This Privacy Policy explains how Element Softworks Ltd collects, uses, shares and protects personal data when you use Growth Hub- our business-management platform for Marketing, Sales, Operations and HR - together with the Growth Hub website atgrowthhub.and-element.com and the application atgrowth-hub.and-element.io.
Please read it alongside our Terms of Service. If you access Growth Hub through an organisation that subscribes on your behalf, that organisation's own privacy notice may also apply to how they use the platform.
1. Who we are
Growth Hub is provided by Element Softworks Ltd(trading as &Element) - referred to in this policy as "we", "us" or "our". We are the data controller for the personal data described in the sections marked "we are the controller" below, and a data processor for customer content as described in section 12.
2. Scope of this policy
This policy covers personal data processed when you:
- visit or interact with the Growth Hub marketing website;
- create or use a Growth Hub account and workspace;
- are added to a workspace as a team member by an administrator;
- submit information through a Growth Hub hosted form or booking page;
- are recorded as a lead, contact or organisation within a customer's workspace; or
- connect a third-party account (Google, Microsoft or LinkedIn) to Growth Hub.
3. The information we collect
3.1 Account and profile data
When you register or are invited to a workspace, we process your name, email address, password (stored only as a secure hash), profile photo, job title, phone number, role and permission settings, workspace membership, and your notification and interface preferences. If you sign in with Google, we receive your Google account email address, name and profile picture (see section 5).
3.2 Content you create in Growth Hub
Growth Hub is a workspace where our customers manage their own business data. This "customer content" may include personal data about our customers' own leads, contacts and staff, including:
- CRM records - leads, contacts, organisations, lead spaces, custom fields, tags, engagement scores and activity history;
- Communications - notes, @mentions, tasks, email history logged against a lead, and messages sent from the platform;
- Forms & booking - submissions made through hosted forms and public booking pages, including any fields the customer chooses to collect;
- Projects & operations - projects, phases, budgets, allocations, schedules, planning data and time entries;
- Meetings - meeting metadata, and, where the AI Notetaker is used, recordings, transcripts and generated summaries (see section 8);
- Files - documents, images and attachments uploaded to records, tickets or messages.
For customer content, the subscribing organisation decides what data is collected and why. We process it on their behalf under section 12.
3.3 Connected-account data
Where you choose to connect a third-party account, we access only the data needed for the feature you enable. This is described in detail for Google in section 4 and for Microsoft and LinkedIn in section 5.
3.4 Usage, device and log data
We automatically collect limited technical data needed to operate and secure the service: IP address, browser and device type, pages and features accessed, timestamps, referring pages, and diagnostic or error logs. We are the controller of this data.
3.5 Cookies
Growth Hub uses only strictly necessary cookies - a secure session cookie to keep you signed in, a security token to protect against cross-site request forgery, and a cookie that remembers your interface preferences (such as light or dark mode). We do not use advertising or cross-site tracking cookies within the application. The marketing website loads web fonts from Google Fonts, which may log your IP address as part of serving those files.
4. Google user data and Limited Use
Some Growth Hub features rely on Google APIs. Growth Hub's use and transfer of information received from Google APIs adheres to theGoogle API Services User Data Policy, including its Limited Use requirements. We request access to your Google data only when you explicitly connect your Google account, and only for the scopes below:
| Google data / scope | Why Growth Hub uses it |
|---|---|
Basic profile & email (openid, userinfo.email, userinfo.profile) | To authenticate you and identify your account when you sign in with Google. |
Gmail - read (gmail.readonly) | To match and display emails exchanged with a lead or contact in your CRM timeline, so your team can see the conversation history. |
Gmail - send (gmail.send) | To let you send and reply to emails to leads and contacts directly from Growth Hub, on your behalf. |
Calendar events (calendar.events) | To read your calendar so meetings appear in Growth Hub and the AI Notetaker can join them, and to create events when you schedule a meeting from a lead. |
Google Analytics - read (analytics.readonly) | To display your website analytics inside your Growth Hub dashboard. |
Search Console - read (webmasters.readonly) | To display your search-performance and SEO data inside your Growth Hub dashboard. |
Our Limited Use commitment. In relation to data obtained through Google Workspace APIs (including Gmail and Calendar):
- we use it only to provide and improve the specific features you have enabled, as described above;
- we do not use it to develop, improve or train generalised or non-personalised AI or machine-learning models;
- we do not transfer or sell it to third parties for advertising, resale or any purpose unrelated to providing the feature;
- we do not allow humans to read it, except with your explicit consent for a specific issue you raise, where required for security or to comply with the law, or on data that has been aggregated and anonymised.
You can disconnect your Google account at any time from your integration settings, which revokes Growth Hub's access going forward. You can also review and revoke access at myaccount.google.com/permissions.
5. Microsoft and LinkedIn connected data
If you connect a Microsoft account, we access your Outlook calendar events so meetings appear in Growth Hub and the AI Notetaker can join Microsoft Teams calls. If you connectLinkedIn, we access the organisation pages and posts you authorise so that your published content and its performance can be shown in Growth Hub. As with Google, we request only the permissions needed for the feature you enable, use the data only to provide that feature, and let you disconnect at any time from your integration settings.
