Legal

Privacy Policy

Preamble

With the following privacy policy, we aim to inform you about which types of your personal data (hereinafter also referred to as "data") we process, for what purposes and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences.

Controller: Growth&Partners GmbH, Johannes Caspari, Schönhauser Allee 9, 10119 Berlin, Germany. Email: hello@morrowcollective.eu.

Last updated: August 2026

Overview of processing activities

The following overview summarizes the types of data processed and the purposes of their processing, and refers to the data subjects concerned. Categories of data processed include inventory data, contact data, content data, usage data, as well as meta, communication and process data.

Data subjects include communication partners, users of our online offering, prospective clients, customers, and applicants.

Purposes of processing include, among others, the provision of our online offering and its user-friendliness, contact and communication, security measures, the management and handling of inquiries, as well as applicant management.

Relevant legal bases

Below you will find an overview of the legal bases under the GDPR on which we process personal data. Consent (Art. 6 (1)(a) GDPR): The data subject has given consent to the processing of their personal data for a specific purpose.

Performance of a contract and pre-contractual inquiries (Art. 6 (1)(b) GDPR): Processing is necessary for the performance of a contract to which the data subject is party, or to take steps prior to entering into a contract.

Legal obligation (Art. 6 (1)(c) GDPR): Processing is necessary for compliance with a legal obligation to which we are subject.

Legitimate interests (Art. 6 (1)(f) GDPR): Processing is necessary for the purposes of the legitimate interests pursued by us or a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject.

Security measures

In accordance with statutory requirements, we take appropriate technical and organizational measures to ensure a level of protection appropriate to the risk. Such measures include, in particular, safeguarding the confidentiality, integrity and availability of data by controlling physical and electronic access, as well as the access, input, transfer, availability and separation of data.

Specifically, we use, among other things, TLS/SSL encryption for the transmission of data, two-factor authentication for access to sensitive systems, and regular penetration tests to verify our IT security.

Deletion of data

The data we process will be deleted in accordance with statutory requirements as soon as any consent permitting its processing is revoked or other permissions cease to apply. If the data is not deleted because it is required for other legally permissible purposes, its processing is restricted to those purposes.

Rights of data subjects

As a data subject, you have various rights under the GDPR. You have the right to object to the future processing of data concerning you, insofar as the processing is based on legitimate interests.

You also have the right to obtain information about the data we process concerning you, the right to have inaccurate data corrected, the right to erasure or restriction of the processing of your data, and the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format (data portability).

You furthermore have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement, if you believe that the processing of personal data concerning you violates the GDPR.

Use of cookies

Cookies are small files stored on users' devices. We only use technically and functionally necessary cookies required for the operation of our online offering, for example to store language settings or to ensure the security of our online offering. Pursuant to § 25 (2) TTDSG, no consent is required for the use of these cookies.

Website tracking

We use Matomo Analytics to analyze the use of our online offering. Matomo is an open-source solution that is operated on our own servers, meaning that no data is passed on to third parties. Matomo follows a privacy-first approach: users' IP addresses are anonymized before storage. The legal basis is Art. 6 (1)(f) GDPR.

Provision of the online offering

In order to provide our online offering securely and efficiently, we make use of hosting providers' services. Our online offering is hosted with Hostinger. Within this hosting, contact data, content data, contract data, usage data, and meta and communication data of customers, prospective clients and visitors are processed in particular. The legal basis is Art. 6 (1)(f) GDPR.

Contact and inquiry management

When contacting us, for example by email, phone, or via a contact form, the information provided by the inquiring person is processed to handle the inquiry. This information is deleted once it is no longer required for the purposes of its processing, in particular after the respective inquiry has been resolved. The legal basis is Art. 6 (1)(b) and (f) GDPR.

Data processing in the context of grant program search and application

As part of our service to identify suitable funding programs and to support the application process, we process information about your company, your project, and other data required for review and application. The legal basis is Art. 6 (1)(b) GDPR.

To optimize this process, we additionally use AI-supported services, including those provided by OpenAI and Anthropic. Where possible, the data processed is anonymized or pseudonymized before being transmitted to these services, so that a direct identification of individual persons is excluded wherever feasible.

Video conferencing

For consultations and appointments, we use video conferencing services, including Google Meet and Microsoft Teams. In the course of this use, names, image and audio recordings where applicable, and technical connection data are processed. The privacy notices of the respective providers additionally apply. The legal basis is Art. 6 (1)(b) and (f) GDPR.

Applicant data

If individuals apply to us, we process the data submitted with the application (e.g. contact and communication data, application documents, information provided during the interview) for the purpose of selecting suitable candidates. The legal basis is Art. 6 (1)(b) GDPR in conjunction with the applicable national regulations on employee data protection. Once the application process has been completed, the data is generally deleted, unless statutory retention obligations prevent this.

Changes to this privacy policy

We ask you to regularly review the content of our privacy policy. We will adjust the privacy policy as soon as changes to the data processing we carry out make this necessary.

Definitions

"Personal data" means any information relating to an identified or identifiable natural person.

"Processing" means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.