Privacy Policy
Clear, practical information about what we collect, why we collect it, and your rights under GDPR.
Overview
This Privacy Policy explains how CDMG Automation ("we") handles personal data when you visit our website, contact us, use our customer portal, or use our chat assistant.
We process personal data only when needed to provide the service, respond to requests, operate the portal, and improve reliability. We do not sell personal data.
Data we collect
Depending on how you interact with the site, we may collect:
- Contact details you submit via forms (name, email, company, message).
- Order information (plan, add-ons) and basic customer details for checkout or quote requests.
- Portal account data (email, authentication events) and business records stored in the portal.
- Chat messages you send to the assistant and the assistant responses.
- Technical data such as IP address, device information, and server logs for security and debugging.
- Functional storage (cookies/local storage) for language preference and cart state.
Purposes and legal basis (GDPR)
We process data under these legal bases:
- Contract (Art. 6(1)(b)) - to provide the service you request, including setup and ongoing subscription.
- Legitimate interests (Art. 6(1)(f)) - to secure, maintain, and improve our website and services.
- Consent (Art. 6(1)(a)) - where you choose to provide optional information or enable optional features.
- Legal obligation (Art. 6(1)(c)) - where required for accounting or compliance.
Typical purposes include responding to inquiries, onboarding, operating automations, providing support, processing payments (if enabled), and generating performance reporting.
Retention
We keep personal data only as long as needed for the purposes described above:
- Contact and quote requests: kept for a reasonable period to handle follow-up and sales discussions.
- Portal data: stored for the duration of the active service and as needed for legitimate business records.
- Security logs: kept for a limited time unless required to investigate incidents.
Exact retention periods may depend on your contract and legal requirements. You can request deletion where applicable.
Sharing and processors
We may share personal data with service providers that help us run the website and deliver the service. These providers act as processors under GDPR and are bound by contractual obligations.
- Hosting and form processing: Netlify (for site hosting and form submissions).
- AI processing for chat: OpenAI (only when you use the chat assistant).
- Portal infrastructure: PostgreSQL (Neon) + custom authentication.
- Payments (if enabled): Stripe (checkout and billing).
At the moment, we do not use third-party analytics cookies on this website. If we add analytics in the future, we will update this policy and, where required, request consent.
Security
We apply reasonable technical and organizational measures to protect data against unauthorized access, alteration, disclosure, or destruction.
- Access control and least-privilege for internal tools.
- Encrypted transport (HTTPS) for website and API requests.
- Monitoring and alerts to detect failures or abuse.
No system is perfectly secure. If you suspect a security issue, contact us immediately.
Cookies and tracking
We use functional storage to make the website work smoothly. This may include a language preference cookie and local storage for cart state.
- Language preference: remembers the language you selected.
- Cart: remembers selected plans and add-ons so you can checkout.
If we introduce optional analytics or marketing tracking, we will provide a clear notice and, where required, consent controls.
Your rights
Under GDPR, you may have the right to request access, rectification, deletion, restriction, portability, and to object to processing in certain cases.
- Access: get a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion where applicable.
- Portability: receive data in a portable format.
- Objection: object to certain processing based on legitimate interests.
To exercise your rights, contact us at contact@cdmgautomation.com or support@cdmgautomation.com.
Changes to this policy
We may update this Privacy Policy to reflect changes in our services or legal requirements. The latest version will always be published on this page.