Privacy Policy
Last updated: 4 September 2026
1. Who we are
MARKETING PLATFORM SOLUTIONS LTD, trading as MAPD Analytics, provides business data integration, cloud data infrastructure, analytics, dashboards, reporting and AI-assisted business-data exploration services.
- Company number: 16849562
- Registered office: 6 Manor House Lane, Datchet, Slough, England, SL3 9EG
- Email: hello@mapdanalytics.com
This Privacy Policy applies to:
- The public MAPD Analytics website (mapdanalytics.com) and its enquiry process.
- MAPD's provisioned data integration, analytics and reporting services.
- Communications between MAPD and prospective or existing clients.
2. Our data-protection roles
MAPD generally acts as a data controller for website enquiries, prospective-client information, sales communications, service administration, security records and its own legal obligations.
When MAPD retrieves or processes business data from a client's connected systems under the client's instructions, the client generally acts as the controller and MAPD generally acts as the processor or service provider. The precise roles may depend on the contract, the data and the circumstances. Where required, processing of client-controlled data may also be governed by a separate data-processing agreement.
3. Information collected through the public website
Through the public website, MAPD may collect:
- Names and business names.
- Business email addresses and other contact details.
- Information you submit through enquiry forms.
- Correspondence and sales communications.
- Basic technical, diagnostic, security and server-log information.
- Cookie or website analytics information, only where those tools are actually used (see section 15).
The public website does not itself retrieve or store clients' connected-platform analytics datasets. Enquiry-form details may be transmitted directly to MAPD's email system; this still counts as processing personal information even where it is not stored in a website database.
4. Client and service-administration information
To set up and run the service, MAPD may process:
- Client contact details and user/administrator details.
- Project and implementation requirements.
- Contract, billing and support information.
- Account configuration and connection status.
- Connected-platform account and asset identifiers.
- Audit, diagnostic, security and operational logs.
5. Connected Platform data
"Connected Platforms" are the third-party systems a client chooses to connect to MAPD's service. These may include advertising platforms, analytics platforms, social-media platforms, booking systems, payment systems, customer relationship management systems, e-commerce systems and other client-approved business tools.
- Clients decide which platforms and accounts to connect.
- MAPD accesses only accounts and data that the client has authorised.
- The precise information retrieved depends on the platform, the permissions selected and the agreed implementation.
- MAPD uses official authorization or delegated-access methods where available, and does not ask clients to share platform passwords where such a method exists.
- Connected Platform data is used to provide the agreed ingestion, organisation, validation, analytics, dashboard, reporting and support services.
- MAPD does not sell Connected Platform data and does not use it for unrelated advertising.
- Clients may revoke a connection or ask MAPD to disconnect it. Revoking a connection prevents future retrieval but may not automatically delete information already processed into the client's analytics environment.
Client analytics environments are provisioned separately from the public marketing website, using a dedicated client project, environment or logically separated cloud resources on Google Cloud.
6. TikTok data
Where a client or authorised user chooses to connect a TikTok account, TikTok's official authorization process may permit MAPD Analytics and its connection-service provider to retrieve information covered by the permissions selected by the user. Depending on the permissions granted, this may include basic account identifiers, display name, username, avatar, public profile information, profile statistics and information about published videos and their available engagement or performance statistics.
The relevant TikTok permissions may include user.info.basic, user.info.profile, user.info.stats and video.list.
MAPD Analytics uses this information only to provide the client's requested data integration, analytics, dashboards, reporting and performance insights. MAPD does not use these permissions to publish, modify or delete TikTok content. MAPD does not sell TikTok user data or use it for unrelated advertising.
TikTok authorization may be managed through Nango. Authorised TikTok data is subsequently processed and stored within the relevant client's Google Cloud analytics environment rather than within the public MAPD Analytics marketing website.
Connecting TikTok is optional and requires the user's express authorization. Users may revoke access through their TikTok account settings or contact MAPD Analytics to request disconnection. MAPD Analytics is not owned, operated, sponsored, certified or endorsed by TikTok.
7. How information is used
MAPD may use information to:
- Respond to website enquiries and assess prospective projects.
- Communicate with prospective and existing clients.
- Provide and administer contracted services.
- Connect authorised business systems and retrieve, organise, model and validate business data.
- Provide dashboards, analytics and reports.
- Answer user-requested questions about business data where AI functionality has been enabled.
- Provide technical support and monitor service reliability and security.
- Detect fraud, abuse and unauthorised access.
- Maintain audit and operational records and improve the service.
- Comply with legal, regulatory and contractual obligations.
- Establish, exercise or defend legal claims.
MAPD does not use client data to train public AI models. Where an AI feature is enabled for a client, it is used to answer that client's questions about their own data within the agreed service.
