Privacy Policy
Last updated
This policy explains what happens to personal data when you use madison-technologies.com (the "Site"). It covers the Site only. Data processed inside client projects is governed by the agreement with that client.
The Site is operated by Madison Technologies Malaysia PLT (LLP0020780-LGN), a limited liability partnership registered under the laws of Malaysia, with its registered office at Level 9, Tower B, Menara UOA Bangsar, 5, Jalan Bangsar Utama 1, Bangsar, 59000 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, Malaysia. For the purposes of the UK and EU General Data Protection Regulation, that entity is the controller for Site data.
Madison Technologies is established in Malaysia only, and runs delivery from Da Nang, Vietnam. Its clients in Europe and the United States are served through partner organisations: there is no branch, subsidiary or other establishment of Madison Technologies in the EEA, the United Kingdom or the United States.
What we collect
Three categories, for three different reasons. Nothing else is collected, and there is no account system, no advertising pixel and no cross-site tracking.
| Data | When | Why |
|---|---|---|
| Name, email address, and optionally phone number and company | Only when you submit the contact form | To reply to your enquiry |
| The message you write | Only when you submit the contact form | To understand and answer it |
| IP address, browser user-agent string, and a Google reCAPTCHA score | On contact form submission | To block automated abuse and enforce a submission rate limit. Without this the form is a spam relay. |
| Pages viewed, approximate location (country/city level), device and browser type, and interactions such as which case studies you open | On every visit, subject to the consent rules below | To understand which content is useful |
| Your language choice and your answer to the cookie banner | Stored on your device only | So the Site remembers them. These never leave your browser. |
What analytics never receives
Analytics events are stripped of anything that looks like a name, an email address or a phone number before they leave your browser. This is enforced in code rather than by policy: values matching those patterns are dropped at the single function every analytics event passes through.
What is measured is behaviour in the aggregate — that a contact form was opened from the services page, that an article was read to the end, that a button was clicked three times in a second and probably does not work. The content of anything you type is never sent, with one exception: a blog search term, which is what the search feature is for.
Legal basis for processing
If you are in the UK or the EEA, we rely on the following bases.
| Processing | Basis |
|---|---|
| Replying to your contact enquiry | Steps taken at your request before entering a contract (Art. 6(1)(b)) |
| Spam prevention and rate limiting | Legitimate interests — keeping the Site usable and secure (Art. 6(1)(f)) |
| Analytics cookies and measurement | Your consent (Art. 6(1)(a)), which you may withdraw at any time |
| Remembering your language and cookie choice | Strictly necessary for a service you requested; no consent required |
International transfers
Madison Technologies is established in Malaysia and the providers above are global. Personal data is therefore transferred outside the country where it was collected, including outside the UK and the EEA — to our own systems in Malaysia, and to the providers listed above.
Malaysia is not covered by a UK or EU adequacy decision, so those transfers rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum. Cloudflare, Google and Twilio (SendGrid) each incorporate the same clauses into the data processing terms they publish, and we rely on those terms together with the technical safeguards described under Security below.
How long we keep it
When the period ends the data is deleted. Aggregate statistics that can no longer identify anyone may be kept indefinitely.
| Data | Retained for |
|---|---|
| Contact form submissions | 24 months after our last contact with you |
| Rate-limiting records (IP address) | 30 days |
| Analytics data | 14 months |
Your rights
To exercise any of these, email hello@madison.dev. We will respond within one month. We may need to confirm your identity first, which protects you from someone else making a request in your name.
- Access — ask what personal data we hold about you and receive a copy
- Rectification — have inaccurate data corrected
- Erasure — have your data deleted, where no legal obligation requires us to keep it
- Restriction — ask us to pause processing while a dispute is resolved
- Portability — receive the data you gave us in a machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — decline analytics at any time, without affecting anything already lawfully processed
Changing your cookie choice
Clearing your browser storage for this Site removes the stored answer, and the banner appears again on your next visit if your location requires it. Your stored answer also expires automatically after 180 days, so you will be asked again.
A browser-level tracking blocker or "Do Not Track" setting will also prevent analytics from loading, and we do not attempt to work around either.
Complaints
If you are unhappy with how we have handled your data, please tell us first at hello@madison.dev — most issues are resolved quickly.
You also have the right to complain to a data protection authority: in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the supervisory authority of the country where you live or work.
Children
This Site is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has submitted personal data, contact us and we will delete it.
Security
The Site is served over HTTPS only, with HSTS, a Content Security Policy and a strict set of security headers. Contact form submissions are protected by reCAPTCHA and a rate limit, and are transmitted over encrypted connections.
No system is perfectly secure. If you find a vulnerability, please report it to hello@madison.dev rather than disclosing it publicly, and we will work with you on a fix.
Changes to this policy
When this policy changes materially, the date at the top changes and, for changes that affect how we use data you have already given us, we will make the change visible on the Site rather than expecting you to re-read this page.
Contact
Email hello@madison.dev for anything in this policy, including data subject requests.
Postal address: Madison Technologies Malaysia PLT, Level 9, Tower B, Menara UOA Bangsar, 5, Jalan Bangsar Utama 1, Bangsar, 59000 Kuala Lumpur, Wilayah Persekutuan Kuala Lumpur, Malaysia.
We have not appointed a representative in the EEA or the United Kingdom under Article 27 of the EU or UK GDPR. Our processing of visitor data from those regions is occasional, is limited to answering enquiries and to analytics you have consented to, involves no special category data and no large-scale monitoring, and so falls within the exemption in Article 27(2). Write to us directly at the email or postal address above — we answer in English.