Data Processing Agreement
This edition applies to the Closed Beta. It is written for the Service as it actually operates today: replies to Google Business Profile reviews, replies to Facebook and Instagram public comments and mentions, and replies to Messenger and Instagram direct messages, generated by OpenAI models, published either after your approval or autonomously according to your per-channel configuration. It does not cover functionality the Service does not have. When the Service changes, this Agreement must change with it.
Contents
- Definitions
- Scope, Roles and Precedence
- Instructions and Purpose Limitation
- Your Obligations as Controller
- Publishing Modes and Responsibility for Output
- AI Processing and No-Training Commitment
- Confidentiality and Personnel
- Security Measures
- Sub-processors
- International Transfers
- Data Subject Requests
- Personal Data Breach
- Impact Assessments and Prior Consultation
- Audit and Information Rights
- Deletion and Return
- Platform Terms Flow-Down
- EU AI Act Allocation
- Liability and Indemnity
- Term, Termination and Changes
- Governing Law and Jurisdiction
- Annex 1 — Details of Processing
- Annex 2 — Technical and Organisational Measures
- Annex 3 — Approved Sub-processors
- Annex 4 — Standard Contractual Clauses
This Data Processing Agreement (the "DPA") is entered into between [FULL REGISTERED NAME + ח.פ. / ע.מ. NUMBER], an Israeli [company / sole proprietorship] trading as "Maromel", of PO Box 123, Kokhav Ya'ir Tzur Yigal, Israel ("Maromel", "we", "Processor") and the customer identified in the applicable order or account registration ("Customer", "you", "Controller"). It is incorporated by reference into, and forms part of, the Terms of Use (the "Principal Agreement"). It takes effect on the date you first connect a Connected Account and requires no signature; we will execute a counter-signed copy on request.
1. Definitions
1.1. "Data Protection Laws" means all laws applicable to the processing under this DPA, including: Regulation (EU) 2016/679 ("GDPR"); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection; the Israeli Protection of Privacy Law, 5741-1981 and the Protection of Privacy Regulations (Data Security), 5777-2017; and the California Consumer Privacy Act as amended ("CCPA") and comparable United States state privacy legislation.
1.2. "Connected Account" means a Google Business Profile location, Facebook Page or Instagram professional account that you have authorised the Service to access.
1.3. "End User" means an individual who interacts with a Connected Account — by leaving a review or rating, posting a comment or mention, or sending a direct message.
1.4. "Interaction Content" means End User personal data received by the Service through a Connected Account, as itemised in Annex 1, together with the AI-generated replies to it.
1.5. "AI Input" means the prompt transmitted to the AI provider, comprising your Configuration Data and the text of the specific item being answered. "AI Output" means the reply text returned.
1.6. "Platform Data" means data obtained from Meta platforms. "Google User Data" means data obtained through Google APIs.
1.7. "Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. Under the CCPA, Maromel is a "service provider" and you are a "business"; under Israeli law, Maromel is a "holder" (מחזיק) and you are the "owner of the database" (בעל מאגר).
2. Scope, Roles and Precedence
2.1. Your data, your decisions. You are the Controller of Interaction Content. Maromel is the Processor and processes Interaction Content solely on your behalf and on your instructions.
2.2. Where Maromel is Controller. This DPA does not apply to personal data of you and your personnel — account, billing, usage, support and marketing data — in respect of which Maromel acts as an independent Controller under its Privacy Policy.
2.3. Independent controllers. Meta and Google are independent controllers in respect of their own platforms. Neither is a Sub-processor of Maromel. Data you cause to be published on those platforms is thereafter governed by their terms.
2.4. Precedence. In the event of conflict, the order of precedence is: (a) the Standard Contractual Clauses in Annex 4; (b) this DPA; (c) the Privacy Policy; (d) the Principal Agreement.
2.5. No CCPA sale. The parties acknowledge that no monetary or other valuable consideration is exchanged for personal information under this DPA, and that the disclosure of Interaction Content to Maromel is not a "sale" or "sharing" under the CCPA. Maromel will not retain, use or disclose Interaction Content other than to perform the Service, will not combine it with personal information received from other sources except as permitted for a service provider, and will comply with any applicable CCPA obligation directly imposed on service providers.
