
Privacy Policy

Effective date: September 15, 2026
Last updated: September 15, 2026
1. Who We Are
Fresh Ground Solutions, Inc. ("Fresh Ground," "we," "us," "our") is a technology advisory and delivery company. We offer three services: AI (consulting, implementation, and training), Advise (fractional CTO leadership), and Build (software delivery and cloud).
Fresh Ground Solutions, Inc. is a Webapper company. Webapper Services, LLC operates webapper.com under its own privacy policy at webapper.com/privacy-policy.
This policy covers freshground.solutions and freshground.ai, our marketing and outreach activity, and our client engagements.
How to reach us
Fresh Ground Solutions, Inc.
117 E Mountain Ave., Suite 222
Fort Collins, CO 80525
United States
Email: info@freshground.solutions
Our role. Fresh Ground Solutions, Inc. is the data controller (or "business," under US state law) for the information described in this policy. When we process data on behalf of a client under a services agreement, that client is the controller and we act as their processor. Section 12 covers that relationship.
2. The Short Version
We are a business-to-business company. Almost all the personal information we handle is professional contact information: your name, your work email, your company, and your role.
Here is what matters most:
- We do outbound. We research companies that look like a fit and reach out. Section 4 explains exactly where that data comes from and what your rights are. If you want out, one email ends it permanently.
- We do not sell your data. Not to anyone, for any price.
- We use analytics and advertising cookies. You can turn them off, and we honor Global Privacy Control.
- Client data is not ours. We do not mine it, sell it, or train AI models on it.
The rest of this policy is the detail behind those four points.
3. Information We Collect
3.1 Information you give us directly
| What | Where it comes from |
|---|---|
| Name, work email, company, phone, and whatever you write | Contact forms on freshground.solutions and freshground.ai |
| Name, email, meeting time, and any notes | Our booking page, which runs on Google Calendar |
| Email address and preferences | Newsletter and content signups |
| Whatever you type into the chat, and the conversation transcript | Our on-site AI concierge chat, powered by Fin by Intercom |
| Contact details, billing information, project materials, and credentials needed to do the work | Client engagements |
| Assessment responses and the business context you share | AI Readiness Assessment |
3.2 Information we collect automatically
When you visit our sites we and our providers collect:
- Log data: IP address, browser type and version, date and time stamps, referring and exit pages
- Cookie and similar identifiers: see Section 8
- Analytics and marketing attribution: pages viewed, session duration, traffic source, campaign parameters, approximate city-level location derived from IP address, and device characteristics
IP addresses, cookie identifiers, and similar online identifiers are personal information under the GDPR, the UK GDPR, the CCPA, and the US state laws in Section 11. We treat them that way.
3.3 Information from other sources
This is the part most privacy policies leave out. Ours does not. See Section 4.
3.4 What we do not collect
We do not knowingly collect government identification numbers, payment card numbers (we invoice and are paid by wire or bank transfer, so we never handle card data), precise geolocation, biometric data, or health information. We do not seek information about your race, religion, political opinions, or sexual orientation.
We do not sell your sensitive personal data. We do not sell your biometric data. We do not sell personal data at all, as "sale" is defined under US state privacy laws.
4. Business Contact Data and Outbound Outreach
We identify businesses that may benefit from our services and contact the people who make those decisions. This section explains that process honestly, because you deserve to know how we got your email address.
4.1 Where the data comes from
We source and verify business contact information using:
| Source | What it provides |
|---|---|
| Hunter | Professional email addresses associated with a company domain |
| Findymail | Professional email addresses, found and verified |
| LinkedIn Sales Navigator | Professional profile and company information used to identify decision makers |
| Google Places | Publicly listed business names, locations, categories, and contact details |
| DataForSEO | Search and web data used to identify companies and their online presence |
| Ahrefs | Website and search visibility data used for company research |
| Public sources | Company websites, professional networking profiles, public directories, press coverage, and public filings |
| Referrals | Introductions from partners, clients, and contacts |
We look for business contact information in a professional capacity: your work email, your role, your company, and public information about that company. We do not seek or want your personal email address, home address, or anything about your life outside work.
4.2 What we do with it
We store it in our CRM and use outbound email platforms to send and manage campaigns. Section 7 lists every provider we use, and it is the authoritative list. We use the data to send you a relevant, specific message about whether our services fit your business. We do not resell it, rent it, trade it, or contribute it to any shared database.
4.3 Our legal basis
In the United States, our outreach complies with the CAN-SPAM Act. Every message identifies us truthfully, uses accurate subject lines and headers, discloses that it is a commercial message, includes a valid physical postal address, and offers a working opt-out that we honor within 10 business days. In practice we honor it immediately.
