FRESH GROUND SOLUTIONS

Privacy Policy

Privacy & Terms

Effective date: September 15, 2026

Last updated: September 15, 2026


1. Who We Are

Fresh Ground Solutions, Inc. ("Fresh Ground," "we," "us," "our") is a technology advisory and delivery company. We offer three services: AI (consulting, implementation, and training), Advise (fractional CTO leadership), and Build (software delivery and cloud).

Fresh Ground Solutions, Inc. is a Webapper company. Webapper Services, LLC operates webapper.com under its own privacy policy at webapper.com/privacy-policy.

This policy covers freshground.solutions and freshground.ai, our marketing and outreach activity, and our client engagements.

How to reach us

Fresh Ground Solutions, Inc.

117 E Mountain Ave., Suite 222

Fort Collins, CO 80525

United States

Email: info@freshground.solutions

Our role. Fresh Ground Solutions, Inc. is the data controller (or "business," under US state law) for the information described in this policy. When we process data on behalf of a client under a services agreement, that client is the controller and we act as their processor. Section 12 covers that relationship.


2. The Short Version

We are a business-to-business company. Almost all the personal information we handle is professional contact information: your name, your work email, your company, and your role.

Here is what matters most:

  1. We do outbound. We research companies that look like a fit and reach out. Section 4 explains exactly where that data comes from and what your rights are. If you want out, one email ends it permanently.
  2. We do not sell your data. Not to anyone, for any price.
  3. We use analytics and advertising cookies. You can turn them off, and we honor Global Privacy Control.
  4. Client data is not ours. We do not mine it, sell it, or train AI models on it.

The rest of this policy is the detail behind those four points.


3. Information We Collect

3.1 Information you give us directly

WhatWhere it comes from
Name, work email, company, phone, and whatever you writeContact forms on freshground.solutions and freshground.ai
Name, email, meeting time, and any notesOur booking page, which runs on Google Calendar
Email address and preferencesNewsletter and content signups
Whatever you type into the chat, and the conversation transcriptOur on-site AI concierge chat, powered by Fin by Intercom
Contact details, billing information, project materials, and credentials needed to do the workClient engagements
Assessment responses and the business context you shareAI Readiness Assessment

3.2 Information we collect automatically

When you visit our sites we and our providers collect:

  • Log data: IP address, browser type and version, date and time stamps, referring and exit pages
  • Cookie and similar identifiers: see Section 8
  • Analytics and marketing attribution: pages viewed, session duration, traffic source, campaign parameters, approximate city-level location derived from IP address, and device characteristics

IP addresses, cookie identifiers, and similar online identifiers are personal information under the GDPR, the UK GDPR, the CCPA, and the US state laws in Section 11. We treat them that way.

3.3 Information from other sources

This is the part most privacy policies leave out. Ours does not. See Section 4.

3.4 What we do not collect

We do not knowingly collect government identification numbers, payment card numbers (we invoice and are paid by wire or bank transfer, so we never handle card data), precise geolocation, biometric data, or health information. We do not seek information about your race, religion, political opinions, or sexual orientation.

We do not sell your sensitive personal data. We do not sell your biometric data. We do not sell personal data at all, as "sale" is defined under US state privacy laws.


4. Business Contact Data and Outbound Outreach

We identify businesses that may benefit from our services and contact the people who make those decisions. This section explains that process honestly, because you deserve to know how we got your email address.

4.1 Where the data comes from

We source and verify business contact information using:

SourceWhat it provides
HunterProfessional email addresses associated with a company domain
FindymailProfessional email addresses, found and verified
LinkedIn Sales NavigatorProfessional profile and company information used to identify decision makers
Google PlacesPublicly listed business names, locations, categories, and contact details
DataForSEOSearch and web data used to identify companies and their online presence
AhrefsWebsite and search visibility data used for company research
Public sourcesCompany websites, professional networking profiles, public directories, press coverage, and public filings
ReferralsIntroductions from partners, clients, and contacts

We look for business contact information in a professional capacity: your work email, your role, your company, and public information about that company. We do not seek or want your personal email address, home address, or anything about your life outside work.

4.2 What we do with it

We store it in our CRM and use outbound email platforms to send and manage campaigns. Section 7 lists every provider we use, and it is the authoritative list. We use the data to send you a relevant, specific message about whether our services fit your business. We do not resell it, rent it, trade it, or contribute it to any shared database.

4.3 Our legal basis

In the United States, our outreach complies with the CAN-SPAM Act. Every message identifies us truthfully, uses accurate subject lines and headers, discloses that it is a commercial message, includes a valid physical postal address, and offers a working opt-out that we honor within 10 business days. In practice we honor it immediately.

