Privacy Policy
Early Access notice. Maromel is currently offered as a limited closed beta to a capped group of business participants for evaluation and testing. Section 3 of this Policy describes the additional data practices, logging, human review and limitations that apply during the Early Access phase. If you are not willing to accept those terms, do not use the Service.
Contents
- Introduction and Scope
- Who We Are
- Closed Beta Programme
- Our Roles: Controller and Processor
- Information We Collect
- How We Use Information
- AI Processing and Sub-processors
- Sharing of Information
- Meta Platform Compliance
- Google API Services Compliance
- Publishing Modes and AI Transparency
- Human Oversight and Escalation
- International Data Transfers
- Data Retention
- Deletion Requests
- Data Security and Incident Notification
- Your Rights and End User Requests
- Cookies and Tracking
- Children's Privacy
- Third-Party Links
- Sensitive Personal Data
- Changes to This Policy
- Contact Us
- Annex A — Sub-processors
- Annex B — EU/UK/IL Legal Disclosures
1. Introduction and Scope
This Privacy Policy (the "Policy") describes how Maromel ("Company", "we", "us" or "our") collects, uses, stores, discloses and otherwise processes personal data in connection with our AI-powered social engagement and response platform (collectively, the "Service").
What the Service actually does. The Service connects, via official platform APIs and only with the permissions you grant, to your business accounts on Google Business Profile, Facebook Pages, and Instagram professional accounts (the "Supported Platforms"). It retrieves public reviews and comments, and private messages, and generates and publishes replies to them.
The Service does not scrape data outside official APIs and does not initiate contact with individuals who have not first contacted your business.
This Policy forms an integral part of our Terms of Use and, where applicable, our Data Processing Agreement ("DPA"). Where consent is the legal basis for a particular processing activity we will ask for it separately, and you may withdraw it at any time. If you do not agree with this Policy, do not use the Service.
2. Who We Are
The entity responsible for the processing described in this Policy is:
Legal entity: Maromel Operations
Mailing address: PO Box 123, Kokhav Ya'ir Tzur
Yigal, Israel
General contact:
hello@maromel.com
Privacy contact:
privacy@maromel.com
Security and vulnerability reports:
security@maromel.com
We are a small software company established and operating in Israel. All privacy enquiries, rights requests and complaints are handled directly by us at the privacy address above; we do not route them through third parties.
3. Closed Beta Programme
3.1. Scope of the Beta. The Service is currently made available only under a closed, invitation-based beta programme (the "Beta"), so that we can validate output quality, response accuracy, safety filters and platform integrations before general release. The Service may contain defects, may be interrupted, reset or reconfigured without notice, and may produce output that is inaccurate, incomplete, off-brand or factually wrong. We give no uptime, accuracy or availability commitment during the Beta. You should not treat the Dashboard as your only record of customer communications.
3.2. Enhanced logging. To diagnose defects and measure quality, during the Beta we retain a fuller record than we intend to retain at general release, including the prompt and configuration sent to the AI model, the model's raw output, any output suppressed or escalated by our safety filters, and whether you approved, edited or rejected a draft. Retention periods for these records are in Section 14.
3.3. Human review — public content. By enrolling in the Beta you affirmatively agree that a limited number of authorised personnel may access and read Interaction Content consisting of publicly visible material (Google reviews and ratings, Facebook and Instagram comments and mentions) together with the corresponding AI output, solely for quality assurance, defect diagnosis, safety-filter tuning and abuse prevention.
3.4. Human review — private messages. We treat private messages (Messenger, Instagram DM) as strictly confidential. Personnel will not read private message content unless: (a) you raise a specific support request that cannot be resolved without it; (b) it is necessary to investigate a security incident, fraud or abuse; (c) it is required by law or binding legal process; or (d) you explicitly opt in to private-message quality sampling using the dedicated control in the Dashboard, which is off by default and can be withdrawn at any time.
3.5. Safeguards for human review. Personnel performing review are bound by written confidentiality obligations, access is granted on a least-privilege basis, and every access to Interaction Content is logged with the identity of the accessing person and the reason for access. Those logs are available to you on request.
