Privacy Policy
Last updated: September 2, 2026
This notice is issued by Fossa Partners LLC ("Fossa Partners," "we," "us," and "our") and explains how we may collect, use, disclose, store, and otherwise process personal data. This notice may be amended or updated from time to time, so please check back regularly for updates.
This Privacy Policy is addressed to individuals outside our company with whom we interact, including customers, prospective customers, authorized users, website visitors, research participants, survey respondents, interview participants, and other users of our products and services (together, "you" and "your"). Your privacy is important to us. This Privacy Policy describes our information practices for our websites, data collection activities, software tools, and related services, including Fossa Partners, GovGTM, Stativ, and GovWire.
I. COLLECTION AND USE OF PERSONAL DATA
Fossa Partners LLC is a software and services provider. Depending on the product and context, we may collect or obtain personal data about you either directly from you, indirectly from our customers or partners, automatically through your use of our websites and services, or from publicly available or third-party sources where permitted by law.
Information we may collect directly from you
We may collect personal data that you voluntarily provide to us, including when you:
- visit our websites;
- request a demo;
- create an account;
- subscribe to communications;
- contact us by email, form, phone, or otherwise;
- upload documents, content, or other materials;
- participate in interviews, surveys, or research activities;
- use AI-assisted features, browser extensions, or support channels.
This information may include your name, business email address, phone number, company name, job title, account credentials, billing information, communications with us, survey responses, and any views, opinions, prompts, or other content you voluntarily share.
Information we may collect from customers or other sources
In some cases, our customers may provide us with personal data in connection with their use of our Services. For example:
- a customer may provide contact information for interviewees, stakeholders, or team members in connection with GovGTM debrief or research-related services;
- a customer may provide URLs, domains, user roles, team-member information, or other business information in connection with Stativ;
- a customer may upload documents, submissions, responses, proposals, accessibility artifacts, or related materials that contain personal data.
Where we receive personal data from a customer in order to provide contracted services to that customer, we will process that data for the specific business purposes for which the customer engaged us, subject to applicable law and our agreements with that customer.
Information collected automatically
When you use our websites or Services, we may automatically collect certain information, including:
- IP address;
- device identifiers;
- browser type and version;
- operating system;
- date and time of access;
- pages viewed;
- referring and exit URLs;
- usage logs;
- clickstream data;
- session data;
- diagnostic data;
- cookie and similar technology data.
Product-specific examples
Fossa Partners
When you visit the Fossa Partners corporate website, we may collect account information, contact details, inquiry submissions, and related website and usage activity associated with your visit or organization.
GovGTM
When you use GovGTM, we may collect opportunity details, company context, uploaded documents, draft responses, debrief inputs, interview data, survey responses, internal notes, prompts, and AI-generated summaries or analysis associated with your account or organization.
Stativ
When you use Stativ, we may collect monitored URLs, scan targets, HTML content, issue data, screenshots, accessibility findings, audit logs, extension usage, AI assistant prompts and responses, subscription information, and related account activity.
GovWire
When you use GovWire, we may collect account information, content preferences, subscription data, search queries, saved items, notification settings, and related usage activity associated with your account or organization.
How we use personal data
We may use personal data for the following purposes:
- providing, operating, administering, and maintaining our websites and Services;
- authenticating users and managing accounts;
- processing transactions and subscriptions;
- responding to inquiries, requests, and support issues;
- delivering reports, outputs, and contracted services;
- operating AI-assisted features;
- monitoring service performance, quality, usage, and security;
- detecting, preventing, investigating, and addressing fraud, abuse, misuse, and technical issues;
- developing, improving, maintaining, and supporting our Services;
- sending administrative messages, updates, technical notices, and service communications;
- sending marketing and promotional communications, subject to applicable law and opt-out rights;
- complying with legal obligations and enforcing our rights.
Legal basis and processing context
Depending on the circumstances, we may process personal data on the basis of consent, our legitimate business interests, the legitimate business interests of our customers, performance of a contract, or compliance with legal obligations. Where we collect data directly from you for our own business purposes, those purposes may include responding to requests for information, monitoring website activity, sales and marketing activity, service administration, and support. Where we process data on behalf of a customer, we do so to provide the contracted service to that customer.
We do not intend to collect or process special categories of sensitive personal data through our general websites or Services, and we request that customers and users not submit such information unless expressly requested and authorized in writing by Fossa Partners.
Children's privacy
Our Services are not directed to children, and we do not knowingly collect personal data from children under 13. If we learn that we have collected such data, we will take reasonable steps to delete it.
