Read this first
MadeYouViral, referred to as “MadeYouViral”, “we”, “us” or “our”, is responsible for personal information processed for our own business purposes. We act as a controller when you visit our website, contact us, request a proposal, book a call, receive our marketing or become a client.
When we process personal information only on a client's documented instructions as part of a service, the client is normally the controller and MadeYouViral is normally a processor or service provider. The client's privacy notice and our written data processing terms apply to that processing.
This website is intended for businesses and adults. It is not directed to children. If a feature, provider or purpose described below is not currently enabled, the relevant processing begins only if and when that feature is activated and the required notice or consent is provided.
Who to contact
Privacy questions, rights requests and complaints can be sent to [email protected]. Use the subject “Privacy request”. You may also contact us through madeyouviral.com/contact.
For a formal legal notice that must be delivered by post, ask for our current notice address before sending it. If applicable law requires a representative or data protection officer, their details will be provided in the relevant collection notice or on request.
Scope
This policy covers visitors, prospective clients, clients, suppliers, business contacts, people who interact with our advertising or content, and people whose information is supplied to us by a client or authorised third party.
It does not govern an independent third party's website, platform or service. Their own terms and privacy notices apply when you leave our environment or use an integration operated by them.
Information we may collect
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact | Name, role, company, work or personal email, telephone number, billing or mailing address and social profile details. | You, your organisation, a referral, a public business source or an authorised partner. |
| Enquiry and qualification | Goals, challenges, budget range, timeline, preferred call time, website, campaign details and answers submitted through forms or chat. | You or someone authorised to enquire for your organisation. |
| Communications | Emails, call notes, chat messages, support requests, feedback and records of consent or preferences. | Your interactions with us and our communication providers. |
| Client and project | Contracts, proposals, briefs, approvals, credentials you choose to share, deliverables, account contacts, performance information and service history. | You, your team, connected accounts and authorised platforms. |
| Transaction | Invoices, payment status, tax information and limited payment references. Full card details are normally collected directly by a payment provider, not by us. | You, your organisation, banks and payment processors when enabled. |
| Device and usage | IP address, browser, device, operating system, language, approximate location derived from IP, referring URL, pages, timestamps, errors and security events. | Servers, security services, cookies and similar technologies. |
| Marketing and advertising | Campaign source, interactions, conversions, audience attributes, consent status and suppression preferences. | You, our website and advertising or analytics providers when enabled. |
| Public and third-party | Professional information, company details and content lawfully available from websites, social networks, directories, partners or data providers. | Public sources and third parties permitted to disclose it. |
| Derived information | Likely service fit, lead stage, preferences, campaign attribution and insights created from the information above. | Our analysis, automation and staff. |
We do not ask you to submit government identifiers, passwords, full payment card details or sensitive information such as health, biometric, genetic, political, religious or precise location data through ordinary website forms or chat. Do not place confidential, special category or sensitive personal information in the AI chat unless we specifically request it through an appropriate secure process.
Why we use information
| Purpose | UK and EEA lawful basis | What this includes |
|---|---|---|
| Respond and qualify | Steps requested before a contract and legitimate interests. | Responding to enquiries, assessing fit, preparing calls, proposals and recommendations. |
| Provide services | Contract, legitimate interests and legal obligation. | Onboarding, project delivery, support, reporting, account management, billing and record keeping. |
| Operate and secure | Legitimate interests and legal obligation. | Hosting, debugging, fraud prevention, access control, abuse detection, backups and incident response. |
| Communicate | Contract, legitimate interests or consent where required. | Transactional messages, service updates, appointment confirmations and requested follow-up. |
| Market responsibly | Consent where required and legitimate interests where permitted. | Relevant business marketing, audience measurement, advertising and suppression of people who opt out. |
| Improve and develop | Legitimate interests. | Understanding demand, improving journeys, testing features and developing products, services and content. |
| Comply and defend | Legal obligation and legitimate interests. | Tax, accounting, regulatory requests, legal claims, audits, sanctions screening and enforcing agreements. |
| Corporate activity | Legitimate interests and legal obligation. | Due diligence, financing, reorganisation, sale, acquisition or transfer of all or part of the business. |
Where we rely on legitimate interests, we consider the necessity of the processing and balance our interests against your rights. You may request information about a relevant assessment. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out lawfully.