6. How we use personal data, and our lawful bases
Under the UK GDPR and EU GDPR we rely on the following lawful bases:
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account and workspace | Performance of a contract |
| Providing the Growth Hub features you use, including connected integrations | Performance of a contract; consent (for optional integrations) |
| Processing customer content on our customers' instructions | Handled as processor - the customer's lawful basis applies (section 12) |
| Securing the platform, preventing abuse and debugging | Legitimate interests |
| Improving and developing the service (using aggregated or de-identified data) | Legitimate interests |
| Billing, accounting and tax | Performance of a contract; legal obligation |
| Sending service and administrative messages | Legitimate interests; legal obligation |
| Sending marketing about Growth Hub (where permitted) | Consent, or legitimate interests where allowed by law; you can opt out at any time |
| Complying with legal requests and enforcing our terms | Legal obligation; legitimate interests |
7. AI features
Growth Hub offers optional AI features, such as lead summaries and drafting assistance. To provide these, relevant content (for example a lead's activity, or a meeting transcript) is sent to our AI provider,OpenAI, to generate the output. This content is processed only to return a result to you; it is not used by us or by OpenAI to train generalised AI models under the applicable API terms. AI-generated output can be inaccurate or incomplete and should be reviewed before you rely on it. Data obtained through Google Workspace APIs is used with AI only to provide a feature you have enabled and never to train models, consistent with our Limited Use commitment in section 4.
8. Meeting recording and transcription (AI Notetaker)
Where a customer enables the AI Notetaker, a bot joins scheduled video calls (such as Google Meet, Microsoft Teams or Zoom) to record audio and video, produce a transcript, and generate notes and summaries that are saved to the workspace. Recordings and transcripts may contain personal data about all participants.
Responsibility for consent. The customer that enables and uses the AI Notetaker is the controller of those recordings and is responsible for informing participants and obtaining any consent required by the laws that apply to their meetings. We provide the tool and process recordings on the customer's instructions as their processor.
9. Sharing your data and our subprocessors
We do not sell personal data. We share it only with service providers ("subprocessors") that help us run Growth Hub, and only as needed to provide the service. Each is bound by contract to protect the data and use it only on our instructions.
| Provider | Purpose | Primary region |
|---|---|---|
| Google (Google Cloud / Workspace APIs) | Sign-in, Gmail, Calendar, Analytics, Search Console and Places integrations | EU / US |
| Microsoft | Outlook calendar and Microsoft Teams integration | EU / US |
| LinkedIn page and post integration | EU / US | |
| OpenAI | AI summaries and drafting features | US |
| Amazon Web Services (S3) | Secure file and attachment storage | EU / UK |
| Resend | Sending transactional and campaign email | US |
| Browserbase | Secure sign-in for the AI Notetaker meeting bot | US |
| DataForSEO | SEO and search-data enrichment | EU / US |
| Hosting & database providers | Running the application and storing workspace data | EU / UK |
We may also disclose personal data where required to comply with the law, respond to a valid legal request, protect our rights or safety, or in connection with a merger, acquisition or sale of assets (in which case we will notify affected customers). A current list of subprocessors is available on request from [email protected].
10. International transfers
Some subprocessors are located outside the UK and the European Economic Area. Where personal data is transferred to such countries, we rely on an adequacy decision where one exists, or on appropriate safeguards such as the UK International Data Transfer Agreement / Addendum and the European Commission's Standard Contractual Clauses. You can request details of the safeguards in place using the contact details in section 18.
11. Data retention
We retain personal data for as long as it is needed for the purposes set out in this policy:
- Customer content is retained for the life of the workspace and is deleted or returned after the account is closed, in line with section 12 and our agreement with the customer.
- Account and profile data is retained while your account is active and for a reasonable period afterwards.
- Connected-account tokens are retained until you disconnect the integration, after which access is revoked.
- Billing and accounting records are retained for as long as required by law (generally six years in the UK).
- Logs and diagnostic data are retained for a limited period for security and troubleshooting.
12. Our role - controller and processor
When we provide the platform to a subscribing organisation, that organisation is the controller of the customer content in its workspace (its leads, contacts, communications, meeting recordings and so on), and we act as its processor, handling that data only on its documented instructions. If you are an individual whose data appears in a customer's workspace and you wish to exercise your rights, please contact that organisation; we will assist them in responding. We are the controller for account, billing, website and usage data relating to our direct customers and their users.
13. Security
We use technical and organisational measures appropriate to the risk, including encryption of data in transit, hashing of passwords, workspace isolation, role-based access controls and least-privilege access to production systems. No system is completely secure, but we work to protect your data and to notify affected parties and regulators of any personal data breach as required by law.
14. Your rights
Subject to the UK GDPR and EU GDPR, you have the right to access a copy of your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to certain processing; to data portability; and to withdraw consent at any time where processing is based on consent. To exercise these rights, contact us using section 18. You also have the right to complain to the UK Information Commissioner's Office (ICO) atico.org.uk, or to your local supervisory authority.
15. Children
Growth Hub is a business tool that is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
16. Third-party websites
Growth Hub and this website may link to third-party sites and services. We are not responsible for their content or privacy practices, and we encourage you to read their privacy policies.
17. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "last updated" date above and, where appropriate, notify you through the service or by email. Continued use of Growth Hub after a change takes effect means you accept the updated policy.
18. Contact us
For any question about this policy or to exercise your rights, contact: