Privacy Policy
Effective date: July 28, 2026
Last updated: July 28, 2026
This Privacy Policy explains how Utah CRO Corp. d/b/a DataXGrowth (“DataXGrowth,” “DXG,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit dataxgrowth.com, submit a form, communicate with us, request a Growth Audit, engage our consulting services, or interact with DataXGrowth AI and related services (collectively, the “Services”).
This Policy applies to information we handle as a controller or business for our own purposes. When we process information on behalf of a client, the client generally determines the purposes and means of processing, and we act as a processor, service provider, or contractor under the applicable agreement. If a client agreement conflicts with this Policy regarding client-provided data, the client agreement controls.
By using the Services, you acknowledge the practices described in this Policy. If you do not agree, do not provide personal information through the Services.
1. Scope and who we are
DataXGrowth is a growth marketing consultancy that provides strategy, analytics and attribution, SEO and AEO, conversion optimization, paid acquisition strategy, growth technology, audits, and AI-enabled marketing intelligence. Our Services are primarily intended for businesses and professionals, but business contact information can still be personal information.
This Policy does not govern a client’s independent privacy practices, third-party websites or platforms, or information processed solely under a separate employee, contractor, or applicant notice.
2. Personal information we collect
The information we collect depends on how you interact with us, the Services you request, the technologies enabled on the Site, and the data sources a client authorizes us to use.
Information you provide directly
- Contact and business information, such as your name, business email address, phone number, company, job title, and location.
- Inquiry and engagement information, such as your goals, marketing challenges, budget or timing information, service interests, project requirements, and messages submitted through forms.
- Communications and content, including emails, call notes, meeting recordings or transcripts when notice or consent is provided as required, feedback, files, and other materials you choose to share.
- Commercial, contract, and billing information, such as proposals, service history, transaction records, billing contacts, and payment-related details. Payment information may be processed by third-party payment providers rather than stored directly by us.
- Privacy request information needed to understand, verify, and respond to a request.
Please do not send sensitive personal information unless it is necessary for an agreed service and you are authorized to provide it.
Information collected automatically
- Device and network information, such as IP address, device or browser identifiers, browser and device characteristics, operating system, language, approximate location derived from IP address, and pseudonymous fingerprint or identity-resolution signals.
- Usage information, such as pages viewed, referring and exit pages, timestamps, clicks, form interactions, session activity, and interactions with content or campaigns.
- Cookie and advertising information, including cookie identifiers, consent choices, campaign parameters, and information used to measure or personalize marketing where permitted.
- Diagnostics and security information, such as logs, error reports, suspected abuse, and information used to protect the Site and Services.
Client and service data
When a client authorizes us to perform consulting, analytics, integration, or DataXGrowth AI services, we may process data from the client’s systems. Depending on the engagement, this may include:
- Website, search, advertising, ecommerce, CRM, sales, lifecycle, attribution, and revenue data.
- Authorized operational context from tools such as Slack, Asana, meeting platforms, project-management systems, campaign briefs, strategy documents, and structured files.
- Business contact information and information about a client’s personnel, prospects, leads, customers, or users that appears in authorized sources.
- Integration credentials, API tokens, access permissions, and configuration data used to connect approved systems.
Clients are responsible for providing appropriate notices, obtaining required permissions or consents, and ensuring they have a lawful basis to provide Client Data to us. We process Client Data only for the agreed scope, client instructions, security, support, legal compliance, and other purposes permitted by the applicable agreement.
Information from other sources
We may receive information from clients, referrals, business partners, service providers, integration platforms, public business sources, and social or professional networks. We may combine this information with information collected through the Services.
3. DataXGrowth AI
DataXGrowth AI is a consulting-led marketing intelligence system. With client authorization, it connects quantitative performance data with operational context to identify material changes, evaluate likely explanations, prepare evidence-linked insights, and recommend actions. DataXGrowth specialists review material outputs before they are delivered through approved dashboards or workflows.
DataXGrowth AI is not designed to independently change campaigns, budgets, websites, or business strategy without human governance and client-approved workflows. We do not use Site visitor information to make decisions that produce legal or similarly significant effects.
We maintain client-specific access and context controls designed to prevent one client’s identifiable data from being exposed to another client. We do not use identifiable Client Data or client confidential information to train generalized public or cross-client AI models unless the client expressly authorizes that use in writing.
We may create and use aggregated or de-identified information to operate, secure, measure, and improve the Services, provided that the information cannot reasonably be used to identify an individual or client. We do not attempt to re-identify de-identified information except to test whether de-identification measures are effective or as permitted by law.
4. How we use personal information
- Provide, operate, configure, support, and secure the Site and Services.
- Respond to inquiries, schedule conversations, prepare proposals, and manage client relationships.
- Deliver Growth Audits, consulting work, analytics, dashboards, integrations, research, and DataXGrowth AI outputs.
- Connect authorized data sources, validate data quality, reconcile metrics, detect trends, and prepare human-reviewed recommendations.
- Administer contracts, billing, records, and business operations.
- Measure Site and campaign performance, understand audience behavior, and improve content, user experience, and Services.
- Send service communications and, where permitted, marketing communications about relevant DataXGrowth offerings.
- Prevent fraud, misuse, security incidents, and violations of our agreements or policies.
- Comply with law, enforce agreements, establish or defend legal claims, and respond to lawful requests.
- Create aggregated or de-identified analytics and business insights.
5. Legal bases for processing
Where applicable law requires a legal basis, we process personal information as necessary to perform a contract or take requested pre-contract steps; based on our legitimate interests in operating, improving, securing, and marketing our business; with your consent; or to comply with legal obligations and protect legal rights. You may withdraw consent at any time, but withdrawal does not affect processing already completed or processing based on another lawful ground.
6. Cookies and similar technologies
We and our providers may use cookies, pixels, tags, local storage, pseudonymous device fingerprinting, identity-resolution tools, and similar technologies. Current Site technologies may include Google Tag Manager, Google Analytics and Google Ads, Meta Pixel, LinkedIn Insight Tag, FullContact, FingerprintJS, and Primer Analytics. Providers may change as our technology stack changes. Depending on the technologies enabled and your choices, these may include:
- Strictly necessary technologies used for security, fraud prevention, site operation, form delivery, and consent management.
- Analytics and performance technologies used to measure traffic, engagement, attribution, and Site performance.
- Functionality technologies used to remember preferences or support embedded tools and experiences.
- Advertising technologies used to measure campaigns, build audiences, or deliver more relevant advertising where permitted.
You can block or delete cookies through your browser. Where a consent or cookie-preference tool is presented, you can use it to change non-essential cookie choices. Blocking some technologies may affect Site functionality.
Where required by applicable law, we treat a recognized opt-out preference signal, including Global Privacy Control, as a request to opt out of sale, sharing, or targeted advertising for the browser or device sending the signal. Because these signals are browser- and device-specific, you may need to enable the signal on each browser and device. Other “Do Not Track” signals are not standardized, so we do not respond to them unless required by law.
7. How we disclose personal information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
- Cloud hosting, content management, form, scheduling, communications, CRM, analytics, advertising, payment, accounting, security, IT, and professional-service providers.
- AI, data, dashboard, integration, and collaboration providers used to deliver an authorized client engagement.
- Clients and their authorized users when information or an output is delivered as part of a client-directed service.
- Business partners or subcontractors supporting a specific service, subject to appropriate contractual restrictions.
- Lawyers, accountants, insurers, auditors, and other professional advisers.
- Government authorities, law enforcement, courts, or other parties when required by law or reasonably necessary to protect rights, safety, and security.
- A buyer, investor, lender, or successor in connection with a merger, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
We do not sell personal information for money. Some disclosures of identifiers and internet or network activity to advertising or analytics providers may be considered a “sale,” “sharing,” or targeted advertising under certain state privacy laws, even when no money is exchanged. You may opt out as described in the “Your privacy rights and choices” section.
We do not knowingly sell or share the personal information of individuals under 16 years of age.
8. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, the applicable client agreement, and legal, accounting, security, and dispute-resolution requirements. Intended periods depend on the category and context:
- Inquiry and business-contact records are generally retained while the relationship is active and for a reasonable period afterward, typically up to three years after the last meaningful interaction.
- Client Data is retained for the engagement and then returned, deleted, or retained as specified by the client agreement and documented instructions, subject to limited backup, security, and legal-retention needs.
- Contracts, invoices, and transaction records may be retained for up to seven years or longer if required by law.
- Analytics, cookie, and campaign data is retained according to the applicable provider configuration, generally for no longer than 26 months unless a longer period is needed for security, attribution, or legal purposes.
- Security logs are generally retained for up to 24 months unless an incident or legal obligation requires longer retention.
- Privacy requests, consent records, and opt-out records are retained for the period required to demonstrate compliance.
When information is no longer needed, we delete, de-identify, or securely isolate it. Residual copies may remain temporarily in backups until the applicable backup cycle expires.
9. Your privacy rights and choices
Depending on where you live and subject to applicable exceptions, you may have the right to:
- Confirm whether we process your personal information and access or know the information we hold.