3.6. End of the Beta. We may end or suspend the Beta at any time. Unless you transition to a paid subscription, we will delete or irreversibly de-identify all Interaction Content and Beta logs associated with your account within thirty (30) days of the earlier of the end of the Beta or your withdrawal from it.
3.7. Feedback. If you send us feedback, bug reports or suggestions, you grant us a perpetual, worldwide, royalty-free licence to use them to improve the Service. Please do not include personal data of your customers in feedback.
4. Our Roles: Controller and Processor
4.1. Company as controller. We are the controller for the account, billing, usage, support and marketing data of our business customers and their personnel.
4.2. Company as processor. We act solely as a data processor for personal data of individuals who interact with your Connected Accounts — reviewers, commenters and message senders ("End Users") — including the content of their reviews, comments, mentions and direct messages and the associated metadata ("Interaction Content"). You are the controller of that data.
4.3. What that means for you. As controller of Interaction Content you are responsible for establishing a lawful basis for the processing, for giving End Users the privacy notice required by applicable law — including that replies may be generated automatically by AI — for obtaining any consent required in your markets, for handling End User rights requests, and for complying with the terms of each Supported Platform. Our DPA sets out the full allocation and applies automatically without signature.
5. Information We Collect
From you: account information (full name, business name, business email address, and password stored only as a salted hash); Configuration Data (brand voice settings, response rules, escalation rules, business facts, opening hours, FAQ content, product and service information); billing details where the Service is paid, collected by our payment processor — we never store full card numbers or CVV codes; and the content of your support correspondence with us.
From Connected Accounts: the account, Page, profile or location identifier, display name, profile picture, page category, the list of locations you administer, and the OAuth access and refresh tokens required to operate the Service. Tokens are encrypted at rest and are never displayed in the Dashboard or written to logs.
Interaction Content: review and rating text, comment and mention text, private message text and attachment references, together with sender display name or handle, profile picture URL, platform-scoped user identifier, conversation, message, post and review identifiers, delivery and read status, and timestamps. We do not request or receive End Users' email addresses, phone numbers, contact lists, location history or advertising identifiers.
AI input and output: the assembled prompt sent to the model (your Configuration Data plus the text of the item being answered) and the reply text returned, together with any safety-filter classification, suppression or escalation decision and the record of whether the output was published, edited or rejected.
Automatically: IP address, browser and device type, operating system, language, referring URL, pages and features used, session timestamps, error traces, and audit logs of which interactions were retrieved and answered, in which mode, at what time and on which channel.
6. How We Use Information
We process personal data to provide and operate the Service (authenticating you, retrieving interactions, generating drafts, publishing or sending approved replies, showing history in the Dashboard), to handle billing and keep the accounting records required by law, to provide support and diagnose defects, to detect and prevent fraud, abuse and security incidents, to improve the Service using aggregate statistics, to send service and security announcements, and to comply with legal obligations. We send marketing emails only with your consent, which you may withdraw at any time.
Interaction Content is ring-fenced. We use it only to provide the Service to the business whose Connected Account it came from, and to meet legal obligations. We do not use it for advertising, to build or enrich profiles of End Users, for our own marketing, or to benefit any other customer.
No AI model training on your data — unconditional. We do not use Interaction Content, Configuration Data, AI input, AI output, or any data obtained from Meta or Google APIs to train, fine-tune, retrain or otherwise develop any generalised or foundation AI model, whether our own or a third party's. This applies without exception, including to anonymised or aggregated derivatives of that content. Where we measure the Service's performance we use statistical counters that contain no content and no identifiers.
No automated decisions with legal effect. The Service generates and publishes text. It does not make decisions producing legal effects or similarly significant effects concerning any individual within the meaning of Article 22 of the GDPR, and must not be configured to make eligibility, pricing, credit, employment, insurance, housing or benefit determinations.
7. AI Processing and Sub-processors
7.1. The only AI provider we use. To generate replies the Service transmits AI input to OpenAI, L.L.C. through its commercial API. OpenAI is our sole AI sub-processor; we do not send your data to any other model provider. As at the date of this Policy, OpenAI's published API policies provide that data submitted through the API is not used to train or improve OpenAI's models, and that API inputs and outputs are retained for up to thirty (30) days solely for abuse monitoring before deletion, unless a longer period is required by law.
