1. INTRODUCTION AND SCOPE
1.1 Who We Are. This Privacy Policy (this "Policy") is issued by Affluent Ventures LLC, a Delaware limited liability company doing business as "029 Growth" ("029 Growth," the "Company," "we," "us," or "our"), with its business address at 111B S Governors Ave, STE 28959, Dover, Delaware 19904, United States. For all matters relating to this Policy and the processing of Personal Data, you may contact us at victor@029growth.com.
1.2 Business-to-Business Only. The Company provides growth, marketing, and technology services exclusively to businesses and professionals, primarily in the financial markets sector, including brokers, trading platforms, investment firms, financial technology companies, funds, private equity firms, and their founders, executives, and investors. Our Website, communications, and Services are not directed to consumers acting for personal, family, or household purposes, and we do not knowingly collect Personal Data from individuals acting in that capacity.
1.3 What This Policy Covers. This Policy describes how we collect, use, disclose, retain, and otherwise process Personal Data in our capacity as a controller (or "business," as that term is used under certain U.S. state laws) in connection with:
(a) our website located at https://029growth.com and any related pages (the "Website");
(b) our business development, prospecting, and business-to-business direct marketing activities conducted in our own name;
(c) our advertising, analytics, and content activities;
(d) our communications, meetings, and events with Business Contacts; and
(e) our relationships with Clients, vendors, and partners and their respective representatives.
1.4 What This Policy Does Not Cover. When we provide Services to a Client and process Personal Data on that Client's behalf and in accordance with its documented instructions, including when we build or operate outbound, advertising, or content systems for a Client or send communications in a Client's name ("Client Campaign Data"), we act as a processor or service provider and the Client acts as the controller. The Client's privacy notice governs that processing. Section 8 describes our role in more detail.
1.5 Relationship to Other Terms. This Policy should be read together with our Website Terms of Use and with any Master Services Agreement, Statement of Work, or Data Processing Agreement entered into with the Company. As between the Company and a Client, a signed agreement controls in the event of a conflict with this Policy.
2. DEFINITIONS
In this Policy, the following capitalized terms have the meanings set out below.
"Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data described in this Policy, including, to the extent applicable: the Delaware Personal Data Privacy Act (6 Del. C. ch. 12D) (the "DPDPA"); the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (the "CCPA"); other U.S. state comprehensive privacy laws; the Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003, 15 U.S.C. § 7701 et seq. (the "CAN-SPAM Act"); Canada's Anti-Spam Legislation ("CASL") and the Personal Information Protection and Electronic Documents Act ("PIPEDA"); Regulation (EU) 2016/679 (the "GDPR"); the GDPR as retained in the law of the United Kingdom together with the UK Data Protection Act 2018 (the "UK GDPR"); the Swiss Federal Act on Data Protection (the "FADP"); and national laws implementing Directive 2002/58/EC (the "ePrivacy Directive"), including the UK Privacy and Electronic Communications Regulations 2003 ("PECR").
"Business Contact" means an individual who interacts with us, or whom we contact, in his or her professional or commercial capacity, including Prospects, representatives of Clients, investors, partners, vendors, and event participants.
"Business Contact Data" means Personal Data relating to a Business Contact in that capacity, such as name, job title, employer, business email address, business postal address, professional profile URL, and professional background.
"Client" means a business that has entered into an agreement with the Company for the provision of Services.
"Personal Data" means any information relating to an identified or identifiable natural person and includes "personal information" and "personal data" as defined under Applicable Data Protection Law. Personal Data does not include de-identified, anonymized, or aggregated information.
"Prospect" means a Business Contact whom we have identified as potentially interested in our Services or with whom we seek to establish a business relationship.
"Services" means the growth, outbound engineering, advertising engineering, content engineering, data, and technology services provided by the Company.
"Signals" means information indicating a business event or business intent, such as a funding round, hiring activity, a change in leadership, a liquidity event, a partnership, advertising activity, engagement with content, or a visit to our Website.
"Sale," "Sell," "Share," "Sharing," "Targeted Advertising," and "Profiling" have the meanings given to them under Applicable Data Protection Law.
