Privacy Policy
Last updated: August 25, 2026
1. Who is responsible
Growis AG (CHE-236.625.032)
Anton-Julius-Eggstein-Gasse 1
6005 Luzern, Switzerland
Represented by: Stefan Vukovic
For all privacy and legal matters: legal@growis.ch
Growis AG is the data controller for personal data processed through this website under the Swiss Federal Act on Data Protection (nFADP), the EU General Data Protection Regulation (GDPR), and comparable laws.
2. What we collect and why
Contact form
When you submit the contact form we collect the information you enter: your first and last name, work email, phone number, and position/role, plus — optionally — your company and LinkedIn profile URL, together with the service you select and your message. First name, last name, email, phone, position, and message are required; company and LinkedIn are optional. We use this only to answer your inquiry and prepare a potential engagement. Legal basis: steps prior to entering a contract (GDPR Art. 6(1)(b)) and our legitimate interest in responding to you.
Where your inquiry is stored (our own platform)
Your submission is stored in our in-house client-management platform, which runs the Twenty CRM on infrastructure we operate ourselves in Switzerland. Your data is not sent to an external CRM provider. No decision producing legal or similarly significant effects about you is made solely by automated means — a person reviews every inquiry.
Scheduling (Google)
If you book a call, Google LLC processes your name, email, and chosen time slot through Google Calendar appointment scheduling, under its own privacy policy. Legal basis: steps prior to entering a contract.
Meeting recordings and transcripts
If you attend an online meeting with us, we record it and have it transcribed automatically so that we can produce meeting notes. You are told this in advance, in writing, above the meeting link, and again verbally at the start of the call. If you do not want to be recorded, tell us beforehand or at the start of the meeting and we will not record. If you object during a call, we stop immediately and delete the recording made up to that point.
The recording is processed and stored by our provider Fathom Video Inc.in the United States, and an AI system is used to generate the summary; Fathom uses Anthropic, OpenAI and Google as AI sub-processors, none of which are permitted to use the recording to train their models. The transfer to the United States is covered by Fathom's certification under the Swiss–U.S. Data Privacy Framework, with Standard Contractual Clauses as a fallback. We keep the recording and the transcript for the duration of our business relationship, and in any case no longer than five years, then delete them. You can ask us to delete them at any time by writing tolegal@growis.ch, and we will. Legal basis: your consent (GDPR Art. 6(1)(a)) and, under Swiss law, the consent of all participants required by Art. 179ter of the Swiss Criminal Code. You may withdraw consent at any time with effect for the future.
Client documents (Tresorit)
If you become a client, we share deliverables and exchange documents with you through Tresorit, a Swiss provider owned by Swiss Post. Files are end-to-end encrypted with keys we hold, so Tresorit cannot read their contents, and are stored in Swiss data centres. Legal basis: performance of our contract with you.
Business contacts and correspondence
If you contact us by email or we work together day to day, we process your business contact details and our correspondence in Google Workspace (email, calendar, documents) to manage the relationship. Legal basis: performance of a contract or our legitimate interest in orderly business communication.
Prospecting from public registers (Zefix / SOGC)
To identify companies we may be able to help, we process publications of the Swiss commercial register: the daily notices of the Swiss Official Gazette of Commerce (SOGC/SHAB), obtained through the open-data interface of Zefix, the Central Business Name Index of the Federal Office of Justice. These officially published notices can contain personal data of company officers, such as names and functions. We store them in our self-hosted client-management platform in Switzerland, where a person reviews them; entries not relevant to our services are marked as such and not used for outreach. Legal basis: our legitimate interest in business-to-business prospecting based on officially published register data. You can object to this processing at any time via legal@growis.ch.
Register data source: Zefix — Central Business Name Index, Federal Office of Justice, Switzerland (open government data, used with source attribution).
Spam and abuse protection
Our contact form is protected by Cloudflare Turnstile, a privacy-friendly CAPTCHA that checks whether a submission is human. It processes limited technical data, including your IP address, and does not use cookies to track you across sites. To block duplicate and abusive submissions we may also briefly process your IP address and a one-way hash of your submission. Legal basis: our legitimate interest in a secure, spam-free form.