7.2. Data minimisation. We send the model only what it needs to draft the reply. We do not transmit access tokens, billing data, the data of any other customer, or End User platform identifiers.
7.3. Sub-processor obligations. Every sub-processor is engaged under a written contract imposing data protection obligations no less protective than those we owe you, restricting onward transfer, requiring appropriate security measures, and requiring deletion or return of the data on termination. We remain responsible for their performance. The current list is in Annex A.
7.4. Changes. We will notify you by email and by updating Annex A at least thirty (30) days before adding or replacing a sub-processor that processes Interaction Content. If you reasonably object on data protection grounds you may terminate the affected part of the Service without penalty.
8. Sharing of Information
We do not sell personal data, and we do not share it for advertising or cross-context behavioural advertising. We disclose personal data only: to the Supported Platforms, so that replies can be published or sent under your account and on your behalf; to OpenAI, as described in Section 7; to the infrastructure sub-processors listed in Annex A; to our professional advisers under duties of confidentiality; where required by applicable law, regulation or binding request from a competent authority, or to establish or defend legal claims; and in connection with a merger or sale of assets, subject to the recipient being bound by terms no less protective than this Policy.
We do not disclose personal data to data brokers, advertising networks, credit reference agencies or list vendors under any circumstances.
9. Meta Platform Compliance
9.1. Our receipt, use and storage of data obtained from Facebook, Instagram and Messenger ("Platform Data") is governed by the Meta Platform Terms and Developer Policies in addition to this Policy. Where those terms are stricter, they prevail. We use Platform Data solely to provide the user-facing features of the Service that are prominent in our Dashboard, as configured and authorised by you.
9.2. We do not:
- sell, license or purchase Platform Data;
- use Platform Data for advertising, ad targeting, ad measurement or retargeting;
- use Platform Data to build, augment or enrich profiles of individuals;
- use Platform Data — including private message content — to train or develop any generalised AI model;
- transfer Platform Data to any data broker, advertising network or monetisation platform;
- use Platform Data to determine eligibility for credit, insurance, employment, housing or education;
- combine Platform Data across unrelated customers, or use one customer's Platform Data to benefit another.
9.3. Human access. Personnel do not read Platform Data except in the limited circumstances set out in Sections 3.3 to 3.5.
9.4. Retention and deletion. We retain Platform Data only for as long as it serves the legitimate business purpose of operating the Service for you, in accordance with Section 14. We delete it as soon as reasonably possible when you disconnect the Connected Account, when you close your account, when an End User or Meta submits a valid deletion request, or when we cease operating the relevant feature.
9.5. Requesting deletion. You or an End User may request deletion of Platform Data through the Dashboard, through our deletion page at maromel.com/data-deletion, or by emailing privacy@maromel.com. We also operate a programmatic data deletion callback endpoint that receives and processes deletion requests initiated from Facebook or Instagram automatically, returning a confirmation code and a status URL. Timelines are in Section 15.
9.6. Revoking access. You may revoke the Service's access at any time from the Dashboard, on Facebook via Settings & Privacy → Settings → Business Integrations, or on Instagram via Settings → Apps and Websites. Revocation stops all further retrieval and publication immediately.
9.7. Automated experience disclosure. Consistent with Meta's messaging policies, conversations handled by an AI agent carry a disclosure that the recipient is interacting with an automated system, presented at the start of a thread, after a significant gap in the conversation, and on any handover from a human to the AI agent.
9.8. Messaging windows. The Service sends messages only in response to a message or action initiated by the End User and only within the standard messaging window permitted by Meta. It does not send promotional, re-engagement or broadcast messages, and does not use message tags to circumvent that window.
9.9. Security. We maintain a published channel for reporting security vulnerabilities at security@maromel.com, investigate reports promptly, and will notify Meta and affected customers of any incident involving unauthorised access to Platform Data in accordance with Section 16.
