Madcraft Inc. EU-U.S. Data Privacy Framework Privacy Notice

Proposed Effective Date: Jul 31, 2026

1. Scope of This Notice

This Data Privacy Framework Privacy Notice (“DPF Notice”) supplements Madcraft Inc.’s general Privacy Policy and describes how Madcraft Inc. (“Madcraft,” “we,” “us,” or “our”) protects personal data received in the United States from the European Union in reliance on the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”).

This DPF Notice applies only to Madcraft Inc. and to personal data other than human resources data. It does not cover employee or other human resources data transferred in the context of an employment relationship. Where this DPF Notice conflicts with Madcraft’s general Privacy Policy, this DPF Notice governs the processing of personal data covered by the EU-U.S. DPF.

2. EU-U.S. Data Privacy Framework Commitment

Madcraft Inc. complies with the EU-U.S. Data Privacy Framework as set forth by the U.S. Department of Commerce. Madcraft Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. If there is any conflict between the terms of this DPF Notice and the DPF Principles, the DPF Principles shall govern.

Information about the EU-U.S. DPF, including the DPF Principles and Madcraft’s certification after it becomes effective, is available through the Data Privacy Framework Program website.

3. Madcraft’s Roles

Madcraft may process covered personal data as a controller for its own business operations and as a processor or service provider on behalf of its clients. When Madcraft processes personal data on behalf of a client, it does so in accordance with that client’s instructions, the applicable services agreement and data-processing terms. Individuals may also direct requests to the relevant client where that client controls the data.

4. Personal Data Covered

Depending on the relationship and services involved, covered personal data may include names and business contact details; employer, job title and professional information; client and prospective-client information; account and login information; emails, correspondence and meeting information; project and support-request information; website submissions and form data; IP addresses, device identifiers, browser information, cookies and similar identifiers; website usage and analytics information; approximate location derived from IP address; marketing preferences; billing and transaction information; and personal data supplied by clients for processing through websites, portals, applications or other digital platforms.

Madcraft does not intentionally request health or medical information, government identification numbers, biometric information, precise location information, information about children or other sensitive personal data for its ordinary business purposes.

5. Purposes of Processing

Madcraft may process covered personal data to provide digital strategy and professional services; design, develop and operate websites, portals, applications and digital platforms; provide hosting, maintenance and technical support; administer accounts, projects and client relationships; communicate with clients, prospects, suppliers and website visitors; respond to enquiries and support requests; conduct analytics and improve services; perform marketing and business-development activities; process billing and transactions; protect systems and prevent fraud or security incidents; enforce agreements; and meet legal, regulatory, accounting and reporting obligations.

Madcraft will not process covered personal data in a manner incompatible with the purposes for which it was collected or subsequently authorised by the individual.

6. Sources of Personal Data

Madcraft may receive covered personal data directly from individuals, clients and prospective clients; from client organisations for which Madcraft provides services; from Madcraft’s European operations and business partners; through websites, forms, portals, applications and support channels; and from service providers that support Madcraft’s business operations.

7. Disclosures and Accountability for Onward Transfers

Madcraft may disclose covered personal data to cloud and hosting providers; information-technology, security and communications providers; analytics and marketing platforms; payment, accounting and billing providers; professional advisers; contractors and delivery partners; Madcraft affiliates; clients where Madcraft processes data on their behalf; parties involved in a corporate transaction; and public authorities where disclosure is legally required.

Madcraft does not sell covered personal data for monetary consideration or provide it to unrelated third parties for their own direct-marketing purposes.

When Madcraft transfers covered personal data to a third-party controller, it will comply with the Notice and Choice Principles and enter into a contract providing that the data may be processed only for limited and specified purposes consistent with the individual’s consent and that the recipient will provide the same level of protection as the DPF Principles.

When Madcraft transfers covered personal data to an agent acting on its behalf, it will transfer the data only for limited and specified purposes; require the agent to provide at least the same level of privacy protection required by the DPF Principles; take reasonable and appropriate steps to ensure that the agent processes the data consistently with Madcraft’s obligations; require the agent to notify Madcraft if it can no longer provide the required level of protection; and, upon notice, take reasonable and appropriate steps to stop and remediate unauthorised processing.

