Data Processing Agreement
Last modified: 23 August 2026
Version: 1.0
This Data Processing Agreement (the "DPA") forms part of the Marmot Data Terms of Service (the "Principal Agreement") between Marmot Data Ltd, 66 Paul Street, London, EC2A 4NA, company number 17420684 (the "Processor"), and the company using Marmot Data services (the "Controller").
This DPA governs the requirements of UK Data Protection Laws to the extent that the Controller's use of the Service involves the Processing of Personal Data. It is complementary to the Privacy Policy at https://marmotdata.io/privacy.
By accepting the Principal Agreement, the Controller also accepts this DPA. No separate signature is required; a signable copy is available on request to support@marmotdata.io. The term of this DPA follows the term of the Principal Agreement. Terms not defined here have the meaning given in the Principal Agreement. Where this DPA conflicts with the Principal Agreement in relation to Processing of Personal Data, this DPA prevails.
Whereas:
(A) The Controller acts as a data controller.
(B) The Controller wishes to use the Service, which involves the Processing of Personal Data by the Processor acting as a data processor.
(C) The Parties wish to lay down their rights and obligations in accordance with UK Data Protection Laws.
1. Definitions
1.1 "UK Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, and any other applicable data protection legislation in force in the United Kingdom from time to time.
1.2 "UK GDPR" means the retained EU law version of Regulation (EU) 2016/679 as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018. "EU GDPR" means Regulation (EU) 2016/679 where applicable to the Controller.
1.3 "Controller Personal Data" means any Personal Data Processed by the Processor on behalf of the Controller in connection with the Principal Agreement.
1.4 "Sub-processor" means any person appointed by the Processor to process Controller Personal Data on behalf of the Controller.
1.5 "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings given to them in the UK GDPR.
2. Processing of Controller Personal Data
2.1 The Processor shall comply with UK Data Protection Laws in the Processing of Controller Personal Data, and shall not process Controller Personal Data other than on the Controller's documented instructions.
2.2 The Controller instructs the Processor to process Controller Personal Data to: (a) provide the Service and related technical support; (b) fulfil legal obligations or resolve disputes; and (c) maintain the security, availability, and functionality of the Service. The Principal Agreement, this DPA, and the Controller's use of the Service constitute the Controller's complete and final documented instructions.
2.3 The Processor shall inform the Controller if, in its opinion, an instruction infringes UK Data Protection Laws.
2.4 The Controller warrants that it has a valid lawful basis for the Processing it instructs, and that it has provided all necessary privacy notices to Data Subjects.
2.5 The Controller shall not submit special category Personal Data, or Personal Data relating to criminal convictions and offences, to the Service without the Processor's prior written agreement.
2.6 The Processor acts as a controller in its own right in respect of Personal Data it processes for account administration, billing, and security monitoring. That Processing is described in the Privacy Policy and is outside the scope of this DPA.
2.7 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in the Schedule.
3. Processor Personnel
3.1 The Processor shall take reasonable steps to ensure the reliability of any person who may have access to Controller Personal Data, shall limit access to those who need it for the purposes of the Principal Agreement, and shall ensure that all such persons are subject to confidentiality undertakings or statutory obligations of confidentiality.
4. Security
4.1 In accordance with Article 32 of the UK GDPR, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons.
4.2 The Processor shall assess the risks associated with its Processing activities and apply measures consistent with Article 32, ensuring the security of Controller Personal Data at all times.
5. Sub-processing
5.1 The Controller grants the Processor general authorisation to engage the Sub-processors listed in the Schedule and to transfer Controller Personal Data to them.
5.2 The Processor shall give the Controller not less than 30 days' notice by email of any intended addition or replacement of a Sub-processor. The Controller may object on reasonable data protection grounds within that period. If the Processor is unable to accommodate the objection, the Controller may terminate the Principal Agreement without penalty and receive a pro-rata refund of Fees paid in advance for the period after termination.
5.3 The Processor shall ensure that each Sub-processor is bound by a written agreement no less protective than this DPA, and shall remain fully liable to the Controller for the performance of each Sub-processor's obligations.
6. Data Subject Rights
6.1 Taking into account the nature of the Processing, the Processor shall reasonably assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights. Where the Service provides functionality enabling the Controller to respond itself, the Controller shall use it.
6.2 The Processor shall promptly notify the Controller if it receives a request directly from a Data Subject, and shall not respond substantively except on the Controller's instructions or as required by law.
7. Personal Data Breach
7.1 The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Controller Personal Data, providing sufficient information to enable the Controller to meet its own obligations under UK Data Protection Laws. Where full information is not available at the time, it shall be provided in phases as it becomes available.
7.2 The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach. Notification is not an acknowledgement of fault or liability.
