Last Updated: 15 November 2025
We take your privacy seriously. This policy explains how Handshake collects, uses, and protects personal data when you use our AI-powered outreach automation platform. Key points:
Grow Digital Services DMCC ("we", "us", "our", or "Handshake") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:
Company Details:
Grow Digital Services DMCC
Dubai, United Arab Emirates
Email: contact@grow.ae
Website: www.grow.ae
This Privacy Policy should be read in conjunction with our Terms and Conditions.
When you use our services, we collect information that you provide directly to us, including:
Account Information:
Campaign Information:
Communication Data:
When you use our platform to conduct outreach, we process personal data about your prospects, including:
Important: For prospect data, we act as a data processor on behalf of our clients (data controllers). Our clients are responsible for ensuring they have a lawful basis for collecting and processing this data.
We automatically collect certain information when you access our platform:
We receive data from integrated platforms such as:
We use your information to:
We use artificial intelligence and machine learning to:
We use information to:
We may use your contact information to:
We process data to:
We process personal data based on the following legal grounds:
| Processing Purpose | Legal Basis |
|---|---|
| Service delivery to clients | Contractual necessity |
| Payment processing | Contractual necessity |
| Prospect outreach (on client's behalf) | Legitimate interests / Client's lawful basis |
| Platform improvement and analytics | Legitimate interests |
| Marketing communications | Consent (where required) / Legitimate interests |
| Security and fraud prevention | Legitimate interests |
| Legal compliance | Legal obligation |
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We share information with trusted third-party service providers who assist us in operating our platform, including:
These providers are contractually obligated to protect your data and use it only for specified purposes.
We integrate with and share data with platforms necessary for service delivery:
Your use of these platforms is also governed by their respective privacy policies and terms of service.
If you are an End User of one of our Partners (agencies using our white-label services), we share your data with that Partner as necessary to deliver services.
We may disclose your information if required to do so by law or in response to:
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change and any choices you may have.
We are based in the United Arab Emirates, but our services are used globally. Your data may be transferred to, stored in, and processed in countries other than your own, including:
When we transfer data internationally, we implement appropriate safeguards, including:
GDPR Compliance: For European Economic Area (EEA) residents, we comply with GDPR requirements for international data transfers and ensure appropriate safeguards are in place.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations.
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 2 years |
| Campaign and messaging data | Duration of campaign + 1 year |
| Prospect conversation history | Duration of active outreach + 6 months |
| Financial and billing records | 7 years (legal requirement) |
| Support communications | 3 years after closure |
| Analytics and aggregated data | Indefinitely (anonymised) |
You may request deletion of your data at any time, subject to our legal obligations to retain certain records. Upon account termination, we will delete or anonymise your data in accordance with these retention periods unless longer retention is required by law.
We implement comprehensive security measures to protect your data against unauthorised access, alteration, disclosure, or destruction:
Important: While we implement robust security measures, no system is completely secure. You are responsible for maintaining the security of your account credentials and should notify us immediately of any suspected unauthorised access.
You have the right to:
You can:
You have the right to request deletion of your data, subject to:
You can:
Where processing is based on your consent, you may withdraw consent at any time. This does not affect the lawfulness of processing before withdrawal.
Our platform uses AI to generate messages and evaluate conversations. You have the right to:
If you have concerns about how we handle your data, you have the right to lodge a complaint with:
To exercise any of these rights, please contact us at: contact@grow.ae
We will respond to requests within one month (or as required by applicable law). We may need to verify your identity before fulfilling certain requests.
Our website and platform use cookies and similar tracking technologies:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential Cookies | Required for platform functionality, authentication, security | Session / Persistent |
| Analytics Cookies | Usage statistics, performance monitoring | Up to 2 years |
| Functional Cookies | Remember preferences, settings | Up to 1 year |
| Marketing Cookies | Track effectiveness of campaigns (with consent) | Up to 1 year |
You can control cookies through:
Note: Blocking essential cookies may affect platform functionality.
We use third-party analytics services (e.g., Google Analytics) that may set their own cookies. These are governed by the respective third parties' privacy policies.
Our services are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
If you believe we have collected data from a child, please contact us immediately.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
We will notify you of material changes by:
Your continued use of our services after changes become effective constitutes acceptance of the updated Privacy Policy.
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR, including:
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including:
Note: We do not sell personal information as defined by the CCPA.
We comply with UAE data protection laws and regulations, including Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
We act as a data controller for:
We act as a data processor on behalf of our clients (data controllers) for:
When acting as a processor, our clients are responsible for:
We process data on behalf of our clients in accordance with their instructions and our Data Processing Agreement.
For questions about this Privacy Policy or our data practices:
Grow Digital Services DMCC
Dubai, United Arab Emirates
Email: contact@grow.ae
Website: www.grow.ae
For specific privacy concerns or to exercise your data rights:
Email: contact@grow.ae
Subject Line: "Privacy Request" or "Data Rights Request"
If you have concerns about our data handling practices:
Data Protection Officer
Email: laura@grow.ae
This Privacy Policy is provided as a comprehensive template and should be reviewed by qualified legal counsel before implementation. Privacy laws vary by jurisdiction and change frequently. This document should be tailored to your specific data processing activities and reviewed regularly to ensure ongoing compliance with applicable laws.
If you handle data from the EU/EEA, consider obtaining legal advice on GDPR compliance, including appointment of a Data Protection Officer if required.