Last updated: 26 September 2026
This policy explains how AGR Group (“TouchTargets“, “we“, “us“) handles personal data and client data when you use touchtargets.com and app.touchtargets.com (together, the “Service“).
Who we are (data controller):
AGR Group, India
NO.28-5-711, LG 182, Housing Board Colony, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Andhra Pradesh, 515001, India
Email: [email protected]
For personal data of people who appear in the data you connect (for example, names in reviews or on your site), you are usually the controller and we are your processor. See “Our role” below.
1. What we collect
1.1 Account data
- Name, email address, password (stored hashed), role in your workspace, and invitations you send or accept.
- Business and billing details: company name, billing country, currency, tax ID (such as GST number or VAT ID), and invoice history.
- Support messages and notification preferences (email, WhatsApp).
1.2 Data from connected services
When you connect a site and verify that you own its domain, we read data from:
- Google Search Console: clicks, impressions, positions, queries and pages, and URL inspection results.
- Google Analytics 4 (GA4): traffic, landing pages and referral data, including visits from AI assistants.
- Bing Webmaster Tools: traffic and query data.
- Google PageSpeed Insights: performance results for your public pages. This needs nothing from you beyond the site URL.
Search Console, GA4 and Bing are read-only. You grant access by adding our service account or Bing account as a user on your property, and you can remove it at any time. We keep this data in our own database as daily figures (see section 6).
1.3 Crawl data
After you verify a domain, we crawl your public website to audit it. We store page URLs, status codes, titles, headings, meta tags, canonical and robots directives, headers, links between pages, page text needed for analysis, and the issues we find. We also probe about 35 well-known paths (for example .env, .git, backups) to check whether sensitive files are exposed. For those probes we inspect the response in memory only. We never store, log or show the contents, only the type, status, content type and size.
Our crawler identifies itself as TouchTargetsBot (details at https://touchtargets.com/bot), obeys robots.txt and Crawl-delay, and runs only while your domain verification stays in place.
1.4 Business brain content
What you enter about your business: company profile, offerings (with optional prices), audiences, competitors, goals, brand voice and proof points. We use it so our AI agents can work in your voice and for your goals.
1.5 Usage, technical and audit data
Log-in times, IP address, browser and device type, pages visited in the app, actions taken by you and by our agents (an audit log with before and after states), and records of each AI call (workspace, agent, tokens, cost).
1.6 What we do not collect
We do not collect the content of your Google account, email or files. We do not read payment card numbers (our payment provider does).
2. How we use your data
- To provide the Service: syncing your data, auditing your site, producing reports, recommendations and drafts, and taking approved actions.
- To bill you and to meet tax and legal duties.
- To keep the Service secure, prevent abuse and fix faults.
- To contact you about your account, approvals, reports and service changes.
- To improve the Service using aggregated or de-identified usage data. We do not use your connected Google data for this.
We do not sell your personal data. We do not use your data for advertising.
3. How AI processes your data
Our AI agents use the Anthropic API (Claude models). When an agent works on your account, the relevant parts of your data (for example, search performance, crawl findings and business brain content) are sent to Anthropic to generate the output.
- Anthropic processes this data to provide the API response. Anthropic’s Commercial Terms prohibit it from training its models on customer content, and our API inputs and outputs are not used to train Anthropic’s models.
- We do not use your data to train or fine-tune any AI or machine-learning model, ours or anyone else’s.
- All model calls go through one internal gateway that logs which workspace, agent, tokens and cost were involved.
- Text that comes from outside, such as web pages, reviews, emails and AI answers, is treated as data and never as instructions to the agent.
- Agents can only use the tools they have been given, and any action that changes something outside our app needs your approval first (see our Terms of Service).
- We do not use free-tier AI services for client data.
AI output can be wrong. You should review it before relying on it.
4. Google API Services User Data Policy
TouchTargets’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, for data we receive from Google APIs (Search Console, Google Analytics 4, Google Drive, Google Ads and any other Google API we use):
- Limited to a stated purpose. We use it only to provide and improve the user-facing features of the Service that you asked for: showing your performance data, auditing your site, and producing reports and recommendations for you.
- No transfer except as allowed. We do not transfer it to others unless it is needed to provide or improve those user-facing features (for example, to our sub-processors listed below), to comply with law, or as part of a merger or sale of assets with notice to you.
- No advertising. We do not use it to serve ads, including retargeting, personalised or interest-based advertising.
- No human reading, except where permitted. We do not allow humans to read it unless we have your consent for specific data, it is needed for security purposes (such as investigating abuse), it is needed to comply with law, or the data is aggregated and used for internal operations in line with applicable law.
- No AI model training. We do not use Google user data to develop, improve or train generalised AI or machine-learning models. It is sent to Anthropic only to generate the output you asked for, as described in section 3.
