Privacy Policy
Last updated 9 September 2026
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Privacy Code”). It describes how Mative S.r.l. processes the personal data of natural persons (the “Data Subject”) who visit or interact with the website www.mative.ai (the “Application”).
This notice covers the website. The Mative Cloud services supplied to customers are governed by separate agreements and, where Mative acts as a processor, by a data processing agreement under Article 28 GDPR.
1. Data Controller
- Company name: Mative S.r.l.
- Registered and operating office: Via San Pio da Pietrelcina 81, 83100 Avellino (AV), Italy
- Tax code / VAT number: 03190070643
- E-mail: info@mative.ai
- Certified e-mail (PEC): mative@pec.cloud
- Telephone: +39 0825 1920080
Data Protection Officer (DPO). Mative has not appointed a DPO, as the conditions set out in Article 37 GDPR are not met: the Controller's core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. For any data protection matter, please use the contact form with “Privacy” as the subject, or the contact details in § 1.
2. Categories of personal data processed
Data provided voluntarily by the Data Subject through the contact forms, the questionnaire, requests for informational material, newsletter sign-up, the AI assistant and the AI Project Maker:
- identification and contact data: first name, last name, e-mail address, telephone number, company or organisation;
- content of communications: the text of the enquiry, the subject and body of support tickets, questionnaire answers, and messages exchanged with the AI assistant;
- contact source: an indication of the channel the enquiry came from (contact form, questionnaire, newsletter, AI assistant, AI Project Maker), used to route the request to the relevant internal function.
Data collected automatically:
- technical and connection data: IP address, browser and operating system type and version, date and time of the request, referring page. These are recorded in the hosting provider's logs and used for infrastructure security and for the anti-abuse rate limits applied to the forms;
- interaction data collected by the hCaptcha anti-fraud system, which analyses how the page is interacted with and certain device characteristics in order to distinguish a human from a script (see § 6);
- usage statistics collected through Google Analytics, only where consent has been given via the cookie banner (see § 7);
- browsing and communication-interaction data collected by the Controller's marketing automation platform, only where separate and specific consent has been given: pages visited and the order in which they were visited, where the visit came from, opens and clicks on e-mails received, and the interest score derived from them (see § 7 and § 9).
The Application does not require account creation, does not host any payment process, and does not collect payment card details, bank account details or authentication credentials. Special categories of data (Article 9 GDPR) are neither requested nor knowingly processed: please do not enter such data in free-text fields or in the chat.
Providing the data marked as mandatory in the forms is necessary in order to respond to the enquiry; without it the Controller cannot reply. Providing any other data is optional.
A Data Subject who supplies the Controller with third-party personal data (for example a colleague's contact details) must inform those individuals of this processing and is responsible for the lawfulness of the disclosure.
3. Cookies and storage technologies
The Application uses cookies and other technologies that store information on the Data Subject's device. No non-essential technology is activated before express consent is given. Full details, including the table of every individual cookie and instructions for withdrawing consent, are set out in the Cookie Policy.
4. Purposes, legal bases and retention
| # | Purpose | Legal basis | Retention |
|---|---|---|---|
| a | Responding to enquiries, quotation, demo and commercial material requests; handling support tickets | Art. 6(1)(b) GDPR — pre-contractual steps taken at the Data Subject's request | 24 months from the last meaningful contact, unless a contractual relationship is established |
| b | Performance of the contract and management of the customer relationship | Art. 6(1)(b) GDPR | Term of the contract and, thereafter, 10 years (ordinary limitation period) |
| c | Sending the newsletter and promotional communications about Mative products and services | Art. 6(1)(a) GDPR — express, specific consent, withdrawable at any time | Until consent is withdrawn or the recipient unsubscribes |
| d | Sending commercial e-mail about products or services similar to those already purchased, to existing customers only | Art. 130(4) Privacy Code (“soft spam”) — legitimate interest, with the right to object in every communication | Until an objection is raised |
| e | Security of the Application: anti-fraud protection of forms, request rate limiting, security logging | Art. 6(1)(f) GDPR — the Controller's legitimate interest in protecting its infrastructure from automated abuse | Technical logs: 12 months |
| f | Compliance with legal obligations, in particular accounting and tax obligations | Art. 6(1)(c) GDPR | 10 years (Art. 2220 Italian Civil Code) |
| g | Establishing, exercising or defending legal claims | Art. 6(1)(f) GDPR — legitimate interest | Duration of the dispute and until the time limits for appeal have expired |
| h | Statistical measurement of website usage | Art. 6(1)(a) GDPR and Art. 122 Privacy Code — consent given via the cookie banner | See Cookie Policy |
| i | Handling job applications submitted through the Careers section | Art. 6(1)(b) GDPR — pre-contractual steps taken at the candidate's request | 12 months from receipt, unless the Data Subject consents to longer retention for future openings |
| j | Marketing automation: measuring browsing and e-mail interactions, attributing where a contact came from, computing an interest score and, on that basis, selecting the content and timing of promotional communications (profiling) | Art. 6(1)(a) GDPR and Art. 122 Privacy Code — express and specific consent, separate from the one given for statistics, withdrawable at any time | Until consent is withdrawn or an objection is raised and, in any event, 24 months from the Data Subject's last interaction |
At the end of the retention periods, data is deleted or irreversibly anonymised.
