Legal

Privacy Policy

Marathon Systema LLC  ·  Effective Date: May 1, 2026  ·  Last Updated: August 24, 2026

Marathon Systema LLC (“Marathon Systema,” “we,” “us,” or “our”) is committed to protecting the privacy and security of the information entrusted to us by our clients and visitors. This Privacy Policy explains what information we collect, how we use it, with whom we share it, how we protect it, and what rights you have with respect to your information.

Please read this policy carefully. By engaging our services, visiting our website, or communicating with us, you acknowledge the practices described in this Privacy Policy.

Table of Contents

1.Who We Are
2.Scope of This Policy
3.Information We Collect
4.How We Collect Information
5.How We Use Your Information
6.Legal Bases for Processing
7.How We Share Your Information
8.Third-Party AI Tools and Platforms
9.Meta Business Platform Data
10.Our Role: Controller and Processor
11.Data Retention
12.Data Security
13.California Privacy Rights (CCPA/CPRA)
14.Other U.S. State Privacy Rights
15.International Data Transfers
16.Marketing Communications
17.Business-to-Business Context
18.Third-Party Links and Services
19.Children's Privacy
20.Changes to This Privacy Policy
21.Contact Us

1. Who We Are

Marathon Systema LLC is a Wyoming limited liability company. We are an AI automation and software company: we design, build, deploy, and maintain custom software systems tailored to the operational needs of each business we work with. Our work includes internal business platforms, workflow and process automation, AI-assisted systems, AI-generated creative services, and integrations with the Meta Business platform, including the WhatsApp Business Platform, Instagram messaging, and Messenger. We serve businesses primarily in the United States and Latin America. Our registered address is 30 North Gould Street, Ste R, Sheridan, WY 82801, USA.

For privacy-related inquiries, contact us at:

  • Email: admin@marathonsystema.com
  • Phone: (307) 998-2092
  • Mailing Address: 2048 Biscayne Dr, Lewisville, TX 75067, USA

2. Scope of This Policy

This Privacy Policy applies to:

  • All individuals and businesses that engage Marathon Systema LLC for services (collectively, “Clients”).
  • Visitors to our websites, social media pages, and any digital properties we operate.
  • Any person who communicates with us by email, phone, messaging platforms, or any other channel.
  • People who contact one of our Clients through a system we built and operate, including on WhatsApp, Instagram, and Messenger. For that data our role is limited: see Section 10.

This Policy does not apply to the practices of third-party companies, platforms, or service providers that we may use in delivering services, except as described in this Policy. It also does not replace the privacy policy of a business you contacted through a system we operate on its behalf.

3. Information We Collect

3.1 Information You Provide Directly

CategoryExamples
Business contact informationFull name, company name, job title, business email, business phone, business mailing address
Project and creative materialsCreative briefs, design references, photographs, architectural plans, brand guidelines, logos, text content
Communication recordsEmails, messages, call notes, meeting summaries, and any written or verbal communications
Contractual informationSignatures, agreement acceptance, service terms, and project scope documents
Feedback and reviewsTestimonials, reviews, satisfaction ratings, and project feedback

3.2 Financial and Payment Information

To process payments for our services, we collect bank account details (for wire transfer purposes only), invoicing information, and payment confirmation records. Marathon Systema LLC does not store raw banking credentials beyond what is strictly necessary to complete a transaction.

3.3 Technical and Usage Data

When you interact with our digital properties, we may automatically collect IP address, browser type, device type, pages visited, referring URLs, approximate geographic location, and email interaction data.

3.4 Information Collected Through Third Parties

We may receive information from referral partners, publicly available professional profiles, and social media platforms where you interact with our content.

4. How We Collect Information

We collect information through direct submission (forms, email, contracts), service delivery (materials and feedback during a project), digital interaction (cookies and analytics), and payment processing (via Mercury Bank and Wise Business).

5. How We Use Your Information

5.1 Service Delivery

To provide, manage, and fulfill the AI automation and AI creative services agreed upon in our service agreements, and to communicate project updates, revisions, and deliverables.

5.2 Financial Operations

To issue invoices, process payments, collect fees, and maintain accounting records in compliance with financial reporting obligations.

5.3 Business Operations and Administration

To manage client relationships, maintain project records, store executed contracts, and enforce our service agreements.

5.4 Legal and Compliance

To comply with applicable laws, respond to lawful government requests, protect our rights, and investigate potential fraud or unauthorized use of our services.