10. Google API Services Compliance
10.1. Maromel's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
10.2. Specifically, for data obtained through the Google Business Profile API:
- we limit our use of the data to providing and improving user-facing features that are prominent in the Maromel Dashboard — displaying your reviews and publishing the replies you have configured or approved;
- we do not transfer the data except as necessary to provide or improve those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition after obtaining your explicit consent;
- we do not allow humans to read the data except with your affirmative agreement for specific interactions (which Beta users give under Section 3.3), where necessary for security or to investigate abuse or fraud, to comply with applicable law, or where the data has been aggregated and de-identified for internal operations;
- we do not transfer or use the data for serving advertisements, including retargeting, personalised or interest-based advertising; we do not sell it; we do not transfer it to data brokers or advertising platforms; and we do not use it for credit-worthiness assessments;
- we do not use Google user data to train, fine-tune or develop generalised AI or machine-learning models.
11. Publishing Modes and AI Transparency
11.1. Two modes, configurable per customer and per channel. In Review & Approve Mode the AI agent prepares a draft and nothing is published or sent until a human authorised by you approves it; this is the default for new accounts during the Beta. In Autonomous Mode, where you enable it for a channel, the AI agent publishes or sends replies without item-by-item approval, within the rules and escalation thresholds you configured. Enabling Autonomous Mode requires an explicit confirmation in the Dashboard, which we log with the identity of the person who enabled it and the timestamp.
11.2. You are the publisher of record in both modes. All content published or sent through your Connected Accounts is published in your name, under your platform account, and on your authority. As between us, you are the author and publisher of that content and remain solely responsible for it, whether or not you personally reviewed the individual item and whether or not it was drafted by the AI. We act as a technical conduit executing your configuration.
11.3. AI transparency disclosure. Because the Service includes AI agents that interact directly with individuals in private messaging channels, the Service inserts a clear disclosure informing the recipient that they are interacting with an artificial intelligence system. The disclosure appears no later than the first interaction in a conversation, is repeated after a significant gap, and is repeated on any handover from a human to the AI agent. It is enabled by default. You may not disable it for interactions with individuals located in any jurisdiction whose law requires disclosure of automated or AI-generated communications, including the European Union, the United Kingdom and California; if you disable it elsewhere you do so on your own responsibility as the business operating the account. We are also working towards machine-readable marking of AI-generated text output as the relevant technical standards mature.
11.4. Accuracy of AI output. AI-generated text can be wrong. Output may misstate prices, availability, policies, entitlements or facts about your business, and may misread tone or intent. Output does not constitute a representation, warranty, offer or commitment by us. Where output creates a binding statement, that statement is yours.
12. Human Oversight and Escalation
12.1. Regardless of the mode selected, the Service is designed to withhold automated publication and route the interaction to your queue for human handling where it detects: reviews of one or two stars or strongly negative sentiment; allegations of injury, illness, food safety or physical danger; legal threats or demands for compensation above a threshold you set; content indicating self-harm, abuse or a person at risk; apparent data subject rights requests; content that appears to contain government identifiers, payment details or health information; signals that the sender may be a minor; discriminatory, harassing or hateful content; requests for regulated medical, legal or financial advice; and input the model cannot answer with sufficient confidence. These rules are configurable and we recommend leaving them enabled.
12.2. Where an End User asks to speak to a person, the Service stops automated replies on that conversation and marks it for human attention. You are responsible for staffing that queue.
12.3. You can pause all automation instantly, per channel or globally, using the kill switch in the Dashboard.
12.4. Best effort, not a guarantee. The classifiers, filters and escalation rules in this Section are quality-improving measures. They are probabilistic and will produce both false positives and false negatives. We do not warrant that they will detect every sensitive, unlawful or inappropriate interaction, and they do not replace your own oversight.
13. International Data Transfers
13.1. We are established in Israel, which benefits from a European Commission adequacy decision that the Commission reviewed and upheld in January 2024. Personal data may therefore flow from the EEA to us without additional safeguards. If that decision were amended, suspended or withdrawn we would put Standard Contractual Clauses in place and notify you.
13.2. Because cloud infrastructure and AI services are global, data is also processed in the United States and in the other locations listed in Annex A. For those transfers we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), the UK International Data Transfer Addendum, and, where the recipient is certified, the EU–US and UK–US Data Privacy Frameworks.
