Privacy Policy
Last updated: March 21, 2026
1. Data Controller
Madison Agency, Bucharest, Romania ("Madison," "we," "us") is the data controller for personal data processed through the Madison AI platform.
2. Data We Collect
Account Data: Name, email address, company name, role, authentication credentials.
Business Data: Brand guidelines, logos, documents, content calendars, social media credentials (OAuth tokens), advertising account connections.
Integration Data: Third-party API keys (encrypted), OAuth tokens, platform connection metadata.
Usage Data: Feature usage patterns, module interactions, session data, device information, IP addresses.
Generated Content: AI-generated text, images, reports, analytics, and all platform-created materials.
3. How We Use Your Data
• Service provision and platform functionality
• Authentication and account security
• AI content generation and processing
• Analytics and platform improvement (aggregated, anonymized)
• Communication about your account and platform updates
• Legal compliance and fraud prevention
We do NOT sell your personal data. We do NOT use your data for purposes beyond service provision without explicit consent.
4. Third-Party Processors
We share data with the following processors, all under appropriate data processing agreements:
• Vercel (hosting, edge functions) US/EU
• Neon (PostgreSQL database) EU
• Cloudflare R2 (file storage) EU
• Upstash (Redis caching) EU
• Railway (background services) US/EU
• Resend (transactional email) US
• PostHog EU (analytics) EU
• Sentry (error tracking) EU
• BetterStack (monitoring) EU
• Anthropic (Claude AI, built-in) US
• Google (Gemini AI, built-in) US/EU
• User-selected AI providers (when you connect your own keys)
5. Data Retention
Account data is retained while your account is active. Upon account deletion request, all personal data is hard-deleted within 30 days. Anonymized, aggregated analytics data may be retained indefinitely. Backups containing personal data are purged on their regular rotation cycle (maximum 90 days).
6. Your Rights (GDPR)
Under GDPR, you have the right to:
• Access: Request a copy of all personal data we hold about you.
• Rectification: Correct inaccurate or incomplete data.
• Erasure: Request deletion of your personal data ("right to be forgotten").
• Data Portability: Export your data in JSON, CSV, or ZIP format.
• Restriction: Request limitation of processing in certain circumstances.
• Object: Object to processing based on legitimate interests.
• Withdraw Consent: Withdraw any previously given consent at any time.
To exercise these rights, contact us at hello@madisonagency.ro. We will respond within 30 days.
7. Security Measures
• AES-256-GCM encryption for stored credentials and API keys
• HTTPS/TLS encryption for all data in transit
• Role-Based Access Control (RBAC) for platform access
• Rate limiting and DDoS protection via Cloudflare
• Regular security audits and penetration testing
• Incident response procedures
While we implement industry-standard security measures, absolute security cannot be guaranteed. We will notify affected users and relevant authorities of any data breach as required by GDPR.
8. International Data Transfers
Some of our processors are based outside the EU. Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
9. Children
Madison AI is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-platform notification. The "Last updated" date at the top indicates the most recent revision.
11. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with:
• ANSPDCP (Romanian Data Protection Authority): www.dataprotection.ro
• Your local EU supervisory authority
We encourage you to contact us first at hello@madisonagency.ro so we can address your concerns directly.
12. Contact
Data Controller: Madison Agency
Location: Bucharest, Romania
Email: hello@madisonagency.ro