Privacy and cookie policy
What HelloMarkus does with your data, and with the data of your business’s customers: why, for how long, with whom, and how you stay in control.
This is a translation for information. The French version, published at the address below, is the only binding one. hellomarkus.ai/confidentialite
In short
- We don’t sell your data and we don’t use it for advertising.
- We keep the minimum, for as long as needed: your IP address 30 days, the contact details from an audit that leads nowhere 3 years, the proof of your call-back consent 3 years after it ends.
- On the website, audience measurement (Google Analytics, PostHog) only starts with your consent, and you can change your mind whenever you like.
- On the website, Markus, an AI assistant, answers your questions: your conversation is kept for 30 days, or 3 years if you leave your details with your consent.
- Came through a partner? They see your audit and may call you back.
- Your customers’ data (loyalty card, prize wheel) belongs to you: we only process it on your behalf.
- A question, a request about your data: contact@hellomarkus.ai. Answer within one month.
1. Who is responsible
The controller of the processing described here is HELLOMARKUS, a French simplified joint-stock company (SAS) with a share capital of 100 euros, registered with the Trade and Companies Register (RCS) of Paris under number 104 607 551, whose registered office is at 47 rue Vivienne, 75002 Paris, France (“HelloMarkus”).
For any question about personal data or to exercise a right: contact@hellomarkus.ai, or by post to the registered office. HelloMarkus has not appointed a data protection officer; these requests are handled by its President.
2. When HelloMarkus acts for a business
When a person takes a business’s loyalty card, plays its prize wheel, or leaves a review on its Google profile, it is that business that is responsible for their data. HelloMarkus processes it for the business, as a processor, under the data processing agreement in the terms of sale: it does not use it for its own purposes and does not sell it.
To exercise their rights, that person contacts the business; they may also write to contact@hellomarkus.ai, and HelloMarkus forwards the request without delay. Every loyalty card carries a link to stop receiving messages. When they add their card to Apple Wallet or Google Wallet, Apple or Google receives it, under its own rules.
3. What is processed, why and for how long
| Processing | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Visits to the website and the app | IP address, browser, pages requested (hosts’ logs); anti-abuse counters, in hashed form. | Run the website and the app, protect them, prevent abuse. | Legitimate interest (security and operation). | Technical logs: according to each host’s rules. Anti-abuse counters: 1 day. |
| The free audit | Name, address and website of the business; public data from its Google profile and its website; first name, email and phone number left to receive the details; answers to the questions while waiting; IP address and browser; source (link, campaign). | Run the audit, send it, link it to the account created afterwards, prevent abuse. | Steps taken at the person’s request before a possible contract; legitimate interest for abuse prevention. | IP address and browser: 30 days. First name, email and phone number: 3 years after the last contact, then erased, unless the person becomes a client. Data read through the Google Places API: 30 days. |
| Call-back and follow-ups after the audit | First name, email, phone, business, key figures from the audit, enquiry score, call-back consent (text, date, time, IP address), messages prepared and sent, objection list. | Call back the person who asked for it; send them at most three follow-up emails about their audit; prepare the call. | Call-back by phone, text message or messaging: consent (box never ticked in advance, withdrawable at any time). Follow-up emails to a professional about their business: legitimate interest, with an opt-out link in every message. Tips and offers by email: consent (optional box). | Call-back consent: valid for 12 months; its proof is kept 3 years after it ends. Call brief: 1 year. Record of follow-ups: 3 years. Objection list: in hashed form (without the number or email in plain text), kept for at least 3 years to respect the objection. |
| The account and use of the app | First name, last name, email, phone; password (never stored in plain text) or Google or LinkedIn sign-in; businesses, members, settings, content, history of what Markus does. | Provide the service ordered. | Performance of the contract. | For as long as the account exists. Deletion on request, within the month. An account with no subscription or sign-in for 3 years is deleted. |
