Legal
GrowthMate Subprocessor List
GrowthMate Subprocessor List
Effective date: 24 July 2026 Last updated: 24 July 2026
This Subprocessor List identifies third-party service providers used to operate GrowthMate and explains the purposes for which they may process personal data or Customer Data.
GrowthMate is operated by:
QOPTERVZN INFOCOM PRIVATE LIMITED
Plot No. 19, At – Khokarla Balaji Nagar, Behind Bhaiyaji Nagar Bhupali Duplex Bhandara, Maharashtra India – 441904
In this Subprocessor List:
- “GrowthMate,” “we,” “us” or “our” means QOPTERVZN INFOCOM PRIVATE LIMITED.
- “Customer” means a person or organization using GrowthMate.
- “Customer Data” means information submitted, connected, imported, generated or otherwise processed through a GrowthMate Workspace.
- “Personal Data” means information relating to an identified or reasonably identifiable individual.
- “Subprocessor” means a third party engaged by GrowthMate to process Customer Data on GrowthMate’s behalf when GrowthMate acts as a processor or Data Processor.
- “Service Provider” includes third parties that may act as a processor, independent controller, Data Fiduciary, joint controller or other legally recognized role depending on the service and applicable terms.
- “Connected Platform” means an external service connected by a Customer, including Google Analytics, Google Search Console, Google Ads or Umami.
- “AI Model Provider” means a third-party provider whose artificial-intelligence model is accessed through OpenRouter.
This Subprocessor List should be read together with the GrowthMate Privacy Policy, Terms of Service, Cookie Policy, Data Processing Agreement, Data Deletion Instructions and Google API Data-Use Disclosure.
1. GrowthMate’s processing roles
GrowthMate may act as a Data Fiduciary, controller or business in relation to:
- account registration;
- authentication;
- billing;
- customer communications;
- product analytics;
- security;
- GrowthMate’s own advertising;
- legal compliance; and
- administration of the Services.
GrowthMate may act as a Data Processor, processor or service provider when processing Customer Data on behalf of a Customer, including:
- connected website analytics;
- Google Search Console data;
- Google Ads data;
- Umami data;
- reports;
- recommendations;
- implementation briefs;
- action-management records; and
- other information submitted or connected by a Customer.
A provider’s legal role may vary depending on the relevant product, processing purpose and contractual arrangement.
The inclusion of a provider in this list does not mean that every provider receives every category of Personal Data or Customer Data.
GrowthMate limits disclosures to information reasonably necessary for the relevant purpose.
2. Core infrastructure subprocessors
2.1 MilesWeb
Provider: MilesWeb Internet Services Private Limited and applicable affiliates
Services provided:
- cloud hosting;
- server infrastructure;
- website and application hosting;
- database hosting;
- file storage;
- networking;
- backups;
- server administration; and
- infrastructure support.
Purpose of processing:
MilesWeb provides infrastructure used to operate the GrowthMate Website, Application, databases, integrations, reports, recommendations and related services.
Data that may be processed:
- account identifiers;
- user profiles;
- Workspace information;
- business information;
- connected analytics data;
- connected search-performance data;
- connected advertising data;
- generated reports;
- recommendations;
- implementation briefs;
- action records;
- encrypted integration credentials;
- application logs;
- security logs;
- support information; and
- technical information.
Categories of individuals:
- GrowthMate account holders;
- Customer team members;
- Workspace administrators;
- report recipients;
- specialists assigned to actions;
- individuals represented in Customer Data; and
- website visitors whose data appears in connected analytics systems.
Processing locations:
MilesWeb may process or store data in the hosting location selected and configured by GrowthMate, together with locations used for authorized infrastructure support, network delivery, security and backups.
Safeguards:
GrowthMate applies or requires appropriate safeguards including:
- access controls;
- encryption in transit;
- protection of stored credentials;
- tenant separation;
- restricted administrative access;
- logging;
- monitoring;
- backups;
- confidentiality obligations; and
- deletion procedures.
