Privacy Policy
Last updated: August 5, 2026
This Privacy Policy explains how Denvo LLC ("Denvo", "we", "us") collects and uses personal data when you visit the Marnis website, create an account, work in a workspace, import contacts, or use the assistant.
Marnis is operated by Denvo LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. This policy is written with the EU/EEA General Data Protection Regulation (GDPR) in mind and also covers visitors from other regions.
1. Controller and contact
The controller responsible for the processing described in this policy is Denvo LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States. For all privacy requests, including requests from users in the European Economic Area, the United Kingdom, or Switzerland, contact: privacy@marnis.co.
For the content you and your colleagues enter into a workspace - the people, companies, notes, and relationships - your organization is the controller and we act as processor on its behalf. That processing is described in the Data Processing Addendum; section 10 explains how the two roles fit together.
2. Data we collect
Account data: when you sign up, we store your email address, your name, a password hash, and authentication session metadata managed through Supabase Auth, together with your workspace membership, role, and personal settings.
Workspace content: everything you record in Marnis - people, companies, places, interests, the typed relationships between them, notes, interactions, reminders, visibility settings, chats with the assistant, and the audit records of who changed what. This regularly contains personal data of third parties, such as the business contact details, employer, role, and interests of the people in your network.
Imported data: where you import contacts, calendar entries, mail metadata, or an export you obtained from another service, we store what the import contains and where it came from, so that every entry can be traced back to its source.
Assistant data: the questions you ask, the excerpts of your workspace content used to answer them, the tools the assistant called, and its answers. Every run is recorded in the audit log of your workspace.
Waitlist data: if you enter your email address on our waitlist page, we store that address and the date of the entry, and nothing else. We use it solely to contact you when a place becomes available.
Technical data: our hosting provider records server logs including IP address, request headers, and timestamps for security and operations.
Support data: if you contact us, we process the content of your message and your contact details to answer your request.
3. Purposes and legal bases
Performance of a contract (Art. 6(1)(b) GDPR): creating and managing your account and workspace, storing and searching your content, running imports, answering questions with the assistant, providing support, and processing subscriptions and payments.
Legitimate interests (Art. 6(1)(f) GDPR): securing the service, preventing abuse and fraud, keeping operational logs and audit records, and defending legal claims. For the business contact data of third parties that you record in your network, the legitimate interest in maintaining professional relationships is regularly the basis on which your organization processes it; we do so on its instructions.
Legal obligations (Art. 6(1)(c) GDPR): retaining billing and tax records and responding to lawful requests from authorities.
Consent (Art. 6(1)(a) GDPR): if you leave your email address on our waitlist page, we use it on the basis of your consent to contact you about access to Marnis. You can withdraw your consent at any time with effect for the future by writing to privacy@marnis.co, and we will delete the entry. Waitlist entries are deleted at the latest 24 months after they were made.
Apart from that, we do not process personal data on the basis of consent, and we do not use consent-based analytics services or non-essential cookies.
4. Cookies and local storage
Strictly necessary cookies are set without consent because the service cannot work without them: the Supabase authentication session cookies that keep you signed in, and one cookie that records which workspace you last worked in (marnis_workspace, maximum age 12 months, httpOnly). These store no tracking profiles.
We do not set any analytics or tracking cookies. Your browser stores one local storage entry with your light or dark theme preference. It contains no identifier and is never sent to any third party. You can remove it at any time through your browser's site data settings.
5. Third parties in your network
Marnis is used to record information about people who are not users of Marnis themselves. Where personal data is not collected from the person concerned, Article 14 GDPR requires that they be informed about the processing. Marnis supports your organization in meeting that obligation, but your organization decides whom to record and remains responsible for informing them.
Contacts are private by default. Sharing a contact beyond the people who already have access to it requires an explicit decision by the person who owns that connection. Where a request reaches across workspaces, it is answered as an aggregated signal only, no network is disclosed, and an introduction is made by a person, not by handing over a record.
If you are recorded in someone's Marnis workspace and want to know what is stored about you, contact the organization that maintains the workspace. If you do not know which organization that is, write to privacy@marnis.co and we will forward your request.