5.5 Marketing and Business Development

To share portfolio work and case studies (subject to your service agreement and Section 16), and to send service updates if you have opted in.

5.6 Service Improvement

To analyze how our services are used and develop new offerings based on aggregate, non-identifiable insights.

We do not sell, rent, or monetize your personal information to any third party for their own commercial purposes.

6. Legal Bases for Processing

We rely on contract performance, legitimate interests, legal obligation, and consent as lawful bases for processing personal data, depending on the specific use.

7. How We Share Your Information

We do not sell or rent your personal information. We may share it only with service providers (banking, AI platforms, cloud storage, communication services, accounting software), as required by law, in connection with a business transfer, or with your consent.

8. Third-Party AI Tools and Platforms

Marathon Systema LLC uses third-party artificial intelligence platforms as integral tools in production. These platforms may process the materials and inputs you provide to us as part of project execution.

Platforms we currently use include: Midjourney, Runway, Google Gemini, Kling, Higgsfield, and other AI platforms selected based on project requirements.

When we submit your project materials to these platforms, those platforms may process and temporarily retain such inputs in accordance with their own terms of service. We do not control how these third-party platforms handle submitted data. Marathon Systema LLC will not submit sensitive personal information to any AI platform without your express written consent.

9. Meta Business Platform Data

Part of our work is building and operating messaging and automation systems on the Meta Business platform for our Clients, including the WhatsApp Business Platform, Instagram messaging, and Messenger. This section describes that specific processing, and it governs where it conflicts with anything more general in this Policy.

9.1 What We Access

When a Client authorizes us to connect their Meta assets, we may access and process:

CategoryExamples
Business account dataBusiness portfolio ID, WhatsApp Business Account ID, phone number ID, Page and Instagram account IDs, display name, message templates
Message content and metadataMessages exchanged between the Client and the people who contact them, timestamps, delivery and read status, attachments sent through the conversation
End-user contact dataPhone number, platform-scoped user ID, profile display name, and any detail the person volunteers in the conversation
Conversation contextReferral and ad attribution when a person arrives from a Click to WhatsApp or Messenger ad, assignment, status, tags, and internal notes written by the Client's staff
Access credentialsAccess tokens and identifiers issued by Meta, stored encrypted and used only to operate the Client's integration

We access only the assets a Client explicitly grants, and only for as long as that authorization is in place. A Client can revoke it at any time from their Meta Business settings.

9.2 How We Use It, and What We Never Do

We use Meta platform data solely to deliver, operate, support, secure, and troubleshoot the system the Client engaged us to build. That includes routing incoming messages, running the automations the Client configured, presenting conversations in the Client's shared inbox, and reporting on the Client's own activity.

We do not sell, rent, license, or monetize Meta platform data. We do not use it to target advertising to end users, to build or enrich independent profiles or audiences, to train machine learning models of our own or of any third party, or for any purpose unrelated to the service the Client engaged us to provide.

Our handling of this data is subject to Meta's own terms and policies, including the Meta Platform Terms, the Meta Terms for WhatsApp Business, the Meta Hosting Terms for Cloud API, and Meta's Developer Policies. Where those terms impose a stricter obligation than this Policy, the stricter obligation applies.

9.3 Data Minimization and Security

We request the narrowest permissions that make the system work, and nothing more. Access tokens and channel credentials are stored encrypted at rest. Data is isolated per Client, so one Client's conversations are never reachable from another Client's workspace. Internal logs record entity identifiers rather than message content, names, or phone numbers.

9.4 Sensitive Information

Our messaging systems are not designed or authorized to store medical records, diagnoses, treatment notes, clinical results, payment card data, or government identifiers, and Clients agree not to configure them to do so. If you sent such information in a message, ask the business you contacted to remove it.

9.5 What Happens When an Engagement Ends

When a Client ends an engagement, we revoke the access tokens for that integration and delete or return the Meta platform data we processed for that Client within 90 days, except for records we are required to retain under Section 11.

10. Our Role: Controller and Processor

The same company can hold two different roles over two different sets of data, and the distinction decides who is able to act on a request.

Whose dataOur roleWhat that means
Our own Clients, and visitors to our websiteControllerWe decide why and how the data is processed. Send requests directly to us and we action them.
The customers and end users of our Clients, including everyone who messages a Client on WhatsApp, Instagram, or MessengerService provider and processorThe Client decides why and how. We act only on the Client's documented instructions, never for our own purposes.

