Privacy policy
Last updated: 3 August 2026
This policy explains what personal data we collect when you use Maditon, why we collect it, and what you can do about it. It covers your rights under the EU General Data Protection Regulation (GDPR) and the EU Data Act. Our processors are EU or EU-adequate only — we do not transfer personal data to the United States.
1. Who we are
The controller for personal data processed through Maditon is Abiton Ventures AB, a Swedish aktiebolag. Registered office and organisation number are available on request. Privacy contact: privacy@maditon.com. We act as controller for account, billing, and authentication data, and as processor for the content customers put into the product on behalf of their organisations.
We have not appointed a Data Protection Officer because we do not meet the thresholds in Article 37 GDPR. Privacy-related enquiries go to the privacy contact above.
2. What personal data we collect
- Account data: name, email, organisation, role.
- Authentication data: received via Zitadel — subject identifier, email, name, and profile attributes.
- Billing data: Stripe customer and subscription identifiers only. We never store card numbers, CVVs, or bank details. Following the GDPR principle of data minimisation (Art. 5(1)(c)), we send Stripe only what it needs to bill you: organisation name, country, VAT number, billing email (for receipts and dunning notices), and your interface language. We do not send your personal name to Stripe.
- Product data: the organisations you represent, the AI systems you describe, the evidence files you upload, your learning progress, and the risk classifications you draft and accept.
- Communications: support emails and in-product feedback.
- Technical data: access logs (IP used only for rate-limiting and abuse detection) and server logs (metadata only, 90-day retention).
- CRA Readiness Scan submissions: if you use the free scan at maditon.com/cra-scan and ask for the report, we collect your email address, an optional company name, and your answers. This is a marketing enquiry with no account attached and is covered separately in section 12.
3. Why we collect it, and on what legal basis
- Contract (Art. 6(1)(b)): to deliver the Service your organisation subscribed to.
- Legitimate interest (Art. 6(1)(f)): security, abuse prevention, and aggregate product analytics (Plausible — cookieless).
- Legal obligation (Art. 6(1)(c)): tax and accounting record retention, responding to supervisory-authority requests.
- Consent (Art. 6(1)(a)): only where we ask for it explicitly — currently unused in the product.
4. Who we share data with
We share personal data only with the processors below, each acting under a signed data processing agreement. We do not sell personal data and we do not share it for advertising.
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Zitadel Cloud | Identity provider, SSO, MFA | Switzerland | EU adequacy decision (CH–EU) |
| Stripe Payments Europe Ltd | Billing and payment processing | Ireland (EU) | DPA + SCCs for onward transfers |
| MailPace (OhMySMTP Ltd) | Transactional email — trial and billing notices, deadline reminders, and the CRA Readiness Scan report | United Kingdom (EU-hosted) | DPA, UK adequacy decision |
| Brevo (Sendinblue SA) | Marketing email and newsletter only | France (EU) | DPA, EU data storage |
| Mistral AI SAS | AI classification and content generation | France (EU) | DPA, no training on submitted data |
| UpCloud Ltd | Managed PostgreSQL (production database) | Finland (EU) | DPA |
| Hetzner Online GmbH | Compute and object storage | Germany / Finland (EU) | DPA |
| Plausible Insights OÜ | Aggregate, cookieless analytics | Estonia (EU, hosted on Hetzner DE) | DPA — no personal data transmitted |
| BunnyCDN | Website content delivery (maditon.com) | Slovenia (EU edge nodes only) | DPA, EU-only edge configuration |
| Google Ireland Ltd | Advertising conversion measurement — only on /cra-scan, and only if you press Accept on the banner there | Ireland (EU entity); onward transfer to Google LLC (US) | Your consent, plus Google's SCCs and EU–US Data Privacy Framework certification |
Stripe data minimisation. Stripe is our billing processor. We share with Stripe only the data it needs to operate billing: organisation name (the legal entity on the invoice), billing email, country, VAT number, and your interface language. Your personal name is not transmitted to Stripe. We hold it inside Maditon's own database and share it only with the EU-headquartered processors that need it (Zitadel for authentication, Brevo for transactional email).
5. International transfers
Zitadel is located in Switzerland and MailPace in the United Kingdom; both countries benefit from a European Commission adequacy decision, so no additional safeguards are needed for those transfers. Every other processor used to deliver the Service is located in the EU/EEA. Using the Service does not transfer your personal data to the United States.
