LEGAL / PRIVACY

MARKETING PILOT - PRIVACY POLICY

Effective date: 22.07.2026 Last updated: 22.07.2026 Version: 1.0 Document language: English Status: Draft prepared for implementation verification and Romanian legal review

1. Who we are

Marketing Pilot is operated by:

  • Legal entity: MARKETPILOTAI S.R.L.
  • Trading name: Marketing Pilot
  • Registered office: str. Mihail Kogalniceanu, nr. 10-12, Albina, Braila, 817171, Romania
  • Company registration number: J2026043173002
  • VAT number: RO55141813
  • Website: https://www.marketingpilot.eu
  • General contact: office@marketingpilot.eu
  • Support contact: support@marketingpilot.eu
  • Privacy contact: office@marketingpilot.eu

For the personal data that we determine how and why to process, MARKETPILOTAI S.R.L. is the data controller.

In this Privacy Policy, “Marketing Pilot”, “we”, “us”, and “our” refer to MARKETPILOTAI S.R.L. References to “you” include visitors, account holders, business representatives, authorised users, prospective customers, support contacts, and other persons whose personal data we process.

Marketing Pilot is an AI-assisted marketing-content creation, campaign-planning, scheduling, and social-media publishing service. It is primarily intended for businesses and professionals.

2. Scope of this Privacy Policy

This Privacy Policy explains how we process personal data when you:

  • visit our website
  • create or use a Marketing Pilot account
  • sign in using email and password or a supported authentication provider
  • complete onboarding and create a Business Brain
  • upload prompts, business information, files, logos, images, or other media
  • generate text, images, campaigns, plans, or other AI Output
  • connect a Facebook, Instagram, LinkedIn, X, Google, or other supported account
  • schedule or publish Content
  • subscribe to a free or paid plan
  • communicate with support
  • participate in a referral, coupon, beta, or early-access programme
  • receive service, billing, security, legal, or marketing communications; or
  • otherwise interact with Marketing Pilot.

This Privacy Policy does not govern personal data processed independently by third-party platforms such as Meta, Google, LinkedIn, X, Stripe, or another provider. Their processing is governed by their own privacy notices and terms.

3. Our roles as controller and processor

Marketing Pilot may process personal data in different legal roles.

3.1 Marketing Pilot as controller

We generally act as controller for:

  • account registration and identity data
  • authentication and security
  • subscription and billing administration
  • customer support
  • service communications
  • product usage and internal analytics
  • fraud, abuse, and security prevention
  • legal compliance
  • management of our contractual relationship
  • optional direct marketing
  • website cookies and similar technologies under our control; and
  • our own business administration.

3.2 Marketing Pilot as processor

A Business User may place personal data about other people into prompts, uploaded media, business information, campaigns, posts, or other Content.

Where we process that personal data solely on the Business User’s documented instructions to provide the Service, the Business User is normally the controller and Marketing Pilot is normally its processor.

Examples may include:

  • a customer name included in a testimonial
  • a recognisable person appearing in an uploaded image
  • an employee’s name included in a planned post
  • a client contact included in business information
  • personal data included in a support attachment
  • personal data contained in a prompt or generated campaign; or
  • personal data scheduled for publication to a social platform.

Where Article 28 of the GDPR applies, the processing must be governed by a Data Processing Agreement. Business Users must not upload or instruct us to process third-party personal data unless an applicable Data Processing Agreement is in place and the Business User has a lawful basis and all necessary notices, permissions, and safeguards.

3.3 Independent or joint processing by third-party platforms

When you connect or publish to a Third-Party Platform, that platform may process personal data as an independent controller for its own purposes, including authentication, security, platform operation, content moderation, analytics, advertising, and compliance.

In limited situations, applicable law may treat us and a Third-Party Platform as joint controllers for a specific processing operation. Where that occurs, we will provide any additional information required by law and, where required, make the essence of the relevant arrangement available.

4. Personal data we collect

The personal data we collect depends on how you use the Service, the plan you select, the features you activate, and the permissions you grant.

4.1 Account and identity data

We may collect:

  • name
  • email address
  • password hash or authentication credential information
  • user identifier
  • account creation date
  • language
  • timezone
  • account status
  • role or administrative permission
  • profile settings
  • consent and policy-acceptance records
  • referral code
  • login method; and
  • age or eligibility confirmation where required.

We do not store your plain-text password.

4.2 Business and onboarding data

We may collect:

  • business name
  • industry
  • business description
  • business location
  • physical address
  • phone number
  • website
  • products or services
  • target audiences
  • audience segments and age ranges
  • marketing goals
  • brand voice
  • brand positioning
  • customer personas
  • pain points
  • value propositions
  • content pillars
  • calls to action
  • brand preferences; and
  • confirmation that you are authorised to represent the business.

Some business data may relate to an identifiable sole trader, founder, employee, contact person, or customer and may therefore be personal data.

4.3 Business Brain data

The Business Brain is a structured profile generated from information you provide. It may contain or infer:

  • brand summary
  • positioning
  • personas
  • customer characteristics
  • marketing goals
  • voice guidelines
  • content pillars
  • proposed calls to action
  • suggested messaging
  • business strengths or weaknesses; and
  • other structured marketing information.

The Business Brain is designed to profile a business or brand, not to make decisions producing legal or similarly significant effects about a natural person. You must not use it to make employment, credit, insurance, housing, education, healthcare, legal, or other high-impact decisions about people.

4.4 Prompts, Content, and AI data

We may process:

  • prompts and instructions
  • uploaded text
  • draft posts
  • generated captions
  • hashtags
  • calls to action
  • campaign plans
  • generated variants
  • translations
  • generated images
  • feedback and edits
  • approved and scheduled Content
  • publishing status
  • failure and retry information
  • moderation or safety flags
  • identifiers linking Inputs to Outputs
  • generation settings
  • model or provider selection
  • token or usage information; and
  • technical metadata required to create and deliver AI Output.

Prompts and Content may contain personal data if you include it. You should not include personal data unless it is necessary, lawful, and appropriate for the intended use.

4.5 Media-library data

We may process:

  • uploaded images
  • logos
  • graphics
  • file names
  • file type
  • dimensions
  • file size
  • descriptions
  • thumbnails
  • upload date
  • owner or account identifier
  • generated-media identifiers
  • image-generation settings; and
  • technical or embedded metadata contained in a file.

Uploaded images may reveal faces, locations, vehicle numbers, documents, device information, or other personal data. Before uploading media, you must review it and remove unnecessary personal, confidential, or location information.

4.6 Social-account connection data

When you connect a supported social account, we may receive or process:

  • platform user identifier
  • account or profile name
  • Page identifier
  • Page name
  • Instagram Business account identifier
  • LinkedIn member identifier
  • X account identifier
  • profile image or limited profile information
  • access token
  • refresh token where applicable
  • token expiry
  • permissions or scopes granted
  • connected account status
  • publishing destination
  • account eligibility information
  • platform API responses
  • post or media identifiers returned after publication
  • platform error messages; and
  • information needed to revoke or refresh a connection.

We process only the permissions and data reasonably required for the selected integration. Connecting an account does not give us ownership of the account.

4.7 Publishing and calendar data

We may process:

  • draft, scheduled, publishing, published, failed, or deleted status
  • selected platform
  • scheduled date and time
  • timezone
  • publication request
  • publication result
  • platform post identifier
  • retry history
  • error code
  • campaign identifier
  • calendar entry
  • user approval action
  • edit history where enabled; and
  • internal activity records.

A “Published” status may reflect a successful technical response from a platform. You should verify important publications directly on the relevant platform.

4.8 Subscription, transaction, and billing data

We may process:

  • plan
  • billing interval
  • subscription status
  • trial status
  • customer identifier
  • payment-provider identifier
  • transaction reference
  • invoice details
  • billing name
  • billing address
  • VAT number
  • currency
  • amount
  • tax information
  • coupon
  • payment status
  • renewal date
  • cancellation date
  • refund or chargeback information; and
  • limited payment-method metadata such as card brand and last four digits, where provided by the payment processor.

Payment providers process full card details under their own systems. We do not intend to store full payment-card numbers or card security codes.

4.9 Support and communications data

We may process:

  • name
  • email address
  • ticket category
  • ticket priority
  • subject
  • message content
  • attachments
  • replies
  • ticket status
  • diagnostic information
  • satisfaction feedback
  • service notices
  • billing communications
  • security communications
  • legal notices
  • marketing preferences; and
  • records of when a communication was sent, delivered, opened, or acted upon, where lawful and technically enabled.

