Skip to content
Switching tools? We’ll help you move.See how
GrowthxAI Outreach

Privacy Policy

Last updated: 23 September 2026. Effective from the same date.

At ResourcePlan Solution Private Limited ("GrowthxAI", "we", "us" or "our"), protecting personal data is a priority. This policy explains what personal data we collect when you visit our website at growthxai.com, use GrowthxAI Outreach at app.growthxai.com (the "Platform"), use our API, Chrome extension or Claude connector, or contact us; why we collect it; who we share it with; how long we keep it; and the rights you have over it.

We process personal data in accordance with the laws that apply to us and to you, including Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the UK GDPR, India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), and applicable United States state privacy laws such as the California Consumer Privacy Act ("CCPA"), as applicable (together, the "Applicable Regulations").

1. Who is the data controller?

The data controller (and, under the DPDP Act, the data fiduciary) for the personal data described in this policy is ResourcePlan Solution Private Limited, an Indian private limited company (CIN U62013RJ2023PTC090277) with its registered office at 45-46, Shiv Marg, Guru Jhambeshwar Nagar A, Block E, Vaishali Nagar, Jaipur, Rajasthan 302021, India.

Privacy questions and requests: privacy@growthxai.com. Our grievance officer for the purposes of the DPDP Act can be reached at the same address; see section 12.

2. Two roles: our data and your workspace data

GrowthxAI Outreach is a tool that businesses use to run LinkedIn and email outreach. That means personal data flows through it in two different ways, and this policy only covers the first.

  • Data about you (we are the controller). Your account, billing, support, usage and website data, and the data of the people you invite to your workspace. This policy covers that data.
  • Data in your workspace (you are the controller, we are the processor). The leads you import or collect, the messages sent and received through your senders, and the session data and mailbox tokens of the accounts you connect ("Customer Data"). Our customer decides whose data goes in and why, so our customer is the controller. We process Customer Data only on the customer's instructions, under our Data Processing Agreement, and we do not use it for our own purposes.

If you received a message sent through GrowthxAI Outreach and want to know what data the sender holds on you, or want it deleted, or want them to stop, contact the sender first: they control that data. You can also email privacy@growthxai.com with the message you received and we will pass your request to the customer concerned and, where the law requires, take reasonable steps ourselves.

3. What personal data do we collect?

"Personal data" means any information that identifies an individual, directly or indirectly. Depending on how you interact with us, we may collect:

Data you give us

  • Account and identification data: full name, email address, password (stored hashed), workspace name, role, profile picture, time zone and language.
  • Professional data: company name, website, job title, company type, team size, the tool you currently use and your goals, when you tell us on a sign-up or demo form.
  • Third-party sign-in: if you sign in with Google or Microsoft, the name and email address that provider shares with us. We never receive your password for that provider.
  • Billing data: billing name, billing address, tax identifiers (for example GSTIN or VAT number), plan and invoice history. Card and bank details are collected and stored by our payment provider (Stripe); we see only the last four digits, card brand and expiry.
  • Connected-account data: the identity of each LinkedIn account and mailbox you connect (name, profile URL, email address), the proxy country you choose, and the encrypted session data or OAuth tokens needed to send on its behalf. Passwords for LinkedIn are never shared with us: the account owner logs in through a hosted page. Gmail and Outlook connect through OAuth. For other mailboxes, the IMAP/SMTP details you enter are stored encrypted.
  • Support and other communications: emails, chat messages, demo bookings, call notes and, where we tell you in advance, recordings of calls with our team.
  • Anything else you choose to give us, for example in a survey, a testimonial or a job application.

Data we collect automatically

  • Usage data: the features you use, sequences and actions you schedule, exports you run, and an audit log of changes made in your workspace (who did what, when).
  • Technical and log data: IP address, device and browser type, operating system, language, referring page, pages viewed, timestamps, error reports and request headers.
  • Cookies and similar technologies, as described in our Cookie Policy.

Data we receive from others

  • From your workspace Owner or Manager, when they invite you as a member or client viewer (name, email, role and client scope).
  • From our payment provider, such as payment success or failure and fraud signals.
  • From public or business sources, such as your company website or LinkedIn company page, to understand who our customers are and to keep our records accurate.

Where certain data are mandatory, we will tell you at the point of collection. Without them we may not be able to provide the Platform.

4. Why we use it, on what legal basis, and for how long

The table below summarises how we use your personal data, the legal basis we rely on under the GDPR and equivalent laws, and how long we keep it.

