This Data Processing Agreement ("DPA") forms part of the agreement between Markin AI, S.L. ("Markin", processor) and the enterprise customer ("Customer", controller) that has subscribed to the Markin platform.
1. Subject matter
Markin processes personal data on behalf of Customer to provide the Service described in the order form: ingesting Customer Data, detecting revenue opportunities, generating candidate actions, running experiments and returning 1:1 next best actions.
2. Nature and purpose of processing
Storage, structuring, analysis, machine-learning inference, and transmission of Customer Data solely for the purpose of providing the Service, ensuring its security and improving its reliability.
3. Categories of data subjects and data
End users of Customer's B2C products; business contacts of Customer. Data typically includes identifiers, transactional events, product usage events, subscription attributes and communication metadata. Special categories of data are not required and should not be sent to the Service.
4. Duration
For the duration of the subscription and the retention window agreed in the order form. On termination, Markin will delete or return Customer Data within 30 days.
5. Markin's obligations
- Process personal data only on documented instructions from Customer.
- Ensure staff authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (see Security Measures).
- Assist Customer with data subject requests and DPIAs.
- Notify Customer without undue delay of a personal data breach.
6. Subprocessors
Customer authorises Markin to engage the subprocessors listed at /legal/subprocessors. Markin will provide prior notice of any addition or replacement and Customer may object on reasonable grounds.
7. International transfers
Where personal data leaves the EEA, Markin relies on the European Commission's Standard Contractual Clauses (Module 3) and applies supplementary measures as needed.
8. Security measures
Encryption in transit and at rest, least-privilege access with SSO and MFA, network isolation, audit logging, key rotation, backup and restore testing, and regular third-party penetration testing.
9. Audit
Markin will make available to Customer information necessary to demonstrate compliance and, on reasonable notice, allow audits conducted by an independent auditor bound by confidentiality.
10. Signature
This DPA is incorporated by reference into the order form. Customers who require a signed copy should contact legal@markin.ai.