4.10 Usage, device, log, and security data

We may process:

  • IP address
  • approximate location derived from IP
  • browser
  • device type
  • operating system
  • language
  • date and time
  • pages or screens viewed
  • actions taken
  • session identifier
  • login attempts
  • authentication events
  • referral source
  • error logs
  • API requests
  • rate-limit events
  • security events
  • suspected abuse
  • application performance
  • crash information
  • cookie or similar identifiers; and
  • administrative access logs.

4.11 Referral and promotional data

We may process:

  • referral code
  • referrer account identifier
  • referred account identifier
  • attribution date
  • eligibility status
  • coupon use
  • reward status
  • anti-fraud indicators; and
  • transaction information needed to validate a reward.

We should not disclose unnecessary information about a referred person to the referrer.

4.12 Data collected from other sources

We may receive personal data from:

  • Google or another authentication provider
  • Meta when you connect Facebook or Instagram
  • LinkedIn
  • X
  • a payment provider
  • an email or support provider
  • an analytics, security, fraud-prevention, hosting, or infrastructure provider
  • a referrer through a referral code
  • your employer, client, agency, or authorised representative
  • public authorities or professional advisers; and
  • another user where they include your data in Content.

Where Article 14 of the GDPR applies, we will provide the required information directly or rely on a lawful exception only where that exception genuinely applies.

5. Personal data we ask you not to provide

Marketing Pilot is not designed to collect or process unnecessary highly sensitive personal data.

Unless expressly agreed in writing and supported by an appropriate lawful basis and safeguards, do not provide:

  • health data
  • genetic data
  • biometric data used for identification
  • racial or ethnic origin
  • political opinions
  • religious or philosophical beliefs
  • trade-union membership
  • sex-life or sexual-orientation data
  • criminal-conviction or offence data
  • national identification numbers
  • passport or identity-card copies
  • payment-card numbers
  • passwords or authentication secrets
  • private keys
  • children’s data
  • confidential legal, medical, financial, or employment files; or
  • personal data that you are not authorised to use.

If you include such data despite this warning, that does not automatically make the processing lawful. We may block, restrict, quarantine, or delete Content where reasonably necessary for security, legal compliance, or protection of affected persons.

6. Why we process personal data and our legal bases

The applicable legal basis depends on the processing context.

Purpose | Typical data | Legal basis Create and administer an account | Identity, contact, account, settings | Performance of a contract or steps before entering a contract Authenticate users and maintain sessions | Authentication, device, log, security data | Contract and legitimate interests in securing the Service Complete onboarding and create the Business Brain | Business data, prompts, preferences | Contract Generate text, images, campaigns, and variants | Inputs, Content, settings, AI data | Contract; processor instructions where customer-controlled data is involved Store and manage media | Files, metadata, account identifiers | Contract Connect social accounts | Platform identifiers, tokens, permissions | Contract and your explicit connection instruction Schedule and publish approved Content | Content, calendar, social connection, publishing data | Contract and your publication instruction Process payments and subscriptions | Billing, transaction, tax data | Contract and legal obligations Issue invoices and maintain financial records | Billing, tax, transaction data | Legal obligation Provide support | Contact, ticket, account, diagnostic data | Contract and legitimate interests Send operational, billing, security, and legal messages | Contact, account, subscription, security data | Contract, legal obligation, and legitimate interests Send optional marketing | Contact and preference data | Consent where required; in limited cases legitimate interests or applicable existing-customer rules Maintain internal product analytics | Usage, event, device, account data | Legitimate interests; consent where cookies or similar technologies require it Prevent fraud, abuse, attacks, and unauthorised access | Log, device, account, security data | Legitimate interests and legal obligations Enforce Terms and protect legal rights | Account, Content, communication, transaction, log data | Legitimate interests and establishment, exercise, or defence of legal claims Comply with lawful requests | Relevant account, transaction, Content, and log data | Legal obligation Improve the Service | Usage, feedback, support, de-identified or aggregated information | Legitimate interests; consent where required Administer referrals, coupons, and trials | Referral, account, transaction, anti-fraud data | Contract and legitimate interests Manage corporate transactions | Relevant customer, contract, and business records | Legitimate interests, subject to confidentiality and legal safeguards

6.1 Contractual necessity

If processing is necessary to create or perform your account or Subscription, failure to provide the required data may prevent us from providing the relevant feature.