PurposeLegal basisRetention
Creating and managing your account and workspace, authenticating you, providing the Platform, API, extension and connectorPerformance of a contract (or steps at your request before one)Lifetime of the account, then the closure period in section 8
Connecting your LinkedIn accounts and mailboxes and sending and receiving on their behalfPerformance of a contractUntil the sender is disabled with "Purge stored secrets" or the workspace is deleted
Billing, invoicing, collecting payment and preventing payment fraudPerformance of a contract; legal obligationInvoices and transaction records for 8 years after the financial year, as Indian company and tax law requires
Answering support requests, demo requests and other messagesPerformance of a contract; legitimate interest in helping you3 years from the last contact
Sending service messages: re-login reminders, stalled-sequence alerts, payment notices, changes to termsPerformance of a contract; legal obligationLifetime of the account
Securing the Platform, detecting abuse and enforcing our Terms and Acceptable Use PolicyLegitimate interest in keeping the Platform and the people you contact safe; legal obligationLogs 12 months; audit log for the lifetime of the workspace; abuse records 3 years
Improving the Platform: understanding how features are used, fixing errors, developing new featuresLegitimate interest in improving our productUsage data 24 months, then aggregated or anonymised
Product news and marketing to customers and people who asked about the productConsent where required; otherwise legitimate interest in promoting our product, with an opt-out in every message3 years from the last contact, or until you opt out
Website analytics and cookie-based measurementConsent, where the law requires itUp to 25 months (see the Cookie Policy)
Keeping records of your consent and of your privacy requestsLegal obligation; legitimate interest in proving complianceProof of identity is deleted once verified; the request record is kept for 3 years
Complying with the law, responding to lawful requests, and establishing or defending legal claimsLegal obligation; legitimate interestAs long as the obligation or claim lasts

Where we rely on legitimate interests we have balanced them against your rights. You can object at any time (see section 10). Where we rely on consent, you can withdraw it at any time without affecting processing that took place before you withdrew.

We do not sell personal data and we do not share it for cross-context behavioural advertising, in the sense those terms are used in the CCPA. We do not use Customer Data to train general-purpose AI models.

5. Google and Microsoft user data

If you connect a Gmail mailbox, our use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Gmail data only to send the emails you schedule, to receive replies and show them in your inbox, and to keep each lead's timeline. We do not use it for advertising, we do not sell it, and humans at GrowthxAI read it only with your permission, for security, or where the law requires. The same limits apply to mailboxes connected through Microsoft. You can revoke access at any time from your Google or Microsoft account settings or by disabling the sender in the Platform. See our Disclosure for details.

6. Who we share personal data with

We share personal data only as needed, with:

  • Our staff and contractors, on a need-to-know basis and under confidentiality obligations.
  • Our service providers (processors), who act on our instructions: database and back-end hosting (Supabase), LinkedIn and mailbox connectivity, payments (Stripe), the Platform's own transactional email (Resend), AI processing with our key (Google Gemini), proxy providers for LinkedIn senders, website and application hosting, analytics, support and customer-relationship tools. The current list, with what each one does and the data involved, is on our Security & trust page.
  • Your own AI provider, only if you add your own Gemini, Anthropic or OpenAI key. That provider then processes your AI requests under your own agreement with them.
  • The platforms you connect, such as LinkedIn, Google and Microsoft, which receive the messages and actions you schedule.
  • Other members of your workspace, according to the roles and client scopes your Owner sets. Your name, email and activity in the workspace are visible to them as the Platform's permissions allow.
  • Professional advisers such as lawyers, accountants and auditors, under confidentiality.
  • Authorities and other parties where the law requires it, for example to comply with a court order, to protect our rights or the safety of any person, or to investigate fraud or abuse.
  • A buyer or successor, if we are involved in a merger, acquisition, financing or sale of assets. Your data would remain protected by this policy and we would tell you before it becomes subject to a different one.
  • Anyone else, with your consent.

7. International transfers

We are based in India, and our service providers process data in India, the United States, the European Union and other countries. Where personal data protected by the GDPR or UK GDPR is transferred outside the EEA or the United Kingdom, we rely on one of the following safeguards:

  • transfer to a country the European Commission or the UK government has found to provide adequate protection (GDPR Article 45);
  • the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary measures where needed (GDPR Article 46);
  • the EU-US Data Privacy Framework, for providers certified under it; or
  • another lawful derogation under GDPR Chapter V, where the above do not apply.

Where personal data protected by the DPDP Act is transferred outside India, we do so in line with that Act and any restrictions notified by the Indian government. Email us to ask for a copy of the safeguards we use.

