Data processing agreement
In short
- If we build or maintain a system that handles data about your users or customers, you're the controller and we're the processor: we process that data only for your project and on your instructions.
- We protect it with technical and organisational measures, keep it confidential and help you with your users' requests and with any breaches.
- We use sub-processors (hosting, database, email, AI), which we list for you, and we tell you before adding a new one.
- When the work ends, we return or delete the data.
- This agreement forms part of every services contract in which we process data on your behalf, with no need to sign it separately.
This summary helps you find your way; it doesn't replace the full text.
1. The parties and when it applies
This agreement is made between the client (“the controller”) and Martín Silva Molina, who operates The Mariscal (Ul. Ivana Rendića 28b, 10000 Zagreb, Hrvatska), “the processor”, and meets art. 28(3) of Regulation (EU) 2016/679 (GDPR). It applies when, in providing the services under the Terms of service (development, hosting, maintenance, support, AI agents), the processor processes personal data on the controller's behalf. It forms part of the services contract from the moment the proposal is accepted; it can also be signed if needed.
If a proposal or a signed contract governs the processing differently, what's agreed there prevails, as long as it complies with art. 28 GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter
- The project services described in the proposal.
- Duration
- For as long as the services contract lasts and, after that, for the time needed to return or delete the data as set out in “When the work ends”.
- Nature
- Developing, testing, deploying, hosting, backing up, supporting and maintaining the controller's system; access to its data only when that work requires it.
- Purpose
- Running, maintaining and improving the controller's system, on its instructions.
3. Types of data and data subjects
Whatever the controller decides to process in its system, as described in the proposal. Typically:
- Data subjects: the controller's users, customers, subscribers, employees or contacts.
- Data: identity and contact details (name, email, phone), account data, orders and order history, messages and content they upload, technical data (IP address, device, logs) and whatever users write to an AI agent.
- Special category data (art. 9 GDPR) or children's data: only if the proposal expressly says so, and with the additional measures agreed there.
4. The controller's responsibilities
- Having a lawful basis for each processing activity and informing its users (through its own privacy policy).
- Giving lawful, documented instructions: the proposal, this agreement and anything it asks for in writing during the project.
- Deciding what data is processed, what for and how long it's kept.
5. The processor's commitments
- To process the data only on the controller's documented instructions, including for transfers to third countries, unless the law requires otherwise (in which case it tells the controller first, where the law allows). If an instruction seems to breach the GDPR, it says so straight away.
- To make sure the people authorised to process the data have committed to confidentiality or are under a legal duty of confidentiality.
- To apply the art. 32 GDPR security measures described in Security measures.
- To follow the rules on sub-processors in Sub-processors.
- To help the controller, as far as possible, respond to data subjects' requests (access, rectification, erasure, objection, portability…). If a data subject writes to the processor directly, it passes the request on to the controller without answering on its behalf.
- To help the controller comply with arts. 32 to 36 GDPR (security, breaches, impact assessments and prior consultation), based on the information it has.
- When the work ends, to return or delete the data, as the controller chooses (When the work ends).
- To give the controller the information it needs to show compliance, and to allow and contribute to audits, as set out in Audits.
6. Security measures
- Encryption in transit (HTTPS/TLS) and, with the providers that offer it, at rest.
- Least-privilege access: only the people working on the project, with personal accounts, two-step verification wherever possible and limited permissions; access is revoked when the work ends.
- Access control in the application: every function that touches data checks the session and who owns the data.
- Separate environments: development uses test data; real data lives only in production.
- Backups before every significant change and according to the database provider's plan.
- Logging and error monitoring without unnecessary personal data.
- Abuse limits (rate limiting) on public functions.
- Dependency reviews and security updates during the maintenance period you've contracted.
7. Sub-processors
The controller gives the processor general authorisation to use sub-processors. The ones we usually use are listed below; each project's proposal says which apply (and any the controller engages in its own name aren't our sub-processors):
| Sub-processor | Service | Location |
|---|---|---|
| Vercel Inc. | Hosting and server functions | USA and global network |
| Convex, Inc. | Database and functions | USA |
| Clerk, Inc. | Accounts and sign-in | USA |
| Cloudflare, Inc. | DNS, network and file storage | USA and global network |
| Resend (Plus Five Five, Inc.) | Sending emails | USA |
| PostHog, Inc. | Analytics (with users' consent) | EU (Frankfurt) |
| Functional Software, Inc. (Sentry) | Error tracking | EU (Germany) |
| AI model providers chosen for the project (for example Groq, Cerebras, OpenAI, Anthropic or Google) | AI agent responses | Depends on the provider, stated in the proposal |
- The processor imposes on each sub-processor, by contract, data protection obligations equivalent to those in this agreement, and remains liable to the controller for them.
- Before adding or replacing a sub-processor, it gives notice by email at least 30 days in advance (or less if it's urgent for security reasons). The controller can object on reasonable grounds within that period; if no alternative can be found, either party can terminate the affected part of the service without penalty.
8. International transfers
When a sub-processor processes data outside the European Economic Area, the transfer relies on a Chapter V GDPR safeguard: an adequacy decision (for example, the EU-US Data Privacy Framework for certified providers) or the European Commission's standard contractual clauses (Decision (EU) 2021/914), with any supplementary measures needed.
9. Security breaches
If the processor becomes aware of a security breach affecting the controller's data, it notifies the controller without undue delay and within 48 hours at the latest of becoming aware of it, with the information available (what happened, what data and roughly how many data subjects, the likely consequences, the measures taken or proposed, and a contact), and fills in the rest as it comes to light. That way the controller can notify the authority within the 72 hours required by art. 33 GDPR.
10. Audits
The processor answers the controller's reasonable questionnaires about the processing in writing and provides the security documentation its sub-processors publish. If that isn't enough, the controller can request an audit, with 30 days' notice, during business hours, no more than once a year (except after a breach or at an authority's request), at its own expense and carried out by an auditor bound by confidentiality. Sub-processors are audited through their certifications and reports.
11. When the work ends
When the service ends, the processor hands the controller its data in a common format (for example, JSON or CSV) or transfers it to the controller's accounts, as the controller chooses, and then deletes it from the systems it controls within 30 days (backups are deleted on their normal cycle, within at most another 90 days), unless the law requires it to be kept. On request, it confirms the deletion in writing.
12. Liability and precedence
Each party's liability is governed by art. 82 GDPR and the Terms of service. If this agreement conflicts with another part of the contract on data protection, this agreement prevails. Questions or requests: hey@themariscal.com.
Versions
- v1.0 · 11 October 2026 · First version.