6.2 Legitimate interests

Where we rely on legitimate interests, those interests may include:

  • operating and improving the Service
  • securing accounts and infrastructure
  • preventing fraud and abuse
  • providing customer support
  • understanding feature usage
  • maintaining business and legal records
  • protecting users, third parties, and our rights
  • managing referrals and promotions; and
  • communicating with business contacts.

We will not rely on legitimate interests where your interests, rights, or freedoms override ours. You may object to processing based on legitimate interests as described below.

6.3 Consent

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.

Consent may be used for:

  • non-essential cookies or similar technologies
  • optional marketing
  • optional permissions that are not necessary for the core Service; and
  • another purpose clearly presented at the time consent is requested.

6.4 Legal obligations and claims

We may process data to comply with accounting, tax, consumer-protection, data-protection, cybersecurity, court, regulatory, or other legal obligations, and to establish, exercise, or defend legal claims.

7. AI processing

7.1 How AI features use data

When you use AI features, relevant Inputs may be transmitted to one or more AI-model or image-generation providers to create the requested Output. We may also process technical metadata needed to route, secure, meter, moderate, troubleshoot, and deliver the request.

AI processing may involve:

  • transforming business information into a Business Brain
  • generating or rewriting text
  • creating variants
  • translating Content
  • planning campaigns
  • generating images
  • suggesting subjects, angles, hashtags, or calls to action
  • applying safety filters
  • detecting technical failures; and
  • evaluating whether a request is permitted.

7.2 Human review

AI Output is probabilistic and may be inaccurate, fabricated, biased, offensive, unlawful, or unsuitable. Marketing Pilot does not make AI Output automatically true or legally compliant.

You must review all generated text and media before scheduling, publishing, or otherwise using it.

7.3 Model training and provider use

We will not intentionally authorise the use of Customer Content to train a general-purpose model unless:

  • the practice is clearly disclosed
  • an appropriate legal basis exists
  • contractual and security safeguards are in place; and
  • any required choice or consent is provided.

AI providers may process limited data for security, abuse monitoring, debugging, or legally required retention according to their terms and the configuration used by Marketing Pilot. The applicable provider configuration and retention must be reflected in our subprocessor records and contractual safeguards.

Do not assume that removing Content from Marketing Pilot automatically removes an Output that has already been copied, exported, published, or independently retained by a third party.

7.4 AI Output containing personal data

AI may generate names, likenesses, or other information relating to real or fictional persons. You must not treat generated personal data as verified.

You must not use Marketing Pilot to:

  • impersonate a person
  • create unlawful deepfakes
  • fabricate endorsements
  • create fake testimonials attributed to real customers
  • make high-impact decisions about individuals
  • publish sensitive personal data
  • create defamatory or deceptive personal claims; or
  • violate image, privacy, personality, or intellectual-property rights.

7.5 AI transparency

Where required by law or platform rules, AI-generated or manipulated Content must be labelled or disclosed. Marketing Pilot may provide technical or visible transparency features, but the user remains responsible for reviewing the final Content and applying any disclosure required for the intended use, audience, territory, and platform.

8. Automated decision-making and profiling

Marketing Pilot uses automation to generate Content, organise a Business Brain, apply plan limits, route requests, detect technical errors, and support security or abuse prevention.

We do not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning users within the meaning of Article 22 of the GDPR.

If we introduce such processing, we will provide additional information about:

  • the logic involved
  • the significance and expected consequences
  • the legal basis
  • available safeguards
  • human intervention
  • the ability to express a point of view; and
  • the ability to contest the decision.

Where an automated security or abuse control restricts access, you may contact support to request review, subject to security and legal limitations.

9. Cookies and similar technologies

We may use cookies, local storage, pixels, software development kits, or similar technologies.

9.1 Strictly necessary technologies

These may be used without consent where permitted because they are necessary for:

  • authentication
  • session management
  • security
  • fraud prevention
  • load balancing
  • saving privacy choices
  • maintaining the shopping or subscription flow; and
  • delivering a feature explicitly requested by you.

9.2 Preference technologies

These may remember:

  • language
  • timezone
  • interface preferences; and
  • other optional settings.

9.3 Analytics technologies

These may help us understand:

  • page visits
  • feature usage
  • errors
  • performance
  • conversion paths; and
  • service reliability.

Where consent is legally required, analytics technologies will not be activated before valid consent.

9.4 Marketing technologies

Marketing or cross-site tracking technologies will be used only where permitted by law and, where required, after consent.

