Privacy Policy
Frontier Consulting runs consultfrontier.ai and the AI advisory services delivered from it. This page explains what personal information we collect, why we collect it, how long we keep it, and the rights you have over your data. Plain English where possible. Legal language only where the regulation requires it.
01Who we are
Frontier Consulting is the trading name for the AI advisory practice operated by Adam Grey. We operate this website and deliver the advisory retainer described at /advisor. For questions about this policy or about your data, write to a.grey@consultfrontier.com.
02What we collect
Information you give us directly
- Email address, when you download the playbook or sign up for the retainer.
- Name, firm, and role, when you fill out the discovery-call booking or the onboarding form.
- Portfolio details (named portcos, sectors, current AI stack, board cadence), when you become a retainer client and complete the onboarding intake.
- Payment information, processed by Stripe. We never see or store your full card number.
- Anything you tell us by email, on calls, or via Loom drops, which becomes engagement-related working memory.
Information we collect automatically
- Standard server logs (IP address, browser type, referrer, timestamp) when you visit the site.
- Analytics data (page views, scroll depth, button clicks) for the purpose of improving the site.
- Cookies set by us and our processors, detailed in section 6.
03Why we collect it
Six purposes. We do not collect data for any purpose outside of these:
- To deliver the playbook PDF when you request it.
- To schedule and conduct discovery calls.
- To process and manage retainer subscriptions and invoices.
- To prepare the weekly brief, quarterly deep-dive, and portfolio opportunity flags for each retainer client.
- To respond to your inquiries and provide engagement-related support.
- To meet our legal, tax, and accounting obligations.
04Who processes data on our behalf
We use a small set of sub-processors. Each is bound by a data processing agreement and is responsible for security on their end of the pipe. The current list:
| Processor | Purpose | Data category |
|---|---|---|
| Stripe | Payment processing for the retainer subscription | Email, name, billing address, payment method |
| Calendly | Discovery-call scheduling | Email, name, timezone, call notes |
| Resend | Transactional email delivery (playbook, briefs, flags) | Email, name, firm |
| WordPress / Automattic | Website hosting | Server logs, cookies |
| Google Workspace | Internal email and document storage | Engagement-related correspondence |
If we change the sub-processor list, we update this page and the "Last updated" stamp at the top. For retainer clients, we also include a note in the next weekly brief.
05Confidentiality of engagement data
If you become a retainer client, you and Frontier sign a mutual non-disclosure agreement before the first call. That agreement governs how we treat your portfolio details, deal data, and any internal information shared during the engagement. The terms in that NDA take precedence over this privacy policy where the two overlap.
In plain English: your portfolio details are yours. We use them to build your brief and your flags. We do not share them with other clients, do not aggregate them into a public dataset, and do not train any external AI model on them.
06Cookies
The site uses three categories of cookies:
- Essential cookies that keep the site working (session state, form persistence). These cannot be disabled.
- Analytics cookies that show us aggregate behaviour (page views, scroll depth, click paths). You can disable these in your browser.
- Third-party cookies set by Stripe (for fraud prevention on the checkout) and Calendly (for the embedded scheduler), with their own policies linked below.
Your browser controls all cookies. Most browsers let you reject non-essential cookies for any site, including this one. We honour the Global Privacy Control signal automatically.
07How long we keep it
- Playbook download email: kept until you unsubscribe or 24 months, whichever is sooner. No follow-up sequence applies.
- Discovery-call notes: kept for 18 months for follow-up purposes. Deleted on request at any time.
- Retainer engagement data: kept for 7 years post-engagement to meet tax and professional record-keeping obligations. Deleted at the end of that period.
- Server logs and analytics: kept for 13 months, then aggregated and anonymised.
08Your rights
Under GDPR, the UK Data Protection Act, and CCPA, you have the right to:
- Access the personal information we hold about you.
- Correct any information that is inaccurate or incomplete.
- Delete your information, subject to our legal retention obligations.
- Restrict or object to how we use your information.
- Receive a portable copy of your information in a machine-readable format.
- Withdraw consent at any time where consent was the basis for processing.
To exercise any of these rights, email a.grey@consultfrontier.com. We respond within 30 days. If you are in the EEA or UK and you are not satisfied with our response, you may complain to your national data protection authority.
09California residents
If you are a California resident, you have specific rights under the California Consumer Privacy Act and the California Privacy Rights Act. These mirror the rights in section 8 above, plus:
- The right to know what personal information we have collected, the sources, and the purpose.
- The right to know whether we sell or share personal information. We do neither.
- The right to opt out of sale or sharing. Since we do neither, no opt-out is required.
- The right to non-discrimination for exercising any of these rights.
10Children
This site is built for private-equity operating partners. It is not directed at anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact a.grey@consultfrontier.com and we will delete it.
11Security
We protect personal information with the controls expected of a professional services firm: encrypted storage for engagement data, TLS in transit on every page, two-factor authentication on every internal account, encrypted backups, and least-privilege access for any tooling that touches client data. Payment information is processed by Stripe under PCI-DSS Level 1 compliance and never touches our servers.
No system is impenetrable. If we ever experience a breach affecting your personal information, we will notify you within 72 hours of becoming aware, in line with GDPR requirements.
12Updates to this policy
We update this policy when our practices change or when regulation moves. The "Last updated" stamp at the top of the page tells you when the current version went live. For material changes, retainer clients receive a direct notice and the change is summarised in the next weekly brief.
13Contact
Questions about this policy, requests to exercise your rights, or any concerns about how your data is handled go to the same place: