Privacy Policy
Effective 23 July 2026.
Who we are
Growth Path Agency S.R.L. ("Growth Path", "we", "us") is the controller of personal data processed through this website, growthpath.systems.
Legal name: Growth Path Agency S.R.L.
Registered office: Str. Drumul Putnei nr. 38-42, Et. 4, Ap. 33, Sector 3, Bucureşti, Romania.
Trade Registry No.: J2025042918007 (Oficiul Registrului Comerţului de pe lângă Tribunalul Bucureşti).
Unique Registration Code (CUI): RO51980049 (VAT-registered).
EUID: ROONRC.J2025042918007.
Share capital: 1,000 RON (fully paid).
Privacy contact: [email protected].
We have not appointed a Data Protection Officer. Our processing does not meet the thresholds in Art. 37 GDPR or in Law 190/2018. For any request under this policy, email the privacy contact above.
What this policy covers
This policy explains how we collect, use, and protect personal data when you visit growthpath.systems or interact with us through the site.
It does not cover third-party sites we link to, offline conversations and introductions, or services we deliver to clients under a signed engagement. Those engagements are governed by the separate data-processing terms in the relevant Master Services Agreement.
What we collect
We keep the data we collect as small as possible. Four categories.
Server and hosting logs. Our hosting and delivery provider (Cloudflare) records technical metadata when you load a page: IP address, user-agent string, timestamps, and response status. These logs help us investigate errors and detect abuse.
Aggregate site analytics. We use Plausible Analytics to count page views and understand which content works. Plausible does not set cookies and does not store personal identifiers. It generates a daily-rotating, salted hash of IP plus user-agent to count unique visitors, and discards the hash every 24 hours. You cannot be identified or tracked across sites.
Waitlist, audit, and email submissions. If you join the Scout waitlist, we collect the email address you submit and the source tag of the form. If you request a Deep Audit, we collect the name, email, company, company website, and prompt you submit so we can confirm scope and reply. We store the contact details through Loops, our email platform. We add you to Growth Path AI marketing emails only when you tick the marketing consent checkbox.
Direct communication. If you email us, reply to one of our emails, or click "Book a call" and reach us at [email protected], we process the email address, the content of the message, any attachments, and (when a meeting is scheduled) the calendar metadata.
We do not process special-category data (health, biometric, political opinion, religion), we do not collect the Romanian CNP (Cod Numeric Personal), and we do not target children. This is a B2B site.
Why we collect it and legal basis
We process each category of data under one of the lawful bases in GDPR Art. 6.
Server logs run on Art. 6(1)(f) — our legitimate interest in operating a secure, functional website.
Plausible aggregates run on Art. 6(1)(f) — our legitimate interest in understanding which content helps readers. No tracking, no profiling, no cross-site identifiers.
Your waitlist and marketing email consent runs on Art. 6(1)(a) — the consent you give when you submit the form or tick the marketing consent checkbox. You can withdraw that consent at any time from any email we send you or by emailing [email protected].
Deep Audit requests, direct communication, and meeting bookings run on Art. 6(1)(b) where we are taking steps toward a possible engagement, and on Art. 6(1)(f) where we are replying to B2B inbound without a contract in view.
Processors and recipients
We share personal data with a small list of processors that help us run the site and communicate with you.
Cloudflare, Inc.: website hosting, DNS, DDoS protection, and Turnstile spam protection on forms. Primary edge in EU regions. DPA · subprocessors.
Plausible Insights OÜ: privacy-friendly, cookieless analytics. Hosted in Germany. Aggregates only; no personal identifiers stored. Privacy policy · data policy.
Loops (Astrodon Corp.): transactional email, Scout waitlist email, Deep Audit request notifications, and checkbox-based marketing email. US-based. DPA.
Google (Calendar / Meet): scheduling and video for booked calls. In scope only when you book a meeting with us.
We may also disclose personal data when required by law, court order, or regulator request, or where necessary to protect our rights, investigate fraud, or respond to emergencies threatening life or physical safety.
