Legal

Privacy Policy

How My Marketing Mix handles personal data, customer content, integration data, cookies and AI-assisted processing across the platform.

Last updated: 28 June 2026Türkçe oku

1. Controller and scope

My Marketing Mix is operated by MAD CAT LABS YAPAY ZEKA VERİ BİLİMLERİ VE YAZILIM ANONİM ŞİRKETİ. Trade Registry No: 1140106; MERSİS: 0610168252400001.

Address: Seyrantepe Mah. Gökdeniz Sk. No: 15 İç Kapı No: 6 Kağıthane / İstanbul, Türkiye. You can contact us at [email protected] or +90 (212) 274 67 33 for privacy, personal data and account requests.

This policy covers our website, application, APIs, Strategy Lab, Asset Creation, Marketing Mix, reporting, support, integrations and related SaaS services.

2. Our role as controller and processor

We act as a controller for account administration, billing, user security, product usage, marketing preferences and support operations.

For campaign data, briefs, files, brand assets, integration data and marketing data processed on behalf of customers, we may act as a processor under the relevant agreement and customer instructions.

3. Sources of data

  • Directly from you: account creation, demo requests, contact forms, support requests, billing details, campaign briefs, file uploads, prompts, comments and feedback.
  • Automatically from your platform use: session records, IP address, device/browser data, security logs, error records, usage events, token renewal records and in-product activity history.
  • From integrations you connect: ad accounts, analytics accounts, CRM records, campaign performance, audience/segment data, file or design sources and connection permissions.
  • From corporate account administrators: workspace membership, roles, invitations, permissions, plan and subscription information.
  • From partners and service providers: payment confirmation, email delivery status, support records, security alerts and operational service logs.

4. Categories of data we process

  • Identity and contact data, including name, email, phone, company, role, team membership and authentication records.
  • Account and permission data, including workspace membership, roles, invitations, session records and security logs.
  • Customer content, including campaign briefs, chat messages, files, images, documents, brand assets, prompts, comments, revisions, outputs and reports.
  • Marketing and performance data, including campaigns, budgets, conversions, channel performance, CRM, analytics, ad account, marketing mix modeling data, scenario outputs and optimization recommendations.
  • Integration data from Google, Meta, LinkedIn, TikTok, Canva, HubSpot, Salesforce and similar services within the permissions you grant.
  • Technical data, including IP address, device and browser data, operating system, language/locale, logs, errors, security events, usage metrics, cookies and local storage records.
  • Commercial records, including plan, subscription, quote, contract, invoice, payment status, collection, requests and support records.
  • Communication and preference data, including product announcement preferences, email notifications, support correspondence, demo/event requests and marketing permissions.

5. Purposes of processing

  • Creating accounts, authenticating users, managing workspaces and enforcing permissions.
  • Providing Strategy Lab, Asset Creation, Marketing Mix, reporting, integration, automation and support features.
  • Generating AI-assisted briefs, analyses, creative assets, reports, recommendations and models.
  • Retrieving, syncing and visualizing data from advertising, analytics, CRM and creative production tools you connect.
  • Maintaining security, preventing abuse, debugging, measuring service quality and improving the product.
  • Managing billing, accounting, collection, contracts, legal retention and official requests.
  • Sending product updates, marketing communications and event invitations where permitted; operating essential session, security and in-product usage records.
  • Analyzing product performance, feature usage, capacity needs and service quality using aggregated or de-identified data.

6. Legal bases

  • Performance of a contract or steps taken before entering into a contract.
  • Compliance with legal obligations.
  • Establishment, exercise or defense of legal claims.
  • Legitimate interests, provided that rights and freedoms are not overridden.
  • Processing expressly provided by law.
  • Consent where required.

7. AI, automation and modeling

The platform may use AI systems for brief generation, strategy development, campaign analysis, creative production, reporting, image editing, OCR, marketing mix modeling and optimization recommendations.

Customer-provided content is technically processed to generate requested outputs, preserve project context, maintain workflows and run quality and security controls.

AI outputs may include advertising, budget, targeting, design, report or strategy recommendations. These outputs do not replace final decision-making; publishing, budget allocation and use on third-party platforms remain under the user's control.

We do not use personal data to make solely automated decisions that produce legal or similarly significant effects. If such a feature is introduced, appropriate notice, review and objection mechanisms will be provided.