AI chat and automation
Our live chat may send your question, recent conversation history, page URL and any qualification answers you provided to our n8n workflow and connected AI services. This is used to generate a response, route your enquiry and prepare human follow-up.
AI output may be incomplete or incorrect and is not a final professional commitment. We do not use the website chat to make a decision that produces legal or similarly significant effects without meaningful human involvement. Do not submit secrets, regulated data or information you lack authority to share.
Automated decisions and profiling
We may use limited automation to categorise an enquiry, identify a likely service, measure campaign attribution, prioritise follow-up or detect abuse. These activities support staff and do not, by themselves, determine eligibility for credit, employment, insurance or another legal right.
If we introduce solely automated decision-making with legal or similarly significant effects, we will provide a specific notice, explain the main logic and consequences, and provide any right to human review required by law.
Who may receive information
- Our team and contractors: authorised people who need the information for sales, delivery, support, finance, security or legal work and are subject to confidentiality duties.
- Cloudflare and infrastructure providers: DNS, proxying, security, content delivery, servers, databases, monitoring, backups and technical operations.
- Resend and communication providers: transactional email, enquiry confirmations and internal lead notifications.
- n8n and connected AI providers: workflow automation, chat routing, response generation and authorised business processes.
- Professional advisers: accountants, auditors, insurers, banks, payment providers, lawyers and consultants where necessary.
- Client-selected platforms: advertising, analytics, CRM, content, commerce, hosting or automation systems needed to deliver an agreed project.
- Authorities and claim participants: regulators, courts, law enforcement and counterparties where disclosure is legally required or reasonably necessary to protect rights, safety and security.
- Corporate transaction participants: prospective buyers, sellers, investors, lenders and advisers under appropriate confidentiality safeguards.
If enabled in the future, services such as Google Analytics, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, Stripe, PayPal or social sign-in may process information under their own notices. Non-essential analytics or advertising technology will be subject to consent or another valid legal basis where required. We do not authorise providers to use client confidential information for unrelated purposes.
Sale, sharing and targeted advertising
We do not sell personal information for money. Some privacy laws define “sale”, “sharing” or “targeted advertising” broadly enough to include disclosure through advertising cookies, pixels or audience tools. If we activate those tools, we will provide any required notice and opt-out control before using them.
Where legally required, we will recognise a valid Global Privacy Control signal as a request to opt out for that browser and device. We do not use sensitive personal information to infer characteristics or for cross-context behavioural advertising.
International transfers
Our providers, clients and team may process information in the United Kingdom, European Economic Area, United States and other countries. Privacy protections can differ between countries.
Where restricted by law, we use an approved transfer mechanism such as an adequacy decision, the UK International Data Transfer Agreement or Addendum, European Commission Standard Contractual Clauses, contractual protections, certification or another lawful safeguard. You may request information about the safeguard relevant to your data.
How long we keep information
| Record | Typical period | Reason |
|---|---|---|
| Enquiries, bookings and chat | Up to 24 months after the last meaningful interaction. | Follow-up, service history, quality, dispute prevention and suppression of unwanted contact. |
| Client and supplier records | During the relationship and normally 7 years after it ends. | Delivery, accounting, tax, audit, insurance and legal claims. |
| Payment and tax records | Normally 7 years, or longer if law requires. | Financial and legal compliance. |
| Security and server logs | Normally 30 days to 12 months, unless needed for an incident. | Security, diagnostics, fraud prevention and resilience. |
| Marketing records | Until consent is withdrawn, the purpose ends or the record becomes inactive under our review rules. | Relevant communication and proof of permission. |
| Suppression records | As long as reasonably necessary. | To remember and respect an opt-out. |
| Backups | Until overwritten under the backup cycle. | Business continuity and disaster recovery. |
These periods are starting points. We may keep information longer where a contract, legal hold, complaint, tax rule, regulator or active claim requires it, and may delete it sooner when it is no longer needed. We use the amount, nature, sensitivity, risk and purpose of the information to set a final period.
Security
We use risk-based technical and organisational measures designed to protect personal information. Measures may include encryption in transit, access controls, least-privilege permissions, authentication, backups, provider reviews, logging, patching, confidentiality duties and incident procedures.