3. Instructions and Purpose Limitation
3.1. Documented instructions. Your documented instructions comprise: this DPA; the Principal Agreement; your configuration in the Dashboard, including the channels you enable, the publishing mode you select per channel, your brand voice, your response rules, your exclusions and your escalation thresholds; and any further written instruction you give us. We will not process Interaction Content for any other purpose.
3.2. Unlawful instructions. We will inform you without undue delay if, in our opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is amended or confirmed. We are not obliged to give legal advice and our failure to identify an unlawful instruction does not transfer your responsibility to us.
3.3. What we will not do. We will not: use Interaction Content for our own purposes; sell, rent or license it; use it for advertising, ad targeting or measurement; build or enrich profiles of End Users; combine it with the data of any other customer; disclose it other than as permitted by this DPA; or use it to train AI models (Section 6).
3.4. Compelled disclosure. If we receive a legally binding request from a public authority for Interaction Content we will, unless legally prohibited: notify you before responding; challenge the request where we consider there are reasonable grounds; disclose only the minimum required; and direct the authority to you as Controller. We will keep a record of such requests and provide a summary to you on request.
4. Your Obligations as Controller
4.1. You represent, warrant and undertake that:
- you have a valid legal basis for the collection and processing of Interaction Content, including for the use of AI-generated replies and for any automated processing of private messages;
- you have provided End Users with all information required by Data Protection Laws about how their data is used, including that responses may be generated automatically by AI and that a third-party processor and AI provider are involved, and have obtained any consent required in your markets;
- you hold, and will maintain, valid authority over every Connected Account you connect, including where you connect an account on behalf of another business, in which case you warrant that you have that business's authority to do so and that you will pass through the terms of this DPA to it;
- you comply with the Meta Platform Terms, the Meta Developer Policies, the Messenger and Instagram messaging policies, the Google Business Profile API terms and the Google API Services User Data Policy in your use of the Service;
- you will not input, and will not configure the AI agents to solicit, the categories of prohibited and sensitive data listed in Section 21 of the Privacy Policy;
- your instructions and configuration do not require us to process Interaction Content in a way that infringes Data Protection Laws;
- you will not use the Service for regulated advice, emergency or safety-critical communication, or on accounts whose primary audience is children;
- you will maintain the day-to-day oversight described in Section 5 and in Section 3 of the Privacy Policy.
4.2. You are responsible for the accuracy, quality and legality of the Configuration Data you supply, and for the consequences of factual errors in it. If your configuration tells the AI that a policy, price or entitlement exists, the AI will state that it does.
5. Publishing Modes and Responsibility for Output
5.1. You choose the mode per channel. The Service offers two publishing modes, and your Dashboard configuration determines which applies to each channel:
- Review & Approve Mode — AI Output is queued and is published or sent only after a human you authorise approves it. This is the default.
- Autonomous Mode — AI Output is published or sent without item-by-item approval, within the rules you configured. Enabling it requires an explicit confirmation in the Dashboard, which we log with the identity of the person who enabled it, the channel, and the timestamp.
5.2. You are the publisher of record in both modes. All content published or sent through a Connected Account is published in your name, under your platform account, and on your authority. As between the parties, you are the author and publisher of that content and bear sole responsibility for it, including for any claim in defamation, misrepresentation, consumer protection, unfair commercial practices, intellectual property, discrimination or breach of platform terms, and including where the content was generated by the AI and you did not read it before it was published. Maromel acts as a technical conduit executing your configuration and makes no representation about the content of any reply.
5.3. Autonomous Mode is your risk decision. You acknowledge that we have informed you that Review & Approve Mode reduces the risk of unsuitable content being published, that Autonomous Mode is offered as a convenience, and that by enabling it you accept the incremental risk of automated publication on the channels concerned. Nothing in this Section limits our own liability for a breach of this DPA or for a Personal Data Breach caused by us.
