Privacy policy
Last updated: 24 September 2026
This policy explains what personal data we collect when you use Maditon, why we collect it, and what you can do about it. It covers your rights under the EU General Data Protection Regulation (GDPR) and the EU Data Act. Our processors are EU or EU-adequate only — we do not transfer personal data to the United States, with one opt-in exception on the free CRA Readiness Scan page (section 5).
1. Who we are
The controller for personal data processed through Maditon is Abiton Ventures AB, a Swedish aktiebolag. Company registration number 559576-3797. VAT number SE559576379701. Registered address: Mölndalsvägen 5E, 412 63 Göteborg, Sweden. Privacy contact: privacy@maditon.com. We act as controller for account, billing, and authentication data, and as processor for the content customers put into the product on behalf of their organisations.
We have not appointed a Data Protection Officer because we do not meet the thresholds in Article 37 GDPR. Privacy-related enquiries go to the privacy contact above.
2. What personal data we collect
- Account data: name, email, organisation, role.
- Authentication data: received via Zitadel — subject identifier, email, name, and profile attributes.
- Billing data: Stripe customer and subscription identifiers only. We never store card numbers, CVVs, or bank details. Following the GDPR principle of data minimisation (Art. 5(1)(c)), we send Stripe only what it needs to bill you: organisation name, country, VAT number, billing email (for receipts and dunning notices), and your interface language. We do not send your personal name to Stripe.
- Product data: the organisations you represent, the AI systems you describe, the evidence files you upload, your learning progress, and the risk classifications you draft and accept; the suppliers you register and the addresses of their published documents; the documents you add or upload, including the ones you mark private; the systems and services you describe and the support contacts you record for a supplier, which may be a named person's work email or phone number; the procurement projects and decisions you record; and the questionnaires you upload, your compliance profile, and the answers you approve.
- Communications: support emails and in-product feedback, invitations you send to colleagues, and the daily change email about your supplier register for members who have turned it on.
- Technical data: access logs (IP used only for rate-limiting and abuse detection) and server logs (metadata only, 90-day retention).
- CRA Readiness Scan submissions: if you use the free scan at maditon.com/cra-scan and ask for the report, we collect your email address and your answers. This is a marketing enquiry with no account attached and is covered separately in section 12.
3. Why we collect it, and on what legal basis
- Contract (Art. 6(1)(b)): to deliver the Service your organisation subscribed to.
- Legitimate interest (Art. 6(1)(f)): security, abuse prevention, and aggregate product analytics (Plausible — cookieless).
- Legal obligation (Art. 6(1)(c)): tax and accounting record retention, responding to supervisory-authority requests.
- Consent (Art. 6(1)(a)): only where we ask for it explicitly, and always separately from the contract. Today that is two things: the marketing-email opt-in in your notification settings, which is off unless you turn it on; and, on the CRA Readiness Scan page, the advertising cookie set only if you press Accept on the banner shown there. Neither is required to use the Service, and withdrawing either is as easy as giving it.
4. Who we share data with
We share personal data only with the processors below, each acting under a signed data processing agreement. We do not sell personal data and we do not share it for advertising. When we add or replace a processor that handles your organisation's content, we give at least 30 days' notice and you may object, as set out in section 5 of the Data Processing Agreement.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Zitadel Cloud | Identity provider, SSO, MFA | Switzerland | EU adequacy decision (CH–EU) |
| Stripe Payments Europe Ltd | Billing and payment processing | Ireland (EU) | DPA + SCCs for onward transfers |
| MailPace (OhMySMTP Ltd) | Transactional email — the sign-in codes and magic links our identity provider sends, trial and billing notices, invitations, deadline reminders, the daily change email and weekly digest, and the CRA Readiness Scan report | United Kingdom (EU-hosted) | DPA, UK adequacy decision |
| Brevo (Sendinblue SA) | Marketing email and newsletter only | France (EU) | DPA, EU data storage |
| Mistral AI SAS | AI classification, content generation, and the reading of vendors' published legal documents | France (EU) | DPA. Model training on submitted data switched off for our account; inference on Mistral's EU regional endpoint |
| UpCloud Ltd | Managed PostgreSQL (production database) | Finland (EU) | DPA |
| Hetzner Online GmbH | Compute and object storage | Germany / Finland (EU) | DPA |
| Plausible Insights OÜ | Aggregate analytics. No cookies, no persistent cross-site identifier | Estonia (EU, hosted on Hetzner DE) | DPA — IP and user-agent processed transiently into a daily rotating identifier, not stored |
| Bugsink B.V. | Error tracking. Events can contain IP addresses, user identifiers and stack traces | Netherlands (EU) | DPA — raw events retained 60 days |
| BunnyCDN | Website content delivery (maditon.com) | Slovenia (EU edge nodes only) | DPA, EU-only edge configuration |
| Google Ireland Ltd | Advertising conversion measurement — only on /cra-scan, and only if you press Accept on the banner there | Ireland (EU entity); onward transfer to Google LLC (US) | Your consent, plus Google's SCCs and EU–US Data Privacy Framework certification |
Stripe data minimisation. Stripe is our billing processor. We share with Stripe only the data it needs to operate billing: organisation name (the legal entity on the invoice), billing email, country, VAT number, and your interface language. Your personal name is not transmitted to Stripe. We hold it inside Maditon's own database and share it only with the EU-headquartered processors that need it (Zitadel for authentication, MailPace for transactional email).