2.2 PostHog
Provider: PostHog, Inc. and applicable affiliates
Services provided:
- product analytics;
- feature-usage measurement;
- conversion-funnel analysis;
- feature flags;
- error monitoring;
- application-performance analysis; and
- landing-page session replay.
Purpose of processing:
PostHog helps GrowthMate understand how users interact with the Services, identify product errors, evaluate onboarding and feature adoption, improve user experience and monitor product performance.
Data that may be processed:
- pseudonymous browser or device identifiers;
- opaque internal user identifiers;
- opaque Workspace identifiers;
- pages and screens viewed;
- product events;
- feature interactions;
- onboarding activity;
- report and recommendation interaction events;
- subscription-plan category;
- user-role category;
- browser type;
- device type;
- operating system;
- approximate location;
- IP address;
- error category;
- application version;
- feature-flag exposure; and
- masked landing-page session information.
Session-replay scope:
PostHog session replay may be enabled only on the public GrowthMate landing page available through growthmate.net.
Session replay is not enabled inside the authenticated GrowthMate Application available through app.growthmate.net.
Data GrowthMate does not intentionally send to PostHog:
- passwords;
- OAuth access tokens;
- OAuth refresh tokens;
- API keys;
- complete payment-card information;
- connected Customer reports;
- complete report text;
- complete recommendation text;
- implementation-brief contents;
- raw Google Ads search terms;
- raw Search Console query contents;
- customer campaign names;
- complete connected analytics datasets;
- private user notes; or
- confidential Customer Data not required for product analytics.
Consent controls:
Where consent is required, PostHog analytics and session replay operate only after the user grants the applicable analytics consent.
Processing locations:
Data may be processed in the PostHog Cloud region selected and configured by GrowthMate and in locations used by PostHog’s authorized subprocessors.
Safeguards:
GrowthMate configures PostHog to:
- mask sensitive landing-page form fields;
- exclude passwords and authentication credentials;
- avoid session recording inside the authenticated Application;
- use opaque user and Workspace identifiers;
- respect consent and opt-out preferences;
- separate production and testing environments;
- restrict authorized access;
- apply retention limits; and
- minimize the information included in analytics events.
2.3 Brevo
Provider: Brevo and applicable affiliated entities
Services provided:
- transactional email;
- authentication messages;
- security notifications;
- report delivery;
- account communications;
- customer-support communications;
- billing communications; and
- consented marketing email.
Purpose of processing:
Brevo is used to send and manage communications requested by or relevant to GrowthMate users.
Data that may be processed:
- recipient name;
- email address;
- account identifier;
- Workspace information;
- email subject;
- email content;
- report-delivery information;
- delivery status;
- bounce information;
- unsubscribe status;
- email-open information where enabled and permitted;
- link-interaction information where enabled and permitted;
- IP address; and
- technical delivery information.
Data GrowthMate does not intentionally send through Brevo:
- passwords;
- complete payment-card information;
- OAuth credentials;
- API keys;
- unnecessary raw connected-platform data; or
- sensitive personal information unrelated to the communication.
Processing locations:
Brevo may process data in the European Economic Area and in other locations used by its authorized subprocessors, subject to applicable transfer safeguards.
Safeguards:
GrowthMate uses Brevo subject to:
- access restrictions;
- contractual confidentiality;
- data-processing terms;
- unsubscribe controls;
- suppression lists;
- restricted account access; and
- lawful international-transfer mechanisms where required.
3. Artificial-intelligence subprocessors
3.1 OpenRouter
Provider: OpenRouter, Inc. and applicable affiliates
Services provided:
- access to artificial-intelligence models;
- AI model routing;
- model-provider selection;
- model fallback;
- AI request processing;
- usage measurement;
- model availability management; and
- related AI infrastructure.
Purpose of processing:
GrowthMate uses OpenRouter to access artificial-intelligence models for functions including:
- explaining structured analytical findings;
- creating plain-language business summaries;
- generating role-specific implementation briefs;
- summarizing recommendations;
- categorizing or formatting information;
- improving report readability;
- assisting with customer support; and
- other user-facing AI features.