5.4. Safety measures are best-effort. We apply the filters, classifiers and escalation rules described in Section 12 of the Privacy Policy. They are probabilistic, will produce false positives and false negatives, and are a quality measure rather than a warranty. We do not warrant that unsuitable, unlawful or sensitive interactions will always be detected or escalated.
5.5. Human handover. Where an End User requests a human, or where an interaction is escalated, the Service stops automated replies on that conversation. You are responsible for staffing and monitoring that queue and for the consequences of failing to do so.
6. AI Processing and No-Training Commitment
6.1. The single AI Sub-processor. AI Input is transmitted to OpenAI, L.L.C. through its commercial API. OpenAI is our only AI Sub-processor. We do not transmit Interaction Content to any other model provider.
6.2. Data minimisation. AI Input contains only the text of the item being answered and your Configuration Data. It does not contain access tokens, billing data, the data of any other customer, or End User platform identifiers. Where your configuration calls for a personalised salutation, the End User's given name is included; you can disable that in the Dashboard.
6.3. No training — unconditional. Maromel will not, and will not permit any Sub-processor to, use Interaction Content, AI Input, AI Output, Configuration Data, Platform Data or Google User Data to train, fine-tune, retrain, benchmark or otherwise develop any generalised or foundation AI or machine-learning model. This commitment applies without exception, including to anonymised, pseudonymised or aggregated derivatives of that content. Where Maromel measures Service performance it does so using content-free statistical counters.
6.4. OpenAI's terms. We contract with OpenAI on its business API tier under a data processing agreement. As at the date of this DPA, OpenAI's published policies provide that API data is not used to train OpenAI models and is retained for up to thirty (30) days for abuse monitoring before deletion. Our configuration is recorded in Annex 3. If OpenAI materially changes those terms to your detriment we will notify you and, at your election, either move to a configuration that restores the position or allow you to terminate the affected part of the Service without penalty.
6.5. Model versions. We may change the model version we call within the same provider without notice, and will not do so in a way that increases the categories of data transmitted or reduces the protections in this Section.
7. Confidentiality and Personnel
7.1. We will treat Interaction Content as confidential and will not disclose it except as permitted by this DPA.
7.2. Access to Interaction Content is limited to personnel who need it to perform the Service, is granted on a least-privilege basis, is reviewed at least quarterly, and is revoked promptly on role change or departure.
7.3. All personnel with such access are bound by written confidentiality obligations that survive the end of their engagement, and receive privacy and security training at onboarding and at least annually.
7.4. Human review. Human reading of Interaction Content is limited to the circumstances in Sections 3.4 to 3.6 of the Privacy Policy. In particular, private message content is read only for a support request you raised, for a security or abuse investigation, where required by law, or under the separate Dashboard opt-in which is off by default. Every access is logged with the identity of the person and the reason, and the log is available to you on request for twelve (12) months.
8. Security Measures
8.1. We implement and maintain the technical and organisational measures set out in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing as well as the risks to Data Subjects.
8.2. We may update those measures provided the level of protection is not materially reduced. Annex 2 will be updated to reflect material changes.
8.3. We maintain the documentation required of a database holder under the Israeli Protection of Privacy Regulations (Data Security), 5777-2017, including the information security procedure, systems mapping, access register and incident register.
9. Sub-processors
9.1. General authorisation. You give general authorisation for Maromel to engage the Sub-processors listed in Annex 3.
9.2. Notice of changes. We will notify you by email, and by updating Annex 3, at least thirty (30) days before adding or replacing a Sub-processor that processes Interaction Content.
9.3. Objection. You may object on reasonable data protection grounds within fourteen (14) days of that notice. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees. Continued use after the notice period without objection constitutes approval.
9.4. Flow-down. Each Sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this DPA. Where the Sub-processor fails to fulfil those obligations, Maromel remains fully liable to you for the performance of that Sub-processor's obligations.
10. International Transfers
10.1. Maromel processes Interaction Content in Israel, which benefits from a European Commission adequacy decision reviewed and upheld in January 2024, and in the further locations listed in Annex 3.
