any right, email privacy@growthpath.systems. We respond within 30 days, per GDPR Art. 12(3). If your request is complex, we may extend by up to two further months and will tell you within the first 30 days.
Security
We protect personal data with:
Encryption in transit: HTTPS across the whole site, TLS 1.2 or higher.
Least-privilege access: processor consoles are access-controlled and multi-factor-authenticated, and only the people who need a given console have one.
Written Data Processing Agreements with every processor listed above.
A written incident-response procedure. If a personal data breach occurs that is likely to result in risk to individuals, we notify ANSPDCP within 72 hours and the affected data subjects without undue delay, per Arts. 33 and 34 GDPR.
Children
This site is directed at business professionals and not at children.
We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data to us, email privacy@growthpath.systems and we will delete it.
Complaints
You can file a complaint with the Romanian supervisory authority at any time.
Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucureşti, Romania.
Telephone: +40 318 059 211 · +40 318 059 212.
Email: anspdcp@dataprotection.ro.
Web: dataprotection.ro.
If you live or work in another EU member state, you can also lodge a complaint with the supervisory authority in that country.
Before filing a complaint, you are welcome — but not required — to contact us first at privacy@growthpath.systems so we can try to resolve the issue directly.
Changes to this policy
We update this policy as our processing changes or as law changes.
Material changes are flagged at the top of the page for a reasonable period. The effective date below always reflects the most recent version.
Effective date: 3 September 2026. This policy reflects that growthpath.systems no longer hosts an email or waitlist form. The AI Visibility Loop waitlist now lives on heralded.ai.