Data Processing Addendum

Last updated: August 5, 2026

This Data Processing Addendum ("DPA") forms part of the Marnis Terms of Service between the customer ("Customer") and Denvo LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States ("Denvo"). It applies whenever Denvo processes personal data on behalf of the Customer through the Customer's workspace, imports, assistant runs, and related support workflows.

This DPA reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and applies automatically to all customers by using the service; no signature is required. In case of conflict between this DPA and the Terms of Service, this DPA prevails for data protection matters.

1. Roles and scope

The Customer is the controller for the personal data contained in its workspace: the people, companies, relationships, notes, interactions, and imported records it decides to store. Denvo acts as processor when it processes that data to provide the service, and only on the Customer's documented instructions.

Denvo acts as an independent controller for account administration, billing, security, product operations, and legal compliance data relating to the Customer's own users of Marnis. That processing is described in the Privacy Policy, not this DPA.

2. Subject matter, duration, nature and purpose

Subject matter: storing, structuring, searching, and displaying the relationship data the Customer records or imports into its workspace, including derived views such as the network graph, the paths between contacts, reminders, and answers generated by the assistant.

Duration: for the term of the Customer's use of Marnis, until account deletion or termination, plus any period required by law.

Nature and purpose: reading and writing workspace records on the Customer's instruction, running the imports the Customer starts, computing relationships and paths from that data, passing the excerpts needed to answer a request to the model provider named in section 7, and providing support.

3. Categories of data subjects and personal data

Data subjects: the Customer's members and employees, and the people the Customer records in its network - contacts, prospects, partners, and other individuals in the Customer's professional environment, most of whom are not users of Marnis.

Categories of personal data: identity and business contact data, employer, role, place, professional interests, typed relationships between people and companies, notes and interaction records written by the Customer, reminders, visibility settings, imported records and their provenance, and audit records.

Special categories of personal data under Article 9 GDPR, such as health, religious, or political data, are outside the intended scope of the service. The Customer must not enter them, and the product uses controlled vocabularies rather than free text where a field would otherwise invite them. The Customer must likewise not use Marnis to evaluate, rank, or score the people in its own organization.

4. Processing instructions

Denvo processes Customer data only on documented instructions, including workspace configuration, visibility settings, imports, assistant runs, support requests, security, abuse prevention, and account deletion. Instructions are given through product settings, support requests, this DPA, the Terms of Service, and any written agreement signed by both parties.

Denvo will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend execution of that instruction until it is confirmed or changed. Denvo may process data where required by applicable law; in that case Denvo will inform the Customer before processing unless the law prohibits it.

5. Confidentiality

Denvo restricts access to Customer data to personnel and systems that need it to operate, secure, support, or improve the service. All personnel authorized to process Customer data are bound by contractual or statutory confidentiality obligations that survive the end of their engagement.

6. Security (Art. 32 GDPR)

Taking into account the state of the art and the risks of the processing, Denvo implements appropriate technical and organizational measures, including: HTTPS/TLS encryption in transit; encryption at rest; strict separation between the workspaces of different customers; server-side authorization checks on every request; row level security in the database; service-role access only in trusted server contexts; a per-workspace audit log covering changes and assistant runs; a confirmation step before any AI-proposed record becomes a fact; and audited account deletion flows.

Denvo may update these measures over time provided the overall level of protection is not reduced.

7. Subprocessors

The Customer grants Denvo general authorization to engage the subprocessors listed below to provide hosting, authentication, database storage, language model processing, and map services. Denvo imposes data protection obligations on subprocessors consistent with this DPA and remains liable for their performance.

VercelEuropean Union (Frankfurt), global edge infrastructure
Purpose
Hosting for the Marnis web application and the public website.
Data
HTTP requests, IP addresses, headers, logs, and deployment metadata.
Role
Subprocessor / hosting provider
SupabaseEuropean Union (Frankfurt)
Purpose
Authentication, application database, row level security, and file storage for the workspace.
Data
Account data, workspace and membership data, sessions, and all content you create in Marnis: entities, relationships, notes, interactions, chats, and audit records.
Role
Subprocessor / application backend
Mistral AIEuropean Union (France)
Purpose
Language model processing for the assistant: understanding a question, extracting entities and relationships from a note or voice memo, and writing the answer.
Data
The text of the request and the excerpts of your workspace content needed to answer it, including names of people and companies. No training on customer data.
Role
Subprocessor / model provider
MapboxUnited States / global infrastructure
Purpose
Map tiles and geocoding for the map view, and resolving place names to coordinates.
Data
IP address and map requests of the viewing browser, and the place names submitted for geocoding.
Role
Subprocessor / map provider

Denvo will inform the Customer of intended additions or replacements of subprocessors at least 10 days in advance by updating this page and, for material changes, by in-app or email notice. The Customer may object on reasonable data protection grounds; if no solution is found, the Customer may terminate the affected service and delete the account.

8. Assistance and data subject requests

Taking into account the nature of the processing, Denvo will assist the Customer with appropriate technical and organizational measures in fulfilling the Customer's obligations to respond to data subject requests (Art. 12-23 GDPR), and with the Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), where the request relates to data processed by Denvo and cannot be handled directly by the Customer. The product provides an export covering all data held about a given person for this purpose.

If a data subject contacts Denvo directly about data processed on behalf of the Customer, Denvo will forward the request to the Customer without undue delay and will not respond on the merits without the Customer's instruction, unless legally required.

9. Personal data breach notification

Denvo will notify the Customer without undue delay, and no later than 72 hours after becoming aware, of a personal data breach affecting Customer data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate volume of data and data subjects concerned, likely consequences, and measures taken or proposed. Denvo will cooperate with the Customer in investigating and remediating the breach.

10. Deletion and return

The Customer can export its workspace data in a machine-readable format at any time while the account is active. On account deletion, Denvo deletes the workspace and its records, including entities, relationships, notes, interactions, chats, and audit records, followed by deletion of the authenticated users belonging to it.

After the end of the services, Denvo will delete remaining Customer data unless applicable law requires storage; payment providers may retain payment records where legally required.

11. Audits and information

Denvo will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, including summaries of security measures and relevant provider certifications. Where this is insufficient, Denvo will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, at reasonable intervals, with reasonable prior written notice, during business hours, without disrupting operations, and subject to confidentiality. The Customer bears the costs of such audits unless they reveal material non-compliance.

12. International transfers

Customer data is stored and processed in the European Union. Because Denvo is located in the United States, administrative access for support, security, and operations, and the use of providers with US infrastructure, can involve a transfer of personal data from the EU/EEA, the United Kingdom, or Switzerland to the United States. For these transfers, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), Module Two (controller to processor), with the Customer as data exporter and Denvo as data importer, including the UK International Data Transfer Addendum and the Swiss adaptations where applicable. Sections 2, 3, 6, and 7 of this DPA serve as the annexes describing the processing, data categories, security measures, and subprocessors.

Where a subprocessor is certified under the EU-U.S. Data Privacy Framework, transfers to that subprocessor may instead rely on the corresponding adequacy decision.

13. Governing law and contact

This DPA is governed by the laws of the State of New Mexico, USA, except where mandatory data protection law of the Customer's jurisdiction applies, including the Standard Contractual Clauses, which are governed as set out in the clauses themselves.

For DPA or data processing questions, contact: legal@marnis.co.