Growth Station

Privacy Notice

How Growth Machine processes lead and business contact data, which rights apply, and how to exercise them.

Public documentVersion 2026.08Updated Aug 16, 2026
Português

Growth Station — Privacy Notice for Leads and Business Contacts

Last updated: August 16, 2026
Company: Growth Machine Editora e Aceleração Ltda.

Translation notice: This English version is provided for convenience. If it conflicts with the original Portuguese document, the Portuguese version prevails.

This document was prepared in accordance with Articles 9 and 18 of Brazil's General Data Protection Law (Lei Geral de Proteção de Dados, or "LGPD" — Law No. 13,709/2018).


1. Who We Are

Growth Machine Editora e Aceleração Ltda. ("Growth Machine") is the company responsible for Growth Station, a SaaS sales engagement and prospecting platform used by companies ("Projects") to manage sales operations.

When your personal data is processed:

  • The company that contacted you (the Project/customer using Growth Station) is the Controller of your data. It decides why and how your data is processed.
  • Growth Machine acts as the Processor. We process your data solely under the Controller's instructions and on its behalf.

2. Personal Data We Process

When a company uses Growth Station to manage its sales prospecting activities, the following personal data may be processed:

CategoryExamples
IdentificationName, email address(es), telephone number(s), mobile number(s)
Professional informationJob title/role, company, LinkedIn profile, website
LocationCity, state, country
CommunicationsEmail content, WhatsApp messages, telephone call recordings and transcripts
ProspectingSales funnel status, notes, tags, custom fields
EnrichmentAdditional data obtained automatically, such as publicly available company information

3. How Your Data Is Used

Your personal data is processed for the following purposes:

  1. Sales prospecting — Contacting and following up on business opportunities.
  2. Multichannel communication — Sending emails and WhatsApp messages and making telephone calls.
  3. Relationship management — Recording interactions, scheduling meetings, and tracking progress through the sales funnel.
  4. AI-powered automation — Generating personalized messages and analyzing interactions when enabled by the Controller.
  5. CRM synchronization — Sharing data with the Controller's customer relationship management system when configured.

The Controller (the Project that added your data) determines the legal basis for processing your personal data. The most common legal bases are:

  • Legitimate interests (Article 7, IX of the LGPD) — for B2B sales prospecting.
  • Consent (Article 7, I of the LGPD) — where the Controller adopts it as the basis.

Call recording: calls placed through the Platform are recorded and transcribed by default. The Platform does not collect or store the Lead's consent to recording — giving the required prior notice and securing an adequate legal basis is the responsibility of the Controller conducting the call.


5. Who May Process Your Data

The following third parties may process your data solely to provide the services:

Third partyPurposeCountry
Amazon Web Services (AWS)Infrastructure and storageUnited States/Brazil
MongoDB AtlasDatabase servicesUnited States/Brazil
NylasEmail delivery and synchronizationUnited States
TwilioWhatsApp messagingUnited States
Telecommunications providersVoIP telephone calls (TIM, API4COM)Brazil
OpenAIAI processing when enabledUnited States
CRMsSynchronization with Pipedrive, HubSpot, RD Station, Kommo, Salesforce, and Bitrix24According to each provider

The complete and current list is available in our Subprocessors document.


6. International Data Transfers

Your data may be transferred to servers located outside Brazil, particularly in the United States, through the subprocessors listed above. These transfers are made under Article 33 of the LGPD and protected by:

  • Data processing agreements (DPAs) with each subprocessor.
  • Standard contractual clauses (SCCs).
  • Encryption in transit (TLS/HTTPS).

7. Data Retention

Your data is retained for as long as the Controller considers it necessary for its prospecting purpose. After the Controller's agreement with Growth Station ends, the data is retained for 30 days to allow export and is then deleted within an additional 30 days, unless a legal retention obligation applies.


8. Use of Artificial Intelligence

Growth Station may use AI models to:

  • Generate and personalize prospecting messages.
  • Transcribe and analyze telephone calls.
  • Suggest next actions to the Controller's sales team.

Important:

  • AI does not make final decisions about you. Actions remain subject to human oversight by the Controller.
  • Data sent to the AI provider (OpenAI) is not used to train its models, under the applicable agreement.
  • You may request human review of an automated decision that affects you (Article 20 of the LGPD).

9. Email Tracking

Emails sent through the Platform may contain:

  • An open-tracking pixel to detect whether an email was opened.
  • Tracked links to detect link clicks.

These technologies apply to every email sent through the Platform. You can prevent open detection by disabling automatic image loading in your email client.


10. Your Rights

Under Articles 17 through 22 of the LGPD, you have the right to:

RightDescription
Confirmation and accessLearn whether your data is processed and obtain a copy
CorrectionCorrect incomplete, inaccurate, or outdated data
DeletionRequest deletion of your data
PortabilityReceive your data in a structured format
Information about sharingLearn who receives your data
Withdrawal of consentWithdraw consent at any time
Review of automated decisionsRequest human review of decisions made by AI

How to Exercise Your Rights

  1. Contact the company that approached you. It is the Controller of your data and your primary point of contact.
  2. If you do not know which company it is or do not receive a response, contact us:

We will forward your request to the Controller within 2 business days.


11. Data Security

We apply technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) for all communications.
  • Data isolation by company through logical multi-tenant separation.
  • Role-based access control (RBAC).
  • Continuous security monitoring.
  • Data processing agreements with all subprocessors.

12. Changes to This Notice

We may update this Notice periodically. The current version will always be available on our website and Platform.


13. Contact

  • Email: privacidade@growthedge.com.br
  • Data Protection Officer (DPO): Natália Caroline Batista
  • Address: Rua Berrini, 500, 8th floor, São Paulo, SP, Brazil

This document was prepared in accordance with Brazil's LGPD (Law No. 13,709/2018).

Your feedback matters

Did this guide answer your question?

It only takes a few seconds and helps us keep the knowledge base useful.

Nesta página

Reviewed Aug 16, 2026

Content maintained by Privacy — Growth Machine