Your privacy and data security are our top priorities. Learn how we protect your healthcare information in compliance with global regulations including HIPAA, GDPR, and other privacy laws.
Mercato Agency ("Mercato", "we", "us") is committed to protecting the personal data of our clients, partners, and website users. We are the data controller for personal information collected through our website and related services globally.
Our practices comply with applicable data protection laws including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Australian Privacy Act (APPs), the New Zealand Privacy Act, and other relevant regulations.
Enterprise-grade security measures
HIPAA, GDPR, CCPA certified
Clear data handling practices
We collect various categories of personal data when you use Mercato's website or services, or when we otherwise interact with you:
We may collect sensitive categories of data (health, race, etc.) only if you voluntarily provide them and only with explicit consent. We never collect children's data under 16 without parental consent.
Mercato uses personal data only for legitimate business purposes, based on lawful grounds under GDPR Article 6:
Providing and improving our AI-powered marketing and lead-generation services
Emails, customer support, billing and account management
Understanding usage patterns and tailoring content to your preferences
Verifying identity, preventing abuse, and complying with legal obligations
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction:
TLS for data in transit, AES-256 for data at rest
Multi-factor authentication and principle of least privilege
Continuous security monitoring and intrusion detection
ISO/IEC 27001 and NIST framework alignment
Regular security awareness and best practices training
Comprehensive breach notification and response plan
Mercato respects your privacy rights under applicable laws. Depending on your location, you may have the following rights:
To exercise any of these rights, please contact us using the information provided in the Contact section below. We will verify your identity and respond within legal timeframes (typically 30 days).
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
📧 privacy@mercato.com
🏢 Mercato Agency
📍 Attn: Privacy Department
You may also lodge a complaint with your local data protection authority if you believe your privacy rights have been violated. We are committed to working with authorities to resolve any concerns.
We may update this Privacy Policy from time to time. Significant changes will be notified on our website or via email. This policy applies globally and incorporates all applicable data protection regulations.