In the EEA and UK, we rely on legitimate interests under GDPR Article 6(1)(f) to process business contact data for B2B outreach. We have assessed that interest against your rights and limited our processing accordingly: professional contact data only, relevant and targeted messages rather than bulk sends, and immediate removal on request.

Where you were not the source, GDPR Article 14 applies. When we obtain your data from somewhere other than you, we must tell you. Our first message to you links to this policy, which identifies us, explains where we got your information, why we are contacting you, how long we will keep it, and how to make us stop.

We prospect in North America. Our outbound outreach targets businesses in the United States and Canada. We do not market our services to individuals or businesses in the European Economic Area or the United Kingdom, we do not advertise in EEA or UK languages or currencies, and we do not use geolocation to target people there.

If you are in the EEA or UK and you contact us, or we reach you in error, the GDPR rights in Section 11 apply to you in full and we honor them. Tell us to stop and we will, permanently.

4.4 Your rights over this data, stated plainly

  • You can tell us to stop, and we will. Reply to any message, click the unsubscribe link, or email info@freshground.solutions. Under the GDPR the right to object to direct marketing is absolute. We do not require a reason, and we do not ask for one.
  • You can ask what we hold about you and we will tell you, including where we got it.
  • You can ask us to delete it and we will, except for a minimal suppression record. That record exists only to guarantee we never contact you again, which is the outcome you asked for.
  • You can ask us to correct it if it is wrong.

We keep prospect data that never becomes a conversation for 24 months, then delete it.


5. Why We Collect It

PurposeInformation usedGDPR / UK GDPR legal basis
Respond to your inquiry or bookingContact and booking dataLegitimate interests, and steps prior to a contract at your request
Deliver AI, Advise, and Build servicesClient engagement data, billing dataPerformance of a contract
Business development outreachBusiness contact data (Section 4)Legitimate interests, or consent where local law requires it
Score and prioritize leads against our ideal customer profileContact details, company information, engagement historyLegitimate interests
Answer questions through our on-site AI chatChat transcripts, anything you typeLegitimate interests, and steps prior to a contract at your request
Send newsletters and contentEmail address, preferencesConsent, or legitimate interests for existing clients where permitted
Run the AI Readiness Assessment and give you resultsAssessment responses, business contextLegitimate interests, and steps prior to a contract at your request
Operate, secure, and troubleshoot our sitesLog dataLegitimate interests
Understand site usage and improve itAnalytics dataConsent where required, otherwise legitimate interests
Run and measure advertising campaignsAdvertising identifiers, conversion and attribution dataConsent
Bill you and keep financial recordsBilling and transaction dataPerformance of a contract, and legal obligation
Meet legal, tax, and regulatory obligationsAs requiredLegal obligation

Where we rely on legitimate interests, you can object at any time and we will stop unless we have compelling grounds to continue. For direct marketing, there are no compelling grounds that override your objection, so we simply stop.

Where we rely on consent, you can withdraw it at any time.

AI in our own operations

We sell AI services, so being specific about how we use AI on ourselves is the least we can do.

Our on-site chat is AI-powered. Fin by Intercom answers visitor questions in real time. Conversations are processed to generate responses and stored as transcripts. A person can join the conversation at any point, and you can ask to speak to one.

We use AI to score and prioritize leads. We rank inbound and prospective contacts against our ideal customer profile so we know who to talk to first. This is prioritization, not a decision about you. It does not set your price, deny you a service, or produce any legal or similarly significant effect, and a person makes every actual decision about who we contact and what we offer. You can object to it at any time under Section 11.

We do not use your data to train foundation models. We configure our AI providers to exclude our data from their training wherever that setting exists.


6. How Long We Keep It

CategoryRetention period
Prospect and business contact data that never becomes a conversation24 months
Inquiry and booking data that does not become a client relationship24 months from last contact
Client engagement recordsDuration of the engagement, plus 7 years for tax, accounting, and legal claim purposes
Billing and financial records7 years, to meet US tax recordkeeping requirements
Marketing subscriptionsUntil you unsubscribe, plus a permanent suppression record
Opt-out and suppression recordsKept indefinitely, so we never contact you again
Log data90 days
Analytics data26 months

7. Who We Share It With

We do not sell your personal information, and we do not share it with third parties for their own marketing.

We share it with service providers who help us operate. Each is bound by contract to use it only for the services they provide to us.

