Privacy Policy
Your privacy is important to us. This policy explains how we handle your personal data with transparency and care.
Last updated: July 20, 2026
01Introduction
gr0.ai, operated by Sean Maraj, Inc. ("Company", "we", "us", or "our"), is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website gr0.ai (the "Site") and use our services.
By accessing or using our Site, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our services.
Draft pending final legal review. Our registered postal address and our Data Protection Officer / EU-UK representative contact (or confirmation that none is required) are being finalized and will be added here upon counsel sign-off.
02Our Two Roles: Controller and Processor
gr0.ai is a multi-tenant software-as-a-service platform: businesses (our "customers" or "tenants") use it to run their CRM and their marketing, sales, and customer-success operations with AI agents. That means we handle personal data in two distinct legal roles, and your rights run to different parties depending on which role applies:
- gr0.ai as controller. For visitors to this website, prospects we contact, people who create or administer a gr0.ai account, and billing contacts, we decide how and why the data is processed. This Privacy Policy is addressed to you directly.
- gr0.ai as processor. For personal data our customers store or process inside the platform — their CRM contacts, message recipients, imported prospect lists, and similar records — the customer is the controller and we process that data only on their documented instructions, under a Data Processing Addendum consistent with GDPR Article 28 (see our DPA).
If your data lives in a gr0.ai customer's CRM and you want to exercise your privacy rights over it, the request belongs with that business (the controller). If you send it to us instead, we will forward it to the relevant customer without undue delay and assist them in responding, as GDPR Article 28 requires.
03Information We Collect
We collect information you provide directly to us, including:
- Name, email address, phone number, and job title when you contact us or book a call
- Company name, size, and industry for service matching purposes
- Payment information processed securely by our payment processor (Stripe)
- Communications you send us via email or contact forms
We also collect information automatically when you use our Site:
- Log data including IP address, browser type, pages visited, and time spent
- Device information such as hardware model and operating system
- Cookies and similar tracking technologies (see our Cookie Policy)
- Usage data about how you interact with our features
04Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:
- Contract performance ; to provide the services you have requested
- Legitimate interests ; for analytics, fraud prevention, and service improvement
- Consent ; for marketing communications (you may withdraw at any time)
- Legal obligation ; where required by applicable law
05Personal Data We Obtain From Third-Party Sources (GDPR Article 14)
In addition to information you give us directly, we may obtain a limited set of business-to-business (B2B) contact data about professionals at companies that fit our services — such as a work email, business phone number, job title, employer, and public professional profile. Because this data is not collected from you directly, we provide the following notice under Article 14 of the GDPR.
Categories of data. Business-contact and firmographic details (name, work email, business phone, role, company, and publicly available professional information).
Source categories. We obtain this data from:
- Business-data and sales-intelligence providers and list vendors (data brokers)
- Publicly available sources (company websites, public professional networks, public registries)
- Partners and referrals, where permitted by law
Legal basis. We process this indirectly-collected B2B prospect data on the basis of our legitimate interests (GDPR Article 6(1)(f)) in B2B outreach, marketing, and business development, balanced against your rights and freedoms. We do not use it for purposes incompatible with that basis.
Your right to object. You have the right to object at any time to processing based on our legitimate interests, including profiling, and to opt out of direct marketing — after which we stop and suppress your details. Your access, rectification, erasure, restriction, and portability rights (below) also apply. Contact [email protected].
Provenance and retention. When sourced prospect data enters our platform we record its provenance — the source, the lawful basis, and the time — so every record is traceable to the basis it was processed under. Sourced prospect data that shows no engagement is retained for 180 days by default, after which it is due for review and erasure or suppression.
06How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve our AI marketing services
- Process transactions and send related information including purchase confirmations and invoices
- Send administrative information such as policy changes and service updates
- Respond to your comments, questions, and requests
- Send marketing and promotional communications (with your consent)
- Monitor and analyze trends, usage, and activities in connection with our services
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
- Comply with legal obligations and resolve disputes
07Information Sharing and Disclosure
We do not sell your personal information. We may share your information with:
- Service providers (subprocessors) — third parties that process data on our behalf: hosting (Hetzner, Germany/EU), CDN & security (Cloudflare), our LLM gateway (OpenRouter) and the model providers it routes requests to, email delivery (Resend), messaging & voice (Twilio), and payment processing (Stripe). A current list is on our Subprocessors page.
- Expert network members ; solely to facilitate matching with your project requirements, with your consent
- Business transfers ; in connection with any merger, sale of assets, or acquisition
- Legal requirements ; when required by law or to protect the rights, property, or safety of our company, customers, or others
We never sell your personal information, and we do not share it for cross-context behavioral advertising.Separately, mobile opt-in and SMS consent information is never shared with third parties or affiliates for marketing or promotional purposes and is excluded from all data-sharing described here (see "Mobile Messaging & SMS Consent" below).
