Legal
Privacy Policy
Effective date: August 22, 2026
This Privacy Policy explains, in plain language, what personal information GROWTH FOUNDRY LLC ("Growth Foundry", the "Company", "we", "us") collects through the website joingrowthfoundry.com, why we collect it, what we do with it, how long we keep it, and the rights you can exercise over it. It applies to every page of this website, in English and Spanish, and to the email exchanges that follow an inquiry submitted through it.
1. Who is responsible for your data
The controller of personal information processed through this website is GROWTH FOUNDRY LLC, a limited liability company organized under the laws of the State of New Mexico, United States, with its business address at 1209 Mountain Road Pl NE Ste R, Albuquerque, NM 87110, USA. For every question, request or complaint related to personal data you can write to info@joingrowthfoundry.com or to the postal address above. We have not appointed a Data Protection Officer because the scale and nature of our processing do not require one; privacy requests are handled directly by company management.
2. Information we collect, and where it comes from
Information you give us. When you submit the contact form (on the homepage or on the contact page) we receive the data you type into it: your full name, your company name (optional), your work email address, the content of your message and the language of the page you used. Submitting the form also records that you ticked the privacy consent checkbox. If you later correspond with us by email, we receive whatever information you choose to include in those messages.
Information collected automatically. Our web server keeps standard access and security logs, which record the IP address of each request, the date and time, the page requested, the HTTP status, the referring page and the browser identification string (user agent). These logs exist for every website on the internet that takes security seriously; we use them exclusively to operate, secure and troubleshoot the service.
Information we do NOT collect. This website contains no analytics trackers, no advertising pixels, no social media widgets, no session recording, no fingerprinting and no third-party fonts or scripts. We do not buy data about you from anyone, and we do not combine website data with external sources.
3. Purposes and legal bases
We process personal information for the following purposes, each supported by a legal basis where such a basis is required (for example under the EU or UK GDPR):
Responding to your inquiry and scheduling a Business Assessment — based on your consent (Art. 6(1)(a) GDPR), given when you tick the consent box, and on pre-contractual steps taken at your request (Art. 6(1)(b) GDPR).
Preparing proposals and providing contracted services — based on the performance of a contract or steps prior to entering one (Art. 6(1)(b) GDPR).
Keeping business records of correspondence, proposals and engagements — based on our legitimate interest in documenting our commercial activity (Art. 6(1)(f) GDPR) and on legal obligations where records retention is mandatory.
Securing the website, preventing spam and abuse (including the anti-bot honeypot field in the form and server-side validation) — based on our legitimate interest in protecting our infrastructure (Art. 6(1)(f) GDPR).
Complying with applicable law, court orders or lawful requests from authorities — based on legal obligation (Art. 6(1)(c) GDPR).
We do not use personal information for automated decision-making or profiling, and we do not send marketing communications unless you have expressly requested or consented to them.
4. Categories of data
The categories of personal data we process are limited to: identification data (name), professional contact data (work email, company name), the content of the communications you send us, technical connection data (IP address, user agent, timestamps) and consent records (the fact and time of your consent, and your cookie banner choice as described in the Cookie Policy). We do not request, and ask you not to send, special categories of data such as health, political, religious or biometric information; if a message contains such data we will delete it unless keeping it is legally required.
5. Recipients — who sees your data
Your data is not sold, rented or traded to anyone. It is not shared with advertising networks, data brokers or analytics companies, because we use none.
The website and its mailbox run on hosting infrastructure operated for Growth Foundry (a managed web and mail server). The hosting provider processes data on our behalf strictly to store and transmit it, under contractual confidentiality and security obligations, and cannot use it for its own purposes.
Beyond hosting, we disclose personal information only: (a) when a law, regulation, court order or enforceable governmental request requires it; (b) to professional advisers (lawyers, accountants) bound by confidentiality, where necessary to protect our rights; or (c) as part of a merger, acquisition or sale of assets, in which case the successor remains bound by this policy for the data transferred.