ProviderWhat they doWhat they receive
WebflowHosts freshground.solutions and freshground.aiSite traffic data, form submissions
Amazon Web ServicesCloud infrastructure, and email delivery through Amazon SESData in our systems, outbound email content and addresses
Google WorkspaceBusiness email, calendar, and our booking pageEmail content, meeting details
CopperCRM for client and prospect relationshipsContact and communication data
Instantly, SmartLeadOutbound campaign sending and managementBusiness contact data, engagement events
Hunter, FindymailEmail discovery and verificationCompany domains and contact lookups
LinkedIn Sales NavigatorProspect and company researchSearch and profile queries. A source of information to us.
Google Places / DataForSEO / AhrefsCompany and market researchQuery data. These are sources of information to us.
Google Ads, Meta Ads, LinkedIn AdsAdvertising and conversion measurementAdvertising identifiers, conversion events
Windsor.aiMarketing attribution across channelsCampaign and conversion data
Google Analytics 4, Google Search ConsoleWebsite analytics and search performanceUsage and device data, IP address
Intercom (Fin)On-site AI concierge chatChat transcripts, contact details you provide in the conversation
Our bankReceiving payment by wire or bank transferPayment instructions and remittance details. No card data is collected.
QuickBooks (Intuit)Invoicing and financial recordsBilling and transaction data

Each provider above is contractually limited to using the information only for the services it provides to us.

We also disclose personal information when the law requires it, when we need to protect rights or safety, in connection with a merger or sale of assets (you will be notified), or when you ask us to.

Within the Webapper group. We share limited information with Webapper Services, LLC where it is necessary to run shared operations such as accounting and administration, and where a client engagement involves both companies. Webapper is bound by the same commitments described here.


8. Cookies, Analytics, and Advertising

TypePurposeCan you turn it off?
Strictly necessarySite delivery, security, remembering your privacy choicesNo. The sites will not work correctly without these.
AnalyticsUnderstanding which pages work and how the sites performYes
Advertising and attributionMeasuring campaigns and showing our ads on other sites, including Google Ads, Meta Ads, and Windsor.ai attributionYes

Your choices

When you first visit either site, our consent banner lets you accept or reject analytics and advertising cookies. Strictly necessary cookies are always on, because the sites cannot function without them. You can change your choice at any time through the banner's settings link.

You can also block cookies in your browser settings, opt out of Google Analytics with Google's browser add-on, adjust ad personalization at Google Ads Settings and Meta ad preferences, and use the Digital Advertising Alliance's opt-out tools: WebChoices for browsers, AppChoices for mobile apps, or the unified control page. The Network Advertising Initiative retired its own opt-out tool on September 15, 2025, so we no longer link to it.

Global Privacy Control

We honor the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat it as a valid opt-out of targeted advertising and any sharing of your personal data. Colorado, Texas, California, and several other states require recognition of signals like this.

We do not respond to "Do Not Track," because no common industry standard defines what a site should do with it. GPC is the signal we honor.


9. Where Your Information Goes

We are based in the United States and our infrastructure is primarily in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal information will be transferred to and processed in the United States.

For those transfers we rely on the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK GDPR applies, along with supplementary measures including encryption in transit and at rest and access controls.

Some of our providers also participate in the EU-U.S. Data Privacy Framework. That framework remains formally in force but is subject to ongoing legal challenge, so we do not rely on it as our only transfer mechanism.

Email us for a copy of the safeguards we use.


10. How We Protect It

We maintain safeguards appropriate to the sensitivity of what we hold:

  • Encryption in transit (TLS) and at rest
  • Role-based access, limited to people who need it
  • Multi-factor authentication on administrative accounts
  • Authenticated email using SPF, DKIM, and DMARC with a reject policy, which protects you from anyone spoofing our domains
  • Monitoring and audit logging of meaningful operations
  • Vendor security review before onboarding a provider

No system is perfectly secure, and we cannot guarantee absolute security.

If a breach occurs, we will notify you and the relevant regulators as required by law. Under the GDPR that means notifying the supervisory authority within 72 hours of becoming aware where the breach poses a risk to individuals. US state breach notification laws set their own deadlines, and we will meet whichever applies.


11. Your Rights

Your rights depend on where you live. We extend the core rights below to everyone who asks, regardless of location.

11.1 How to exercise them

Email info@freshground.solutions with "Privacy Request" in the subject line, or write to our mailing address in Section 1.

Verification. We verify your identity before acting, usually by confirming information we already hold. We do not collect new identifying information just to verify a request.

Authorized agents. You may use one. We will ask for proof of authority.

Timing. Within 45 days for US state law requests, within one month for GDPR and UK GDPR requests. Complex requests may be extended once, by 45 days or two months respectively, and we will tell you first.

Cost. Free, unless a request is manifestly unfounded, excessive, or repetitive.

No retaliation. We will never deny service, change your price, or reduce quality because you exercised a privacy right.

11.2 If you are in the EEA, the UK, or Switzerland

You have the rights to access, rectify, erase, restrict processing, portability, object to processing based on legitimate interests (and to object to direct marketing absolutely, at any time, without giving a reason), withdraw consent, and not be subject to solely automated decisions with legal or similarly significant effects. We do not make such decisions.

