Privacy Policy

Last updated 9 September 2026

This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Privacy Code”). It describes how Mative S.r.l. processes the personal data of natural persons (the “Data Subject”) who visit or interact with the website www.mative.ai (the “Application”).

This notice covers the website. The Mative Cloud services supplied to customers are governed by separate agreements and, where Mative acts as a processor, by a data processing agreement under Article 28 GDPR.

1. Data Controller

Data Protection Officer (DPO). Mative has not appointed a DPO, as the conditions set out in Article 37 GDPR are not met: the Controller's core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. For any data protection matter, please use the contact form with “Privacy” as the subject, or the contact details in § 1.

2. Categories of personal data processed

Data provided voluntarily by the Data Subject through the contact forms, the questionnaire, requests for informational material, newsletter sign-up, the AI assistant and the AI Project Maker:

Data collected automatically:

The Application does not require account creation, does not host any payment process, and does not collect payment card details, bank account details or authentication credentials. Special categories of data (Article 9 GDPR) are neither requested nor knowingly processed: please do not enter such data in free-text fields or in the chat.

Providing the data marked as mandatory in the forms is necessary in order to respond to the enquiry; without it the Controller cannot reply. Providing any other data is optional.

A Data Subject who supplies the Controller with third-party personal data (for example a colleague's contact details) must inform those individuals of this processing and is responsible for the lawfulness of the disclosure.

3. Cookies and storage technologies

The Application uses cookies and other technologies that store information on the Data Subject's device. No non-essential technology is activated before express consent is given. Full details, including the table of every individual cookie and instructions for withdrawing consent, are set out in the Cookie Policy.

4. Purposes, legal bases and retention

# Purpose Legal basis Retention
a Responding to enquiries, quotation, demo and commercial material requests; handling support tickets Art. 6(1)(b) GDPR — pre-contractual steps taken at the Data Subject's request 24 months from the last meaningful contact, unless a contractual relationship is established
b Performance of the contract and management of the customer relationship Art. 6(1)(b) GDPR Term of the contract and, thereafter, 10 years (ordinary limitation period)
c Sending the newsletter and promotional communications about Mative products and services Art. 6(1)(a) GDPR — express, specific consent, withdrawable at any time Until consent is withdrawn or the recipient unsubscribes
d Sending commercial e-mail about products or services similar to those already purchased, to existing customers only Art. 130(4) Privacy Code (“soft spam”) — legitimate interest, with the right to object in every communication Until an objection is raised
e Security of the Application: anti-fraud protection of forms, request rate limiting, security logging Art. 6(1)(f) GDPR — the Controller's legitimate interest in protecting its infrastructure from automated abuse Technical logs: 12 months
f Compliance with legal obligations, in particular accounting and tax obligations Art. 6(1)(c) GDPR 10 years (Art. 2220 Italian Civil Code)
g Establishing, exercising or defending legal claims Art. 6(1)(f) GDPR — legitimate interest Duration of the dispute and until the time limits for appeal have expired
h Statistical measurement of website usage Art. 6(1)(a) GDPR and Art. 122 Privacy Code — consent given via the cookie banner See Cookie Policy
i Handling job applications submitted through the Careers section Art. 6(1)(b) GDPR — pre-contractual steps taken at the candidate's request 12 months from receipt, unless the Data Subject consents to longer retention for future openings
j Marketing automation: measuring browsing and e-mail interactions, attributing where a contact came from, computing an interest score and, on that basis, selecting the content and timing of promotional communications (profiling) Art. 6(1)(a) GDPR and Art. 122 Privacy Code — express and specific consent, separate from the one given for statistics, withdrawable at any time Until consent is withdrawn or an objection is raised and, in any event, 24 months from the Data Subject's last interaction

At the end of the retention periods, data is deleted or irreversibly anonymised.

Legitimate interest balancing. For purposes e), d) and g) the Controller has carried out a balancing assessment between its own interest and the rights of the Data Subject, concluding that the processing is limited to what is necessary and does not cause disproportionate prejudice. A summary of that assessment may be requested through the contact form, and the Data Subject in any event has the right to object under Article 21 GDPR (see § 12).

5. AI assistant and AI Project Maker

The Application provides a conversational assistant and a project-outline generator built on large language models (LLMs).

How it works. The text entered by the Data Subject, together with system instructions defined by Mative, is transmitted to the infrastructure of Groq, Inc. (Mountain View, California, United States), which processes the request and returns a response. Groq acts as a processor appointed by Mative.

