Mazzen

Legal

Privacy Policy

Operated by Venum Agency S.R.L. · Last updated: June 2026

1. Controller identity

The data controller for personal data processed through mazzen.net is: Venum Agency S.R.L. Str. Transilvaniei 52, Baciu, Cluj, Romania, 407055 CUI: 43350174 | J12/3833/2020 Email: contact@mazzen.net Venum Agency S.R.L. is registered with and subject to the supervision of the ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal), Romania's national data protection supervisory authority.

2. Legal framework

This Privacy Policy is drafted in compliance with: • Regulation (EU) 2016/679 (GDPR) • Legea nr. 190/2018 — Romanian law on GDPR implementation measures • Legea nr. 506/2004 — on electronic communications privacy

3. Data we collect

3.1 Account and identity data — Full name, email address, and company name (if applicable), collected at registration. 3.2 Usage and technical data — URLs and domains submitted for crawling or audit; audit queries, search inputs, and report history; IP address, browser type, device type, and operating system; session duration and feature usage patterns. 3.3 Payment data — Billing information is processed directly by Stripe, Inc. We do not store full card numbers or sensitive payment credentials. Stripe acts as an independent data controller for payment data they collect. 3.4 Communication data — Emails and support messages sent to contact@mazzen.net. 3.5 Cookies and tracking data — See the Cookie Policy for full details.

4. Purposes and legal bases

Where processing is based on legitimate interest, you have the right to object at any time. See Section 7 for your rights. Personal data is processed for: • Providing and maintaining the Service (contractual necessity) • Billing and subscription management (contractual necessity) • Security, fraud prevention, and abuse detection (legitimate interest) • Improving platform functionality and user experience (legitimate interest) • Complying with legal obligations (legal obligation)

5. Data storage and retention

5.1 Storage location — User data is stored on Supabase infrastructure located in West EU — Ireland (AWS eu-west-1). All data remains within the European Economic Area (EEA). 5.2 Retention periods — Account data is retained for the duration of the subscription plus 12 months after account closure. Audit reports and crawl data are retained according to your plan's storage limits. Payment records are retained for 5 years for tax compliance purposes. 5.3 — After the applicable retention period, data is securely deleted or anonymized.

6. Data sharing and third parties

We do not sell your personal data. We share data only with the following categories of processors, all bound by Data Processing Agreements (DPAs) ensuring GDPR-compliant handling: • Supabase — database and infrastructure hosting (EU) • Stripe, Inc. — payment processing • Google LLC — analytics (anonymized, consent-based) • Bright Data — web data infrastructure for crawling features • OpenAI / Google (Gemini) — LLM processing for Entity Audit outputs

7. Your rights under GDPR

As a data subject, you have the following rights: • Right of access (Art. 15) — request a copy of your personal data • Right to rectification (Art. 16) — correct inaccurate data • Right to erasure (Art. 17) — request deletion of your data • Right to restriction (Art. 18) — limit how we process your data • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format • Right to object (Art. 21) — object to processing based on legitimate interest, including analytics • Right to withdraw consent (Art. 7(3)) — for consent-based processing such as marketing emails • Right not to be subject to automated decision-making (Art. 22) — Mazzen does not make legally significant automated decisions about users To exercise any of these rights, contact us at contact@mazzen.net. We will respond within 30 days in accordance with Art. 12 GDPR.

8. Data breach notification

In the event of a personal data breach, Venum Agency S.R.L. will notify the ANSPDCP within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected users without undue delay, in accordance with Art. 34 GDPR.

9. Right to lodge a complaint

If you believe your data has been processed unlawfully, you have the right to lodge a complaint with: ANSPDCP — Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucuresti Website: www.dataprotection.ro

10. Data security

We implement appropriate technical and organizational measures including: • Encrypted data transmission (TLS/HTTPS) • Authentication controls and API key protection • Rate limiting and access controls • Regular security reviews of our infrastructure • Data minimization — we only collect what is necessary to deliver the Service

11. Children's data

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided data, it will be deleted promptly.

12. Changes to this policy

We may update this Privacy Policy periodically. Material changes will be communicated via email at least 14 days before taking effect. The latest version is always available at mazzen.net/privacy.