This Acceptable Use Policy ("AUP") applies to all use of HelloGrowthCRM by Customers, their authorised users, and anyone accessing the Service through Customer credentials. By using the Service you agree to comply with this AUP. We may update it from time to time and will publish material changes here.
Plain-English Summary
This summary is provided for convenience only. It does not replace or override the full policy below.
- Use the CRM for lawful business. Don't store illegal, infringing, or abusive content in it.
- Only message and call people you have a lawful basis to contact, honour every opt-out, and never spam.
- Get required consent before recording or transcribing calls, and review AI output before acting on it or sending it.
- Don't attack, probe, scrape, or reverse engineer the platform — security research goes through the vulnerability disclosure programme.
- Breaking these rules can lead to warnings, feature suspension, or account termination — immediately, if other customers are at risk.
1. Lawful use
You may use HelloGrowthCRM only for lawful business purposes and in compliance with applicable laws of your jurisdiction and of any jurisdiction in which the Data Principals or Data Subjects are located.
2. Prohibited content and activities
You will not use the Service to upload, store, transmit, generate, or distribute content that:
- infringes intellectual-property, trade-secret, publicity, or privacy rights of any person;
- is defamatory, harassing, threatening, abusive, hateful, obscene, or sexually explicit;
- exploits or endangers minors;
- contains malware, viruses, ransomware, worms, or any other malicious code;
- violates export-control, sanctions, anti-bribery, anti-money-laundering, or similar laws;
- impersonates another person or misrepresents your identity, affiliation, or authority.
3. Communications, dialer, and email rules
The Service includes outbound communication features (calls, SMS, WhatsApp, email sequences). When using these features you will:
- only contact people who have given you a lawful basis to be contacted (consent, prior business relationship, or another lawful basis under TCPA, CAN-SPAM, GDPR, DPDPA, TRAI, or other applicable law);
- honour opt-outs and unsubscribe requests promptly and permanently;
- not use the Service for unsolicited bulk messaging, robocalling, or spam;
- respect Do-Not-Call lists and quiet hours required by your jurisdiction;
- not spoof caller-ID, sender domains, or message metadata;
- obtain any consents required for call recording, voice transcription, or AI-assisted call summaries before recording or transcribing.
4. Data quality and minors
- Do not upload personal data of minors except where you have lawful, verifiable parental consent.
- Do not upload special-category data (e.g. health, biometrics, financial credentials, sexual orientation) unless we have agreed to a specific addendum.
- Maintain the accuracy of CRM data and honour Data Principal / Data Subject correction requests within the timeframes required by law.
5. AI features
When you use AI features (drafting, summarisation, lead scoring, agentic AI), you are responsible for reviewing AI output before using it for business decisions or external communications. Do not use AI features to generate content that violates this AUP, deceive recipients about whether they are interacting with a human, or evade consent or disclosure requirements.
6. System integrity and security
You will not, and will not attempt to:
- probe, scan, or test the vulnerability of the Service except under our published vulnerability-disclosure programme at /legal/vulnerability-disclosure;
- circumvent rate limits, billing, authentication, or access controls;
- reverse engineer, decompile, or extract underlying source code, except as permitted by law;
- use the Service to launch a denial-of-service or any other attack against any system;
- scrape the Service or use it to scrape, train, or fine-tune third-party AI models in a way that breaches third-party rights.
7. Reseller, white-label, and resale
You may not resell, sublicense, or white-label the Service without a written agreement from us. Agency partners are subject to a separate Partner Agreement.
8. Reporting and enforcement
To report a violation of this AUP, email abuse@hellogrowthcrm.com. We may investigate suspected violations and, depending on severity, may issue a warning, suspend specific features, suspend the account, or terminate the Agreement, with or without prior notice. Where suspension is required for the protection of other customers, we may act first and notify the affected Customer afterwards.
9. Cooperation with law enforcement
We may cooperate with law-enforcement requests that are valid under applicable law. Where permitted, we will notify the affected Customer before disclosing data, except where such notification is prohibited.
Key terms explained
This policy references several laws and technical terms. In plain terms:
- TCPA: the US Telephone Consumer Protection Act — the law governing automated calls and texts to US numbers, including consent and Do-Not-Call requirements.
- CAN-SPAM: the US law setting rules for commercial email, including truthful headers and a working unsubscribe mechanism.
- GDPR:the European Union's General Data Protection Regulation, which requires a lawful basis for processing personal data of people in the EU. The people the data is about are called Data Subjects.
- DPDPA:India's Digital Personal Data Protection Act, the Indian counterpart, where the people the data is about are called Data Principals.
- TRAI regulations:India's telecom rules on commercial communications, including registered sender requirements and quiet hours for marketing calls and SMS.
- Special-category data: data given extra legal protection — for example health data, biometrics, or financial credentials — which needs a specific addendum before it can be stored here.
- Spoofing:falsifying caller-ID, a sender domain, or message metadata so a communication appears to come from someone it doesn't.
- Opt-out:a recipient's request to stop receiving communications. Once received, it must be honoured promptly and permanently across all channels.
Related policies
This AUP supplements the Terms of Service. How personal data is handled is covered by the Privacy Policy and, for customer data processed on your behalf, the Data Processing Addendum. Security and compliance documentation is available in the Trust Center.