Who we are
Growth Path Agency S.R.L. ("we", "us") operates Heralded and is the controller of personal data processed through heralded.ai and app.heralded.ai.
Legal name: Growth Path Agency S.R.L.
Registered office: Str. Drumul Putnei nr. 38-42, Et. 4, Ap. 33, Sector 3, Bucureşti, Romania.
Trade Registry No.: J2025042918007.
Unique Registration Code (CUI): RO51980049 (VAT-registered).
EUID: ROONRC.J2025042918007.
Share capital: 1,000 RON (fully paid).
Privacy contact: privacy@heralded.ai.
We have not appointed a Data Protection Officer because our processing does not meet the thresholds in Art. 37 GDPR or Law 190/2018. Send any request under this policy to the privacy contact above.
What this policy covers
This policy covers the public Heralded website, the Heralded application, Heralded Snapshot reports, account authentication, billing, and optional connections you make to third-party services such as Google Search Console.
It does not cover third-party sites we link to or client services delivered under a separate signed agreement. Those providers and agreements carry their own privacy terms.
What we collect
We collect only what is needed to operate Heralded, protect it from abuse, and deliver the product you request.
Site and security data. Hosting and abuse-prevention systems process technical request data such as IP address, user-agent, timestamps, response status, and browser signals. We use it to serve pages, prevent automated abuse, enforce rate limits, and investigate errors.
Aggregate analytics. We use Umami, which we host ourselves on our own hardware, to count page views and product events. It sets no cookies and stores nothing on your device. It counts unique visitors with a salted hash of IP plus user-agent; the salt rotates monthly, and the hash is specific to Heralded, so you cannot be tracked anywhere else. Because we host it, no third party receives this data.
Email sign-ups. If you give us your email address on the site, we collect the address, the form source, and whether you separately chose to receive marketing updates. Signing up does not require marketing consent.
Account data. If you create an account, we process your email address, authentication identifiers, account settings, and security events. If you choose Google sign-in, Google provides the account details shown on its consent screen; we never receive your Google password.
Scan and product data. When you run a scan, we process the domain you submit, the public pages we crawl, the buyer questions generated for the scan, engine answers and citations, competitors, scores, reports, usage records, and product diagnostics. Do not submit a domain or content you are not permitted to analyse.
Billing data. Stripe processes payment-card details. We receive transaction identifiers, billing status, country and tax information, purchased credits, and invoice details, but not your full card number.
Direct communication. If you use the support form or email us, we process your name, address, message, any scan or invoice reference you provide, attachments, and the metadata needed to reply.
Heralded is a B2B product. We do not intentionally collect special-category data, Romanian CNP identifiers, or data from children.
Why we collect it and legal basis
Contract and steps before contract — Art. 6(1)(b). We process account, scan, billing, support, and connected-service data to provide the product you request, administer credits, and respond before a purchase.
Legitimate interests — Art. 6(1)(f). We process security logs, abuse signals, operational diagnostics, and cookieless aggregate analytics to keep Heralded reliable, understand whether the product works, and protect paid scan capacity. We balance these interests against your rights and keep the data limited.
Consent — Art. 6(1)(a). Email sign-ups, optional marketing email, and optional Google connections run on the choices you make. You can withdraw consent from an email, your account settings, Google's permissions page, or by contacting privacy@heralded.ai.
Legal obligation — Art. 6(1)(c). We retain invoicing and tax records where Romanian or EU law requires it.
Processors and recipients
Vercel Inc. hosts and delivers the website and application in EU regions. Vercel BotID performs first-party abuse analysis on protected form and scan routes. DPA · privacy notice.
Cloudflare, Inc. provides authoritative DNS for heralded.ai and associated network security services. DPA · subprocessors.
Our self-hosted Plunk email system and Amazon Web Services SES store email contacts, deliver support-form notifications, and send transactional and separately consented marketing email. AWS privacy.
Railway Corporation hosts the backend application and database in Amsterdam, Netherlands.
Stripe processes payments, tax calculation, invoices, and refunds. Privacy policy.
Google provides sign-in and, only when you connect it, read-only Google Search Console access. Google also receives the information required to present and record its own OAuth consent flow.
The AI providers used by a scan process submitted buyer questions and public website context under our vendor agreements. The current engine set is shown in the product before you run a scan. We do not send account passwords or payment-card details to those providers.
