Last updated: September 3, 2026
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement governing Customer’s access to and use of the Marcenta services, including any applicable order form, statement of work or online terms (the "Agreement"). It is entered into by Marcenta, with its registered address at DLF Westend Heights, Akshayanagar, Bengaluru 560114 ("Marcenta"), and the customer identified in the Agreement ("Customer").
This DPA applies only to the extent Marcenta processes Customer Personal Data on Customer's behalf in connection with the Services and Applicable Data Protection Law applies to that processing. It takes effect on the effective date of the Agreement or, if later, when Marcenta first processes Customer Personal Data on Customer's behalf.
1. DEFINITIONS AND ROLES
“Applicable Data Protection Law” means any data protection, privacy or data-security law applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, the California Consumer Privacy Act as amended, India’s Digital Personal Data Protection Act, 2023 and rules made under it, and equivalent or successor laws.
“Customer Personal Data” means Personal Data processed by Marcenta or a Subprocessor on Customer’s behalf in connection with the Services. It excludes Personal Data that Marcenta processes as an independent controller for its own legitimate business purposes, such as account administration, billing, fraud prevention, service security and business communications.
“Personal Data”, “Controller”, “Processor”, “Business”, “Service Provider”, “Data Subject”, “Data Principal”, “Process”, “Processing” and similar terms have the meanings given under the Applicable Data Protection Law that uses them.
“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Marcenta’s or a Subprocessor’s possession or control. It does not include unsuccessful attempts that do not compromise Customer Personal Data.
“Subprocessor” means a third party engaged by Marcenta to process Customer Personal Data on Customer’s behalf in connection with the Services.
For Customer Personal Data, Customer is the Controller (or equivalent role under Applicable Data Protection Law) and Marcenta is the Processor. If Customer acts as a Processor for another Controller, Customer appoints Marcenta as its Subprocessor and represents that it has authority to do so. Each party remains responsible for its independent obligations under Applicable Data Protection Law.
2. PROCESSING OF CUSTOMER PERSONAL DATA
Marcenta will process Customer Personal Data only to provide, secure, maintain and support the Services; in accordance with the Agreement, Customer’s use and configuration of the Services, and Customer’s documented instructions; or as required by applicable law.
The Agreement, this DPA, Customer’s configuration and use of the Services, and authorized support requests constitute Customer’s documented instructions. Instructions outside the ordinary functionality of the Services may require a separate written agreement and may be subject to reasonable charges.
If Marcenta reasonably believes an instruction violates Applicable Data Protection Law, Marcenta may notify Customer and suspend the affected processing while the parties address the issue.
Marcenta will not sell Customer Personal Data, use it for advertising unrelated to providing the Services, or use Customer Personal Data to train generalized AI models unless Customer expressly agrees otherwise in writing.
3. CUSTOMER RESPONSIBILITIES
Customer is responsible for the lawfulness of the Customer Personal Data it provides or makes available to Marcenta and for its instructions to Marcenta. Customer will provide required notices and obtain all rights, permissions, consents or other lawful bases required for Marcenta and its Subprocessors to process Customer Personal Data as contemplated by the Agreement and this DPA.
Customer will ensure that its use of the Services and its instructions comply with Applicable Data Protection Law, protect its accounts and credentials, configure permissions appropriately, and use the Services only for data and purposes the Services are reasonably designed to support.
Unless Marcenta expressly agrees otherwise in writing, Customer will not submit protected health information, payment-card numbers, government identification numbers, biometric or genetic data, Personal Data of known children, or other highly sensitive or special-category Personal Data for which the Services are not intended.
4. CONFIDENTIALITY AND SECURITY
Marcenta will limit access to Customer Personal Data to personnel and contractors who need access to provide, secure or support the Services and who are subject to appropriate confidentiality obligations.
Marcenta will maintain appropriate administrative, technical and organizational safeguards designed to protect the security, confidentiality and integrity of Customer Personal Data, taking into account the nature, scope, context and purposes of the processing and the risks involved.
Marcenta may update its security measures and underlying technology from time to time, provided that it does not materially reduce the overall level of protection for Customer Personal Data during the applicable subscription term.
5. PERSONAL DATA BREACHES
Marcenta will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, Marcenta will provide information concerning the nature of the Personal Data Breach, the categories of affected data, likely consequences, and measures taken or proposed to contain, investigate, mitigate or remediate the incident. Information may be provided in phases as the investigation progresses.
Notification of or response to a Personal Data Breach is not an admission of fault or liability. Customer remains responsible for determining whether and how to notify regulators, Data Subjects or other parties unless Applicable Data Protection Law places that obligation directly on Marcenta.
Marcenta will provide reasonable cooperation with legally required notifications or investigations. Assistance that is unusually burdensome or outside ordinary product functionality may be subject to reasonable charges, except to the extent the assistance is required because Marcenta breached this DPA.
