Privacy Policy
Last updated 24 September 2026
This notice is provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the “GDPR”) and to Italian Legislative Decree 196/2003 as amended by Legislative Decree 101/2018 (the “Privacy Code”). It describes how Mative S.r.l. processes the personal data of natural persons (the “Data Subject”) who visit or interact with the website www.mative.ai (the “Application”).
This notice covers the website. The Mative Cloud services supplied to customers are governed by separate agreements and, where Mative acts as a processor, by a data processing agreement under Article 28 GDPR.
1. Data Controller
- Company name: Mative S.r.l.
- Registered and operating office: Via San Pio da Pietrelcina 81, 83100 Avellino (AV), Italy
- Tax code / VAT number: 03190070643
- E-mail: info@mative.ai
- Certified e-mail (PEC): mative@pec.cloud
- Telephone: +39 0825 1920080
Data Protection Officer (DPO). Mative has not appointed a DPO, as the conditions set out in Article 37 GDPR are not met: the Controller's core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. For any data protection matter, please use the contact form with “Privacy” as the subject, or the contact details in § 1.
2. Categories of personal data processed
Data provided voluntarily by the Data Subject through the contact forms, the questionnaire, requests for informational material, newsletter sign-up, the AI assistant and the AI Project Maker:
- identification and contact data: first name, last name, e-mail address, telephone number, company or organisation;
- content of communications: the text of the enquiry, the subject and body of support tickets, questionnaire answers, and messages exchanged with the AI assistant;
- contact source: an indication of the channel the enquiry came from (contact form, questionnaire, newsletter, AI assistant, AI Project Maker), used to route the request to the relevant internal function.
Data collected automatically:
- technical and connection data: IP address, browser and operating system type and version, date and time of the request, referring page. These are recorded in the hosting provider's logs and used for infrastructure security and for the anti-abuse rate limits applied to the forms;
- interaction data collected by the hCaptcha anti-fraud system, which analyses how the page is interacted with and certain device characteristics in order to distinguish a human from a script (see § 6);
- usage statistics collected through Google Analytics, only where consent has been given via the cookie banner (see § 7);
- browsing and communication-interaction data collected by the Controller's marketing automation platform, only where separate and specific consent has been given: pages visited and the order in which they were visited, where the visit came from, opens and clicks on e-mails received, and the interest score derived from them (see § 7 and § 9).
Data derived by the Controller:
- data derived from the automated analysis of enquiries: type of enquiry, industry, solution of interest, any timescales and a one-line summary, inferred from the text of the enquiry and attached to the contact record (see § 9).
The Application does not require account creation, does not host any payment process, and does not collect payment card details, bank account details or authentication credentials. Special categories of data (Article 9 GDPR) are neither requested nor knowingly processed: please do not enter such data in free-text fields or in the chat.
Providing the data marked as mandatory in the forms is necessary in order to respond to the enquiry; without it the Controller cannot reply. Providing any other data is optional.
A Data Subject who supplies the Controller with third-party personal data (for example a colleague's contact details) must inform those individuals of this processing and is responsible for the lawfulness of the disclosure.
3. Cookies and storage technologies
The Application uses cookies and other technologies that store information on the Data Subject's device. No non-essential technology is activated before express consent is given. Full details, including the table of every individual cookie and instructions for withdrawing consent, are set out in the Cookie Policy.
