Growth-Pilot.ai Privacy Policy

Last updated: August 2026

Growth Pilot AI Limited (company number 17134407), registered at Waterdells, Pottersheath Road, Welwyn, England, AL6 9TA ("Growth Pilot", "we", "us"), provides growth-marketing and lead-generation services powered by CRM, data enrichment and AI tools. This policy explains how we handle personal data. Contact: [email protected].

1. When we are a controller and when we are a processor

Our role under data protection law depends on the data in question:

  • Where we are the controller: we determine how and why personal data is used in relation to our own customers and account users, visitors to our website, prospective customers of Growth Pilot, and our personnel. This policy governs that data.

  • Where we are a processor: when we deliver services to a client (running campaigns, sourcing and enriching prospect and lead data, and administering a CRM on the client’s behalf), we act as a data processor on that client’s documented instructions. The client is the data controller of that data, and our processing is governed by our Data Processing Agreement (DPA) with the client.

If you have been contacted as part of a client’s campaign, or your details have been processed for one of our clients, the relevant controller is our client, and you should refer to that client’s privacy notice. If you contact us, we will forward your request to the relevant client and, where we hold your data as processor, act on their instructions, including adding you to our suppression list so that you are not contacted again.

2. Personal data we collect (as controller)

  • Data you provide: name, company, job title, email address, account credentials, and payment information.

  • Usage and technical data: IP address, device and browser type, and activity on our website and platform.

  • Data from third parties: information from the integrations and service providers we use to operate and improve our own services.

CRM and outreach data uploaded into the platform, and prospect data we source for a client, are handled by us as a processor on the client’s behalf (see section 1) and are not covered by this section.

3. How we use personal data, and our lawful bases (as controller)

  • To provide, operate and secure our platform and website: performance of a contract.

  • To communicate with you about your account and services, and to carry out our own business-to-business marketing: legitimate interests (and consent where required).

  • To take payment and keep financial records: performance of a contract and legal obligation.

  • To comply with legal obligations: legal obligation.

Where we rely on legitimate interests, we balance those interests against your rights and keep a record of that assessment.

4. AI and your data

We use AI tools to deliver our services. We do not use your data to train public AI models. You are responsible for ensuring you have the right to upload any third-party personal data into the platform.

5. Sharing your data

We share personal data with trusted service providers who help us run our business (including hosting, analytics and CRM infrastructure), with payment processors, and with authorities where required by law. We require these providers to protect personal data and to use it only for the purposes we specify. We do not sell personal data.

Our own team and personnel, including staff and contractors located outside the UK who support client onboarding, setup and account management, may access personal data to deliver and support the services. They act under confidentiality obligations and may use personal data only to provide the services.

6. Sub-processors (services provided to clients)

Where we act as a processor for a client, we engage sub-processors within categories including cloud hosting and infrastructure, analytics, customer relationship management (CRM), outreach and messaging automation, data-research and enrichment, and artificial-intelligence (AI) tools. A current list is available to clients on request and is governed by the DPA.

7. International transfers

Some of our personnel and service providers are located outside the United Kingdom. Where personal data is transferred to, or accessed from, a country outside the UK, we put in place appropriate safeguards, such as reliance on UK adequacy regulations, the ICO’s International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with any additional measures required. We can provide details of the countries concerned and the safeguards in place on request.

8. Retention

We keep personal data for which we are the controller only for as long as necessary for the purpose for which it was collected. Our own business and financial records are typically kept for up to six years to meet legal and accounting obligations. Personal data we process on behalf of a client is retained in accordance with that client’s instructions and our DPA, and is deleted or returned at the end of the engagement.

9. Your rights

You have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. You may object to direct marketing at any time. To exercise any right, or to unsubscribe from our own marketing, contact [email protected]. If your data was processed as part of a client’s campaign, we will forward your request to the relevant client (the controller) and act on their instructions as processor, including suppressing you from further contact. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

10. Cookies

We use strictly necessary cookies to run our website and optional analytics cookies to understand usage. You can manage cookies through your browser settings and our cookie settings.

11. Changes and contact

We may update this policy from time to time. For any question about this policy or your personal data, contact Growth Pilot AI Limited at [email protected].