Groundworks AI
Pricing About Blog Log in Start free
Legal · Subscribers

Subscriber Privacy Notice

Effective date: 27 September 2026 · Version 1.8 · Minor · Scout & Scout Team

This notice explains what personal data we process when you use the Scout or Scout Team product, why, on what legal basis, who we share it with, and your rights under the EU General Data Protection Regulation (GDPR) and Finnish data-protection law. It is separate from, and complementary to, our website Privacy Policy, which covers personal data we collect through groundworksai.com (the waitlist, bookings, the newsletter, and site logs).

1. Who we are (data controller)

Groundworks Marketing AI Oy (Business ID / Y-tunnus 3625461-9), Finland, trading as Groundworks AI, is the controller for the personal data described in this notice. Registered address Toinen Linja 3 B 24, 00530 Helsinki, Finland. For privacy questions or to exercise your rights, contact us at privacy@groundworksai.com.

2. Scope and roles

This notice covers personal data processed inside the Scout/Scout Team product for subscribers. We hold three different roles depending on the data, and it matters which one applies to you:

  • We are the controller for your account and billing data — the data that identifies you as our customer and lets us run your subscription (see §1, §3, and the legal bases in §4).
  • We are your processor for personal data contained in the content you generate, your inputs, and your connected audiences/integrations (for example, contacts you address in outreach). For that data you are the controller and we act on your instructions. The Data Processing Agreement governs that relationship — not this notice.
  • We are the controller for the aggregated, anonymised usage metrics described in §5a — but only where you give the separate, optional consent set out there. Without that consent, we do not carry out that processing.
  • If you were invited to a seat on someone else's Scout Team account, §2a is for you.
  • If you opened a strategy link someone shared with you, §2b is for you.
  • Tools you connect (§6c): what we read from and write to them on your instruction is data you control, and we process it as your processor under the DPA. The connection itself (its tokens and settings) is account data we control.

2a. If you were invited to a seat (Scout Team)

This section is for people invited to a seat on someone else's Scout Team account. Your terms are the Seat terms.

1. Who is responsible for your data. Groundworks Marketing AI Oy is the controller for your data as a person: the details used to invite you, your login, your voice profile and the private material you give Scout. The business that invited you (the account holder) is the controller for the posts published for its business, and we process those on its behalf.

2. What we hold, and where it came from.

WhatSource
Your name, email address and roleThe account holder, when they invited you
Anything they pre-filled: a short bio, a writing sample, up to three topicsThe account holder, if they chose to
Your login (a password we store only as a hash, or your Google sign-in)You
Your writing sample, role and topics if you add or change them, and your acceptance of our termsYou
Your voice profile — a model of how you write, built from your samples and your editsBuilt by us from the above
Your drafts, approvals and editsYour use of the seat
Your LinkedIn identity and posts, if you connect your own LinkedIn account (see §6a)LinkedIn, with your authorisation (a seat connects its own account; the connection is yours, not the account holder's)
Technical and usage dataAutomatically

3. Why, and on what legal basis.

PurposeLegal basis (GDPR Art. 6)
Sending you the invitation (and a reminder if the account holder resends it)Legitimate interests (Art. 6(1)(f)) — the account holder's interest in adding a colleague, and ours in delivering the service they pay for
Running your seat once you acceptPerformance of a contract with you (Art. 6(1)(b)) — the Seat terms
Work an admin assigns you, and what you write and approve for itPerformance of the account holder's contract with us; we process it for the account holder, who is its controller (it belongs to the business, as your own posts published for it do)
Service messages, such as the daily post notificationLegitimate interests (Art. 6(1)(f))
Product news by emailYour consent (Art. 6(1)(a)), only if you tick the separate box; you can withdraw it at any time
Security and preventing misuseLegitimate interests (Art. 6(1)(f))

4. Who sees it. The account holder's administrators can see your name, email, role, when you were invited, and whether you have opened Scout in the last five days. Inside Scout they cannot see your drafts or posts, your voice profile or your writing sample. Today the account holder's account export does include your voice profile and writing sample. We are removing that, and this notice will say so when it is done. Our sub-processors (§6) process your data for us, including Anthropic, whose models generate your drafts (§5). We do not sell it.