4. Purposes, legal bases and retention
| # | Purpose | Legal basis | Retention |
|---|---|---|---|
| a | Responding to enquiries, quotation, demo and commercial material requests; handling support tickets | Art. 6(1)(b) GDPR — pre-contractual steps taken at the Data Subject's request | 24 months from the last meaningful contact, unless a contractual relationship is established |
| b | Performance of the contract and management of the customer relationship | Art. 6(1)(b) GDPR | Term of the contract and, thereafter, 10 years (ordinary limitation period) |
| c | Sending the newsletter and promotional communications about Mative products and services | Art. 6(1)(a) GDPR — express, specific consent, withdrawable at any time | Until consent is withdrawn or the recipient unsubscribes |
| d | Sending commercial e-mail about products or services similar to those already purchased, to existing customers only | Art. 130(4) Privacy Code (“soft spam”) — legitimate interest, with the right to object in every communication | Until an objection is raised |
| e | Security of the Application: anti-fraud protection of forms, request rate limiting, security logging | Art. 6(1)(f) GDPR — the Controller's legitimate interest in protecting its infrastructure from automated abuse | Technical logs: 12 months |
| f | Compliance with legal obligations, in particular accounting and tax obligations | Art. 6(1)(c) GDPR | 10 years (Art. 2220 Italian Civil Code) |
| g | Establishing, exercising or defending legal claims | Art. 6(1)(f) GDPR — legitimate interest | Duration of the dispute and until the time limits for appeal have expired |
| h | Statistical measurement of website usage | Art. 6(1)(a) GDPR and Art. 122 Privacy Code — consent given via the cookie banner | See Cookie Policy |
| i | Handling job applications submitted through the Careers section | Art. 6(1)(b) GDPR — pre-contractual steps taken at the candidate's request | 12 months from receipt, unless the Data Subject consents to longer retention for future openings |
| j | Marketing automation: measuring browsing and e-mail interactions, attributing where a contact came from, computing an interest score and, on that basis, selecting the content and timing of promotional communications (profiling) | Art. 6(1)(a) GDPR and Art. 122 Privacy Code — express and specific consent, separate from the one given for statistics, withdrawable at any time | Until consent is withdrawn or an objection is raised and, in any event, 24 months from the Data Subject's last interaction |
| k | Automated analysis of the text of enquiries submitted through the forms, in order to identify their type and assign them to the relevant person with the appropriate priority (profiling, see § 9) | Art. 6(1)(b) GDPR — pre-contractual steps taken at the Data Subject's request, for enquiries about products and services; Art. 6(1)(f) GDPR — the Controller's legitimate interest in handling enquiries in an orderly and timely manner, with the right to object under Article 21 GDPR | Same period as set out in point a) for contact data |
At the end of the retention periods, data is deleted or irreversibly anonymised.
Legitimate interest balancing. For purposes e), d), g) and k) the Controller has carried out a balancing assessment between its own interest and the rights of the Data Subject, concluding that the processing is limited to what is necessary and does not cause disproportionate prejudice. A summary of that assessment may be requested through the contact form, and the Data Subject in any event has the right to object under Article 21 GDPR (see § 12).
5. AI assistant and AI Project Maker
The Application provides a conversational assistant and a project-outline generator built on large language models (LLMs).
How it works. The text entered by the Data Subject, together with system instructions defined by Mative, is transmitted to the infrastructure of Groq, Inc. (Mountain View, California, United States), which processes the request and returns a response. Groq acts as a processor appointed by Mative.
What we retain. The service is stateless: Mative does not store conversation history on its systems. The conversation remains in the Data Subject's browser for the duration of the session. If the Data Subject voluntarily chooses to forward the conversation by e-mail or to leave their contact details to be contacted back, the content and the contact details are recorded in the company CRM and processed for purposes a) and k) of § 4.
Model training. The Groq Services Agreement expressly prohibits the provider from using Inputs or Outputs to train or fine-tune its models, unless the customer instructs otherwise — which Mative has never done. The content transmitted is therefore not used to train or improve the provider's models, and the provider does not retain it except as necessary to provide the service, to comply with legal obligations and to ensure the reliable operation of the service.
Transfer outside the EEA. Processing takes place in the United States: see § 8.
Limitations. Responses are automatically generated, may contain inaccuracies and do not constitute professional advice or a binding contractual offer. Please do not enter unnecessary personal data, confidential information or special categories of data into the chat.
6. Anti-fraud protection of forms
The forms on the Application and the AI assistant are protected by hCaptcha, a service provided by Intuition Machines, Inc. (San Francisco, California, United States). To determine whether a request comes from a human being, hCaptcha collects and processes the IP address, browser and device information, and data on how the page is interacted with, and may store information on the device.
The processing relies on the Controller's legitimate interest (Article 6(1)(f) GDPR) in protecting its forms from automated submissions and from fraudulent flooding of the CRM; use of the service is indispensable in order to submit the forms. The processing is described in the hCaptcha privacy policy.
7. Usage statistics and marketing automation
Subject to consent given via the cookie banner, the Application uses Google Analytics 4, provided by Google Ireland Limited (Dublin, Ireland). The service collects pseudonymised — not anonymous — data on pages visited, session duration and navigation paths, in order to measure website usage in aggregate form.
If consent is not given, or is withdrawn, the Google Analytics script is not loaded and no analytics cookie is set. Mative has not enabled Google Signals or interest-based advertising features. Further information is available in the Google privacy policy.
The Google Maps map in the footer is not loaded automatically: it appears only after an express click on the relevant button, from which point Google's terms and privacy notice apply.
Marketing automation. Subject to a further consent, separate from the one for statistics and given through the same banner, the Application loads the tracking script of the marketing automation platform hosted and operated by Mative at mkt.mative.ai: the data is not disclosed to a third-party marketing automation vendor.
What it collects. The pages visited and the order in which they were visited, where the visit came from (search engine, social network, campaign, another website), the device and browser type, the IP address and — for those who have left their contact details — opens and clicks on the e-mails they receive. This information is tied to a pseudonymous identifier held in three first-party cookies (mtc_id, mautic_device_id and mautic_referer_id) and, for the first two, mirrored in the browser's local storage and, from the moment the Data Subject submits a form, to their contact record.
What it is for. Measuring which content generates interest, attributing where a request came from, and computing an interest score that guides the content and timing of promotional communications. This constitutes profiling: the logic applied, its consequences and the Data Subject's rights are set out in § 9.
If consent is not given, or is withdrawn, the script is not loaded, no tracking cookie is set, and any already present are removed from the browser. Tracking covers www.mative.ai only: the www.mative.cloud website hosts no tracking script.
8. Recipients of personal data and transfers outside the European Economic Area
Personal data is processed by the Controller's authorised personnel, appropriately instructed and bound by confidentiality, and may be disclosed to the following recipients:
| Recipient | Role and activity | Location | Transfer safeguards |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Processor — hosting of the Application, CDN, perimeter protection | European Union (Luxembourg) | Processing within the EEA; Standard Contractual Clauses for any third-country access |
| Groq, Inc. (Groq's privacy policy) | Processor — processing of requests to the AI assistant and AI Project Maker; automated analysis of the text of enquiries submitted through the forms (see § 9) | United States | Data Processing Addendum under Art. 28 GDPR and Standard Contractual Clauses, Module 2 (EU Decision 2021/914), incorporated into the Groq Services Agreement. For the analysis of enquiries, the Data Subject's first name, last name, e-mail address and telephone number are not transmitted to the provider |
| Mistral AI SAS (Mistral's privacy policy) | Sub-processor in the Synapsis ML chain — generation of the embeddings used to search the assistant's document base. It receives the text of the question, not the Data Subject's identifying data | European Union (France) | Processing within the EEA |
| Intuition Machines, Inc. (hCaptcha) | Processor — anti-fraud protection of forms | United States | Standard Contractual Clauses and supplementary measures |
| Google Ireland Limited | Processor — usage statistics (subject to consent); map service on user activation | Ireland, with possible transfers to Google LLC (USA) | EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses |
| Hetzner Online GmbH | Processor — hosting of the marketing automation platform, of the CRM system and of the Synapsis ML application that drives the AI assistant | European Union (Germany) | Processing within the EEA |
| Amazon Web Services, Inc. — Amazon SES | Processor — e-mail delivery infrastructure | United States (us-east-1 region) |
EU–US Data Privacy Framework adequacy decision and Standard Contractual Clauses, incorporated into the AWS GDPR Data Processing Addendum |
| E-mail and IT service providers, accounting, tax and legal advisers | Processors or independent controllers, according to their role | European Union | — |
| Judicial and administrative authorities | Independent controllers, in the cases provided for by law | Italy / EU | — |
The CRM system and the marketing automation platform into which contacts are recorded are hosted on infrastructure operated by the Controller and do not involve disclosure to a third-party CRM or marketing automation vendor: the parties listed in the table supply the underlying infrastructure and the e-mail delivery service, not the handling of the data itself. The same applies to the Synapsis ML application that drives the AI assistant: it runs on the same infrastructure, so the Data Subject's question is processed within the European Economic Area before it is transmitted to the model provider.
