Back to home

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Madspek ("Madspek," "we," "us," or "our") collects, uses, stores, and protects information across our services, including AI Readiness Audits, custom AI agent builds, secure data connections, customer support agents, and marketing/content automation agents. It applies to all Madspek clients and, where relevant, to end users who interact with systems or content we build or operate on a client's behalf.

Where a specific service involves distinct data practices — such as our Marketing & Content Automation Agents (Section 4) or engagements involving health information subject to HIPAA (Section 5) — this policy includes a dedicated section addressing that service specifically.

1. Who This Policy Covers

  • Clients who engage Madspek for AI agent consulting, development, or managed services across any industry (e.g., healthcare, retail, SaaS, professional services)
  • Authorized users at each Client organization who interact with tools or dashboards Madspek builds or operates
  • End users who interact with agents or published content Madspek operates on a Client's behalf, only to the limited extent described below

2. Information We Collect

From Clients directly

  • Business name, contact details, and account information
  • Workflow, data, and business context Clients share with us to design and build their AI agents (varies by engagement — e.g., patient communication content for a healthcare client, product/pricing information for a retail client)
  • Login credentials for any Madspek-built dashboard (stored securely; passwords are hashed, never stored in plain text)

Through connected systems and third-party accounts

Where an engagement requires connecting to a Client's existing systems (e.g., a CRM, a database, or social/business platform accounts), we receive and store only what's necessary to operate that specific integration, which may include:

  • API credentials, OAuth access tokens, and refresh tokens
  • Account identifiers for connected systems
  • Performance or usage data made available by connected platforms, relevant only to that Client's own systems

We do not request or retain more access than is necessary to perform the agreed engagement.

Generated automatically through our services

  • Content, drafts, edit history, and approval records generated through any Madspek-built workflow tool
  • System logs (timestamps, error logs, API request logs) used for troubleshooting and security monitoring

3. How We Use Information

We use the information described above solely to:

  • Design, build, and operate the AI agents and workflows a Client has engaged us for
  • Where applicable, generate content or actions on a Client's behalf, subject to that Client's own review and approval process
  • Retrieve relevant performance data to improve the specific engagement for that Client
  • Maintain security, prevent fraud, and troubleshoot technical issues
  • Communicate with Clients about their engagement

We do not sell Client data, and we do not use one Client's data to inform or benefit another Client's engagement.

4. Marketing & Content Automation Agents — Service-Specific Practices

For clients who engage Madspek's marketing/content automation agents (which draft, review, approve, and publish content to platforms such as Google Business Profile, Facebook, Instagram, and TikTok), the following applies specifically:

  • When a Client authorizes Madspek to connect their Google Business Profile, Facebook Page, Instagram Business account, or TikTok account, we receive and store OAuth access and refresh tokens, basic account identifiers (e.g., Page ID, Business Profile location ID), and performance metrics made available by each platform for that Client's own published content.
  • Content drafts are generated using the Anthropic Claude API; content submitted for drafting is processed to produce the requested output and is subject to Anthropic's own data handling terms.
  • Published content and connected account access are scoped entirely to the individual Client who authorized the connection — never shared or reused across other Clients.
  • A Client may revoke Madspek's access to any connected account at any time, both directly through that platform's own account settings and by notifying us.

5. Health Information and HIPAA

Some Madspek engagements involve clients who are "covered entities" under the US Health Insurance Portability and Accountability Act (HIPAA), such as healthcare providers, pharmacies, and hospitals. Where an engagement involves Madspek creating, receiving, maintaining, or transmitting Protected Health Information (PHI) on such a Client's behalf, Madspek enters into a Business Associate Agreement (BAA) with that Client, and handles such PHI in accordance with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

This does not apply uniformly across all engagements. For example, our marketing/content automation service (Section 4) operates on general business and marketing content — such as public pricing information and general educational content — and does not involve creating, accessing, or transmitting individual patients' health records or prescription data as part of that service. Where any future engagement expands to include patient-specific communications or PHI, a separate BAA is executed with that Client before such data is handled.

6. Third-Party Services We Use

Depending on the engagement, we may rely on the following categories of third-party providers, each governed by their own privacy and data-handling terms:

  • Google Business Profile API, Meta Graph API, and TikTok Content Posting API — used only for clients engaged in our marketing/content automation service, to publish content on their authorization
  • Anthropic Claude API and other AI model providers — used to power the agents we build across engagements
  • Cloud hosting and database providers — used to store Client information, credentials, and generated content securely

We only share the minimum information necessary with each provider to perform its specific function.

7. Data Storage and Security

  • Credentials and access tokens are stored encrypted at rest and in transit
  • Access to Client data within Madspek is restricted to authorized personnel who need it to deliver the engagement
  • We use industry-standard security practices, including access controls and monitoring, to protect against unauthorized access, alteration, or disclosure

No system can guarantee absolute security, but we take reasonable, industry-standard steps to protect the information we hold.

8. Data Retention

  • We retain Client information and connected account credentials for as long as the engagement remains active
  • Upon a Client's request to end an engagement, we will disconnect any integrations, revoke stored tokens, and delete Client-specific data within a reasonable period, except where retention is required for legal, security, or accounting purposes

9. Your Rights

Depending on your location, you may have specific rights under applicable data protection law, including the EU General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and US state privacy laws (e.g., California's CCPA/CPRA). Where applicable, these include the right to:

  • Access the information we hold about you
  • Correct inaccurate information
  • Request deletion of your data ("right to erasure"), subject to the retention exceptions noted in Section 8
  • Request a copy of your data in a portable format
  • Object to, or request a restriction on, certain processing of your data
  • Withdraw consent, where processing is based on consent, without affecting processing carried out before withdrawal
  • Revoke Madspek's access to any connected account at any time, directly through that platform's own settings, in addition to notifying us

Consistent with PIPEDA's accountability principle, Madspek maintains a designated point of contact responsible for data protection compliance, reachable via the details in Section 12.

To make a request, contact us using the details in Section 12. We will respond within the timeframe required by applicable law.

International Data Transfers

Madspek is headquartered in India. Where we process data belonging to Clients or individuals located in the EU, UK, US, or Canada, this may involve transferring data to, or processing data in, India or other countries where our service providers operate. Where required by applicable law, we take appropriate steps to safeguard such transfers (for example, through contractual protections with our service providers). Madspek's own governing law for its client agreements (see our Terms of Service) does not limit or override data protection rights you may hold under the law applicable to your own location.

10. Children's Privacy

Madspek's services are intended for use by business clients and their authorized personnel. Our services are not directed at, and we do not knowingly collect information from, individuals under the age of 18.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to active Clients, and the "Last updated" date at the top of this page will reflect the most recent revision.

12. Contact Us

If you have questions about this Privacy Policy or how your information is handled, contact us at kirtan@madspek.com.