Data Processing Agreement (DPA)
Last updated: 17.07.2026
This Data Processing Agreement ("DPA") is an integral annex to Marrek's Terms of Use and applies whenever Marrek processes personal data on behalf of the Client acting as Controller.
1. Processing Instructions and CCPA/GDPR Requirements
Marrek (Processor/Service Provider) processes data solely on the documented instructions of the Client (Controller/Business).
Marrek is prohibited from: selling or sharing information; using data outside the scope of providing the service; combining consumer data from other sources.
Marrek undertakes to reasonably assist the Controller in responding to Data Subject Requests.
2. List of Sub-processors
The Client authorizes the engagement of the following sub-processors:
Google Cloud Console — cloud hosting and database storage (USA / EU).
WayForPay — payment and subscription processing (Ukraine / EU).
OpenRouter — AI request routing (ZDR endpoints) (USA).
Meta / Telegram — messaging platforms (global).
Marrek will notify the Client 30 days before changing or adding new sub-processors.
3. Technical and Organizational Measures (TOMs)
To protect data, Marrek implements the following security measures (Technical and Organizational Measures):
Encryption: all data is transmitted over TLS 1.2+ (in transit) and encrypted at rest on Google Cloud servers.
Access Control (RBAC): only authorized personnel have access to databases, on a need-to-know basis (Role-Based Access Control).
Authentication: multi-factor authentication (MFA) is used for administrators.
Monitoring: continuous logging and infrastructure monitoring for threats.
Backups: automatic database backups, retained for no more than 90 days.
4. Audit and Data Breach
The Controller (Client) has the right to conduct reasonable audits or request documented confirmation from Marrek of compliance with data protection requirements.
In the event of a personal data breach, Marrek will notify the Client without undue delay (within 48–72 hours) to meet GDPR requirements.
5. International Data Transfers (SCCs)
Transfers of data from the Client in the EU to Ukraine are governed by Module 2 of the SCCs (Controller-to-Processor), and transfers from Marrek to OpenRouter (USA) are governed by Module 3 of the SCCs.
This document is provided for informational purposes and does not constitute legal advice. The current version may be updated.
