Legal · Effective August 2026
Privacy Policy
This policy explains how automaatic handles personal data. GRWTH LAB is the data controller for the service. Contact: [email protected].
Data we collect
Depending on how you use the service, we collect:
- Google account information used to sign in: name, email address, and profile identifier;
- account and API information, including key status, session identifiers, usage, and quota events;
- pages, referral information, and service events needed to operate and understand the service;
- queries, requested markets, and other research needs you provide or navigate to;
- email domain information used to tailor results to the organization you represent;
- security information, including a one-way hash of an IP address rather than the raw address; and
- report delivery and download events.
The public site does not use third-party advertising or analytics trackers. Public CMS NPPES organization data displayed on data pages is not collected from site visitors.
Why we use the data
- to create and secure your account and provide requested data tools and reports;
- to personalize results and improve coverage based on observed research needs;
- to enforce quotas, prevent abuse, diagnose errors, and maintain service reliability;
- to measure whether pages and agent workflows work as intended; and
- where you explicitly consent, to enable relevant providers to contact you based on your search interests.
We rely on performance of our contract to provide requested services, legitimate interests in securing and improving the service, consent for optional provider contact, and legal obligations where applicable. You may withdraw consent at any time without affecting prior lawful processing.
Sharing and processors
We use service providers for hosting, authentication, email delivery, and operational support. They process data under our instructions. If you opt in to relevant provider contact, we may share the research interest and contact information needed for that purpose. We do not sell personal data through a public data marketplace.
We may disclose data when required by law, to protect the service or its users, or as part of a corporate transaction subject to appropriate safeguards.
Retention
Account data is kept while the account is active and deleted or anonymized after an account deletion request, except where law or security obligations require a limited record. Service events and research queries are retained for no longer than 24 months after the last relevant activity. Security records are retained for no longer than 12 months. Generated report downloads expire after 90 days. Backups age out on their normal rotation after primary deletion.
International processing
Providers may process data outside your country. Where required, GRWTH LAB uses recognized transfer safeguards, including contractual protections, and limits access to what is necessary to provide the service.
Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or objection to processing. You may also withdraw consent and lodge a complaint with your data protection authority. Use the account deletion control when available or email [email protected]. We may need to verify your identity before completing a request.
Security and changes
We use access controls, hashed credentials and network identifiers, limited OAuth scopes, and operational monitoring to protect the service. No system is completely secure. Material changes to this policy will be dated on this page.