Who We Are
Colossal AI Consulting ("Colossal," "we," "us," or "our") is an AI consulting practice based in Greenwood, Indiana, United States. We help small businesses get named and cited by AI answer engines, and we build practical AI and automation into their operations.
For the purposes of data protection law, Colossal AI Consulting acts as a controller of the personal information described in this policy that we collect through our website and marketing activities, and as a processor of client data we handle while delivering consulting services under a written agreement.
Information We Collect
We collect only what we need to run our business and deliver our services. Categories include:
Information you give us
- Contact details such as your name, business email address, phone number, company name, website, and role, submitted through forms, assessments, or email.
- Assessment and questionnaire responses, including answers about your business, tooling, team size, and marketing challenges.
- Scheduling information when you book a call, including the times you select and any notes you add.
- Correspondence, including emails, messages, and call notes you share with us.
- Billing information for clients, such as billing contact and address. Payment card details are handled by our payment processor and are never stored on our systems.
Information collected automatically
- Device and usage data such as IP address, browser type, operating system, referring URL, pages viewed, and time spent on pages.
- Cookie and tag data collected through Google Tag Manager and connected analytics or advertising tags. See Section 05.
Information from third parties
- Public web and business data about companies, including information we retrieve when running an AI visibility scan on a business or its website.
- Advertising and referral data from platforms such as Google, Meta, and LinkedIn when you reach us through an ad or campaign link.
We do not intentionally collect sensitive personal information such as government identification numbers, health records, financial account numbers, biometric data, or precise geolocation. Please do not submit that information through our website forms.
How We Use Information
| Purpose | What that means in practice |
|---|---|
| Deliver our services | Run visibility scans, score assessments, prepare findings, and communicate about active work. |
| Respond to inquiries | Answer questions, schedule calls, and send proposals or scopes of work. |
| Improve the site and offerings | Understand which pages, guides, and tools are useful, fix problems, and refine our content. |
| Marketing communications | Send relevant business updates and resources, subject to your consent where required and always with an unsubscribe option. |
| Advertising measurement | Measure whether campaigns reach the right audiences and produce qualified conversations. |
| Billing and administration | Issue invoices, keep records, and manage our business operations. |
| Legal and security | Comply with law, enforce agreements, prevent fraud and abuse, and protect our systems. |
We do not sell personal information, and we do not share it for cross-context behavioral advertising in the sense defined by California law.
Legal Bases for Processing
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract — to deliver services you or your company have engaged us for.
- Legitimate interests — to run and improve our business, secure our systems, and conduct business-to-business outreach in a proportionate way.
- Consent — for non-essential cookies and for marketing email where consent is required. You may withdraw consent at any time.
- Legal obligation — to meet tax, accounting, and other statutory requirements.
Cookies & Analytics
Our site uses cookies and similar technologies, deployed through Google Tag Manager. These fall into three groups:
- Strictly necessary — required for the site to load and function. These cannot be switched off.
- Analytics — help us understand aggregate traffic patterns and which content performs well.
- Advertising — allow us to measure campaign performance and, where applicable, show relevant ads on third-party platforms.
You can control cookies through your browser settings, including blocking or deleting them. Blocking some cookies may affect how parts of the site work. You can opt out of Google Analytics across all sites using the Google Analytics Opt-out Browser Add-on.
We honor Global Privacy Control (GPC) signals where they are legally recognized.
Sharing & Disclosure
We share personal information only in the following circumstances:
- Service providers who process data on our behalf under contract, including website and form hosting, email delivery, scheduling, analytics, advertising measurement, cloud storage, AI model providers, accounting, and payment processing.
- Professional advisers such as accountants and attorneys, where necessary and under confidentiality obligations.
- Business transfers in connection with a merger, acquisition, financing, or sale of assets, subject to the protections in this policy.
- Legal requirements when we are required to disclose information by law, subpoena, or valid governmental request, or where disclosure is necessary to protect rights, safety, or property.
We require our service providers to protect personal information and to use it only for the purposes we specify.
Client & Project Data
During an engagement, clients may give us access to systems and records that contain personal information about their own customers, patients, or employees. When that happens:
- We act on the client's documented instructions and process that data only to deliver the agreed services.
- Access is limited to what the engagement requires, and is removed at the end of the engagement.
- Where a client requires a Data Processing Agreement, a Business Associate Agreement, or similar terms, those terms govern and take precedence over this policy for the data they cover.
- We return or delete client data at the client's request, subject to any legal retention requirement.
Use of AI Tools
AI is core to what we measure and what we build. We query AI answer engines as part of our visibility scans, and we use third-party AI services in our own operations and in the systems we deliver. Our standing practices:
- We use enterprise or business tiers that contractually exclude customer content from being used to train the provider's models, wherever such a tier is available.
- We minimize what is sent to any AI service, and we remove or mask identifiers where the task does not require them.
- Visibility scans send business-level queries (company name, category, location) to answer engines. They are not used to send personal information about individuals.
- Automated outputs that could affect an individual are reviewed by a person before they are acted on. We do not make decisions producing legal or similarly significant effects on individuals through automated processing alone.
- Client-specific configurations, including which providers may be used, are agreed in the engagement contract.
Data Retention
| Data | Typical retention |
|---|---|
| Website analytics and cookie data | Up to 14 months |
| Inquiry and assessment submissions | Up to 24 months from last contact |
| Marketing contacts | Until you unsubscribe or ask to be removed |
| Active client records and deliverables | Duration of the engagement plus 3 years |
| Invoices and financial records | 7 years, as required for tax and accounting |
| Client system data accessed during a project | Removed at engagement close, or earlier on request |
When information is no longer needed, we delete it or irreversibly anonymize it.
Security
We maintain administrative, technical, and physical safeguards appropriate to the size of our practice and the sensitivity of the data we handle. These include encryption in transit, access controls and multi-factor authentication on business accounts, least-privilege access to client systems, credential management through a password manager, and periodic review of the vendors we rely on.
No method of transmission or storage is completely secure. If we become aware of a breach affecting your personal information, we will notify you and any required regulator without undue delay and in accordance with applicable law.
Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct information that is inaccurate or incomplete.
- Delete personal information, subject to legal retention obligations.
- Port your data to another provider in a portable format.
- Object to or restrict certain processing, including direct marketing.
- Withdraw consent at any time, without affecting processing already carried out.
- Opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined under California law.
- Be free from discrimination for exercising any of these rights.
To make a request, email nick@colossalaiconsulting.com with the subject line "Privacy Request." We will verify your identity, respond within 30 days where required by law, and tell you if we need more time. You may use an authorized agent where the law permits. If you are unsatisfied with our response, you may lodge a complaint with your local supervisory authority.
To stop marketing email, use the unsubscribe link in any message or email us directly.
Children's Privacy
Our website and services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
International Visitors
We operate from the United States, and the service providers we use may process data in the United States and other countries. If you access our site from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. Where required, we rely on Standard Contractual Clauses or another approved transfer mechanism to protect that data.
Changes to This Policy
We may update this policy to reflect changes in our practices, technology, or legal obligations. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material, we will provide additional notice by email or a prominent notice on the site before they take effect. Continued use of the site after the effective date means you accept the revised policy.
Contact Us
Questions, requests, or concerns about this policy or how we handle data:
- Email: nick@colossalaiconsulting.com
- Mail: Colossal AI Consulting, Greenwood, Indiana, United States
- Policy URL: colossalaiconsulting.com/privacy
This policy is provided for general informational purposes and is not legal advice. If your business is subject to specific regulatory regimes, have counsel review it against your obligations.