13.3. You may request a copy of the relevant transfer mechanism, with commercially sensitive terms redacted, by writing to privacy@maromel.com.
14. Data Retention
14.1. We keep personal data no longer than necessary. Unless a longer period is required by law, the following periods apply:
| Category | Retention period |
|---|---|
| Account and Configuration Data | Life of the account, then 30 days after closure |
| OAuth access and refresh tokens | Revoked immediately on disconnection; deleted within 7 days |
| Public Interaction Content (Google reviews, Facebook and Instagram comments and mentions) and the replies to them | 12 months from the interaction, or until disconnection or account closure, whichever is earlier |
| Private message content (Messenger, Instagram DM) and the replies to it | 90 days from the last message in the conversation, or until disconnection or account closure, whichever is earlier |
| AI input and raw AI output logs | 30 days, extended to 90 days during the Beta for defect diagnosis (Section 3.2) |
| Audit trail of approvals and rejections, and human-access logs | 12 months, retained without message content |
| Technical, security and error logs | 12 months |
| Support correspondence | 24 months from resolution |
| Invoices, billing and accounting records | 7 years, as required by Israeli bookkeeping and tax legislation |
14.2. Beta data. All Interaction Content and Beta logs are deleted within thirty (30) days of the end of the Beta or your withdrawal from it, unless you transition to a paid subscription, in which case the periods above continue to apply.
14.3. Backups. Encrypted backups are retained on a rolling thirty-five (35) day cycle. Data deleted from production is purged from backups by expiry of that cycle; we do not restore deleted data from backups except in a disaster-recovery event, in which case the deletion is re-applied.
14.4. Legal hold. We may retain specific data beyond these periods only where and for as long as necessary to comply with a legal obligation, respond to binding legal process, or establish or defend a legal claim. Data under legal hold is isolated, is not used for any operational purpose, and is deleted when the hold ends.
15. Deletion Requests
15.1. You can request deletion in the Dashboard (individual records, disconnecting a channel, or closing your account), through our deletion page at maromel.com/data-deletion, by emailing privacy@maromel.com, or — for Facebook and Instagram — through our data deletion callback endpoint, which processes requests initiated from those platforms automatically.
15.2. Timelines. We acknowledge requests within five (5) business days, complete deletion from production systems within thirty (30) days, and purge the data from backups by expiry of the cycle described in Section 14.3. Where a request is complex we may extend by a further thirty (30) days and will tell you why.
15.3. What we cannot delete. We cannot remove content from the Supported Platforms themselves. A review on Google, a comment on Facebook or Instagram, and the messages in a Messenger thread continue to exist on those platforms after we delete our copy; only the platform or the account holder can remove them there. We also cannot delete data we are legally required to retain under Section 14.4.
15.4. Effect of disconnection. Disconnecting a Connected Account immediately stops all retrieval and all publication on that channel, revokes and deletes the stored tokens, and starts deletion of the associated Interaction Content.
16. Data Security and Incident Notification
16.1. We maintain technical and organisational measures including: TLS 1.2 or above for all data in transit and AES-256 encryption at rest; OAuth tokens held in a dedicated secrets manager with separate key management, never in source code or logs; role-based access control on a least-privilege basis with multi-factor authentication for production access; logical separation of each customer's data with tenant-scoped authorisation on every request; centralised audit logging of administrative and data access; code review, dependency and secret scanning; encrypted backups with tested restoration; a written incident response plan; and written confidentiality undertakings and security training for all personnel with access to personal data.
16.2. We maintain the documentation required of a database holder under the Israeli Protection of Privacy Regulations (Data Security), 5777-2017, including the information security procedure, systems mapping, access register and incident register.
16.3. Notification to you. Where we become aware of a personal data breach affecting Interaction Content or your own data, we will notify you without undue delay and in any event within seventy-two (72) hours, describing the nature of the incident, the categories and approximate volume of data and individuals affected, the likely consequences, the measures taken, and a contact point. Where the full picture is not yet available we will provide information in phases rather than delay the first notification.
16.4. Your obligations. Where we act as processor, you as controller are responsible for assessing whether the incident must be notified to a supervisory authority or to affected End Users, and for making that notification. We will provide the information and assistance you reasonably need.