9.5 Your choices

Where a consent-management interface is provided, you can:

  • accept or reject non-essential categories
  • make granular choices
  • change your choice later; and
  • withdraw consent as easily as it was given.

A separate Cookie Policy or consent interface should identify the actual technologies, providers, purposes, and lifetimes in use. Browser settings may also allow you to block or delete cookies, but doing so may affect functionality.

10. How we share personal data

We may share personal data only where reasonably necessary and lawful.

10.1 Service providers and subprocessors

We may use providers for:

  • cloud hosting
  • databases
  • storage
  • content delivery
  • authentication
  • AI text generation
  • AI image generation
  • automation and job processing
  • email delivery
  • customer support
  • payment processing
  • invoicing
  • analytics
  • consent management
  • error monitoring
  • cybersecurity
  • fraud prevention
  • backup
  • communications; and
  • professional services.

Processors may process data only under contractual instructions and confidentiality, security, deletion, and data-protection obligations.

Business Users may request the current subprocessor list from office@marketingpilot.eu. Where required by an applicable Data Processing Agreement, we will provide notice of material subprocessor changes.

10.2 Third-Party Platforms

When you connect or publish to a platform, we may transmit authorised Content and related data to:

  • Meta for Facebook and Instagram
  • LinkedIn
  • X
  • Google for authentication or another enabled Google service; and
  • another platform you deliberately connect.

The platform may receive personal data and process it under its own terms and privacy notice.

10.3 Payment providers

Billing and transaction information may be shared with Stripe or another authorised payment provider. Payment providers may act as independent controllers for some fraud-prevention, legal, and payment-processing activities.

10.4 Professional advisers

We may share relevant data with lawyers, accountants, auditors, insurers, banks, and consultants subject to confidentiality and legal duties.

10.5 Authorities and legal recipients

We may disclose data where reasonably necessary to:

  • comply with law
  • respond to a binding request
  • protect a person’s rights or safety
  • investigate fraud or security incidents
  • enforce our Terms
  • establish, exercise, or defend legal claims; or
  • cooperate with a competent regulator or court.

We will assess requests and disclose only data reasonably required, unless prohibited from doing so.

10.6 Corporate transactions

Data may be disclosed in connection with a merger, financing, acquisition, restructuring, insolvency, sale of assets, or transfer of the Service. We will apply confidentiality and data-protection safeguards and provide notice where required.

10.7 Public disclosure initiated by the user

Content you choose to publish may become public. Public Content may be copied, indexed, shared, downloaded, archived, or retained by third parties outside our control.

11. International data transfers

We are established in Romania. Some providers or Third-Party Platforms may process personal data outside Romania, the European Economic Area, or the country where you are located.

Where the GDPR applies and personal data is transferred outside the EEA, we will use an appropriate transfer mechanism, such as:

  • an adequacy decision
  • the European Commission’s Standard Contractual Clauses
  • another valid Article 46 safeguard
  • an applicable certification or framework recognised by the European Commission; or
  • a limited derogation under Article 49 where legally justified.

Where required, we will:

  • assess the legal and practical circumstances of the transfer
  • carry out a transfer impact assessment
  • adopt supplementary contractual, organisational, or technical measures
  • minimise the data transferred
  • use encryption or pseudonymisation where appropriate; and
  • monitor whether the transfer mechanism remains valid.

You may request information about the applicable safeguards by contacting office@marketingpilot.eu. Some contractual information may be redacted to protect security, confidentiality, or third-party rights.

12. Data retention

We retain personal data only for as long as reasonably necessary for the purposes described, including contractual, legal, accounting, security, dispute-resolution, and enforcement needs.

The following schedule reflects our intended default retention model and must be read subject to legal holds, mandatory law, platform requirements, active disputes, and technical backup cycles.