| The connection with Google and social networks | Access authorisations, connected profiles and accounts, reviews (display name of the author, rating, text), posts, profile statistics. | Act on the client’s profile and social accounts, at their request. | Performance of the contract. | As long as the connection exists; deleted when disconnected or with the account. |
| Payment and invoicing | Name, email, billing address, VAT number, payments and subscriptions. The card is entered and kept by Stripe. | Collect payments, invoice, keep the accounts. | Performance of the contract; legal obligation (accounting). | Invoices and accounting documents: 10 years (article L123-22 of the French Commercial Code). |
| The AI log | What is sent to the model and what it answers, the volume processed, the duration, the cost, the errors. | Check quality, correct errors, control costs. | Legitimate interest. | For as long as the account exists, and 3 years at most. |
| Support and calls | Exchanges by email or phone; calls booked online (name, email, phone, notes, source). | Reply, prepare and hold the call. | Legitimate interest; steps taken at the person’s request. | 3 years after the last contact. |
| The chat with Markus on the website | Messages written in the chat and Markus’s replies, the page and the language, the date; if the person chooses, their first name, email or phone number, and the proof of their consent (the text shown, the date and time). The IP address is only used for anti-abuse counters, in hashed form. | Answer questions about HelloMarkus, its modules and prices; offer the free audit or a call; get back to the person who asked; improve the answers. | The replies: legitimate interest (answering a request for information) and steps taken at the person’s request. Contact details kept to get back to the person: consent (box never ticked in advance, withdrawable at any time). | Without contact details: 30 days after the last message. With contact details and consent: the consent to be contacted is valid for 12 months; the conversation, the contact details and the proof of consent are deleted 3 years after the last exchange. In the browser: for as long as the tab is open. |
| Audience and usage measurement | Pages viewed, clicks, source, device, session recording (input fields masked); in the client area, the account email. | Understand what is useful and improve the website and the app. | Website and public pages of the app: consent (banner). Signed-in client area: legitimate interest in improving the service, with a right to object at any time. | Cookies: 13 months at most. Statistics: 25 months at most. |
| The HelloMarkus Observatory | Public data from the Google profiles of the businesses measured (name, address, rating, reviews and display name of their author), collected by a data provider. | Publish statistics by city, as totals, shares and medians, without naming any business or any person. | Legitimate interest (statistics and public information). | The detail is erased within 30 days; only the aggregates remain. |
The audit, call-back and Observatory data that is not provided by the person themselves comes from Google’s public pages (business profiles and reviews) and from the business’s website, collected by data providers. The data requested for the audit and the account is necessary to provide them; the consent boxes are optional.
4. AI and enquiry scoring
Markus relies on artificial intelligence models: Claude, from Anthropic, for writing, and Gemini, from Google, for images. Only the data needed for the task is sent to them (the business’s profile, a review and the display name of its author to reply to it, a prospect’s first name for a follow-up), under the contracts listed below.
An audit enquiry receives a score (hot, warm or cold), calculated from its answers and its audit, so that those who need it most are called back first. This score produces no legal effect and decides nothing on its own: a person from the team or the partner always decides what happens next. There is no fully automated decision within the meaning of article 22 of the GDPR.
When Markus interacts directly with a person, it says that it is an AI assistant.
In the website chat, Markus answers from the website’s pages and the catalogue prices, and says it is an AI from its first message. It never keeps contact details on its own: only the chat form does, when the person ticks the consent box.
5. Who receives the data
- The HelloMarkus team, each member for what they need.
- The partner (an agency or an integrator, “Partner × HelloMarkus”): it sees the audit, the contact details and the score of the people who came through its link, whom it may call back, and the follow-up of its clients. It is responsible for how it uses them.
- The processors listed below, each for its own task.
- The platforms connected by the client (Google, social networks), which receive what it publishes, and Google, which receives the profile searches made through its Places API; these services act under their own rules.
- The authorities, upon lawful request.
HelloMarkus neither sells nor rents any personal data.