16.5. Notification to authorities and platforms. Where we act as controller we will notify the competent supervisory authority within seventy-two (72) hours where the breach is likely to result in a risk to individuals' rights, and will notify the Israeli Privacy Protection Authority of a severe security incident where required under Israeli law. We will notify Meta and Google of incidents affecting data obtained through their APIs.
16.6. We maintain a public security reporting channel at security@maromel.com and an internal register of all personal data breaches, including those we assess as not notifiable together with the reasoning.
16.7. No absolute guarantee. No method of transmission or storage is completely secure. While we use commercially reasonable means to protect personal data, we cannot guarantee absolute security.
17. Your Rights and End User Requests
17.1. Depending on your jurisdiction, you have the right to be informed about our processing, to access the personal data we hold about you and receive a copy, to have inaccurate or incomplete data rectified, to have your data erased where a ground in applicable law applies, and to have processing restricted in defined circumstances.
17.2. You also have the right to data portability — to receive the data you provided in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible; the right to object to processing based on our legitimate interests, and to object to direct marketing at any time and without justification; the right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; the right not to be discriminated against for exercising your rights; and the right to lodge a complaint with a supervisory authority — the Israeli Privacy Protection Authority (הרשות להגנת הפרטיות), your local Data Protection Authority in the EEA, or the UK Information Commissioner's Office, as applicable. You also have the right to an effective judicial remedy.
17.3. How to exercise them. Write to privacy@maromel.com or use the controls in the Dashboard. We verify your identity using information already associated with your account and will not request more data than necessary to do so. We respond within thirty (30) days, extendable by a further thirty (30) days for complex requests with notice to you. We do not charge for responding unless a request is manifestly unfounded or excessive, in which case we will tell you the fee before proceeding. You may use an authorised agent, with written proof of authorisation.
17.4. End Users. If you left a review, posted a comment or sent a message to a business that uses Maromel, that business is the controller of your personal data and is the right first point of contact. You may nevertheless write to privacy@maromel.com or use maromel.com/data-deletion. Within five (5) business days we will identify the relevant business, forward your request to it and assist it in responding; where we can act on a deletion request in our own systems without instruction we will do so within thirty (30) days and confirm to you. As explained in Section 15.3, we cannot remove your review, comment or message from Google, Facebook or Instagram. Nothing in this Section limits your right to complain directly to a supervisory authority.
18. Cookies and Tracking
18.1. We use strictly necessary cookies for authentication, session management, security and remembering your preferences. These are required for the Service to function and cannot be disabled without preventing you from logging in.
18.2. We run no advertising, retargeting or interest-based advertising tags anywhere in the Service. Where we introduce analytics or other non-essential technologies, we will not set them for visitors in the EEA or the UK until you have given consent through a consent banner, granular by category and as easy to refuse as to accept, withdrawable at any time. We honour the Global Privacy Control signal.
18.3. You can also block or delete cookies in your browser settings.
19. Children's Privacy
19.1. The Service is a business tool and is not directed to children. We do not knowingly permit anyone under eighteen (18) to register as a user.
19.2. Because End Users reach your business through public platforms, we cannot verify their age, and a review, comment or message may originate from a minor. We do not knowingly process personal data of minors and we do not profile End Users. Where the Service detects signals that a sender may be a minor, the interaction is escalated for human handling under Section 12.1.
19.3. You must not use the Service on any account whose audience is primarily children, and must not configure the AI agents to solicit personal data from anyone who may be a minor. If you believe we hold personal data of a child, contact privacy@maromel.com and we will delete it promptly.
20. Third-Party Links
The Service links to and integrates with third-party platforms, including Google, Facebook, Instagram and Messenger. We do not control them and are not responsible for their content, practices or privacy policies. Your use of a Supported Platform is governed by that platform's own terms and privacy policy, which you should read.
21. Sensitive Personal Data
21.1. Unless we have agreed otherwise in writing, you must not input, upload or configure the AI agents to solicit: government identifiers (Israeli teudat zehut, national ID, passport or driving licence numbers); financial credentials (full card numbers, CVV codes, bank details, PINs or passwords); biometric data used for identification; special categories of data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, health or psychological data, sex life or sexual orientation; or precise location and criminal record data.
