logo
MENU
icon
logo
MENU
icon

Privacy Policy

Privacy Policy

Privacy Policy

Last updated: 15 September 2026

1. Controller

1. Controller

The controller responsible for processing personal data through this website is:

Tsvetoslava Kapatsinova
trading as GrowDACH+
Huttegnasse 5/3
1140 Vienna
Austria
Email: contact@growdach.com
Website: www.growdach.com

2. General information

2. General information

We process personal data in accordance with the General Data Protection Regulation, the Austrian Data Protection Act and the Austrian Telecommunications Act.

We only process personal data where this is necessary to operate our website, analyse its use, respond to enquiries, assess membership applications, manage business relationships, arrange meetings or fulfil legal and contractual obligations.

3. Website hosting through Framer

3. Website hosting through Framer

This website is created and hosted using Framer, a service provided by:

Framer B.V.
Rozengracht 207B
1016 LZ Amsterdam
The Netherlands

When you visit our website, technical information may be processed automatically. This may include your IP address, browser type, device information, operating system, referring website, pages accessed, date and time of access and security related information.

This processing is necessary to display the website correctly, maintain its security and prevent misuse. The legal basis is our legitimate interest under Article 6(1)(f) GDPR.

When Framer processes personal data on our behalf, GrowDACH+ acts as the controller and Framer acts as a processor. Framer may engage subprocessors and may process data outside the European Economic Area. Where required, international transfers are protected through an adequacy decision, Standard Contractual Clauses or another safeguard recognised under the GDPR.

More information is available in the Framer Privacy Statement.

4. Google Analytics

4. Google Analytics

We use Google Analytics 4 to understand how visitors use our website and to improve its content, structure and performance.

Google Analytics is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may also process data through affiliated companies, including Google LLC in the United States.

Google Analytics may process information such as:

  • Pages visited

  • Date and time of the visit

  • Approximate geographic location

  • Referring website

  • Browser and device information

  • Operating system

  • Interaction with website content

  • Session duration and navigation behaviour

Google Analytics uses cookies and similar technologies, including the “_ga” cookie and related Analytics cookies, to distinguish visitors and generate aggregated usage statistics.

For visitors from the European Union, Switzerland and the United Kingdom, Google states that individual IP addresses are used to derive approximate geographic information and are discarded before being logged or stored.

Google Analytics is activated only after you have provided consent through our cookie banner. The legal basis is your consent under Article 6(1)(a) GDPR and the applicable provisions of the Austrian Telecommunications Act.

You may refuse or withdraw your consent at any time through the Cookie Settings available on our website. Withdrawing consent does not affect the lawfulness of processing that occurred before the withdrawal.

Google Analytics cookies may remain on your device for up to two years unless you delete them earlier. User level and event level data within Google Analytics is retained for a maximum of fourteen months. Aggregated statistical reports may be retained for longer because they do not directly identify individual visitors.

Data may be processed in the United States. Where required, transfers are protected through the EU US Data Privacy Framework, Standard Contractual Clauses or another legally recognised safeguard.

We do not use Google Analytics to make solely automated decisions about individual visitors.

More information is available in the Google Privacy Policy and in the Google Analytics privacy information.

5. Membership application form

5. Membership application form

When you submit a membership application, we process the information you provide through the application form. This may include:

  • Your name, business email address and telephone number

  • Your company name, company website and country of headquarters

  • Your industry, team size, annual revenue and funding stage

  • Your plans and objectives for Austria and the DACH market

  • Information about previous market activities

  • Information about customers or partners you want to reach

  • Your expectations regarding a GrowDACH+ membership

  • Information about how you heard about GrowDACH+

We process this information to assess whether your company is a suitable fit for GrowDACH+, respond to your application, arrange an introductory conversation and take steps towards a possible business relationship.

The legal basis is Article 6(1)(b) GDPR, where processing is necessary to take steps at your request before entering into an agreement. We may also rely on our legitimate interest in evaluating potential members and managing business relationships under Article 6(1)(f) GDPR.

Submitting an application does not create a contract or activate a membership. Applications are reviewed personally. We do not use solely automated decision making to accept or reject applications.

Application data may be stored for up to twelve months after our last contact. If a membership or another business relationship is established, relevant information may be retained for the duration of the relationship and for applicable statutory retention periods.

We do not automatically add applicants to a newsletter or marketing distribution list without a separate legal basis or consent.

6. HubSpot CRM

6. HubSpot CRM

We use HubSpot as a customer relationship management system to organise applications, enquiries, contacts and business relationships.

HubSpot services are provided by HubSpot Ireland Limited and HubSpot, Inc.

We may store the following information in HubSpot:

  • Name and professional contact details

  • Company, position and professional role

  • Communication history

  • Membership application information

  • Meeting notes and follow up activities

  • Information about interests, business needs and potential cooperation

  • Membership or customer status

  • Source of the business contact

The information may come directly from you through our website, emails, meetings, events or other communication. We may also receive professional contact information through referrals or publicly available business sources such as company websites and professional platforms.

We use this information to:

  • Process membership applications

  • Respond to enquiries

  • Manage relationships with applicants, members and partners

  • Document business communication

  • Organise meetings and follow up activities

  • Prepare and perform agreements

  • Maintain relevant business contacts

The legal basis is Article 6(1)(b) GDPR where processing relates to a potential or existing agreement. For general business relationship management, the legal basis is our legitimate interest under Article 6(1)(f) GDPR.