10.2. For transfers of Interaction Content originating in the EEA, the UK or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses referenced in Annex 4 apply, completed as set out there, supplemented by the UK International Data Transfer Addendum for UK transfers and by the Swiss adaptations for Swiss transfers.
10.3. We conduct and document a transfer impact assessment for each such transfer and will provide it, with commercially sensitive content redacted, on request.
10.4. EEA-only processing. On your written request we will, subject to availability, configure your account to host Interaction Content in an EEA region and to route AI generation through OpenAI's EU regional endpoint.
11. Data Subject Requests
11.1. Where we receive a request from an End User to exercise a right in respect of Interaction Content, we will not respond to it substantively ourselves except as set out in 11.3, and will instead forward it to you within five (5) business days, identifying the Connected Account concerned.
11.2. We will provide reasonable assistance, at no additional charge for a proportionate volume of requests, to enable you to respond, including by providing search, export and deletion tools in the Dashboard.
11.3. Deletion requests we may action directly. To comply with our own obligations under the Meta Platform Terms and the Google API Services User Data Policy, we may action an End User's request to delete their data from our systems without waiting for your instruction, and will notify you when we do. This does not relieve you of your own obligation to respond to the End User.
11.4. We will not disclose Interaction Content to a person claiming to be a Data Subject without verifying identity, and will not disclose data relating to other individuals in the course of responding.
12. Personal Data Breach
12.1. We will notify you without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Interaction Content.
12.2. The notification will include, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point. Where information is not yet available we will provide it in phases without delaying the initial notification.
12.3. You are responsible for determining whether the breach must be notified to a Supervisory Authority or to affected End Users, and for making that notification. We will not notify your End Users directly unless required by law or instructed by you.
12.4. We will notify Meta and Google of incidents affecting Platform Data or Google User Data as required by their platform terms, and will inform you when we do.
12.5. A notification under this Section is not an admission of fault or liability.
13. Impact Assessments and Prior Consultation
13.1. We will provide reasonable assistance with your data protection impact assessments and any prior consultation with a Supervisory Authority, to the extent they relate to our processing and the information is not otherwise available to you.
13.2. We maintain our own impact assessment covering the AI processing of communications content and will make the relevant parts available to you.
14. Audit and Information Rights
14.1. On request, and no more than once in any twelve (12) month period unless required by a Supervisory Authority or following a Personal Data Breach, we will make available the information necessary to demonstrate compliance with this DPA, including our security documentation, our sub-processor list, our policies, and any third-party audit report or certification we hold.
14.2. Where that information is insufficient, you may conduct an audit, or mandate an independent auditor who is not a competitor of Maromel and who signs a confidentiality undertaking, on thirty (30) days' written notice, during business hours, without unreasonable disruption, and limited in scope to systems and records relevant to the processing of your Interaction Content. You bear the cost unless the audit reveals material non-compliance.
14.3. Audit rights do not extend to the data or systems of other customers, to source code, or to any information whose disclosure would breach a duty owed to a third party.
15. Deletion and Return
15.1. On termination of the Principal Agreement, on disconnection of a Connected Account, or on your written instruction, we will delete all Interaction Content in our possession within thirty (30) days, and purge it from encrypted backups by expiry of the rolling thirty-five (35) day backup cycle.
15.2. Before deletion you may export your interaction history in a structured, machine-readable format from the Dashboard. We will retain the data for thirty (30) days after termination to allow you to do so, unless you instruct immediate deletion.
15.3. We may retain Interaction Content beyond those periods only where and for as long as required by law, in which case we will isolate it, cease all other processing, and delete it when the requirement ends. We will tell you which categories are affected and why.
15.4. We will certify deletion in writing on request.
16. Platform Terms Flow-Down
16.1. Both parties acknowledge that the Meta Platform Terms, the Meta Developer Policies, the Messenger and Instagram messaging policies, the Google Business Profile API terms and the Google API Services User Data Policy apply to the processing and that, where those terms impose a stricter obligation than this DPA, the stricter obligation prevails.
