Updated October 6, 2026
Privacy policy
How Mador handles the personal data of people who use mador.ai: which data, why, who receives it, for how long and how you can ask about it. The service measures businesses, not people: personal data is only used to send you the report, run your account and take payment.
1. The controller
The data controller is:
- Controller
- Vladzslau Humenny
- Legal form
- self-employed individual
- Tax ID (NIF)
- Y9810181M
- Address
- Calle San Blas, Edif. Sand Club, Puerta 203, Golf del Sur, Las Chafiras, 38639 San Miguel de Abona, Santa Cruz de Tenerife, Spain
- Privacy contact
- support@mador.ai
The controller has not appointed a data protection officer (DPO): it is not required for this service. For any privacy question write to the address above.
2. Which data, why and on what basis
The legal basis is the reason the law (art. 6 of EU Regulation 2016/679, GDPR) accepts for processing data. For each moment the site collects data:
| When | Which data | Why | Legal basis |
|---|---|---|---|
| Free scan | Business name, area, category, website if you give it. This is data about the business, not about you. The IP address is not stored: only an encrypted fingerprint is kept. | Run the measurement and show you the report. Limit abuse (a few scans per day per connection at most). | Steps you ask for before a contract (art. 6.1.b). Legitimate interest in the security of the service (art. 6.1.f). |
| Email for the full report (and «Try an agent») | Email, plus the report it refers to. If you don't have one yet, an account is created with that email. | Open the full report, send you the four emails that explain your number (days 0, 3, 7 and 14) and give you access to the area. | Consent (art. 6.1.a), given by leaving your email after reading the note under the field. You withdraw it in one tap from the link at the bottom of every email. |
| Signing in to the area | Email, sign-in code (only its fingerprint is kept), encrypted IP fingerprint, expiry and use date. | Let you in without a password through an emailed link, and protect the account. | Contract (art. 6.1.b). Legitimate interest in security (art. 6.1.f). |
| Subscription and payment | Email, plan, subscription status, Stripe customer and subscription codes. Billing address and VAT number are collected by Stripe on its own page. Card details never pass through mador.ai. | Activate and renew the plan, issue invoices, handle cancellations and refunds. | Contract (art. 6.1.b). Legal obligation for invoices and accounting (art. 6.1.c). |
| Client area and profile | What you write about the business: name, website, public address, phone and email, opening hours, services, online profiles, competitors, questions. The public text of the business website, if you ask to read it. | Run the plan's measurements, prepare the profile, articles and answers to publish. | Contract (art. 6.1.b). |
| Area assistant (chat) | The messages you write and the answers. The conversation stays in your browser. The server keeps a copy of each exchange with account, project and cost. | Answer your questions about the project. Check quality and costs and fix mistakes. | Contract (art. 6.1.b). Legitimate interest in service quality (art. 6.1.f). |
| Site assistant (chat), if you use it | The messages you write and the answers. A copy on the server with an encrypted IP fingerprint. The conversation also stays in your browser. | Answer questions about the service and start a scan if you ask. Limit abuse. | Steps you ask for before a contract (art. 6.1.b). Legitimate interest (art. 6.1.f). |
| Voice messages in the chats, if you use them | The audio you record. It goes through OpenAI only to be transcribed, and Mador does not keep it: not on the server, not in the database. The transcribed text lands in the text box and becomes a chat message only if you send it. | Turn your voice into text, which you can correct before sending it. | Same as the chat you use it in (art. 6.1.b). |
| Contact requests (Agency, markets) | Email, message, language, page you came from, encrypted IP fingerprint. | Reply to you and prepare an offer. | Steps you ask for before a contract (art. 6.1.b). |
| Email to your technician | The email of the person you ask to receive the instructions (for example whoever runs your website). | Send them the instructions you asked for and the link to say «done». | Legitimate interest of the client and of Mador in carrying out the request (art. 6.1.f). Whoever gives the address must be entitled to do so. |
| Partner Program, if you join | Name, email, public name, where you promote Mador, tax code, account holder and IBAN. Clicks on your link counted per day (no IP), clients and commissions. | Attribute the clients you bring, calculate and pay commissions. For visitors from your link, the cookie that remembers it only starts with their consent. | Contract (art. 6.1.b). Legal obligation for payments (art. 6.1.c). |
| Advertising (Meta pixel and Conversions API), when active and only if you consent | Pages visited on mador.ai and Meta's cookies (_fbp, _fbc). When you start a free scan: IP address and browser. When you leave your email after a scan, activate a plan or move to Growth: your email as an encrypted fingerprint (SHA-256, never in plain text), IP address, browser and plan price. For payments Mador keeps the cookies, IP and browser from the moment you open checkout until the event is sent to Meta. | Measure how many people who come from Mador's ads on Facebook and Instagram start a scan, leave their email or subscribe. | Consent (art. 6.1.a), given in the banner. You withdraw it whenever you want from the bottom of every page. |
- When
- Free scan
- Which data
- Business name, area, category, website if you give it. This is data about the business, not about you. The IP address is not stored: only an encrypted fingerprint is kept.
