Effective date: 27 September 2026 · Version 1.8 · Minor · Scout & Scout Team
This notice explains what personal data we process when you use the Scout or Scout Team product, why, on what legal basis, who we share it with, and your rights under the EU General Data Protection Regulation (GDPR) and Finnish data-protection law. It is separate from, and complementary to, our website Privacy Policy, which covers personal data we collect through groundworksai.com (the waitlist, bookings, the newsletter, and site logs).
Groundworks Marketing AI Oy (Business ID / Y-tunnus 3625461-9), Finland, trading as Groundworks AI, is the controller for the personal data described in this notice. Registered address Toinen Linja 3 B 24, 00530 Helsinki, Finland. For privacy questions or to exercise your rights, contact us at privacy@groundworksai.com.
This notice covers personal data processed inside the Scout/Scout Team product for subscribers. We hold three different roles depending on the data, and it matters which one applies to you:
This section is for people invited to a seat on someone else's Scout Team account. Your terms are the Seat terms.
1. Who is responsible for your data. Groundworks Marketing AI Oy is the controller for your data as a person: the details used to invite you, your login, your voice profile and the private material you give Scout. The business that invited you (the account holder) is the controller for the posts published for its business, and we process those on its behalf.
2. What we hold, and where it came from.
| What | Source |
|---|---|
| Your name, email address and role | The account holder, when they invited you |
| Anything they pre-filled: a short bio, a writing sample, up to three topics | The account holder, if they chose to |
| Your login (a password we store only as a hash, or your Google sign-in) | You |
| Your writing sample, role and topics if you add or change them, and your acceptance of our terms | You |
| Your voice profile — a model of how you write, built from your samples and your edits | Built by us from the above |
| Your drafts, approvals and edits | Your use of the seat |
| Your LinkedIn identity and posts, if you connect your own LinkedIn account (see §6a) | LinkedIn, with your authorisation (a seat connects its own account; the connection is yours, not the account holder's) |
| Technical and usage data | Automatically |
3. Why, and on what legal basis.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Sending you the invitation (and a reminder if the account holder resends it) | Legitimate interests (Art. 6(1)(f)) — the account holder's interest in adding a colleague, and ours in delivering the service they pay for |
| Running your seat once you accept | Performance of a contract with you (Art. 6(1)(b)) — the Seat terms |
| Work an admin assigns you, and what you write and approve for it | Performance of the account holder's contract with us; we process it for the account holder, who is its controller (it belongs to the business, as your own posts published for it do) |
| Service messages, such as the daily post notification | Legitimate interests (Art. 6(1)(f)) |
| Product news by email | Your consent (Art. 6(1)(a)), only if you tick the separate box; you can withdraw it at any time |
| Security and preventing misuse | Legitimate interests (Art. 6(1)(f)) |
4. Who sees it. The account holder's administrators can see your name, email, role, when you were invited, and whether you have opened Scout in the last five days. Inside Scout they cannot see your drafts or posts, your voice profile or your writing sample. Today the account holder's account export does include your voice profile and writing sample. We are removing that, and this notice will say so when it is done. Our sub-processors (§6) process your data for us, including Anthropic, whose models generate your drafts (§5). We do not sell it.
5. How long we keep it.
6. Your rights. The rights in §9 apply to you in full, and you exercise them with us directly at privacy@groundworksai.com, not through the account holder. You can also complain to the Office of the Data Protection Ombudsman (tietosuoja.fi).