In the EEA and UK, we rely on legitimate interests under GDPR Article 6(1)(f) to process business contact data for B2B outreach. We have assessed that interest against your rights and limited our processing accordingly: professional contact data only, relevant and targeted messages rather than bulk sends, and immediate removal on request.
Where you were not the source, GDPR Article 14 applies. When we obtain your data from somewhere other than you, we must tell you. Our first message to you links to this policy, which identifies us, explains where we got your information, why we are contacting you, how long we will keep it, and how to make us stop.
We prospect in North America. Our outbound outreach targets businesses in the United States and Canada. We do not market our services to individuals or businesses in the European Economic Area or the United Kingdom, we do not advertise in EEA or UK languages or currencies, and we do not use geolocation to target people there.
If you are in the EEA or UK and you contact us, or we reach you in error, the GDPR rights in Section 11 apply to you in full and we honor them. Tell us to stop and we will, permanently.
4.4 Your rights over this data, stated plainly
- You can tell us to stop, and we will. Reply to any message, click the unsubscribe link, or email info@freshground.solutions. Under the GDPR the right to object to direct marketing is absolute. We do not require a reason, and we do not ask for one.
- You can ask what we hold about you and we will tell you, including where we got it.
- You can ask us to delete it and we will, except for a minimal suppression record. That record exists only to guarantee we never contact you again, which is the outcome you asked for.
- You can ask us to correct it if it is wrong.
We keep prospect data that never becomes a conversation for 24 months, then delete it.
5. Why We Collect It
| Purpose | Information used | GDPR / UK GDPR legal basis |
|---|---|---|
| Respond to your inquiry or booking | Contact and booking data | Legitimate interests, and steps prior to a contract at your request |
| Deliver AI, Advise, and Build services | Client engagement data, billing data | Performance of a contract |
| Business development outreach | Business contact data (Section 4) | Legitimate interests, or consent where local law requires it |
| Score and prioritize leads against our ideal customer profile | Contact details, company information, engagement history | Legitimate interests |
| Answer questions through our on-site AI chat | Chat transcripts, anything you type | Legitimate interests, and steps prior to a contract at your request |
| Send newsletters and content | Email address, preferences | Consent, or legitimate interests for existing clients where permitted |
| Run the AI Readiness Assessment and give you results | Assessment responses, business context | Legitimate interests, and steps prior to a contract at your request |
| Operate, secure, and troubleshoot our sites | Log data | Legitimate interests |
| Understand site usage and improve it | Analytics data | Consent where required, otherwise legitimate interests |
| Run and measure advertising campaigns | Advertising identifiers, conversion and attribution data | Consent |
| Bill you and keep financial records | Billing and transaction data | Performance of a contract, and legal obligation |
| Meet legal, tax, and regulatory obligations | As required | Legal obligation |
Where we rely on legitimate interests, you can object at any time and we will stop unless we have compelling grounds to continue. For direct marketing, there are no compelling grounds that override your objection, so we simply stop.
Where we rely on consent, you can withdraw it at any time.
AI in our own operations
We sell AI services, so being specific about how we use AI on ourselves is the least we can do.
Our on-site chat is AI-powered. Fin by Intercom answers visitor questions in real time. Conversations are processed to generate responses and stored as transcripts. A person can join the conversation at any point, and you can ask to speak to one.
We use AI to score and prioritize leads. We rank inbound and prospective contacts against our ideal customer profile so we know who to talk to first. This is prioritization, not a decision about you. It does not set your price, deny you a service, or produce any legal or similarly significant effect, and a person makes every actual decision about who we contact and what we offer. You can object to it at any time under Section 11.
We do not use your data to train foundation models. We configure our AI providers to exclude our data from their training wherever that setting exists.
6. How Long We Keep It
| Category | Retention period |
|---|---|
| Prospect and business contact data that never becomes a conversation | 24 months |
| Inquiry and booking data that does not become a client relationship | 24 months from last contact |
| Client engagement records | Duration of the engagement, plus 7 years for tax, accounting, and legal claim purposes |
| Billing and financial records | 7 years, to meet US tax recordkeeping requirements |
| Marketing subscriptions | Until you unsubscribe, plus a permanent suppression record |
| Opt-out and suppression records | Kept indefinitely, so we never contact you again |
| Log data | 90 days |
| Analytics data | 26 months |
7. Who We Share It With
We do not sell your personal information, and we do not share it with third parties for their own marketing.