What we retain. The service is stateless: Mative does not store conversation history on its systems. The conversation remains in the Data Subject's browser for the duration of the session. If the Data Subject voluntarily chooses to forward the conversation by e-mail or to leave their contact details to be contacted back, the content and the contact details are recorded in the company CRM and processed for purpose a) of § 4.

Model training. The Groq Services Agreement expressly prohibits the provider from using Inputs or Outputs to train or fine-tune its models, unless the customer instructs otherwise — which Mative has never done. The content transmitted is therefore not used to train or improve the provider's models, and the provider does not retain it except as necessary to provide the service, to comply with legal obligations and to ensure the reliable operation of the service.

Transfer outside the EEA. Processing takes place in the United States: see § 8.

Limitations. Responses are automatically generated, may contain inaccuracies and do not constitute professional advice or a binding contractual offer. Please do not enter unnecessary personal data, confidential information or special categories of data into the chat.

6. Anti-fraud protection of forms

The forms on the Application and the AI assistant are protected by hCaptcha, a service provided by Intuition Machines, Inc. (San Francisco, California, United States). To determine whether a request comes from a human being, hCaptcha collects and processes the IP address, browser and device information, and data on how the page is interacted with, and may store information on the device.

The processing relies on the Controller's legitimate interest (Article 6(1)(f) GDPR) in protecting its forms from automated submissions and from fraudulent flooding of the CRM; use of the service is indispensable in order to submit the forms. The processing is described in the hCaptcha privacy policy.

7. Usage statistics and marketing automation

Subject to consent given via the cookie banner, the Application uses Google Analytics 4, provided by Google Ireland Limited (Dublin, Ireland). The service collects pseudonymised — not anonymous — data on pages visited, session duration and navigation paths, in order to measure website usage in aggregate form.

If consent is not given, or is withdrawn, the Google Analytics script is not loaded and no analytics cookie is set. Mative has not enabled Google Signals or interest-based advertising features. Further information is available in the Google privacy policy.

The Google Maps map in the footer is not loaded automatically: it appears only after an express click on the relevant button, from which point Google's terms and privacy notice apply.

Marketing automation. Subject to a further consent, separate from the one for statistics and given through the same banner, the Application loads the tracking script of the marketing automation platform hosted and operated by Mative at mkt.mative.ai: the data is not disclosed to a third-party marketing automation vendor.

What it collects. The pages visited and the order in which they were visited, where the visit came from (search engine, social network, campaign, another website), the device and browser type, the IP address and — for those who have left their contact details — opens and clicks on the e-mails they receive. This information is tied to a pseudonymous identifier held in three first-party cookies (mtc_id, mautic_device_id and mautic_referer_id) and, for the first two, mirrored in the browser's local storage and, from the moment the Data Subject submits a form, to their contact record.

What it is for. Measuring which content generates interest, attributing where a request came from, and computing an interest score that guides the content and timing of promotional communications. This constitutes profiling: the logic applied, its consequences and the Data Subject's rights are set out in § 9.

If consent is not given, or is withdrawn, the script is not loaded, no tracking cookie is set, and any already present are removed from the browser. Tracking covers www.mative.ai only: the www.mative.cloud website hosts no tracking script.

8. Recipients of personal data and transfers outside the European Economic Area

Personal data is processed by the Controller's authorised personnel, appropriately instructed and bound by confidentiality, and may be disclosed to the following recipients:

Recipient Role and activity Location Transfer safeguards
Amazon Web Services EMEA SARL Processor — hosting of the Application, CDN, perimeter protection European Union (Luxembourg) Processing within the EEA; Standard Contractual Clauses for any third-country access
Groq, Inc. Processor — processing of requests to the AI assistant and AI Project Maker United States Data Processing Addendum under Art. 28 GDPR and Standard Contractual Clauses, Module 2 (EU Decision 2021/914), incorporated into the Groq Services Agreement
Intuition Machines, Inc. (hCaptcha) Processor — anti-fraud protection of forms United States Standard Contractual Clauses and supplementary measures
Google Ireland Limited Processor — usage statistics (subject to consent); map service on user activation Ireland, with possible transfers to Google LLC (USA) EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses
Hetzner Online GmbH Processor — hosting of the marketing automation platform and of the CRM system European Union (Germany) Processing within the EEA
Amazon Web Services, Inc. — Amazon SES Processor — e-mail delivery infrastructure United States (us-east-1 region) EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses, incorporated into the AWS GDPR Data Processing Addendum
E-mail and IT service providers, accounting, tax and legal advisers Processors or independent controllers, according to their role European Union
Judicial and administrative authorities Independent controllers, in the cases provided for by law Italy / EU

The CRM system and the marketing automation platform into which contacts are recorded are hosted on infrastructure operated by the Controller and do not involve disclosure to a third-party CRM or marketing automation vendor: the parties listed in the table supply the underlying infrastructure and the e-mail delivery service, not the handling of the data itself.

