Data Processing Agreement

Data Processing Agreement

Last updated: April 5, 2026

1. Scope and Application

This Data Processing Agreement ("DPA") supplements the Terms of Service between Makinari ("Processor") and the customer ("Controller"). It reflects the parties' agreement regarding the processing of personal data on behalf of the Controller in connection with the Services provided by Makinari under the Terms of Service.

2. Processing of Personal Data

Controller Instructions: We shall process Customer Personal Data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by applicable law to which the Processor is subject.

Nature and Purpose: The processing of Customer Personal Data is carried out to provide the Services as described in the Terms of Service, which includes storing data, providing AI-agent automation, routing data to large language models, and facilitating customer relationship management.

3. Sub-processing

The Controller provides general authorization for the Processor to engage sub-processors to process Customer Personal Data on behalf of the Controller. The Processor currently engages third-party sub-processors to provide infrastructure services, AI capabilities, and customer support.

The Processor will ensure that any sub-processor it engages provides sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of applicable data protection laws.

4. Data Subject Rights

We shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the data subject's rights laid down in applicable data protection laws. We will promptly notify the Controller if we receive a request from a data subject under any data protection laws in respect of Customer Personal Data.

5. Security

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

6. International Transfers

Any transfer of Customer Personal Data outside the European Economic Area (EEA), the United Kingdom, or Switzerland to countries which do not ensure an adequate level of data protection shall be governed by appropriate safeguards, such as the Standard Contractual Clauses (SCCs).

7. Contact Us

If you have any questions or require an executed copy of this DPA, please contact us at privacy@makinari.com.