We share it with service providers who help us operate. Each is bound by contract to use it only for the services they provide to us.
| Provider | What they do | What they receive |
|---|---|---|
| Webflow | Hosts freshground.solutions and freshground.ai | Site traffic data, form submissions |
| Amazon Web Services | Cloud infrastructure, and email delivery through Amazon SES | Data in our systems, outbound email content and addresses |
| Google Workspace | Business email, calendar, and our booking page | Email content, meeting details |
| Copper | CRM for client and prospect relationships | Contact and communication data |
| Instantly, SmartLead | Outbound campaign sending and management | Business contact data, engagement events |
| Hunter, Findymail | Email discovery and verification | Company domains and contact lookups |
| LinkedIn Sales Navigator | Prospect and company research | Search and profile queries. A source of information to us. |
| Google Places / DataForSEO / Ahrefs | Company and market research | Query data. These are sources of information to us. |
| Google Ads, Meta Ads, LinkedIn Ads | Advertising and conversion measurement | Advertising identifiers, conversion events |
| Windsor.ai | Marketing attribution across channels | Campaign and conversion data |
| Google Analytics 4, Google Search Console | Website analytics and search performance | Usage and device data, IP address |
| Intercom (Fin) | On-site AI concierge chat | Chat transcripts, contact details you provide in the conversation |
| Our bank | Receiving payment by wire or bank transfer | Payment instructions and remittance details. No card data is collected. |
| QuickBooks (Intuit) | Invoicing and financial records | Billing and transaction data |
Each provider above is contractually limited to using the information only for the services it provides to us.
We also disclose personal information when the law requires it, when we need to protect rights or safety, in connection with a merger or sale of assets (you will be notified), or when you ask us to.
Within the Webapper group. We share limited information with Webapper Services, LLC where it is necessary to run shared operations such as accounting and administration, and where a client engagement involves both companies. Webapper is bound by the same commitments described here.
8. Cookies, Analytics, and Advertising
| Type | Purpose | Can you turn it off? |
|---|---|---|
| Strictly necessary | Site delivery, security, remembering your privacy choices | No. The sites will not work correctly without these. |
| Analytics | Understanding which pages work and how the sites perform | Yes |
| Advertising and attribution | Measuring campaigns and showing our ads on other sites, including Google Ads, Meta Ads, and Windsor.ai attribution | Yes |
Your choices
When you first visit either site, our consent banner lets you accept or reject analytics and advertising cookies. Strictly necessary cookies are always on, because the sites cannot function without them. You can change your choice at any time through the banner's settings link.
You can also block cookies in your browser settings, opt out of Google Analytics with Google's browser add-on, adjust ad personalization at Google Ads Settings and Meta ad preferences, and use the Digital Advertising Alliance's opt-out tools: WebChoices for browsers, AppChoices for mobile apps, or the unified control page. The Network Advertising Initiative retired its own opt-out tool on September 15, 2025, so we no longer link to it.
Global Privacy Control
We honor the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat it as a valid opt-out of targeted advertising and any sharing of your personal data. Colorado, Texas, California, and several other states require recognition of signals like this.
We do not respond to "Do Not Track," because no common industry standard defines what a site should do with it. GPC is the signal we honor.
9. Where Your Information Goes
We are based in the United States and our infrastructure is primarily in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to and processed in the United States.
For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK GDPR applies, along with supplementary measures including encryption in transit and at rest and access controls.
Some of our providers also participate in the EU-U.S. Data Privacy Framework. That framework remains formally in force but is subject to ongoing legal challenge, so we do not rely on it as our only transfer mechanism.
Email us for a copy of the safeguards we use.
10. How We Protect It
We maintain safeguards appropriate to the sensitivity of what we hold:
- Encryption in transit (TLS) and at rest
- Role-based access, limited to people who need it
- Multi-factor authentication on administrative accounts
- Authenticated email using SPF, DKIM, and DMARC with a reject policy, which protects you from anyone spoofing our domains
- Monitoring and audit logging of meaningful operations
- Vendor security review before onboarding a provider
No system is perfectly secure, and we cannot guarantee absolute security.
If a breach occurs, we will notify you and the relevant regulators as required by law. Under the GDPR that means notifying the supervisory authority within 72 hours of becoming aware where the breach poses a risk to individuals. US state breach notification laws set their own deadlines, and we will meet whichever applies.
11. Your Rights
Your rights depend on where you live. We extend the core rights below to everyone who asks, regardless of location.
11.1 How to exercise them
Email info@freshground.solutions with "Privacy Request" in the subject line, or write to our mailing address in Section 1.
Verification. We verify your identity before acting, usually by confirming information we already hold. We do not collect new identifying information just to verify a request.
Authorized agents. You may use one. We will ask for proof of authority.
Timing. Within 45 days for US state law requests, within one month for GDPR and UK GDPR requests. Complex requests may be extended once, by 45 days or two months respectively, and we will tell you first.
Cost. Free, unless a request is manifestly unfounded, excessive, or repetitive.
No retaliation. We will never deny service, change your price, or reduce quality because you exercised a privacy right.