AI models used:
GrowthMate may use any suitable AI model made available through OpenRouter.
The model used for a particular request may vary according to:
- feature requirements;
- output quality;
- model capability;
- availability;
- processing speed;
- cost;
- safety;
- context limits;
- language support;
- data-handling requirements; and
- service reliability.
GrowthMate does not guarantee that the same AI model or AI Model Provider will be used for every request.
Downstream AI Model Providers:
OpenRouter routes requests to third-party AI Model Providers. These providers may include, without limitation:
- OpenAI;
- Anthropic;
- Google;
- Meta;
- Mistral AI;
- xAI;
- Microsoft;
- Amazon;
- Cohere;
- DeepSeek;
- Qwen;
- Perplexity;
- NVIDIA;
- Together AI;
- Fireworks AI;
- Groq;
- other commercial AI providers;
- open-model hosting providers; and
- additional providers made available through OpenRouter.
The specific downstream AI Model Provider used may vary from one request to another.
Each AI Model Provider may have its own terms, processing locations, security measures, logging practices, retention periods and model-training policies. OpenRouter provides routing controls for provider data collection and Zero Data Retention, while individual provider practices may differ.
Data that may be processed:
Depending on the requested feature, OpenRouter and the selected AI Model Provider may process:
- structured analytical findings;
- metric names;
- metric values;
- comparison periods;
- recommendation categories;
- recommendation priority;
- responsible-role categories;
- summarized evidence;
- business context supplied by the Customer;
- user instructions;
- report sections;
- implementation-brief inputs;
- generated text;
- model-selection metadata;
- token usage;
- timestamps;
- request identifiers; and
- technical processing information.
Data minimization:
GrowthMate limits information submitted through OpenRouter to information reasonably necessary to generate the requested output.
Where reasonably possible, GrowthMate submits:
- structured findings instead of complete raw datasets;
- aggregated values instead of individual-level records;
- opaque identifiers instead of names;
- category labels instead of confidential descriptions;
- selected evidence instead of complete reports; and
- sanitized content instead of unrestricted database records.
Data GrowthMate does not intentionally submit through OpenRouter:
- passwords;
- OAuth access tokens;
- OAuth refresh tokens;
- Google authorization codes;
- API keys;
- complete payment-card details;
- CVV codes;
- bank credentials;
- authentication cookies;
- private cryptographic keys;
- complete raw Google Analytics exports;
- complete raw Google Search Console exports;
- complete raw Google Ads exports;
- unnecessary Google Ads search terms;
- unnecessary Search Console query contents;
- complete Customer databases;
- government-identification documents;
- sensitive health information;
- biometric information;
- children’s personal data;
- information unrelated to the requested AI output; or
- other information prohibited by law or applicable platform policies.
OpenRouter prompt and response settings:
GrowthMate does not intentionally enable optional OpenRouter prompt or response logging for production Customer Data.
GrowthMate does not intentionally opt in to the use of Customer prompts and outputs for OpenRouter product improvement or generalized model training.
Where supported and appropriate, GrowthMate may configure OpenRouter requests to:
- deny routing to providers that use inputs for model training;
- require Zero Data Retention endpoints;
- restrict requests to approved providers;
- disable unnecessary fallback providers;
- apply provider-specific restrictions; and
- limit the use of models that do not meet GrowthMate’s data-protection requirements.
OpenRouter states that it does not retain prompts and responses unless optional prompt logging is enabled, but downstream AI Model Providers may have separate data-handling practices.
Models without Zero Data Retention:
Where a selected model or provider does not offer Zero Data Retention, GrowthMate may:
- avoid sending confidential Customer Data;
- use only minimized and structured information;
- remove direct identifiers;
- select a different model;
- select a different endpoint;
- disable the affected model for sensitive features; or
- apply other safeguards appropriate to the processing risk.
Human review:
AI-generated outputs may be incomplete, inaccurate or unsuitable for a particular use.