You may lodge a complaint with your supervisory authority, found through the European Data Protection Board or, in the UK, the Information Commissioner's Office. We would like the chance to address it first.

Because we do not offer services to, or monitor the behavior of, people in the EEA or UK, we have not appointed a representative under GDPR Article 27. This would change if we began marketing into those regions.

11.3 If you are in California

Under the CCPA as amended by the CPRA, you have the rights to know, access, correct, delete, opt out of sale or sharing, limit the use of sensitive personal information, and non-discrimination.

We do not sell or share personal information as those terms are defined by the CCPA. We do not collect or use sensitive personal information beyond what is necessary to provide our services.

Categories collected in the last 12 months. Identifiers (name, work email, phone, IP address), commercial information (services inquired about or purchased), internet activity (interaction with our sites and campaigns), professional information (company, role, industry), and city-level geolocation inferred from IP address. Sources are you directly, your device automatically, and the sources in Section 4.1. We disclose them for business purposes to the providers in Section 7.

Shine the Light. California Civil Code Section 1798.83 lets California residents ask about information shared with third parties for their direct marketing purposes. We do not share information for that purpose.

11.4 If you are in Colorado

Fresh Ground Solutions, Inc. is a Colorado company, and the Colorado Privacy Act applies to us directly.

Under the CPA you have the rights to confirm whether we process your personal data and access it, correct inaccuracies, delete it, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects.

We honor universal opt-out mechanisms, including Global Privacy Control, as the CPA requires.

Appeals. If we decline a request, appeal by replying to our decision or emailing info@freshground.solutions with "Privacy Appeal" in the subject line. We respond within 45 days. If we deny the appeal, we will give you a written explanation and a way to contact the Colorado Attorney General at coag.gov.

11.5 If you are in Texas

Under the Texas Data Privacy and Security Act you have the rights to confirm and access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale, and profiling with legal or similarly significant effects.

Appeals. If we decline a request, appeal by replying to our decision or emailing info@freshground.solutions with "Privacy Appeal" in the subject line. We respond within 60 days. If we deny the appeal, you may complain to the Texas Attorney General at texasattorneygeneral.gov.

11.6 If you are in another US state

Comprehensive privacy laws are in effect in California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. More take effect in Oklahoma and Alabama in 2027 and Vermont in 2028.

The rights are broadly similar: confirm and access, correct, delete, portability, and opt out of targeted advertising, sale, and profiling. Use the process in Section 11.1, tell us your state, and we will apply your state's law, including the right to appeal a denial where your state provides one.

11.7 Marketing opt-out, everywhere

Every marketing and outreach email has an unsubscribe link. Use it, reply and ask, or email us. We will stop, and we will keep a suppression record so it does not happen again. We will still send transactional messages tied to an active engagement, such as invoices and support responses.


12. Client Data and Our Role as a Processor

When we deliver AI, Advise, or Build work, we handle personal information that belongs to our client and their users.

  • The client is the controller. They decide what is collected and why. Their privacy policy governs it, not this one.
  • We are the processor, acting on their documented instructions, under a data processing agreement where the law requires one.
  • We do not use client data for our own purposes. We do not sell it, mine it for marketing, or use it to train AI models.

AI engagements specifically. Our AI work may involve configuring, integrating, or operating AI systems that process client data. In those engagements:

  • The client decides what data enters the system and for what purpose
  • We do not use client data to train foundation models, and we configure third-party AI providers to exclude client data from their training wherever that setting exists
  • We document which AI providers process client data, and the client approves them
  • Specific terms are set in the engagement agreement, which controls over this policy

If you are an end user of a system we built or operate for a client, contact that client to exercise your rights. They are the controller.


13. Children

Our services are built for businesses and are not directed at children. We do not knowingly collect personal information from children under 13, or from anyone under 16 without the consent required by law in their jurisdiction.

If you believe a child has given us personal information, contact us at info@freshground.solutions and we will delete it promptly.


14. Other Websites

Our sites link to sites we do not control, and our services integrate with third-party platforms. This policy does not apply to them. Read the privacy policy of wherever you land.


15. Changes to This Policy

We update this policy when our practices or the law changes, and we revise the "Last updated" date at the top.

If a change materially affects how we use your personal information, we will give clear notice before it takes effect, by email or a prominent notice on our sites, and we will obtain consent where the law requires it.

Prior versions are available on request.


16. Questions and Complaints

Email info@freshground.solutions or write to us at the address in Section 1.

We take privacy complaints seriously and will respond. If you are not satisfied, you can contact your state Attorney General, or your supervisory authority in the EEA or UK, as described in Section 11.