DPA — Data processing agreement
Based on GDPR Art. 28 · Version 1.0 in force
1. Parties and purpose
This agreement is entered into between the client (controller) and Markova Labs SL (Tax ID / CIF B93926095, with registered address at Calle Sofora 15, Floor 2, 28020 Madrid, Spain) as processor, for the use of Falcon under GDPR (EU) 2016/679.
2. Duration, nature and purpose
Duration: that of the client's subscription. Purpose: providing the URL shortening, QR code and analytics service. Nature: processing of the client's account data and anonymized analytics events associated with their links.
3. Data types and categories
Client identification data (email, name) and technical data of their link visitors (country, device, OS, language, source, date). The IP is processed only as a salted truncated hash.
4. Location and transfers
All data is processed on EU infrastructure. There are no transfers to third countries.
5. Sub-processors
The sub-processor list (infrastructure, email) is available on request; any change is notified 30 days in advance, with a right to object.
6. Processor obligations
- Process data only following the controller's documented instructions.
- Ensure confidentiality of personnel with access.
- Implement appropriate technical and organizational measures (encryption in transit, access control, logging).
- Notify security breaches without undue delay and within 72 hours at most.
- Assist the controller with impact assessments and authority inquiries.
7. Return and deletion
Upon termination, data is deleted (the client can export it beforehand from their dashboard). Deletion is self-service and total.
8. Audit
The controller may audit compliance upon reasoned request and prior notice.
To request the signed DPA, write to hello@markovalabs.io.