Legal Document • v3.0

Privacy Policy
grwow.ai

We take your privacy seriously. Read how we collect, use, and protect your data — worldwide.

📅 Effective: July 27, 2026
✅ Last Updated: July 27, 2026
🌎 Global Compliance
🏠
Section 01

Introduction

Welcome to grwow.ai. This Privacy Policy explains how AJKA Group LLC, doing business as grwow.ai, collects, uses, stores, shares, and protects personal information when you use our websites, applications, AI services, and related products.

We comply with applicable privacy laws worldwide — including GDPR, CCPA/CPRA, TCPA, CAN-SPAM, CASL, and applicable Caribbean and Latin American data protection regulations.

By accessing or using grwow.ai, you acknowledge that you have read and understood this Privacy Policy.
🚀
Section 02

Who We Are

grwow.ai is an AI-powered business operating system helping businesses worldwide centralize, automate, and grow their operations. Our platform includes: CRM, AI Assistants, AI Voice Agents, Websites, Funnels, Appointment Scheduling, Email Marketing, SMS/MMS, WhatsApp Business, Live Chat, Social Media Management, Online Courses, Communities, Reputation Management, Workflow Automation, Sales Pipelines, Reporting, API Integrations, Invoicing, Payment Processing, and future AI-powered features.

AJKA Group LLC • 30 N Gould St, Sheridan, WY 82801, USA • [email protected] • grwow.ai
🔍
Section 03

Scope

This Privacy Policy applies to the grwow.ai website and all subdomains, the platform and all features, mobile apps, AI-powered features, customer support, all grwow.ai communications, marketing, online forms, booking pages, community features, courses, and integrations operated by grwow.ai — including all interactions via email, SMS, WhatsApp, social media, and voice calls.

This policy does not apply to third-party websites or services not controlled by grwow.ai, even if they integrate with our platform.

📖
Section 04

Definitions

  • Account — your registered grwow.ai account
  • Customer — any business or individual subscribing to grwow.ai services
  • Data Controller — entity determining the purposes and means of processing
  • Data Processor — entity processing data on behalf of a Controller
  • End User — individual whose data is processed through grwow.ai by a Customer
  • Personal Information — any information that identifies or can be linked to an individual
  • Processing — any operation on personal information (collecting, storing, using, sharing, deleting)
  • Services — all grwow.ai products, tools, APIs, and communications
  • Sensitive Personal Information — racial origin, religious beliefs, financial, health, biometric data
  • Sub-Processor — third party processing data on behalf of grwow.ai
🌟
Section 05

Our Privacy Principles

  • We only collect information necessary to provide and improve our Services
  • We are transparent about how personal information is processed
  • We implement privacy by design and by default
  • We implement reasonable technical and organizational safeguards
  • We do not sell personal information
  • We give users meaningful control over their information
  • We respect your choices regarding marketing and communications
  • We continuously improve our privacy and security practices
⚖️
Section 06

Data Controller and Processor Roles

When We Act as Data Controller: grwow.ai is the Data Controller for personal information relating to our own customers, website visitors, prospects, billing, support, and marketing activities. We determine the purposes and legal basis for processing and are directly responsible for compliance.
When We Act as Data Processor: When our Customers use grwow.ai to process personal information about their own contacts, grwow.ai acts solely as a Data Processor. The Customer remains the Data Controller and is responsible for determining purposes, legal basis, providing notices to End Users, and responding to rights requests.

Customers requiring a formal Data Processing Agreement (DPA) may request one at [email protected].

📊
Section 07

Information We Collect

A) You Provide Directly

  • Name, email address, phone number
  • Company name, business address, business details
  • Billing, invoicing, and payment information
  • Account credentials and login information
  • Messages, inquiries, and support communications
  • Form, survey, quiz, and lead generation submissions
  • Consent records for SMS, email, voice, and WhatsApp
  • Profile details and preferences

B) Collected Automatically

  • IP address, browser type, OS, and device information
  • Pages visited, session data, referral URLs
  • Cookies, pixels, web beacons, and tracking technologies
  • Call recordings and message logs (where permitted by law)
  • Appointment, booking, and calendar activity
  • Platform usage and interaction logs

C) From Third Parties

  • Social media platforms (lead ads, messaging APIs, integrations)
  • Payment processors
  • Analytics and data enrichment services
  • Public databases or business registries
⚙️
Section 08

How We Use Your Information

  • Provide, operate, and improve our platform and Services
  • Personalize your experience
  • Send marketing communications (with your explicit consent only)
  • Process transactions and send confirmations
  • Respond to inquiries and deliver customer support
  • Schedule appointments and send reminders (SMS, email, WhatsApp)
  • Deliver automated messages and AI-powered communications (with consent)
  • Manage sales pipelines and workflows on behalf of Customers
  • Send review and reputation request messages on behalf of Customers
  • Post content to social media on your behalf
  • Comply with legal and regulatory obligations
  • Detect and prevent fraud, abuse, and security incidents
  • Analyze usage to improve our Services
  • Power AI features as described in Section 9
🤖
Section 09

Artificial Intelligence Features & Transparency

grwow.ai may use artificial intelligence technologies to provide features such as AI assistants, automated responses, content generation, workflow automation, and business insights.

AI & Your Data: Unless explicitly stated otherwise, personal information is not used to train publicly available AI models. Where AI providers process information on our behalf, they do so under contractual and legal obligations that restrict use for external model training.
AI Output Disclaimer: AI-generated outputs — including written content, responses, summaries, and recommendations — may contain inaccuracies or errors. AI-generated content should not be relied upon as legal, financial, medical, tax, or other professional advice. Users remain responsible for reviewing AI-generated content before acting upon it.

grwow.ai uses AI and automation to assist users but does not make legally significant decisions about individuals solely through automated processing without appropriate human oversight where required by law (including GDPR Article 22). To request human review of an automated decision, contact [email protected].

🌍
Section 10

Responsible AI Commitment

👀 Human Oversight
AI features are designed to assist, not replace, human judgment. Human review mechanisms are maintained for significant decisions.
⚖️ Bias Reduction
We monitor AI performance and apply fairness considerations to identify and mitigate biases in outputs.
💡 Transparency
We are clear about when and how AI is being used within our platform and communications.
🔒 Privacy by Design
AI features are developed with data minimization and purpose limitation built in from the start.
🛡️ Security
AI systems are subject to the same security controls applied across our entire platform.
🔄 Continuous Improvement
We review and refine our AI practices as technology and regulatory guidance evolves.
🇪🇺
Section 11

Legal Basis for Processing (GDPR)

For users in the EEA, United Kingdom, and other jurisdictions requiring a legal basis:

  • Consent — when you have explicitly opted in to receive communications or specific processing
  • Contractual necessity — when processing is required to deliver a service you requested
  • Legitimate interests — for fraud prevention and platform improvement, where not overridden by your rights
  • Legal obligation — when required to comply with applicable law

You have the right to withdraw consent at any time. Withdrawing consent does not affect the lawfulness of prior processing.

📱
Section 12

SMS and Text Messaging

By providing your phone number and opting in, you consent to receive SMS/MMS from grwow.ai or our Customers, including marketing content, appointment reminders, transactional notifications, customer service follow-ups, and review requests.

📱 SMS Compliance Info
📅Message frequency may vary
💰Message and data rates may apply
To opt out at any time: reply STOP
To get help: reply HELP or email [email protected]
🔒We never share your number with third parties for their marketing
Compliant with: TCPA (US) • A2P 10DLC (The Campaign Registry) • CASL (Canada)
💌
Section 13

Email Marketing

By providing your email and opting in, you consent to receive emails from grwow.ai or our Customers, including newsletters, promotions, product updates, and transactional messages.

To unsubscribe: click the unsubscribe link in any email, or email [email protected]. Opt-out requests are processed within 10 business days.

Compliant with: CAN-SPAM Act (US) • CASL (Canada) • GDPR (EU/EEA)
🎤
Section 14

AI Voice & Automated Phone Calls

With your prior written or verbal consent, we may contact you via phone — including AI-powered automated voice calls — for appointment reminders, sales follow-ups, customer service, and marketing.

To opt out: say “Stop” during an AI voice call, or contact [email protected]. Calls may be recorded where required; you will always be informed when a call is being recorded. Compliant with applicable TCPA regulations.

💬
Section 15

WhatsApp Messaging

With your explicit consent, we may send you WhatsApp Business messages for marketing, service updates, appointment reminders, and customer support.

To opt out: reply STOP to any WhatsApp message, or contact [email protected]. Subject to Meta’s Terms of Service and WhatsApp Business Policy.

🗩️
Section 16

Live Chat & Conversational AI

Our website and Customer websites may feature live chat widgets and AI-powered chat agents. Conversations may be stored for service improvement, used for follow-up communications, and processed by AI systems to generate responses (anonymized for AI training). All chat data is protected under this Privacy Policy.

📅
Section 17

Appointment Booking & Scheduling

When you book via our platform or a Customer booking page, we collect your name, contact details, and booking information to confirm appointments, send reminders via SMS/email/WhatsApp, follow up afterward, and sync with calendar services (e.g., Google Calendar).

📷
Section 18

Social Media & Lead Ads

If you submit information through a social media lead ad (Facebook, Instagram, TikTok, LinkedIn), your data is collected per this Privacy Policy and the platform’s own policies. We may follow up via email, SMS, phone, or WhatsApp, and may add you to retargeting audiences. Retargeting is conducted only where permitted by applicable law.

💳
Section 19

Payments & Invoicing

Payments are processed by secure third-party payment processors. We do not store your full payment card details. Transaction records and financial data are retained as required by law (typically 7 years in the United States).

🍪
Section 20

Cookies & Tracking

We use cookies, web beacons, pixels, and similar technologies to maintain sessions, analyze traffic, improve experience, support retargeting, track marketing conversions, and deliver personalized content.

