Taking on new builds — book a free discovery call

Legal

Privacy Policy

What we collect, why we collect it, who we share it with, and what you can ask us to do about it.

Last updated: 1 August 2026

01Who we are

The Automation Creators builds automation and AI systems for businesses. We are a registered US LLC based in Austin, Texas, working with clients in the United States, the European Union and the MENA region.

This policy covers theautomationcreators.com and every service we provide through it. It explains what we do with information about you — whether you are a visitor, a prospect, a client or an applicant.

02What we collect

You give us

  • —Contact details: name, email, phone number, company
  • —What you tell us about the process you want automated
  • —Anything you send in an application: links, a CV, work samples
  • —Correspondence with us by email, phone or through the site

We collect automatically

  • —IP address, browser and device type, operating system
  • —Pages visited, time on page, referring site
  • —Cookie identifiers, where you have accepted them

We do not collect

We do not ask for and do not want payment card numbers, government identifiers, health information, or any special category data. If you send it anyway, we delete it.

03How we use it

  • —To answer your enquiry and run the discovery call
  • —To scope, quote, build and hand over the work
  • —To assess an application and to contact you about it
  • —To keep the site working, and to understand which pages are useful
  • —To meet our legal, tax and accounting obligations

We do not sell your information. We do not share it for anyone else’s advertising.

05Client data during a build

Delivering an automation usually means we are given access to systems that hold your own customers’ data. Two things are true of that access:

  • —We work under credentials you issue and can revoke. We ask for the narrowest permissions the build allows.
  • —We do not take a copy of your data, and we do not need one to build.

For that data we are a processor and you are the controller: we act on your instructions. Where the GDPR applies we will sign a data processing agreement before work starts. After handover our access ends unless you keep us on.

For Meta Instant Forms

How we handle data from our Facebook & Instagram lead ads

If you submit an Instant Form on one of our Facebook or Instagram ads, the details you enter — name, email, phone number and your answers — are passed to our CRM so we can contact you about your enquiry. That data is used for that purpose only. It is not sold, and it is not shared with anyone beyond the processors listed below. You can ask us to delete it at any time.

06Who we share with

Only the processors we need to run the business. Each is bound by contract to protect your information and to use it only on our instructions.

ProcessorWhat forWhere
GoHighLevelCRM, forms, calendar bookingUnited States
Google WorkspaceEmail, documents, storageUnited States, EU
Meta PlatformsLead ads and Instant FormsUnited States, EU
Hosting and CDNServing this websiteUnited States, EU

We also disclose information where the law requires it, and to professional advisers bound by confidentiality. If the business is ever sold, information may transfer to the buyer under the same protections.

07How long we keep it

  • —Enquiries that do not become work: 24 months, then deleted
  • —Client records: for the duration of the engagement and 7 years after, for tax and legal reasons
  • —Applications: 12 months, unless you ask us to keep them on file for longer
  • —Analytics: 14 months

08Your rights

Depending on where you live, you can ask us to:

  • —Tell you what we hold about you, and give you a copy
  • —Correct anything that is wrong
  • —Delete it
  • —Restrict or object to how we use it
  • —Receive it in a portable format
  • —Withdraw consent you have given

Write to us and we will respond within 30 days. We will not charge you and we will not treat you differently for asking.

09International transfers

We work with clients and processors across borders, so information may be transferred outside the country you live in — including to the United States. Where the GDPR applies, those transfers rely on the European Commission’s Standard Contractual Clauses or on an adequacy decision.

10Security

Encryption in transit, access limited to the people who need it, multi-factor authentication on the accounts that matter, and credentials held in a password manager rather than in a document.

No system is perfectly secure. If a breach affects your information and the risk is material, we will tell you and the relevant regulator within the time the law allows.

11Cookies

Essential cookies keep the site working and cannot be switched off. Analytics cookies tell us which pages are read; they run only if you accept them. You can clear or block cookies in your browser at any time, though parts of the site may stop working.

12Children

This site is for businesses. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.

13Regional notices

United States

California & other state laws

We do not sell personal information and we do not share it for cross-context behavioural advertising. California residents have the right to know, delete, correct and opt out, and not to be discriminated against for exercising them.

Canada

PIPEDA & provincial laws

We collect with your knowledge and consent, use it only for the purposes described here, and you may request access to what we hold.

14Changes

We update this policy when what we do changes. The date at the top of the page always shows the current version. Material changes will be flagged on the site before they take effect.

15Contact & complaints

For anything in this policy — a request, a correction, a complaint — please reach out and we will deal with it.

If you are in the EU or UK and are not satisfied with our response, you may complain to your local supervisory authority.