Legal
Privacy notice
This notice explains what personal data MaziFy processes when you visit mazify.io, ask for a demo or use the service, why we process it, how long we keep it, who helps us, and the rights you have.
1. Who we are
MaziFy is operated by [Company legal name], [Registered address] ("MaziFy", "we", "us"). MaziFy is a service that runs Instagram pages for its customers: it finds what matters in a niche, writes and fact-checks posts, designs them and publishes them through Instagram's official API.
We are the controller of the personal data of people who visit this site, ask for a demo, or hold a customer account. When we process personal data that appears in the content and audience of a page you connect (for example a comment on one of your posts), we do so on your behalf, as your processor, to provide the service you asked for.
Questions about this notice or your data: hello@mazify.io.
2. Data we process
Visitors to mazify.io
The public site sets no cookies, runs no analytics or advertising tags and loads nothing from third parties. To deliver pages, our servers necessarily receive your IP address and the details of each request. We do not keep access logs of the public site.
Demo requests
When you use the "Book a demo" form we store what you type into it: your name, work email, Instagram handle or website (optional), niche and message (optional), with the time you sent it. We do not store your IP address or browser details with your request. To stop abuse, the form's endpoint counts recent requests per IP address in the server's memory only; those counts are never written to disk or logs.
Customer accounts
If you become a customer we process your account data: your name and contact details, the sign-in credentials of your control room (a password hash and a two-factor secret, stored encrypted), the settings you choose, and records of the plan and fees we agreed.
Connected Instagram accounts
To publish for a page, you connect an Instagram professional account (Business or Creator) and grant MaziFy an access token through Meta. We store that token encrypted at rest, with a key kept outside the database, and use it only for the page you connected: to publish, to read the page's own insights and, if you turn it on, to moderate comments. We store the page's Instagram user id and handle.
Page content and insights
We store the posts, captions, images, carousels, stories and reels we prepare and publish for your page, the approvals and edits you make, and the insights Instagram reports for them (such as reach, views, likes, saves and shares). If comment moderation is on, we store the comments it reviews, including the commenter's username and the comment text.
Sources
We read the public sources configured for your niche (news sites, feeds and data providers) and keep the raw items we collect for up to 30 days. These are public publications, not data about you.
Logs
We keep operational logs and an audit trail of administrative actions (who changed what, and when), plus records of each AI call (model, size, cost and outcome) to run, secure and bill the service. Each sign-in to the control room records the IP address and browser it came from, to protect your account. We write these without the content of demo requests.
3. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Answer your demo request and arrange a demo | Demo request | Steps you asked for before a contract (Art. 6(1)(b)); our legitimate interest in replying to business enquiries (Art. 6(1)(f)) |
| Provide the service: create, check and publish content for your pages | Account, connected accounts, page content and insights, sources | Performance of our contract with you (Art. 6(1)(b)) |
| Keep the service secure and prevent abuse | Logs, audit trail, in-memory request counts | Legitimate interest in protecting the service and our customers (Art. 6(1)(f)) |
| Bookkeeping and legal obligations | Plan and fee records | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data, use it for advertising, or make decisions about you that have legal or similarly significant effects based solely on automated processing.
4. How long we keep it
- Demo requests: deleted automatically 12 months after you send them. Ask us and we delete yours sooner.
- Customer account, connected accounts, page content and insights: for as long as your account is active. When a page is disconnected or your account ends, we delete its data on request and at the latest within 30 days (see data deletion).
- Collected source items: 30 days.
- Backups: we keep the 30 most recent nightly backups (about 30 days), so deleted data leaves them within about that time.
- Plan and fee records: as long as tax and accounting law requires.
5. Sub-processors
We use a small number of providers to run MaziFy. Each processes personal data only on our instructions and only for the purpose below.
| Provider | What they do for us |
|---|---|
| Meta Platforms (Instagram Graph API) | Publishes the content you approve to your connected page and returns its insights and comments. |
| Anthropic | Provides the AI models that analyse sources, write and check captions and, if comment moderation is on, classify comments. Under its commercial terms Anthropic may not train its models on the content we send. |
| Cloudflare (R2 storage) | Stores rendered images and videos so Instagram can fetch them for publishing, and stores our nightly database backups (in which credentials stay encrypted). |
| Hetzner | Hosts the servers that run MaziFy, its database and this website. |
| Telegram | Delivers operational notifications to our team (including new demo requests) and, if you use it, your approval and report messages. |
| Sentry | Receives technical error reports, only if error reporting is enabled. Credentials are removed from every report before it is sent. |
| [Email provider] | Hosts our hello@mazify.io mailbox, where we answer demo requests, questions and data requests. |
We will update this list before we add or replace a sub-processor.
6. International transfers
Some of these providers process data outside the European Economic Area and the United Kingdom. Where they do, we rely on the safeguards the law provides, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
7. Security
- Instagram access tokens and other credentials are encrypted at rest, and never shown back in the control room, logs or messages.
- The control room requires a password and a two-factor code, uses secure session cookies, and asks for a fresh code before any credential changes.
- All traffic to MaziFy is encrypted in transit (HTTPS).
- Every administrative action is recorded in an audit trail.
8. Your rights
Under the GDPR and similar laws you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or send it to you or another provider in a portable format. Where we rely on your consent, you can withdraw it at any time.
Email hello@mazify.io from the address the request concerns, or tell us how we can confirm it's you. We answer within one month. You also have the right to complain to your local data protection authority.
If you are a follower or commenter of a page that uses MaziFy, the page owner decides how that page's data is used; we will pass your request to them and help them answer it.
9. Children
MaziFy is a business service. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, contact us and we will delete it.
11. Changes and contact
We will update this notice when our processing changes and show the date at the top. If a change affects customers materially, we will tell them before it applies.
Contact: [Company legal name], [Registered address], hello@mazify.io.