11.2 If you are in the EEA, the UK, or Switzerland
You have the rights to access, rectify, erase, restrict processing, portability, object to processing based on legitimate interests (and to object to direct marketing absolutely, at any time, without giving a reason), withdraw consent, and not be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions.
You may lodge a complaint with your supervisory authority, found through the European Data Protection Board or, in the UK, the Information Commissioner's Office. We would like the chance to address it first.
Because we do not offer services to, or monitor the behavior of, people in the EEA or UK, we have not appointed a representative under GDPR Article 27. This would change if we began marketing into those regions.
11.3 If you are in California
Under the CCPA as amended by the CPRA, you have the rights to know, access, correct, delete, opt out of sale or sharing, limit the use of sensitive personal information, and non-discrimination.
We do not sell or share personal information as those terms are defined by the CCPA. We do not collect or use sensitive personal information beyond what is necessary to provide our services.
Categories collected in the last 12 months. Identifiers (name, work email, phone, IP address), commercial information (services inquired about or purchased), internet activity (interaction with our sites and campaigns), professional information (company, role, industry), and city-level geolocation inferred from IP address. Sources are you directly, your device automatically, and the sources in Section 4.1. We disclose them for business purposes to the providers in Section 7.
Shine the Light. California Civil Code Section 1798.83 lets California residents ask about information shared with third parties for their direct marketing purposes. We do not share information for that purpose.
11.4 If you are in Colorado
Fresh Ground Solutions, Inc. is a Colorado company, and the Colorado Privacy Act applies to us directly.
Under the CPA you have the rights to confirm whether we process your personal data and access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects.
We honor universal opt-out mechanisms, including Global Privacy Control, as the CPA requires.
Appeals. If we decline a request, appeal by replying to our decision or emailing info@freshground.solutions with "Privacy Appeal" in the subject line. We respond within 45 days. If we deny the appeal, we will give you a written explanation and a way to contact the Colorado Attorney General at coag.gov.
11.5 If you are in Texas
Under the Texas Data Privacy and Security Act you have the rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects.
Appeals. If we decline a request, appeal by replying to our decision or emailing info@freshground.solutions with "Privacy Appeal" in the subject line. We respond within 60 days. If we deny the appeal, you may complain to the Texas Attorney General at texasattorneygeneral.gov.
11.6 If you are in another US state
Comprehensive privacy laws are in effect in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. More take effect in Oklahoma and Alabama in 2027 and Vermont in 2028.
The rights are broadly similar: confirm and access, correct, delete, portability, and opt out of targeted advertising, sale, and profiling. Use the process in Section 11.1, tell us your state, and we will apply your state's law, including the right to appeal a denial where your state provides one.
11.7 Marketing opt-out, everywhere
Every marketing and outreach email has an unsubscribe link. Use it, reply and ask, or email us. We will stop, and we will keep a suppression record so it does not happen again. We will still send transactional messages tied to an active engagement, such as invoices and support responses.
12. Client Data and Our Role as a Processor
When we deliver AI, Advise, or Build work, we handle personal information that belongs to our client and their users.
- The client is the controller. They decide what is collected and why. Their privacy policy governs it, not this one.
- We are the processor, acting on their documented instructions, under a data processing agreement where the law requires one.
- We do not use client data for our own purposes. We do not sell it, mine it for marketing, or use it to train AI models.
AI engagements specifically. Our AI work may involve configuring, integrating, or operating AI systems that process client data. In those engagements:
- The client decides what data enters the system and for what purpose
- We do not use client data to train foundation models, and we configure third-party AI providers to exclude client data from their training wherever that setting exists
- We document which AI providers process client data, and the client approves them
- Specific terms are set in the engagement agreement, which controls over this policy
If you are an end user of a system we built or operate for a client, contact that client to exercise your rights. They are the controller.
13. Children
Our services are built for businesses and are not directed at children. We do not knowingly collect personal information from children under 13, or from anyone under 16 without the consent required by law in their jurisdiction.
If you believe a child has given us personal information, contact us at info@freshground.solutions and we will delete it promptly.
14. Other Websites
Our sites link to sites we do not control, and our services integrate with third-party platforms. This policy does not apply to them. Read the privacy policy of wherever you land.
15. Changes to This Policy
We update this policy when our practices or the law changes, and we revise the "Last updated" date at the top.
If a change materially affects how we use your personal information, we will give clear notice before it takes effect, by email or a prominent notice on our sites, and we will obtain consent where the law requires it.
Prior versions are available on request.
16. Questions and Complaints
Email info@freshground.solutions or write to us at the address in Section 1.
We take privacy complaints seriously and will respond. If you are not satisfied, you can contact your state Attorney General, or your supervisory authority in the EEA or UK, as described in Section 11.