GrowthMate may apply automated validation and human review where appropriate, but Customers remain responsible for reviewing AI-generated recommendations before:
- modifying a website;
- changing an advertising campaign;
- changing a budget;
- implementing SEO changes;
- making financial decisions;
- communicating claims to third parties; or
- taking another material business action.
Processing locations:
OpenRouter and downstream AI Model Providers may process requests in the United States, European Union, India or other countries depending on:
- the selected model;
- the selected provider;
- the selected endpoint;
- routing settings;
- provider availability;
- regional infrastructure; and
- account configuration.
Legal role:
OpenRouter generally acts as GrowthMate’s AI routing and processing service provider.
The selected AI Model Provider may act as:
- a subprocessor;
- an independent service provider;
- an independent controller in limited circumstances; or
- another role determined by its terms and the relevant processing activity.
Safeguards:
GrowthMate applies or requires safeguards including:
- data minimization;
- input sanitization;
- removal of credentials;
- restricted API-key access;
- server-side API calls;
- provider-selection controls;
- model-policy review;
- access logging;
- separation of Customer Data from GrowthMate advertising data;
- contractual data-processing protections;
- international-transfer safeguards where required; and
- retention and deletion controls.
4. Payment service provider
4.1 Razorpay
Provider: Razorpay Software Private Limited and applicable Razorpay entities
Services provided:
- payment processing;
- subscription payments;
- recurring-payment mandates;
- payment authentication;
- payment confirmation;
- refunds;
- invoices;
- payment-risk management; and
- fraud prevention.
Purpose of processing:
Razorpay processes payments for GrowthMate subscriptions and related purchases.
Data that may be processed:
- billing name;
- email address;
- telephone number;
- billing address;
- business information;
- tax information;
- GST information;
- transaction amount;
- currency;
- payment method;
- subscription status;
- payment status;
- invoice information;
- device information;
- IP address; and
- fraud-prevention information.
Sensitive payment information:
Complete payment-card numbers, CVV codes, bank authentication credentials and equivalent sensitive payment information are processed by Razorpay and are not intended to be stored by GrowthMate.
Legal role:
Razorpay may act as:
- an independent Data Fiduciary or controller for regulated payment, fraud-prevention and compliance purposes; and
- a processor or service provider for certain payment functions performed on GrowthMate’s instructions.
Processing locations:
Razorpay may process information in India and in other locations used by its authorized payment-network, banking, fraud-prevention and infrastructure providers.
Safeguards:
GrowthMate limits the billing information it retains to information necessary for:
- subscription management;
- invoicing;
- refunds;
- accounting;
- tax compliance;
- fraud prevention; and
- dispute resolution.
5. Google services
Google may act as a connected-platform provider, processor, independent controller, advertising provider or service provider depending on the applicable Google product.
5.1 Google OAuth and Google APIs
Provider: Google LLC and applicable Google affiliates
Services provided:
- Google account authorization;
- OAuth authentication;
- Google Analytics APIs;
- Google Search Console APIs;
- Google Ads APIs; and
- connected-account discovery.
Purpose of processing:
Google APIs allow Customers to authorize GrowthMate to retrieve and analyze information from their selected Google accounts and properties.
Data that may be processed:
- Google account identifier;
- authorization scopes;
- authorization status;
- Google Analytics account and property information;
- Google Search Console property information;
- Google Ads customer-account information;
- website analytics;
- search-performance data;
- campaign data;
- advertising costs;
- conversion data;
- revenue values;
- account metadata; and
- synchronization information.
GrowthMate’s use of connected Google data:
GrowthMate uses connected Google data only to:
- provide the requested integration;
- display reports;
- analyze performance;
- generate recommendations;
- create implementation briefs;
- identify data-quality issues;
- compare connected sources;
- monitor outcomes; and
- provide support requested by the Customer.
Connected Google data is not used to:
- advertise GrowthMate;
- create GrowthMate remarketing audiences;
- create GrowthMate Customer Match audiences;
- build unrelated advertising profiles;
- sell personal information;
- provide data to data brokers; or
- provide unrelated services without authorization.
Processing locations:
Google may process information through its global infrastructure.
