1. Roles
For workspace content (products, owners, teams, notes, imported activity), the customer is the controller and Arvyo Limited is the processor. For account, billing and usage data needed to run Marqab, Arvyo is a controller, as described in the privacy policy.
2. Subject matter and duration
We process workspace content only to provide, secure and support Marqab, for the life of the workspace and the retention periods in the privacy policy (live systems 30 days after deletion; backups 90 days).
3. Instructions
We process that content on your documented instructions: using the product, this DPA, and the terms. We will tell you if an instruction appears to break applicable law.
4. Security and staff
Measures are summarised on /security: TLS, encryption at rest for secrets, tenant isolation, RBAC, staff audit. Staff who access production are limited to those who need it.
5. Sub-processors
You authorise the providers on /subprocessors. We will post material changes there. Each is bound to process data only to provide their service to us.
6. Assistance and deletion
We will help you respond to data-subject requests that concern workspace content. Owners can export and delete from Settings; you can also email [email protected]. After deletion we wipe live copies within 30 days, except records we must keep (billing, six years).
7. International transfers
Where required, we rely on appropriate safeguards such as standard contractual clauses. See the privacy policy’s transfers section.
8. Liability
Liability under this DPA follows the limitation in the terms, to the extent the law allows.