Legal
Privacy policy
Last changed: 28 September 2026
This is a translation of the Dutch privacy policy. In the event of any discrepancy, the Dutch version prevails.
This privacy policy explains which personal data Hello Growth BV processes when you visit our website, fill in the contact form or email us, and when we approach you because your company may be a good fit for us. It also explains why we do so, who we share data with, how long we keep it and what rights you have.
In short
We process the data you give us yourself and the technical data needed to run and secure the website. We use our own statistics, without cookies, to count how the website is used. If you give your consent through the cookie banner, we also use Google Analytics to measure how the website is used, the LinkedIn Insight Tag, Google Ads and the Meta Pixel to measure what our advertising achieves, and Snitcher to recognise which company is visiting us. We also look for companies that suit us, and for the people who work there, in order to approach them. We do not sell data.
Who is responsible
Hello Growth BV is the controller within the meaning of the General Data Protection Regulation (GDPR). We are located at Anton Geesinkstraat 1, 1382 NA Weesp, the Netherlands, and registered with the Dutch Chamber of Commerce under number 94255059. You can reach us at info@hellogrowth.ai.
This policy covers hellogrowth.ai, the contacts that result from it and our own business development. When we process personal data on behalf of a client, for example in a system we build for that client, the client is responsible and we record the arrangements in a data processing agreement. This policy does not cover that processing.
The contact form
When you fill in the contact form, we process your name, email address and message, and, if you provide them, your company name and phone number. We also store how you would like to be contacted (email, phone or video call), which part of the day suits you best, the language you used and when you submitted the form.
We use this data to answer your question and, if you wish, to schedule a conversation. You receive a confirmation by email and we receive a notification in our mailbox. If your question concerns a possible assignment, we process your data to take steps at your request before entering into an agreement (Article 6(1)(b) GDPR). Otherwise, the legal basis is our legitimate interest in answering questions put to us (Article 6(1)(f) GDPR).
Preventing misuse of the form
We want to prevent the form from being misused automatically, for example to send large numbers of messages or confirmation emails. We therefore count how many requests arrive from the same internet address per hour. We do not store your IP address for this: we only store a code derived from it by a one-way calculation (a hash). For the same reason, we count how many confirmations are sent to the same email address per hour. The legal basis is our legitimate interest in a secure and usable website (Article 6(1)(f) GDPR).
Your visit to the website
On every visit, our hosting provider receives the technical data your browser sends, such as your IP address, browser type, the page you request and the time. This data is needed to deliver the page to you, trace faults and fend off attacks. It ends up in server logs that are deleted automatically after a short period. The legal basis is our legitimate interest in a working and secure website (Article 6(1)(f) GDPR).
The fonts on the website are loaded from our own server. Your browser does not connect to Google or any other party for them.
Measuring website visits with our own statistics
We measure ourselves how the website is used: which pages are viewed, roughly for how long, how visitors arrive (for example a search engine, LinkedIn or a campaign link), which buttons and links are clicked and whether the contact form is submitted. We also record the type of device, browser, operating system and country, but no version numbers or screen details. These statistics run on our own website and database; no data goes to any other party.
Without your consent, we place or read nothing on your device for this. To group individual page views into a single visit, our database calculates a one-way code (a hash) from your IP address, your browser details and a secret code that changes every day. We do not store your IP address or browser details themselves. The secret code for a day is deleted the following night, after which not even we can link a code to an internet address. A visit on a later day therefore counts as a new, unrecognisable visitor. The legal basis is our legitimate interest in knowing how our website is used and what our efforts achieve (Article 6(1)(f) GDPR). You can always object; just email us.
If you consent to analytics cookies, we also place a cookie containing a random number (hg_vid), so that we recognise a later visit from the same browser and can see whether visitors return. If you withdraw your consent, we delete that cookie. The legal basis for this is your consent (Article 6(1)(a) GDPR).
If you submit the contact form, we record with your request which source your visit came from, so we can see which channels lead to conversations. We keep data about individual visits for 13 months. After that, we only keep daily totals, without any characteristic of a visitor.
Measuring website visits with Google Analytics
If you consent to analytics cookies through the cookie banner, we use Google Analytics 4 to see how visitors use the website: which pages are viewed, how far people scroll, which links are clicked and whether forms are submitted. For this, Google Analytics places cookies containing a random number, so that a later visit from the same device is recognised. Google Analytics does not store your IP address.