II. PROTECTION, DISCLOSURE, AND PROCESSING OF PERSONAL DATA
We do not sell personal data for money. We may disclose personal data to third parties only as described in this Privacy Policy, as required to provide our Services, as directed by our customers, or as otherwise permitted or required by law.
Categories of recipients
We may disclose personal data to:
- our service providers, contractors, and vendors that help us operate the business or provide the Services, such as hosting, infrastructure, analytics, billing, support, communications, and AI processing providers;
- our customers, where we are acting on their behalf and your participation or data relates to a service we provide to them;
- legal, regulatory, administrative, and governmental authorities where required by law, subpoena, court order, or legal process;
- parties involved in an actual or proposed financing, merger, acquisition, sale of assets, reorganization, bankruptcy, or similar transaction;
- parties necessary to investigate, detect, prevent, or address fraud, security, abuse, unlawful conduct, or violations of our agreements;
- other parties where you direct us or consent to the disclosure.
If we engage a third-party processor to process personal data for a legitimate business purpose, that processor will be expected to handle personal data under appropriate confidentiality and data protection obligations.
AI processing providers
Some AI-assisted features may involve transmitting data to third-party AI service providers for the purpose of generating outputs for you. We use such providers only to support the requested service functionality. We do not state in this Privacy Policy that Fossa Partners, GovGTM, Stativ, or GovWire is GDPR compliant, and we do not state that any of these products is SOC 2 certified.
Security
We use commercially reasonable administrative, technical, and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. These measures may include access controls, encrypted transmission, logging, authentication controls, and internal confidentiality obligations.
Because the internet is an open system, no method of transmission over the internet and no method of electronic storage is completely secure. Although we take reasonable steps to protect personal data, we cannot guarantee the security of personal data transmitted to us or stored in our systems.
We also maintain internal controls around employee and contractor access to systems that process personal data, generally on a need-to-know basis.
International transfers
If you are located outside the United States, you should be aware that personal data you provide to us may be transferred to, stored in, and processed in the United States and other jurisdictions where we or our service providers operate. By using the Services or otherwise providing information to us, you understand that your information may be transferred to the United States, which may have data protection laws that differ from those in your jurisdiction.
We do not represent in this Privacy Policy that we offer GDPR-compliant transfer mechanisms.
III. DATA RETENTION AND ERASURE
We take reasonable steps to ensure that personal data is retained only for as long as necessary for the purposes for which it was collected, including to provide the Services, fulfill contractual obligations, maintain appropriate business records, resolve disputes, enforce agreements, and comply with applicable legal, accounting, tax, or reporting requirements.
Retention periods may vary depending on the type of data, the product used, the nature of the relationship, and applicable legal requirements. When personal data is no longer needed, we will take reasonable steps to delete, anonymize, or otherwise de-identify it, unless retention is required by law or for the establishment, exercise, or defense of legal claims.
You may request deletion of your personal data by contacting us at hello@fossapartners.com. We will respond to such requests in accordance with applicable law and our agreements with you, and we may need to verify your identity before acting on a request.
IV. YOUR RIGHTS AND CHOICES
Depending on your location and applicable law, you may have certain rights with respect to your personal data, which may include the right to access, correct, update, or delete your personal data; the right to object to or restrict certain processing; the right to data portability; and the right to withdraw consent where we rely on consent. You may also have rights under specific state privacy laws, such as the California Consumer Privacy Act, as amended.
To exercise these rights, you may:
- update your account settings or profile information directly within the applicable product;
- unsubscribe from marketing communications using the link provided in each message or by contacting us;
- disable or manage cookies through your browser settings, noting that some features may not function properly without them; or
- contact us at hello@fossapartners.com to submit a request regarding your personal data.
We will respond to verified requests within the timeframes required by applicable law. We may need to verify your identity before acting on a request, and we may decline a request where an exception applies under applicable law.
V. COOKIES AND SIMILAR TECHNOLOGIES
We and our service providers may use cookies, web beacons, pixels, and similar technologies on our websites to operate and maintain the Services, remember preferences, measure usage, and understand how visitors use our sites. We may also use these technologies for analytics and, where permitted, for marketing.
Most browsers allow you to control or disable cookies through their settings. Disabling cookies may affect the functionality of some features of our websites. We do not use cookies to sell your personal data.
VI. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this notice. We encourage you to review this Privacy Policy periodically. Your continued use of the Services after changes are posted means that you accept the updated Privacy Policy.
VII. CONTACT INFORMATION
If you have any questions about this Privacy Policy or our data practices, please contact us at hello@fossapartners.com.