We may retain prospective business contact information for up to twenty four months after the last meaningful interaction. Information relating to an active member, customer or partner relationship may be stored for the duration of that relationship and for applicable statutory retention periods.

HubSpot processes customer data on our behalf as a processor. Personal data may be processed in the United States. HubSpot uses recognised transfer mechanisms, including the EU US Data Privacy Framework and Standard Contractual Clauses, where applicable.

More information is available in the HubSpot Privacy Policy and the HubSpot Data Processing Agreement.

We do not send marketing emails solely because a contact has been entered into HubSpot. Marketing communications are sent only where we have consent or another legal basis allowing us to do so. Recipients may unsubscribe at any time.

7. Google Workspace

7. Google Workspace

We may use Google Workspace services, including Gmail, Google Drive and Google Sheets, to receive communications, store applications and manage business information.

These services are provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

The legal basis is Article 6(1)(b) GDPR for precontractual and contractual communication and Article 6(1)(f) GDPR for the secure and efficient organisation of our business activities.

Google may engage subprocessors or process certain information outside the European Economic Area. Where required, international transfers are protected through an adequacy decision, Standard Contractual Clauses or another recognised safeguard.

More information is available in the Google Privacy Policy.

8. Email and direct enquiries

8. Email and direct enquiries

If you contact us by email or another communication channel, we process the contact details and information you provide to respond to your enquiry and manage subsequent communication.

The legal basis is Article 6(1)(b) GDPR where your enquiry concerns a potential or existing agreement. For other enquiries, the legal basis is our legitimate interest in responding to business communications under Article 6(1)(f) GDPR.

We retain correspondence for as long as necessary to process the enquiry and manage the business relationship. Statutory retention obligations may require longer storage.

9. Meeting bookings through Cal.com

9. Meeting bookings through Cal.com

Our website contains links that allow you to arrange an introductory call through Cal.com.

When you book a meeting, information such as your name, email address, selected meeting time, time zone and any information entered in the booking form may be processed.

Cal.com is provided by:

Cal.com, Inc.
2261 Market Street, Suite 4382
San Francisco, California 94114
United States

We use this information to schedule, organise and conduct the requested meeting. The legal basis is Article 6(1)(b) GDPR and our legitimate interest in efficiently organising business appointments under Article 6(1)(f) GDPR.

Cal.com processes booking information on our behalf. Data may be processed in the United States using recognised transfer safeguards.

More information is available in the Cal.com Privacy Policy.

10. Cookies and consent management

10. Cookies and consent management

Our website uses technically necessary cookies and, with your consent, analytics cookies.

Technically necessary cookies are used to operate and secure the website. Where these cookies are strictly necessary, they are processed on the basis of our legitimate interest under Article 6(1)(f) GDPR and the applicable provisions of the Austrian Telecommunications Act.

Google Analytics cookies are only activated after you have provided consent.

You can accept or reject analytics cookies through the cookie banner. You can also withdraw or change your decision at any time through the Cookie Settings available on our website.

Rejecting analytics cookies does not restrict access to the website or the membership application.

11. External links and social media

11. External links and social media

Our website may contain links to external websites and social media platforms, including LinkedIn. When you follow an external link, the respective provider may process personal data according to its own privacy policy.

GrowDACH+ does not control how independent external websites process personal data.

12. Recipients of personal data

12. Recipients of personal data

Personal data may be accessed by authorised persons working with GrowDACH+ where this is necessary for the relevant purpose.

We may also share information with processors providing website hosting, analytics, customer relationship management, cloud storage, email, scheduling or technical support services.

We may disclose information to public authorities, courts or professional advisers where this is required by law or necessary to establish, exercise or defend legal claims.

We do not sell personal data.

13. International data transfers

13. International data transfers

Some service providers may process personal data outside the European Economic Area.

Where no European Commission adequacy decision applies, we use appropriate safeguards such as Standard Contractual Clauses or another legally recognised transfer mechanism.

Further information about the applicable safeguards can be requested by contacting us.

14. Your rights

14. Your rights

Under the GDPR, you may have the right to:

  • Request access to your personal data

  • Request correction of inaccurate or incomplete information

  • Request deletion of your personal data

  • Request restriction of processing

  • Object to processing based on legitimate interests

  • Receive certain information in a structured and machine readable format

  • Withdraw consent at any time where processing is based on consent

To exercise your rights, contact us at contact@growdach.com. We may request appropriate information to verify your identity.

You also have the right to lodge a complaint with:

Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
Website: www.dsb.gv.at
Email: dsb@dsb.gv.at

15. Data security

15. Data security

We take appropriate technical and organisational measures to protect personal data against accidental or unlawful loss, alteration, unauthorised access or disclosure.

Access to personal data is limited to authorised persons and service providers who require it for the relevant purpose.

16. Changes to this Privacy Policy

16. Changes to this Privacy Policy

We may update this Privacy Policy if our website, services, legal obligations or data processing activities change.

The current version will always be available on this website. The date of the latest update is stated at the beginning of this Privacy Policy.