GrowthProof
Data Processing Addendum
This Data Processing Addendum is incorporated into the agreement between the GrowthProof customer and Shawal Kabir Chy, trading as GrowthProof and applies when GrowthProof processes customer personal data on the customer's behalf.
Effective and last updated: July 31, 2026
Roles
- The customer is the controller or business responsible for deciding what client data is uploaded and shared.
- GrowthProof acts as a processor or service provider for tenant data handled through the product.
- Where the customer processes personal data for its own client, the customer may be a processor and GrowthProof its subprocessor. Each party remains responsible for determining its role under applicable law.
- GrowthProof may act as an independent controller or business for account administration, security, billing metadata, legal compliance, and its own business records as described in the Privacy Policy.
Processing scope
- Processing is limited to providing the application, storing evidence, generating reports, sending requested product emails, providing support, and maintaining security records.
- Customers must not upload passwords, private keys, payment-card data, malware, unnecessary personal data, or regulated or sensitive data that GrowthProof has not agreed in writing to process.
- Client viewers only receive access to reports and evidence intentionally shared by authorized tenant users.
- Processing continues for the subscription term and any documented retention or deletion period. Data subjects may include customer personnel, MSP clients, client viewers, and individuals referenced in uploaded evidence.
- Data may include identifiers, business contact information, account and role data, client-system information, audit events, notes, links, reports, and files selected by the customer.
Processor obligations
- GrowthProof processes customer personal data only on documented instructions, including instructions expressed through normal use of the service, unless processing is required by law. Where legally permitted, GrowthProof will inform the customer of that requirement before processing.
- Personnel authorized to process customer data are subject to confidentiality obligations and access is limited according to role and operational need.
- GrowthProof maintains appropriate technical and organizational safeguards, including authenticated access, tenant-scoped authorization, private storage, controlled file URLs, audit logging, and encryption in transit.
- GrowthProof will reasonably assist the customer with data-subject requests, security obligations, impact assessments, and regulator consultations, taking into account the nature of processing and information available.
- GrowthProof will notify the customer if, in its reasonable view, a customer instruction infringes applicable data-protection law, unless prohibited from doing so.
Security incidents
- GrowthProof will notify affected customers without undue delay after becoming aware of a personal-data breach involving their customer data, where notification is required by applicable data-protection law.
- Notice will include available information about the nature of the incident, likely consequences, affected data, mitigation, and a contact for follow-up. Information may be provided in phases as the investigation progresses.
- Customer notification does not constitute an admission of fault or liability. Customers remain responsible for notifications they must make to their clients, individuals, or regulators.
Subprocessors and transfers
- The customer gives general written authorization for GrowthProof to use service providers that process customer personal data. Current providers may include Supabase, Vercel, Cloudflare, Resend, Sentry, PostHog, and Google for the functions described in the Privacy Policy, to the extent each provider processes customer personal data.
- Loops processes marketing waitlist contacts outside tenant workspaces. Lemon Squeezy acts as merchant of record for payment activities rather than as GrowthProof's subprocessor for those independent activities.
- GrowthProof will require subprocessors to protect personal data through written terms appropriate to their processing and remains responsible for its processor obligations to the extent required by law.
- Material subprocessor changes will be communicated through the service, policy update, or account contact where required. Customers with a reasonable data-protection objection should contact GrowthProof promptly.
- Where personal data is transferred internationally, the parties must rely on an applicable legal transfer mechanism, which may include an adequacy decision, approved standard contractual clauses, or another valid safeguard.
- Where completed transfer annexes, the EU Standard Contractual Clauses, or a UK transfer agreement or addendum are required, those terms apply only when validly incorporated or executed; this online Addendum does not itself complete customer-specific transfer details.
Deletion, return, and audits
- Cancellation alone does not request deletion. Account owners may request export or deletion through Settings or support, and a deletion request starts a 30-day read-only grace period before tenant-scoped data is queued for deletion.
- Minimal billing, webhook, and audit records may be retained where needed for accounting, fraud prevention, security, or legal defense.
- On termination and written request, GrowthProof will delete or return customer personal data unless retention is required by law. Backup or provider-managed copies may remain until ordinary deletion cycles complete and remain protected during that period.
- GrowthProof will provide information reasonably necessary to demonstrate compliance. Where that information is insufficient, the customer may request a proportionate audit no more than once annually, subject to confidentiality, security, scope, and cost controls.
Customer obligations and order of precedence
- The customer must provide lawful instructions, configure access appropriately, respond to data-subject requests, and ensure it has authority to upload, use, and disclose all customer data.
- The customer must not use GrowthProof for categories of regulated or sensitive data that require safeguards not expressly supported by the service without a separate written agreement.
- If this Addendum conflicts with the general Terms on personal-data processing, this Addendum controls. Any signed enterprise agreement or applicable standard contractual clauses control over this online Addendum to the extent of a conflict.
Contact
Questions about this policy may be sent to Shawal Kabir Chy, trading as GrowthProof at support@getgrowthproof.com.
Business address: Road 8, House 405, Block D, Bashundhara R/A, Dhaka 1229, Bangladesh