We have concluded a data processing agreement with Google, we have switched off data sharing with Google for its own purposes and we do not link Google Analytics to other Google services. We only use the figures to improve the website. The legal basis is your consent (Article 6(1)(a) GDPR).
Advertising on LinkedIn
If you consent to marketing cookies through the cookie banner, we load the LinkedIn Insight Tag. It lets us measure whether people who click on our LinkedIn ads go on to, for example, fill in the contact form. It also lets us show ads to people who have visited our website before. To do this, LinkedIn links your visit to your LinkedIn account, if you have one. We do not see names: we only receive totals and overviews by group, such as job function or industry.
We and LinkedIn Ireland Unlimited Company are jointly responsible for collecting and transmitting this data. What LinkedIn does with the data afterwards is LinkedIn’s responsibility; please read LinkedIn’s privacy policy for that. In your LinkedIn settings, you can also indicate that you do not want to see ads based on your website visits. The legal basis is your consent (Article 6(1)(a) GDPR).
Advertising through Google and Meta
If you consent to marketing cookies, we also load Google Ads and the Meta Pixel. They let us measure whether people who click on our ads in Google or on Facebook and Instagram go on to, for example, submit the contact form, and let us show ads to people who have visited our website before. Google and Meta place cookies for this and may link your visit to your account with them, if you have one. We only see totals, not names.
What Google and Meta do with the data afterwards is their own responsibility; please read their privacy policies for that. The legal basis is your consent (Article 6(1)(a) GDPR).
Recognising which company visits us
If you consent to marketing cookies, we also load Snitcher. That service looks up which company belongs to your IP address, so we can see which organisations view our website and which pages they read. We see the company name, not who you are: it does not give us your name or email address. Snitcher places storage in your browser so a visit can be linked to an earlier one.
Snitcher B.V. processes this data on our behalf and on our instructions; we have a data processing agreement for it. If you work from home or over a mobile connection, the lookup usually returns no company. The basis is your consent (Article 6(1)(a) GDPR).
Approaching companies that suit us
We actively look for companies that are a good fit for our services. To do so, we collect data about companies and the people who work there, mainly from public sources such as company websites, the Dutch Chamber of Commerce’s Business Register and LinkedIn. We sometimes use services that supplement business contact details. This concerns business data: your name, job title, the organisation you work for, your business email address and phone number, and the link to your public LinkedIn profile.
Partly with the help of software, we assess whether a company fits what we do, for example based on its industry, size and the systems it uses. That assessment concerns the company, not you as a person. If a company fits, we may contact the people there who deal with these kinds of topics, by email, phone or through LinkedIn.
The legal basis is our legitimate interest in bringing our services to the attention of companies that may benefit from them (Article 6(1)(f) GDPR). We limit ourselves to business data related to your role. When we contact you, we tell you in our first message where we obtained your data and how you can let us know that you do not want to be contacted again.
If you no longer want to be contacted by us, please let us know. We will stop immediately and delete your data. We only keep your name and email address on a list of people we no longer contact, so that we do not accidentally add you again.
Logging in
The login page is only intended for people who have been given an account by Hello Growth BV. For such an account, we process your email address and password. We do not store the password in readable form, only as a hash. If you log in with Google or LinkedIn, we receive your name, email address and possibly your profile picture from that party. Google and LinkedIn are responsible for their own processing of your data. The legal basis is the agreement or collaboration for which you use the account (Article 6(1)(b) GDPR).
Applying for a job
If you respond to a vacancy by email or sign up as a freelancer, we only use your data to assess your application and to contact you. We keep it until four weeks after the procedure has ended. If we would like to keep it longer because a position may open up later, we first ask for your consent, and we then keep it for no more than one year.
Cookies and storage on your device
On your first visit, we use a cookie banner to ask whether you accept analytics and marketing cookies. We do not place them without your consent. You can change or withdraw your choice at any time through Cookie preferences at the bottom of every page. The cookie banner also shows exactly which cookies we use and how long they are kept.
