PRIVACY POLICY

TRIX AUTOMATION
LAST UPDATED: JANUARY 2025

This Privacy Policy explains how Growth Trigger AI ("Company," "we," "our," or "us") collects, uses, stores, and discloses information when we provide automation, marketing, analytics, and CRM-related services to our clients ("Clients"), and when we process the data of their customers ("End Users") as part of these services.

1. SCOPE OF POLICY

This policy applies to all data we process in the course of delivering services to Clients, including but not limited to cold email campaigns, paid advertising automation, CRM integration, hiring workflows, and analytics dashboards.

We are committed to ensuring the confidentiality, integrity, and availability of all personal data, and comply with applicable privacy and data protection laws, including:

  • • The General Data Protection Regulation (EU GDPR and UK GDPR)
  • • The California Consumer Privacy Act (CCPA) and CPRA
  • • The CAN-SPAM Act
  • • The U.S. Health Insurance Portability and Accountability Act (HIPAA), where applicable
  • • Other U.S. federal and state privacy laws, as relevant

2. DATA WE COLLECT

We collect the following types of data:

FROM CLIENTS:

  • • Business contact information
  • • Login credentials for platforms under managed services
  • • CRM data and campaign performance analytics

FROM END USERS (ON BEHALF OF CLIENTS):

  • • Contact details (name, email, phone)
  • • Communication preferences
  • • Behavioral data (interactions with campaigns, websites, ads)
  • • Lead qualification information

Where our Clients lawfully collect and share personal data with us (e.g., via API or file upload), we process that data strictly as a service provider or data processor.

3. HOW WE USE THE DATA

We use collected data to:

  • • Deliver services outlined in contracts with Clients
  • • Conduct campaign and sales performance analytics
  • • Provide automation workflows
  • • Customize outreach and user experience for Clients
  • • Improve our internal tools, systems, and analytics models

Note: We may anonymize or pseudonymize data to use in internal analytics, model training, benchmarking, and system optimization. This usage is conducted in a way that does not identify any Client or End User personally.

4. LEGAL BASIS FOR PROCESSING

Our legal bases include:

  • • Performance of a contract (with Clients)
  • • Legitimate interest (e.g., internal analytics, fraud prevention)
  • • Consent (where required by law)

5. DATA RETENTION

We retain data only as long as necessary to:

  • • Fulfill service obligations
  • • Comply with applicable legal obligations
  • • Protect our legitimate business interests (e.g., backups, dispute resolution)

Data we process on behalf of Clients is deleted or returned upon termination of services, unless otherwise required by law.

6. DATA SHARING AND DISCLOSURE

We may share personal data with:

  • • Subprocessors (cloud infrastructure, analytics providers, email providers) under contractual safeguards
  • • Legal authorities, if compelled by law

We do not sell End User or Client data.

7. INTERNATIONAL DATA TRANSFERS

When data is transferred outside the originating jurisdiction (e.g., from EU to U.S.), we implement Standard Contractual Clauses (SCCs) or similar safeguards as required by law.

8. DATA SUBJECT RIGHTS

Depending on your jurisdiction, you may have rights to:

  • • Access or correct your data
  • • Object to or restrict certain processing
  • • Request deletion of your data
  • • File a complaint with a regulatory authority

Requests can be made via tj@trixautomation.com.

9. HIPAA COMPLIANCE (WHERE APPLICABLE)

For services that involve protected health information (PHI), we enter into Business Associate Agreements (BAAs) and comply with HIPAA standards, including:

  • • Role-based access controls
  • • Encrypted data storage and transfer
  • • Breach notification procedures

10. SAFEGUARDS AND SECURITY

We implement technical and organizational measures including:

  • • Encrypted storage and transit
  • • MFA for all admin accounts
  • • Role-based access and audit trails
  • • Regular data integrity checks

11. CHANGES TO THIS POLICY

We may update this policy periodically to reflect changes in technology, regulations, or services. Clients will be notified of material changes via email or dashboard notification.

This policy forms part of our contractual framework with Clients and is binding upon all parties engaging with our services.

QUESTIONS ABOUT THIS POLICY?

Contact us at:

EMAIL: tj@trixautomation.com
COMPANY: Growth Trigger AI (Trix Automation)