Legitimate interest balancing. For purposes e), d) and g) the Controller has carried out a balancing assessment between its own interest and the rights of the Data Subject, concluding that the processing is limited to what is necessary and does not cause disproportionate prejudice. A summary of that assessment may be requested through the contact form, and the Data Subject in any event has the right to object under Article 21 GDPR (see § 12).
5. AI assistant and AI Project Maker
The Application provides a conversational assistant and a project-outline generator built on large language models (LLMs).
How it works. The text entered by the Data Subject, together with system instructions defined by Mative, is transmitted to the infrastructure of Groq, Inc. (Mountain View, California, United States), which processes the request and returns a response. Groq acts as a processor appointed by Mative.
What we retain. The service is stateless: Mative does not store conversation history on its systems. The conversation remains in the Data Subject's browser for the duration of the session. If the Data Subject voluntarily chooses to forward the conversation by e-mail or to leave their contact details to be contacted back, the content and the contact details are recorded in the company CRM and processed for purpose a) of § 4.
Model training. The Groq Services Agreement expressly prohibits the provider from using Inputs or Outputs to train or fine-tune its models, unless the customer instructs otherwise — which Mative has never done. The content transmitted is therefore not used to train or improve the provider's models, and the provider does not retain it except as necessary to provide the service, to comply with legal obligations and to ensure the reliable operation of the service.
Transfer outside the EEA. Processing takes place in the United States: see § 8.
Limitations. Responses are automatically generated, may contain inaccuracies and do not constitute professional advice or a binding contractual offer. Please do not enter unnecessary personal data, confidential information or special categories of data into the chat.
6. Anti-fraud protection of forms
The forms on the Application and the AI assistant are protected by hCaptcha, a service provided by Intuition Machines, Inc. (San Francisco, California, United States). To determine whether a request comes from a human being, hCaptcha collects and processes the IP address, browser and device information, and data on how the page is interacted with, and may store information on the device.
The processing relies on the Controller's legitimate interest (Article 6(1)(f) GDPR) in protecting its forms from automated submissions and from fraudulent flooding of the CRM; use of the service is indispensable in order to submit the forms. The processing is described in the hCaptcha privacy policy.
7. Usage statistics and marketing automation
Subject to consent given via the cookie banner, the Application uses Google Analytics 4, provided by Google Ireland Limited (Dublin, Ireland). The service collects pseudonymised — not anonymous — data on pages visited, session duration and navigation paths, in order to measure website usage in aggregate form.
If consent is not given, or is withdrawn, the Google Analytics script is not loaded and no analytics cookie is set. Mative has not enabled Google Signals or interest-based advertising features. Further information is available in the Google privacy policy.
The Google Maps map in the footer is not loaded automatically: it appears only after an express click on the relevant button, from which point Google's terms and privacy notice apply.
Marketing automation. Subject to a further consent, separate from the one for statistics and given through the same banner, the Application loads the tracking script of the marketing automation platform hosted and operated by Mative at mkt.mative.ai: the data is not disclosed to a third-party marketing automation vendor.
What it collects. The pages visited and the order in which they were visited, where the visit came from (search engine, social network, campaign, another website), the device and browser type, the IP address and — for those who have left their contact details — opens and clicks on the e-mails they receive. This information is tied to a pseudonymous identifier held in three first-party cookies (mtc_id, mautic_device_id and mautic_referer_id) and, for the first two, mirrored in the browser's local storage and, from the moment the Data Subject submits a form, to their contact record.
What it is for. Measuring which content generates interest, attributing where a request came from, and computing an interest score that guides the content and timing of promotional communications. This constitutes profiling: the logic applied, its consequences and the Data Subject's rights are set out in § 9.
If consent is not given, or is withdrawn, the script is not loaded, no tracking cookie is set, and any already present are removed from the browser. Tracking covers www.mative.ai only: the www.mative.cloud website hosts no tracking script.
8. Recipients of personal data and transfers outside the European Economic Area
Personal data is processed by the Controller's authorised personnel, appropriately instructed and bound by confidentiality, and may be disclosed to the following recipients:
| Recipient | Role and activity | Location | Transfer safeguards |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Processor — hosting of the Application, CDN, perimeter protection | European Union (Luxembourg) | Processing within the EEA; Standard Contractual Clauses for any third-country access |
| Groq, Inc. | Processor — processing of requests to the AI assistant and AI Project Maker | United States | Data Processing Addendum under Art. 28 GDPR and Standard Contractual Clauses, Module 2 (EU Decision 2021/914), incorporated into the Groq Services Agreement |
| Intuition Machines, Inc. (hCaptcha) | Processor — anti-fraud protection of forms | United States | Standard Contractual Clauses and supplementary measures |
| Google Ireland Limited | Processor — usage statistics (subject to consent); map service on user activation | Ireland, with possible transfers to Google LLC (USA) | EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses |
| Hetzner Online GmbH | Processor — hosting of the marketing automation platform and of the CRM system | European Union (Germany) | Processing within the EEA |
| Amazon Web Services, Inc. — Amazon SES | Processor — e-mail delivery infrastructure | United States (us-east-1 region) |
EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses, incorporated into the AWS GDPR Data Processing Addendum |
| E-mail and IT service providers, accounting, tax and legal advisers | Processors or independent controllers, according to their role | European Union | — |
| Judicial and administrative authorities | Independent controllers, in the cases provided for by law | Italy / EU | — |
The CRM system and the marketing automation platform into which contacts are recorded are hosted on infrastructure operated by the Controller and do not involve disclosure to a third-party CRM or marketing automation vendor: the parties listed in the table supply the underlying infrastructure and the e-mail delivery service, not the handling of the data itself.