There is exactly one exception, and it is opt-in. On the free CRA Readiness Scan page — and nowhere else on maditon.com or in the product — pressing Accept on the cookie banner loads Google's advertising tag, which involves an onward transfer to Google LLC in the United States. That transfer rests on your consent together with Google's Standard Contractual Clauses and its certification under the EU–US Data Privacy Framework. Press Decline, or simply ignore the banner, and no request is made to any Google server at all. The scan works identically either way.
6. Retention
We keep account data while your subscription is active and for 30 days after cancellation so that export and recovery remain possible. Audit and security logs are retained for at least 90 days. Email delivery metadata (Brevo message IDs) is retained until you delete your account. Soft-deleted records are permanently purged after 30 days. You can trigger immediate deletion at any time (see below).
7. Your rights
You have the right to access, rectification, erasure, restriction, portability, objection, and to withdraw consent at any time. You can also lodge a complaint with a supervisory authority. Our product includes self-serve endpoints for the two most common requests:
- Access and portability: Settings → Data & privacy → "Export all personal data (GDPR)" covers Articles 15 and 20. A second export covers all organisation data under the EU Data Act.
- Erasure: Settings → Delete account. Your account is anonymised immediately and organisational data is permanently removed within 30 days.
- Rectification, restriction, objection: email privacy@maditon.com. We respond within 30 days.
8. Cookies
Only strictly-necessary session cookies are used during authentication and payment, and our analytics (Plausible) is cookieless. The single exception is the CRA Readiness Scan page, where an advertising cookie is set if — and only if — you press Accept on the banner shown there. See the Cookie policy for the full list.
9. AI processing
The Service uses AI to generate draft risk classifications, document templates, and learning content. When you trigger an AI action, the relevant content from your organisation is sent to Mistral AI SAS (France, EU) to produce the draft. Mistral does not train on submitted data (per the DPA). All AI outputs are drafts until a named user of your organisation explicitly accepts them — see the Terms of service, section 4.
The AI features of Maditon prepare drafts for human review. The Service does not take any automated decision producing legal or similarly significant effects on an individual — Article 22 GDPR does not apply. Each draft is bound to the named user who accepts it inside the Service, and that acceptance — not the AI output — is the legally relevant act. This positioning aligns with the preparatory-task carve-out in Article 6(3)(d) of Regulation (EU) 2024/1689 (the EU AI Act).
10. Children
Maditon is a business-to-business service and is not directed at users under 16.
11. Security
We use TLS in transit, encryption at rest, Zitadel-managed authentication with MFA available, structured audit logging, and 90-day security-log retention. Incident response is documented internally and affected customers are notified within 72 hours of a confirmed personal-data breach.
12. The free CRA Readiness Scan
maditon.com/cra-scan hosts a free questionnaire about the Cyber Resilience Act. It is a marketing asset, not part of the Service, and it works differently from the rest of this policy — so it gets its own section.
Nothing is sent to us while you take the scan. The questions are scored in your browser against a fixed set of rules. No AI is involved and no answers leave the page unless you decide to ask for the report.
If you ask for the report, we receive and store: your email address, the company name if you chose to give one, your answers, the verdict the scan produced, and any campaign parameters (utm_*) in the URL that brought you to the page. We do not ask for, and have no way to receive, your name, your phone number, or your address.
- Legal basis: your request for the report is a step taken at your request prior to entering into a contract, or our legitimate interest in responding to a business enquiry (Art. 6(1)(b) and 6(1)(f)). The separate, unticked marketing checkbox is consent (Art. 6(1)(a)) and covers nothing but future marketing email.
- What we do with it: we send you the report once, via MailPace. We do not add you to any mailing list unless you ticked the box. We do not sell or share the data.
- Where it lives: our managed PostgreSQL database with UpCloud in Finland (EU).
- Retention: 24 months from your submission, then deletion — or immediately on request.
- Erasure: a scan lead has no account, so there is no self-serve delete button. Email privacy@maditon.com and we remove your address and everything attached to it. No form, no reason required, usually within a few days and in any case within the month Article 12(3) allows.
- Advertising: see section 5 for the one consent-gated transfer to Google, and the Cookie policy for the cookie it sets.
13. Changes to this policy
Material changes are notified by email to the billing contact at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact and supervisory authority
Privacy enquiries: privacy@maditon.com. General support: support@maditon.com.
Our lead supervisory authority is the Swedish Authority for Privacy Protection (IMY — Integritetsskyddsmyndigheten). You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence or workplace.