Corporate Privacy Policy & Data Rights
Effective Date: August 25, 2026. Growfitable ("we", "our", or "us"), a digital product and communication platform operated by Codecurv, enforces rigorous data protection and governance standards across all services under GDPR, CCPA/CPRA, and DPDP frameworks.
1. Legal Entity Ownership & Information We Collect
This website, the Growfitable Growth OS, and associated proprietary SaaS modules (including WaLink Pro) are owned, engineered, and legally operated by Codecurv (Data Controller). We collect only data necessary to deliver our growth intelligence, diagnostic audits, and WhatsApp communication software:
- ✓Direct Business Parameters: Full name, verified work email, corporate contact numbers, business website URLs, revenue tiers, and custom project scopes submitted via `/portal` or `/contact`.
- ✓Meta WhatsApp Integration Telemetry: For businesses connecting via WaLink Pro Embedded Signup, we process Meta WhatsApp Business Account (WABA) IDs, Phone Number IDs, display names, and encrypted system tokens strictly to facilitate authorized message routing and webhook management.
- ✓Automated Diagnostic & Session Logs: Public domain Core Web Vitals, speed audit indices, search engine visibility telemetry, truncated IP addresses, user-agent data, and local interface state (stored in `localStorage`).
2. Processing Purposes & Non-Sale Commitment
Codecurv processes all data collected via Growfitable strictly under legitimate business interests, contractual necessity, and explicit user consent:
- ✓Communication SaaS & Real-Time Lead Routing: Powering multi-tenant WhatsApp inbox routing, agent conversation assignment, and encrypted webhook dispatch for customer interactions.
- ✓Growth Blueprint Formulation: Analyzing audit telemetry and growth parameters to generate 15-page diagnostic roadmaps and performance optimization plans.
- ✓Zero Data Monetization Policy: Neither Codecurv nor Growfitable ever sells, rents, leases, or trades Meta Platform Data or user information to third-party data brokers, ad networks, or unauthorized aggregators.
3. Approved Sub-Processors & Webhooks
Data is routed strictly through certified enterprise infrastructure providers maintaining high-grade cryptographic security:
| SUB-PROCESSOR | FUNCTION & SERVICE | DATA LOCATION / SECURITY |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Cloud API & Webhook Infrastructure | End-to-End TLS 1.3 / AES-256 Webhook |
| Google Cloud Platform | Traffic Telemetry, Security & Analytics | ISO 27001 / SOC 2 / EU-US DPF Certified |
| ImageKit CDN | High-Speed Global Asset Delivery | Edge Cached / Isolated HTTPS |
| Zoho Corporation | Transactional System Notifications & SMTP Relay | TLS 1.3 Encrypted Mail Infrastructure |
4. User Data Deletion Instructions & Revocation
In compliance with Meta Platform Terms, GDPR (Right to Erasure), and CCPA, users and client organizations can completely delete their stored data and revoke application access through the following standardized methods:
- 1Self-Service Disconnection: Log into your Growfitable dashboard, navigate to Settings → WhatsApp Business Account, and click Disconnect WABA. This immediately halts webhook processing and archives the live token.
- 2Revoking via Facebook Settings: Go to your Facebook account → Settings & Privacy → Settings → Business Integrations. Locate Growfitable / WaLink Pro and click Remove to permanently revoke access permissions.
- 3Manual Deletion Request: Send an email to hello@growfitable.com with the subject line "Data Deletion Request" and your registered business email/domain. Our engineering team will purge all associated customer records, tokens, and lead logs from active databases within 24–48 hours and provide written confirmation.
5. Cryptographic Security & Data Governance
Codecurv implements enterprise-grade technical and physical controls to safeguard platform data:
- ✓Encryption Standards: All data in transit is encrypted using modern TLS 1.3 cryptographic suites. Sensitive credentials and permanent access tokens stored at rest are secured using AES-256-GCM authenticated encryption.
- ✓Role-Based Access (PoLP): Internal data access is restricted to verified personnel on a strict Principle of Least Privilege basis protected by multi-factor authentication.