5. How long we keep it.

  • If you do not accept the invitation, the link expires after 7 days. We are adding automatic deletion of your details, and anything pre-filled for you, 30 days after the link expires. Until that is live, they are kept with the account holder's account; write to privacy@groundworksai.com and we will delete them.
  • While you have a seat, we keep your data for as long as the seat exists.
  • When your seat ends: posts already published stay with the account holder, with your name on its record of them, marked "former seat". You can ask us to remove your name; we weigh that against the account holder's interest in an accurate record. We are changing what happens to your voice profile when a seat ends: it will leave the account holder's account at once, and we will keep the personal part of it for you for 30 days so you can start your own Scout with it, download it or delete it. Until that change is live, it stays in the account holder's account until you or they ask us to delete it, or the account ends. You can ask us at any time at privacy@groundworksai.com.

6. Your rights. The rights in §9 apply to you in full, and you exercise them with us directly at privacy@groundworksai.com, not through the account holder. You can also complain to the Office of the Data Protection Ombudsman (tietosuoja.fi).

2b. If you opened a shared strategy link

A Scout subscriber can share a view-only page of their marketing strategy through a link. This section is for people who open one.

  • What we process. Your IP address, while you load the page, to keep the page secure and to limit how often it can be requested (no more than 60 requests in 15 minutes from one address). It is held only for that window and in our standard short-lived request logs, and is not linked to you.
  • What we store. Nothing that identifies you. We count how many times the link has been opened and record the date it was last opened. We do not store your IP address, browser details, location or the page you came from against the link.
  • Who is responsible for the content. The page shows statements written by the subscriber who shared it; they decide whom to share it with and are responsible for what it says. It shows no quotes, sources or names of other people.
  • Legal basis. Our legitimate interests (Art. 6(1)(f)) in keeping the service secure and preventing misuse; and, for the open count, in showing the subscriber that their link is used.
  • Your rights. §9 applies. Because we store nothing that identifies you, we will usually be unable to find data about you (Art. 11); write to privacy@groundworksai.com if you think otherwise.

3. What we collect

CategoryExamplesSource
Account & billingName, business name, email, login credentials, plan, payment details (held by Stripe — we do not store full card numbers)You
Intake dataThe Day-0 intake form (company context, ICP, offer and positioning, voice, growth motion, cadence preferences)You
Website-scrape dataBrand tokens (logo, colours, fonts), primary CTA, and image assets crawled from your own website, which you confirm or edit at intakeFirst-party crawl of your site, with your instruction
In-platform signalsYour review/approval history and patterns, content-fuel responses, self-reported outcomesYour use of the service
Connected tools (Scout Team)The tool's account identifiers, your sealed tokens and any client secret you give us, the connection's settings; what we read from the tool on your instruction (see §6c)You, and the tool, with your authorisation
LinkedIn connection (Scout & Scout Team)Your LinkedIn member identity; the posts we publish on your instruction; and the performance of those posts (e.g. impressions, reach, saves, link clicks, followers gained)LinkedIn’s API, with your authorisation
Audience/recipient data in your contentPersonal data of people you address in generated content/outreachYou (you are controller — see the DPA)
Seat-holder data (Scout Team)For people invited to a seat on someone else's account — see §2aThe account holder, then the seat-holder
Technical & usageIP address, device/browser data, log and usage data within the productAutomatically

We do not intentionally collect special-category personal data, and you should not submit it through the service.

4. Why we use it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Provide, operate, and support the service; generate and deliver your contentPerformance of a contract (Art. 6(1)(b))
Process payments and manage subscriptionsContract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c))
Improve and secure the service; prevent abuseLegitimate interests (Art. 6(1)(f)) — our interest in keeping the service reliable, secure, and free of misuse, and in fixing and improving it, balanced against your rights
Connect the tools you choose, and read from and write to them on your instruction (Scout Team)Contract (Art. 6(1)(b)) and your authorisation
Publish posts you have approved to your LinkedIn profile, and read the performance of those posts (Scout & Scout Team — only if you connect LinkedIn)Performance of a contract (Art. 6(1)(b)) and your authorisation
Product/service communications to you (e.g. run notifications)Legitimate interests (Art. 6(1)(f)) — our interest in keeping an active subscriber informed about the service they pay for
Comply with legal obligationsLegal obligation (Art. 6(1)(c))
Improve our marketing methodology and benchmarks using aggregated, anonymised usage metrics (optional — see §5a)Consent (Art. 6(1)(a)) — only where you opt in; withdrawable at any time

We do not sell your personal data.