You can stop our access at any time by removing our service account from your Search Console or GA4 property (or by revoking access in your Google Account settings once Google sign-in is available). You can also disconnect the connector in the app. See section 6 for deletion.
5. Sub-processors and who we share data with
We share data only with providers that help us run the Service, under contracts that require them to protect it. The named providers are listed on our sub-processors page, https://touchtargets.com/subprocessors, which forms part of this policy. In short:
- Hosting: our servers are in India (currently Oracle Cloud).
- AI: Anthropic (Claude API).
- Google and Microsoft (Bing): the sources of the search and analytics data you connect, and the PageSpeed API.
- Payments: Paddle (merchant of record, outside India) and Razorpay (India).
- Messaging: Meta (WhatsApp Cloud API) and a transactional email provider (to be named).
We may also disclose data if the law requires it, or to protect our rights, or in a business transfer (with notice to you). We will update the sub-processors page before adding or replacing a provider that handles client data, and will tell clients by email at least 30 days ahead.
6. Retention and deletion
- Account and workspace data: kept while your account is active.
- Connected data: site-level daily totals are kept for as long as your workspace exists. Search query-and-page detail older than 16 months is rolled up into monthly summaries. Page-level Search Console data and Bing query detail are currently kept in full.
- Crawl data: we keep the pages and issues of the last 6 crawls per site (the last 3 for sites of 25,000 pages or more), link data for the last 2 crawls, and run summaries for as long as your workspace exists. Older detail is deleted automatically each day.
- Audit log: kept for as long as your workspace exists, so you can see what was changed and undo changes within 30 days.
- Billing records: kept as long as Indian tax and accounting law requires.
- Disconnecting or losing verification: stops all syncing and crawling. Data already synced is kept unless you ask us to delete it.
- Deleting your data: you can ask us at any time to delete your workspace or personal data (see section 11). We will delete or anonymise it within 30 days, except records we must keep by law. Backups roll off within 35 days of the deletion.
- After cancellation: your data stays available for export for 30 days, then we delete the workspace and its data (backups roll off within 35 days).
7. Data export
You can ask for a copy of your data at any time, and you can export it before cancelling. Until self-serve export is available in the app, export is on request: email [email protected] and we will send your data in a common machine-readable format (such as CSV or JSON) within 30 days.
8. International transfers
We are based in India. Our hosting, sub-processors and you may be in other countries, so your data may be transferred to and processed in India, the United States and other countries.
- For transfers of personal data from the EEA, UK or Switzerland, we rely on the EU Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum. A data processing agreement (DPA) is available on request at [email protected].
- Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act“), we transfer personal data outside India only to countries and under conditions not restricted by the Government of India.
9. Our role
- For your account data (your name, email, billing details), we are the controller (called “Data Fiduciary” under the DPDP Act).
- For personal data inside the data you connect or crawl (for example, customer names in reviews or on your website), you are the controller or Data Fiduciary and we are your processor. We process it only on your instructions and as this policy and our Terms of Service describe. You are responsible for having a lawful basis to give us that data.
10. Cookies
We use:
- Essential cookies to keep you signed in, protect forms from forgery and remember your session. The app cannot work without them.
- Analytics cookies on touchtargets.com (our marketing website) only: we use Google Analytics 4 to understand how the site is used. Where the law requires consent (for example in the EEA and UK), we ask first and you can refuse.
The app (app.touchtargets.com) uses essential cookies only.
We do not use advertising cookies. You can block or delete cookies in your browser, but the app may then not work.
11. Your rights and how to use them
Under the DPDP Act (India)
You have the right to: access information about the personal data we process; correct and update it; erase it; nominate another person to exercise your rights if you die or become incapacitated; and have your grievances redressed. You may withdraw consent at any time (this does not affect what we did before, and we may keep data we must keep by law).
Under the GDPR and UK GDPR (where they apply to you)
You have the right to access, correct, erase, restrict or object to processing, data portability, and to withdraw consent. You may also complain to your local data protection authority.
How to make a request
Email [email protected] from the address on your account. We may need to verify your identity. We will reply within 30 days, or sooner where the law requires it.
Grievance Officer (DPDP Act)
Name: Rakesh Reddy
Address: AGR Group, NO.28-5-711, LG 182, Housing Board Colony, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Andhra Pradesh, 515001, India
Email: [email protected]
If we do not resolve your grievance, you may complain to the Data Protection Board of India once it is established and open to complaints.
12. Security
We use encryption in transit, encrypted storage for credentials, separation between client workspaces, access controls, an audit log, and controls that keep our crawler and connectors to domains you have verified. No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
13. Children
The Service is for businesses and is not for anyone under 18. We do not knowingly collect children’s data.
14. Changes to this policy
We may update this policy. If a change is material, we will tell you by email or in the app before it takes effect. The “Last updated” date shows the latest version.
15. Contact
AGR Group
NO.28-5-711, LG 182, Housing Board Colony, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Andhra Pradesh, 515001, India
[email protected]