6. Processors and transfers outside the EU
These providers process data for HelloMarkus, under contract, according to its instructions. When data leaves the European Union, the transfer relies on a safeguard provided for by the GDPR.
| Provider | What it does | Company and country | Where the data is | Safeguard outside the EU |
|---|---|---|---|---|
| Supabase | The database, accounts, files and server functions. | Supabase Pte. Ltd., Singapore | European Union (Ireland, Amazon Web Services) | Standard contractual clauses of the European Commission |
| Netlify | Hosting of the app: visitors’ IP addresses and logs. | Netlify, Inc., United States | United States and global delivery network | EU-US Data Privacy Framework, and standard contractual clauses |
| Hostinger | Hosting of the hellomarkus.ai website and of the websites created for clients: visitors’ IP addresses and logs. | Hostinger International Limited, Cyprus | European Union | Not applicable: established in the European Union |
| Stripe | Payment and subscriptions: name, email, billing address, card (entered at Stripe). | Stripe Payments Europe, Limited, Ireland | European Union and United States | EU-US Data Privacy Framework, and standard contractual clauses |
| Anthropic (Claude) | The AI that writes: audit, review replies (with the display name of their author), posts, follow-ups, and Markus’s replies in the website chat. | Anthropic Ireland, Limited, Ireland | United States (Anthropic PBC) | Standard contractual clauses of the European Commission |
| Google (Gemini) | The AI that creates images: the business’s logo and photos, the business name. | Google Cloud France SARL, France | European Union and United States | EU-US Data Privacy Framework (Google LLC), and standard contractual clauses |
| Google Analytics | Audience measurement on the website, only after your consent. | Google Ireland Limited, Ireland | European Union and United States | EU-US Data Privacy Framework (Google LLC), and standard contractual clauses |
| PostHog | Measuring use of the website and the app (page views, clicks, session recording) and the email of the signed-in account. | PostHog Inc., United States | European Union (Germany) | EU-US Data Privacy Framework, and standard contractual clauses |
| Resend | Sending emails: audit results, end of trial, follow-ups, reminders. | Plus Five Five, Inc., United States | United States | EU-US Data Privacy Framework, and standard contractual clauses |
| DataForSEO | Google’s public data for the audit, rank tracking and the Observatory, including reviews (display name of the author). | DataForSEO OÜ, Estonia | European Union (Germany) and United States | Standard contractual clauses of the European Commission |
| Make | The connection with clients’ Google profiles: reviews and their author’s name, replies, posts, statistics. | Celonis, Inc., United States | European Union or United States, depending on the account region | EU-US Data Privacy Framework, and standard contractual clauses |
| Cal.com | Booking calls: name, email, phone, notes, source. | Cal.com, Inc., United States | United States | EU-US Data Privacy Framework, and standard contractual clauses |
| Upload-Post | Publishing posts on clients’ social accounts. | Tonvi Tech SL, Spain | European Union | Not applicable: established in the European Union |
| Firecrawl | Reading the business’s website during the audit (its public content). | SideGuide Technologies, Inc., United States | United States | No safeguard published by the provider to date; only the public content of the audited website is sent to it, never any contact data |
| Bright Data | Reading the business’s public Instagram and TikTok profiles. | Bright Data Ltd., Israel | Israel | Adequacy decision of the European Commission (Israel) |
The EU-US Data Privacy Framework is the European Commission’s adequacy decision of 10 July 2023; the standard contractual clauses are those adopted by the Commission in 2021. A copy of these safeguards can be requested from contact@hellomarkus.ai.
7. Everyone’s rights
Everyone may, at any time and free of charge:
- access their data and obtain a copy;
- have it corrected or erased;
- restrict its processing, or object to it, in particular, and without having to give reasons, to prospecting;
- withdraw a consent given (call-back, offers by email, audience measurement), without affecting what was done before;
- receive the data they provided in a common format, to pass it on elsewhere;
- give instructions on what happens to their data after their death.
How. Write to contact@hellomarkus.ai; or click the stop link in every follow-up email; or, for cookies, click “Manage cookies” at the bottom of every page of the website. The answer arrives within one month (three at most for a complex request, with an explanation). If there is reasonable doubt about identity, proof may be requested.
Complaints. Anyone may lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online: cnil.fr.
9. Security
- Encrypted exchanges (HTTPS) and encrypted stored data, hosted in the European Union.
- Each business’s data separated in the database: an account only sees the businesses it is a member of.
- Team access limited to what is needed; passwords never stored in plain text.
- As little data as possible: the audit IP address erased at 30 days, the objection list kept in hashed form.
In the event of a data breach presenting a risk, HelloMarkus notifies the CNIL within 72 hours and, if the risk is high, the people concerned.
10. Changes
This policy may change, for example when a service or a provider changes. The date of the last update is at the top of the page; a significant change is announced to clients by email.