Skip to content

Marsin legal

Data Processing Addendum

This Data Processing Addendum forms part of the Marsin Terms or customer agreement when INSIDEA, Inc. processes Customer Personal Data on a customer's behalf.

Last updated: August 4, 2026

1. Scope and roles

The customer is the controller or business, and INSIDEA, Inc. is the processor or service provider, for Customer Personal Data processed to provide Marsin. Each party will comply with the privacy and data-protection laws that apply to its role. Capitalized terms not defined here have the meaning in the agreement or applicable law.

2. Processing details

Processing covers hosting, organizing, retrieving, analyzing, generating, transmitting, securing, supporting, and deleting data as needed to provide Marsin. The duration is the agreement plus the documented offboarding and deletion period. Data subjects may include customer users, prospects, customers, employees, contractors, partners, and other people whose data the customer submits or connects.

Data may include identifiers, business contact details, communications, marketing engagement, account and transaction context, connected-system data, and content selected by the customer. The customer must not submit special-category or highly sensitive data unless it has confirmed a lawful basis and appropriate safeguards with INSIDEA, Inc.

3. Instructions and confidentiality

INSIDEA, Inc. will process Customer Personal Data only on documented customer instructions, including the agreement, product configuration, and authorized user actions, unless law requires otherwise. Personnel with access are bound by confidentiality obligations and receive access appropriate to their responsibilities.

4. Security measures

  • Encryption in transit and protection for stored integration credentials.
  • Tenant-scoped access controls, authentication, role controls, and audit records.
  • Secure development, dependency management, operational monitoring, backup, and incident-response practices proportionate to risk.
  • Processes for access review, offboarding, export, retention, and deletion.

5. Subprocessors

The customer authorizes the subprocessors on the Subprocessors page. INSIDEA, Inc. remains responsible for each subprocessor's performance of data-protection obligations to the extent required by law and contract. Customers with a contractual objection right may object on reasonable grounds as described on that page.

6. Assistance and incidents

Taking into account the nature of processing and information available, INSIDEA, Inc. will reasonably assist the customer with data-subject requests, security obligations, regulatory consultations, and impact assessments. We will notify the customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data and provide available information needed for the customer's response.

7. Return, deletion, and audits

At the end of the service, the customer may request an export before deletion. INSIDEA, Inc. will return, delete, or anonymize Customer Personal Data according to the customer's documented offboarding decision, subject to backup cycles and legal retention. On reasonable written request, we will provide information needed to demonstrate compliance. Any audit will be coordinated to protect other customers, confidentiality, security, and service availability.

8. International transfers

When Customer Personal Data protected by the EEA GDPR, UK GDPR, or Swiss data law is transferred to a country without an adequacy decision, the parties will use an applicable transfer mechanism. Where the 2021 European Commission Standard Contractual Clauses are used, Module Two applies to controller-to-processor transfers, INSIDEA, Inc. acts as data importer, and the parties must complete the customer-specific annexes. The UK Addendum and Swiss adaptations apply where relevant.

9. Conflict and contact

If this DPA conflicts with the agreement on processing Customer Personal Data, this DPA controls. Commercial terms and governing law remain as stated in the agreement, except the Standard Contractual Clauses control where required.

Data-protection contact: privacy@marsin.ai. Customers that require a countersigned DPA, completed transfer annexes, or a copy of applicable transfer safeguards may request them from that address.