A Scout subscriber can share a view-only page of their marketing strategy through a link. This section is for people who open one.
| Category | Examples | Source |
|---|---|---|
| Account & billing | Name, business name, email, login credentials, plan, payment details (held by Stripe — we do not store full card numbers) | You |
| Intake data | The Day-0 intake form (company context, ICP, offer and positioning, voice, growth motion, cadence preferences) | You |
| Website-scrape data | Brand tokens (logo, colours, fonts), primary CTA, and image assets crawled from your own website, which you confirm or edit at intake | First-party crawl of your site, with your instruction |
| In-platform signals | Your review/approval history and patterns, content-fuel responses, self-reported outcomes | Your use of the service |
| Connected tools (Scout Team) | The tool's account identifiers, your sealed tokens and any client secret you give us, the connection's settings; what we read from the tool on your instruction (see §6c) | You, and the tool, with your authorisation |
| LinkedIn connection (Scout & Scout Team) | Your LinkedIn member identity; the posts we publish on your instruction; and the performance of those posts (e.g. impressions, reach, saves, link clicks, followers gained) | LinkedIn’s API, with your authorisation |
| Audience/recipient data in your content | Personal data of people you address in generated content/outreach | You (you are controller — see the DPA) |
| Seat-holder data (Scout Team) | For people invited to a seat on someone else's account — see §2a | The account holder, then the seat-holder |
| Technical & usage | IP address, device/browser data, log and usage data within the product | Automatically |
We do not intentionally collect special-category personal data, and you should not submit it through the service.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide, operate, and support the service; generate and deliver your content | Performance of a contract (Art. 6(1)(b)) |
| Process payments and manage subscriptions | Contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) |
| Improve and secure the service; prevent abuse | Legitimate interests (Art. 6(1)(f)) — our interest in keeping the service reliable, secure, and free of misuse, and in fixing and improving it, balanced against your rights |
| Connect the tools you choose, and read from and write to them on your instruction (Scout Team) | Contract (Art. 6(1)(b)) and your authorisation |
| Publish posts you have approved to your LinkedIn profile, and read the performance of those posts (Scout & Scout Team — only if you connect LinkedIn) | Performance of a contract (Art. 6(1)(b)) and your authorisation |
| Product/service communications to you (e.g. run notifications) | Legitimate interests (Art. 6(1)(f)) — our interest in keeping an active subscriber informed about the service they pay for |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Improve our marketing methodology and benchmarks using aggregated, anonymised usage metrics (optional — see §5a) | Consent (Art. 6(1)(a)) — only where you opt in; withdrawable at any time |
We do not sell your personal data.
(Art. 13(2)(e) GDPR.) Providing your account, billing, and intake data is a contractual requirement — we need it to deliver the subscription, and without it we cannot provide the service (e.g. we cannot bill you, set up your account, or generate content fitted to your business). Providing data through the integrations you choose to connect — the LinkedIn connection, and the newsletter, social and workspace integrations in Scout Team — is optional, but the related features will not work if you do not. The product works without the LinkedIn connection; you copy approved content out manually instead. The methodology opt-in in §5a is likewise entirely optional — declining it has no effect on your subscription or the service you receive.
Automated decision-making. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing (Art. 22 GDPR). Content is generated using AI, but every item is surfaced to you for review and approval in The Review before it is used — a human (you) is always in the loop.
To generate your content, we send relevant inputs and signals to Anthropic's Claude via Anthropic's commercial API. Anthropic processes this data as our sub-processor to return generated content. Anthropic does not use commercial-API inputs or outputs to train its models by default, and deletes them within 30 days of processing (longer only where required for safety review or by law). We are in the process of arranging Zero-Data-Retention (ZDR) with Anthropic for our production models; if and once ZDR is in place, Anthropic retains no inputs or outputs at rest beyond returning your content. Until then, the 30-day default above applies. You never provide an Anthropic API key; we operate the service under a single commercial account.
With your consent, we use usage metrics only — such as approval rates, output volume, revision rates, completion patterns and time to approval — in aggregated and anonymised form, to improve our marketing methodology and benchmarks, so the service gets better for everyone over time. We never include your content, your positioning or strategy text, or anything that identifies you, your business or your customers. Aggregated and anonymised means combined with other subscribers’ metrics so that the result does not identify you or your business.