Data category | Intended default retention Account and profile data | For the life of the account, then normally deleted or anonymised within 30 days after an effective deletion request or final account termination Business onboarding and Business Brain data | For the life of the account or until deleted, then normally removed from active systems within 30 days Drafts, campaigns, prompts, generated Content, and media | Until deleted by the user or the account ends, then normally removed from active systems within 30 days Social access and refresh tokens | Until disconnection, expiry, revocation, or account termination, then disabled or deleted as soon as reasonably practicable Publishing history and technical status | For the life of the account and normally up to 3 years afterward where needed for support, disputes, platform compliance, and legal claims Subscription and billing records | For the contractual relationship and the legally required accounting and tax period, currently generally five years in Romania subject to statutory exceptions Support tickets | Normally 3 years after closure, longer where needed for an active dispute, security incident, or legal obligation Security, authentication, and application logs | Normally 12 months; selected records may be retained up to 24 months or longer for an active security investigation or legal claim Consent and policy-acceptance records | For as long as the relevant processing continues and normally 3 years afterward to demonstrate compliance Marketing preferences | Until withdrawal or suppression; evidence of consent and unsubscribe records may be kept for up to 3 years after the last relevant communication Referral and anti-fraud records | Normally for the programme and up to 3 years afterward, subject to accounting or dispute requirements Data-subject request records | Normally 3 years after the request is closed Backups | Normally overwritten or deleted within 90 days, unless isolated for a legal hold or security investigation De-identified or genuinely anonymous statistics | May be retained for longer where individuals are no longer identifiable

Deletion from active systems may not immediately remove data from encrypted backups. Backup data is not intended for normal operational access and will be deleted or overwritten according to the backup cycle. If a backup is restored, applicable deletion requests should be reapplied where technically and legally required.

We may retain minimal data necessary to:

  • prevent fraud or repeated abuse
  • maintain a suppression list
  • prove contract, consent, or compliance history
  • comply with legal obligations; or
  • establish, exercise, or defend legal claims.

13. Account deletion and social disconnection

13.1 Account deletion

You may request account deletion through any available account interface or by contacting support@marketingpilot.eu or office@marketingpilot.eu.

Account deletion and Subscription cancellation are separate actions. Deleting an account may not automatically cancel a payment arrangement if the cancellation process has not been completed.

Before deletion, you should export any Content you wish to retain.

13.2 Social disconnection

You may disconnect a platform through Marketing Pilot, the relevant platform, or both.

Disconnection may:

  • stop future publication
  • revoke or expire permissions
  • prevent token refresh; and
  • remove the connection from the active account.

Disconnection may not:

  • delete posts already published
  • cancel a request already accepted by the platform
  • delete records the platform must retain
  • remove copies created by other users; or
  • immediately erase all data from backup or platform systems.

For urgent removal of published Content, use the native platform controls.

13.3 Platform-originated deletion requests

Where a platform sends us a valid user-data deletion request, we will process it according to the applicable platform rules and law. We may provide a confirmation code or status page where required by that platform.

14. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

Measures may include, where appropriate:

  • encryption in transit
  • encryption at rest
  • password hashing
  • access controls
  • least-privilege permissions
  • separation of production and development access
  • secrets management
  • token protection
  • logging and monitoring
  • rate limiting
  • vulnerability management
  • backup and recovery procedures
  • incident-response procedures
  • supplier assessments
  • employee and contractor confidentiality
  • administrative access logging; and
  • periodic review of security controls.

No system is completely secure. You are responsible for:

  • using a strong, unique password
  • protecting your email and devices
  • enabling available security features
  • not sharing credentials
  • reviewing connected accounts
  • revoking access that is no longer needed; and
  • reporting suspected unauthorised access promptly.

Report a suspected security incident to support@marketingpilot.eu.

15. Personal-data breaches

We maintain procedures to assess and respond to suspected personal-data breaches.

Where required by the GDPR, we will:

  • notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a notifiable breach
  • inform affected persons without undue delay where the breach is likely to result in a high risk to their rights and freedoms; and
  • notify affected Business Users where we act as processor and the incident affects personal data processed on their behalf.

Notifications may be delayed or limited where law enforcement, security, confidentiality, or another lawful restriction applies.

16. Your data-protection rights

Subject to legal conditions and exceptions, you may have the right to:

  • Access: obtain confirmation and a copy of your personal data.
  • Rectification: correct inaccurate or incomplete personal data.
  • Erasure: request deletion of personal data.
  • Restriction: request that processing be limited.
  • Portability: receive certain data in a structured, commonly used, machine-readable format and request transmission where technically feasible.
  • Object: object to processing based on legitimate interests.
  • Object to direct marketing: object at any time to direct marketing, including related profiling.
  • Withdraw consent: withdraw consent at any time where processing relies on consent.
  • Automated-decision safeguards: request human intervention and contest a qualifying solely automated decision.
  • Complain: complain to a competent supervisory authority.
  • Judicial remedy: seek a remedy before a competent court.