- Why
- Run the measurement and show you the report. Limit abuse (a few scans per day per connection at most).
- Legal basis
- Steps you ask for before a contract (art. 6.1.b). Legitimate interest in the security of the service (art. 6.1.f).
- When
- Email for the full report (and «Try an agent»)
- Which data
- Email, plus the report it refers to. If you don't have one yet, an account is created with that email.
- Why
- Open the full report, send you the four emails that explain your number (days 0, 3, 7 and 14) and give you access to the area.
- Legal basis
- Consent (art. 6.1.a), given by leaving your email after reading the note under the field. You withdraw it in one tap from the link at the bottom of every email.
- When
- Signing in to the area
- Which data
- Email, sign-in code (only its fingerprint is kept), encrypted IP fingerprint, expiry and use date.
- Why
- Let you in without a password through an emailed link, and protect the account.
- Legal basis
- Contract (art. 6.1.b). Legitimate interest in security (art. 6.1.f).
- When
- Subscription and payment
- Which data
- Email, plan, subscription status, Stripe customer and subscription codes. Billing address and VAT number are collected by Stripe on its own page. Card details never pass through mador.ai.
- Why
- Activate and renew the plan, issue invoices, handle cancellations and refunds.
- Legal basis
- Contract (art. 6.1.b). Legal obligation for invoices and accounting (art. 6.1.c).
- When
- Client area and profile
- Which data
- What you write about the business: name, website, public address, phone and email, opening hours, services, online profiles, competitors, questions. The public text of the business website, if you ask to read it.
- Why
- Run the plan's measurements, prepare the profile, articles and answers to publish.
- Legal basis
- Contract (art. 6.1.b).
- When
- Area assistant (chat)
- Which data
- The messages you write and the answers. The conversation stays in your browser. The server keeps a copy of each exchange with account, project and cost.
- Why
- Answer your questions about the project. Check quality and costs and fix mistakes.
- Legal basis
- Contract (art. 6.1.b). Legitimate interest in service quality (art. 6.1.f).
- When
- Site assistant (chat), if you use it
- Which data
- The messages you write and the answers. A copy on the server with an encrypted IP fingerprint. The conversation also stays in your browser.
- Why
- Answer questions about the service and start a scan if you ask. Limit abuse.
- Legal basis
- Steps you ask for before a contract (art. 6.1.b). Legitimate interest (art. 6.1.f).
- When
- Voice messages in the chats, if you use them
- Which data
- The audio you record. It goes through OpenAI only to be transcribed, and Mador does not keep it: not on the server, not in the database. The transcribed text lands in the text box and becomes a chat message only if you send it.
- Why
- Turn your voice into text, which you can correct before sending it.
- Legal basis
- Same as the chat you use it in (art. 6.1.b).
- When
- Contact requests (Agency, markets)
- Which data
- Email, message, language, page you came from, encrypted IP fingerprint.
- Why
- Reply to you and prepare an offer.
- Legal basis
- Steps you ask for before a contract (art. 6.1.b).
- When
- Email to your technician
- Which data
- The email of the person you ask to receive the instructions (for example whoever runs your website).
- Why
- Send them the instructions you asked for and the link to say «done».
- Legal basis
- Legitimate interest of the client and of Mador in carrying out the request (art. 6.1.f). Whoever gives the address must be entitled to do so.
- When
- Partner Program, if you join
- Which data
- Name, email, public name, where you promote Mador, tax code, account holder and IBAN. Clicks on your link counted per day (no IP), clients and commissions.
- Why
- Attribute the clients you bring, calculate and pay commissions. For visitors from your link, the cookie that remembers it only starts with their consent.
- Legal basis
- Contract (art. 6.1.b). Legal obligation for payments (art. 6.1.c).