4a. Do you have to provide this data?

(Art. 13(2)(e) GDPR.) Providing your account, billing, and intake data is a contractual requirement — we need it to deliver the subscription, and without it we cannot provide the service (e.g. we cannot bill you, set up your account, or generate content fitted to your business). Providing data through the integrations you choose to connect — the LinkedIn connection, and the newsletter, social and workspace integrations in Scout Team — is optional, but the related features will not work if you do not. The product works without the LinkedIn connection; you copy approved content out manually instead. The methodology opt-in in §5a is likewise entirely optional — declining it has no effect on your subscription or the service you receive.

Automated decision-making. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing (Art. 22 GDPR). Content is generated using AI, but every item is surfaced to you for review and approval in The Review before it is used — a human (you) is always in the loop.

5. AI processing (Anthropic / Claude)

To generate your content, we send relevant inputs and signals to Anthropic's Claude via Anthropic's commercial API. Anthropic processes this data as our sub-processor to return generated content. Anthropic does not use commercial-API inputs or outputs to train its models by default, and deletes them within 30 days of processing (longer only where required for safety review or by law). We are in the process of arranging Zero-Data-Retention (ZDR) with Anthropic for our production models; if and once ZDR is in place, Anthropic retains no inputs or outputs at rest beyond returning your content. Until then, the 30-day default above applies. You never provide an Anthropic API key; we operate the service under a single commercial account.

5a. Optional — using anonymised usage metrics to improve our methodology

With your consent, we use usage metrics only — such as approval rates, output volume, revision rates, completion patterns and time to approval — in aggregated and anonymised form, to improve our marketing methodology and benchmarks, so the service gets better for everyone over time. We never include your content, your positioning or strategy text, or anything that identifies you, your business or your customers. Aggregated and anonymised means combined with other subscribers’ metrics so that the result does not identify you or your business.

  • Not switched on yet. If you opt in, we record your choice, but no metrics are combined until this feature is switched on.
  • Entirely optional, and separate from your subscription. You give this permission through a dedicated, unticked opt-in — never as a condition of using the service, and never bundled with your acceptance of our Terms (Art. 7(4) GDPR). The service works fully whether or not you opt in.
  • Legal basis: your consent (Art. 6(1)(a) GDPR).
  • Withdraw at any time — in your settings, or at privacy@groundworksai.com. Withdrawal stops any further such use going forward and does not affect the lawfulness of processing carried out before you withdrew (see §9).
  • We use this data only in aggregated, anonymised form for the purpose described here. We do not sell it, and we do not use it to make automated decisions about you (see §4a).
  • LinkedIn-derived data is excluded from this permission. Performance data we retrieve from LinkedIn is never included in the aggregated metrics described here, whether or not you opt in — LinkedIn’s developer terms do not permit that data to be combined with other data.

6. Sub-processors

We use the following third parties to provide the service. Each processes personal data only as needed to perform its function, under contract. The Data Processing Agreement (Annex III) carries the authoritative list.

Sub-processorPurposeApplies to
AnthropicAI content generation (Claude)Scout & Scout Team
Fly.io (EU region)Product application hosting / data storageScout & Scout Team
StripePayment processingScout & Scout Team
NotionWorkspace-context read (the source you nominate)Scout Team
BeehiivNewsletter publishingScout Team

Website-only providers (e.g. our website host and form/scheduling tools) are listed in the website Privacy Policy, not here. Stripe processes your account and billing data, for which we are the controller — it is a controller-side processor for that data. Tools you connect with your own sign-in (§6c) are not listed: they are yours, not our sub-processors. Notion and Beehiiv remain listed while we confirm whether any subscriber data reaches them through an account of ours. The LinkedIn connection works differently: we connect to LinkedIn directly, so we hold your LinkedIn access token ourselves (and a refresh token where LinkedIn issues one), encrypted at rest, and delete them when you disconnect or your subscription ends. LinkedIn does not appear in the table above because it is not our sub-processor — see §6a.

6a. The LinkedIn connection (Scout & Scout Team)

When you connect LinkedIn, we act on your instruction through LinkedIn’s own API: we publish posts you have approved to your own profile, and we read how those posts performed.

We request four permissions, and only four. LinkedIn’s approval would let our application ask for twelve; we decline eight of them. The four we ask for, and what each is for:

PermissionWhat it lets us do
Post on your behalfPublish a post you have approved to your own profile.
Comment on your behalfAdd the first comment to your own post — this is where we put any link, because a link in the post itself reduces how many people LinkedIn shows it to.
Read your post analyticsShow you how your own posts performed.
Read your basic profileIdentify your LinkedIn account, so we publish to the right profile.
  • Two of the four are write-only, and that asymmetry is deliberate. We can publish a post and add a comment to it. We cannot read your feed, read anyone’s comments, or read your messages — we do not ask for the permissions that would allow any of that, and one of them (reading members’ posts) LinkedIn does not grant at all.
  • We read data about you only. We retrieve nothing about the people who see, react to, or comment on your posts, and so we show you nothing about them.
  • What we retrieve is shown only to you: inside the product, or through an AI assistant you have connected (§6b).
  • LinkedIn is an independent controller, not our sub-processor. What LinkedIn does with your data is governed by LinkedIn’s own terms and privacy policy, which apply to you directly.
  • How long we keep it. We keep LinkedIn-derived performance data for no longer than LinkedIn’s own developer terms permit — currently a 48-hour storage window for post-performance metrics, confirmed with LinkedIn on 1 September 2026. If LinkedIn changes that limit, ours changes with it. We delete the data in any event when you disconnect, when your subscription ends, or on your request — whichever comes first.
  • Disconnect at any time in your settings. On disconnection we revoke our access, delete your tokens, and delete the performance data retrieved under the connection.

6b. Connecting Scout to an AI assistant (the Scout connector)

You can connect Scout to an AI assistant or developer tool that you choose, such as Claude, ChatGPT, Claude Code or Cursor. Once connected, that assistant can do in Scout what you can do: read your drafts, edit, approve, skip and publish them, and read or change your theme and settings. It acts only when you, through that assistant, ask it to. Setup is described at groundworksai.com/install.

  • Your choice, your recipient. When you ask a connected assistant to do something, we send the result to that assistant: for example a draft’s text and image, your theme, your settings, or a one-post performance summary. The assistant’s provider is not our sub-processor. You choose it and send data to it on your own instruction, so what it does with that data is governed by your agreement with that provider and its privacy policy. We do not choose, control or contract with it. Do not connect an assistant you would not trust with your drafts.
  • What we keep about a connection. We keep the connection’s name, when it was created, when it was last used, and when it expires or is revoked. For a connection made by signing in, we also keep the assistant’s registered name and web address. We keep keys and refresh keys only as one-way hashes, never in readable form. We do not keep the conversation you have with the assistant, because we never receive it; we receive only the requests it makes to Scout.
  • LinkedIn data through a connection. If you ask a connected assistant how one of your posts did, we give it the same summary we would show you in the product: one post at a time, your own posts only, in sentences. The §6a limits apply, including the 48-hour window. Once that summary reaches your assistant, how long it is kept is governed by your agreement with the assistant’s provider.
  • Disconnect at any time. You can revoke any connection under Settings → Account → API access. Revoking a connection stops it working immediately. The connection’s record is deleted with your account (§8).
  • Legal basis. This is part of providing the service you asked for (§4, performance of contract).

6c. Tools you connect (Scout Team)

Scout Team can connect to tools you already use, such as HubSpot or a newsletter tool, using your own sign-in (and, where the tool needs one, a connection you create in it and paste into Scout).

  • Your tool, your instruction. The tool's provider is not our sub-processor: you choose it and your agreement with it governs what it does with your data. We read and write only what the product describes, when you ask.
  • What we keep about a connection. The tool's account identifiers, your access and refresh tokens and any client secret you gave us (sealed, never readable), and the connection's settings.
  • HubSpot, specifically. When you ask for suggestions, we read contacts and deals owned by you in HubSpot (name, job title, company, country, lifecycle stage, opt-out status, and deal name, stage, dates, amount and lost reason). We read them live and do not store the list; we keep only a reference to the contact you pick. We do not read contacts' email addresses for suggestions, and we never suggest a contact who has opted out. When you mark a warm message as sent, we add a note to that contact in HubSpot. When you export an outbound sequence, we keep the recipient's name, email and company until 30 days after the export (or 90 days after your last change if you never export), and may create them in HubSpot as a lead. A newsletter you export arrives as a draft; you send it from HubSpot.
  • The people in your CRM. For their data you are the controller and we are your processor (DPA Annex I). You are responsible for having a lawful basis to contact them.
  • Disconnect at any time. We delete the tokens, any client secret and any cached data at once, and any records imported from the tool within 30 days. What you confirmed into your account stays.

