Last updated: October 7, 2026
This Privacy Policy explains how Be Mario collects, uses, shares and protects personal data when you visit bemario.com, request a free audit, receive an email from me, or become a client. It is written to meet the EU and UK General Data Protection Regulation (GDPR), the Law on Personal Data Protection of North Macedonia, and US state privacy laws where they apply. If anything is unclear, email mario@bemario.com.
1. Who is responsible for your data
The data controller is Mario Petkovski, trading as Be Mario, North Macedonia (“I”, “me”). Contact for all privacy matters: mario@bemario.com. I am a small business and am not required to appoint a Data Protection Officer; I handle privacy requests personally.
2. Who this policy applies to
- visitors to bemario.com;
- people who submit the free audit form or email me;
- business contacts I reach out to by email (B2B prospects);
- clients and their staff, and suppliers.
My services are for businesses. This website is not directed at children, and I do not knowingly collect data from anyone under 18.
3. The personal data I collect
| Category | Examples | Source |
|---|---|---|
| Contact data | Name, job title, work email, company name, website | You (form, emails), public sources |
| Audit request data | Brand website, optional monthly Meta spend range, anything you add in your emails | You |
| Communication data | Emails, replies, opt-out requests, feedback, approvals | You |
| Client and billing data | Company details, billing address, VAT number, payment records, brief answers | You |
| Public business data | Your company’s public ads (Meta Ad Library), website content, public reviews, public social profiles | Public sources |
| Technical data | IP address, browser and device type, pages visited, referring page, campaign tags (UTM), timestamps | Your browser, server logs, my security tools |
| Email engagement data | Whether an outreach email was delivered, opened or clicked, and replies | My email tools |
| Advertising data (optional) | Page views and form submissions measured by the Meta Pixel, if enabled | Your browser, with consent where required |
I do not ask for, and you should not send me, sensitive data such as health information about you or your customers. If a client’s Deliverables require customer reviews or testimonials, I use only content the client is entitled to share.
4. Why I use your data and the legal basis
| Purpose | Legal basis |
|---|---|
| Preparing and sending a free audit you requested, and following up about it | Steps you asked for before a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Delivering paid services, managing the client relationship, approvals and revisions | Performance of a contract (Art. 6(1)(b)) |
| Invoicing, accounting, tax and legal record-keeping | Legal obligation (Art. 6(1)(c)) |
| B2B outreach to businesses that may benefit from my services | Legitimate interest (Art. 6(1)(f)), and national e-marketing rules for business contacts |
| Website security, spam and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Understanding which channels bring visitors, improving the website | Legitimate interest (Art. 6(1)(f)) |
| Measuring my own advertising with the Meta Pixel | Consent (Art. 6(1)(a)) where required by law |
| Establishing, exercising or defending legal claims | Legitimate interest (Art. 6(1)(f)) |
Legitimate interest. My interests are running and growing a small business, keeping the website safe, and contacting businesses with relevant offers. I balance these against your rights by collecting only business contact data, limiting contact to a few emails, offering a one-click way to opt out, and never selling data. You can object at any time (section 10).
5. Business outreach (if I emailed you first)
- I contact businesses, usually founders or marketing leads, when I believe my services are relevant to their advertising.
- I find business contact details on public sources such as the company website, its imprint or contact page, public social profiles and the Meta Ad Library, and I may use email-finding and verification tools to check an address is valid.
- I send a short sequence of plain-text emails (normally no more than four). Every email identifies me and includes a simple way to opt out.
- If you reply “no”, ask me to stop, or object, I stop immediately and add your email and domain to a suppression list so you are not contacted again, including by future campaigns.
- Outreach emails may be sent from separate sending domains that redirect to bemario.com; they are still sent by me and covered by this policy.
- My email tools may record delivery, opens and clicks to manage sending and avoid contacting you more than necessary.
6. Cookies and similar technologies
| Type | Purpose | Needs consent? |
|---|---|---|
| Essential (WordPress, security) | Make the site and form work, protect against abuse | No |
| Bot protection (Cloudflare Turnstile, if enabled) | Check that form submissions come from a human | No (security) |
| Advertising (Meta Pixel, if enabled) | Measure visits and form submissions from my own ads | Yes, in the EU/UK and where required |
The free audit form also stores a short-lived, hashed record linked to your IP address on the server for about one hour to prevent spam; this is not a cookie and is not used to identify you. You can block or delete cookies in your browser settings, and you can manage ad preferences in your Meta account.