3. PERSONAL DATA WE COLLECT
3.1 Personal Data You Provide to Us. We collect Personal Data that you provide directly, including:
(a) Identifiers and contact information: name, business email address, company, job title, and business postal address;
(b) Scheduling information: when you book a meeting with us, your name, email address, company, selected time, and your answers to booking questions;
(c) Communications: the content of emails, LinkedIn messages, and other correspondence with us;
(d) Contract and billing information: signatory details, proposal and contract records, and invoicing and payment records. We do not store full payment card numbers;
(e) Meeting content: audio, video, transcripts, and summaries of calls that we record with notice, as described in Section 5.7; and
(f) Testimonials and feedback, which we publish only with your permission.
3.2 Personal Data Collected Automatically. When you visit the Website or interact with our communications, we and our service providers collect:
(a) Device and usage data: IP address, browser type and settings, device identifiers, operating system, referring URL, pages viewed, date and time of access, clickstream data, and approximate location derived from your IP address;
(b) Cookie and pixel data, as described in Section 10;
(c) Email engagement data: whether an email was delivered, opened, or clicked and which links were followed, collected through tracking pixels and link redirects; and
(d) Visit association data: if you have previously interacted with us, for example by clicking a link in one of our emails or submitting a form, our customer relationship management system may associate your subsequent Website visits with your existing contact record.
3.3 Personal Data from Third-Party Sources. We obtain Business Contact Data and Signals from third-party sources as described in Section 4.
3.4 Inferences. We derive inferences from the Personal Data described above, such as the likely relevance of our Services to your role or company, your seniority, and a fit score used to prioritize communications ("Lead Scoring").
3.5 Sensitive Data. We do not intentionally collect or process sensitive data or special categories of Personal Data, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation, genetic data, biometric data used for identification, precise geolocation, government-issued identification numbers, or financial account credentials. Please do not provide such data to us. If we become aware that we have received such data unintentionally, we will delete it unless we are required by law to retain it.
4. HOW WE SOURCE AND ENRICH BUSINESS CONTACT DATA
4.1 Sources. We obtain Business Contact Data from the following categories of sources:
(a) Publicly available sources, including company websites, press releases, public filings, corporate, commercial, and regulatory registers, news media, and conference and event materials;
(b) Licensed business-to-business data providers, including commercial databases of business contact and company information such as AI Ark, which provide such data under license and represent that they obtain it lawfully;
(c) Professional networks, including information that you make available on professional networks such as LinkedIn, accessed in accordance with the terms of the relevant platform;
(d) Signal sources, including sources of information about funding, hiring, leadership changes, liquidity events, and advertising activity, such as public advertising libraries;
(e) Advertising and social media platforms, including engagement data relating to our advertisements and content;
(f) Referrals and introductions from Business Contacts, partners, and Clients; and
(g) Events, including attendee information and contacts exchanged at events.
4.2 Enrichment and Processing Activities. We may combine Business Contact Data from multiple sources; verify business email addresses, including through email verification services; deduplicate and normalize records; classify companies and contacts by industry, size, geography, role, and seniority; associate Signals with company and contact records; apply Lead Scoring; and prioritize outreach. We use automated tools, including artificial intelligence tools, to support these activities, subject to human oversight.
4.3 Our Principles. We limit Business Contact Data to information relevant to your professional role. We do not use personal, non-business contact details for prospecting, except where you have published those details for business purposes. We apply opt-out requests across all channels, and we maintain a suppression list to ensure that opted-out individuals are not contacted again.
4.4 Information for Individuals Whose Data We Obtain Indirectly. Where we obtain your Personal Data from a source other than you, we provide you with information about our processing no later than at the time of our first communication with you, including by a reference to this Policy in that communication. The categories of Personal Data concerned and their sources are described in Sections 3 and 4.1.
5. PURPOSES OF PROCESSING AND LEGAL BASES
We process Personal Data for the purposes set out below. For individuals in the European Economic Area ("EEA"), the United Kingdom, and Switzerland, we also state the legal basis on which we rely under the GDPR, the UK GDPR, or the FADP, as applicable.
5.1 Operating, securing, and improving the Website. Legal basis: our legitimate interests in providing a functional and secure website (Art. 6(1)(f) GDPR). Non-essential cookies and similar technologies are used only with your consent where consent is required (Art. 6(1)(a) GDPR and national laws implementing the ePrivacy Directive).
5.2 Responding to inquiries and scheduling meetings. Legal basis: taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interests in responding to business inquiries (Art. 6(1)(f) GDPR).
5.3 Business-to-business prospecting and direct marketing in our own name, by email, LinkedIn, and postal mail, including handwritten correspondence. Legal basis: our legitimate interests in marketing our Services to businesses and to individuals whose professional role makes our Services relevant to them (Art. 6(1)(f) GDPR). In balancing those interests against your rights, we take into account that we process only Business Contact Data, that our communications relate to your professional role, that we limit the frequency of contact, that every communication offers a simple means to opt out, and that we honor objections without delay. Where applicable law requires your prior consent for a particular channel, including electronic marketing to recipients in certain jurisdictions, we rely on your consent or do not use that channel.
5.4 Advertising, retargeting, and audience matching, including the use of advertising cookies and pixels and the upload of hashed identifiers to advertising platforms such as LinkedIn Matched Audiences, Meta Custom Audiences, and Google Customer Match. Legal basis: your consent where consent is required (Art. 6(1)(a) GDPR); otherwise our legitimate interests in reaching relevant business audiences (Art. 6(1)(f) GDPR). U.S. residents may opt out as described in Sections 10 and 11.
5.5 Analytics and content engagement. We measure the use of the Website and the performance of our content, and we may combine engagement with our content on platforms such as LinkedIn, X, and YouTube with our records in order to prioritize relevant communications. Legal basis: your consent for non-essential cookies (Art. 6(1)(a) GDPR); otherwise our legitimate interests in understanding the effectiveness of our content and communications (Art. 6(1)(f) GDPR).
5.6 Entering into and performing contracts with Clients, vendors, and partners, including communication with their representatives. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interests in managing business relationships with organizations (Art. 6(1)(f) GDPR).
5.7 Recording and transcribing meetings. We may record, transcribe, and summarize video calls using a meeting recording service (Fathom) for note-taking, quality, and contract performance. We inform participants at the start of each recorded call, and you may ask us to proceed without recording. Where applicable law requires the consent of all participants, we obtain that consent before recording. Legal basis: your consent (Art. 6(1)(a) GDPR) or, where permitted, our legitimate interests in accurate records of business discussions (Art. 6(1)(f) GDPR).
5.8 Legal compliance, sanctions screening, security, and fraud prevention. Legal basis: compliance with legal obligations (Art. 6(1)(c) GDPR) and our legitimate interests in protecting our business, systems, and users (Art. 6(1)(f) GDPR).
5.9 Establishing, exercising, or defending legal claims. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
5.10 Internal operations, research, and development, including the creation of de-identified and aggregated statistics to improve our Services. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
5.11 Corporate transactions, including due diligence in connection with a financing, merger, acquisition, reorganization, or sale of assets. Legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
We do not use Personal Data for purposes that are incompatible with the purposes described above without first providing notice and, where required, obtaining your consent.
6. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING
6.1 Use of Artificial Intelligence. We use artificial intelligence tools, including large language models provided by third parties such as Anthropic, to research companies, summarize publicly available information, draft personalized business communications, classify data, and support our engineering work. The use of these tools is subject to human oversight.
6.2 Model Training. Where available, we use artificial intelligence services under commercial terms that do not permit the provider to use our inputs to train its general-purpose models.
6.3 Profiling and Automated Decision-Making. We use Lead Scoring and similar Profiling solely to prioritize business communications. We do not engage in decision-making based solely on automated processing that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR, and we do not engage in Profiling in furtherance of decisions that produce legal or similarly significant effects within the meaning of U.S. state privacy laws. You may object to Profiling as described in Section 11.
7. DISCLOSURE OF PERSONAL DATA
7.1 Service Providers and Processors. We disclose Personal Data to service providers that process it on our behalf and in accordance with our instructions, under written agreements that require them to protect it. These include providers of the following services:
- HubSpot: customer relationship management, marketing automation, forms, website tracking, and cookie consent management;
- Google: Google Workspace (email, calendar, documents), Google Analytics, and Google Ads;
- Slack: internal communication;
- Linear: project management;
- EmailBison: email sending infrastructure;
- AI Ark: business contact data and enrichment;
- Anthropic: artificial intelligence models and tools;
- Calendly: meeting scheduling;
- Fathom: meeting recording, transcription, and summaries;
- Scribeless: handwritten postal correspondence;
- PandaDoc: proposals, contracts, and electronic signatures;
- 1Password: credential management;
- Railway: hosting of internal software and automations;
- GitHub: source code hosting;
- Sentry: error and performance monitoring; and
- website hosting, content delivery, and email verification providers.
