Groundworks AI
Pricing About Blog Log in Start free
Legal · Subscribers

Data Processing Agreement

Effective date: 2 July 2026 · Version 1.0 · Scout & Scout Team

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Groundworks Marketing AI Oy (Business ID / Y-tunnus 3625461-9), Finland, trading as Groundworks AI ("Processor", "we"), and the Subscriber ("Controller", "you"). It applies where we process personal data on your behalf in providing Scout or Scout Team. Capitalised terms not defined here have the meaning in the GDPR (Regulation (EU) 2016/679).

1. Roles

You are the controller of the personal data you submit to or generate through the service that relates to identifiable individuals — including data about people you address in generated content or outreach, and personal data within your inputs, integrations, and audiences ("Controller Personal Data"). We process it as your processor, only as set out in this DPA. (Where we determine purposes — e.g. your account, billing, and our website visitors — we act as controller under the Privacy Notice, and this DPA does not apply to that data.)

We do not process Controller Personal Data for our own purposes: we determine no purpose or means for it beyond your instructions, and acting on those instructions does not make us a controller of it (Art. 28(10) GDPR).

2. Scope and instructions

We will process Controller Personal Data only:

  • to provide, maintain, and support the service in accordance with the Terms;
  • on your documented instructions (the Terms, your configuration, and your use of the service constitute your instructions) — including with regard to any transfer of Controller Personal Data to a third country or international organisation — unless required to do so by EU or member-state law, in which case we will inform you before processing unless that law prohibits it; and
  • as required by EU or member-state law, in which case we will inform you unless the law prohibits it.

We will tell you if, in our opinion, an instruction infringes the GDPR.

3. Our obligations

We will:

  1. Confidentiality — ensure persons authorised to process Controller Personal Data are bound by confidentiality;
  2. Security — implement appropriate technical and organisational measures under Art. 32 (see Annex II);
  3. Assist you — taking into account the nature of processing, assist you with: responding to data-subject requests (Art. 12–23), security (Art. 32), breach notification (Art. 33–34), and data-protection impact assessments and prior consultation (Art. 35–36);
  4. Breach notification — notify you without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data, with the information you reasonably need to meet your own obligations;
  5. Deletion/return — at the end of the service, delete or return Controller Personal Data as set out in clause 7;
  6. Audit — make available the information needed to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable confidentiality and frequency limits.

4. Sub-processors

You give general authorisation for us to engage the sub-processors listed in Annex III. We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor, during which you may object on reasonable data-protection grounds; if the objection cannot be resolved, you may terminate the affected service.

The social-publishing aggregator (Scout Team — bundle.social) holds tokens for the social accounts you connect and is a sub-processor; we store only a reference to your connected account, not the tokens.

5. Data-subject requests

If a data subject contacts us directly regarding Controller Personal Data, we will (unless legally required to respond) refer them to you and assist you in responding, including via the in-product export.

6. International transfers

We process Controller Personal Data in the EU/EEA. Where a sub-processor processes it outside the EEA, we ensure an appropriate transfer mechanism is in place. The mechanisms in place are: Anthropic (US) — EU Standard Contractual Clauses, Module Three (processor-to-processor); Notion (US) — EU–US Data Privacy Framework certification; Beehiiv (US) — EU Standard Contractual Clauses, Module Two; Stripe (US, controller-side) — EU–US Data Privacy Framework certification, with SCCs in its Data Transfers Addendum. Fly.io processes in the EU. For any UK transfer the UK IDTA/Addendum applies.

7. Deletion and return

On termination or expiry of the service, we will delete or return Controller Personal Data at your choice, and delete existing copies, unless EU/member-state law requires retention. Pending deletion, data is retained for a bounded window so you can resume:

  • Retention window (pause/resume): 90 days from the date the subscription is paused or cancelled, during which your data is preserved so you can resume with continuity.
  • Deletion: on cancellation we deliver an export within 48 hours, then hard-delete within 30 days; on retention-window expiry without resume, hard-deletion completes within 30 days of expiry. Copies are purged from backups within one backup-rotation cycle.
  • Statutory override: billing/transaction records required by Finnish accounting law are retained for the statutory period and deleted thereafter; this override does not extend to your intake, content, or signal data.

8. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (clause 13), to the extent permitted by law. These inter-party limits do not affect either party's liability to a data subject under Art. 82 GDPR, or any other liability that cannot be limited under applicable law.

9. Governing law

This DPA is governed by the laws of Finland and forms part of, and is subject to, the Terms of Service. The Finnish supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).

Annex I — Details of processing

  • Subject matter: provision of the Scout/Scout Team content-generation service.
  • Duration: the term of the subscription, plus the retention window in clause 7.
  • Nature and purpose: generating, storing, and (for Scout Team) publishing marketing content using AI and connected integrations on your instruction.
  • Types of personal data: personal data within your inputs and prompts; names, email addresses, and other contact details of the contacts, prospects, and audiences you address in generated content or outreach; integration-account identifiers and engagement metrics (Scout Team). We do not require special-category data and you must not submit it.
  • Categories of data subjects: your contacts, prospects, newsletter and social audiences, and named individuals referenced in your content.
  • Special-category data: none intended; you must not submit special-category data.

Annex II — Technical and organisational security measures

These are the Art. 32 measures Groundworks AI maintains as Processor. Our Security & Data Handling Statement is the source of truth for the detailed, current measures; this Annex summarises them and is read together with it.

  • Encryption. Personal data is encrypted in transit (TLS) and at rest in the application data store.
  • Hosting & residency. The application and primary data store are hosted in an EU region (Fly.io, Amsterdam) with managed Postgres.
  • Access control & tenancy isolation. Role-based access on a least-privilege basis; multi-tenant isolation (row-level security) so one subscriber's data is not accessible to another; authenticated administrative access only, no shared production accounts.
  • Authentication. Credential controls for subscriber and administrative access.
  • Logging & monitoring. Application and access logging; monitoring for anomalous activity.
  • Integration-token handling. OAuth/publishing tokens for connected accounts are held by the relevant sub-processor (the publishing aggregator), encrypted at rest; Groundworks AI stores only a reference to the connected account, not the tokens.
  • Sub-processor due diligence. Each sub-processor is engaged under a DPA with obligations no less protective than this DPA (clause 4); the data path is reviewed before onboarding.
  • Breach response. A documented breach-detection and response process supporting the notification duty in clause 3(4) and Art. 33–34.
  • Deletion & backups. Deletion and retention per clause 7, including propagation to sub-processors and purge from backups within one rotation cycle.

Annex III — Authorised sub-processors

This schedule lists sub-processors that may process Controller Personal Data. Providers that process only website-visitor data (where Groundworks AI is the controller, e.g. the website host and website lead capture) are listed in the website Privacy Policy, not here. Stripe processes the subscriber's own account/billing data, for which Groundworks AI is controller; it is listed below for transparency as a controller-side processor.

Sub-processorFunctionLocation / mechanismApplies to
AnthropicAI content generation (Claude)US — SCCs Module Three (no training by default; ≤30-day retention; Zero-Data-Retention being arranged)Scout & Scout Team
Fly.ioHosting / storageEU region (Amsterdam)Scout & Scout Team
NotionWorkspace context (the source you nominate)US — EU–US DPF certified (Notion Labs, Inc.)Scout Team
bundle.socialSocial publishing; token custodyEngaged for Scout Team publishing under its own DPAScout Team
BeehiivNewsletter publishingUS — EU SCCs Module Two (per its DPA)Scout Team
Stripe (controller-side)Payment processing (account/billing data)US — EU–US DPF certified (+ SCCs in its Data Transfers Addendum)Scout & Scout Team

Effective 2 July 2026 · Version 1.0 · Forms part of the Terms of Service · Groundworks AI is the trading name of Groundworks Marketing AI Oy · groundworksai.com

Groundworks AI

Your new marketing co-worker. The output of a marketing team, without the headcount.

Product

  • Scout
  • Scout Team
  • Pricing

Company

  • About

Connect

  • LinkedIn
  • Contact
Groundworks AI Oy · Finland · 2026
For investors Privacy Terms