All processors are appointed under Article 28 GDPR and are contractually bound to process the data solely on the Controller's instructions, applying appropriate technical and organisational measures.
Where data is transferred outside the EEA, the Controller applies the safeguards provided for in Chapter V GDPR, as set out in the table above. A copy of the safeguards adopted may be requested through the contact form.
Personal data is never disseminated, sold or transferred to third parties for their own marketing purposes.
9. Automated decision-making and profiling
Pursuant to Article 13(2)(f) GDPR, the Controller does not carry out solely automated decision-making producing legal effects concerning the Data Subject or similarly significantly affecting them.
The AI assistant and the AI Project Maker generate text automatically, but do not take decisions about the Data Subject: every assessment of a commercial or support request is carried out by human personnel.
Profiling for marketing purposes. Subject to specific consent (§ 4(j) and § 7), the Controller processes browsing and e-mail interaction data in order to build an interest profile of the Data Subject.
Logic involved. Each relevant behaviour — visiting particular pages, returning to the website, opening a communication or clicking a link within it — is assigned a score, according to predetermined rules defined by the Controller. The sum of those scores places the contact in a segment.
Consequences. The segment determines which content the Data Subject receives and how often, and flags to sales staff which contacts to follow up first. It does not determine prices, contractual terms or access to services, and it produces no legal effect nor similarly significantly affects the Data Subject: Article 22 GDPR therefore does not apply, and every commercial approach is preceded by a human assessment.
Rights. The Data Subject may object at any time and without giving reasons to profiling for direct marketing purposes (Article 21(2) GDPR): following an objection the profile is no longer updated or used. Withdrawing consent, via the “Cookies settings” link in the footer, stops collection immediately and removes the cookies already set. The rights of access, rectification and erasure under § 12 remain unaffected.
10. Processing methods and security measures
Processing is carried out using electronic and, residually, paper-based tools, with logic strictly related to the stated purposes. The Controller applies technical and organisational measures appropriate under Article 32 GDPR, including: encryption of communications in transit (HTTPS), role-based access control, rate limiting on public forms, server-side input validation, segregation of application credentials, and logging of security-relevant events.
11. Minors
The Application is addressed to professionals, businesses and public bodies and is not intended for persons under sixteen years of age. The Controller does not knowingly collect personal data from minors. A holder of parental responsibility who believes a minor has provided their data may report this through the contact form and the data will be deleted without delay.
12. Rights of the Data Subject
The Data Subject has the right to:
- access their personal data and obtain a copy of it (Art. 15);
- obtain rectification of inaccurate data or completion of incomplete data (Art. 16);
- obtain erasure of the data, in the cases provided for (Art. 17);
- obtain restriction of processing (Art. 18);
- receive their data in a structured format and obtain its portability to another controller (Art. 20);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
- object to processing based on legitimate interest, on grounds relating to their particular situation (Art. 21(1)).
Objection to direct marketing. Under Article 21(2) GDPR, the Data Subject has the right to object at any time and without giving reasons to the processing of their data for direct marketing purposes. Following an objection, the data will no longer be processed for that purpose. The objection may be exercised through the contact form or by using the unsubscribe link included in every communication.
Withdrawing cookie consent. Consent given through the banner can be changed or withdrawn at any time via the “Cookies settings” link in the footer of every page of the website.
Requests may be submitted through the contact form, to the contact details in § 1, or to the certified e-mail address given there. The Controller responds within one month of receipt; that period may be extended by two further months where necessary, taking into account the complexity and number of requests, with reasoned notice given to the Data Subject within the first month (Article 12(3) GDPR). Exercising these rights is free of charge, save in the case of manifestly unfounded or excessive requests.
13. Complaint to the supervisory authority
A Data Subject who considers that the processing of their personal data infringes applicable law has the right to lodge a complaint with the Italian supervisory authority:
Garante per la protezione dei dati personali Piazza Venezia 11 — 00187 Rome, Italy www.garanteprivacy.it — protocollo@pec.gpdp.it
without prejudice to the right to an effective judicial remedy (Articles 77 and 79 GDPR).
14. Changes to this notice
The Controller may update this notice to reflect legislative changes or the evolution of the services offered. The version in force is always published on this page, with the date of the last update. Where changes materially affect processing based on consent, the Controller will highlight them and, where necessary, obtain consent again.