All processors are appointed under Article 28 GDPR and are contractually bound to process the data solely on the Controller's instructions, applying appropriate technical and organisational measures.

Where data is transferred outside the EEA, the Controller applies the safeguards provided for in Chapter V GDPR, as set out in the table above. A copy of the safeguards adopted may be requested through the contact form.

Personal data is never disseminated, sold or transferred to third parties for their own marketing purposes.

9. Automated decision-making and profiling

Pursuant to Article 13(2)(f) GDPR, the Controller does not carry out solely automated decision-making producing legal effects concerning the Data Subject or similarly significantly affecting them.

The AI assistant and the AI Project Maker generate text automatically, but do not take decisions about the Data Subject: every assessment of a commercial or support request is carried out by human personnel.

Profiling for marketing purposes. Subject to specific consent (§ 4(j) and § 7), the Controller processes browsing and e-mail interaction data in order to build an interest profile of the Data Subject.

Logic involved. Each relevant behaviour — visiting particular pages, returning to the website, opening a communication or clicking a link within it — is assigned a score, according to predetermined rules defined by the Controller. The sum of those scores places the contact in a segment.

Consequences. The segment determines which content the Data Subject receives and how often, and flags to sales staff which contacts to follow up first. It does not determine prices, contractual terms or access to services, and it produces no legal effect nor similarly significantly affects the Data Subject: Article 22 GDPR therefore does not apply, and every commercial approach is preceded by a human assessment.

Rights. The Data Subject may object at any time and without giving reasons to profiling for direct marketing purposes (Article 21(2) GDPR): following an objection the profile is no longer updated or used. Withdrawing consent, via the “Cookies settings” link in the footer, stops collection immediately and removes the cookies already set. The rights of access, rectification and erasure under § 12 remain unaffected.

10. Processing methods and security measures

Processing is carried out using electronic and, residually, paper-based tools, with logic strictly related to the stated purposes. The Controller applies technical and organisational measures appropriate under Article 32 GDPR, including: encryption of communications in transit (HTTPS), role-based access control, rate limiting on public forms, server-side input validation, segregation of application credentials, and logging of security-relevant events.

11. Minors

The Application is addressed to professionals, businesses and public bodies and is not intended for persons under sixteen years of age. The Controller does not knowingly collect personal data from minors. A holder of parental responsibility who believes a minor has provided their data may report this through the contact form and the data will be deleted without delay.

12. Rights of the Data Subject

The Data Subject has the right to:

Objection to direct marketing. Under Article 21(2) GDPR, the Data Subject has the right to object at any time and without giving reasons to the processing of their data for direct marketing purposes. Following an objection, the data will no longer be processed for that purpose. The objection may be exercised through the contact form or by using the unsubscribe link included in every communication.

Withdrawing cookie consent. Consent given through the banner can be changed or withdrawn at any time via the “Cookies settings” link in the footer of every page of the website.

Requests may be submitted through the contact form, to the contact details in § 1, or to the certified e-mail address given there. The Controller responds within one month of receipt; that period may be extended by two further months where necessary, taking into account the complexity and number of requests, with reasoned notice given to the Data Subject within the first month (Article 12(3) GDPR). Exercising these rights is free of charge, save in the case of manifestly unfounded or excessive requests.

13. Complaint to the supervisory authority

A Data Subject who considers that the processing of their personal data infringes applicable law has the right to lodge a complaint with the Italian supervisory authority:

Garante per la protezione dei dati personali Piazza Venezia 11 — 00187 Rome, Italy www.garanteprivacy.itprotocollo@pec.gpdp.it

without prejudice to the right to an effective judicial remedy (Articles 77 and 79 GDPR).

14. Changes to this notice

The Controller may update this notice to reflect legislative changes or the evolution of the services offered. The version in force is always published on this page, with the date of the last update. Where changes materially affect processing based on consent, the Controller will highlight them and, where necessary, obtain consent again.

Top ^