1. Who we are
Bridgital Group, LLC ("Bridgital", "we", "us") is a Texas limited liability company. We build and support AI-powered operating systems for solo experts and small advisory firms, and we run workshops, advisory retainers, and build engagements.
This policy explains what personal information we collect, why we collect it, who we share it with, and what you can ask us to do about it.
Contact for privacy questions
Email: [email protected]
Mail: Bridgital Group, LLC, 1556 Godwin St, Unit 2, Houston, TX 77023, United States
2. What this policy covers
This policy covers:
- Our websites, including bridgital.io and advisor.bridgital.io
- Our marketing, including email, text messages, webinars, and outreach on LinkedIn
- Our sales process, including calls, proposals, and onboarding
- Our services, including workshops, builds, and advisory retainers
What it does not cover. We build systems on our clients' own accounts. When we work inside a client's email, calendar, CRM, or files, the client decides what happens to the data in those systems and we act on their instructions. In privacy law terms, the client is the controller and we are the processor or service provider. Section 9 explains how we handle that. If you are a customer, employee, or contact of one of our clients, ask that client for their own privacy notice.
3. Information we collect
3.1 Information you give us
| What | When |
|---|---|
| Name, email address, company, role | You submit a form on our site, book a call, or register for a workshop or webinar |
| Mobile phone number | You choose to give it to us and separately agree to receive text messages. See section 6 |
| What you are struggling with, in your own words | Our signup form asks about your current pain and situation |
| Business context you share on calls, in email, or in shared documents | Sales conversations, onboarding, and delivery |
| Billing details | You buy something from us. Card details go directly to our payment processor. We never see or store full card numbers |
| Account credentials and access you grant us | You connect us to your own tools during a build. See section 9 |
3.2 Information we collect automatically
When you visit our site we collect:
- Analytics data through Google Analytics 4: pages viewed, approximate location derived from IP address, device and browser type, referring site, and page performance measurements.
- Attribution data stored in your browser: which campaign, source, or link first brought you to us and which one you arrived on most recently. We store this in your browser's local storage under the keys
bt_attr_first,bt_attr_last,bt_vid, andbt_sid, and we attach it to a form submission so we know which marketing actually works. - Server and security logs through our hosting provider, including IP address and request details, used to keep the site up and to block abuse.
Consent. Analytics storage is switched off by default. We use Google Consent Mode v2, so until you accept the banner, Google receives only cookieless measurement pings with no identifier stored on your device. Your choice is remembered in local storage under bt_consent. You can change it by clearing your browser storage for our site and choosing again.
We do not run advertising pixels or retargeting tags on our site.
3.3 Information we get from other sources
We do business development, and part of that means finding people we think we can help before they have ever heard of us. We may collect business contact information from:
- Public professional profiles, including LinkedIn, and public engagement on posts
- Business data providers and enrichment services, which supply work email addresses, job titles, and company details
- Referrals and introductions from clients and people in our network
- Publicly available company sources such as websites and press
This is business contact information about people in a professional capacity. It is not personal or household data, and we do not build profiles of your private life. We never add a phone number obtained this way to a text messaging list. Text messages go only to people who gave us their number and opted in directly. If we contact you and you would rather we did not, reply and say so, or email [email protected]. We will stop and add you to our suppression list.
3.4 Call recordings and transcripts
We often record and transcribe sales calls and client calls so we can capture action items and avoid making you repeat yourself. Recording is announced at the start of the call by the meeting platform, the transcription assistant, or by us. If you do not want a call recorded, say so and we will turn it off. You can ask us to delete a recording or transcript at any time.
4. Why we use your information
| Purpose | Legal basis under GDPR / UK GDPR |
|---|---|
| Reply to enquiries and run our sales process | Steps taken at your request before entering a contract |
| Deliver workshops, builds, and advisory work, and invoice for them | Performance of a contract |
| Send marketing emails and newsletters you signed up for | Consent, which you can withdraw at any time |
| Send text messages you opted in to receive | Consent, which you can withdraw at any time |
| Business-to-business outreach to people we believe we can help | Our legitimate interest in growing the business, balanced against your interests. You can object at any time |
| Measure which pages and campaigns work | Consent, through the cookie banner |
| Keep the site secure and available, prevent fraud and abuse | Our legitimate interest in protecting our systems |
| Meet tax, accounting, and legal obligations | Legal obligation |
5. What we do not do
- We do not sell your personal information, and we never have.
- We do not share your personal information for cross-context behavioral advertising or targeted advertising.
- We do not use your data, or our clients' data, to train public AI models. Our AI vendors are engaged under terms that exclude our inputs and outputs from training their general models.
- We do not run advertising or retargeting trackers on our site.
6. Text messages and mobile information
This section explains how we handle mobile phone numbers and text messaging.
6.1 We do not share your mobile information
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except for the aggregators, carriers, and messaging service providers who are strictly necessary to deliver the messages you asked for. Those providers may only use the information to transmit the message and for nothing else.
This applies regardless of anything else in this policy. The sharing described in section 7 does not apply to mobile phone numbers or SMS consent data.
We never sell, rent, or transfer mobile numbers or opt-in data to anyone, including lead generators and data brokers.
6.2 How we get your consent
We only text people who gave us their mobile number and separately agreed to receive messages. Consent is collected through an unchecked checkbox that you tick yourself, and it is never a condition of buying anything from us. We do not buy phone lists, we do not text numbers we found through enrichment or scraping, and we do not treat consent given to another business as consent given to us.