Website measurement (cookieless, no consent needed)
We use Cloudflare Web Analytics, a privacy-friendly, cookieless service that reports aggregate visit statistics without setting cookies, without cross-site tracking, and without building a profile of you. Legal basis: our legitimate interest in understanding site usage.
Analytics and advertising (only with your consent)
With your explicit opt-in via our cookie banner, we additionally use Google Analytics 4 (with IP anonymization) to understand site usage, and the Meta Pixel to measure the performance of our campaigns. Neither loads before you accept. Legal basis: consent (GDPR Art. 6(1)(a)), which you can withdraw at any time (see section 4).
Technical logs
Our hosting provider Cloudflare processes IP addresses and request metadata to deliver the site securely and defend against attacks. Legal basis: legitimate interest in a secure, functioning website.
3. Recipients and international transfers
We process personal data on infrastructure we operate ourselves wherever we can. The following external processors are involved in running this website:
- Cloudflare, Inc. (hosting, security, Turnstile bot protection, and cookieless Web Analytics), USA
- Resend, Inc. (transactional email that notifies us of form submissions; sending region EU), USA
- Slack Technologies, LLC / Salesforce (internal notification of new inquiries), USA
- Linear Orbit, Inc. (internal tracking of new inquiries), USA
- Google LLC (appointment scheduling via Google Calendar), USA
- Google LLC (analytics), USA, only after consent
- Meta Platforms, Inc. (advertising measurement), USA, only after consent
The following processors are involved beyond the website itself:
- Fathom Video Inc. (recording, transcription and summarisation of online meetings), USA, certified under the Swiss–U.S. Data Privacy Framework, with Anthropic PBC, OpenAI and Google as AI sub-processors
- Tresorit AG (encrypted exchange of client documents), Switzerland
- Infomaniak SA (encrypted nightly backups of our client-management platform; data is encrypted before upload, so Infomaniak stores only ciphertext), Switzerland
- Google LLC (Google Workspace: business email, calendar, and documents in the course of our relationship with you), USA
Our client-management platform, built on the Twenty CRM, runs on infrastructure we operate ourselves in Switzerland; the personal data it holds is not shared with an external CRM provider.
Transfers to the USA rely on the EU-US and Swiss-US Data Privacy Framework where the provider is certified, and otherwise on Standard Contractual Clauses. We do not sell personal data.
4. Cookies and how to withdraw consent
Analytics and marketing cookies load only after you click "Accept all" in our banner. "Only necessary" keeps the site cookie-free apart from your stored choice. Cloudflare Web Analytics uses no cookies and therefore runs regardless of this choice. You can change your mind at any time:
5. Retention
Inquiry data is kept in our client-management platform for as long as needed to handle your request and manage our business relationship, and thereafter only for legal retention duties, then deleted. Copies in our email inbox, Slack, and Linear follow the same principle and are cleared in the ordinary course. Meeting recordings and their transcripts are kept for the duration of our business relationship and in any case no longer than five years, then deleted; you can request deletion at any time vialegal@growis.ch. Analytics data is retained per Google Analytics settings (14 months) in aggregated form; Cloudflare Web Analytics is aggregate only. Consent choices are stored in your browser until you reset them.
6. Your rights
Under the nFADP and GDPR you can request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. You may lodge a complaint with the Swiss FDPIC or your local supervisory authority.
California residents (CCPA/CPRA)
You have the right to know, correct, and delete personal information, and to opt out of "sharing" for cross-context behavioral advertising. We do not sell personal information. Declining our cookie banner prevents the sharing associated with the Meta Pixel. To exercise any right, email us; we do not discriminate against you for doing so.
Other jurisdictions
Where laws such as Japan's APPI, Singapore's PDPA, or comparable Asian data protection regulations apply, we honor the access, correction, and deletion rights they grant. Contact us at the address in section 1.
7. Security
The site is served exclusively over HTTPS with strict transport security and a restrictive content security policy. Form submissions travel encrypted; we receive them by email (via Resend) and store them in our self-hosted client-management platform, with internal notifications sent to Slack and Linear. Personal data in our CRM stays on infrastructure we operate ourselves in Switzerland, reachable only through an access-controlled connection, with encrypted nightly backups stored in Switzerland. To keep the form secure we use Cloudflare Turnstile and short-lived rate-limiting, as described in section 2.
8. Changes
We update this policy when our tooling or the law changes. The date at the top tells you the current version.