5. International transfers
Zitadel is located in Switzerland and MailPace in the United Kingdom; both countries benefit from a European Commission adequacy decision, so no additional safeguards are needed for those transfers. Every other processor used to deliver the Service is located in the EU/EEA. Using the Service does not transfer your personal data to the United States.
There is exactly one exception, and it is opt-in. On the free CRA Readiness Scan page — and nowhere else on maditon.com or in the product — pressing Accept on the cookie banner loads Google's advertising tag, which involves an onward transfer to Google LLC in the United States. That transfer rests on your consent together with Google's Standard Contractual Clauses and its certification under the EU–US Data Privacy Framework. Press Decline, or simply ignore the banner, and no request is made to any Google server at all. The scan works identically either way.
6. Retention
We keep account data while your subscription is active and for 30 days after cancellation so that export and recovery remain possible. Audit and security logs are retained for at least 90 days. Email delivery metadata (the sending provider's message ID and the delivery outcome — never the message body) is retained until you delete your account. Soft-deleted records are permanently purged after 30 days. Copies of suppliers' documents and their readings are kept while the document is in your register and purged 30 days after you remove it. Encrypted database backups are kept for 30 days. MailPace keeps the bodies of emails it sent for up to 30 days; we keep only the message ID and the delivery outcome. Where the law requires longer retention — accounting records for seven years under the Swedish Bookkeeping Act — we keep only what that law covers; see the Terms of service, section 10. You can request deletion at any time (see below).
7. Your rights
You have the right to access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. You can also lodge a complaint with a supervisory authority. Our product includes self-serve endpoints for the two most common requests:
- Access and portability: Settings → Data & privacy → "Export all personal data (GDPR)" covers Articles 15 and 20. A second export covers all organisation data under the EU Data Act.
- Erasure: Settings → Delete account opens a 30-day window during which you can still cancel the request. Your account is locked meanwhile, and when the window ends your personal data is anonymised. Your organisation's content follows section 6: it is kept while the organisation has a subscription and purged 30 days after cancellation.
- Rectification, restriction, objection: email privacy@maditon.com. We respond within 30 days.
8. Cookies
A single first-party cookie remembers your language choice, and is set before you sign in. Beyond that, only strictly-necessary session cookies are used during authentication and payment, and our analytics (Plausible) is cookieless. The single exception is the CRA Readiness Scan page, where an advertising cookie is set if — and only if — you press Accept on the banner shown there. See the Cookie policy for the full list.
9. AI processing
The Service uses AI to generate draft risk classifications, document templates, learning content, and readings of vendors' legal documents. When you trigger an AI action on your own content, that content is sent to Mistral AI SAS (France, EU) to produce the draft. Model training on submitted data is switched off for our account, and inference runs on Mistral's EU regional endpoint. All AI outputs are drafts until a named user of your organisation explicitly accepts them — see the Terms of service, section 4.
