top of page

Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions (“Agreement”) between Marketiki and the Client.

1. Roles of the Parties

For the purposes of applicable Data Protection Laws:

  • The Client acts as the Data Controller

  • Marketiki acts as the Data Processor

Marketiki shall process Personal Data only on behalf of the Client and in accordance with the Client’s documented instructions.

2. Scope and Purpose of Processing

Marketiki processes Personal Data solely for the purpose of providing access to and operating its software platform, including related support and functionality.

Marketiki does not determine the purposes or means of processing Personal Data carried out by the Client.

3. Categories of Data and Data Subjects

3.1 Data Subjects
Personal Data may relate to:

  • customers or potential customers

  • employees, contractors, or representatives

  • business contacts

  • users of the Client’s campaigns

3.2 Types of Personal Data
Personal Data may include:

  • names

  • email addresses

  • phone numbers

  • company information

  • IP addresses and technical data

4. Processing Instructions

Marketiki shall:

  • process Personal Data only as necessary to provide the Services

  • follow the documented instructions of the Client

  • inform the Client if any instruction violates applicable Data Protection Laws

5. Confidentiality

Marketiki shall ensure that all personnel authorized to process Personal Data:

  • are subject to confidentiality obligations

  • receive appropriate training regarding data protection

6. Security Measures

Marketiki shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • protection against unauthorized access

  • protection against accidental loss, destruction, or damage

Marketiki shall also ensure that any third-party providers involved in processing Personal Data apply appropriate security measures.

7. Sub-processors

Marketiki may engage third-party service providers (“sub-processors”) to support the provision of the Services.

Marketiki shall:

  • ensure that sub-processors process Personal Data only on documented instructions and are bound by data protection obligations equivalent to those in this DPA

  • remain responsible for the performance of its sub-processors

8. Data Subject Rights

Taking into account the nature of the processing, Marketiki shall assist the Client, where reasonably possible, in responding to requests from data subjects, including:

  • access

  • rectification

  • deletion

  • restriction

  • portability

If Marketiki receives a request directly, it shall notify the Client without undue delay.

9. Assistance with Compliance

Marketiki shall provide reasonable assistance to the Client in ensuring compliance with applicable Data Protection Laws, including:

  • data protection impact assessments (where applicable)

  • cooperation with supervisory authorities

10. Personal Data Breach

In the event of a Personal Data Breach, Marketiki shall:

  • notify the Client without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach

  • provide relevant information about the breach

  • take reasonable steps to mitigate its effects

11. International Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), Marketiki shall ensure that appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs)

  • or other legally recognized transfer mechanisms

12. Return and Deletion of Data

Upon termination or expiration of the Agreement, Marketiki shall, at the Client’s choice:

  • delete Personal Data; or

  • return Personal Data to the Client

unless retention is required by applicable law.

13. Audits

The Client may request information necessary to demonstrate compliance with this DPA.

Any audit shall:

  • be conducted with reasonable notice

  • be limited in scope

  • not disrupt Marketiki’s operations

The Client shall bear the costs of any audit.

14. Liability

Liability under this DPA shall be subject to the limitations set out in the Terms and Conditions.

15. Governing Law

This DPA shall be governed by the laws of the Netherlands.

bottom of page