All processors are appointed under Article 28 GDPR and are contractually bound to process the data solely on the Controller's instructions, applying appropriate technical and organisational measures.
Where data is transferred outside the EEA, the Controller applies the safeguards provided for in Chapter V GDPR, as set out in the table above. A copy of the safeguards adopted may be requested through the contact form.
Personal data is never disseminated, sold or transferred to third parties for their own marketing purposes.
9. Automated decision-making and profiling
Pursuant to Article 13(2)(f) GDPR, the Controller does not carry out solely automated decision-making producing legal effects concerning the Data Subject or similarly significantly affecting them.
The AI assistant and the AI Project Maker generate text automatically, but do not take decisions about the Data Subject. Enquiries submitted through the forms are classified automatically, as described below, but every decision on how to follow up a commercial or support request is taken by human personnel.
Automated analysis of enquiries. When the Data Subject submits an enquiry containing a message — through the contact form, the questionnaire, the AI Project Maker or the AI assistant, where they choose to forward the conversation or to leave their contact details — the text of the enquiry is analysed automatically by an artificial intelligence service, in order to understand its nature and assign it to the relevant person with the appropriate priority (§ 4(k)).
Data analysed. Only the text of the message, including questionnaire answers, the company name if provided and the form the enquiry came from are transmitted to the service. First name, last name, e-mail address and telephone number are not transmitted. The message is transmitted as written: any personal data the Data Subject has included in it, including data about third parties, is therefore transmitted together with the rest of the text. Please do not include in the message personal data that is not needed for the enquiry.
Data derived. The analysis returns the type of enquiry, the industry, the solution of interest, any timescales and a one-line summary. This data is saved in the contact record and retained for the same period as the contact data (§ 4(a)).
Qualification and consequences. Since it assesses the interests expressed by the Data Subject — the solution, the industry, the timescales — the classification constitutes a form of profiling within the meaning of Article 4(4) GDPR, distinct from the marketing profiling described below. It determines only the order in which enquiries are handled and the person who replies. It does not determine prices, contractual terms, access to services or whether the enquiry is accepted, and it produces no legal effect nor similarly significantly affects the Data Subject: Article 22 GDPR therefore does not apply. Every enquiry is always answered by a person.
Searching the document base. To find the documents relevant to a question, its text is converted into a numeric representation (an embedding) by Mistral AI SAS, established in the European Union, acting as a sub-processor in the Synapsis ML chain. Only the text of the question is transmitted to Mistral: not the Data Subject's name, e-mail address or telephone number. The processing takes place within the European Economic Area.
Provider. The analysis is performed by Groq, Inc. (Mountain View, California, United States), the same provider as the AI assistant, acting as a processor appointed by the Controller under Article 28 GDPR. The contractual terms described in § 5 apply: the content transmitted is not used to train or improve the provider's models, and the provider does not retain it except to the extent stated there. The transfer to the United States and the related safeguards are set out in § 8.