7.2 Advertising and Social Media Platforms. We disclose Personal Data to, and receive Personal Data from, LinkedIn, Meta, and Google in connection with advertising, audience matching, conversion measurement, and our company pages. These platforms generally act as independent controllers of the Personal Data they process. For certain processing, such as page insights and data collected through their pixels on our Website, we may be joint controllers with the relevant platform under Article 26 of the GDPR. Upon request, we will provide the essence of the relevant joint controller arrangement.
7.3 No Transfer of Our Marketing Data to Clients. We do not sell or rent Personal Data collected for our own marketing purposes to Clients or other third parties for their independent use.
7.4 Professional Advisers and Financial Institutions. We disclose Personal Data to our lawyers, accountants, auditors, insurers, banks, and payment providers where necessary for the purposes described in this Policy.
7.5 Legal and Regulatory Disclosures. We disclose Personal Data where we believe in good faith that disclosure is required by law, regulation, subpoena, court order, or other legal process; to respond to requests from public authorities; to enforce our agreements; or to protect the rights, property, or safety of the Company, our Clients, or others.
7.6 Corporate Transactions. We may disclose Personal Data to a prospective or actual acquirer, investor, successor, or assignee in connection with a financing, merger, acquisition, reorganization, bankruptcy, or sale of all or part of our business or assets, subject to appropriate confidentiality obligations.
7.7 With Your Consent. We disclose Personal Data to other parties with your consent or at your direction.
7.8 No Sale for Monetary Consideration; Sharing for Advertising. We do not sell Personal Data for monetary consideration. Our use of advertising cookies and pixels and of audience matching may constitute a "Sale," "Sharing," or "Targeted Advertising" under certain U.S. state laws. You may opt out as described in Sections 10 and 11.
8. CLIENT CAMPAIGNS: OUR ROLE AS PROCESSOR AND SERVICE PROVIDER
8.1 Roles. When we process Client Campaign Data, the Client is the controller and the Company acts as a processor or service provider, in accordance with a Data Processing Agreement and the Client's documented instructions.
8.2 Client Responsibility. Each Client is responsible, as controller, for establishing a lawful basis for its campaigns; providing required notices; obtaining consents where required; the content, accuracy, and legality of its messages and claims; compliance with laws and regulations applicable to its products, services, and target markets, including rules governing financial promotions and the marketing of financial instruments; and providing us with its do-not-contact lists.
8.3 Exercising Your Rights. Communications sent as part of a Client campaign identify the Client as the sender. If you wish to exercise your rights with respect to such communications, please contact the Client directly. If we receive a request relating to Client Campaign Data, we will forward it to the relevant Client without undue delay and assist the Client as required by our agreement with it.
8.4 No Independent Use. We do not use Client Campaign Data for our own purposes, except as permitted by our agreement with the Client and by Applicable Data Protection Law, for example to maintain the security of our systems, to comply with legal obligations, or to create de-identified and aggregated statistics.
9. FINANCIAL MARKETS NOTICE
The Website, our content, and our communications concern the growth, marketing, and technology Services of the Company. Nothing on the Website or in our communications constitutes investment, legal, tax, or financial advice, or an offer or solicitation to buy or sell any security or other financial instrument. The Company is not a broker-dealer, investment adviser, placement agent, or investment manager. Where our Services support a Client in regulated activities, the Client remains solely responsible for compliance with the laws and regulations applicable to those activities.
10. COOKIES, PIXELS, AND SIMILAR TECHNOLOGIES
10.1 Technologies We Use. We and our partners use cookies, pixels, tags, scripts, and similar technologies in the following categories:
(a) Strictly necessary: technologies required to operate and secure the Website and to store your privacy preferences;
(b) Analytics: Google Analytics and HubSpot analytics, used to measure how the Website is used and how our content performs;
(c) Advertising and marketing: the Meta Pixel, the LinkedIn Insight Tag, Google Ads conversion and remarketing tags, and HubSpot tracking, used to measure the effectiveness of our advertising, to build and reach audiences, and to associate Website visits with existing contact records; and
(d) Email tracking: tracking pixels and link redirects in our emails, used to determine whether our emails are delivered, opened, and clicked.
The cookie banner on the Website lists the specific technologies, their providers, and their durations.
10.2 Visitors in the EEA, United Kingdom, and Switzerland. We use technologies other than strictly necessary technologies only with your prior consent, which you give through our cookie banner. You may withdraw or change your consent at any time through the "Cookie Settings" link in the footer of the Website.