We use the following third parties to provide the service. Each processes personal data only as needed to perform its function, under contract. The Data Processing Agreement (Annex III) carries the authoritative list.
| Sub-processor | Purpose | Applies to |
|---|---|---|
| Anthropic | AI content generation (Claude) | Scout & Scout Team |
| Fly.io (EU region) | Product application hosting / data storage | Scout & Scout Team |
| Stripe | Payment processing | Scout & Scout Team |
| Notion | Workspace-context read (the source you nominate) | Scout Team |
| Beehiiv | Newsletter publishing | Scout Team |
Website-only providers (e.g. our website host and form/scheduling tools) are listed in the website Privacy Policy, not here. Stripe processes your account and billing data, for which we are the controller — it is a controller-side processor for that data. Tools you connect with your own sign-in (§6c) are not listed: they are yours, not our sub-processors. Notion and Beehiiv remain listed while we confirm whether any subscriber data reaches them through an account of ours. The LinkedIn connection works differently: we connect to LinkedIn directly, so we hold your LinkedIn access token ourselves (and a refresh token where LinkedIn issues one), encrypted at rest, and delete them when you disconnect or your subscription ends. LinkedIn does not appear in the table above because it is not our sub-processor — see §6a.
When you connect LinkedIn, we act on your instruction through LinkedIn’s own API: we publish posts you have approved to your own profile, and we read how those posts performed.
We request four permissions, and only four. LinkedIn’s approval would let our application ask for twelve; we decline eight of them. The four we ask for, and what each is for:
| Permission | What it lets us do |
|---|---|
| Post on your behalf | Publish a post you have approved to your own profile. |
| Comment on your behalf | Add the first comment to your own post — this is where we put any link, because a link in the post itself reduces how many people LinkedIn shows it to. |
| Read your post analytics | Show you how your own posts performed. |
| Read your basic profile | Identify your LinkedIn account, so we publish to the right profile. |
You can connect Scout to an AI assistant or developer tool that you choose, such as Claude, ChatGPT, Claude Code or Cursor. Once connected, that assistant can do in Scout what you can do: read your drafts, edit, approve, skip and publish them, and read or change your theme and settings. It acts only when you, through that assistant, ask it to. Setup is described at groundworksai.com/install.
Scout Team can connect to tools you already use, such as HubSpot or a newsletter tool, using your own sign-in (and, where the tool needs one, a connection you create in it and paste into Scout).
We host and process data in the EU/EEA (our application runs in an EU region — Fly.io EU, see §6). Some sub-processors process data outside the EEA, principally in the United States (e.g. Anthropic, Stripe). Where they do, the transfer is protected by an appropriate safeguard under Chapter V GDPR — the EU–US Data Privacy Framework where the provider is certified, and/or the European Commission's Standard Contractual Clauses. You can obtain a copy of the relevant safeguard, or details of the mechanism that applies to a specific sub-processor, by contacting privacy@groundworksai.com.
We keep personal data for as long as needed for the purposes above and to meet legal obligations. Specifically:
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to processing; data portability; and — where we rely on your consent — withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal. To exercise any right, contact privacy@groundworksai.com. We provide an in-product export to support access/portability. We respond without undue delay and within one month of your request (extendable by two further months for complex or numerous requests, in which case we will tell you), per Art. 12(3) GDPR.
You also have the right to lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) — tietosuoja.fi.
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, EU-region hosting, and sub-processors who maintain recognised security standards. No system is perfectly secure; we will notify you and the supervisory authority of a personal-data breach where required by law.
The Scout/Scout Team product uses only the essential cookies/local storage needed to sign you in and run the application (e.g. session management). It does not use advertising or tracking cookies. Cookies on the public website are covered by the website Privacy Policy.
The service is for business use by adults. It is not directed at children, and we do not knowingly collect data from anyone under 18.
We may update this notice. The version and date at the top show when it last changed, and each version is tagged material or minor:
Privacy questions and rights requests: privacy@groundworksai.com. Supervisory authority: Office of the Data Protection Ombudsman, Finland (tietosuoja.fi).
Effective 27 September 2026 · Version 1.8 · Groundworks AI is the trading name of Groundworks Marketing AI Oy · groundworksai.com