Analytics cookies come from Google Analytics and from our own statistics, and are used to measure how the website is used. Marketing cookies come from LinkedIn, Google Ads, Meta and Snitcher. The LinkedIn, Google Ads and Meta ones are used to measure the effect of our ads and to show ads to previous visitors; the Snitcher ones to recognise which company is visiting us.
Functional cookies and storage do not require consent, because the website does not work properly without them. We remember your choice in the cookie banner. If you log in, you receive session cookies, which disappear when you log out or when the session expires. And your browser keeps a copy of pages and images you have viewed (through a so-called service worker), so that the website loads faster and also works without an internet connection. This copy contains no personal data, and pages behind the login are never stored.
Who we share data with
We do not sell or rent personal data. We do work with service providers that process data on our behalf. We have agreed with them on security and confidentiality, and they may not use the data for their own purposes. These are:
Supabase, for storing contact requests, login accounts and our data about companies and contact persons. The database is located in Ireland.
Microsoft, for our email and the confirmations the form sends (Microsoft 365).
Vercel, for hosting the website.
Google, for Google Analytics, only if you have consented to it.
Snitcher, which looks up from the IP address which company is visiting our website, only if you have consented to it.
Services we use to collect, supplement and process data about companies and business contacts.
For the LinkedIn Insight Tag and the Meta Pixel, LinkedIn and Meta are not our service providers but jointly responsible with us for collecting and transmitting the data. Beyond that, we only disclose data where the law requires us to, for example in response to a lawful request from a supervisory authority or the police.
Transfers outside the European Union
Supabase, Microsoft, Vercel, Google, Meta and LinkedIn are American companies or belong to an American group. Even when data is stored in Europe, it may be processed from the United States, for example for maintenance or support. The same may apply to other service providers. We ensure that such transfers comply with the GDPR: on the basis of the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the basis of the European Commission’s standard contractual clauses. If you would like to know which safeguard applies to which party, please email us.
How long we keep data
We keep contact requests and the emails about them for up to two years after the last contact. This allows us to find an earlier conversation if you get in touch with us again later. If your question leads to an assignment, we keep the data needed for it for as long as we work together. Data that ends up in our accounts, such as invoices, we keep for seven years because the law requires it.
We delete data about companies and contact persons that we have collected ourselves no later than one year after collecting it if there has been no contact, and no later than two years after the last contact. If you ask us not to contact you again, we delete it immediately, apart from the entry on our list.
Data in Google Analytics is deleted automatically after 14 months. We delete data about individual visits in our own statistics after 13 months; the secret code behind the visitor hash after just one day. The cookie banner shows how long cookies remain on your device. The code we use to count requests per internet address is deleted together with the request. Server logs are deleted automatically after a short period. We delete a login account as soon as you no longer need access. For job applications, the periods under Applying for a job apply.
Security
We take appropriate technical and organisational measures to protect your data against loss and unlawful use. The connection to the website is encrypted (https). Contact requests and data about companies and contact persons can only be viewed by Hello Growth BV staff who are logged in, and only people who need access to our systems have it. If you think something is wrong with the security of your data, please let us know immediately at info@hellogrowth.ai.
Your rights
You have the right to access your data and to have it corrected or erased. You can also ask us to restrict the processing of your data or to receive it in a common file format. Where we process your data on the basis of our legitimate interest, you can object to that. You can always object to the use of your data to contact you; we will then stop immediately. If you have given consent, for example for cookies, you can withdraw it at any time.
Send your request to info@hellogrowth.ai or by post to Hello Growth BV, Anton Geesinkstraat 1, 1382 NA Weesp, the Netherlands. We respond within one month. If we are unsure whether a request really comes from you, we may ask you to confirm who you are. Please do not send us a copy of your passport or identity card for this.
If you disagree with how we handle your data, please let us know first so we can look for a solution together. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your own country.
Automated decisions
We do not make decisions about you that are taken solely by a computer and that have legal or similarly significant effects on you. The assessment of whether a company suits us concerns the company and only determines whether we get in touch.
Links to other websites
Our website contains links to other websites, such as LinkedIn. This privacy policy does not apply to those websites. Please read the privacy policy of the party concerned.
Changes
If the way we work changes, we update this policy. The date of the last change is shown at the top.
Contact
Do you have questions about this privacy policy or about your data? Email us at info@hellogrowth.ai.