Sitegrown

Privacy notice

What we know about you, and how to make us forget it.

Most people reading this page got an e-mail from us about their business and want to know where we found their address. That answer is in section 2, in plain words: a public business listing, a legitimate interest, twelve months, one click to stop.

Updated 30 August 2026

1. Who is responsible

Sitegrown Studio is the controller of the personal data described here. Write to hello@sitegrown.com for anything on this page — access, correction, erasure, objection — and a person answers within a working day.

Our processing is subject to the GDPR (Regulation (EU) 2016/679) and, for e-mail, to the national marketing rules of the country the recipient is in.

2. If you received an offer e-mail from us

This is the notice required by Article 14 of the GDPR, given at the moment of first contact.

  • What we hold: your business name, the business contact address the e-mail went to, the town, the business category, the link to the public profile we found it on, and afterwards whether the e-mail was delivered, clicked, replied to or unsubscribed from.
  • Where it came from: publicly published business listings — Google Maps / Google Business profiles, Facebook business pages and the open Overture Maps dataset. We did not buy a list and we did not take anything from a private profile.
  • Why: to show that business a working preview of a website we built for it and to offer to publish it. That is our only purpose; we do not profile, score or resell anything.
  • Legal basis: our legitimate interest in offering a business service to a business (Article 6(1)(f)). Where national law requires consent for a recipient — Poland, and sole traders and private individuals in Lithuania and the UK — we do not write at all.
  • How long: the address and the message content for 12 months after the last contact; after that the address is deleted and only an irreversible hash remains, so that an unsubscribe keeps working without us keeping the address itself.
  • Who else sees it: nobody outside the processors in section 6. We do not sell or share data with advertisers.

You can object at any time, and you do not have to give a reason. The one-click link at the bottom of every letter removes the address immediately; replying with “no thanks” has the same effect. Nothing further is sent after that.

3. If you are a client

For an order we keep the business name, the contact e-mail, the domain, the amount and the payment status. Card details never reach us: the payment is taken by monobank (Universal Bank JSC) acquiring, and we only see the result of it.

Invoices and payment records are kept as long as accounting law requires. The website content you give us is yours; we process it to build and run your site, as set out in the data processing agreement inside the service agreement.

4. If you write to us through the site

The contact and support forms store what you type, your e-mail address and the page you sent it from, so we can answer and keep a record of the request. We keep those messages for 12 months.

5. Websites we host and this site

We count page views of the sites we host — the site, the day and the country, nothing that identifies a visitor. There are no cookies, no advertising pixels and no cross-site tracking on this site or on the sites we build.

Standard server logs (IP address, request, user agent) exist for security and are kept briefly by our infrastructure providers.

6. Who processes data for us

  • Microsoft Azure (West Europe) — the application, the database and the scheduled jobs. Data is stored in the EU.
  • Cloudflare — DNS, the hosting of client websites, e-mail routing for replies.
  • monobank (Universal Bank JSC) — card payments and invoices.
  • Resend — transactional e-mail (renewal reminders, order notifications).
  • Zoho — the mailboxes used to send and receive our business e-mail.

Each of them acts on our instructions under a data processing agreement. Where data leaves the EU it does so under the European Commission's standard contractual clauses.

7. Your rights

You can ask for a copy of the data we hold about you, ask us to correct or erase it, object to processing based on legitimate interest, or ask us to restrict it. Erasure of an outreach record is done within a month and leaves only the hash needed to keep you off the list.

If you think we have handled your data badly you can complain to your national supervisory authority — in Lithuania the State Data Protection Inspectorate (VDAI), in Ireland the Data Protection Commission, in the UK the ICO.

8. Changes

This notice was last updated on 30 August 2026. If it changes materially we publish the new version here before the change takes effect.