16.2. Maromel undertakes, in respect of Platform Data and Google User Data: not to sell, license or purchase it; not to use it for advertising, retargeting or ad measurement; not to transfer it to a data broker, advertising network or monetisation platform; not to use it to build or augment profiles; not to use it for credit, insurance, employment, housing or education eligibility decisions; not to use it to train generalised AI models; to restrict human access as set out in Section 7.4; to delete it on disconnection, on a valid deletion request, or when no longer needed; and to maintain a published vulnerability reporting channel.
16.3. You undertake the equivalent obligations in respect of your own use of the Service and of the content it publishes on your behalf, and will not use the Service in a manner that would cause Maromel to breach a platform term.
16.4. Either party may suspend the affected processing where continuing it would breach a platform term, on notice to the other.
17. EU AI Act Allocation
17.1. For the purposes of Regulation (EU) 2024/1689, whose Article 50 transparency obligations became applicable on 2 August 2026, the parties record that Maromel acts as the provider of the AI system and you act as its deployer.
17.2. Maromel will: design and deliver the Service so that individuals interacting directly with an AI agent are informed that they are interacting with an AI system, no later than the first interaction; provide that disclosure as a default-on control that cannot be disabled for individuals in the European Union or the United Kingdom; implement machine-readable marking of AI-generated text output in accordance with the transition period applicable to generative systems placed on the market before 2 August 2026; provide you with the information you need to meet your own obligations as deployer; and maintain technical documentation of the system.
17.3. You will: operate the Service with the disclosure control enabled wherever required by law; not attempt to remove, obscure or override any AI disclosure or marking; supply accurate Configuration Data; exercise the human oversight described in Section 5; and comply with any obligation that attaches to you as deployer, including any obligation to inform your own staff or audience.
17.4. If you disable a disclosure in a jurisdiction where it is required, or override it by technical means, you assume sole responsibility for the resulting non-compliance and will indemnify Maromel under Section 18.4.
18. Liability and Indemnity
18.1. Each party bears its own compliance. Each party is responsible for its own compliance with Data Protection Laws in its own role. Nothing in this DPA transfers a statutory obligation of a Controller to a Processor, or of a Processor to a Controller.
18.2. Cap. Subject to Sections 18.3 and 18.5, each party's aggregate liability arising out of or in connection with this DPA is subject to the limitation of liability in the Principal Agreement, and the liability of both parties together under the Principal Agreement and this DPA does not exceed that cap in aggregate. Where no fees or only nominal fees have been paid, that cap is the greater of (a) the fees paid by the Customer in the twelve (12) months preceding the claim and (b) twenty-five thousand New Israeli Shekels (ILS 25,000).
18.3. What cannot be capped. Nothing in this DPA limits liability that cannot be limited by law, including liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, wilful misconduct, or a Data Subject's statutory rights under Article 82 of the GDPR or comparable provisions. The parties acknowledge that an administrative fine imposed on a party by a Supervisory Authority for its own infringement cannot be shifted to the other party by contract.
18.4. Your indemnity. You will indemnify Maromel against all losses, claims, fines, damages, costs and reasonable legal fees arising out of: (a) content published or sent through your Connected Accounts, including any claim in defamation, misrepresentation, consumer protection, discrimination or intellectual property; (b) your lack of a lawful basis, notice or consent for the processing of Interaction Content; (c) inaccurate, unlawful or misleading Configuration Data you supplied; (d) your breach of a platform term or of Section 4, 5, 16.3 or 17.3; (e) your input of prohibited or sensitive data contrary to Section 23 of the Privacy Policy; or (f) your disabling or overriding of an AI disclosure where it was required.
18.5. Our indemnity. Maromel will indemnify you against losses, claims, fines, damages and reasonable legal fees arising out of a Personal Data Breach caused by Maromel's breach of Section 8, or Maromel's processing of Interaction Content in breach of Section 3.3 or 6.3, subject to the cap in Section 18.2.
18.6. Beta acknowledgement. You acknowledge that the Service is a closed beta, that it is provided without warranty of accuracy, availability or fitness for a particular purpose, and that you have chosen to use it on that basis. This does not limit Maromel's obligations under Sections 3, 6, 7, 8, 12 or 15, which apply in full during the Beta.