8. Integrations and third-party services

For user-connected integrations, the scope of processing depends on the permissions granted on the relevant platform and in the integration settings. Removing an integration stops new data retrieval, but historical records may be retained where required for contracts, security or legal obligations.

Integrations may involve processing account names, campaign IDs, performance metrics, creative assets, audience/segment data, CRM records, report outputs or authorization tokens.

Third-party services may have their own privacy policies, security practices, retention periods and API rules.

9. Sharing and recipients

Data may be shared with cloud infrastructure, storage, email, notification, analytics, payment, support, security, AI model, integration providers, authorized public authorities and business partners only as required to provide the service.

For corporate accounts, company administrators may access user membership, roles, projects, activity, files, reports, support requests and billing information to manage the company account.

Data may be shared where required for legal obligations, official requests, audits, collection, contract performance, security review, merger/acquisition or corporate restructuring.

We do not sell personal information. When marketing technologies are enabled for cross-context behavioral advertising, retargeting or campaign measurement, those activities are handled under any preference/consent mechanisms required by applicable law and the disclosures in the Cookie Policy.

10. International transfers

The cloud infrastructure, integration providers, AI model providers, support tools or operational services used to provide the services may be located outside Türkiye. Personal data may therefore be transferred abroad or processed abroad to provide the services.

Where international transfers are required, we use safeguards under KVKK, GDPR and applicable laws, such as adequacy decisions, appropriate safeguards, standard contractual clauses, data processing agreements or consent where appropriate.

11. Cookies, local storage and tracking technologies

Cookies and similar technologies are used for login, refresh-token renewal, security, OAuth flows, language routing, remembering in-product preferences and preserving editor experiences.

When tools such as Google Analytics, Google Ads, Meta Pixel/CAPI, TikTok, LinkedIn, Yandex Metrica, Hotjar and similar technologies are enabled, the cookies, purposes and preference controls are explained separately in the Cookie Policy.

12. Retention and deletion

Personal data is retained for as long as necessary for the relevant purpose. Account data is retained while the account is active; billing records for statutory periods; logs for reasonable security periods; marketing permissions until withdrawn or as required by law.

Project, brief, file, chat, report and integration records may be retained while the account is active or as necessary to provide the contracted service. Account closure or deletion requests remain subject to legal retention obligations, dispute records, security logs and backup cycles.

When the retention purpose ends, data is deleted, destroyed, anonymized or restricted. Data in backups may remain during the ordinary backup cycle and is not otherwise processed unless restored to active systems.

13. Security

We apply reasonable technical and administrative measures such as access controls, role-based permissions, logging, monitoring, backup, encryption, secret management and vendor security review.

No internet-based system can guarantee absolute security. Users should use strong passwords, keep access permissions current and protect API keys and integration tokens.

14. Children's privacy

The services are not directed to persons under 18. We do not intentionally collect personal data from children.

If you believe personal data of a child has been submitted to the platform, contact us at [email protected]. After appropriate verification, deletion or access restriction will be assessed.

15. User controls and choices

You can manage account information, team memberships, integration connections, notification preferences and certain project content through the product interface.

You may remove integrations, clear browser cookies and site data, unsubscribe from marketing communications or submit data access/deletion requests through support.

For corporate accounts, certain deletion, export or access requests may depend on company-admin instructions, contracts and legal retention obligations.

16. Your rights

Under Turkish KVKK Article 11, you may request information, access, correction, deletion/destruction, notification to third parties, objection to automated analysis and compensation for unlawful processing.

Users in the EU/EEA may have GDPR rights to access, rectification, erasure, restriction, portability, objection and withdrawal of consent. Users under applicable US state privacy laws may have rights to know, access, delete, correct, opt out of certain sale/sharing activities, limit use of sensitive personal information and not be discriminated against for exercising rights.

We aim not to use sensitive personal data for purposes other than providing the service, maintaining security or meeting legal obligations unless a specific legal basis or consent mechanism applies.

17. Requests and complaints

You can send requests to [email protected] or to our registered address. Requests are handled within applicable legal timeframes and, for KVKK requests, generally no later than 30 days.

To respond to your request, we may need to verify your identity, account or authority to act. For requests submitted by an authorized representative, proof of authorization may be requested.

You may also contact the Turkish Personal Data Protection Authority, your EU/EEA supervisory authority or the relevant US state authority where applicable.

18. Updates

This policy may be updated due to changes in product features, integrations, legal requirements or operational processes. For material changes, reasonable notice methods will be used.