5.2 Google Analytics
Provider: Google LLC and applicable Google affiliates
Services provided:
- website analytics;
- acquisition measurement;
- conversion measurement;
- product analytics; and
- marketing attribution.
Purpose of processing:
Google Analytics helps GrowthMate understand visits, engagement, signup journeys, conversions and product usage.
Data that may be processed:
- cookie identifiers;
- device identifiers;
- IP address;
- approximate location;
- browser information;
- device information;
- operating system;
- page visits;
- referring source;
- campaign attribution;
- interaction events;
- signup events;
- checkout events; and
- subscription events.
Consent category: Analytics
Where prior consent is required, Google Analytics operates only after analytics consent has been granted.
Data GrowthMate does not intentionally send to Google Analytics:
- passwords;
- OAuth credentials;
- complete payment-card information;
- sensitive personal information;
- complete Customer reports;
- raw connected Google Ads data;
- raw Search Console data; or
- URLs containing secret tokens.
5.3 Google Ads, remarketing and Customer Match
Provider: Google LLC and applicable Google affiliates
Services provided:
- Google Ads conversion measurement;
- Google Ads remarketing;
- enhanced conversions;
- Customer Match;
- advertising attribution; and
- GrowthMate advertising.
Purpose of processing:
Google Ads is used to measure GrowthMate advertising and reach eligible users who have interacted with GrowthMate or directly provided information to GrowthMate.
Data that may be processed:
- advertising identifiers;
- cookie identifiers;
- IP address;
- browser and device information;
- page visits;
- advertising campaign information;
- signup events;
- checkout events;
- subscription events;
- consent signals; and
- eligible first-party contact information.
Consent category: Advertising
Where prior consent is required, Google Ads advertising technologies operate only after advertising consent has been granted.
Customer Match data:
GrowthMate may use first-party contact information directly supplied to GrowthMate for Customer Match where:
- GrowthMate has an appropriate lawful basis;
- required consent has been obtained;
- the user has not opted out;
- the information was not obtained from connected Customer accounts;
- the information is not sensitive; and
- the use complies with applicable Google requirements.
GrowthMate does not upload the following to Customer Match:
- Customer-connected Google Analytics data;
- Customer-connected Search Console data;
- Customer-connected Google Ads data;
- Customer campaign information;
- Customer search terms;
- generated Customer reports;
- Customer recommendations;
- implementation briefs;
- OAuth credentials;
- children’s data; or
- sensitive personal information.
6. Meta and WhatsApp services
6.1 WhatsApp Business Platform
Provider: Meta Platforms, Inc., WhatsApp LLC and applicable affiliates
Services provided:
- WhatsApp Business messaging;
- transactional notifications;
- report delivery;
- support communications;
- account notifications; and
- consented marketing messages.
Purpose of processing:
WhatsApp may be used to deliver requested reports, service messages, alerts, support responses and permitted promotional communications.
Data that may be processed:
- telephone number;
- recipient name;
- message content;
- message template;
- delivery status;
- read status;
- communication preference;
- opt-out status;
- device information; and
- communication metadata.
Marketing communications:
Non-essential WhatsApp marketing messages are sent only where GrowthMate has an appropriate legal basis and required permission.
Recipients may opt out using the method provided in the message or by contacting GrowthMate.
Data GrowthMate does not intentionally send through WhatsApp:
- passwords;
- OAuth credentials;
- API keys;
- complete payment-card information; or
- unnecessary confidential Customer Data.
6.2 Meta Business Tools
Provider: Meta Platforms, Inc. and applicable affiliates
Services provided:
- Meta Pixel;
- Meta Conversions API;
- advertising conversion measurement;
- campaign attribution;
- remarketing;
- website custom audiences; and
- customer-list custom audiences.
Purpose of processing:
Meta Business Tools may be used to measure GrowthMate advertising and reach eligible audiences.
Data that may be processed:
- Meta cookie identifiers;
- advertising identifiers;
- IP address;
- browser and device information;
- page visits;
- signup events;
- checkout events;
- subscription events;
- advertising campaign information;
- consent information; and
- eligible first-party contact information.
Consent category: Advertising
Where prior consent is required, Meta advertising technologies operate only after advertising consent has been granted.
Data GrowthMate does not intentionally share with Meta for advertising:
- connected Google Analytics data;
- connected Google Search Console data;
- connected Google Ads data;
- connected Umami data;
- Customer campaign names;
- Customer search terms;
- generated Customer reports;
- recommendation text;
- implementation briefs;
- OAuth credentials;
- passwords;
- complete payment information; or
- confidential Customer business information.
7. Connected platforms
Customers may connect external services to GrowthMate.
Connected platforms may include:
- Google Analytics;
- Google Search Console;
- Google Ads;
- Umami;
- Meta products;
- customer-selected analytics systems; and
- future services selected by the Customer.
A Connected Platform may not be a GrowthMate subprocessor where:
- the Customer has a direct account with the provider;
- the Customer independently accepted the provider’s terms;
- the provider determines its own processing purposes;
- the provider independently controls account data; or
- the Customer separately directs the platform to disclose data to GrowthMate.
Customers are responsible for:
- having authority to connect the platform;
- using an authorized account;
- complying with the platform’s terms;
- providing required privacy notices;
- obtaining required consent; and
- ensuring the connection complies with applicable law.
8. Information excluded from GrowthMate advertising
GrowthMate does not intentionally use or disclose the following for GrowthMate’s own advertising, remarketing, Customer Match or custom-audience activities:
- Customer-connected Google Analytics information;
- Customer-connected Search Console information;
- Customer-connected Google Ads information;
- Customer-connected Umami information;
- Customer website analytics rows;
- Customer advertising search terms;
- Customer campaign names;
- Customer revenue reports;
- generated recommendations;
- implementation briefs;
- action notes;
- OAuth access tokens;
- OAuth refresh tokens;
- account passwords;
- API keys;
- complete payment credentials; or
- confidential Customer business information.
GrowthMate’s advertising audiences are based only on eligible first-party information collected directly through GrowthMate’s own Website, Application, subscription process and communications.
9. Provider-selection requirements
Before permitting a provider to process production Customer Data, GrowthMate considers factors including:
- processing purpose;
- categories of data;
- confidentiality;
- security practices;
- access controls;
- breach-notification obligations;
- deletion capabilities;
- retention practices;
- processing locations;
- international-transfer safeguards;
- use of further subprocessors;
- audit information;
- service reliability;
- legal compliance;
- AI model-training practices;
- AI prompt-retention practices; and
- compatibility with applicable Google, Meta and other platform policies.
GrowthMate may restrict or discontinue use of a provider that no longer meets its legal, security, privacy or operational requirements.
10. Obligations imposed on subprocessors
Where GrowthMate appoints a provider as a subprocessor, GrowthMate requires appropriate contractual or equivalent protections addressing:
- processing only for authorized purposes;
- compliance with documented instructions;
- confidentiality;
- reasonable security safeguards;
- restricted personnel access;
- incident notification;
- assistance with privacy-rights requests;
- assistance with deletion;
- applicable data-protection law;
- international data transfers;
- use of further subprocessors;
- data return or deletion; and
- information reasonably necessary to demonstrate compliance.
GrowthMate remains responsible for its own obligations to Customers under an applicable Data Processing Agreement.
11. International transfers
Some providers may process Personal Data or Customer Data outside India or outside the Customer’s country.
Where required, GrowthMate may use safeguards including:
- data-processing agreements;
- contractual data-protection clauses;
- European Commission Standard Contractual Clauses;
- the United Kingdom International Data Transfer Addendum;
- adequacy decisions;
- regional processing;
- transfer-risk assessments;
- encryption;
- data minimization;
- access restrictions; and
- other lawful transfer mechanisms.
The applicable transfer safeguard depends on:
- the Customer’s location;
- the individuals represented in the data;
- the provider;
- the processing location;
- the service configuration; and
- applicable law.
