1. Data Controller
Responsible for data processing in connection with this website and the services offered is:
David Proga
Simple.Grow
c/o Impressumservice Dein-Impressum
Stettiner Straße 41, 35410 Hungen, Germany
+49 (0) 174 6629095
david.proga@simplegrow.io
2. Subject of This Privacy Policy
This Privacy Policy explains how personal data is processed when using the Simple.Grow service. Simple.Grow is a service offering that provides and manages AI Employees – AI agents that handle defined tasks in day-to-day business operations – for businesses in the DACH region. The core product is the AI phone assistant (Speed-to-Lead): calls the business cannot answer are forwarded to an AI voice assistant that takes down the request, answers questions, books appointments and, on request, confirms to the caller by SMS. Data of end customers and callers of the managed companies may also be processed in this context.
3. Types of Data Processed
When using Simple.Grow, the following categories of personal data may be processed:
- Contact data (name, phone number, email address)
- Address data
- Project data (e.g., information about the planned project)
- Communication records
- Appointment booking information
- Review and feedback data
- Call data of the AI phone assistant: caller's phone number, time and duration of the call, call transcript (text), details given during the call (name, request, preferred appointment). The audio stream is processed only for the duration of the call and is not recorded (see Section 8.11)
- Payment and contract data (name, billing address, email address, payment status; payment instruments are held exclusively by the payment provider, see Section 8.13)
The specific types of data processed depend on the functional scope of the automation systems activated by the customer.
4. Purpose of Processing
Personal data is processed for the following purposes:
- Content creation and optimization (e.g., LinkedIn posts, specialist articles, reports)
- Research and analysis (e.g., market research, competitive analyses)
- Automated reports and KPI tracking
- Automated customer communication and appointment scheduling
- Automated answering and handling of calls and inquiries by an AI phone assistant, including instant replies to missed calls, appointment booking in the business's calendar and sending an appointment confirmation by SMS
- Payment processing, invoicing and contract management (conclusion, cancellation, refund)
- Process optimization and workflow automation
- AI assistance and decision support
- Inquiry processing and support
5. Legal Basis for Processing
For our own processing activities (e.g., via this website or for customer support), we rely on the following legal bases under Art. 6 GDPR:
- Art. 6(1)(a) GDPR (consent, e.g., when expressing interest via contact form)
- Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures, e.g., payment processing via Stripe as well as taking down a request and confirming an appointment by SMS when a caller asks for it during the call)
- Art. 6(1)(c) GDPR (legal obligation, e.g., documenting an advertising objection, retention of invoice data under tax law)
- Art. 6(1)(f) GDPR (legitimate interest)
Regarding the processing of end customer data by our clients:
Simple.Grow merely provides the technical means. The legal responsibility for compliance with all data protection obligations towards end customers lies exclusively with the respective business or company using Simple.Grow. This includes in particular the information obligations under Art. 13/14 GDPR and the existence of a valid legal basis for each data processing activity. For the AI phone assistant, Simple.Grow provides the business with a text module for its own privacy policy and the announcement identifying the assistant as AI at the start of each call.
Roles for the AI phone assistant: Where Simple.Grow operates the phone assistant for a customer, the customer is the controller and Simple.Grow the processor (Section 6, DPA). Where Simple.Grow uses the phone assistant for its own phone number (callbacks on missed calls to Simple.Grow), Simple.Grow itself is the controller; the legal basis is then Art. 6(1)(b) GDPR (the caller's request) and Art. 6(1)(f) GDPR (reachability without staff while unavailable).
6. Data Processing on Behalf
Insofar as we process personal data of end customers on behalf of businesses/companies (e.g., as part of automated contact processes), this is done on the basis of a Data Processing Agreement pursuant to Art. 28 GDPR. Simple.Grow will never independently use or disclose personal data to third parties unless a legal obligation exists or the customer has expressly consented.
7. Data Disclosure
Personal data is only disclosed to third parties if this is necessary for the performance of the contract or if a legal obligation exists. Disclosure for advertising purposes or outside the processes defined in the agreement does not take place.
8. Services and Infrastructure Used
8.1 n8n (n8n.io)
For the automation and integration of internal processes (e.g., importing meeting notes), we use n8n, an open-source automation platform. We run our own instance of the open-source version on the hosting platform Railway (Railway Corp., USA), not the n8n cloud variant. A Data Processing Agreement pursuant to Art. 28 GDPR exists with Railway; data is transferred on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Hosting: Own instance on Railway infrastructure, transfer to the USA under EU Standard Contractual Clauses
- No n8n Cloud: Only the open-source version is used. No data is transferred to n8n GmbH or their cloud services
- Not used in the phone assistant: Call data of the AI phone assistant is not processed via n8n
- Data encryption: All transmitted data is protected via HTTPS; sensitive data can additionally be stored encrypted
- Access restrictions: Strict access controls via API keys and role management
- Transparent processing: Workflows document data flows in detail
- No disclosure to third parties: n8n processes data only within defined workflows on our own instance
8.2 Trigger.dev (trigger.dev)
For orchestrating and executing background tasks, we use Trigger.dev (Trigger.dev Inc., USA), a platform for managing AI workflows and automations, in its cloud variant. A Data Processing Agreement pursuant to Art. 28 GDPR exists with Trigger.dev Inc.; data is transferred on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Hosting: Trigger.dev Cloud, transfer to the USA under EU Standard Contractual Clauses
- Data encryption: All transmitted data is protected via HTTPS
- Access restrictions: Strict access controls via API keys and role management
- Task orchestration: Trigger.dev orchestrates the AI Employees (e.g., content creation, research, reports) as well as the instant-reply and follow-up messages of the Speed-to-Lead system and logs all processing steps
- Data minimization: Only task execution logs remain with Trigger.dev; the actual data is stored in our Supabase database in the EU (Section 8.3)
8.3 Supabase
For data storage and database infrastructure, we use Supabase, a GDPR-compliant open-source platform as an alternative to proprietary database solutions.
- Server location: Exclusively EU and/or Germany-based servers
- Data encryption: Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Row Level Security (RLS): Granular access control at the database level
- SOC 2 Type II certified: Regularly audited security standards
- No disclosure to third parties: Data is stored exclusively within the scope of the agreed processing
- Data minimization: Only data required for the respective purpose is stored
8.4 Large Language Models (AI Models)
Simple.Grow uses the Large Language Model Claude (Anthropic) via AWS Bedrock EU Inference Profiles as a programming interface (API). Simple.Grow places particular emphasis on data protection and GDPR compliance.
- EU processing: AI processing is carried out exclusively via AWS Bedrock EU Inference Profiles with server location Frankfurt am Main (EU). Customer data demonstrably does not leave the EU. No transfer of personal data to third countries takes place.
- Data processing via the API: When using the AI model via the API, the data required for processing the request is transmitted to AWS Bedrock EU. This data is processed exclusively to generate the desired response and is not used for other purposes. Data provided via the API is not used for training AI models.
- No permanent storage: No personal data is permanently stored with the AI provider as part of the API usage. Temporary caching for processing occurs exclusively in the EU (Frankfurt) and is deleted after a maximum of 24 hours.
- Data-minimizing implementation: Simple.Grow ensures that only the minimum necessary data is transmitted to the API. Sensitive or personal data is anonymized or pseudonymized before transmission.
No use of the web interface: Simple.Grow exclusively uses the API interface, not the AI provider's web interface. All interactions occur via the API and are subject to the above-mentioned safeguards.
Exception for the AI phone assistant: Real-time speech processing of the phone assistant is not carried out via AWS Bedrock EU but via the US-based providers listed in Section 8.11. The safeguards described there apply to that service.
8.5 AI Regulation (EU AI Act)
Simple.Grow observes the requirements of Regulation (EU) 2024/1689 (AI Regulation / EU AI Act) in the development, provision, and operation of its AI systems.
- Risk classification: The AI systems used are classified as general-purpose AI with limited risk. They are not high-risk AI systems within the meaning of Art. 6 EU AI Act.