8. Lawful bases
Under UK GDPR, MAPD relies on the following lawful bases, as applicable:
- Taking steps at someone's request before entering a contract.
- Performance of a contract.
- Legitimate interests in marketing, operating, improving and securing a business analytics service.
- Consent where required, including optional platform connections or non-essential cookies.
- Compliance with legal obligations.
- Establishing, exercising or defending legal claims where applicable.
9. Service providers and subprocessors
MAPD uses carefully selected service providers necessary to operate and deliver its services. Depending on the engagement, these may include:
- Google Cloud Platform — client-specific cloud infrastructure, application hosting, data processing, security and storage.
- Nango — OAuth connection and credential management.
- Dashboard and analytics-interface providers.
- Website hosting providers and email/communication providers.
- Security, monitoring, logging and technical-support providers.
- Approved AI-service infrastructure where an AI feature has been enabled for a client.
These providers may process information only as necessary to provide their contracted services, and appropriate contractual and security controls are used where required. Nango and other infrastructure providers may act as subprocessors when MAPD acts as the client's processor. MAPD may disclose information where legally required, to protect legal rights, or as part of a legitimate business sale or restructuring. MAPD does not sell personal data or Connected Platform data.
10. International transfers
Some service providers may process information outside the United Kingdom. Where required, MAPD uses appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or other legally recognised transfer safeguards.
11. Data retention
MAPD retains information only for as long as reasonably necessary to respond to enquiries, provide the contracted service, maintain security, audit and backup records, resolve disputes, meet contractual, legal, tax and regulatory obligations, and establish, exercise or defend legal claims.
Retention periods depend on the type of information, the client agreement, the purpose for which it was collected, legal requirements, and security and backup arrangements. Connected Platform data will be deleted, returned or anonymised when the service ends or following a valid deletion instruction, subject to the client agreement, applicable law, legitimate record-keeping requirements and normal backup-retention cycles.
12. Security
MAPD uses reasonable technical and organisational safeguards appropriate to the nature of the service, which may include restricted access, credential and secret protection, encryption in transit and at rest where supported, cloud identity and access management, separation between client projects or environments, logging and monitoring, backup and recovery controls, secure development and deployment practices, and periodic review of access.
No internet-based service can guarantee absolute security, but MAPD works to protect the information entrusted to it.
13. Individual rights
Under UK data-protection law, individuals may have the right to:
- Access their personal data.
- Correct inaccurate data.
- Request deletion of their data.
- Restrict or object to processing.
- Data portability, where applicable.
- Withdraw consent where processing relies on consent.
- Rights relating to automated decision-making, where applicable.
- Complain to the UK Information Commissioner's Office.
These rights depend on the circumstances and applicable law. Where MAPD acts as a processor, it may refer the request to the relevant client or assist the client in responding.
14. TikTok disconnection and data deletion
To disconnect TikTok, revoke MAPD Analytics from the security, permissions or connected-app settings of your TikTok account. You may also contact MAPD Analytics to request disconnection.
To request deletion of TikTok data held or managed by MAPD Analytics, email hello@mapdanalytics.com with the subject "TikTok Data Deletion Request". Include enough information for us to identify the relevant client and connection, but do not send your TikTok password, access token or other secret credentials.
MAPD may need to verify your identity, authority over the relevant account and relationship with the client before acting on a request. Where the relevant client controls the data, MAPD may refer the request to that client or obtain the client's instructions.
15. Cookies
The public MAPD Analytics website uses only strictly necessary cookies and similar storage required for the website to function and remain secure (for example, hosting and session-related storage).
The website does not currently use optional analytics, advertising or measurement cookies. If that changes, this policy will be updated and any required consent will be obtained before non-essential cookies are placed.
16. Children
MAPD Analytics is a business service intended for adults acting on behalf of businesses. MAPD does not knowingly request Connected Platform access from children or knowingly provide its service directly to children.
17. Third-party links and platforms
The website and service may link to or integrate with third-party platforms. Those platforms operate under their own terms and privacy policies. MAPD is not responsible for the independent privacy practices of third parties acting outside MAPD's instructions.
18. Changes to this Privacy Policy
This policy may be updated to reflect service changes, new Connected Platforms, legal or regulatory changes, or changes to service providers or security practices. The "Last updated" date will be revised and material changes will be communicated where appropriate.
19. Contact and complaints
Trading as MAPD Analytics
Company number: 16849562
Registered office: 6 Manor House Lane, Datchet, Slough, England, SL3 9EG
Email: hello@mapdanalytics.com
You may also complain to the UK Information Commissioner's Office: ico.org.uk/make-a-complaint.