7. Where your data is processed

We host and process data in the EU/EEA (our application runs in an EU region — Fly.io EU, see §6). Some sub-processors process data outside the EEA, principally in the United States (e.g. Anthropic, Stripe). Where they do, the transfer is protected by an appropriate safeguard under Chapter V GDPR — the EU–US Data Privacy Framework where the provider is certified, and/or the European Commission's Standard Contractual Clauses. You can obtain a copy of the relevant safeguard, or details of the mechanism that applies to a specific sub-processor, by contacting privacy@groundworksai.com.

8. How long we keep it

We keep personal data for as long as needed for the purposes above and to meet legal obligations. Specifically:

  • While your subscription is active, we keep your data for the life of the subscription.
  • When your subscription is paused or ends, your settings and signal pool are retained for 60 days so you can resume with continuity. On cancellation we provide an export of your content within 48 hours.
  • After that, your data is deleted within 30 days (of cancellation, or of the 60-day pause window expiring without resume), including from backups within one backup cycle.
  • LinkedIn-derived performance data is kept under the shorter bound in §6a, not the general periods above.
  • Seat-holders — see §2a. People who open a shared link — nothing is kept that identifies them (§2b).
  • Connected tools — tokens, client secrets and cached data are deleted at once on disconnection, and imported records within 30 days (§6c).
  • If you create an account but never finish setting up, and never subscribe, we keep only your account record and email address. We email you at 30 days to say the account will be removed, and delete it 14 days after that — 44 days from signup — unless you finish setting up in the meantime, which cancels the deletion. There is no intake, content or signal data to export in this case, because none was created.
  • Billing and accounting records we are legally required to keep are retained for the statutory period under the Finnish Accounting Act (Kirjanpitolaki 1336/1997, ch. 2 §10): accounting books and financial statements for at least 10 years, and vouchers and related business correspondence for at least 6 years, in each case from the end of the financial year — after which they are deleted. This applies only to those records; it does not extend to your intake, content, or signal data.

9. Your rights

Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and — where we rely on your consent — withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal. To exercise any right, contact privacy@groundworksai.com. We provide an in-product export to support access/portability. We respond without undue delay and within one month of your request (extendable by two further months for complex or numerous requests, in which case we will tell you), per Art. 12(3) GDPR.

You also have the right to lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) — tietosuoja.fi.

10. Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, EU-region hosting, and sub-processors who maintain recognised security standards. No system is perfectly secure; we will notify you and the supervisory authority of a personal-data breach where required by law.

11. Cookies and in-product storage

The Scout/Scout Team product uses only the essential cookies/local storage needed to sign you in and run the application (e.g. session management). It does not use advertising or tracking cookies. Cookies on the public website are covered by the website Privacy Policy.

12. Children

The service is for business use by adults. It is not directed at children, and we do not knowingly collect data from anyone under 18.

13. Changes

We may update this notice. The version and date at the top show when it last changed, and each version is tagged material or minor:

  • Material change — for example adding a sub-processor or a new purpose or legal basis for processing your data — we will notify you and ask you to actively accept the updated notice before you continue using the service (the same tiered re-acceptance that applies to the Terms of Service, clause 16). Until you accept, new content runs are paused and your data is retained.
  • Minor change — clarifications or non-material updates — we will post the updated version and notify you in-product or by email; continued use is acceptance.

14. Contact

Privacy questions and rights requests: privacy@groundworksai.com. Supervisory authority: Office of the Data Protection Ombudsman, Finland (tietosuoja.fi).

Effective 27 September 2026 · Version 1.8 · Groundworks AI is the trading name of Groundworks Marketing AI Oy · groundworksai.com

Groundworks AI

Your new marketing co-worker. The output of a marketing team, without the headcount.

Product

  • Scout
  • Scout Team
  • Pricing

Company

  • About
  • Comparisons

Connect

  • LinkedIn
  • Contact
Groundworks AI Oy · Finland · 2026
For investors Privacy Terms