Falcon

DPA — Data processing agreement

Based on GDPR Art. 28 · Version 1.0 in force

1. Parties and purpose

This agreement is entered into between the client (controller) and Markova Labs SL (Tax ID / CIF B93926095, with registered address at Calle Sofora 15, Floor 2, 28020 Madrid, Spain) as processor, for the use of Falcon under GDPR (EU) 2016/679.

2. Duration, nature and purpose

Duration: that of the client's subscription. Purpose: providing the URL shortening, QR code and analytics service. Nature: processing of the client's account data and anonymized analytics events associated with their links.

3. Data types and categories

Client identification data (email, name) and technical data of their link visitors (country, device, OS, language, source, date). The IP is processed only as a salted truncated hash.

4. Location and transfers

All data is processed on EU infrastructure. There are no transfers to third countries.

5. Sub-processors

The sub-processor list (infrastructure, email) is available on request; any change is notified 30 days in advance, with a right to object.

6. Processor obligations

  • Process data only following the controller's documented instructions.
  • Ensure confidentiality of personnel with access.
  • Implement appropriate technical and organizational measures (encryption in transit, access control, logging).
  • Notify security breaches without undue delay and within 72 hours at most.
  • Assist the controller with impact assessments and authority inquiries.

7. Return and deletion

Upon termination, data is deleted (the client can export it beforehand from their dashboard). Deletion is self-service and total.

8. Audit

The controller may audit compliance upon reasoned request and prior notice.

To request the signed DPA, write to hello@markovalabs.io.