Privacy Policy
Maera ("we", "us", "our"), a company headquartered in New York, NY, United States, is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, transfer, retain, and secure personal data when you visit maera.com, engage with our Services (including US/international company formation assistance, EIN/ITIN support, AI-powered search optimization/Generative Engine Optimization (GEO/AEO), audits, consultations, content strategies, and related tools), or otherwise interact with us.
We comply with applicable privacy laws, including:
- United States federal and state laws (e.g., CCPA/CPRA for California residents where relevant).
- The EU General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) when we offer goods/services to EU/EEA individuals or monitor their behavior.
- UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data (PDPL) and its executive regulations for UAE-related processing or clients.
1. Information We Collect We collect only data necessary (data minimization):
- Provided by you: Name, email address, phone number, mailing address, billing information, company/job details, identification documents (for formation/compliance), website URLs, content samples, query examples (for GEO/audits/optimization — we process only client-provided and approved data; we do not scrape independently or generate unverified content).
- Automatically collected: IP address, browser type, operating system, device information, pages visited, referral sources, interaction data (via cookies, logs, analytics).
- Non-personal/aggregated: Usage patterns, demographics (aggregated for analytics).
2. How We Use Your Information (Lawful Bases) We process data on these bases:
- Performance of contract — to deliver Services (e.g., formation, audits, AI optimizations).
- Consent — for marketing emails, non-essential cookies (freely given, granular, withdrawable anytime).
- Legitimate interests — fraud prevention, site improvement, analytics (balanced; you may object).
- Legal obligations — compliance, tax, regulatory requirements.
For AI/GEO Services: We apply techniques (e.g., structured data, entity optimization) to enhance visibility of your verified content in third-party AI engines. We do not control those engines (e.g., Google AI Overviews, ChatGPT, Perplexity) and make no guarantees regarding rankings, citations, dominance, or complete neutralization of misinformation, bots, or deepfakes.
3. Cookies and Tracking Technologies Essential cookies (functionality, security) are always on. Non-essential cookies (analytics, advertising, personalization) require opt-in via a granular banner (easy withdrawal; English/Arabic support where relevant). You can manage/disable via browser settings, though this may impact experience.
4. Sharing and Disclosure We do not sell personal data. Sharing is limited to:
- Processors/service providers (e.g., cloud, payment, analytics) under strict data processing agreements (DPAs).
- Legal compliance, government requests, safety, or rights protection.
- Business transfers (merger/acquisition) with notice.
5. International Data Transfers Data is primarily processed in the US. For protected jurisdictions:
- EU/EEA (GDPR): We use the EU-US Data Privacy Framework (DPF — certification where applicable), 2021 Standard Contractual Clauses (SCCs modular), and Transfer Impact Assessments (TIA) for equivalent protection.
- UAE (PDPL): PDPL-permitted mechanisms (adequacy decisions, safeguards, explicit consent if required).
6. Data Security We implement technical, organizational, and physical measures (encryption, access controls, regular testing) aligned with industry standards, GDPR Art. 32, and PDPL obligations. Breaches: We notify supervisory authorities (72 hours under GDPR if high risk) and affected individuals as required. No transmission/storage is 100% secure — use at your risk.
7. Data Retention We retain data only as long as necessary for the purpose, legal obligations, or disputes — then securely delete or anonymize.
8. Your Rights Depending on applicable law (GDPR/PDPL/CCPA), you may:
- Access, rectify, or erase data ("right to be forgotten").
- Restrict processing or object (including to legitimate interests/marketing).
- Request portability.
- Withdraw consent (no effect on prior processing).
- Lodge complaints with authorities (e.g., EU DPAs, UAE Data Office).
Exercise rights: Email support@maera.com (include identity proof). We respond within 1 month (extendable per law).
9. Automated Decision-Making We do not engage in solely automated decisions producing legal or significant effects.
10. Children's Privacy Services not intended for children under 18. We do not knowingly collect data from minors. If discovered, we delete promptly.
11. Links to Third Parties Our site may link to third-party sites — we have no control over their privacy practices. Review their policies.
12. Changes to This Policy We may update (e.g., legal changes). Material changes: Prominent notice or direct email. Continued use = acceptance.
13. Governing Law and Jurisdiction Governed by the laws of the State of New York, United States (without conflict principles). Exclusive jurisdiction: courts of New York County, New York. We fully comply with GDPR/PDPL where applicable; relevant supervisory authorities handle specific complaints.
Contact support@maera.com Maera, 224 W 35th St., Ste 500, #664, New York, NY 10001, USA +1 (646) 920-2604
By using our website or Services, you acknowledge and agree to this Privacy Policy.
Privacy Policy Maera Last Updated: March 2026