Legal

Privacy Policy

MarginFix AI 7784 W. Virginia Road, New York, NY 10032 VAT 55037040 audits@marginfix.ai

01

What we collect

In plain English

Your contact details when you write to us, anonymous usage statistics on this site, and, only once you have hired us, the marketing and revenue data you choose to share.

Contact details you submit (name, email, company), usage analytics on this website, and, only within a contracted audit, read only marketing and revenue data you explicitly grant access to.

02

How we use it

In plain English

To answer you, to deliver the audit you bought, to send what you asked for, and to improve this site. No newsletter unless you ask for one.

  • To respond to enquiries and deliver contracted audits.
  • To send the specific materials you request (e.g. the sample report). No automatic newsletter enrolment.
  • To improve this website via aggregated, anonymized analytics.
03

Client audit data

In plain English

Your audit files stay in our own working environment. Anonymized information goes through the Claude API to help the analysis, none of it trains a model, a senior auditor approves every finding, and the data goes only to the processors listed on this page.

Audit files are maintained in MarginFix’s local working environment. Anonymized audit information is processed through the Claude API to assist analysis. Client data is not used for model training. A senior auditor reviews and approves every finding.

Access is read only and is revoked at your readout. Audit data is shared only with the processors listed in this policy, under contract, and is never sold. Working data is deleted from our systems within 30 days of engagement close, on the schedule below. Details, including the subprocessor table, are on the data security page.

04

How long we keep it

In plain English

Audit working files are deleted within 30 days of the end of the engagement, and any backup within 90. Enquiries that go nowhere are deleted after a year. Contracts and invoices are kept for seven years. Ask us to delete something and we acknowledge it within two business days and aim to finish within 30.

  • Audit access: revoked at the readout; any follow on work needs a new authorization.
  • Audit working data (raw exports, working files, prompts, drafts and our copy of the final report): deleted from our active systems within 30 days of engagement close, after your copies are delivered. Close means delivery or readout, or cancellation; a written extension names its purpose and its deletion date.
  • Backups: audit content is kept out of routine backups where we can; where a backup exists it is purged by 90 days after close, access to it is restricted, and deletions are reapplied after any recovery.
  • Provider copies: governed by the provider terms and their deletion mechanisms; deleting our copy does not by itself delete a provider’s.
  • Enquiries that do not become engagements: deleted after 12 months without meaningful contact, or earlier on request.
  • Contracts, NDAs, invoices and payment records: kept for seven years, subject to the requirements that actually apply to us; raw datasets and report content are never part of this record.
  • Disputes and legal holds: only the necessary records, access restricted, reviewed periodically and deleted when the reason ends.

Deletion requests: write to audits@marginfix.ai. We acknowledge within two business days, verify your identity in proportion to the request, and aim to complete within 30 days, subject to the deadlines and lawful exceptions above. We keep a minimal log of each deletion (engagement reference, categories, date, reviewer and any exception), never a copy of what was deleted. Where audit data is processed on a client’s behalf, individual requests are routed through that client where appropriate.

05

Your rights

In plain English

You can ask to see, fix, export or delete your data at any time by email. Californians and residents of other states with privacy laws have the same rights here; EU visitors keep their GDPR rights.

You may request access, correction, export or deletion of your personal data at any time: audits@marginfix.ai. California residents: under the CCPA/CPRA you may also opt out of “sale” or “sharing” of personal information (we do not sell or share it), and you will never be discriminated against for exercising these rights. Residents of Virginia, Colorado, Connecticut and other states with comprehensive privacy laws (VCDPA, CPA, CTDPA and successors) hold equivalent rights of access, correction, deletion and opt out; the same email honors them all, regardless of your state. EU/EEA visitors retain their GDPR rights, including lodging a complaint with a local supervisory authority.

06

Cookies and consent

In plain English

Nothing optional loads until you say yes on the banner. You can change your mind any time from Cookie settings in the footer.

