1. Who we are
This Privacy Policy explains how THYNKR SYSTEMS LTD, company number 15306717, registered office Office 2, 1st Floor, 73 Station Passage, London E18 1JL, processes personal information as a controller in connection with GrowthPilot and growthpilot.systems. For privacy enquiries, email info@thynkrsystems.com.
2. When this Policy applies
This Policy covers website visitors, people who ask to join GrowthPilot, GrowthPilot account users, billing contacts and people who contact us.
Customers, including agencies, put their own data into GrowthPilot: for example client contacts, invoice recipients, brand information, connected marketing data and content. For that data the customer is the controller and THYNKR is its processor under the Data Processing Agreement. If your information is in a customer’s workspace, the customer’s own privacy information applies, and we may refer your request to that customer.
3. Information we collect
Website visits
The website is delivered through Cloudflare and our hosting provider. Server and security logs may record an IP address (which may be a Cloudflare network address), request time, requested page, response status and browser information. We use these to operate, secure and diagnose the website. Optional analytics is not currently used; see the Cookie Policy.
Requests to join
If you ask to join GrowthPilot, we collect your name, company, email address, business type, the time you agreed to be contacted and a one-way keyed hash of your network address used only to limit abuse. The request is stored in GrowthPilot and emailed to info@thynkrsystems.com so that we can reply.
Accounts and security
For GrowthPilot users we process name, email address, a password hash, second-factor settings, session records, sign-in and security events (including IP address and browser information), roles and workspace memberships, and activity recorded in audit logs.
Billing
For paid plans, Stripe processes billing details and payment card data. We receive billing contact details, subscription status and payment events, not full card numbers.
Correspondence and support
When you email us we process your email address, message and any attachments.
AI requests
When you use AI features, the request content, such as your question, the relevant Brand Profile, curated evidence from connected sources, content briefs and drafts, or public competitor page text, is sent to our AI service and our model provider to produce the result.
4. Why we use personal information and our lawful bases
| Purpose | Lawful basis |
|---|---|
| Providing GrowthPilot accounts, workspaces and features | Contract |
| Sign-in, second-factor codes, security alerts and fraud and abuse prevention | Contract and legitimate interests in keeping the Service secure |
| Subscription billing and tax records | Contract and legal obligation |
| Responding to requests to join and to enquiries | Legitimate interests in responding to people who contact us; consent given in the request form |
| Operating, securing and diagnosing the website and Service | Legitimate interests |
| Complying with law and establishing or defending legal claims | Legal obligation and legitimate interests |
We do not sell personal information. We do not use workspace data or AI requests to train AI models.
5. Marketing
We send service, security and billing messages that are needed to run your account. These are not marketing. We will only send marketing emails where the law allows, and you can opt out at any time.
6. AI and automated processing
GrowthPilot uses AI to analyse marketing evidence and draft content for human review. We do not make solely automated decisions that have legal or similarly significant effects on individuals.
7. Google user data
When you connect Google Search Console, Google Analytics 4 or Google Ads, GrowthPilot requests the narrowest scope offered (read-only access for Search Console and Analytics) and uses the data only to provide the GrowthPilot features you use, such as performance reports, Growth Audits, keyword research and AI analysis for your workspace.
GrowthPilot’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, not used for advertising, not used to develop, improve or train generalised AI or machine-learning models, and not read by people except with your permission, for security or abuse investigation, or where law requires. Access tokens are encrypted, and you can disconnect at any time.
9. International transfers
Some providers process data outside the UK. The GrowthPilot application and database are hosted in Germany and our AI service in the UK. Transfers to the United States and other countries are made under the safeguards shown in the table above, such as the UK International Data Transfer Addendum with standard contractual clauses, or another lawful mechanism.
10. How long we keep information
| Information | Retention |
|---|---|
| Web server access logs | Rotated daily and deleted after 14 days |
| Application logs | Kept in size-limited rotating files and overwritten automatically |
| Sign-in sessions | Expire after 7 days of inactivity or at sign-out |
| AI questions and retry context | Cleared when the task completes, or after one day |
| AI results and supporting evidence | Seven days |
| AI task receipts | Ninety days |
| Requests to join | While we consider and respond to the request and maintain a record of the invitation; deleted on request |
| Account, workspace and audit data | While the account is in use, and afterwards until you ask us to delete it |
| Billing and tax records | As required by tax and accounting law, normally six years |
| Encrypted database backups | Daily backups for 35 days; one monthly backup for 400 days |
When we delete data from the live system, copies in encrypted backups expire on the backup schedule above.
11. Security
We protect personal information with measures including encryption in transit, two-step sign-in for every account, role-based access and tenant isolation checked on every request, encrypted storage of connected-account tokens, human approval for important work, audit logging, encrypted off-site backups with tested restores, and separation of the application, AI and execution services. GrowthPilot does not currently hold a formal security certification such as SOC 2 or ISO 27001. No system can be guaranteed completely secure.
12. Your rights
Depending on the law that applies to you, you may have rights to access, correct or delete your personal information; to restrict or object to processing; to data portability; to withdraw consent; and to object to direct marketing. Rights are subject to legal conditions and exemptions. To make a request, email info@thynkrsystems.com. Where we process your information for a customer, we may refer the request to that customer.
13. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk) in the UK, or to your local data-protection authority.
14. Children
GrowthPilot is a business service and is not directed at children.
16. Changes to this Policy
We may update this Policy when our processing, providers or the law change. The version and dates at the top of this page identify the current Policy.
17. Contact
THYNKR SYSTEMS LTD, Office 2, 1st Floor, 73 Station Passage, London E18 1JL, United Kingdom. Email: info@thynkrsystems.com.