Privacy
We use the information you provide to answer enquiries, deliver requested content and services, process business orders, issue invoices, operate subscriptions, protect the website, and comply with Austrian tax and accounting duties. Payment card details are entered directly with Stripe and are not stored on GrowthEko servers.
1. Data we process
- Contact and business data: name, business email, company or legal business name, website, country, billing address, VAT ID, and information submitted in forms or onboarding.
- Order and contract data: selected service, price, order status, invoice and credit-note data, payment status, Stripe customer, subscription, session, and invoice references.
- Service data: information and files supplied for an audit, membership, support request, call, or implementation activity.
- Technical data: IP address, date and time, browser, device, requested page, referral information, security events, and server logs.
- Communications: emails, support messages, scheduling information, and consent or unsubscribe records.
2. Purposes and legal bases
| Purpose | GDPR legal basis |
|---|---|
| Answering enquiries, applications, and pre-contract requests | Article 6(1)(b) |
| Checkout, payment, subscription, invoice, service delivery, customer portal, and support | Article 6(1)(b) |
| Austrian tax, accounting, retention, and authority obligations | Article 6(1)(c) |
| Website security, fraud prevention, service reliability, and establishment or defence of legal claims | Article 6(1)(f), legitimate interests |
| Email marketing or optional analytics where consent is required | Article 6(1)(a); consent may be withdrawn at any time |
3. Checkout, payment, and invoices
Stripe processes payment and subscription information when you use Checkout or the customer portal. GrowthEko receives the information needed to identify the order, confirm payment, deliver the service, issue or retain the electronic invoice, handle payment failures, and process refunds or credit notes. Complete card numbers and card security codes are entered directly in Stripe's systems and are not stored by GrowthEko.
Stripe may process some data as its own controller under its terms and privacy notice. See Stripe Privacy.
4. Service providers and recipients
Data is shared only where needed for the relevant feature, contract, legal obligation, or legitimate operational purpose. Current categories may include:
- Stripe: checkout, payment, recurring billing, invoices, fraud prevention, and customer portal.
- Vercel: website hosting, content delivery, serverless functions, and technical logs.
- Supabase: application database, customer, order, onboarding, and service records.
- Resend or the configured email provider: transactional and consented marketing email delivery.
- Calendly or the configured scheduling provider: appointment scheduling when used.
- Google Analytics: website analytics only where configured and legally permitted; consent is requested where required.
- Professional advisers and public authorities: tax advisers, accountants, lawyers, courts, and authorities where necessary or legally required.
Processors are engaged under appropriate data-protection terms where required.
5. International transfers
Some providers may process data outside Austria or the European Economic Area. Where GDPR Chapter V requires safeguards, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another legally permitted mechanism. Details about a specific provider's safeguards can be requested by email.
6. Cookies, local storage, and analytics
Technically necessary storage may be used for security, session continuity, form operation, checkout, and customer access. Non-essential analytics or marketing technologies are used only with consent where legally required. You can withdraw consent through the available preference control or by clearing browser storage. Third-party checkout or portal pages may set their own necessary cookies under the provider's policy.
7. Email
Transactional emails such as order confirmations, invoices, payment notices, subscription information, onboarding, security messages, and direct replies are sent because they are required to perform the contract or answer a request. Marketing emails are sent only where a valid legal basis exists. You may unsubscribe using the link in the message or email us; this does not stop essential contract or invoice communications.
8. Retention
- Accounting, invoice, payment, and tax records are generally retained for at least seven years under Austrian retention duties and longer where a legally relevant proceeding requires it.
- Contract and service records are retained for the contract term and applicable limitation periods.
- Unsuccessful applications, routine enquiries, and marketing records are deleted or anonymized when no longer needed, subject to consent evidence, objection records, security, or legal-claim requirements.
- Technical logs are retained only for a proportionate security and troubleshooting period unless an incident requires longer preservation.
9. Required information
Business identity, contact, billing, country, and payment information marked as required is needed to create a valid order, determine the correct tax treatment, issue the invoice, and deliver the service. Without it, checkout or service delivery may not be possible. Optional form fields are labelled or apparent from context.
10. Your rights
Subject to the GDPR's conditions and exceptions, you may request access, correction, deletion, restriction, data portability, or objection. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing. To exercise a right, email info@growtheko.com. We may request information needed to verify identity and protect customer data.
You may lodge a complaint with the Austrian Data Protection Authority: www.dsb.gv.at.
11. Automated decisions
GrowthEko does not currently make decisions producing legal or similarly significant effects solely through automated processing. Stripe and other security providers may use automated fraud and risk signals under their own policies.
12. Security
Reasonable technical and organizational measures are used to protect data, including access controls, encrypted transport, provider security controls, and limiting data to what is needed. No internet service can guarantee absolute security. Please do not send payment card details by email.
13. Business customers and minors
Paid GrowthEko services are intended for business customers and authorized adult representatives. They are not directed at children.
14. Changes
This notice may be updated when services, providers, or legal requirements change. The current version and effective date are published on this page. Material changes affecting an active customer relationship will be communicated where required.
Contact
Privacy requests and questions: info@growtheko.com.