Data processing agreement
Version 1.0 - effective 7 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of service between TMR Digital Ltd (company number 15550089, registered office 60 Tottenham Court Road, Suite 4387a, Fitzrovia, London, W1T 2EW, United Kingdom), trading as Growth Bull ("we", "us", the "Processor"), and the business or agency holding the account (the "Controller", "you"). It applies whenever we process personal data about your customers on your behalf, and it is the written contract required by Article 28(3) of the UK GDPR (and, where it applies, the EU GDPR). Words like "personal data", "processing", "controller", "processor" and "personal data breach" have their GDPR meanings.
Where an agency holds the account and adds its own clients, each client business is the Controller of its customers' data, the agency is our customer and a processor for that business, and we act as the agency's sub-processor on these same terms. The agency is responsible for passing these terms on to its clients.
1. Instructions
We process your customers' personal data only on your documented instructions. Your instructions are: this DPA, the settings you choose in the app (which jobs create requests, the message wording, timing and reminders), the customer lists you connect or upload, and any written instruction you send to hello@growthbull.io. We will tell you at once if we believe an instruction breaks data protection law. We never use your customers' details for our own purposes, never sell or share them, and never contact them except with the review invitations you have set up.
2. Confidentiality
Everyone we authorise to process personal data is bound by a duty of confidence. Staff access to raw customer contact details is masked in our administration screens and logs; only what is needed to diagnose a delivery problem is shown.
3. Security
We take the technical and organisational measures in Annex C, appropriate to the risk: encryption in transit and at rest, encrypted backups, keyed hashing of contact details once they are no longer needed in the clear, least-privilege access, signed webhooks and a published retention schedule.
4. Sub-processors
You give us general written authorisation to use the sub-processors listed in Annex B. We will email the address on your account at least 30 days before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot resolve it, you may end your subscription without penalty before the change takes effect. Every sub-processor is bound by a written contract imposing data protection obligations equivalent to this DPA, and we remain fully liable to you for their performance.
5. Data subject rights
We help you respond to your customers' requests to access, correct, erase, restrict, port or object to the processing of their data. In the app you can erase one customer (every copy we hold, leaving only a hashed do-not-contact record so they are never asked again) and export everything we hold about them as JSON. If a customer contacts us directly we will pass the request to you within five working days and act on your instruction, or, for an opt-out, honour it immediately.
6. Assisting you: breaches and impact assessments
If we become aware of a personal data breach affecting your customers' data we will notify the email address on your account without undue delay and in any case within 24 hours, with what we know, the likely consequences and the measures taken, and we will keep you updated so you can meet your own 72-hour obligation to the ICO. We will give you reasonable assistance with data protection impact assessments and prior consultation about the processing we carry out for you.
7. Deletion and return at the end
While your account is open you can export your data at any time. When you close your account (from Settings, or by asking us) we delete the account and every customer record within 30 days, except: records we must keep by law (VAT and accounting records, six years); the hashed do-not-contact list, kept so an opted-out customer is never messaged again even if the business returns; and copies inside backups, which expire on the windows in the retention schedule and against which every erasure is replayed if a backup is ever restored.
8. Audits and information
We will make available the information you reasonably need to show that we meet Article 28, including this DPA, our record of processing and our sub-processor contracts, and we will allow and contribute to audits or inspections by you or an auditor you mandate, on 30 days' written notice, no more than once a year unless a supervisory authority requires otherwise or a breach has occurred.
9. Your obligations as Controller
You confirm that you have a lawful basis to give us your customers' details and to have review invitations sent to them. For text and email invitations in the UK that means the Privacy and Electronic Communications Regulations "soft opt-in": you collected the details yourself, in the course of a sale or negotiation of your own services, you gave the person a way to refuse marketing when you collected them, and every message we send carries an opt-out (it does). When you upload a list you attest to this for each list, and we record that attestation. You will keep the details accurate, tell us promptly of any customer who objects, and not upload details of anyone who has told you they do not want to hear from you. You are responsible for your own compliance with the UK GDPR and PECR as Controller and will indemnify us against claims arising from instructions or data that breach them.
10. Liability and term
Each party is liable under Article 82 for damage caused by its own processing in breach of the GDPR. Nothing in this DPA limits the liability of either party for anything that cannot be limited by law; otherwise the liability caps in the Terms of service apply. This DPA lasts as long as we process personal data for you and survives termination until every copy is deleted under section 7. If it conflicts with the Terms, this DPA wins for data protection matters. It is governed by the law of England and Wales.