On your first visit, a consent banner lets you accept or decline nonessential cookies, with equal prominence for both choices. Essential cookies (session, security, consent memory) always run. Analytics and advertising technologies load only after you consent, and you can change or withdraw your choice at any time via the “Cookie settings” link in the footer. We record your consent (choice, timestamp, banner version) as the CCPA and GDPR require; your choice is stored for 12 months.

07

Analytics and advertising partners

In plain English

With your consent we use Google Analytics, Microsoft Clarity and the Meta Pixel. LinkedIn is listed but not in use. Each one is listed with what it receives and how to opt out.

With your consent, we use the following third party technologies. Each receives usage data (pages viewed, events such as estimator use or booking steps, approximate location, device information) and sets cookies or similar identifiers:

  • Google Analytics 4 (Google Ireland Ltd.): site analytics. IP addresses are truncated/not logged by GA4 design; we have a data processing agreement with Google and do not enable Google Signals without separate consent. Opt out any time via cookie settings or the Google Analytics opt out add on.
  • Microsoft Clarity (Microsoft Ireland Operations Ltd.): session analytics, aggregated heatmaps and session replays with form input masking. Loads only after you consent to analytics; opt out any time via cookie settings.
  • Meta Pixel (Meta Platforms Ireland Ltd.): advertising measurement for our campaigns on Facebook and Instagram, loaded only after you accept optional cookies. You can withdraw consent at any time through Cookie settings. We operate under Meta’s data processing terms. Manage ad preferences at facebook.com/adpreferences.
  • LinkedIn Insight Tag (LinkedIn Ireland Unlimited Co.): not currently in use; if activated, B2B ad measurement and retargeting. Data is pseudonymized by LinkedIn and aggregated for reporting. Opt out at LinkedIn guest controls.
08

Processors and lawful bases

In plain English

The companies that handle data for us, what each does, where, and the legal ground we rely on. None of the optional tags loads before you consent.

The legal grounds we rely on to process data, per processor.

ProcessorPurposeLocation and transfer basisLawful basis
Netlify, Inc.Website hosting and form intakeGlobal CDN / US (DPF and SCCs)Contract and legitimate interest, Art. 6(1)(b)/(f)
Zoho CorporationCRM: lead records from form submissionsEU data center (crm.zoho.eu)Contract, Art. 6(1)(b)
Anthropic (Claude API)AI assisted analysis of anonymized audit informationPer provider termsContract, Art. 6(1)(b)
Google Workspace (Calendar and Meet)Call scheduling: booking invites and video callsEU/US (DPF and SCCs)Contract, Art. 6(1)(b)
Google Tag ManagerTag management (loads the analytics tags)EU/US (DPF and SCCs)Consent, Art. 6(1)(a)
Google Analytics 4Site analyticsEU/US (DPF and SCCs)Consent, Art. 6(1)(a)
Microsoft ClaritySession analytics (consent gated)EU/US (DPF and SCCs)Consent, Art. 6(1)(a)
Meta PixelAdvertising measurementEU/US (DPF and SCCs)Consent, Art. 6(1)(a)
LinkedIn Insight Tag (not currently in use)B2B ad measurement and retargetingEU/US (DPF and SCCs)Consent, Art. 6(1)(a)

These providers may transfer data to the United States under the EU to US Data Privacy Framework and/or Standard Contractual Clauses. We do not sell personal data, and we do not load any of these tags before consent. A current list of all subprocessors is available at audits@marginfix.ai.

09

Custom and matched audiences

In plain English

We do not build ad audiences from your contact details today. If that ever changes it will need your consent first, and you will be able to object.

We do not currently build matched advertising audiences from your contact data. If we ever do, it will happen only with your consent, using hashed contact data, and you will be able to object at any time at audits@marginfix.ai; we would then suppress your data from every audience list.

10

Contact

In plain English

One address for privacy requests and everything else.

MarginFix AI
7784 W. Virginia Road, New York, NY 10032, USA
VAT Number: 55037040
Privacy requests: audits@marginfix.ai · General: audits@marginfix.ai

Company details also appear in the Terms and Conditions.

Questions about this policy? Write to audits@marginfix.ai. A person answers within one business day.