These rights are not absolute. For example, we may retain data required by accounting law, needed for legal claims, or necessary to protect another person’s rights.

17. How to exercise your rights

Send requests to:

  • Email: office@marketingpilot.eu
  • Alternative support channel: support@marketingpilot.eu
  • Postal address: MARKETPILOTAI S.R.L., str. Mihail Kogalniceanu, nr. 10-12, Albina, Braila, 817171, Romania

Please describe the request and identify the account or interaction concerned.

We may ask for information reasonably necessary to verify identity and authority. We will not request more identity information than necessary.

We normally respond within one month. That period may be extended by up to two additional months for complex or numerous requests, in which case we will inform you of the reason.

Requests are normally free. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee or refuse to act where legally permitted.

If we process data only as processor for a Business User, we may refer the request to that Business User or assist it in responding.

18. Complaints

You may complain to the data-protection authority in the EEA country of your habitual residence, place of work, or place of the alleged infringement.

For Romania, the competent authority is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul General Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, Romania Website: https://www.dataprotection.ro Email: anspdcp@dataprotection.ro

We encourage you to contact us first so that we can attempt to resolve the issue, but you are not required to do so before contacting a supervisory authority.

19. Children

Marketing Pilot is intended for persons who are at least 18 years old or have otherwise reached legal majority in their jurisdiction.

We do not knowingly offer the Service directly to children or knowingly create accounts for children.

Do not upload personal data about a child unless:

  • it is strictly necessary
  • you have a valid legal basis
  • all required parental or guardian permissions and notices exist
  • the use is lawful and appropriate; and
  • the Service expressly permits it.

If you believe a child’s personal data has been provided unlawfully, contact office@marketingpilot.eu.

20. Direct marketing

We may send optional marketing communications only where permitted by law.

Marketing consent is separate from acceptance of the Terms or creation of an account where separate consent is required.

You can unsubscribe by:

  • using the unsubscribe link
  • changing available communication preferences; or
  • contacting office@marketingpilot.eu.

Unsubscribing from marketing does not stop necessary service, security, legal, or billing communications.

We may retain a minimal suppression record so that we do not send marketing after an unsubscribe request.

21. Business Users’ responsibilities

A Business User that provides personal data about another person must ensure that:

  • it is authorised to provide the data
  • a valid lawful basis exists
  • the data is accurate, relevant, and not excessive
  • required privacy notices have been given
  • any required consent has been obtained
  • special-category or criminal-offence data is not processed without a valid legal condition
  • image, privacy, personality, publicity, copyright, and confidentiality rights are respected
  • publication is lawful
  • the intended audience and territory are appropriate
  • the person’s data-protection rights can be respected
  • a Data Processing Agreement is in place where required; and
  • the instructions given to Marketing Pilot are lawful.

The Business User remains responsible for the personal data it chooses to publish. Once published, data may be processed independently by the selected platform and may become public.

22. Data accuracy

You should keep account, billing, business, contact, and social-connection information accurate and current.

AI-generated information is not verified personal data. Do not use AI Output to update a person’s records, make decisions about them, or publish claims about them without independent verification and a lawful basis.

23. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

  • legal or regulatory changes
  • new or changed features
  • new providers
  • new processing purposes
  • security improvements
  • changes to international-transfer mechanisms; or
  • clarification of existing practices.

The updated Policy will state a new effective date and version.

Where a change materially affects existing processing, we will provide notice as required by law. Where consent is legally required for a new purpose, we will request it before that processing begins.

We should maintain access to prior versions where reasonably necessary for transparency and compliance.

24. Language

This Privacy Policy may be available in Romanian and English.

The Romanian version is intended to be the reference version in the event of an inconsistency, to the extent permitted by applicable law.

This language clause does not reduce any mandatory transparency or data-protection right. Each published language version must remain clear, accurate, complete, and consistent. Where applicable law requires information in another language or protects a data subject based on the notice actually provided to them, those requirements remain unaffected.

25. Contact

For privacy questions, rights requests, complaints, or concerns:

  • Controller: MARKETPILOTAI S.R.L.
  • Privacy email: office@marketingpilot.eu
  • Support email: support@marketingpilot.eu
  • Address: str. Mihail Kogalniceanu, nr. 10-12, Albina, Braila, 817171, Romania
  • Website: https://www.marketingpilot.eu