Effective date: 2 July 2026 · Version 1.0 · Scout & Scout Team
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Groundworks Marketing AI Oy (Business ID / Y-tunnus 3625461-9), Finland, trading as Groundworks AI ("Processor", "we"), and the Subscriber ("Controller", "you"). It applies where we process personal data on your behalf in providing Scout or Scout Team. Capitalised terms not defined here have the meaning in the GDPR (Regulation (EU) 2016/679).
You are the controller of the personal data you submit to or generate through the service that relates to identifiable individuals — including data about people you address in generated content or outreach, and personal data within your inputs, integrations, and audiences ("Controller Personal Data"). We process it as your processor, only as set out in this DPA. (Where we determine purposes — e.g. your account, billing, and our website visitors — we act as controller under the Privacy Notice, and this DPA does not apply to that data.)
We do not process Controller Personal Data for our own purposes: we determine no purpose or means for it beyond your instructions, and acting on those instructions does not make us a controller of it (Art. 28(10) GDPR).
We will process Controller Personal Data only:
We will tell you if, in our opinion, an instruction infringes the GDPR.
We will:
You give general authorisation for us to engage the sub-processors listed in Annex III. We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a sub-processor, during which you may object on reasonable data-protection grounds; if the objection cannot be resolved, you may terminate the affected service.
The social-publishing aggregator (Scout Team — bundle.social) holds tokens for the social accounts you connect and is a sub-processor; we store only a reference to your connected account, not the tokens.
If a data subject contacts us directly regarding Controller Personal Data, we will (unless legally required to respond) refer them to you and assist you in responding, including via the in-product export.
We process Controller Personal Data in the EU/EEA. Where a sub-processor processes it outside the EEA, we ensure an appropriate transfer mechanism is in place. The mechanisms in place are: Anthropic (US) — EU Standard Contractual Clauses, Module Three (processor-to-processor); Notion (US) — EU–US Data Privacy Framework certification; Beehiiv (US) — EU Standard Contractual Clauses, Module Two; Stripe (US, controller-side) — EU–US Data Privacy Framework certification, with SCCs in its Data Transfers Addendum. Fly.io processes in the EU. For any UK transfer the UK IDTA/Addendum applies.
On termination or expiry of the service, we will delete or return Controller Personal Data at your choice, and delete existing copies, unless EU/member-state law requires retention. Pending deletion, data is retained for a bounded window so you can resume:
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms (clause 13), to the extent permitted by law. These inter-party limits do not affect either party's liability to a data subject under Art. 82 GDPR, or any other liability that cannot be limited under applicable law.
This DPA is governed by the laws of Finland and forms part of, and is subject to, the Terms of Service. The Finnish supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto).
These are the Art. 32 measures Groundworks AI maintains as Processor. Our Security & Data Handling Statement is the source of truth for the detailed, current measures; this Annex summarises them and is read together with it.
This schedule lists sub-processors that may process Controller Personal Data. Providers that process only website-visitor data (where Groundworks AI is the controller, e.g. the website host and website lead capture) are listed in the website Privacy Policy, not here. Stripe processes the subscriber's own account/billing data, for which Groundworks AI is controller; it is listed below for transparency as a controller-side processor.
| Sub-processor | Function | Location / mechanism | Applies to |
|---|---|---|---|
| Anthropic | AI content generation (Claude) | US — SCCs Module Three (no training by default; ≤30-day retention; Zero-Data-Retention being arranged) | Scout & Scout Team |
| Fly.io | Hosting / storage | EU region (Amsterdam) | Scout & Scout Team |
| Notion | Workspace context (the source you nominate) | US — EU–US DPF certified (Notion Labs, Inc.) | Scout Team |
| bundle.social | Social publishing; token custody | Engaged for Scout Team publishing under its own DPA | Scout Team |
| Beehiiv | Newsletter publishing | US — EU SCCs Module Two (per its DPA) | Scout Team |
| Stripe (controller-side) | Payment processing (account/billing data) | US — EU–US DPF certified (+ SCCs in its Data Transfers Addendum) | Scout & Scout Team |
Effective 2 July 2026 · Version 1.0 · Forms part of the Terms of Service · Groundworks AI is the trading name of Groundworks Marketing AI Oy · groundworksai.com