- Transparency (Art. 50): AI-generated content is labeled as such. The User is transparently informed about the use of AI models, their functionality, and limitations. The AI phone assistant identifies itself as an AI assistant at the start of every call (Art. 50(1)) and offers to hand over to a human or arrange a callback.
- AI Literacy (Art. 4): As part of each AI Employee setup, Simple.Grow provides a documented AI Literacy Introduction covering the use of the system, the approval workflow, and the User's review obligations.
- Human Oversight (Art. 14): All AI systems are equipped with an approval workflow that ensures no outputs enter business operations without human review.
- No prohibited practices (Art. 5): Simple.Grow does not deploy AI systems that fall under the prohibited practices of Art. 5 EU AI Act (e.g., social scoring, subliminal manipulation, exploitation of vulnerabilities).
The detailed regulation of the division of responsibilities between Simple.Grow (Provider) and the User (Deployer) under the EU AI Act can be found in the Terms and Conditions (§9.5–9.11).
8.6 Contact Form (/brief)
Via the contact form at simplegrow.io/en/brief, interested parties can get in touch as part of a direct marketing campaign (personal letters). The following data is collected:
- Required fields: Company name, name, expression of interest (Yes/No)
- Optional fields: Phone number, email address
Purpose and Legal Basis
- For "Yes, interested": The data is processed to make contact and arrange a non-binding conversation about AI Employee services. Legal basis: Art. 6(1)(a) GDPR (consent through active selection in the form).
- For "No, not interested": The response is documented as an advertising objection pursuant to Art. 21 GDPR. Legal basis: Art. 6(1)(c) GDPR (fulfillment of a legal obligation).
Recipients and Processing
Form data is processed via a Vercel Serverless Function (see section 8.7) and forwarded internally. No permanent storage of form data takes place in a database.
Retention Period
- Expression of interest ("Yes"): Data is retained for a maximum of 3 years or until consent is withdrawn.
- Advertising objection ("No"): The response is retained permanently to ensure no further contact is made.
Spam Protection
A honeypot method is used to protect against automated submissions. An invisible form field is used that regular users do not fill out. No external services (such as Google reCAPTCHA) are integrated.
8.7 Vercel (vercel.com)
For website hosting and the provision of API routes, we use Vercel, a cloud platform for static websites and serverless functions.
- Hosting: Static website hosting via Vercel's edge network (global CDN)
- Data processing: Vercel processes server logs (IP addresses, access times) as part of hosting. Personal customer data is not stored on Vercel
- Headquarters: Vercel Inc., USA. Data transfer based on EU Standard Contractual Clauses and the EU-US Data Privacy Framework
8.8 Cal.com (cal.com)
For appointment scheduling, we use Cal.com, an open-source scheduling solution.
- Data processed: Name, email address, and selected time slot when booking a Discovery Call or Needs Assessment appointment
- Purpose: Appointment scheduling and calendar synchronization
- Data protection: Cal.com processes data exclusively for appointment management. Cal.com's privacy policy is available at cal.com/privacy
- Deletion: Appointment booking data is deleted 7 days after the appointment takes place
8.9 Server-Side Reach and Report Measurement
For our own sales outreach (landing pages as well as personalized report and video pages for contacted companies), we use server-side, cookieless measurement. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in reach measurement and in evaluating our own sales outreach).
- No cookies, no localStorage, no fingerprinting: No cookie is set, no entry is written to localStorage or sessionStorage, and no device fingerprinting is performed. A session identifier exists exclusively in the memory of the open browser tab and is lost when the page is closed or reloaded.
- No storage of the IP address: The IP address of the visit is neither read nor stored by the measurement. Since no cookies or comparable recognition techniques are used, no consent under Section 25 TDDDG (the German Telecommunications Digital Services Data Protection Act) is required.
- Events collected: Page view, scroll depth (25/50/75/100%), active dwell time, clicks on calls-to-action and checkout links, and video progress (start, 50%, 90%) on the video pages.