10.3 Visitors in the United States. We may use analytics and advertising technologies subject to your right to opt out through the "Your Privacy Choices" link in the footer of the Website. We treat a Global Privacy Control ("GPC") signal sent by your browser as a valid request to opt out of Sales, Sharing, and Targeted Advertising for that browser and, where we are able to associate the signal with you, for your contact record.
10.4 Do Not Track. There is no uniform standard for recognizing "Do Not Track" signals. We respond to GPC signals as described in Section 10.3.
10.5 Email Tracking. You can prevent email tracking by disabling the automatic loading of images and remote content in your email client. Where applicable law requires consent for email tracking, we either obtain that consent or disable open tracking.
10.6 Additional Controls. You can also manage cookies through your browser settings, use the Google Analytics opt-out browser add-on, adjust your advertising preferences on LinkedIn, Meta, and Google, and use industry opt-out tools, including those available at optout.networkadvertising.org, optout.aboutads.info, and youronlinechoices.eu.
11. YOUR PRIVACY RIGHTS AND CHOICES
11.1 Opting Out of Marketing (All Individuals). You may opt out of our marketing communications at any time, regardless of where you are located, by clicking the unsubscribe link in any of our emails, replying to any of our messages with a request to stop, or emailing victor@029growth.com. You may opt out of postal correspondence and LinkedIn communications in the same way. We process opt-out requests promptly and in any event within ten (10) business days. We retain the minimum information necessary on a suppression list so that we do not contact you again.
11.2 Individuals in the EEA, United Kingdom, and Switzerland. Subject to the conditions and exceptions set out in Applicable Data Protection Law, you have the right to:
(a) access your Personal Data and obtain a copy of it;
(b) request the rectification of inaccurate Personal Data;
(c) request the erasure of your Personal Data;
(d) request the restriction of processing;
(e) receive Personal Data that you have provided to us in a structured, commonly used, and machine-readable format and have it transmitted to another controller;
(f) withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal; and
(g) lodge a complaint with a supervisory authority, in particular in the country of your habitual residence, your place of work, or the place of the alleged infringement.
> RIGHT TO OBJECT. Where we process your Personal Data on the basis of our legitimate interests, you have the right to object to that processing at any time on grounds relating to your particular situation. Where we process your Personal Data for direct marketing purposes, including Profiling to the extent it is related to direct marketing, you have the right to object at any time without giving reasons, and we will then cease processing your Personal Data for those purposes.
11.3 Residents of U.S. States. Depending on your state of residence, you may have the right to:
(a) confirm whether we process your Personal Data and access that Personal Data;
(b) correct inaccuracies in your Personal Data;
(c) delete your Personal Data;
(d) obtain a copy of your Personal Data in a portable format;
(e) opt out of the Sale of your Personal Data, Sharing for cross-context behavioral advertising, Targeted Advertising, and Profiling in furtherance of decisions that produce legal or similarly significant effects; and
(f) not be discriminated against for exercising any of these rights.
Certain U.S. state privacy laws, including the DPDPA, do not apply to Personal Data processed in a commercial or employment context. As a matter of policy, we nonetheless honor requests to access, correct, delete, and opt out from any Business Contact located in the United States, subject to verification and to the exceptions permitted by law.
Appeals. If we decline to take action on your request, you may appeal our decision by emailing victor@029growth.com with the subject line "Privacy Appeal." We will respond to your appeal in writing within sixty (60) days of receipt and will explain the reasons for our decision. If we deny your appeal, you may contact the Attorney General of your state of residence; residents of Delaware may contact the Delaware Department of Justice.
Authorized Agents. You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of authorization and may require you to verify your identity directly with us.
11.4 Additional Disclosures for California Residents. During the twelve (12) months preceding the Effective Date, we collected the following categories of personal information, as defined in the CCPA:
(a) identifiers, such as name, business email address, business postal address, IP address, and online identifiers;
(b) personal information described in Cal. Civ. Code § 1798.80(e), such as name, business address, and employment information;
(c) commercial information, such as records of Services purchased or considered;
(d) internet or other electronic network activity information, such as Website browsing and email engagement data;
(e) approximate geolocation data derived from IP addresses;
(f) audio, electronic, and visual information, such as call recordings;
(g) professional or employment-related information, such as job title, employer, and professional background; and
(h) inferences drawn from the foregoing, such as Lead Scoring.