18.7. Conduct of claims. The indemnified party will notify the indemnifying party promptly, will not settle without consent, and will provide reasonable cooperation at the indemnifying party's cost.
19. Term, Termination and Changes
19.1. This DPA takes effect when you first connect a Connected Account and continues until all Interaction Content has been deleted or returned in accordance with Section 15. Sections 7, 15, 18 and 20 survive termination.
19.2. We may amend this DPA where necessary to reflect a change in Data Protection Laws, a platform requirement, a change to the Sub-processor list, or a change to the Service. We will notify you at least thirty (30) days before a material amendment takes effect, except where a shorter period is required by law or by a platform. If a material amendment materially reduces your protection you may terminate within that period without penalty.
19.3. The current version is always published at maromel.com/dpa. Previous versions are available on request.
20. Governing Law and Jurisdiction
20.1. This DPA is governed by the laws of the State of Israel, and the competent courts of Tel Aviv-Jaffa have exclusive jurisdiction, except that the Standard Contractual Clauses in Annex 4 are governed by the law and subject to the jurisdiction specified in those Clauses.
20.2. Nothing in this Section deprives a Data Subject of a remedy or forum available to them under mandatory law.
Annex 1 — Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Retrieval of customer interactions from the Customer's Connected Accounts, generation of reply text using an AI model, and publication or sending of that reply through the same platform, together with display of interaction history in the Dashboard. |
| Duration | The term of the Principal Agreement, plus the retention and deletion periods in Section 14 of the Privacy Policy and Section 15 of this DPA. |
| Nature of the processing | Collection via platform API, storage, structuring, display, transmission to the AI Sub-processor for text generation, automated content filtering and classification for escalation, transmission back to the platform for publication, logging, and erasure. |
| Purpose | Providing the Service: enabling the Customer to respond to reviews, comments, mentions and direct messages at scale, in the Customer's brand voice, in Review & Approve Mode or Autonomous Mode as configured. |
| Categories of Data Subjects | Individuals who leave reviews or ratings on the Customer's Google Business Profile; individuals who comment on or mention the Customer's Facebook Page or Instagram account; individuals who send direct messages to the Customer via Messenger or Instagram. Also the Customer's own personnel who use the Dashboard. |
| Categories of Personal Data | Display name or handle; profile picture URL; platform-scoped user identifier; the content of the review, rating, comment, mention or message, including any personal data the individual chose to include in it; conversation, message, post and review identifiers; timestamps; delivery and read status; the reply text generated and published; and the approval audit trail. |
| Special categories | None requested, none required and none intentionally processed. Special category data may nevertheless appear where an individual volunteers it in free text. Such content is escalated for human handling under Section 12 of the Privacy Policy and is not used to infer characteristics. Processing is limited to what is necessary to route or answer the specific interaction. |
| Frequency | Continuous, event-driven via platform webhooks and periodic polling, for as long as the Connected Account remains connected. |
| Data not processed | End User email addresses, phone numbers, friend or contact lists, location history, payment data, advertising identifiers, and any platform data outside the scopes granted for the enabled channels. |
Annex 2 — Technical and Organisational Measures
Maromel implements and maintains at least the following. This Annex mirrors Section 16 of the Privacy Policy and must be kept accurate: an inaccurate Annex 2 is itself a compliance exposure.
