Groundworks AI
Pricing About Blog Log in Start free
Legal · Subscribers

Data Processing Agreement

Version 1.3 · Published and in force 27 September 2026 · Material · Scout & Scout Team

Version 1.3 is in force from 27 September 2026. It was first published to take effect on 28 October 2026; the date was brought forward because no subscriber outside the company held an account to give notice to. Existing accounts are asked to accept it at their next sign-in (Terms clause 16). It includes the changes announced for version 1.2, and adds tools you connect and seats.

  • Tools you connect, including LinkedIn (clause 4, Annexes II and III). If you connect LinkedIn, or another tool with your own sign-in (for example HubSpot or Beehiiv), we hold its access and refresh tokens ourselves, sealed at rest, and delete them when you disconnect or leave. The tool is treated as your own tool, acting on your instruction (LinkedIn as an independent controller), not a sub-processor we engage. If we ever treat one as a new sub-processor, your clause 4 right to object applies: write to contact@groundworksai.com.
  • Seats (clauses 1 and 7, Annex I). A seat-holder's own data (their invitation details, login, voice profile and private material) is ours as controller, not yours; the posts they approve for your business, and work you assign them, are yours.
  • Annex I lists the CRM records you let us read, the people you name as outbound recipients, and content you make available through links you create.
  • bundle.social removed (clause 4, Annex III). It was listed ahead of time for Scout Team publishing and was never engaged. No social-publishing aggregator is used: LinkedIn publishing runs directly.
  • Retention wording corrected (clause 7). The 60-day window is for a paused subscription (for example, a failed payment). After a cancellation, we deliver your export within 48 hours and delete your data within 30 days, as the same clause and Terms clause 15 already said. Version 1.1 wrongly said the window started from cancellation as well.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Groundworks Marketing AI Oy (Business ID / Y-tunnus 3625461-9), Finland, trading as Groundworks AI ("Processor", "we"), and the Subscriber ("Controller", "you"). It applies where we process personal data on your behalf in providing Scout or Scout Team. Capitalised terms not defined here have the meaning in the GDPR (Regulation (EU) 2016/679).

1. Roles

You are the controller of the personal data you submit to or generate through the service that relates to identifiable individuals — including data about people you address in generated content or outreach, and personal data within your inputs, integrations, and audiences ("Controller Personal Data"). We process it as your processor, only as set out in this DPA. (Where we determine purposes — e.g. your account, billing, our website visitors, and the personal data of the people you invite to a seat, described below — we act as controller under the Privacy Notice, and this DPA does not apply to that data.)

Seats (Scout Team). When you invite someone to a seat, you give us their name, email address and role, and anything you pre-fill for them. You disclose those details to us as a separate controller, not as your processor; clause 3a of the Terms sets out what you confirm when you do. We are the controller of each seat-holder's own data: their invitation details, login, voice profile and private material. That data serves the seat-holder's own relationship with us under our Seat terms, and it leaves with them when their seat ends. The posts a seat-holder approves for your business, and the work you assign them, are Controller Personal Data, and this DPA applies to them as to any other content.

We do not process Controller Personal Data for our own purposes: we determine no purpose or means for it beyond your instructions, and acting on those instructions does not make us a controller of it (Art. 28(10) GDPR).

2. Scope and instructions

We will process Controller Personal Data only:

  • to provide, maintain, and support the service in accordance with the Terms;
  • on your documented instructions (the Terms, your configuration, and your use of the service constitute your instructions) — including with regard to any transfer of Controller Personal Data to a third country or international organisation — unless required to do so by EU or member-state law, in which case we will inform you before processing unless that law prohibits it; and
  • as required by EU or member-state law, in which case we will inform you unless the law prohibits it.

We will tell you if, in our opinion, an instruction infringes the GDPR.

3. Our obligations

We will:

  1. Confidentiality — ensure persons authorised to process Controller Personal Data are bound by confidentiality;
  2. Security — implement appropriate technical and organisational measures under Art. 32 (see Annex II);
  3. Assist you — taking into account the nature of processing, assist you with: responding to data-subject requests (Art. 12–23), security (Art. 32), breach notification (Art. 33–34), and data-protection impact assessments and prior consultation (Art. 35–36);
  4. Breach notification — notify you without undue delay after becoming aware of a personal-data breach affecting Controller Personal Data, with the information you reasonably need to meet your own obligations;
  5. Deletion/return — at the end of the service, delete or return Controller Personal Data as set out in clause 7;
  6. Audit — make available the information needed to demonstrate compliance with this DPA and allow for and contribute to audits, subject to reasonable confidentiality and frequency limits.