We collect these categories from the sources described in Sections 3 and 4, for the purposes described in Section 5, and we retain them for the periods described in Section 13. We disclose each of these categories for business purposes to the service providers and contractors described in Section 7.1. We do not sell personal information for monetary consideration. We may Share identifiers and internet or other electronic network activity information with advertising platforms, including LinkedIn, Meta, and Google, for cross-context behavioral advertising. We do not collect or use sensitive personal information for the purpose of inferring characteristics about you. We do not knowingly Sell or Share the personal information of individuals under sixteen (16) years of age. We do not offer financial incentives in exchange for personal information.
11.5 Individuals in Canada. We send commercial electronic messages to recipients in Canada only with express or implied consent as permitted under CASL, including where your business email address has been conspicuously published without a statement that you do not wish to receive unsolicited commercial electronic messages and our message relates to your business role. Each message identifies the Company and includes an unsubscribe mechanism. You may request access to or correction of your Personal Data under PIPEDA as described in Section 11.6.
11.6 How to Exercise Your Rights. To exercise any of your rights, email victor@029growth.com with the subject line "Privacy Request" and describe your request. To protect your Personal Data, we verify requests by matching the information you provide with the information we hold, and we may ask for additional information where necessary. We respond to requests within one (1) month under the GDPR, the UK GDPR, and the FADP, and within forty-five (45) days under U.S. state laws. Where permitted by law, we may extend these periods and will inform you of any extension and the reasons for it. We do not charge a fee for handling requests unless a request is manifestly unfounded or excessive.
12. INTERNATIONAL DATA TRANSFERS
12.1 Transfers. The Company is organized in the United States. Our personnel and service providers may process Personal Data in the United States, the European Union, the United Kingdom, and other countries whose data protection laws may differ from those of your country.
12.2 Safeguards. Where we transfer Personal Data from the EEA, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of data protection, we rely on appropriate safeguards, including the certification of the recipient under the EU-U.S. Data Privacy Framework, the UK Extension to that framework, or the Swiss-U.S. Data Privacy Framework; the Standard Contractual Clauses adopted by the European Commission; the UK International Data Transfer Addendum; and the corresponding Swiss adaptations, together with supplementary measures where appropriate. You may request a copy of the relevant safeguards by contacting us.
12.3 Representative. If we designate a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR, we will identify that representative in this Policy.
13. DATA RETENTION
We retain Personal Data only for as long as necessary for the purposes described in this Policy, unless a longer retention period is required or permitted by law. In particular:
(a) Prospect data: until twenty-four (24) months after our last meaningful interaction with you if no business relationship is established, after which we delete or anonymize it;
(b) Suppression list: for as long as necessary to honor your opt-out, limited to the minimum information required for that purpose;
(c) Client and vendor representative data: for the duration of the business relationship and thereafter for up to seven (7) years, or longer where required by tax, accounting, or other legal obligations;
(d) Call recordings and transcripts: up to twelve (12) months after the call, unless a longer period is necessary for the performance of a contract or for the establishment, exercise, or defense of legal claims;
(e) Website server logs: up to thirty (30) days, unless required for security investigations;
(f) Analytics data: up to fourteen (14) months; and
(g) Client Campaign Data: as specified in the applicable Data Processing Agreement, after which we delete or return it at the Client's election.
14. DATA SECURITY
We implement reasonable and appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, loss, misuse, alteration, and disclosure. These measures include encryption in transit, access controls based on the principle of least privilege, multi-factor authentication, centralized credential management, logging and monitoring, vendor due diligence, and incident response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach, we will notify affected individuals, supervisory authorities, and other parties as and when required by Applicable Data Protection Law.
15. THIRD-PARTY PLATFORMS, SERVICES, AND LINKS
The Website and our communications may contain links to, or integrations with, third-party websites, platforms, and services, including LinkedIn, Meta, Google, X, and YouTube. These third parties process Personal Data in accordance with their own privacy policies, and we encourage you to review them. To the maximum extent permitted by applicable law, the Company is not responsible for, and disclaims all liability arising from, the privacy, security, or data practices of any third-party website, platform, or service that is not acting as the Company's processor or service provider. Nothing in this Section limits our obligations with respect to processors and service providers acting on our behalf or any liability that cannot be limited under Applicable Data Protection Law.
