Data Processing Agreement

Effective September 1, 2026

Effective date: 1 September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between MARMEND OÜ, registry code 16861477, Narva mnt 5, 10117 Tallinn, Estonia ("Marmend", the "Processor") and the Customer (the "Controller"), and applies automatically to all Customers whenever Marmend processes personal data on the Customer's behalf. It implements Article 28 GDPR.

1. Roles and Scope

For Customer Data — personal data the Customer or its users submit to the Customer's workspace — the Customer is the controller and Marmend is the processor. Marmend processes Customer Data only to provide the Service and only on the Customer's documented instructions, which are given through the Customer's configuration and use of the Service and these Terms, unless required otherwise by EU or Estonian law (in which case Marmend informs the Customer before processing, unless the law prohibits it).

2. Details of Processing

  1. Subject matter and duration: provision of the Marmend HR and recruiting platform for the duration of the contract, plus the 30-day post-termination export window.
  2. Nature and purpose: hosting, storage, transmission, display, analysis (including optional AI-assisted features enabled by the Customer) and related processing needed to deliver HR and recruiting workflows.
  3. Categories of data subjects: the Customer's job candidates, employees, contractors and platform users.
  4. Categories of personal data: identification and contact details, CVs and application materials, employment records, interview notes and assessments, communications, scheduling data, and any other personal data the Customer chooses to store. The Customer is responsible for not submitting special categories of data unless it has a lawful basis to do so.

3. Processor Obligations

Marmend shall: (a) ensure persons authorized to process Customer Data are bound by confidentiality; (b) implement appropriate technical and organizational measures under Article 32 GDPR, including per-tenant data isolation, encryption in transit and access controls; (c) taking into account the nature of the processing, assist the Customer in responding to data-subject requests and in meeting its obligations under Articles 32–36 GDPR; (d) notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data; (e) at the end of the contract, enable the Customer to export Customer Data for 30 days and then delete it from production systems (backups purge on their rotation schedule); (f) make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits as described in Section 6.

4. Subprocessors

The Customer grants Marmend general authorization to engage subprocessors. Marmend currently uses:

  1. Hetzner Online GmbH (Germany) — cloud hosting of the Service.
  2. Amazon Web Services (Frankfurt region, Germany) — file storage (Amazon S3), including uploaded documents such as CVs, and transactional email delivery (Amazon SES).
  3. Stripe — payment processing.
  4. OpenAI (USA) — certain optional AI-assisted features, engaged only where the Customer enables those features.

Marmend's own AI models run on private infrastructure in Poland and involve no additional subprocessor. Marmend will inform Customers of intended additions or replacements, giving the Customer the opportunity to object on reasonable data-protection grounds; Marmend imposes data-protection obligations on subprocessors equivalent to those in this DPA and remains liable for their performance.

Third-party integrations the Customer connects itself (e.g. Google, Microsoft, LinkedIn, Telegram, Robota.ua) are engaged by the Customer directly and are not Marmend subprocessors.

5. International Transfers

Customer Data is processed within the European Economic Area — in Germany (Hetzner and the AWS Frankfurt region) and Poland (Marmend's own AI infrastructure). A transfer outside the EEA occurs only where the Customer enables optional AI features powered by OpenAI (USA); such transfers are protected by an adequacy decision (the EU–US Data Privacy Framework) or the Standard Contractual Clauses with appropriate supplementary measures.

6. Audits

Marmend will make available documentation (including summaries of security measures and, where available, third-party attestations) sufficient to demonstrate compliance. Where the Customer reasonably requires more, an audit may be conducted no more than once per year, on at least 30 days' notice, during business hours, without disrupting the Service, and subject to confidentiality.

7. Liability and Precedence

The liability provisions of the Terms of Service apply to this DPA. If this DPA conflicts with the Terms regarding the processing of personal data, this DPA prevails.

Contact: [email protected] — MARMEND OÜ, Narva mnt 5, 10117 Tallinn, Estonia. Customers requiring a countersigned copy of this DPA may request one at the same address.