This Data Processing Agreement ("DPA") applies automatically to all customers entering into an agreement with Marad B.V. under the General Terms and Conditions, and governs the processing of personal data by Marad as a processor on behalf of the customer under the GDPR. No separate signature is required.
Article 1 — Definitions
This agreement uses the definitions of the GDPR, including Controller (the customer), Processor (Marad), Personal Data, and Data Subject. Marad B.V. acts as the Processor under this agreement.
Article 2 — Applicability
Customers accept this DPA by entering into agreements with Marad. The customer is the Controller and is responsible for the processing of the Personal Data. The control over the Personal Data is never with Marad.
Article 3 — Description of processing
Marad processes data to deliver its software services, including SaaS platforms and support. Categories of personal data include names, email addresses, job titles, login credentials, and user activity data. Processing continues for the duration of the agreement plus any legally required retention period. Annex 1 sets out the categories of personal data processed in more detail.
Article 4 — Marad's responsibilities
Marad commits to processing personal data exclusively per the customer's instructions and in accordance with GDPR requirements. Marad will not share personal data with or provide it to third parties, unless Marad has obtained prior written permission or instruction from the customer.
Article 5 — Customer responsibilities
The customer must ensure legal compliance, determine the purposes of processing, inform data subjects, and provide accurate data to Marad.
Article 6 — Subprocessors
Marad engages subprocessors as listed on the subprocessors page. Customers receive at least 14 days' notice of any change and may object on data protection grounds within that window. See Annex 2.
Article 7 — Security and data breach
Marad implements technical and organisational measures in line with ISO 27001, as set out in Annex 3. Marad shall notify the customer no more than 24 hours after Marad has become aware of a data breach that has or may have involved access to personal data.
Article 8 — Confidentiality
Personal data processed under this agreement remains confidential. Disclosure to any third party requires written customer permission, unless required by law.
Article 9 — Support access
Named senior engineers may access customer environments for support purposes. Access is logged, multi-factor authenticated, and limited to the personnel necessary to resolve the matter. Access logs are retained for at least 12 months.
Article 10 — Compliance monitoring
Customers may request information about Marad's processing activities, and Marad will respond within five working days. Customers may commission an independent inspection once per year, at the customer's expense.
Article 11 — Duration and termination
Upon termination of the agreement, Marad will destroy the customer's personal data within four weeks after the applicable statutory retention periods expire. Customers may request an accessible copy of their data within two months of termination.
Article 12 — Liability
Standard liability provisions under the General Terms and Conditions apply to this DPA; limitations imposed by mandatory law cannot be overridden.
Article 13 — Governing law
Dutch law governs this DPA. Disputes are submitted to the District Court of Midden-Nederland, in accordance with Article 19 of the General Terms and Conditions.
Article 14 — Closing provisions
Marad may amend this DPA with 30 days' written notice, provided the level of data protection does not diminish. Customers may object to a material change and terminate the affected services with reasonable notice.
Annex 1 — Categories of personal data
Identification data, account data, communication data, marketing data, financial data, legal data, and technical data processed in connection with the delivery of Marad's services.
Annex 2 — Subprocessors
The current subprocessor list is maintained online at marad.com/legal/subprocessors.
Annex 3 — Security measures
Encryption, access controls, backups, incident management, physical security, vulnerability assessments, personnel training, and logging, consistent with Marad's ISO 27001 certification. See the Trust Centre for further detail on Marad's security controls.