Privacy Policy
Effective September 1, 2026
Effective date: 1 September 2026
This Privacy Policy explains how MARMEND OÜ, registry code 16861477, Narva mnt 5, 10117 Tallinn, Estonia ("Marmend", "we", "us") collects, uses and protects personal data in connection with the Marmend platform ("Service") and our websites. We process personal data in accordance with the EU General Data Protection Regulation ("GDPR").
1. Our Two Roles
Marmend acts in two distinct capacities:
As a controller, for data we decide how and why to process: your account and registration data, billing information, website visitor data, support communications and marketing. This Policy covers that processing.
As a processor, for Customer Data — the candidate records, CVs, employee records and communications that our Customers store in their workspaces. For that data, the Customer (typically your employer or the company recruiting you) is the controller, and we process it only on their instructions under our Data Processing Agreement. If you are a candidate or employee whose data is held in a Customer's workspace, please direct privacy requests to that organization first — they control the data, and we will assist them in responding.
2. Data We Collect as a Controller
- Account data: name, email address, password (hashed), workspace and role information you provide at registration.
- Billing data: company details, VAT number, and payment records. Card details are handled by our payment processor (Stripe) and never stored on our systems.
- Usage and log data: IP address, browser and device information, pages visited, and actions taken in the Service, used for security and to operate and improve the Service.
- Cookies and similar technologies: as described in our Cookie Policy.
- Communications: messages you send to support or through our contact forms.
3. Purposes and Legal Bases
- Performance of a contract (Art. 6(1)(b) GDPR): providing the Service, managing your account, billing and support.
- Legitimate interests (Art. 6(1)(f) GDPR): securing the Service, preventing abuse, and improving our product based on aggregate usage.
- Consent (Art. 6(1)(a) GDPR): analytical cookies and marketing communications. Consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c) GDPR): accounting and tax record-keeping under Estonian law.
4. Sharing and Subprocessors
We share personal data only with service providers who process it on our behalf and under contract:
- Hetzner Online GmbH (Germany) — cloud hosting of the Service.
- Amazon Web Services (Frankfurt region, Germany) — file storage (Amazon S3), including uploaded documents such as CVs, and transactional email delivery (Amazon SES).
- Stripe — payment processing.
- OpenAI (USA) — certain optional AI-assisted features, where enabled.
Our own AI models run on private infrastructure in Poland and involve no additional third party. An up-to-date subprocessor list is always available at [email protected].
Where a Customer connects a third-party integration (e.g. Google Calendar, Gmail, Microsoft Outlook, LinkedIn, Telegram, Robota.ua), data flows to that provider under the Customer's instruction and the provider's own terms.
We may also disclose data where required by law or to protect our legal rights.
5. International Transfers
Our infrastructure is located in the European Economic Area — Germany (Hetzner and the AWS Frankfurt region) and Poland (our own AI infrastructure). Personal data is transferred outside the EEA only where optional AI features powered by OpenAI (USA) are used; such transfers are protected by the EU–US Data Privacy Framework or the Standard Contractual Clauses, together with appropriate supplementary measures.
6. Retention
We keep account data for as long as your account is active and delete or anonymize it after termination, subject to the 30-day export window described in our Terms of Service and to statutory retention duties (e.g. Estonian accounting law requires financial records to be kept for 7 years). Backups are purged on their rotation schedule.
7. Your Rights
Under the GDPR you have the right to access, rectify, erase and receive a copy of your personal data, to restrict or object to its processing, and to withdraw consent at any time. To exercise these rights, contact [email protected]. You also have the right to lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) — or with the authority in your country of residence.
8. Security
We maintain appropriate technical and organizational measures, including per-tenant data isolation, encryption of data in transit, role-based access controls and logging. No system is perfectly secure; we notify affected parties of personal-data breaches as required by law.
9. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect their data as a controller.
10. Changes
We may update this Policy. Material changes will be announced at least 30 days in advance on our website. The effective date above always reflects the current version.
Contact: [email protected] — MARMEND OÜ, Narva mnt 5, 10117 Tallinn, Estonia