- When
- Advertising (Meta pixel and Conversions API), when active and only if you consent
- Which data
- Pages visited on mador.ai and Meta's cookies (_fbp, _fbc). When you start a free scan: IP address and browser. When you leave your email after a scan, activate a plan or move to Growth: your email as an encrypted fingerprint (SHA-256, never in plain text), IP address, browser and plan price. For payments Mador keeps the cookies, IP and browser from the moment you open checkout until the event is sent to Meta.
- Why
- Measure how many people who come from Mador's ads on Facebook and Instagram start a scan, leave their email or subscribe.
- Legal basis
- Consent (art. 6.1.a), given in the banner. You withdraw it whenever you want from the bottom of every page.
3. What the site does not collect
- No third-party analytics and no profiling. The Meta advertising pixel and the Partner Program cookie only start with your consent (see the cookies page).
- If you come from a Mador ad on Meta (Facebook or Instagram) and accept marketing cookies, Mador keeps the click code (fbclid) together with the scan, to know which ad you came from.
- No payment card data: only Stripe handles it.
- No plain IP addresses in the database: only encrypted fingerprints, used to limit abuse.
- No special categories of data (health, religion, political opinions and the like). Please don't write them in forms or chats.
Measurements are about businesses: which names AI assistants mention when someone asks for a service in an area. Those names are public business information, and they stay in the archive because they are needed to compare measurements over time.
4. Who receives the data
Mador does not sell or give away personal data. It only entrusts it to the providers needed to run the service, who process it on Mador's behalf (processors, art. 28 GDPR):
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Vercel Inc. | Hosts the site. | All requests to the site, with IP and form data, and technical logs. | Servers in Ireland (Dublin). US company. |
| Turso (ChiselStrike Inc.) | Database. | All the data listed in section 2. | Servers in Ireland (AWS eu-west-1). US company. |
| Stripe | Payments and invoices. | Email, billing details, VAT number, payment details. | Stripe Payments Europe (Ireland). Some data in the US. |
| Resend | Sends the emails. | Recipient address and email text. | US. |
| Anthropic | The AI model behind the chats and the profile texts. | Chat messages, profile data and the text of the business website. | US. |
| OpenAI | Transcribes the voice messages in the chats. | The audio of voice messages, only for transcription. OpenAI keeps API call data for up to 30 days for abuse monitoring. | US. |
| CARTO, OpenStreetMap | Map images. | The IP address of the browser that opens the map. | US/Spain (CARTO), United Kingdom (OpenStreetMap). |
| Meta Platforms Ireland | The advertising pixel and the Conversions API, when active and only with your consent. | Pages visited, Meta's cookies, IP and browser, your email as an encrypted fingerprint and the price of the plan activated. | Ireland. Some data in the US. |
- Provider
- Vercel Inc.
- What it does
- Hosts the site.
- What it receives
- All requests to the site, with IP and form data, and technical logs.
- Where
- Servers in Ireland (Dublin). US company.
- Provider
- Turso (ChiselStrike Inc.)
- What it does
- Database.
- What it receives
- All the data listed in section 2.
- Where
- Servers in Ireland (AWS eu-west-1). US company.
- Provider
- Stripe
- What it does
- Payments and invoices.
- What it receives
- Email, billing details, VAT number, payment details.
- Where
- Stripe Payments Europe (Ireland). Some data in the US.
- Provider
- Resend
- What it does
- Sends the emails.
- What it receives
- Recipient address and email text.
- Where
- US.
- Provider
- Anthropic
- What it does
- The AI model behind the chats and the profile texts.
- What it receives
- Chat messages, profile data and the text of the business website.
- Where
- US.
- Provider
- OpenAI
- What it does
- Transcribes the voice messages in the chats.
- What it receives
- The audio of voice messages, only for transcription. OpenAI keeps API call data for up to 30 days for abuse monitoring.
- Where
- US.
- Provider
- CARTO, OpenStreetMap
- What it does
- Map images.
- What it receives
- The IP address of the browser that opens the map.
- Where
- US/Spain (CARTO), United Kingdom (OpenStreetMap).
- Provider
- Meta Platforms Ireland
- What it does
- The advertising pixel and the Conversions API, when active and only with your consent.
- What it receives
- Pages visited, Meta's cookies, IP and browser, your email as an encrypted fingerprint and the price of the plan activated.
- Where
- Ireland. Some data in the US.