No network, device, storage system or transmission is completely secure. You are responsible for using secure channels, protecting credentials and telling us promptly if you suspect unauthorised access. If a breach creates a legal notification duty, we will notify the relevant regulator and affected people as required.
Your privacy rights
Depending on where you live and the law that applies, you may have rights to be informed, access information, correct it, delete it, restrict processing, object, withdraw consent, receive portable data, opt out of sale, sharing, targeted advertising or certain profiling, limit use of sensitive information, and obtain human review of certain automated decisions.
You may also have the right to appeal a refusal, nominate an authorised agent, complain to a regulator and receive equal service without unlawful discrimination for exercising a right. Rights are not absolute and lawful exceptions may apply.
How to exercise a right
Email [email protected] with your name, contact email, country or state, the relationship you have with us and the right you want to exercise. We may request proportionate information to verify identity and authority. Do not send identity documents unless requested through a secure method.
We will acknowledge and respond within the period required by applicable law. This is commonly one month in the UK and EEA and 45 days under several US state laws, subject to lawful extensions. We normally do not charge a fee, but may charge or refuse a manifestly unfounded, excessive or repetitive request where law permits.
Regional disclosures
UK, EEA and Switzerland: you may contact the Information Commissioner's Office in the UK or the supervisory authority where you live or work. Our processing bases and transfer safeguards are described above.
California and other US states: the categories collected, sources, purposes and recipients are listed in this policy and cover the preceding 12 months. We do not discriminate for exercising a right. Where threshold and scope requirements apply, residents may use an authorised agent and appeal as provided by local law.
Canada: you may request access, correction or details of our accountability and consent practices and complain to the Office of the Privacy Commissioner or applicable provincial authority.
Brazil: data subjects may exercise rights under the LGPD, including confirmation, access, correction, anonymisation, portability where regulated, information about sharing, consent withdrawal and review where applicable.
Australia and New Zealand: where the relevant privacy law applies, you may request access or correction and complain to us before contacting the relevant privacy regulator.
Other regions: we will honour mandatory rights under applicable laws, including those in South Africa, Singapore, India and other jurisdictions, when their territorial and organisational scope applies to us.
Right to object
You have the right to object at any time to direct marketing. You may also object to processing based on legitimate interests, including related profiling. We will stop direct marketing when you object. For other objections, we will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims.
Use an unsubscribe control where provided or email [email protected]. Transactional or service messages that are necessary for an active relationship may continue.
Children
Our website and services are intended for people aged 18 and over and are not directed to children under 13 or the higher digital-consent age that may apply locally. We do not knowingly collect personal information from children through this website.
If you believe a child submitted information, contact us. We will investigate and delete it where required. A client must not provide children's information to us unless the processing is lawful, documented and covered by appropriate parental or guardian consent and safeguards.
Cookies and device storage
We use or may use cookies, local storage, pixels, tags and similar technologies for security, functionality, preferences, analytics and advertising. Strictly necessary technologies may operate without consent where law permits. Non-essential technologies are used only after the legally required choice.
Details, provider examples, purposes and controls are in our Cookie Policy.
Direct marketing
We may send marketing where you asked for it or where law permits relevant business communication. Every commercial email will identify the sender and include a practical opt-out method where required. We maintain a minimal suppression record after an opt-out so we do not contact you again by mistake.
We do not require consent to receive unrelated marketing as a condition of submitting a project enquiry. If a partner sends marketing for us, we remain responsible for ensuring the arrangement is lawful.
Client-supplied data
Clients must have a lawful basis, provide required notices and obtain required permissions before giving us personal information or granting access to a platform. Clients must not instruct us to scrape, enrich, target, email or profile people unlawfully.
Where we act as processor or service provider, processing is governed by the applicable contract or data processing addendum, including confidentiality, security, deletion, subprocessor and international-transfer terms.
Changes to this policy
We may update this policy when our services, providers, technology or legal obligations change. The date at the top identifies the current version. If a change materially affects how we use information already collected, we will provide additional notice and obtain consent where law requires it.
Previous versions may be requested by email. Continued website use does not replace consent where the law requires a separate affirmative choice.
Complaints
Contact us first so we can investigate. Explain what happened, the information involved and the outcome you want. We will handle the complaint fairly and will not retaliate for a good-faith privacy concern.
You may also complain to the regulator with authority where you live or work. UK users can contact the Information Commissioner's Office.