Skip to content

International Privacy Policy

Last updated 8 August 2026 · Version 1.0

This Privacy Policy explains how MapsDoc collects, uses, shares and protects personal information when you visit our website, request a Health Check, contact us, create an account or use our business-visibility services.

1. Who is responsible

The controller responsible for this processing is:

Daniel Effendy, operating under the MapsDoc brand Sole proprietor c/o Block Services Stuttgarter Str. 106 70736 Fellbach Germany Email: hello@mapsdoc.com

MapsDoc serves business customers. Account and business records can nevertheless identify owners, employees, contractors, reviewers and other individuals.

2. Scope and roles

This Policy applies where MapsDoc decides why and how personal information is processed, including website operation, sales, account administration, billing, security and our own business records.

When a customer instructs MapsDoc to process personal information for that customer—for example, contact data used in an approved review workflow—the customer is normally the controller/business and MapsDoc is its processor/service provider. That processing is governed by our Data Processing Addendum and the customer’s privacy notice.

This Policy does not govern third-party websites or platforms that publish their own privacy notices.

3. Information we collect

We may collect:

  • Identity and business information: name, role, company, business address, market, website, profiles and service locations;
  • Contact information: business email address, telephone number and communications preferences;
  • Account information: user ID, organization, authentication events, permissions and settings;
  • Inquiry and Health Check information: business details, goals, responses, diagnostic inputs and resulting recommendations;
  • Service information: connected profiles, listing data, reviews, content, approvals, Requests, Treatment Plans, reports, work history and manager communications;
  • Billing information: plan, billing address, transaction identifiers, payment status, tax information and invoice records; full card details are handled by the payment provider and are not stored by MapsDoc;
  • Communications: messages, support requests, meeting details, feedback and records of notices or consent;
  • Meeting recordings: audio, video and transcripts of Visibility Reviews or other meetings, but only after participants receive notice and any legally required consent is obtained;
  • Technical and usage information: IP address, browser, device, timestamps, pages or features used, referral data, security events, cookie choices and diagnostic logs;
  • Public business information: information from business websites, maps, directories, search results, social profiles, reviews and other public sources; and
  • Customer-provided information: material a business customer lawfully supplies for delivery of the service.

Please do not submit health records, patient data, payment-card numbers, government identifiers or other sensitive information through forms, Requests or content workflows.

4. Sources

We collect information directly from you; from authorized users and business customers; automatically from our website and service; from payment, authentication, hosting and communications providers; from connected platforms at your direction; and from public business sources.

5. Why we use information

We use information to:

  • respond to inquiries and deliver a requested Health Check;
  • evaluate and accept business-customer orders;
  • create, authenticate, secure and administer accounts;
  • provide visibility monitoring, profile care, content, review, listing, reporting and related services;
  • assign and support Visibility Teams and Visibility Managers;
  • process payments, taxes, invoices, renewals and cancellations;
  • send service, security, billing and operational communications;
  • provide support and investigate errors, abuse or security incidents;
  • maintain records, enforce agreements and comply with law;
  • improve the reliability, usability and quality of MapsDoc; and
  • send newsletters and other business marketing where recipients have separately opted in or another lawful basis applies, and respect unsubscribe or objection requests.

We do not sell personal information for money. We do not use personal information for cross-context behavioral advertising. If that changes, we will update this Policy and provide legally required choices before doing so.

6. Legal bases under GDPR

Because MapsDoc is established in Germany, GDPR applies to processing in the context of our establishment. Where GDPR applies, we rely on:

  • contract and pre-contract steps for account, order and service administration (Article 6(1)(b));
  • legal obligations for tax, accounting, sanctions, security and lawful requests (Article 6(1)(c));
  • legitimate interests in operating a secure B2B service, responding to business inquiries, preventing fraud, improving our service and limited business marketing (Article 6(1)(f)); and
  • consent where required for optional cookies, particular communications or another stated purpose (Article 6(1)(a)).

Where information concerns a customer’s business rather than an individual contracting personally, contract administration may instead rely on our legitimate interests and those of the customer.

7. How we disclose information

We disclose information only as reasonably necessary:

  • to personnel and contractors who need it and are bound by confidentiality;
  • to hosting, database, authentication, payment, email, scheduling, monitoring, analytics, support and fulfillment providers;
  • to platforms and directories you connect or authorize us to manage;
  • to professional advisers, auditors and insurers;
  • in a business reorganization, subject to appropriate confidentiality; or
  • to authorities or other parties where required by law or reasonably necessary to protect rights, security and users.

Our current subprocessor and provider information is published separately. Providers may process information as our processor, your processor, or an independent controller depending on the activity. We do not authorize providers to use customer data for their own advertising.

8. International transfers

MapsDoc operates from Germany and may use providers or serve customers in other countries. Information may therefore be processed outside the country where it was collected.