4. Sub-processors

You give general authorisation for us to engage the sub-processors listed in Annex III. We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor, during which you may object on reasonable data-protection grounds; if the objection cannot be resolved, you may terminate the affected service.

Tools you connect. Where you connect a tool with your own sign-in (for example HubSpot, Beehiiv, a website builder, a scheduler or LinkedIn), we act on your instruction against that tool's own service. We hold its access and refresh tokens, and any client secret you give us, sealed at rest, and delete them at once on disconnection or termination. The tool's provider is not a sub-processor we engage: you chose it and contract with it directly. For LinkedIn, which holds data about the member for its own purposes, LinkedIn is an independent controller. We read and write only what the connection's scope and the product allow, and drafting in a tool never publishes or sends: that is a separate step you approve. Where a connected tool can send email to your own list, you are the controller of that list and of its recipients' consent, and we send only a send you have approved on its own. No social-publishing aggregator and no connection broker is engaged. If we ever route your data through a service of ours other than those in Annex III, that service is a new sub-processor and this clause's notice applies.

5. Data-subject requests

If a data subject contacts us directly regarding Controller Personal Data, we will (unless legally required to respond) refer them to you and assist you in responding, including via the in-product export.

6. International transfers

We process Controller Personal Data in the EU/EEA. Where a sub-processor processes it outside the EEA, we ensure an appropriate transfer mechanism is in place. The mechanisms in place are: Anthropic (US) — EU Standard Contractual Clauses, Module Three (processor-to-processor); Notion (US) — EU–US Data Privacy Framework certification; Beehiiv (US) — EU Standard Contractual Clauses, Module Two; Stripe (US, controller-side) — EU–US Data Privacy Framework certification, with SCCs in its Data Transfers Addendum. Fly.io processes in the EU. For any UK transfer the UK IDTA/Addendum applies.

7. Deletion and return

On termination or expiry of the service, we will delete or return Controller Personal Data at your choice, and delete existing copies, unless EU/member-state law requires retention. A seat-holder's own data (clause 1, Seats) is not Controller Personal Data and is not returned to you. When you disconnect a tool, we delete its tokens and any cached data from it at once, and records we imported from it within 30 days; what you confirmed into your account stays. Pending deletion, data is retained for a bounded window so you can resume:

  • Retention window (pause/resume): 60 days from the date the subscription is paused (including a lapsed payment), during which your data is preserved so you can resume with continuity. A cancellation does not start this window; it follows the deletion bullet below.
  • Deletion: on cancellation we deliver an export within 48 hours, then hard-delete within 30 days; on retention-window expiry without resume, hard-deletion completes within 30 days of expiry. Copies are purged from backups within one backup-rotation cycle.
  • Statutory override: billing/transaction records required by Finnish accounting law are retained for the statutory period and deleted thereafter; this override does not extend to your intake, content, or signal data.

8. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (clause 13), to the extent permitted by law. These inter-party limits do not affect either party's liability to a data subject under Art. 82 GDPR, or any other liability that cannot be limited under applicable law.

9. Governing law

This DPA is governed by the laws of Finland and forms part of, and is subject to, the Terms of Service. The Finnish supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).

Annex I — Details of processing

  • Subject matter: provision of the Scout/Scout Team content-generation service.
  • Duration: the term of the subscription, plus the retention window in clause 7.
  • Nature and purpose: generating, storing, and (for Scout Team) publishing marketing content using AI and connected integrations on your instruction, and making content available through links you create.
  • Types of personal data: personal data within your inputs and prompts; names, email addresses, and other contact details of the contacts, prospects, and audiences you address in generated content or outreach; integration-account identifiers and engagement metrics (Scout Team); records you let us read from a CRM you connect (for a contact: name, job title, company, country, lifecycle stage, owner and opt-out status; for a deal: its name, stage, dates, amount and lost reason), read live and not stored, except a reference to a contact you chose; the name, email address and company of a person you name as an outbound recipient; and, for Scout Team seats, the name and content of posts a seat-holder approves for your business. We do not require special-category data and you must not submit it.
  • Categories of data subjects: your contacts, prospects, newsletter and social audiences, named individuals referenced in your content, the people in the CRM records you let us read, and your seat-holders, as the named authors of posts published for your business.
  • Special-category data: none intended; you must not submit special-category data.