Meta is not a supplier like the others. For collecting and sending the data of the pixel and the Conversions API, Mador and Meta are joint controllers (art. 26 GDPR), under Meta's agreement: www.facebook.com/legal/controller_addendum. What Meta then does with that data is Meta's decision, under its own policy: www.facebook.com/privacy/policy
To take its measurements Mador also queries the assistants and services it measures: OpenAI, Anthropic, Google (Gemini, AI Overviews and AI Mode through DataForSEO), Perplexity, xAI, Mistral, Meta, DeepSeek, Moonshot (Kimi), Zhipu (GLM), Alibaba (Qwen) and Microsoft Copilot through Cloro. They only receive generic questions about a category in an area (for example «a good dentist in Turin»), never personal data.
If you connect Mador to ChatGPT or to Claude, the data of your projects is sent to OpenAI or to Anthropic only when you ask for it, inside the conversation. You can disconnect it whenever you want from the Connections page of your area.
Mador may disclose data to the authorities when the law requires it.
5. Transfers outside the European Union
Some providers are US companies and may access the data from there. The transfer is protected by the EU-US Data Privacy Framework, for the companies that have joined it, or by the standard contractual clauses approved by the European Commission (art. 46 GDPR). The United Kingdom has an adequacy decision from the Commission. You can ask for a copy of the safeguards by writing to support@mador.ai.
6. How long
| Data | How long |
|---|---|
| IP fingerprints for scan limits | 24 hours. |
| Email left for the report, without a subscription | Up to 12 months from the last contact, or until you ask to delete it. |
| Account, projects, profile and log of emails sent | For as long as the account exists. After it is closed, 12 months, then deleted. |
| Copy of chat conversations | 12 months. |
| Audio of voice messages | Mador does not keep it. OpenAI keeps API call data for up to 30 days for abuse monitoring. |
| Sign-in codes and sessions | 12 months after expiry, for security. |
| Contact requests | 12 months from the last exchange, or longer if a contract follows. |
| Billing and payment data (including Mador partner commissions) | 6 years, as Spanish commercial and tax law requires. |
| Vercel technical logs | A few days, under Vercel's rules. |
| Meta cookies, IP and browser saved when you open checkout (only with consent to Meta) | Until the event is sent to Meta, then deleted. If the payment does not go through, 7 days. |
- Data
- IP fingerprints for scan limits
- How long
- 24 hours.
- Data
- Email left for the report, without a subscription
- How long
- Up to 12 months from the last contact, or until you ask to delete it.
- Data
- Account, projects, profile and log of emails sent
- How long
- For as long as the account exists. After it is closed, 12 months, then deleted.
- Data
- Copy of chat conversations
- How long
- 12 months.
- Data
- Audio of voice messages
- How long
- Mador does not keep it. OpenAI keeps API call data for up to 30 days for abuse monitoring.
- Data
- Sign-in codes and sessions
- How long
- 12 months after expiry, for security.
- Data
- Contact requests
- How long
- 12 months from the last exchange, or longer if a contract follows.
- Data
- Billing and payment data (including Mador partner commissions)
- How long
- 6 years, as Spanish commercial and tax law requires.
- Data
- Vercel technical logs
- How long
- A few days, under Vercel's rules.
- Data
- Meta cookies, IP and browser saved when you open checkout (only with consent to Meta)
- How long
- Until the event is sent to Meta, then deleted. If the payment does not go through, 7 days.
If you ask for deletion earlier, the data is deleted within a month, except what the law requires to keep.
7. Agency clients
If an agency uses Mador for its own clients, the agency is the controller of those clients' data and Mador processes it on the agency's behalf. Agency clients should contact the agency first; Mador helps it reply.
8. Your rights
At any time you can ask to:
- know which data Mador holds about you and get a copy (access);
- correct it (rectification);
- delete it (erasure);
- limit its use (restriction);
- receive it in a machine-readable format (portability);
- object to processing based on legitimate interest (objection);
- withdraw consent, without affecting what was done before. For emails, the link at the bottom of every message is enough.
Write to support@mador.ai from the address linked to your data. You get an answer within one month. If you are not satisfied you can complain to a supervisory authority: in Spain the Agencia Española de Protección de Datos (www.aepd.es), in Italy the Garante per la protezione dei dati personali (www.garanteprivacy.it), or the authority of the country where you live.
Mador takes no automated decisions with legal effects on you. The report's number measures a business, not a person.
9. Minors
The service is designed for businesses and professionals. It is not aimed at anyone under 18.
11. Changes
When something changes, this page is updated and the date at the top changes. If the change is significant and you have an account, you get an email before it takes effect.