16. BUSINESS-TO-BUSINESS DIRECT MARKETING COMPLIANCE
16.1 Nature of Our Communications. Our direct marketing is conducted exclusively in a business-to-business context and relates to the professional role of the recipient. Business-to-business prospecting is a lawful and customary commercial activity when conducted in accordance with Applicable Data Protection Law and the laws governing electronic communications.
16.2 United States. Our commercial emails comply with the CAN-SPAM Act. They use accurate header and routing information, do not use deceptive subject lines, identify the Company as the sender, include our valid physical postal address, and provide a functioning opt-out mechanism. We honor opt-out requests within ten (10) business days and do not sell or transfer the email addresses of individuals who have opted out.
16.3 Canada. We comply with CASL as described in Section 11.5.
16.4 EEA, United Kingdom, and Switzerland. We comply with national laws implementing the ePrivacy Directive, PECR, and the FADP. The rules for business-to-business electronic marketing differ between countries. Where a country requires the recipient's prior consent for electronic marketing, we obtain that consent or use another lawful channel.
16.5 Postal and LinkedIn Communications. We send postal correspondence, including handwritten cards, and LinkedIn messages on the basis described in Section 5.3 and in accordance with the terms of the relevant platform. You may opt out of these communications as described in Section 11.1.
17. CHILDREN
The Website and our Services are intended for businesses and professionals and are not directed to individuals under eighteen (18) years of age. We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child, we will delete it.
18. LIMITATION OF LIABILITY
To the maximum extent permitted by applicable law, and except as expressly set forth in a written agreement signed by the Company: (a) in no event shall the Company be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenue, business, goodwill, or data, arising out of or relating to this Policy; and (b) the Company's aggregate liability arising out of or relating to this Policy shall not exceed one hundred U.S. dollars (US$100).
Nothing in this Policy excludes or limits: (i) any liability that cannot be excluded or limited under applicable law; (ii) the rights of data subjects under the GDPR, the UK GDPR, or the FADP, including the right to compensation under Article 82 of the GDPR; or (iii) any right that may not be waived under the CCPA or other applicable law.
19. GOVERNING LAW AND DISPUTE RESOLUTION
19.1 Governing Law. This Policy and any dispute arising out of or relating to it shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict of laws principles.
19.2 Forum. Subject to Section 19.6, any action or proceeding arising out of or relating to this Policy shall be brought exclusively in the state or federal courts located in the State of Delaware, including the Superior Court of the State of Delaware and the United States District Court for the District of Delaware, and you and the Company consent to the personal jurisdiction of those courts. If you have entered into a signed agreement with the Company that provides for arbitration or another forum, the dispute resolution provisions of that agreement shall govern.
19.3 Informal Resolution. Before commencing any proceeding, the party asserting a claim shall give the other party written notice describing the claim, and the parties shall attempt in good faith to resolve the dispute within thirty (30) days of that notice.
19.4 WAIVER OF JURY TRIAL. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, YOU AND THE COMPANY EACH KNOWINGLY, VOLUNTARILY, AND IRREVOCABLY WAIVE ANY RIGHT TO A TRIAL BY JURY IN ANY ACTION OR PROCEEDING ARISING OUT OF OR RELATING TO THIS POLICY.
19.5 WAIVER OF CLASS AND REPRESENTATIVE ACTIONS. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, ANY ACTION OR PROCEEDING ARISING OUT OF OR RELATING TO THIS POLICY SHALL BE BROUGHT AND CONDUCTED SOLELY ON AN INDIVIDUAL BASIS, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION.
19.6 Mandatory Law. Nothing in this Section 19 deprives any individual of the protection afforded by mandatory provisions of the law of the country or state of his or her residence, including the right of data subjects in the EEA, the United Kingdom, and Switzerland to lodge a complaint with a supervisory authority and to bring proceedings before the competent courts under Article 79 of the GDPR and equivalent provisions, or waives any right that may not be waived under applicable law.
19.7 Severability. If any provision of this Policy is held to be invalid or unenforceable, that provision shall be enforced to the maximum extent permissible, and the remaining provisions shall remain in full force and effect.
20. CHANGES TO THIS POLICY
We may update this Policy from time to time. The updated version will be indicated by a revised "Last Updated" date and becomes effective upon posting on the Website. Where changes are material, we will provide additional notice as required by Applicable Data Protection Law.
21. CONTACT US
Affluent Ventures LLC, d/b/a 029 Growth 111B S Governors Ave, STE 28959 Dover, Delaware 19904 United States
Email: victor@029growth.com