8. How long we keep personal data

We keep personal data for as long as your account is active and as set out in section 4. When you close your workspace, or we terminate it:

  • the workspace stays readable for 30 days so you can export your data;
  • we then delete account data and Customer Data from our live systems within 90 days;
  • backup copies are removed in the ordinary course of backup rotation, within a further 35 days;
  • we keep invoices, payment records and records needed to establish or defend legal claims for as long as the law requires, and a minimal record of your closure request so we can prove we handled it.

Where we no longer need personal data in identifiable form, we may keep it in aggregated or anonymised form for statistics and product improvement. To ask for deletion before the periods above, see section 10.

9. How we protect personal data

We use technical and organisational measures appropriate to the risk, including HTTPS for the Platform and API, encryption of stored LinkedIn session data and mailbox credentials, hashed API keys, workspace and client isolation with row-level security, role-based access, an audit log of workspace changes, and access to production systems limited to staff who need it. Our providers hold their own certifications; we do not yet hold SOC 2 or ISO 27001. Details are on our Security & trust page.

No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to you, we will notify you and the relevant authority as the Applicable Regulations require. Report a suspected security issue to security@growthxai.com.

10. Your rights

Subject to the conditions and scope set out in the Applicable Regulations, you may exercise the following rights at any time:

  • Right to be informed about how your data is used, which this policy provides.
  • Right of access: a copy of the personal data we hold about you.
  • Right to rectification: correction of inaccurate or incomplete data. You can update most account data in the Platform yourself.
  • Right to erasure ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction of processing.
  • Right to object to processing based on legitimate interests, and at any time to direct marketing.
  • Right to data portability: your data in a structured, commonly used, machine-readable format. Owners and Managers can export leads, messages, actions and the audit log as CSV from the Platform.
  • Right to withdraw consent at any time, without affecting processing carried out before withdrawal.
  • Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions about you.
  • Right to nominate (under the DPDP Act) another person to exercise your rights if you die or become incapacitated.
  • Right to lodge a complaint with a supervisory authority: in India, the Data Protection Board of India; in the EU, the authority in the member state where you live or work; in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first.

California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information (we do not use it for purposes that require this right); and not to be discriminated against for exercising these rights. You may use an authorised agent to make a request.

How to make a request. Email privacy@growthxai.com from the address on your account, or write to us at the address in section 1. We may ask for information to verify your identity, which we delete once verified. We respond within 30 days (or sooner where the law requires) and will tell you if we need more time. Requests are free unless they are manifestly unfounded or excessive.

If you are not our customer but were contacted by one of our customers through the Platform, the customer is the controller of your data. We will forward your request to them and help them respond (see section 2).

11. Cookies, analytics and marketing choices

  • For details of the cookies and similar technologies we use on the website and in the Platform, and how to control them, see our Cookie Policy.
  • Every marketing email we send includes an unsubscribe link. Opting out of marketing does not stop service messages that are needed to run your account, such as re-login reminders, payment notices and changes to our terms.
  • Our website and Platform are not designed to respond to "Do Not Track" browser signals, but we honour Global Privacy Control signals where the law requires it.

12. Grievance officer (India)

In accordance with the DPDP Act and the Information Technology Act, 2000 and the rules made under them, the contact details of our grievance officer are:

Grievance Officer, ResourcePlan Solution Private Limited
45-46, Shiv Marg, Guru Jhambeshwar Nagar A, Block E, Vaishali Nagar, Jaipur, Rajasthan 302021, India
Email: privacy@growthxai.com

We aim to acknowledge grievances within 72 hours and resolve them within 30 days.

13. Children

The Platform is for businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email privacy@growthxai.com and we will delete it.

14. Third-party platforms and links

GrowthxAI Outreach is an independent product and is not affiliated with, endorsed by or sponsored by LinkedIn Corporation. LinkedIn, Google, Microsoft and the other platforms you connect have their own privacy policies, which govern how they handle your data; we encourage you to read them. Our website may link to other sites we do not control, and this policy does not apply to them.

15. Changes to this policy

We may update this policy to reflect changes in the law, in our providers or in the Platform. The new version applies from the "Last updated" date at the top. For significant changes we will notify workspace Owners by email or in the Platform before the change takes effect. Please check this page regularly.

16. Contact

Privacy questions and requests: privacy@growthxai.com
General support: hello@growthxai.com
Security: security@growthxai.com
Post: ResourcePlan Solution Private Limited, 45-46, Shiv Marg, Guru Jhambeshwar Nagar A, Block E, Vaishali Nagar, Jaipur, Rajasthan 302021, India

Your next customers are already on LinkedIn.

Start booking meetings this week. Free for 14 days with up to 3 LinkedIn accounts, no card.

14 days free · 3 LinkedIn accounts · no card

  • Cancel any time in the billing portal
  • Nothing deleted if a payment fails
  • Teammates are free