7. Who I share data with
I don’t sell personal data. I share it only with service providers that help me run the business, under contracts that require them to protect it and use it only on my instructions:
| Provider type | Purpose |
|---|---|
| Website hosting and WordPress | Hosting the website and storing form submissions |
| Google Workspace | Email, documents and file sharing |
| Email delivery and outreach tools (e.g. SMTP service, Instantly) | Sending emails, warm-up, deliverability, reply management |
| Email finding and verification tools | Checking that business email addresses are valid |
| Cloudflare | Security, performance and bot protection |
| Meta Platforms (if the Pixel is enabled) | Ad measurement |
| Automation tools (e.g. Make, Zapier), if connected | Organising leads, e.g. adding them to a spreadsheet |
| AI tools | Helping analyse public business information and draft content (no sensitive data; not used to train public models where settings allow) |
| Banks, Payoneer, accountant | Payments, invoicing, tax compliance |
| Freelancers or assistants I work with | Producing client work, bound by confidentiality |
I may also disclose data if required by law, to protect my rights, or as part of a transfer of my business, in which case the recipient must respect this policy.
8. International transfers
I am based in North Macedonia. Some providers are located in the EU, the United States or other countries. When data is transferred to a country without an adequacy decision, I rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK addendum) or the EU-US Data Privacy Framework for certified providers. You can ask me for more information about these safeguards.
9. How long I keep data
| Data | Retention |
|---|---|
| Audit requests and leads that don’t become clients | Up to 24 months after the last contact |
| Outreach prospects who don’t respond | Up to 12 months after the last email |
| Suppression (do-not-contact) list | As long as needed to respect your opt-out (email or domain only) |
| Client project files and communications | Duration of the engagement plus 3 years |
| Invoices and accounting records | As long as tax and accounting law requires (typically up to 10 years) |
| Spam-prevention data (hashed IP) | About 1 hour |
| Server logs | Per hosting provider settings, normally under 90 days |
10. Your rights
Depending on where you live, you have the right to:
- access the personal data I hold about you and get a copy;
- correct inaccurate data;
- delete your data (“right to be forgotten”);
- restrict how I use your data;
- receive your data in a portable format;
- object to processing based on legitimate interest, and object to direct marketing at any time (I will always stop marketing to you when you object);
- withdraw consent at any time, without affecting earlier processing;
- not be subject to decisions based solely on automated processing (I don’t make any).
To exercise a right, email mario@bemario.com. I will reply within one month (extendable by two months for complex requests, in which case I’ll tell you). I may need to confirm your identity first. Requests are free unless they are clearly unfounded or excessive.
Complaints. You can complain to a supervisory authority: in North Macedonia the Agency for Personal Data Protection (azlp.mk); in the EU the data protection authority of your country; in the UK the Information Commissioner’s Office (ico.org.uk). I’d appreciate the chance to resolve your concern first.
11. US residents
If US state privacy laws (such as the California Consumer Privacy Act) apply, this section is your notice at collection. I collect the categories described in section 3 for the purposes in section 4. I do not sell personal information. If the Meta Pixel is enabled, it may be considered “sharing” for cross-context behavioural advertising; you can opt out by emailing me or by using your browser’s privacy controls, and I will honour such requests. You have the right to know, correct and delete your information, and I won’t discriminate against you for using these rights. I do not use or disclose sensitive personal information.
12. Security
I protect personal data with encrypted connections (HTTPS), reputable providers, strong unique passwords, two-factor authentication, limited access, regular updates and spam protection on forms. No system is perfectly secure, so I can’t guarantee absolute security. If a personal data breach is likely to put your rights at risk, I will notify the competent authority and, where required, you, without undue delay.
13. Links to other websites
This website links to other websites (for example sources for statistics and my own brands). I am not responsible for their privacy practices; please read their policies.
14. Changes to this policy
I may update this policy when my services, tools or the law change. The date at the top shows the latest version. If changes are significant, I will highlight them on this page and, for clients, by email.
15. Contact
Mario Petkovski, Be Mario, North Macedonia. Email: mario@bemario.com.