Legal

Data Processing Agreement

Last updated 1 June 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the MarketLin Terms of Service (the "Agreement") between the Customer and MarketLin AB, org.nr 559549-8915, Kungsängsgatan 17, 753 22 Uppsala, Sweden. It governs MarketLin’s processing of personal data on the Customer’s behalf and reflects the requirements of Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). Where this DPA conflicts with the Agreement on the subject of data protection, this DPA prevails.

1. Roles of the parties

1.1 In respect of personal data contained in the Customer’s connected advertising and analytics accounts and otherwise processed to provide the Service ("Customer Personal Data"), the Customer acts as the controller (or, where the Customer processes such data on behalf of its own clients, as a processor), and MarketLin acts as the processor (or sub-processor).

1.2 In respect of account-administration data, billing data, and MarketLin’s own operation of the Service, MarketLin acts as a controller; that processing is described in the MarketLin Privacy Policy, not this DPA.

2. Subject matter, duration, nature and purpose

2.1 Subject matter: processing of Customer Personal Data as necessary to provide the Service (connecting to marketing and analytics platforms via their APIs and delivering analysis, recommendations, and reporting).

2.2 Duration: for the term of the Agreement, plus the deletion period set out in Section 10.

2.3 Nature and purpose: collection, storage, organisation, structuring, analysis, and generation of derived insights and outputs, by automated means including AI processing, solely to provide the Service to the Customer.

2.4 Full details of the processing are set out in Annex A below.

3. Processor obligations

MarketLin shall:

  • 3.1 Process Customer Personal Data only on the documented instructions of the Customer, including with regard to international transfers, unless required to do otherwise by EU or Member State law (in which case it will inform the Customer, unless that law prohibits it). The Agreement, this DPA, and the Customer’s use of the Service constitute the Customer’s complete and documented instructions.
  • 3.2 Immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
  • 3.3 Ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality.
  • 3.4 Implement the technical and organisational security measures set out in Annex B (Article 32 GDPR).
  • 3.5 Respect the conditions in Section 5 for engaging sub-processors.
  • 3.6 Taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer’s obligation to respond to data subject rights requests (Chapter III GDPR). Where a data subject contacts MarketLin directly regarding Customer Personal Data, MarketLin will forward the request to the Customer and will not respond except on the Customer’s instruction.
  • 3.7 Assist the Customer in ensuring compliance with its obligations under Articles 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to MarketLin.
  • 3.8 Notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, providing the information the Customer reasonably needs to meet its own notification obligations.
  • 3.9 At the Customer’s choice, delete or return all Customer Personal Data after the end of the provision of the Service, and delete existing copies, as set out in Section 10.
  • 3.10 Make available to the Customer the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, as set out in Section 9.

4. Controller obligations

The Customer warrants that it has a valid legal basis for the processing instructed, that it has the right and authority to connect the relevant accounts and to provide Customer Personal Data to MarketLin, and that its instructions comply with applicable data protection law.

5. Sub-processors

5.1 The Customer grants MarketLin general written authorisation to engage sub-processors to process Customer Personal Data. The sub-processors engaged as at the date of this DPA are listed in Annex C and at marketlin.com/subprocessors.

5.2 MarketLin will impose on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for the sub-processor’s performance.

5.3 MarketLin will give the Customer at least 30 days’ prior notice of any intended addition or replacement of a sub-processor (for example by updating Annex C or its online sub-processor list and notifying the Customer). The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.

6. International transfers

6.1 MarketLin will not transfer Customer Personal Data outside the EU/EEA except in compliance with Chapter V GDPR.

6.2 Where a transfer to a third country occurs (including to a sub-processor in Annex C), it is safeguarded by the EU–U.S. Data Privacy Framework where the recipient is certified, and/or by the European Commission’s Standard Contractual Clauses (SCCs) together with any additional measures required following a transfer risk assessment.

6.3 MarketLin operates the Service on Google Cloud Platform in the europe-north1 (Stockholm, Sweden) region, with email via Brevo (France) and asset storage via AWS S3 (France), so that Customer Personal Data is stored at rest within the EU/EEA. Certain sub-processors listed in Annex C (the AI providers, Sentry, and Stripe) are located in the United States and are covered by the safeguards in Section 6.2.

7. Security

MarketLin implements and maintains the technical and organisational measures described in Annex B, appropriate to the risk, in accordance with Article 32 GDPR. MarketLin may update these measures provided the level of protection is not reduced.