Google Search Console data
If you connect Google Search Console, we request read-only access to the Search Console properties you choose to share (the read-only Search Console permission Google calls webmasters.readonly). We only read data for domains you have already verified with Google; we never request write access.
We use this data to show your own site's Search Console performance back to you, inside your own dashboard on this site. We do not use it to train models, and we do not share it with any third party.
Search Console data is stored encrypted at rest, in our EU-region database.
You can disconnect Google Search Console at any time from your account settings. Disconnecting deletes the stored access tokens immediately, and we stop reading new data from that point on.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
International transfers
Loops is a US company. Sending your email to Loops is a transfer of personal data to a third country under Chapter V GDPR. We rely on the Standard Contractual Clauses (Module 2) contained in Loops' Data Processing Agreement, plus the supplementary measures they document (encryption in transit and at rest, access controls, subprocessor governance).
Cloudflare and Plausible serve traffic primarily from EU/EEA regions. Where any operational workload touches a non-EU Cloudflare point-of-presence, the same SCCs apply.
Google (for Calendar and Meet) also relies on Standard Contractual Clauses for EU-to-US transfers.
You can request a copy of the relevant transfer safeguards by emailing [email protected].
How long we keep data
We keep personal data only as long as we need it for the purpose we collected it, plus any period Romanian law requires.
Server logs are retained for up to 30 days.
Plausible aggregates are retained indefinitely; they contain no personal identifiers.
Waitlist email is retained until you unsubscribe, or 24 months after your last engagement with our emails, whichever comes first.
Direct communication and meeting records are retained for up to 36 months after the last exchange. Invoice-related data is retained for the period required by Romanian accounting law (Legea contabilităţii nr. 82/1991), currently 10 years.
Your rights
Under GDPR Arts. 15-22, you have the following rights against us.
Access: you can ask us to confirm what data we hold about you and to receive a copy.
Rectification: you can ask us to correct inaccurate or incomplete data.
Erasure: you can ask us to delete your data (the "right to be forgotten"), subject to any legal retention duties that override it (for example, Romanian fiscal law may require us to keep invoice records for 10 years).
Restriction: you can ask us to pause processing in certain circumstances, such as while we verify a correction request.
Objection: you can object to processing based on our legitimate interests. We will stop unless we demonstrate compelling grounds that override your interests.
Portability: where we process your data under consent or contract, you can receive it in a common machine-readable format.
Withdraw consent: at any time, without affecting the lawfulness of processing carried out before you withdrew.
Automated decisions: you have the right not to be subject to decisions based solely on automated processing that have legal or similarly significant effects. We do not make such decisions.
To exercise any right, email [email protected]. We respond within 30 days, per GDPR Art. 12(3). If your request is complex, we may extend by up to two further months and will tell you within the first 30 days.
Security
We protect personal data with:
Encryption in transit: HTTPS across the whole site, TLS 1.2 or higher.
Least-privilege access: processor consoles are access-controlled and multi-factor-authenticated, and only the people who need a given console have one.
Written Data Processing Agreements with every processor listed above.
A written incident-response procedure. If a personal data breach occurs that is likely to result in risk to individuals, we notify ANSPDCP within 72 hours and the affected data subjects without undue delay, per Arts. 33 and 34 GDPR.
Children
This site is directed at business professionals and not at children.
We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data to us, email [email protected] and we will delete it.
Complaints
You can file a complaint with the Romanian supervisory authority at any time.
Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucureşti, Romania.
Telephone: +40 318 059 211 · +40 318 059 212.
Email: [email protected].
Web: dataprotection.ro.
If you live or work in another EU member state, you can also lodge a complaint with the supervisory authority in that country.
Before filing a complaint, you are welcome — but not required — to contact us first at [email protected] so we can try to resolve the issue directly.
Changes to this policy
We update this policy as our processing changes or as law changes.
Material changes are flagged at the top of the page for a reasonable period. The effective date below always reflects the most recent version.
Effective date: 23 July 2026. This update added the Google Search Console data section above.