Skip to content
Mission Growth
  • Free Tools
  • About
  • Cases
  • Docs
Log in

Privacy policy

Last updated: May 12, 2026Counsel review: pending

Contents

  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Who we share data with
  5. International data transfers
  6. Data retention
  7. Your rights
  8. Security
  9. Cookies and tracking
  10. AI and automated processing
  11. Children's data
  12. Changes to this policy
  13. Contact and complaints
Contents

Contents

  1. Who we are
  2. What data we collect
  3. How we use your data
  4. Who we share data with
  5. International data transfers
  6. Data retention
  7. Your rights
  8. Security
  9. Cookies and tracking
  10. AI and automated processing
  11. Children's data
  12. Changes to this policy
  13. Contact and complaints

Mission Growth Limited operates a B2B AI analytics platform (the Service). This policy explains what personal data we collect about you, how we use it, and what rights you have. We have written it in plain language so it is easy to read.

If you have any questions, email us at contact@missiongrowth.io.

Who we are

Mission Growth Limited is a company incorporated in Hong Kong (Companies Registry No. 78661026). Our registered address is Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R.

For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Mission Growth Limited is the data controller of the personal data it collects about you directly (for example, your name and email address when you create an account or contact us). When we process data on behalf of our customers inside their workspaces, we act as a data processor and their own privacy policy governs that data.

For the purposes of the Hong Kong Personal Data (Privacy) Ordinance (PDPO), Mission Growth Limited is the data user. For the purposes of Turkey's Personal Data Protection Law (KVKK), Mission Growth Limited is the veri sorumlusu (data controller). For privacy matters relating to Turkey, please contact us at contact@missiongrowth.io.

What data we collect

We collect data in 5 categories:

  • Account data: your name, work email address, job title, and company name when you register or are invited to the platform. - Billing data: company billing address, invoice contact, and payment reference numbers. We do not store full card numbers. Payment processing is handled by Airwallex. - Usage data: logs of features you use, pages you visit, actions you take inside the platform, and session recordings (see section 9 for details). - Support data: messages you send us by email or through any support channel, including any content you share to illustrate a problem. - Technical data: IP address, browser type and version, device type, and timezone.

We do not collect sensitive personal data (for example, health information or racial or ethnic origin). The Service is designed for business users. Personal data processed inside your workspace (such as social media profiles or competitor contact data you load into the platform) is processed on your instruction. You are the controller of that data.

How we use your data

We use your data only for the purposes listed below. For each purpose we have identified the legal basis we rely on under the GDPR and KVKK.

  • Providing the Service (account data, usage data, technical data): necessary to perform our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)). - Billing and invoicing (billing data): necessary to perform our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)). - Security and fraud prevention (technical data, usage logs): our legitimate interest in keeping the platform secure (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)). - Product improvement and analytics (usage data, session recordings): our legitimate interest in understanding how the Service is used so we can improve it (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)). You may opt out of analytics cookies at any time (see section 9). - Responding to support requests (support data): our legitimate interest in resolving customer issues. - Legal compliance (any category): where we are required by applicable law to retain or disclose data (GDPR Art. 6(1)(c); KVKK Art. 5(2)(a)).

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

Who we share data with

We share personal data only with the following parties:

  • Sub-processors: companies we engage to help us deliver the Service, including Supabase (database and authentication), Hetzner (server infrastructure), Vercel (frontend hosting), Airwallex (payment processing), OpenAI and Together AI (AI model inference), Composio (tool integrations), and PostHog (product analytics). We maintain a full sub-processor list at /legal/subprocessors. - Professional advisors: lawyers, accountants, and auditors acting under obligations of confidentiality. - Law enforcement or regulatory authorities: where we are legally required to disclose data, or where disclosure is necessary to protect the safety of any person.

We do not share data with other customers or with third parties for their own marketing purposes.

International data transfers

Our service involves transferring personal data across borders. Here is how we protect your data in each case.