7.3 Each party shall bear its own costs of investigation, remediation, and mitigation to the extent a breach is caused by that party, and shall bear any fines, penalties, or damages imposed by a regulator or court to the extent arising from that party's breach of this DPA.
8. Impact Assessments
8.1 The Processor shall provide reasonable assistance to the Controller with data protection impact assessments and prior consultations with Supervisory Authorities required under Articles 35 or 36 of the UK GDPR, in each case solely in relation to Processing by the Processor and taking into account the nature of the Processing and the information available to it.
9. Deletion or Return
9.1 On termination of the Principal Agreement, the Processor shall, at the Controller's option, delete or return all Controller Personal Data. The Controller must make any such request within 30 days of termination, after which the Processor may delete the data.
9.2 The Processor may retain Controller Personal Data where required by law, and in routine backups for up to 90 days after deletion from production systems, during which time it remains subject to this DPA and is not actively processed.
10. Audit Rights
10.1 The Processor shall make available to the Controller on request all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits by the Controller or a mandated auditor.
10.2 The Controller shall not exercise its audit rights more than once per calendar year, except following a Personal Data Breach or an instruction by a regulator. The Controller shall give at least 30 days' prior written notice. Audits shall take place during business hours, shall not disrupt the Processor's operations, and shall be subject to the confidentiality obligations of the Principal Agreement. The Parties shall agree the date, scope, and duration in advance. The Controller shall bear its own costs and reimburse the Processor's reasonable costs of assisting.
10.3 The Processor may satisfy an audit request by providing a current third-party audit report, certification, or completed security questionnaire where this reasonably addresses the request.
11. Data Transfers
11.1 The Processor hosts Controller Personal Data at rest within the United Kingdom and/or the European Economic Area, in accordance with the Principal Agreement.
11.2 The Controller authorises the transfer of Controller Personal Data to the Sub-processors listed in the Schedule, including those located outside the United Kingdom.
11.3 Where Controller Personal Data is transferred to a country not covered by adequacy regulations, the Parties shall ensure appropriate safeguards are in place, relying on the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and, where the EU GDPR applies, the EU Standard Contractual Clauses. Those instruments are incorporated by reference.
11.4 The Parties acknowledge that the European Commission renewed its adequacy decisions in respect of the United Kingdom on 19 December 2025, so transfers from the European Economic Area to the United Kingdom require no additional safeguards for so long as those decisions remain in force.
11.5 If a transfer mechanism relied upon ceases to be available, the Parties shall cooperate in good faith to implement an alternative without undue delay.
12. General Terms
Compliance with applicable laws. The Processor will process Controller Personal Data in accordance with this DPA and the laws applicable to its role. The Processor is not responsible for compliance with laws applicable to the Controller solely by virtue of its business or industry.
Liability. The liability of each party under this DPA is subject to the exclusions and limitations of liability set out in the Principal Agreement.
Changes. The Processor may update this DPA in accordance with the change process in the Principal Agreement, provided no update reduces the protections afforded to Controller Personal Data. Previous versions remain available at https://marmotdata.io/dpa/archive.
Notices. Notices to the Controller shall be sent by email to the address associated with its account. Notices to the Processor shall be sent to support@marmotdata.io.
Governing law. This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, save where the Standard Contractual Clauses or the International Data Transfer Agreement specify otherwise in respect of transfers governed by them.
Schedule
Details of Processing
Subject matter: Provision of Marmot, an open source AI context layer, provided as a hosted service.
Duration: The term of the Principal Agreement, plus any retention period under clause 9.
Nature and purpose: Hosting, storage, retrieval, indexing, transmission, and display of Controller data in order to provide the Service, together with authentication of authorised users, technical support, and maintenance of the security and availability of the Service.
Types of Personal Data: Identity and contact details of authorised users (name, email address, job title); authentication data (credentials, tokens, session identifiers); usage and technical data (IP address, device and browser information, access logs, timestamps, actions performed); and any Personal Data contained within data submitted to the Service by the Controller, the scope of which is determined by the Controller.
Categories of Data Subjects: The Controller's authorised users, typically its employees, contractors, and agents; and any individuals whose Personal Data is contained within data submitted to the Service by the Controller.
Competent Supervisory Authority: The Information Commissioner's Office, or where the EU GDPR applies, the authority determined under Clause 13 of the EU Standard Contractual Clauses.
Approved Sub-processors
| Sub-processor | Purpose | Location of Processing |
|---|---|---|
| Google Cloud | Cloud hosting and infrastructure | United Kingdom and/or European Economic Area |
| Stripe | Payment processing and billing | Ireland; United States |
| Logto Cloud | Authentication and identity management | European Economic Area and/or United States |
Stripe processes payment card and billing data as an independent controller for the purposes of payment processing, fraud prevention, and its obligations under card scheme rules and anti-money laundering legislation. It is listed here for transparency.
Previous versions of this DPA are available in the archive.