Madcraft remains responsible under the DPF Principles if an agent processes covered personal data inconsistently with those Principles, unless Madcraft proves that it was not responsible for the event giving rise to the damage.

8. Individual Choice

Madcraft provides individuals with the opportunity to opt out before their covered personal data is disclosed to a non-agent third party or used for a purpose that is materially different from the purpose for which it was originally collected or subsequently authorised. Individuals may exercise this choice by contacting Madcraft using the details below.

Madcraft may disclose personal data without offering choice where disclosure is made to an agent performing services on Madcraft’s behalf under an appropriate contract or where disclosure is otherwise permitted or required by the DPF Principles or applicable law.

9. Sensitive Personal Data

Madcraft does not intentionally collect sensitive personal data for its ordinary business purposes. If Madcraft receives sensitive personal data covered by the EU-U.S. DPF, including while acting on a client’s instructions, Madcraft will obtain affirmative express consent where the DPF Principles require it before disclosing the information to a third party or using it for a purpose materially different from the purpose for which it was collected or subsequently authorised.

10. Access, Correction and Deletion

Individuals have the right to obtain confirmation of whether Madcraft processes covered personal data relating to them and, subject to the DPF Principles, to access that data and request its correction, amendment or deletion where it is inaccurate or has been processed in violation of the DPF Principles.

Requests may be submitted using the contact information below. Madcraft may take reasonable steps to verify the requester’s identity and may apply limitations permitted by the DPF Principles. Where Madcraft processes the information solely on behalf of a client, Madcraft may refer the request to that client and assist the client as required by contract and applicable law.

11. Security

Madcraft applies reasonable and appropriate administrative, technical, organisational and physical safeguards designed to protect covered personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. Safeguards are proportionate to the risks involved and the nature of the personal data.

12. Data Integrity and Retention

Madcraft takes reasonable steps to ensure that covered personal data is reliable for its intended use, accurate, complete and current. Madcraft limits processing to information relevant to the purposes described in this DPF Notice and retains covered personal data only for as long as it serves a legitimate processing purpose, is needed to perform contractual obligations or is required for legal, regulatory, accounting, security or reporting purposes. Madcraft then deletes, anonymises or securely disposes of the information as appropriate.

13. Required Disclosures

Madcraft may be required to disclose personal data in response to lawful requests by public authorities, including to meet national-security or law-enforcement requirements. Madcraft may also disclose information where otherwise required or permitted by applicable law and the DPF Principles.

14. Questions and Complaints

Individuals should first contact Madcraft with any question, concern or complaint regarding covered personal data. Madcraft will investigate and attempt to resolve eligible complaints and will ordinarily respond within 30 days.

In compliance with the EU-U.S. DPF, Madcraft commits to cooperate with the panel established by the European Union data protection authorities (“EU DPA Panel”) and to comply with the advice given by the EU DPA Panel regarding unresolved complaints concerning Madcraft’s handling of personal data received from the European Union in reliance on the EU-U.S. DPF. This independent recourse mechanism is provided at no cost to the individual.

15. Binding Arbitration

Under certain conditions described in Annex I to the DPF Principles, an individual may be entitled to invoke binding arbitration to address a complaint that has not been resolved through the other recourse and enforcement mechanisms available under the EU-U.S. DPF.

16. Federal Trade Commission Jurisdiction

Madcraft Inc. is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.

17. Changes to This Notice

Madcraft may update this DPF Notice to reflect changes in its practices, services or legal obligations. The current version will be posted with its effective date. Madcraft will not make changes that materially reduce the protection afforded to covered personal data without taking the steps required by the DPF Principles.

18. Contact Information

Privacy Lead: Conor Murphy, Chief Operating Officer

Email: [email protected]

Telephone: (737) 241-2893

Mail: Madcraft Inc., 111 Congress Ave., Suite 500, Austin, TX 78701, United States

Privacy requests and complaints should include enough information for Madcraft to understand and respond to the request. Madcraft may request additional information where reasonably necessary to verify identity or locate the relevant records.

This DPF Notice should be read together with Madcraft’s general Privacy Policy.

Connect with Madcraft

Please click the button below to send this request directly to our inbox via email. This request cannot be submitted via a contact form.

Click here