Transfers from the European Economic Area (EEA). The European Commission has not issued an adequacy decision for Hong Kong. Where we transfer personal data from the EEA to Mission Growth Limited in Hong Kong, or onward to sub-processors located in the United States (Vercel, OpenAI, Together AI, Composio), we rely on the Standard Contractual Clauses approved by the European Commission (Module 2, Controller to Processor) as the appropriate safeguard under GDPR Article 46(2)(c). A copy of the applicable clauses is available upon written request.

Transfers from Turkey. Following the reform of KVKK Article 9 (effective 1 June 2024), cross-border transfers from Turkey are governed by Turkish Standard Contract clauses. We use these clauses with our sub-processors as required under Turkish Data Protection Authority (KVKK) Decision 2024/959.

Transfers from Hong Kong. Section 33 of the PDPO (cross-border transfer restrictions) is not currently in force. We nonetheless follow the PCPD's May 2022 voluntary guidance and use model contractual clauses when transferring data from Hong Kong to sub-processors in the United States. We will update this policy if mandatory cross-border transfer requirements come into force under pending PDPO amendments.

Data retention

We keep personal data only as long as necessary for the purposes described in this policy.

  • Account data: kept for the duration of your subscription and deleted within 90 days of account closure on written request. - Billing data: retained for 7 years to satisfy tax and accounting obligations under Hong Kong law. - Usage and technical data (logs): retained for 12 months for security and product improvement purposes, then deleted. - Support data: retained for 3 years from the date of the support interaction, then deleted. - AI model inference inputs and outputs processed by our LLM sub-processors: retained by those sub-processors for a maximum of 30 days for abuse monitoring purposes, then deleted. They do not use this data for model training.

When you close your account, you may request a data export within 90 days of closure. After that window, your workspace data is securely deleted.

Your rights

Depending on where you are located, you have the following rights in relation to your personal data.

If you are in the EEA or UK (GDPR/UK GDPR): - Access (Art. 15): request a copy of the data we hold about you. - Correction (Art. 16): ask us to correct inaccurate data. - Erasure (Art. 17): ask us to delete your data in certain circumstances. - Restriction (Art. 18): ask us to restrict processing while a dispute is resolved. - Portability (Art. 20): receive your data in a machine-readable format. - Objection (Art. 21): object to processing based on legitimate interests. - Withdraw consent: where we rely on consent, you may withdraw it at any time.

If you are in Turkey (KVKK Art. 11): - Learn whether your personal data is being processed. - Request information about the purpose of processing and whether data is used in accordance with that purpose. - Know the third parties to whom your data is transferred. - Request correction, deletion, or destruction of your data. - Object to the processing of your data by automated means that produces a result against your interests.

If you are in Hong Kong (PDPO DPP5 and DPP6): - Request access to personal data we hold about you. - Request correction of inaccurate data. - We will respond to access and correction requests within 40 days as required by the PDPO. A reasonable fee may be charged for access requests.

To exercise any of these rights, email contact@missiongrowth.io. We will respond within 30 days (or 40 days for HK PDPO requests). We may need to verify your identity before acting on a request.

Security

We take the security of your data seriously. Our technical and organisational measures include:

  • Encryption at rest: all data stored in our Supabase-hosted database is encrypted at rest using AES-256. - Encryption in transit: all connections to and from the platform use TLS 1.3. - Access controls: access to production systems is restricted to authorised personnel and requires multi-factor authentication. - Sub-processor audits: our key infrastructure providers (Supabase, Hetzner, Vercel) hold ISO 27001 and/or SOC 2 certifications. We review their security posture when engaging them and on renewal. - Incident response: if we become aware of a data breach that is likely to cause risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

No system is completely secure. If you discover a potential vulnerability, please email contact@missiongrowth.io and we will respond within 48 hours.

Cookies and tracking

We use cookies and similar technologies on our website and within the platform. Our full Cookie Policy is available at /legal/cookies.