🔒 Essential
Required for the platform to function
📈 Analytical
Understand how users interact with our services
🎯 Marketing
Relevant advertising and retargeting
⚙️ Preference
Remember your settings and choices

Control cookies via your browser settings. EU/EEA users: we obtain consent before placing non-essential cookies per the ePrivacy Directive and GDPR.

🔓
Section 21

Data Sharing & Sub-Processors

We do NOT sell your personal information.

We share data only with trusted service providers who help deliver our Services, including payment processors, cloud hosting providers, AI providers, communication providers, analytics providers, identity providers, and marketing platforms. All sub-processors are bound by data processing agreements and required to maintain appropriate security standards.

A current list of our major sub-processors is available upon request at [email protected] or on our website.

We may disclose data when required by law, court order, or to protect the safety of grwow.ai, Customers, or the public. In the event of a merger or acquisition, personal information may transfer to a successor entity with appropriate notice.

🕐
Section 22

Data Retention & Export

We retain personal information as long as necessary to provide Services, as required by law (e.g., financial records: 7 years), needed to resolve disputes, or while you maintain an active account.

Upon account termination or a verified deletion request, we delete or anonymize your data within 30 days, unless required by law.

Data Export: Customers may request an export of their data in a machine-readable format (CSV/JSON) at any time, including before account closure. Request at [email protected].
⚖️
Section 23

Your Rights

🌎 Rights for Everyone

  • Access — request a copy of your personal information
  • Correction — request correction of inaccurate data
  • Deletion — request deletion (right to be forgotten)
  • Withdraw Consent — for marketing at any time
  • Objection — object to certain data processing

🇪🇺 Additional GDPR Rights (EU/EEA/UK)

  • Data Portability — receive your data in machine-readable format
  • Restrict Processing — limit how we use your data
  • Automated Decision-Making — request human review of automated decisions
  • Lodge a Complaint — with your local data protection authority

🇺🇸 Additional CCPA/CPRA Rights (California)

  • Know what personal information is collected, used, or shared
  • Delete personal information
  • Opt Out of sale/sharing (we do not sell personal information)
  • Non-Discrimination for exercising your rights
  • Correct inaccurate personal information
  • Limit use of sensitive personal information
Contact [email protected] to exercise any right. We respond within 30 days (or 45 days where permitted).
🚫
Section 24

Do Not Sell or Share My Personal Information

grwow.ai does NOT sell, rent, or share personal information for monetary or other valuable consideration as defined under CCPA/CPRA or similar laws. To opt out of cross-context behavioral advertising data sharing, contact [email protected].

👁️
Section 25

Biometric Information

grwow.ai does not intentionally collect biometric identifiers — including fingerprints, facial recognition data, voiceprints, or retina scans — unless explicitly enabled through an integrated third-party service with your prior consent. If a third-party integration collects biometric data, that collection is governed by the third party’s privacy policy and applicable biometric privacy laws (including Illinois BIPA and similar regulations).

🌎
Section 26

International Data Transfers

Your personal information may be transferred to and processed in countries other than where you reside, including the United States and countries where our sub-processors operate.

  • EU/EEA: Standard Contractual Clauses (SCCs) and adequacy decisions
  • Caribbean & Latin America: Equivalent protections under applicable regional frameworks
  • Canada: Compliance with PIPEDA and applicable provincial privacy laws
👪
Section 27

Children’s Privacy

Our Services are not directed to individuals under 13 (or 16 in the EU/EEA). We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it promptly. Parents or guardians may contact us at [email protected].

🛡️
Section 28

Security

Access Controls

  • Principle of Least Privilege: access limited to those who need it for their role
  • Role-Based Access Control (RBAC): permissions assigned by role and responsibility
  • Multi-Factor Authentication (MFA) for all platform access

Data Protection

  • SSL/TLS encryption for all data in transit
  • Encryption of data at rest with industry-standard algorithms
  • Encryption Key Management with regular key rotation

Monitoring & Auditing

  • Audit Logging: significant access and admin actions are logged and retained
  • Continuous security monitoring and anomaly detection
  • Regular penetration testing and vulnerability assessments

Operational Resilience

  • Disaster Recovery: regular backups with documented recovery procedures
  • Business Continuity Planning for Service availability during disruptions
  • Incident Response with defined escalation paths and breach notification

Human Factors

  • Employee data protection training and confidentiality obligations
  • Background checks and access reviews for personnel with data access
🔗
Section 29

Third-Party Links & Integrations

Our Services may link to or integrate with third-party websites and platforms. We are not responsible for their privacy practices. Please review the privacy policies of any third-party services you use in connection with grwow.ai.

🔄
Section 30

Updates to This Privacy Policy

We may update this Privacy Policy to reflect changes in our Services, legal requirements, or business practices. For material changes, we will update the Last Updated date, notify registered users via email, and display a prominent notice on our website. Continued use of our Services after updates constitutes acceptance of the revised policy.

Section 31 — Contact

📞 Privacy Team

Questions, data requests, DPA inquiries, or concerns? We’re here to help.

Website
grwow.ai
Address
30 N Gould St, Sheridan, WY 82801, USA
EU/EEA
Lodge complaints with your local DPA
California
CCPA/CPRA rights via [email protected]