- Correct inaccurate personal information.
- Delete personal information.
- Obtain a portable copy of personal information you provided.
- Opt out of the sale or sharing of personal information, targeted advertising, or certain profiling.
- Limit certain uses or disclosures of sensitive personal information.
- Object to or restrict processing, or withdraw consent where processing is based on consent.
- Appeal a decision we make about a privacy request.
- Receive equal service and not be discriminated against for exercising a privacy right.
To submit a request, use the DataXGrowth Contact page and write “Privacy Request” in your message. Include your name, email address, state or country of residence, relationship with DataXGrowth, and the right you want to exercise. Do not send identity documents unless we request them through a secure method.
Submit a privacy request through the DataXGrowth Contact page
We will verify requests by matching information you provide with information in our records and, when appropriate, confirming control of the relevant email address or account. We may request additional information only when reasonably necessary to verify identity, authority, or the scope of the request. If we cannot verify a request, we will explain why.
An authorized agent may submit a request on your behalf. We may require proof that you gave the agent signed permission and may verify your identity directly, unless the agent has valid legal authority that removes that requirement.
If we deny a request and applicable law gives you a right to appeal, reply to our decision with “Privacy Appeal” and explain why you believe the decision should be reconsidered. You may also have the right to contact your local privacy or data-protection authority.
You can unsubscribe from marketing emails using the link in the message. We may still send non-promotional communications about an active inquiry, contract, security issue, or service.
10. California notice at collection and disclosures
This section supplements the rest of the Policy for California residents. In the preceding 12 months, depending on the interaction, we may have collected the following categories of personal information:
- Identifiers and customer-record information, such as name, email address, phone number, company, postal or billing details, IP address, and online identifiers.
- Commercial information, such as service interests, proposals, transaction history, and client-engagement records.
- Internet or other electronic network activity, such as browsing, referral, interaction, cookie, and campaign data.
- Approximate geolocation derived from IP address.
- Professional or employment-related information, such as company, title, role, and business responsibilities.
- Audio, electronic, visual, or similar information, such as communications, meeting recordings or transcripts, and files provided in connection with an engagement.
- Inferences drawn from the information above, such as likely service interests or marketing recommendations.
- Sensitive personal information, such as account credentials, API tokens, or contents of communications, only when provided or required for an authorized service.
We collect these categories from you, your device, clients, authorized integrations, service providers, business partners, referrals, and public business sources. We use them for the business and commercial purposes described in Sections 3 and 4.
We may disclose each applicable category to service providers, contractors, clients, professional advisers, authorities, and transaction counterparties for the purposes described in Section 7. Depending on enabled marketing technologies and consent choices, identifiers and internet or network activity may also be disclosed to advertising or analytics providers in a manner that California law may define as “selling” or “sharing.” We do not sell personal information for money.
We use sensitive personal information only to provide requested Services, maintain security, authenticate access, prevent abuse, perform permitted business functions, and comply with law. We do not use sensitive personal information to infer characteristics about individuals or for purposes that require a separate right-to-limit notice, unless we provide that notice and choice first.
Our intended retention periods are described in Section 8. We do not retain a category longer than reasonably necessary for the disclosed purpose.
California residents may exercise the rights to know, access, correct, delete, and receive information, and to opt out of sale or sharing, as described in Section 9. We process recognized opt-out preference signals as described in Section 6. We do not knowingly sell or share personal information of consumers under 16.
11. Security
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Measures vary based on the sensitivity and context of the information and may include access controls, least-privilege permissions, authentication, encryption in transit, vendor reviews, client-specific controls, logging, and human review. No system or transmission method is completely secure, and we cannot guarantee absolute security.
12. International data transfers
DataXGrowth is based in the United States, and we and our providers may process information in the United States and other countries. These countries may have privacy laws different from those where you live. Where required, we use appropriate contractual or legal safeguards for international transfers.
13. Children’s privacy
The Services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child provided personal information to us, contact us so we can review and delete it as appropriate.
14. Third-party services and links
The Site may link to or embed third-party websites, forms, scheduling tools, videos, demos, social networks, or other services. Their privacy practices are governed by their own notices. We encourage you to review those notices before providing information.
15. Changes to this Policy
We may update this Policy to reflect changes in our Services, technologies, vendors, or legal obligations. We will post the revised Policy with a new “Last updated” date. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent when required.
16. Contact us
For questions, concerns, or privacy requests, contact:
DataXGrowth (Utah CRO Corp. d/b/a DataXGrowth)
Attn: Privacy
United States