- Personalized report and video pages: For companies previously contacted as part of our sales outreach, we provide individual pages at
/r/<id>(report) and/v/<id>(video). The identifier refers to the contacted company, not to an individual natural person. On these pages, the interactions described above are attributed to that identifier so we can see whether and how an offer was received. This is the only case in which the measurement establishes a link to a specific, already-contacted company. Data subjects may object to this processing at any time pursuant to Art. 21 GDPR; the associated page will then no longer be used, and the attribution will be deleted. - Recipients and storage location: Measurement data is received via a Vercel Serverless Function (see section 8.7) and stored in our Supabase database (EU, see section 8.3).
- Retention period: Anonymous landing page events without a company identifier are automatically deleted after 12 months. Events with a company identifier (report/video pages) are retained for the duration of the active sales outreach and then deleted or anonymized, but no later than 12 months after the last interaction.
8.11 AI Phone Assistant (Vapi, Twilio and Speech Services)
The AI phone assistant answers calls a business cannot take itself, holds a conversation in natural language, takes down the request and, on request, books an appointment. Technically, the assistant runs on the platform Vapi (Vapi Inc., San Francisco, USA). Vapi connects several speech services, each handling one step:
- Telephony: Twilio Inc. (USA) provides the phone number and forwards the call to Vapi. Twilio processes the phone number, time and duration of the call and the audio stream during the connection
- Speech recognition (speech to text): Soniox Inc. (USA) or Deepgram Inc. (USA), depending on the assistant
- Language model (conversation): Google Gemini (Google Ireland Ltd.) or OpenAI (OpenAI Ireland Ltd. / OpenAI L.L.C., USA), depending on the assistant. Data is processed via the respective enterprise API and is not used to train the models
- Speech output (text to speech): ElevenLabs Inc. (USA); fallback Microsoft Azure Speech (Microsoft Ireland Operations Ltd.)
Data processed
- Caller's phone number, time and duration of the call
- Call transcript in text form and the details extracted from it (name, request, preferred appointment, callback number, address, where given)
- The audio stream itself is processed only in real time for recognition and output
No call recording
Calls are not recorded as audio. The platform's recording feature is permanently disabled for all assistants (Section 201 German Criminal Code, confidentiality of the spoken word). Only a text transcript required to handle the request is created.
Identification as AI
The assistant identifies itself as an AI assistant at the start of every call (Art. 50(1) EU AI Act, see Section 8.5). Callers may request a callback from a human at any time.
Legal basis and roles
For businesses using the assistant through Simple.Grow, the business is the controller and Simple.Grow the processor (Section 6, DPA). The legal basis for processing is Art. 6(1)(b) GDPR (pre-contractual measure at the caller's request) and Art. 6(1)(f) GDPR (reachability of the business outside office hours). Section 5 applies to Simple.Grow's own phone number.
Third-country transfers
Vapi, Twilio, Soniox, Deepgram, OpenAI and ElevenLabs are based in the USA. A Data Processing Agreement pursuant to Art. 28 GDPR exists with each of these providers. Data is transferred on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, additionally under the EU-US Data Privacy Framework (adequacy decision of July 10, 2023).
Storage location and retention
- Transcripts and extracted details are stored in our Supabase database in the EU (Section 8.3) and made available to the respective business
- Call logs at Vapi serve operation and troubleshooting only and are deleted there according to the contractually agreed periods
- Transcripts and call metadata are deleted 12 months after the call, unless the business specifies a shorter period or a statutory retention obligation applies
8.12 SMS Delivery (seven.io)
For sending appointment confirmations and short messages from the phone assistant, we use the SMS gateway seven.io (seven communications GmbH & Co. KG, Kiel, Germany). It is used on the basis of a Data Processing Agreement pursuant to Art. 28 GDPR; processing takes place in Germany.