6. Sharing and subprocessors
We share personal data with service providers only as needed to operate Marnis, under contracts that restrict how they may use it. The current service-provider list is:
- Purpose
- Hosting for the Marnis web application and the public website.
- Data
- HTTP requests, IP addresses, headers, logs, and deployment metadata.
- Role
- Subprocessor / hosting provider
- Purpose
- Authentication, application database, row level security, and file storage for the workspace.
- Data
- Account data, workspace and membership data, sessions, and all content you create in Marnis: entities, relationships, notes, interactions, chats, and audit records.
- Role
- Subprocessor / application backend
- Purpose
- Language model processing for the assistant: understanding a question, extracting entities and relationships from a note or voice memo, and writing the answer.
- Data
- The text of the request and the excerpts of your workspace content needed to answer it, including names of people and companies. No training on customer data.
- Role
- Subprocessor / model provider
- Purpose
- Map tiles and geocoding for the map view, and resolving place names to coordinates.
- Data
- IP address and map requests of the viewing browser, and the place names submitted for geocoding.
- Role
- Subprocessor / map provider
The assistant sends only what is needed to answer a request, and only content the requesting user is allowed to see. There is no processing across the workspaces of different customers, and no customer content is used to train models.
We do not sell personal data and do not share it with third parties for their own advertising. We may disclose data where required by law, to enforce our terms, or as part of a merger or acquisition, in which case this policy continues to apply.
7. International transfers
Workspace content is stored and processed in the European Union. Denvo LLC is located in the United States, so administrative access for support, security, and operations, and the use of providers with US infrastructure, can involve a transfer of personal data to the United States.
Where a provider is certified under the EU-U.S. Data Privacy Framework (including the UK Extension and the Swiss-U.S. DPF), transfers rely on that adequacy decision. For other transfers we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with supplementary measures such as encryption in transit and at rest. You can request a copy of the applicable safeguards via privacy@marnis.co.
8. Security
We protect personal data with HTTPS/TLS in transit, encryption at rest, server-side authorization checks on every request, strict separation between the workspaces of different customers, row level security in the database, service-role access only in trusted server contexts, and an audit log covering changes and assistant runs.
No service can guarantee perfect security. You should keep your account secure, invite only the people who need access, and review the visibility of what you record.
9. Retention and deletion
We keep account, workspace, and billing data while your account is active and as long as needed to provide the service, enforce billing, and comply with legal obligations. Operational logs are retained only for as long as needed for security monitoring and debugging and are then deleted or anonymized. Audit records are retained for the period your organization configures.
You can delete individual entries, notes, and chats at any time. Workspace owners can delete the account from settings, which removes the workspace and its records and deletes the authenticated users belonging to it. Payment providers may retain invoices and payment records where legally required for accounting and tax purposes, and we retain billing records for the statutory retention periods.
10. Your rights under the GDPR
If the GDPR applies to you, you have the right of:
- access (Art. 15) and rectification (Art. 16),
- erasure (Art. 17) and restriction of processing (Art. 18),
- data portability (Art. 20),
- objection to processing based on legitimate interests (Art. 21).
Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise these rights, contact privacy@marnis.co. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence, workplace, or the place of the alleged infringement.
When Marnis processes personal data contained in your workspace on your behalf, we act as processor and your organization is responsible for handling requests from the people recorded in it; we will assist as described in the Data Processing Addendum.
11. US state privacy rights
Depending on your state of residence (for example under the California Consumer Privacy Act), you may have rights to know, access, correct, and delete personal information, and to opt out of the sale or sharing of personal information. We do not sell personal information and do not share it for cross-context behavioral advertising. To exercise these rights, contact privacy@marnis.co. We will not discriminate against you for exercising them.
12. Children
Marnis is a business tool intended for professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the service, our providers, or legal requirements change. We will post the updated version on this page with a new "Last updated" date and, for material changes, notify you in the application or by email where appropriate.
14. Contact
For privacy requests and questions about this policy, contact: privacy@marnis.co. Postal address: Denvo LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States.