6.3 What we send and how often
We send messages related to your enquiry, your booking, your workshop, or your engagement with us, such as confirmations, reminders, scheduling changes, and occasional updates about our services. Message frequency varies.
6.4 Costs, help, and opting out
Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
- Reply STOP to any message to opt out. You will get one confirmation and then nothing further.
- Reply HELP for help, or email [email protected].
Opting out of text messages does not opt you out of email, and unsubscribing from email does not opt you out of text messages. Tell us if you want both stopped and we will do both.
6.5 How long we keep it
We keep your mobile number and the record of your consent for as long as you are opted in, and for up to 4 years after you opt out, to prove that consent existed and to make sure we do not message you again by mistake.
7. Who we share information with
We share personal information with service providers who help us run the business. They may only use it to provide their service to us. This section does not apply to mobile phone numbers or SMS opt-in data, which are covered by section 6.1.
| Provider | What they handle |
|---|---|
| Cloudflare | Website hosting, content delivery, and security |
| Google (Analytics, Fonts, Workspace) | Site analytics, web font delivery, and our email, calendar, and documents. Loading fonts from Google transmits your IP address to Google |
| Anthropic | AI processing of text we submit while doing our work |
| Attio | Customer relationship management, where contact and deal records live |
| Airtable | Internal operations and task tracking |
| Apollo.io | Prospect research and contact enrichment |
| Fireflies.ai | Meeting recording, transcription, and summaries |
| Resend | Sending our marketing and transactional email |
| Slack | Internal and client communication |
| Stripe | Payment processing. Stripe handles card data directly under its own privacy policy |
We also share information:
- With professional advisers such as accountants and lawyers, under confidentiality obligations
- If we are required to by law, court order, or a valid government request
- In connection with a sale, merger, or restructuring of the business, in which case this policy continues to apply until the new owner publishes its own
This list changes as our tools change. The current version is always the one published here.
8. International transfers
We are based in the United States and most of our providers are US-based. If you are in the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to the United States. Where required, these transfers rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or the provider's certification under the EU-US Data Privacy Framework, together with additional safeguards where appropriate. You can ask us for details of the mechanism used for a specific provider.
9. Client systems and client data
When we build on your accounts, the following applies:
- You keep ownership and control. The systems we build run on your own accounts and subscriptions. Your data stays in your tools, not ours.
- Access is scoped and temporary. We ask for the minimum access needed for the work and we ask you to revoke it when an engagement ends.
- Credentials. Wherever possible we use delegated access such as OAuth rather than passwords, and we never store your passwords in plain text or in shared files. We will never ask you to send a password by email or chat.
- Confidentiality. Everything we see inside your systems is confidential. We do not use it for any purpose except delivering your engagement.
- Data processing agreement. If you need a DPA, or you are subject to GDPR, HIPAA, or similar obligations, email [email protected] and we will put one in place before work starts.
- Subcontractors. If we bring in a subcontractor who would touch your systems, we tell you first and they are bound by the same confidentiality terms.
10. How long we keep information
| Data | Retention |
|---|---|
| Marketing contacts and prospects | Until you unsubscribe or object, then we keep a minimal suppression record so we do not contact you again |
| Mobile numbers and SMS consent records | While opted in, then up to 4 years after opt-out |
| Enquiries that do not become clients | Up to 24 months after the last contact |
| Client records, contracts, and deliverables | For the engagement plus 7 years, to meet tax and legal requirements |
| Call recordings and transcripts | Up to 24 months, or sooner on request |
| Website analytics | Up to 14 months in Google Analytics |
| Invoices and financial records | 7 years, as required by US tax law |
11. Security
We protect information with access controls, multi-factor authentication on business accounts, encryption in transit, encrypted devices, a password manager for credentials, and least-privilege access to client systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information and the law requires it, we will notify you and the relevant regulator without undue delay.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Delete your information
- Port your information to another provider in a machine-readable format
- Object to processing based on legitimate interests, including direct marketing
- Restrict processing in certain circumstances
- Withdraw consent at any time, without affecting processing already carried out
- Opt out of the sale or sharing of personal information, or of targeted advertising and profiling. We do none of these, so there is nothing to opt out of
- Appeal a decision we make about a rights request. If we decline your request, you can appeal by replying to our response, and we will explain our reasoning
We honor these requests from anyone who asks, regardless of whether a particular law applies to us.
How to exercise them. Email [email protected]. We will respond within 45 days, and within 30 days if GDPR applies. We may need to verify your identity first, usually by confirming you control the email address on the record.
Complaints. If you are in the EEA or UK you can complain to your local data protection authority. If you are in Texas you can contact the Office of the Texas Attorney General. We would rather you told us first so we can fix it.
Marketing opt-out. Every marketing email has an unsubscribe link at the bottom. It works immediately and you never need to explain why. For text messages, reply STOP.
13. Children
Our services are for businesses. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, email [email protected] and we will delete it.
14. Automated decision-making
We use AI tools to draft, summarize, research, and organize. A human reviews the output before it affects you. We do not make decisions that produce legal or similarly significant effects about you through automated processing alone.
15. Links to other sites
Our site links to other websites, and our webinars and workshops may use third-party platforms. We are not responsible for their privacy practices. Read their policies before giving them information.
16. Changes to this policy
We will update this policy when our practices or our tools change. The date at the top always shows the last update. If a change materially affects your rights, we will tell you by email or with a notice on our site before it takes effect.
17. Contact
Bridgital Group, LLC
Email: [email protected]
Mail: 1556 Godwin St, Unit 2, Houston, TX 77023, United States
Web: bridgital.io