08Mobile Messaging & SMS Consent (CTIA)
Mobile opt-in information — including phone numbers collected for SMS/MMS and your consent to receive text messages — is not shared with, or sold to, any third parties or affiliates for their marketing or promotional purposes. This mobile opt-in and SMS consent data is excluded from any "sale" or "sharing" of personal information and from every category of data-sharing described in this Privacy Policy. We disclose it only to the service providers strictly necessary to deliver the messages you requested (for example, our messaging provider Twilio).
Full program details — message types, message frequency, message and data rates, how to opt out (Reply STOP), and how to get help (Reply HELP) — are in our Messaging Terms.
09California Privacy Rights (CCPA/CPRA) — Do Not Sell or Share
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you the right to know, delete, and correct your personal information; the right to opt out of the "sale" or "sharing" of personal information (including sharing for cross-context behavioral advertising); the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. To exercise a do-not-sell / do-not-share request, email [email protected] or send a Global Privacy Control (GPC) signal, which we honor as a valid opt-out. Mobile opt-in and SMS consent data is never sold or shared under any circumstances (see the CTIA section above).
You may use an authorized agent to submit requests. We will not discriminate against you for exercising any CCPA/CPRA right, and we respond within 45 days (extendable once with notice).
Notice at collection.In the preceding 12 months we have collected the following categories of personal information, for the purposes described in "How We Use Your Information" above and retained as described in "Data Retention" below:
- Identifiers — name, email address, phone number, IP address
- Commercial information — services purchased or considered, billing records
- Internet or other electronic network activity — pages visited, interactions with the Site (see our Cookie Policy)
- Professional or employment-related information — job title, employer, company size and industry
- Inferences — service-fit and preference inferences drawn from the above
We do not collect government identifiers, biometric information, or precise geolocation, and we do not use or disclose sensitive personal information for purposes requiring a right to limit under the CPRA. Sources and third-party disclosures for each category are described in "Information We Collect", "Personal Data We Obtain From Third-Party Sources", and "Information Sharing and Disclosure" above.
10Data Retention
We retain personal information for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law. Account data is retained for the duration of your relationship with us plus up to 7 years for legal and tax purposes. Broker-sourced B2B prospect data with no engagement is due for review and erasure or suppression after 180 days by default. You may request deletion at any time subject to legal retention requirements.
11International Data Transfers
We are headquartered in the United States. If you are located outside the US, your information may be transferred to and processed in the US. Where we transfer data from the EEA/UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure an adequate level of data protection.
12Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access ; request a copy of the personal data we hold about you
- Rectification ; request correction of inaccurate or incomplete data
- Erasure ; request deletion of your personal data ("right to be forgotten")
- Restriction ; request we restrict processing of your data
- Portability ; receive your data in a structured, machine-readable format
- Objection ; object to processing based on legitimate interests or direct marketing
- Withdraw consent ; where processing is based on consent, withdraw it at any time
California residents may also exercise rights under the California Consumer Privacy Act (CCPA/CPRA). To exercise any right, contact us at [email protected]. We will respond within 30 days.
13Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest, access controls, and regular security audits. However, no method of transmission over the Internet is 100% secure. We encourage you to use strong passwords and notify us immediately of any suspected unauthorized access.
14Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us and we will take steps to delete such information.
152026 Regulatory Updates
In addition to GDPR + CCPA, we honour the following 2026-current rights and signals:
- Global Privacy Control (GPC) - when your browser sends the Sec-GPC: 1 header, we treat it as a valid opt-out of "sale" or "share" under CPRA and equivalent state laws (Colorado, Connecticut, Virginia, Texas, Oregon).
- CPRA - sensitive personal information - biometric identifiers, precise geolocation, and inferences about protected characteristics are treated as sensitive PI with limited-use defaults. We process these only for the disclosed business purpose.
- AI training opt-out (CCPA delete amendments, 2026) - California residents can request that their personal data not be used to train AI models. We honour these requests within 30 days via [email protected].
- EU Data Act (effective 2025) - for EU users with connected products in our ecosystem, the right to access machine-generated data and port it to a service of your choice.
- State-level expansions - Maryland Online Data Privacy Act (effective Oct 2025), Minnesota Consumer Data Privacy Act (effective Jul 2025), New Jersey Data Privacy Act (effective Jan 2025) and others. Where state law is stricter than the baselines above, we apply state law to residents of that state.
For data subject requests under any of the above: [email protected]. We respond within 30 days (45 in complex cases, with notice).
16Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page with an updated "Last updated" date. We encourage you to review this policy periodically. Continued use of our services after changes constitutes acceptance of the updated policy.
Questions about this policy?
Contact us at [email protected]. gr0.ai is operated by Sean Maraj, Inc.