Privacy Policy
Last updated: July 22, 2026
1. Who we are
Mr. Podcast is operated by MPriet, CVR 32212263, Vermlandsgade 70, st. tv, 2300 København S, Denmark ("MPriet", "Mr. Podcast", "we", "us" or "our"). MPriet is the data controller for the processing described in this policy unless a different controller is clearly identified. Contact us at mp@mrpodcast.com.
This policy covers our websites, branded app, programmes, communities, Mr. Podcast Suite, assessments, support, business outreach and related services. It applies to customers, users, prospects, podcast guests and people who contact or interact with us.
2. Personal data and sources
Depending on the relationship, we may process:
- Account and contact data, including name, email, company, user IDs, login and access status.
- Business and podcast data, including offer, audience, revenue range, podcast name, website, podcast URL, RSS feed, public directory data and planned-podcast information.
- Programme and progress data, including completed Steps and videos, assignments, deadlines, assessments, feedback, rewards and access history.
- Content and production data, including audio, video, transcripts, manuscripts, show notes, graphics, social posts, connected-channel identifiers and publication status.
- Community and support data, including forum posts, comments, private messages, support requests, reports, moderation actions and approved AI-assisted replies.
- Transaction and guarantee data, including product, amount, payment status, invoices and evidence submitted for a voluntary refund guarantee. We normally do not receive full payment-card details.
- Technical and security data, including IP address, device and browser data, timestamps, event and webhook identifiers, cookies, logs, diagnostics and suspected abuse.
- Marketing and prospect data, including professional contact details, public podcast and business information, campaign source, consent or objection status and engagement.
We collect data from you, your use of our services, authorised integrations, payment and publication platforms, public podcast directories and professional data sources such as Rephonic. If you give us data about a guest or another person, you must have a lawful basis to do so.
3. Purposes and legal bases
We process personal data to:
- Create accounts, provide programme and software access, publish authorised podcast and marketing assets, deliver support and fulfil our agreement. The legal basis is performance of a contract or steps requested before a contract.
- Record progression, assess assignments, prepare podcast assessments and administer a voluntary refund guarantee. The legal basis is contract performance and our legitimate interest in consistent programme administration and fraud prevention.
- Operate communities, moderate content, investigate reports, secure systems, deduplicate events and maintain reliable services. The legal basis is our legitimate interests and, where relevant, legal obligations.
- Send operational messages, unlock notifications and approved support replies. The legal basis is contract performance or our legitimate interest in supporting users.
- Send marketing where permitted. The legal basis is consent where required, or another lawful marketing basis. You can opt out at any time.
- Conduct proportionate business-to-business outreach using professional and public podcast data. The legal basis is our legitimate interest in relevant B2B marketing, balanced against the rights of the recipient. Objections and suppression records are respected.
- Keep accounting, tax, dispute and compliance records. The legal basis is legal obligation and establishment, exercise or defence of legal claims.
- Improve content and systems using minimised or aggregated information. The legal basis is our legitimate interest in improving the service.
Where we rely on legitimate interests, you may request information about the relevant balancing assessment.
4. AI-assisted processing and human review
We use AI to classify messages, retrieve relevant Mr. Podcast knowledge, draft replies, evaluate whether assignment questions have genuinely been attempted, analyse podcast material and perform a preliminary check of voluntary refund-guarantee evidence.
AI does not decide whether a viewpoint is correct or whether a person is an attractive customer. A Reward Funnel answer is evaluated only for a genuine attempt to answer each required question. A failed check can delay progression, but the user can submit a new answer or contact us.
A refund-guarantee result is not finally rejected solely by AI. Failed, uncertain or low-confidence checks are eligible for human review, and the customer may provide missing evidence or request review at mp@mrpodcast.com. We record the model or system version, evidence, confidence and decision history where proportionate.
AI inputs may include relevant messages, transcripts, programme records, public podcast data and evidence submitted for the task. We minimise inputs and do not intentionally use guarantee documents to train public models.
5. Recipients and suppliers
We use the following recipients and supplier categories. A service is only used when relevant to the user or workflow, and not every service receives data about every person.
- Cloudflare: hosting, security, Workers, databases, object storage, queues, browser automation, AI and AI gateway services.
- Passion.io: branded app, programme access, community, messages and notifications.
- HighLevel or LeadConnector: websites, forms, contacts, email, CRM, access and progression records.
- Google Workspace and authorised Apps Script integrations: documents, spreadsheets and operational records.
- Google APIs, YouTube and Spotify: customer-authorised publishing, account connection, distribution and public metadata.
- Google Gemini or other authorised Google AI services: a fallback for selected assessment and analysis tasks where enabled.
- Slack: internal Messenger Center review, support approval and operational alerts.
- Zapier: authorised automation between systems.
- Cloudflare Workers AI, Anthropic and AssemblyAI: language-model processing, retrieval, embeddings, transcription and AI gateway services. Cloudflare Workers AI may run configured third-party model families, including Meta Llama and BAAI embedding models, within Cloudflare's service.
- Descript and ElevenLabs: customer-authorised recording, transcription, voice and audio-production workflows.
- Captivate: customer-authorised podcast hosting, RSS publication and analytics workflows.