Annex A - description of the processing
| Subject matter | Inviting a business's customers to leave a Google review after a completed job, and recording the outcome. |
|---|---|
| Duration | For as long as the business holds a Growth Bull account, then deletion under section 7. |
| Nature and purpose | Receiving completed-job records from the business's accounting or CRM software, an uploaded list or manual entry; sending one text or email invitation and one reminder; hosting the review page; recording opens, clicks to Google, private feedback and opt-outs; reporting the results to the business. |
| Categories of data subject | The business's customers (typically homeowners and small-business clients of UK trades). |
| Categories of personal data | Name; mobile number; email address; invoice reference and amount; the messages sent and their delivery status; page opens, Google clicks, star ratings and private feedback text; opt-out records. No special-category data is sought or knowingly processed. |
| Controller's data | Separately, as controller, we hold the account holder's name, email, mobile, business details and billing records under the privacy policy. |
Annex B - authorised sub-processors
| Sub-processor | Purpose | Location of processing | Transfer safeguard |
|---|---|---|---|
| Railway Corporation | Application hosting and the database volume (all customer data at rest, nightly snapshots) | hosting region "ams" | Railway Data Processing Agreement incorporating the EU Standard Contractual Clauses and the UK Addendum; SOC 2 Type 2 |
| Twilio (Twilio Ireland Limited / Twilio Inc.) | Sending review-request text messages and receiving STOP replies | Ireland (EU) and the United States; delivered by UK mobile networks | Twilio Data Protection Addendum (Standard Contractual Clauses, UK Addendum, Binding Corporate Rules) |
| Plus Five Five, Inc. (Resend) | Sending review-request and account emails | United States | Resend Data Processing Agreement with Standard Contractual Clauses and the UK Addendum |
| Google LLC | Sign-in for business accounts and Business Profile lookups (Places API) | United States / global | Receives no customer contact data - only the business account holder's sign-in and the business's public listing reference |
| DataForSEO | Local search-ranking data for the Rank Map | United States / global | Receives no personal data - a search phrase and map coordinates only |
| Revolut Ltd | Card payments, subscriptions and invoices for business accounts | United Kingdom | Receives no customer data - the business account holder's billing details only; card numbers never touch our systems |
Where personal data leaves the UK it is protected by an approved transfer mechanism (the UK International Data Transfer Agreement or Addendum, or EU Standard Contractual Clauses). Changes to this list are notified under section 4.
Annex C - technical and organisational measures
- Encryption in transit: HTTPS everywhere with HSTS; provider APIs over TLS; signed webhooks (Twilio, Resend, Revolut, Xero, QuickBooks, Square) that fail closed.
- Encryption at rest: host volume encryption; accounting and CRM tokens encrypted with AES-256-GCM; every offsite backup encrypted with AES-256-GCM under a separate key before it leaves the server.
- Data minimisation: a customer's name, number and email are held in the clear only while a request is live and inside the 90-day never-ask-twice window, then replaced by a keyed HMAC-SHA256 hash; the do-not-contact list is stored hashed; private feedback text expires after 90 days; uploaded lists are parsed in memory and never stored.
- Access control: passwordless sign-in (Google or single-use emailed links), CSRF protection, per-tenant scoping checked on every request, agency isolation, masked customer details in staff screens and logs, rate limits on public forms.
- Erasure tooling: per-customer erasure and export in the app; whole-account deletion in one click; an erasure ledger replayed onto any restored backup.
- Backups and recovery: consistent nightly snapshots, 7 days on-volume, 30 days encrypted offsite, pruned automatically; documented restore and breach procedures.
- Monitoring: scheduler and delivery health checks with alerts to the operator; server errors recorded without personal data.
Retention schedule
What we keep and for how long. These periods are enforced automatically by the service; the same numbers appear in our record of processing.
| Data | Kept for |
|---|---|
| Customer name, mobile number and email on a review request | Until the request is finished and 90 days have passed (the never-ask-twice window); then replaced by a keyed hash |
| The keyed hash of a customer contact | Twelve months for the repeat-customer filter; permanently on the do-not-contact list (opt-outs, bounces, erasures) |
| Private feedback text | 90 days from when it was left; the star count is kept |
| Message log (what was sent, to whom, delivery status) | 180 days (failed sends 365 days as deliverability evidence); the address is masked as soon as the request is retired |
| Audit trail (who approved what) | 365 days; entries naming a customer are cleared when the request is retired |
| Raw invoice and CRM webhook payloads | 30 days |
| Setup-call bookings (prospects) | 12 months |
| Waiting-list emails | 6 months after the launch email |
| Business account, billing records, connection tokens | While the account is open; deleted within 30 days of closure except VAT and accounting records (six years, HMRC) |
| Backups | On-volume snapshots 7 days; encrypted offsite snapshots 30 days; host volume backups 6 days. Erasures are replayed onto any restored backup |
Contact
Data protection questions, sub-processor objections and breach notices: hello@growthbull.io. Postal address: TMR Digital Ltd, 60 Tottenham Court Road, Suite 4387a, Fitzrovia, London, W1T 2EW, United Kingdom. See also our privacy policy and terms of service.