We use PostHog for product analytics and exception tracking, hosted on EU infrastructure (Frankfurt, eu-central-1). PostHog operates in two distinct modes depending on your consent state:

  • Pre-consent (cookieless mode): PostHog counts visits via a server-side daily-rotating hash. No cookies or localStorage entries are written on your device before you make a consent choice. The hash cannot be reversed to identify you. This is technically equivalent to server log analysis and does not require consent under ePrivacy Directive Article 5(3). - Post-consent (cookie mode): if you accept, PostHog sets a pseudonymous identifier cookie and enables session recording. All form fields are masked by default so any text you type is never captured.

If you reject analytics, PostHog stays in cookieless mode — usage counting continues but no cookies are set and session recording is not enabled. You may switch modes at any time via the cookie preferences panel.

AI and automated processing

The Service uses large language models (LLMs) to generate analytics, insights, and recommendations for your business. Here is what you need to know.

  • No training on your data: we do not use your data, your inputs, or your AI-generated outputs to train, fine-tune, or improve any AI model, including models operated by our AI sub-processors (OpenAI and Together AI). This is contractually required in our agreements with those providers. - Prompts are confidential: your inputs and prompts to the platform are treated as your confidential information. - You own the outputs: all AI-generated outputs produced by the Service in response to your inputs are owned by you. We claim no intellectual property rights in them. - No fully automated decisions with legal effect: we do not make decisions about you using solely automated means that produce a legal or similarly significant effect. An AI output that affects your business strategy is presented for your review and decision, not applied automatically to your account or legal status.

AI outputs may contain errors, omissions, or inaccuracies. You are responsible for reviewing outputs before relying on them for business decisions.

Children's data

The Service is a B2B platform designed for business professionals. It is not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18.

If you believe we have inadvertently collected data from a minor, please contact us at contact@missiongrowth.io and we will delete it promptly.

Changes to this policy

We may update this policy from time to time. If we make material changes (for example, to the purposes for which we process data or the legal basis we rely on), we will notify you by email at least 30 days before the changes take effect. The updated policy will be published at /legal/privacy with a new effective date.

For non-material changes (for example, updated contact details or clarifications), we will publish the updated policy without advance notice. Continued use of the Service after the effective date of any change constitutes acceptance of the updated policy.

Contact and complaints

To contact us about this policy or to exercise your data rights, email contact@missiongrowth.io. Our registered address is Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R.

If you are in the EEA or UK, you have the right to lodge a complaint with the supervisory authority in your country of residence or place of work. You can find the relevant authority at https://edpb.europa.eu/about-edpb/about-edpb/members_en.

If you are in Turkey, you have the right to lodge a complaint with the Turkish Personal Data Protection Authority (KVKK): https://www.kvkk.gov.tr.

If you are in Hong Kong, you have the right to lodge a complaint with the Office of the Privacy Commissioner for Personal Data (PCPD): https://www.pcpd.org.hk. The PCPD may investigate complaints and issue enforcement notices. We aim to resolve all complaints directly before they reach a supervisory authority. Please contact us first.

Legal notice

This document is a current-state version of our legal terms, prepared with research from leading B2B SaaS templates and Hong Kong / EU / Türkiye regulatory sources. It is undergoing review by Hong Kong-licensed counsel and Turkish counsel where applicable. Please contact contact@missiongrowth.io with any questions or to request the latest counsel-reviewed version.

Mission Growth

An always-on growth team. AI catches the signal, experts make the move, you see the result.

Unit 2A, 17/F, Glenealy Tower
1 Glenealy, Central, Hong Kong S.A.R.

Company

  • About
  • Case Studies
  • Free Tools
  • Docs
  • Blog

Legal

  • Privacy
  • Terms
  • Security
  • Cookies
  • DPA
  • Subprocessors
  • KVKK

© 2026 Mission Growth. All rights reserved.

Cookies

We use cookies to keep the site running. Read our policy.

Strictly necessary

Authentication and core platform. Always on.

Analytics

Anonymised product usage via PostHog. Form fields are masked.