- Data processed: Recipient phone number, message text (business name, appointment, address, callback number), time of sending and delivery status
- Transactional messages only: Only confirmations and information requested by the caller during the call are sent. Promotional content (review links, discounts, service offers) is excluded
- Legal basis: Art. 6(1)(b) GDPR (measure at the data subject's request). Consent to SMS delivery is asked for during the call and documented in the transcript
- Retention: Delivery logs are deleted together with the call data after 12 months
8.13 Payment Processing (Stripe)
Payment for Simple.Grow is handled via Stripe (Stripe Payments Europe Ltd., Dublin, Ireland; parent company Stripe Inc., USA). Stripe provides checkout, subscription, invoices and refunds.
- Data processed: Name, email address, billing address, payment instrument (e.g., card details or bank account, held exclusively by Stripe), payment status and invoice history. Simple.Grow does not receive full card details
- Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (retention obligations under commercial and tax law)
- Role of Stripe: For payment processing, Stripe is an independent controller under the GDPR. Stripe's privacy notice is available at stripe.com/privacy. Transfers to Stripe Inc. in the USA are based on the EU Standard Contractual Clauses and the EU-US Data Privacy Framework
- Cancellation and refunds: Cancellation is done via the Stripe customer portal or informally by email. Refunds are issued via Stripe to the original payment instrument
- Retention: Invoice and payment data is retained for 10 years (Section 257 German Commercial Code, Section 147 German Fiscal Code)
8.14 WhatsApp Business (Meta)
For questions before purchase and as an optional reply channel for callers, we use WhatsApp Business or the WhatsApp Business Platform (Meta Platforms Ireland Ltd., Dublin, Ireland). It is used only if the data subject contacts us via WhatsApp themselves or explicitly asks for this channel during a call.
- Data processed: Phone number, profile name, message content and timestamps. Message content is end-to-end encrypted; Meta processes metadata according to its own privacy notices (WhatsApp Business Data Transfer Addendum)
- Legal basis: Art. 6(1)(b) GDPR (the data subject's request) and Art. 6(1)(f) GDPR (communication via the channel chosen by the user)
- Third-country transfer: Meta Platforms Inc. (USA) is certified under the EU-US Data Privacy Framework; EU Standard Contractual Clauses apply in addition
- Retention: WhatsApp conversations are deleted once the request is closed, at the latest after 12 months
8.15 Google Calendar (Appointment Booking for Businesses)
If the phone assistant books appointments directly into a business's Google Calendar, Simple.Grow accesses the shared calendar via a technical service account (Google Ireland Ltd., Dublin, Ireland). The appointment, the caller's name and callback number and the request as appointment description are processed. The legal basis is Art. 6(1)(b) GDPR. Google is certified under the EU-US Data Privacy Framework; processing is based on the Google Cloud Data Processing Terms. If the business uses another calendar (e.g., Cal.com, Section 8.8), this access does not apply.
9. Retention Period
Personal data is retained only as long as necessary for the respective purposes or as required by statutory retention obligations. Automatically stored communication data (e.g., WhatsApp dialogs or meeting minutes) is regularly reviewed and deleted after the relevant periods expire. Call data of the AI phone assistant (transcripts, metadata, SMS logs) is retained for 12 months after the call (Section 8.11), invoice and payment data for 10 years (Section 8.13). At the end of the contract, customer data is deleted within 30 days (DPA Section 10).
10. Rights of Data Subjects
Data subjects have the right to:
- Access to their stored data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing (Art. 21 GDPR)
Requests can be directed to the contact details provided above.
11. Customer Responsibility
Simple.Grow assumes no responsibility whatsoever for any data protection violations arising from improper or non-GDPR-compliant use by the business/company. It is exclusively the User's responsibility to inform their customers in a timely and transparent manner about the use of Simple.Grow and to ensure compliance with all legal requirements.
12. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy as needed, e.g., to adapt it to new legal requirements or technical developments. The current version is always available on our website.
Data Processing Agreement (DPA)
The complete Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is available as a separate document: www.simplegrow.io/en/dpa
The DPA governs the processing of personal data on behalf of the customer, including technical and organizational measures (TOMs), sub-processor list, deletion periods, and notification obligations in case of data breaches.