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2 or above on all external connections, including to platform and AI provider APIs |
| Encryption at rest | AES-256 on all databases, object storage and backups |
| Secrets and tokens | OAuth access and refresh tokens held in a dedicated secrets manager with separate key management, never in source code, configuration files or logs; never displayed in the Dashboard |
| Access control | Role-based, least privilege, mandatory multi-factor authentication for production access, quarterly access review, prompt revocation on role change or departure |
| Tenant isolation | Logical separation with tenant-scoped authorisation enforced on every request; no cross-customer data access path |
| Logging and monitoring | Centralised, tamper-evident audit logs of administrative actions and access to Interaction Content, retained 12 months; alerting on anomalous access |
| Secure development | Peer code review, dependency and secret scanning in CI, static analysis, pre-release security testing, separated development, staging and production environments with no production data in lower environments |
| Vulnerability management | Published reporting channel at security@maromel.com, triage within 3 business days, remediation prioritised by severity, and an external penetration test to be commissioned before general release |
| Backup and recovery | Encrypted daily backups with a 35-day rolling retention, restoration tested at least quarterly, documented business continuity plan |
| Incident response | Written plan with defined roles, escalation path and notification timelines; tested at least annually; incident register maintained |
| Personnel | Written confidentiality undertakings, privacy and security training at onboarding and annually, background screening where lawful |
| Vendor management | Security and privacy assessment before engagement, written data protection terms, periodic reassessment |
| Data minimisation | Only the platform scopes required for enabled channels are requested; AI Input restricted per Section 6.2; retention limits enforced by automated deletion jobs |
| Deletion | Automated enforcement of the retention schedule; deletion on disconnection, account closure and valid deletion request; backup purge on cycle expiry |
| Certifications | None at this stage. Maromel does not hold SOC 2, ISO 27001 or equivalent certification and makes no such claim. |
Annex 3 — Approved Sub-processors
As at the "Last Updated" date. This Annex must match Annex D of the Privacy Policy at all times.
| Sub-processor | Purpose | Data | Location | Safeguard |
|---|---|---|---|---|
| OpenAI, L.L.C. | AI reply generation — sole AI provider | AI Input and AI Output only | United States (api.openai.com). Standard abuse monitoring: retained up to 30 days, not used to train OpenAI models. An EU regional endpoint is available on request. | DPA; SCCs and/or DPF |
| Vercel Inc. | Application hosting and compute | All categories | United States | DPA; SCCs and/or DPF |
| Supabase Inc. | Database and encrypted object storage | All categories | United States | DPA; SCCs |
| Resend Inc. | Transactional and security email | User contact data. No Interaction Content. | United States | DPA; SCCs and/or DPF |
Annex 4 — Standard Contractual Clauses
4.1. Where Interaction Content originating in the EEA is transferred to a Sub-processor in a third country without an adequacy decision, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference, with:
- Module Two (Controller to Processor) applying between the Customer as data exporter and Maromel as data importer where the Customer is established in the EEA; Module Three (Processor to Processor) applying between Maromel and its Sub-processors;
- Clause 7 (docking clause): applies;
- Clause 9(a): Option 2, general written authorisation, with a notice period of thirty (30) days as provided in Section 9.2;
- Clause 11(a) optional independent dispute resolution body: does not apply;
- Clause 13 and Annex I.C competent supervisory authority: the supervisory authority of the Member State in which the Customer is established; where the Customer is not established in the EEA and has not designated a representative under Article 27, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located, in accordance with Clause 13(a);
- Clause 17 governing law: Option 1 — the law of Ireland;
- Clause 18(b) forum: the courts of Ireland;
- Annex I.A (parties) is completed by the identification of the parties in the preamble to this DPA; Annex I.B (description of transfer) is completed by Annex 1 above; Annex II (technical and organisational measures) is completed by Annex 2 above; Annex III (sub-processors) is completed by Annex 3 above.
4.2. United Kingdom. For transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018 applies, with the SCCs as completed above as the Approved EU SCCs, Tables 1 to 3 completed by reference to this DPA and its Annexes, and Table 4 specifying that neither party may end the Addendum as set out in Section 19 of the Mandatory Clauses.
4.3. Switzerland. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Federal Data Protection and Information Commissioner, and the Clauses also protect data of legal entities until Swiss law provides otherwise.
4.4. Where the SCCs conflict with any other provision of this DPA, the SCCs prevail.
Before publishing: complete the legal entity name and registration number in the preamble — it is the only field left — and make sure Annex 2 describes measures you have actually implemented. Overstating your security posture in Annex 2 turns a security question into a misrepresentation question. This document was prepared as a drafting aid and is not legal advice.