Annex II — Technical and organisational security measures

These are the Art. 32 measures Groundworks AI maintains as Processor. Our Security & Data Handling Statement is the source of truth for the detailed, current measures; this Annex summarises them and is read together with it.

  • Encryption. Personal data is encrypted in transit (TLS) and at rest in the application data store.
  • Hosting & residency. The application and primary data store are hosted in an EU region (Fly.io, Amsterdam). The PostgreSQL data store is operated by Groundworks AI on that infrastructure rather than taken as a managed database service, so responsibility for its configuration, backup, and deletion sits with Groundworks AI as Processor, not with the hosting provider.
  • Access control & tenancy isolation. Role-based access on a least-privilege basis; multi-tenant isolation (row-level security) so one subscriber's data is not accessible to another; authenticated administrative access only, no shared production accounts.
  • Authentication. Credential controls for subscriber and administrative access.
  • Logging & monitoring. Application and access logging; monitoring for anomalous activity.
  • Integration-token handling. For every connected tool, including the direct LinkedIn connection, Groundworks AI holds the access and refresh tokens and any client secret itself: sealed with AES-256-GCM at rest, tenant-isolated, access restricted to the services that require it, refreshed on the tool's cycle, revoked and deleted on disconnection or termination, and revoked within the containment window of the incident procedure. Every call a connection may make is on an allow-list, and no allow-listed call sends or publishes without a separate approval.
  • Sub-processor due diligence. Each sub-processor is engaged under a DPA with obligations no less protective than this DPA (clause 4); the data path is reviewed before onboarding.
  • Breach response. A documented breach-detection and response process supporting the notification duty in clause 3(4) and Art. 33–34.
  • Deletion & backups. Deletion and retention per clause 7, including propagation to sub-processors and purge from backups within one rotation cycle.

Annex III — Authorised sub-processors

This schedule lists sub-processors that may process Controller Personal Data. Providers that process only website-visitor data (where Groundworks AI is the controller, e.g. the website host and website lead capture) are listed in the website Privacy Policy, not here. Stripe processes the subscriber's own account/billing data, for which Groundworks AI is controller; it is listed below for transparency as a controller-side processor.

Sub-processorFunctionLocation / mechanismApplies to
AnthropicAI content generation (Claude)US — SCCs Module Three (no training by default; ≤30-day retention; Zero-Data-Retention being arranged)Scout & Scout Team
Fly.ioHosting / storageEU region (Amsterdam)Scout & Scout Team
NotionWorkspace context (the source you nominate)US — EU–US DPF certified (Notion Labs, Inc.)Scout Team
BeehiivNewsletter publishingUS — EU SCCs Module Two (per its DPA)Scout Team
Stripe (controller-side)Payment processing (account/billing data)US — EU–US DPF certified (+ SCCs in its Data Transfers Addendum)Scout & Scout Team

Tools you connect are deliberately not listed above (clause 4): LinkedIn, and any CRM, newsletter tool, website builder or scheduler you connect with your own sign-in. You choose and contract with each; we act on your instruction. LinkedIn, which determines its own purposes for the data it holds about the member, is an independent controller. We have nevertheless given the clause 4 notice of 30 days for this change, so your right to object applies whichever way the characterisation is read. Notion and Beehiiv remain listed above while we confirm whether any subscriber data reaches them through an account of ours; if none does, they will be removed as a minor change.

Version 1.3 · In force from 27 September 2026 · Forms part of the Terms of Service · Groundworks AI is the trading name of Groundworks Marketing AI Oy · groundworksai.com

Groundworks AI

Your new marketing co-worker. The output of a marketing team, without the headcount.

Product

  • Scout
  • Scout Team
  • Pricing

Company

  • About
  • Comparisons

Connect

  • LinkedIn
  • Contact
Groundworks AI Oy · Finland · 2026
For investors Privacy Terms