21.2. Unsolicited sensitive data. End Users sometimes volunteer sensitive information in a review, comment or message. Where our filters detect such content the interaction is escalated for human handling under Section 12.1 rather than answered automatically. Because detection is probabilistic, you remain responsible for monitoring your channels and handling such cases appropriately, including by pausing automation.
21.3. We do not infer characteristics. Where sensitive information reaches the Service, we use it only to generate or route the specific reply being handled and to escalate it. We do not use it to infer characteristics about the individual, do not add it to any profile, and do not retain it beyond the periods in Section 14.
22. Changes to This Policy
22.1. We may update this Policy to reflect new features, additional Supported Platforms, changes to sub-processors or changes in law. We will post the updated Policy at this URL and change the version number and "Last Updated" date.
22.2. Where a change materially reduces your rights or materially expands our use of personal data, we will notify you by email at least thirty (30) days before it takes effect, and where the law requires consent we will ask for it rather than rely on notice.
22.3. Previous versions are available on request from privacy@maromel.com.
23. Contact Us
Privacy questions, rights requests and complaints:
privacy@maromel.com
Security and vulnerability reports:
security@maromel.com
General enquiries:
hello@maromel.com
Postal: PO Box 123, Kokhav Ya'ir Tzur Yigal, Israel
Annex A — Sub-processors
The following third parties process personal data on our behalf to operate the Service. This list is current as at the "Last Updated" date. Transfers outside Israel and the EEA are governed by Standard Contractual Clauses and, where the recipient is certified, Data Privacy Framework certification.
| Sub-processor | Function | Data | Location |
|---|---|---|---|
| OpenAI, L.L.C. | AI text generation — sole AI provider | AI input and AI output only | United States |
| Vercel Inc. | Application hosting and compute | All categories | United States |
| Supabase Inc. | Database and encrypted storage | All categories | United States |
| Resend Inc. | Transactional and security email | Name, email address, notification content. No Interaction Content. | United States |
Meta and Google are not sub-processors. They are independent controllers in respect of their own platforms; we exchange data with them through their APIs at your instruction, and their handling of that data is governed by their own terms and privacy policies.
Annex B — EU/UK/IL Legal Disclosures
Israel. We process personal data in accordance with the Protection of Privacy Law, 5741-1981, as amended by Amendment No. 13 which entered into force on 14 August 2025, and the Protection of Privacy Regulations (Data Security), 5777-2017. We are the owner of the database (בעל מאגר) for User Data and a holder (מחזיק) for Interaction Content. When we collect personal data directly from you we tell you whether provision is voluntary or required, the consequences of not providing it, the purposes of use, to whom it will be disclosed, and your right to inspect and correct it — this Policy together with the notices in our registration and connection flows constitutes that notice. You have the right under sections 13 and 14 of the Law to inspect the data held about you and to request correction or deletion of data that is incorrect, incomplete, unclear or out of date; we respond within thirty (30) days. We do not use personal data for direct mailing within the meaning of the Law. We assess at least annually whether our databases trigger the registration or notification duties under the Law and comply with whichever applies. Nothing in this Policy derogates from any mandatory right under Israeli law.
EEA and United Kingdom (GDPR). Our legal bases are: performance of a contract (Art. 6(1)(b)) for providing the Service, operating the AI agents and managing your account; legal obligation (Art. 6(1)(c)) for accounting, tax and regulatory records; legitimate interests (Art. 6(1)(f)) for security, fraud and abuse prevention, defect diagnosis and aggregate product analytics — for which we have carried out and documented a balancing assessment, available on request; and consent (Art. 6(1)(a)) for marketing communications and for private-message quality sampling under Section 3.4, withdrawable at any time. Where we process Interaction Content we do so strictly as an Article 28 processor under our Data Processing Agreement, which contains the mandatory Article 28(3) terms. We maintain records of processing under Article 30 and a data protection impact assessment covering the AI processing of communications content, the relevant parts of which we will share to support your own assessment as controller. We do not carry out solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22. Transfers are addressed in Section 13. Your rights, including the right to lodge a complaint with a supervisory authority, are set out in Section 17.