8. Platform Data and Limited Use

Consistent with the Agreement, MarketLin processes data obtained from connected platforms in accordance with those platforms’ developer requirements, including the Google API Services User Data Policy (Limited Use) and the Meta Platform Terms. In particular, MarketLin does not sell such data, does not use it for personalised advertising, does not use it to train generalised or non-personalised AI/ML models, and uses it only to provide the user-facing features of the Service. MarketLin’s AI sub-processors (Anthropic, OpenAI, and Google Gemini via Vertex AI) process Platform Data through their APIs solely to generate outputs for the Customer and do not train their models on it.

9. Audit

9.1 MarketLin will make available to the Customer, on request, the information reasonably necessary to demonstrate compliance with this DPA (which may include up-to-date third-party certifications or audit reports where available).

9.2 Where that information is insufficient, the Customer (or an independent auditor bound by confidentiality) may conduct an audit no more than once per 12 months (unless required more frequently by a supervisory authority or following a breach), on reasonable prior notice, during business hours, and in a manner that does not disrupt MarketLin’s operations or compromise the confidentiality of other customers’ data.

10. Deletion and return

10.1 On expiry or termination of the Agreement, or on the Customer disconnecting an account, MarketLin will delete the raw Customer Personal Data associated with that account within 90 days, except where retention is required by EU or Member State law. This deletion is automated.

10.2 Derived outputs (reports, recommendations, aggregated insights) that the Customer has generated may be retained by, and are exportable by, the Customer; these do not contain the raw platform data.

10.3 Database backups are retained for 7 days, after which residual copies of deleted data are overwritten and no longer restored to production.

11. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

12. Governing law

This DPA is governed by the laws of Sweden, and the dispute-resolution provisions of the Agreement apply.

Annex A — Details of the processing

Categories of data subjects: the Customer’s and the Customer’s clients’ end users, website visitors, ad audiences, and prospects whose data appears in the connected advertising and analytics accounts; and the Customer’s authorised users of the Service.

Categories of personal data: pseudonymous advertising and analytics identifiers and online identifiers, campaign engagement and conversion events, aggregated audience and demographic attributes, and account/user administration data. The Service does not retrieve directly identifying end-user personal data from connected accounts.

Special categories of data: none. The Service does not ingest special-category data (Article 9) or criminal-offence data, and the Customer must not instruct such processing.

Frequency: continuous / on a scheduled sync basis for the duration of the Agreement.

Nature and purpose: as set out in Sections 2–3 above.

Retention: raw platform data deleted within 90 days of disconnection or termination (Section 10).

Annex B — Technical and organisational measures (Article 32)

  • Encryption in transit: TLS/SSL enforced on API servers and all datastores.
  • Encryption at rest: enabled, with keys managed via Google Cloud KMS.
  • Data residency: production data stored on Google Cloud Platform in the europe-north1 (Stockholm, Sweden) region.
  • Tenant isolation: logical separation of each customer’s data, enforced by a central authorisation layer (SpiceDB) with deny-by-default and organisation-owned credentials; platform OAuth tokens are stored encrypted and owned at the organisation level.
  • Access control: least-privilege internal access on a need-to-know basis.
  • Scope minimisation: the minimum scope each platform offers for read use is requested; read-only scopes are used where the platform provides them (GA4, Search Console, Meta ads_read, LinkedIn), and where no read-only scope exists (Google Ads, Meta business_management) the minimum available scope is used solely to read data.
  • Backups and resilience: encrypted database backups with a 7-day retention and restoration process.
  • Logging and monitoring: breach-detection and alerting enabling notification within 72 hours; error telemetry via Sentry with request bodies, cookies, and authentication headers stripped.
  • Secure development: access controls on source and infrastructure, with change management for production.
  • Personnel: confidentiality obligations on all staff and contractors with access.

Annex C — Approved sub-processors

An up-to-date list is also maintained at marketlin.com/subprocessors.

Approved sub-processors
Sub-processorRole / serviceLocationTransfer safeguard
Google Cloud PlatformHosting, database, object storage, key management (europe-north1)Stockholm, Sweden (EU)N/A (EU)
Anthropic PBCAI processing (analysis and recommendations); does not train on Customer dataUSADPF / SCCs
OpenAI, L.L.C.AI processing (analysis and recommendations); does not train on API dataUSADPF / SCCs
Google (Gemini via Vertex AI)AI processing (analysis and recommendations); does not train on Customer dataUSADPF / SCCs
StripePayment processing (paid plans)USA / IrelandDPF / SCCs
Brevo (Sendinblue)Transactional and product emailFrance (EU)N/A (EU)
AWS S3Uploaded and mirrored assetsFrance (EU)N/A (EU)
SentryError telemetry only; request bodies, cookies, and authentication headers strippedUSADPF / SCCs