We may disclose data where law, a court, or a regulator requires it, or where necessary to protect rights, investigate fraud, or respond to an emergency.
Google Search Console data
If you connect Google Search Console, Heralded requests the read-only permission Google calls `webmasters.readonly` for properties you own and choose to connect.
What we access. Search queries, clicks, impressions, average position, indexed-page information, and the property identifiers needed to request them. We cannot change your Google account or Search Console configuration.
What we do with it. Heralded connects search performance with AI citations and visibility in the analyses you request. We do not sell the data, use it for advertising, or use it to train general-purpose models.
Storage and deletion. OAuth tokens are encrypted. Retained Search Console data is encrypted at rest in our EU-hosted database. Disconnecting Search Console deletes the stored tokens and stops future reads. Account deletion removes connected-service tokens and imported data, subject to short-lived backups and legal retention duties.
You can disconnect in Heralded or revoke access at myaccount.google.com/permissions. Heralded's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
International transfers
Our primary application and database workloads run in the EU. Some providers, including Amazon Web Services, Stripe, Google, Vercel, and AI engine providers, may process data in the United States or other countries.
Where GDPR Chapter V applies, we rely on an adequacy decision where available or the European Commission's Standard Contractual Clauses plus appropriate supplementary safeguards. You can request information about the applicable safeguard at privacy@heralded.ai.
How long we keep data
Security and hosting logs are retained for up to 30 days unless a security investigation requires longer.
Analytics data is deleted after 24 months.
Sign-up and marketing contacts are retained until you unsubscribe or 24 months after your last engagement, whichever comes first.
Account, scan, and report data remain while your account is active and are deleted after an account-deletion request, subject to backups, fraud-prevention records, and data we must keep by law. Anonymous or aggregated measurements that no longer identify an account may be retained.
Support communication is retained for up to 36 months after the last exchange. Romanian accounting records, invoices, and associated transaction data are retained for the legally required period, currently 10 years.
Your rights
Under GDPR Arts. 15–22 you may request access, rectification, erasure, restriction, objection, and — where processing is based on consent or contract — portability. You may withdraw consent at any time without affecting processing already carried out lawfully.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you.
Email privacy@heralded.ai to exercise a right. We respond within one month under GDPR Art. 12(3), with any permitted extension explained during that first month. We may need to verify your identity before disclosing or deleting account data.
Cookies and similar technologies
The public site does not use analytics or advertising cookies. Our analytics is cookieless by design — it uses a salted hash to count unique visitors, rotated monthly and scoped to Heralded alone — and form submissions are server-side.
A theme preference is stored locally on your device only when you choose Light or Dark instead of System. The application may use strictly necessary session storage or cookies to keep you signed in and protect your account.
Vercel BotID runs on protected submissions to distinguish people from automated abuse. Its request signals are used for security, not advertising or cross-site profiling. These security and authentication technologies are necessary to provide the service under Art. 5(3) of Directive 2002/58/EC as transposed by Romanian Law 506/2004.
Email may contain a tracking pixel. You can block remote images or unsubscribe from any marketing message.
Security
We use HTTPS, encryption at rest for account and connected-service credentials, least-privilege access, multi-factor authentication on processor consoles, abuse controls, and written Data Processing Agreements with processors.
If a personal-data breach is likely to create a risk to individuals, we notify ANSPDCP within 72 hours and affected people without undue delay where GDPR Arts. 33 and 34 require it.
Children
Heralded is directed at business professionals and is not intended for children. We do not knowingly collect data from anyone under 16. If you believe a child submitted data, email privacy@heralded.ai and we will investigate and delete it.
Complaints
You may complain to the Romanian supervisory authority at any time.
Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucureşti, Romania.
Telephone: +40 318 059 211 · +40 318 059 212.
Email: anspdcp@dataprotection.ro.
Web: dataprotection.ro.
If you live or work elsewhere in the EU, you may also complain to the supervisory authority in that country. You are welcome, but not required, to contact privacy@heralded.ai first.
Changes to this policy
We update this policy when our processing or the law changes. Material changes are flagged at the top for a reasonable period.
Effective date: 24 August 2026. This is the first Heralded-specific policy. It covers the new heralded.ai site, BotID-protected forms and scan starts, Heralded accounts and scans, and optional Google Search Console access.