If you messaged a business that uses a system we built and you want your data corrected or deleted, the fastest route is to contact that business, because the records are theirs. You may also write to us: we will forward your request to the Client and delete what we hold once they instruct us. Full instructions are on our Data Deletion Instructions page.

Clients are responsible for having a lawful basis for the data they route through our systems, for giving the notices their own customers are owed, and for collecting any messaging opt-in that applicable law and platform policy require.

11. Data Retention

Type of DataRetention Period
Active client project files and communicationsDuration of engagement + 5 years
Executed contracts and agreements7 years from contract execution
Payment and financial records7 years (IRS and financial compliance)
Marketing communications and consent recordsUntil opt-out, plus 3 years
Technical/usage data (logs, analytics)12 months from collection
Confidential project information3 years from project completion

12. Data Security

We implement commercially reasonable technical and organizational measures including access controls, encrypted communication channels, access-controlled cloud storage, and secure banking platforms. No method of electronic transmission or storage is 100% secure. Notify us immediately at admin@marathonsystema.com if you suspect a security incident.

13. California Privacy Rights (CCPA/CPRA)

13.1 Categories of Personal Information Collected

CCPA CategoryCollectedExamples
IdentifiersYesName, email, phone, business address, IP address
Commercial informationYesServices purchased, payment records, contracts
Professional or employment informationYesJob title, company name, business role
Internet or electronic network activityYesWebsite usage, email interactions
Geolocation dataLimitedApproximate location from IP address only
InferencesNoWe do not build consumer profiles for profiling purposes
Sensitive personal informationNoNot collected in ordinary course of business

13.2 Your California Privacy Rights

Subject to verification of your identity, California residents have the right to know, delete, correct, and opt out of sale/sharing. We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising any CCPA/CPRA rights.

13.3 How to Submit a California Privacy Request

Email admin@marathonsystema.com (subject: “California Privacy Request”) or call (307) 998-2092. We will respond to verified requests within 45 days.

14. Other U.S. State Privacy Rights

Residents of Virginia, Colorado, Connecticut, Texas, Florida, Nevada, and other states with applicable consumer privacy laws may have the right to access, correct, delete, and port their personal information. Email us at admin@marathonsystema.com with subject line “State Privacy Request” and your state of residence.

15. International Data Transfers

Marathon Systema LLC is operated by members who are Costa Rican nationals operating internationally. Your information may be accessed by personnel or systems located outside the United States, including in Costa Rica. By engaging our services, you acknowledge that your information may be transferred to and processed in jurisdictions outside your own.

16. Marketing Communications

Consistent with our service agreements, Marathon Systema LLC reserves the right to use completed project deliverables in our portfolio starting 90 days after delivery or upon the Client's public use of the materials, whichever occurs first.

To opt out of marketing communications, email admin@marathonsystema.com with subject line “Unsubscribe.” We will process your request within 10 business days.

17. Business-to-Business Context

If you are sharing personal information about third parties with us in connection with a project, you represent that you have the authority and all necessary rights and consents to do so. Marathon Systema LLC is not responsible for any failure on your part to obtain necessary consents, and you agree to indemnify us from any claims arising from unauthorized sharing of third-party personal information.

18. Third-Party Links and Services

Our website and communications may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party properties. We encourage you to review their privacy policies before providing any information.

19. Children's Privacy

Our services are directed exclusively to businesses and professionals. We do not knowingly collect personal information from individuals under the age of 18. If you believe we have collected information from a minor, contact us at admin@marathonsystema.com.

20. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, services, or legal requirements. When we make material changes, we will update the “Last Updated” date and notify active clients by email where reasonably practicable. Your continued engagement constitutes acceptance of the changes.

21. Contact Us

For questions, concerns, or requests related to this Privacy Policy:

Marathon Systema LLC

Attn: Privacy

30 North Gould Street, Ste R, Sheridan, WY 82801, USA

Email: admin@marathonsystema.com

Phone: (307) 998-2092

We are committed to resolving privacy concerns and will respond to inquiries within 30 business days.

To request deletion of your data, follow the steps on our Data Deletion Instructions page. The terms governing our services are in our Terms of Service.

This Privacy Policy was drafted to reflect the business practices of Marathon Systema LLC as of the Effective Date above. This document does not constitute legal advice.

© 2026 Marathon Systema LLC. All rights reserved.