For transfers governed by GDPR, we use an available lawful mechanism such as an adequacy decision, the EU–US Data Privacy Framework for a certified recipient, or approved Standard Contractual Clauses with supplementary measures where required. Comparable contractual and due-diligence safeguards are used where Canadian, Australian or New Zealand transfer rules apply.

You may request information about the relevant safeguards at hello@mapsdoc.com.

9. Cookies and similar technologies

We use technologies strictly necessary to provide requested functions, maintain sessions, secure accounts, balance traffic and remember privacy choices. Optional analytics or other non-essential technologies are used only after any legally required consent.

The MapsDoc Cookie Policy provides current categories and controls. You can change optional choices through the cookie settings link where available. Browser blocking may affect essential functionality.

10. AI and automation

MapsDoc uses automation and artificial intelligence to assist monitoring, classification, research, recommendations, content and response preparation, media creation, reporting and quality workflows. Human judgment sets priorities and oversees customer service.

We do not make solely automated decisions about website users or customer representatives that produce legal or similarly significant effects. We do not intentionally use customer confidential information to train a publicly available model. Customer data is sent to an AI provider only where needed for an enabled service workflow and subject to appropriate provider terms and safeguards.

11. Retention

We keep information only for as long as reasonably necessary for the purposes above, including contract performance, security, dispute resolution and legal retention duties. Our general criteria are:

  • inquiries and unsuccessful Health Checks: normally up to 12 months after the last meaningful interaction;
  • waitlist records: until withdrawal, conversion or 12 months of inactivity;
  • accounts, service records and customer communications: for the contract and normally up to three years afterward, unless a longer claim period applies;
  • canceled-customer dashboard access and customer export availability: normally 30 days after service ends, after which the account may be closed and remaining records follow the applicable retention period;
  • meeting recordings and transcripts: normally up to 12 months after the meeting, unless a shorter period is requested or longer retention is needed for an active dispute or documented business requirement;
  • invoices, tax and accounting records: for the period required by German law;
  • security and diagnostic logs: normally 90–180 days, longer where needed for an incident;
  • abandoned checkout data: normally up to 30 days;
  • consent, objection and acceptance records: while needed to demonstrate and honor the choice; and
  • backups: deleted through the normal secured rotation cycle.

We delete or anonymize information after the relevant period unless continued retention is required or lawfully permitted. Customer-controlled data is also subject to the Data Processing Addendum.

12. Security

We use risk-appropriate technical and organizational measures such as access controls, least-privilege administration, tenant separation, encryption in transit, infrastructure encryption at rest, logging, backups, provider review and incident procedures. No online service is completely secure. Customers must protect their access methods and promptly report suspected unauthorized access.

13. Your choices and rights

Depending on where you live and which law applies, you may have rights to request access, correction, deletion, restriction, portability or information about use and disclosure; to object to certain processing; to withdraw consent; and to complain to a regulator. These rights can be subject to identity verification, legal exceptions and retention duties.

Where GDPR applies, Articles 15–21 provide rights of access, correction, deletion, restriction, portability and objection. Consent may be withdrawn at any time without affecting earlier processing. You may complain to a supervisory authority, including:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg Lautenschlagerstraße 20 70173 Stuttgart, Germany https://www.baden-wuerttemberg.datenschutz.de/

Residents of Canada may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial authority. Residents of Australia may contact the Office of the Australian Information Commissioner. New Zealand residents may contact the Office of the Privacy Commissioner. Applicable US state law may provide additional rights, described in the International Country Schedule.

Submit a request to hello@mapsdoc.com. We will not discriminate against you for exercising a legally protected privacy right. Authorized agents must provide evidence of authority. We may ask for information reasonably necessary to verify identity and locate records.

14. Marketing communications

Service, billing and security messages are not marketing and may be sent while necessary for the relationship. Marketing email will identify MapsDoc, provide required sender information and include an unsubscribe method. We honor withdrawals and objections as required by applicable law.

We do not treat the existence of a business email address as universal permission to send marketing. Outreach practices are configured by destination market. Customers using MapsDoc-supported outreach remain responsible for their own recipients, lawful basis and instructions.

15. Children

MapsDoc is a business service and is not directed to children. We do not knowingly solicit or create accounts for children.

16. Customer responsibilities

Business customers remain responsible for personal information they control, including providing notices, establishing a lawful basis, responding to rights requests, configuring outreach lawfully and avoiding unnecessary sensitive data. Where MapsDoc is a processor or service provider, the Data Processing Addendum applies.

17. Changes

We may update this Policy as our services, providers or legal obligations change. The current version and date will be posted here. We will provide appropriate notice before a material change takes effect where required.

18. Contact

Privacy questions, complaints and rights requests: hello@mapsdoc.com