6. International data transfers
Growth Foundry LLC is established in the United States and its server infrastructure may be located in the United States or the European Union. If you contact us from outside those territories, your data will be transferred to them. Where the GDPR or UK GDPR applies to a transfer, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or another lawfully recognized transfer mechanism, together with technical measures (HTTPS/TLS encryption in transit, access restriction on the server). You can request more information about the safeguards applied by writing to info@joingrowthfoundry.com.
7. How long we keep your data
Contact form inquiries and related email threads: up to 24 months after the last exchange, so we can respond to follow-up questions and document what was discussed; earlier deletion on request whenever no legal obligation prevents it.
Client and contract records (where an inquiry becomes an engagement): for the duration of the engagement plus the retention periods required by applicable accounting, tax and commercial law, generally between 3 and 10 years depending on the record.
Server access and security logs: rotated automatically and kept for a maximum of 12 months, used only for security and troubleshooting.
Consent records (including your cookie banner choice, stored in your own browser): your banner choice is stored on your device for a maximum of 12 months, after which the banner asks again. We keep evidence of form consent for as long as we keep the related inquiry.
8. Security
We apply administrative, technical and organizational measures proportionate to the risk of our processing: all traffic is encrypted with HTTPS/TLS; the contact endpoint validates every submission on the server and strips header-injection attempts; a honeypot field rejects automated spam without tracking you; access to the mailbox and server is restricted and password-protected; and the website runs no third-party code that could exfiltrate data. No system connected to the internet can be guaranteed absolutely secure, but our surface area is deliberately minimal: the less data we collect, the less can ever be exposed.
9. Your rights
Depending on the law applicable to you, you have the right to: access the personal data we hold about you and obtain a copy; rectify inaccurate or incomplete data; erase your data ("right to be forgotten"); restrict processing while a dispute is resolved; object to processing based on legitimate interest; receive your data in a portable, machine-readable format; and withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any right, email info@joingrowthfoundry.com from the address your inquiry was sent from (or provide equivalent proof of identity, which we request only to make sure we do not hand your data to someone else). Exercising your rights is free of charge. We respond within 30 days, extendable where the law allows for complex requests, in which case we will tell you why.
10. Visitors from the EEA, UK and Switzerland (GDPR)
If you are located in the European Economic Area, the United Kingdom or Switzerland, all of the rights in section 9 apply to you under the GDPR or its UK and Swiss equivalents, together with the legal bases listed in section 3 and the transfer safeguards in section 6. You additionally have the right to lodge a complaint with your national supervisory authority (in Spain, the Agencia Española de Protección de Datos, www.aepd.es). We would appreciate the chance to resolve any concern directly first, but you are not required to contact us before complaining.
11. US state privacy rights
Growth Foundry LLC is a small New Mexico company and, given its size and data volumes, is generally below the applicability thresholds of state privacy statutes such as the California Consumer Privacy Act (CCPA/CPRA), the Colorado Privacy Act or the Virginia CDPA. We nonetheless honor the spirit of those laws for every visitor: we do not sell personal information, we do not share it for cross-context behavioral advertising, we do not use sensitive personal information beyond what you voluntarily send us, and we will act on access, correction and deletion requests from any US resident submitted to info@joingrowthfoundry.com, without discriminating against you for exercising them.
12. Children
This website addresses businesses and professionals and is not directed to children under 13 (or the higher age applicable in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has submitted personal data through this site, write to info@joingrowthfoundry.com and we will delete it promptly.
13. Third-party links
Pages on this site may link to external websites. Once you leave joingrowthfoundry.com, this policy no longer applies: each destination is governed by its own privacy practices, which we do not control and are not responsible for. Review the privacy policy of any site you visit through an external link.
14. Changes to this policy
We may update this policy when our practices, our infrastructure or the law change. The version in force is always the one published on this page, identified by the effective date shown at the top. If a change materially reduces your rights, we will highlight it visibly on this page for a reasonable period. Substantive changes never apply retroactively to data collected under a previous version without a valid legal basis.
15. Contact
For any privacy matter, request or complaint: GROWTH FOUNDRY LLC, 1209 Mountain Road Pl NE Ste R, Albuquerque, NM 87110, USA — info@joingrowthfoundry.com. We answer privacy correspondence in English and Spanish.