Rights. The Data Subject may object at any time to the automated analysis of their enquiries, including the resulting profiling (Article 21 GDPR), through the contact form or the contact details in § 1. Following an objection, the data derived from the analysis is deleted and the Data Subject's subsequent enquiries are handled without automated analysis. The rights under § 12 remain unaffected, including the right to have inaccurate derived data rectified.
Profiling for marketing purposes. Subject to specific consent (§ 4(j) and § 7), the Controller processes browsing and e-mail interaction data in order to build an interest profile of the Data Subject.
Logic involved. Each relevant behaviour — visiting particular pages, returning to the website, opening a communication or clicking a link within it — is assigned a score, according to predetermined rules defined by the Controller. The sum of those scores places the contact in a segment.
Consequences. The segment determines which content the Data Subject receives and how often, and flags to sales staff which contacts to follow up first. It does not determine prices, contractual terms or access to services, and it produces no legal effect nor similarly significantly affects the Data Subject: Article 22 GDPR therefore does not apply, and every commercial approach is preceded by a human assessment.
Rights. The Data Subject may object at any time and without giving reasons to profiling for direct marketing purposes (Article 21(2) GDPR): following an objection the profile is no longer updated or used. Withdrawing consent, via the “Cookies settings” link in the footer, stops collection immediately and removes the cookies already set. The rights of access, rectification and erasure under § 12 remain unaffected.
10. Processing methods and security measures
Processing is carried out using electronic and, residually, paper-based tools, with logic strictly related to the stated purposes. The Controller applies technical and organisational measures appropriate under Article 32 GDPR, including: encryption of communications in transit (HTTPS), role-based access control, rate limiting on public forms, server-side input validation, segregation of application credentials, and logging of security-relevant events.
11. Minors
The Application is addressed to professionals, businesses and public bodies and is not intended for persons under sixteen years of age. The Controller does not knowingly collect personal data from minors. A holder of parental responsibility who believes a minor has provided their data may report this through the contact form and the data will be deleted without delay.
12. Rights of the Data Subject
The Data Subject has the right to:
- access their personal data and obtain a copy of it (Art. 15);
- obtain rectification of inaccurate data or completion of incomplete data (Art. 16);
- obtain erasure of the data, in the cases provided for (Art. 17);
- obtain restriction of processing (Art. 18);
- receive their data in a structured format and obtain its portability to another controller (Art. 20);
- withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
- object to processing based on legitimate interest, on grounds relating to their particular situation (Art. 21(1)).
Objection to direct marketing. Under Article 21(2) GDPR, the Data Subject has the right to object at any time and without giving reasons to the processing of their data for direct marketing purposes. Following an objection, the data will no longer be processed for that purpose. The objection may be exercised through the contact form or by using the unsubscribe link included in every communication.
Withdrawing cookie consent. Consent given through the banner can be changed or withdrawn at any time via the “Cookies settings” link in the footer of every page of the website.
Requests may be submitted through the contact form, to the contact details in § 1, or to the certified e-mail address given there. The Controller responds within one month of receipt; that period may be extended by two further months where necessary, taking into account the complexity and number of requests, with reasoned notice given to the Data Subject within the first month (Article 12(3) GDPR). Exercising these rights is free of charge, save in the case of manifestly unfounded or excessive requests.
13. Complaint to the supervisory authority
A Data Subject who considers that the processing of their personal data infringes applicable law has the right to lodge a complaint with the Italian supervisory authority:
Garante per la protezione dei dati personali Piazza Venezia 11 — 00187 Rome, Italy www.garanteprivacy.it — protocollo@pec.gpdp.it
without prejudice to the right to an effective judicial remedy (Articles 77 and 79 GDPR).
14. Changes to this notice
The Controller may update this notice to reflect legislative changes or the evolution of the services offered. The version in force is always published on this page, with the date of the last update. Where changes materially affect processing based on consent, the Controller will highlight them and, where necessary, obtain consent again.