Data protection

GDPR

A plain-language overview of GDPR, access control and data handling for MAUDEX workspaces.

GDPR overview

MAUDEX is designed for controlled access, tenant-specific workspaces and clear handling of brand assets, creator submissions and partner downloads. This page explains the intended GDPR approach in plain language.

Roles

For customer workspaces, the tenant or customer is normally responsible for deciding what content and personal data is uploaded, invited, approved and shared. Maude acts as service provider for the platform and related infrastructure.

Data minimization

Only collect and upload the information needed for the showroom, creator workflow or partner access purpose. Avoid uploading unnecessary personal data into files, filenames, comments or descriptions.

Access control

Use private access, invite-only workflows and download gating when content should not be public. Remove users who no longer need access and keep internal roles limited to what each person needs.

Creator submissions

When creators upload content, make sure they understand what they are submitting, how the content may be reviewed, and whether approved work may be published into a showroom or shared with partners.

Rights requests

Where GDPR applies, individuals may have rights to access, correction, deletion, restriction, portability or objection. Requests should be reviewed according to the tenant’s legal obligations and the final data processing setup.

Security and retention

Keep content only as long as needed for the campaign, showroom or business purpose. Archive or delete outdated submissions, partner links and user access when they are no longer needed.

Contact

For GDPR questions, contact hello@maude.se.