6. DATA SUBJECT REQUESTS AND REGULATORY ASSISTANCE
Taking into account the nature of the processing and the functionality available in the Services, Marcenta will provide reasonable assistance to Customer in responding to requests by Data Subjects concerning Customer Personal Data and in meeting processor-assistance obligations required by Applicable Data Protection Law.
If Marcenta receives a request directly from a Data Subject concerning Customer Personal Data, Marcenta may direct the requester to Customer or notify Customer and will not respond substantively on Customer’s behalf unless required by law or agreed by the parties.
On reasonable request, and to the extent required by Applicable Data Protection Law and information available to Marcenta, Marcenta will provide reasonable information and assistance relating to data protection impact assessments, regulator consultations, security of processing and demonstrations of compliance.
Assistance that is unusually burdensome, repetitive or outside ordinary product functionality may be subject to reasonable charges agreed in advance, except to the extent required because Marcenta breached this DPA.
7. SUBPROCESSORS
Customer gives Marcenta general authorization to engage Subprocessors to provide the Services. Marcenta will impose written data-protection obligations on each Subprocessor that are appropriate to the processing it performs and as required by Applicable Data Protection Law.
Marcenta may add, replace or remove Subprocessors as its Services and infrastructure evolve. Marcenta will make information about its material Subprocessors available to Customer and, where Applicable Data Protection Law requires prior notice or an opportunity to object, will provide a reasonable mechanism for doing so.
If Customer objects to a new Subprocessor on reasonable and documented data-protection grounds, the parties will work in good faith to resolve the objection. If no commercially reasonable resolution is available, Marcenta may discontinue the affected feature or Customer may terminate the affected Service, with any refund determined under the Agreement.
Third-party services that Customer independently selects, authorizes or connects to the Services are not Marcenta Subprocessors merely because the Services interoperate with them.
8. INTERNATIONAL TRANSFERS
Marcenta and its Subprocessors may process Customer Personal Data in countries where they operate, subject to Applicable Data Protection Law.
Where a transfer of Customer Personal Data requires an approved transfer mechanism, the parties will use the applicable lawful mechanism. For transfers subject to the EU GDPR or UK GDPR, the European Commission Standard Contractual Clauses and/or the UK International Data Transfer Addendum will apply where required, as described in Schedule 2.
Mandatory transfer terms prevail over this DPA and the Agreement to the extent of any conflict relating to the relevant transfer. Marcenta will provide information reasonably available to it and reasonably necessary for a legally required transfer assessment.
9. RETURN AND DELETION
During the term, Customer may retrieve Customer Personal Data through available product functionality or another method agreed by the parties.
Following expiration or termination of the Agreement, Marcenta will delete or return Customer Personal Data in its control within a commercially reasonable period, unless applicable law requires retention. Customer Personal Data retained in backups or systems from which immediate deletion is technically impracticable may remain until overwritten or deleted through the ordinary retention cycle, during which time it will remain protected under this DPA.
10. COMPLIANCE INFORMATION AND AUDITS
On reasonable request, Marcenta will provide information reasonably necessary to demonstrate its compliance with this DPA, including relevant security information and reasonable responses to data-protection or security questionnaires.
If Applicable Data Protection Law gives Customer a non-waivable audit right and the information provided under Section 10.1 is insufficient, Customer may exercise that right on reasonable advance notice, during normal business hours, at its own cost and in a manner that does not unreasonably disrupt Marcenta’s business or compromise the security or confidentiality of Marcenta or other customers.
Customer may not conduct vulnerability scanning, penetration testing or other technical testing of Marcenta systems without Marcenta’s prior written approval. Nothing in this Section requires Marcenta to disclose other customers’ information, source code, trade secrets, privileged information or information that would create a material security risk.
11. AGGREGATED AND DE-IDENTIFIED DATA
Marcenta may create and use aggregated or de-identified information derived from Customer Personal Data only where the information does not reasonably identify Customer or an individual and to the extent permitted by Applicable Data Protection Law. Marcenta will not attempt to re-identify such information except as permitted by law for testing the effectiveness of de-identification measures.
12. LIABILITY AND GENERAL TERMS
Each party’s liability arising out of or relating to this DPA is subject to the exclusions, limitations and aggregate liability cap in the Agreement, except to the extent a limitation is prohibited by Applicable Data Protection Law or mandatory transfer terms.
This DPA forms part of the Agreement. If there is a conflict concerning the processing of Customer Personal Data, mandatory transfer terms will control first, then this DPA, then the Agreement, unless a later signed document expressly and lawfully states otherwise.
The governing law, dispute resolution, notice, assignment and signature provisions of the Agreement apply to this DPA.
Marcenta may update this DPA where reasonably necessary to comply with changes in Applicable Data Protection Law, provided an update does not materially reduce Customer’s data-protection rights during an active subscription term except where required by law.
SCHEDULE 1: PROCESSING DETAILS
| Item | Description |
|---|---|
| Subject matter and purpose | Processing Customer Personal Data to provide, secure, maintain, support and operate the Services selected and configured by Customer, including analytics, reporting, workflows, integrations, lead routing, calendar and CRM functionality, optional call analysis and AI-enabled features. |
| Duration | For the term of the Agreement and the post-termination deletion period described in Section 9. Certain data may be subject to feature-specific retention periods or ordinary backup and provider retention cycles as described in the Agreement, Documentation or applicable service configuration. |
| Nature of processing | Collection, receipt, organization, storage, retrieval, analysis, matching, transmission to authorized recipients and Subprocessors, restriction, and, where supported through available product functionality or Marcenta operational processes, export, deletion and destruction as necessary to provide the Services. |
| Data subjects | Customer users and personnel; Customer’s customers, prospects, leads and business contacts; meeting or call participants; and other individuals whose Personal Data Customer submits or connects to the Services. |
| Data categories | Business contact and identity data; account and authentication metadata; CRM, sales, marketing, advertising and analytics data; lead and routing data; online identifiers including IP addresses and approximate location derived from IP; calendar, meeting, call, recording, transcript and summary data where enabled; prompts, uploads, reports, generated outputs and workflow execution data; integration and connection metadata; billing contact information; support communications; and operational metadata. |
| Sensitive data | The Services are not intended for the highly sensitive categories restricted under Section 3, and Customer must not submit such data unless Marcenta expressly agrees otherwise in writing. |
| AI processing | Where Customer enables AI features, relevant Customer Personal Data may be provided to third-party AI service providers to perform the requested feature. Marcenta will not use Customer Personal Data to train generalized AI models unless Customer expressly agrees otherwise in writing. |
SCHEDULE 2: REGIONAL TRANSFER AND PRIVACY TERMS
EU/EEA. Where Customer Personal Data is transferred in a manner requiring the European Commission Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914, the applicable module will apply based on the parties’ roles. Module Two applies where Customer is a Controller and Marcenta is a Processor; Module Three applies where Customer is a Processor and Marcenta is a Subprocessor. The parties select general written authorization for Subprocessors, and for purposes of Clause 9 the advance notice period for the addition or replacement of Subprocessors will be ten (10) days. The governing law for the SCCs will be the law of Ireland and the courts of Ireland will have jurisdiction for purposes of the SCCs.
UK. Where a transfer is subject to the UK GDPR and requires a transfer mechanism, the UK International Data Transfer Addendum to the EU SCCs will apply to the relevant transfer, using the information in this DPA and Schedule 1 to complete the applicable tables.
California. To the extent the California Consumer Privacy Act, as amended, applies and Customer is a Business, Marcenta will act as a Service Provider or Contractor for Customer Personal Data and will process such data only for the limited and specified business purposes described in the Agreement and this DPA. Marcenta will not sell or share Customer Personal Data, or retain, use or disclose it outside the direct business relationship or for purposes other than those permitted by applicable law.
Marcenta will notify Customer if it determines it can no longer meet obligations applicable to it as a Service Provider or Contractor under California law, and Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.
India. Where India’s Digital Personal Data Protection Act, 2023 applies, Customer acts as the Data Fiduciary and Marcenta acts as the Data Processor for Customer Personal Data processed on Customer’s behalf. The parties’ obligations under this DPA will be interpreted consistently with those roles and any applicable rules or binding directions issued under that law.
SCHEDULE 3: CURRENT SUBPROCESSORS
The following reflects Marcenta’s current material Subprocessors. Marcenta may update this list in accordance with Section 7.
| Provider | Purpose |
|---|---|
| Railway | Application hosting, deployment, runtime and logs |
| Supabase | Managed database, authentication and platform services |
| Amazon Web Services | Object storage and supporting cloud infrastructure |
| OpenAI | AI-enabled product features |
| Sentry | Application monitoring, errors and performance monitoring |
| Resend | Transactional email delivery |
| Dodo Payments | Subscription and billing operations |
| IPInfo | IP-based country/continent geolocation for lead routing |
| Modal | Hosted call transcription, diarization and AI-assisted call analysis |
| Recall AI | Meeting recording, transcription and related call-processing services where enabled |
Customer-authorized third-party integrations, including advertising, CRM, calendar, messaging or other connected platforms, are not automatically Marcenta Subprocessors where Customer independently selects, directs or authorizes the connection. Marcenta-selected infrastructure and service providers that process Customer Personal Data on Marcenta's behalf are treated as Subprocessors under Section 7.