Vendors' published documents take the same path. A vendor's legal document that is openly published on the web — a privacy policy, terms, a data processing agreement, a sub-processor list, a security page — is read by the same Mistral model on the same EU endpoint, and so is anything you typed or uploaded yourself. No other AI provider reads either. Because a reading quotes a published document word for word, its text is sent as the vendor published it — with email addresses and phone numbers masked, as with all text we send to the model — and nothing about your organisation travels with it. This applies to every AI feature and to all of your content: model training is switched off for our whole account, and inference for every feature runs on the EU endpoint. Documents you mark as private are encrypted under a key that exists only for your organisation and are never used when drafting answers to a questionnaire. Maditon keeps copies of suppliers' published documents to read and compare them; it is not an archive of them, and the originals are the supplier's pages. A reading is a first reading of one document — a set of questions to put to the supplier — not a judgement about the supplier or about any person named in it.
The AI features of Maditon prepare drafts for human review. The Service is built so that it does not decide anything about a natural person: it produces no binding compliance determination, does not profile individuals, and cannot reach a “cleared” state on its own. Each draft stays a draft until a named user of your organisation explicitly accepts it, and that acceptance — not the AI output — is the act with effect. We describe this because it is how the Service is designed and what it technically does. It is not a legal classification of your use of it. How the EU AI Act and Article 22 GDPR apply depends on your intended purpose, how your people actually use the output, whether the human review is meaningful, and what decisions follow downstream — and those are facts about your deployment, not about our product. We keep our own classification assessment under review as the Service changes, and we will tell you if our conclusions about it change.
10. Children
Maditon is a business-to-business service and is not directed at users under 16.
11. Security
We use TLS in transit, encryption at rest, application-level encryption of the documents you mark private under a per-organisation key, Zitadel-managed authentication with MFA available, structured audit logging, and 90-day security-log retention. Incident response is documented internally. We commit to notifying affected customers within 72 hours of confirming a personal-data breach. That is our own contractual commitment to you, not a restatement of the law: the GDPR's 72-hour clock runs to the supervisory authority, and individuals are notified without undue delay where the breach is likely to result in a high risk to them. Where we act as your processor, we notify you without undue delay so you can meet your own obligations as controller.
12. The free CRA Readiness Scan
maditon.com/cra-scan hosts a free questionnaire about the Cyber Resilience Act. It is a marketing asset, not part of the Service, and it works differently from the rest of this policy — so it gets its own section.
Nothing is sent to us while you take the scan. The questions are scored in your browser against a fixed set of rules. No AI is involved and no answers leave the page unless you decide to ask for the report.
If you ask for the report, we receive and store: your email address, your answers, the verdict the scan produced, and any campaign parameters (utm_*) in the URL that brought you to the page. We do not ask for, and have no way to receive, your name, your company, your phone number, or your address. Submissions made before 25 August 2026 may hold a company name, which the form asked for then and no longer does.
- Legal basis: your request for the report is a step taken at your request prior to entering into a contract, or our legitimate interest in responding to a business enquiry (Art. 6(1)(b) and 6(1)(f)). The separate, unticked marketing checkbox is consent (Art. 6(1)(a)) and covers nothing but future marketing email.
- What we do with it: we send you the report once, via MailPace. We do not add you to any mailing list unless you ticked the box. We do not sell or share the data.
- The CRA-module interest list: after the report is sent you can press "Put me on the interest list". That is a separate, deliberate opt-in (consent, Art. 6(1)(a)): your email address is stored on a list used for exactly one thing — a single announcement email if and when the CRA module ships in Maditon. Same storage, same 24-month retention, same erasure route as everything else in this section.
- Where it lives: our managed PostgreSQL database with UpCloud in Finland (EU).
- Retention: 24 months from your submission, then deletion — or immediately on request.
- Erasure: a scan lead has no account, so there is no self-serve delete button. Email privacy@maditon.com and we remove your address and everything attached to it. No form, no reason required, usually within a few days and in any case within the month Article 12(3) allows.
- Advertising: see section 5 for the one consent-gated transfer to Google, and the Cookie policy for the cookie it sets.
13. Changes to this policy
Material changes are notified by email to the billing contact at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact and supervisory authority
Privacy enquiries: privacy@maditon.com. General support: support@maditon.com.
Our lead supervisory authority is the Swedish Authority for Privacy Protection (IMY — Integritetsskyddsmyndigheten). You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence or workplace.