- Ayrshare, Publer and connected social platforms: customer-authorised scheduling and publication. Publer may appear in legacy PPA workflows; Mr. Podcast Suite is the current implementation and audit route for the PPA Implementation Guarantee.
- Placid: generation of authorised visual assets.
- VideoAsk or Typeform, Sendspark and Vimeo: form or video collection, personalised video and video hosting or delivery.
- Stripe and relevant checkout providers: payment, invoicing, fraud prevention and transaction records.
- Instantly: business outreach campaigns and suppression handling.
- Rephonic: professional and public podcast discovery and enrichment.
- HYROS and Google Tag Manager or related Google measurement services: consent-based attribution, analytics and advertising measurement where enabled.
- Meta and Apple podcast services: advertising, connected publication, distribution or public podcast metadata, depending on the feature selected.
- Bunny Fonts: delivery of website fonts and associated technical request data.
We also read public podcast data from directories and platforms such as Apple Podcasts, Amazon Music, Spotify, Acast, Podtail, Podimo, Podcast Addict, Podfriend, Hubhopper and similar services. In that context they are normally public sources or independent platforms, not processors acting on our instructions.
Some payment, advertising, app-store, social, hosting and connected publication platforms act as independent controllers for parts of their processing under their own terms. We may also disclose data to professional advisers, authorities or counterparties when required by law, necessary to protect rights or safety, or as part of a business reorganisation with appropriate safeguards.
Our current operational supplier and data-flow register is available at https://legal.mrpodcast.com/suppliers. It identifies services found in active production workflows and distinguishes processors from connected or public platforms. Supplier roles, subprocessors and locations can change; we review material changes and update the register.
6. International transfers
Some suppliers or their subprocessors process data outside Denmark or the European Economic Area. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses with supplementary measures, or another lawful transfer mechanism. We maintain a supplier and transfer register and review relevant subprocessors and processing locations. You may ask for information about the applicable safeguards.
7. Retention
We apply the following general retention rules unless law, an active dispute or a documented exception requires a different period:
- Active account, programme, production and support data: for the relationship and normally up to 3 years afterwards.
- Community content: while the community and account are active, then deletion or anonymisation where reasonably possible, subject to moderation, legal and other users' conversational context.
- Security, webhook and diagnostic logs: normally up to 12 months.
- Unsuccessful B2B prospect records: normally up to 12 months after the last relevant contact; a minimal suppression record may be kept longer to respect an objection.
- Marketing consent and objection evidence: while used and afterwards for as long as necessary to demonstrate compliance.
- Voluntary guarantee claim evidence and decision records: normally up to 5 years after the end of the financial year in which the claim was resolved, where needed for accounting, fraud prevention or legal claims.
- Accounting material: the current financial year and the legally required period afterwards, generally 5 years from the end of the relevant financial year.
We delete, anonymise or restrict data when the purpose ends. Backup copies expire through controlled retention cycles.
8. Community content and messages
Community posts and comments are visible to users with access to the relevant area. Private messages are not public, but may be processed by authorised systems and staff for support, moderation and security.
Users can use available reporting and blocking controls. We may review, preserve, restrict or remove material involving harassment, unlawful content, infringement, spam, abuse or violations of our Terms. Do not publish sensitive or confidential data that is unnecessary for the discussion.
9. Cookies, analytics and connected platforms
Essential technologies are used for login, security, forms and service delivery. Non-essential analytics, attribution, advertising or tracking technologies are not to be activated before the consent required in the relevant jurisdiction. Where enabled after consent, these may include HYROS and Google Tag Manager or related Google measurement services. Refusing or withdrawing non-essential consent must not prevent access to essential service functions.
The consent interface must identify the relevant purposes and make rejection or withdrawal as accessible as acceptance. Connected third-party platforms may set their own technologies when you deliberately open or connect them under their policies. Server logs and security signals necessary to deliver and protect a requested service are handled separately from optional marketing tracking.
10. Security and incidents
We use proportionate technical and organisational measures, including access controls, secret management, encrypted transport, environment separation, event deduplication, audit records, rate limiting and human approval for sensitive actions. Access is limited by role. No service can guarantee absolute security.
We assess personal-data incidents and notify the competent authority and affected people when legally required.
11. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection. You may withdraw consent without affecting earlier lawful processing. You may also object to direct marketing at any time and request human review of a significant automated result.
Email mp@mrpodcast.com. We may verify your identity. You may complain to Datatilsynet or another competent supervisory authority.
12. Account deletion
You can initiate deletion without signing in at https://legal.mrpodcast.com/account-deletion. We normally complete a verified request within 30 days. We delete or de-identify Passion, HighLevel, community, private-message, support and AI records where legally and technically possible, while preserving only information we are required or entitled to keep.
13. Children
The services are intended for adult business users and are not directed to children. We do not knowingly collect personal data from people under 18.
14. Changes
We update this policy when processing, suppliers or law changes. The current version and date are published here. Material changes are communicated reasonably.
15. Contact
MPriet · CVR 32212263 Vermlandsgade 70, st. tv, 2300 København S, Denmark mp@mrpodcast.com