12. Security incidents involving providers
If GrowthMate becomes aware of a qualifying security incident involving a provider, GrowthMate will take reasonable steps to:
- investigate the incident;
- obtain information from the provider;
- contain the incident;
- assess affected information;
- mitigate potential harm;
- preserve relevant records;
- notify affected Customers where required;
- notify authorities where required; and
- implement appropriate remediation.
A provider security incident does not necessarily mean that Customer Data was accessed or compromised.
13. Addition or replacement of subprocessors
GrowthMate may add, replace or remove providers as the Services develop.
Where required by an applicable Data Processing Agreement, GrowthMate will provide reasonable advance notice before appointing a material new subprocessor that will process Customer Data.
The notice may identify:
- provider name;
- service provided;
- processing purpose;
- categories of data;
- processing location or region; and
- expected appointment date.
Advance notice may not be possible where an immediate change is reasonably necessary to:
- respond to a security incident;
- maintain service availability;
- replace a failed provider;
- comply with law;
- comply with a regulator’s direction;
- preserve Google or Meta platform access;
- address an urgent provider restriction; or
- prevent material harm.
In such circumstances, GrowthMate will provide notice as soon as reasonably practicable where required.
Because OpenRouter may dynamically route requests between approved AI Model Providers, the specific downstream AI Model Provider may change between requests without an individual notice for each request.
GrowthMate treats OpenRouter and its approved AI Model Provider network as a disclosed AI-processing category and applies provider-selection, data-minimization and routing controls appropriate to the information being processed.
14. Objections to a new subprocessor
A Customer that has entered into an applicable Data Processing Agreement may object to a material new subprocessor on reasonable and documented data-protection grounds.
Objections must be sent to:
The objection should include:
- Customer name;
- Workspace information;
- name of the relevant provider;
- specific data-protection concern;
- supporting information; and
- proposed resolution.
GrowthMate and the Customer will attempt in good faith to resolve a valid objection.
Possible resolutions may include:
- additional safeguards;
- limiting information disclosed;
- changing the processing region;
- selecting a different provider;
- disabling the affected feature;
- restricting particular AI models;
- using a different AI Model Provider; or
- ending the affected service in accordance with the applicable agreement.
15. Provider removal and data deletion
When GrowthMate stops using a provider, GrowthMate takes reasonable steps to:
- disable access;
- revoke credentials;
- terminate integrations;
- remove API keys;
- request return or deletion of Customer Data;
- retain only legally required records;
- complete applicable backup cycles; and
- update this Subprocessor List.
Information may remain temporarily in restricted provider backups until overwritten according to the provider’s applicable backup-retention cycle.
16. Customer responsibilities
Customers are responsible for:
- reviewing this Subprocessor List;
- providing required privacy notices;
- having a lawful basis for Customer Data;
- obtaining required consent;
- controlling Workspace access;
- connecting only authorized accounts;
- not submitting prohibited sensitive information;
- reviewing AI-generated output;
- configuring Customer-controlled integrations lawfully;
- responding to privacy requests relating to Customer Data; and
- informing GrowthMate of material legal or contractual restrictions applicable to their data.
Customers should not use GrowthMate for data subject to specialized localization, healthcare, financial, government, children’s-data or other sector-specific restrictions unless GrowthMate has expressly agreed in writing to support the applicable requirements.
17. Changes to this Subprocessor List
GrowthMate may update this Subprocessor List to reflect:
- new providers;
- provider replacements;
- discontinued providers;
- new processing purposes;
- changes in AI models;
- changes in infrastructure;
- changes in processing locations;
- legal requirements;
- security requirements; or
- changes to the Services.
The current version will be published with its effective date and last-updated date.
18. Contact information
Questions, objections or requests concerning GrowthMate’s providers may be sent to:
QOPTERVZN INFOCOM PRIVATE LIMITED
Plot No. 19, At – Khokarla Balaji Nagar, Behind Bhaiyaji Nagar Bhupali Duplex Bhandara, Maharashtra India – 441904
Privacy email: [email protected]
Grievance Officer: Alok Diwate Director [email protected]
Website: https://growthmate.net
Application: https://app.growthmate.net