This translation is provided for information only. Only the French version of this document is legally binding.
Legal information
Privacy Policy
Last updated: 29 June 2026 · Version 3.0
This privacy policy (hereinafter the “Policy”) describes how the company MARA LABS processes personal data in connection with the operation of the “nullbot” software (hereinafter the “Service”) and the website accessible at https://nullbot-website-production.up.railway.app (hereinafter the “Site”).
MARA LABS is committed to protecting the privacy of individuals whose data it processes and to ensuring a high level of protection in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “GDPR”) as well as with amended law No. 78-17 of 6 January 1978, known as the “Informatique et Libertés” law.
The Service has one essential particularity: it orchestrates artificial intelligence Agents that perform real actions on behalf of client companies. This architecture leads MARA LABS to act under two distinct legal capacities, depending on the nature of the data concerned.
Two roles, two liability regimes.
1. MARA LABS, data controller. For the data of Site visitors, prospects, and Customers and authorized users as contracting parties, as well as for data relating to the management of the contractual and commercial relationship, MARA LABS alone determines the purposes and means of the processing. It acts as data controller within the meaning of Article 4(7) of the GDPR, and it is in this capacity that the commitments described in this Policy apply.
2. MARA LABS, processor (Article 28 GDPR). For Client Content — that is, the data submitted to the Service by the Client and processed by the Agents to produce Outputs — MARA LABS acts as a processor. The Client remains the data controller of that data: it determines the purposes, holds the legal bases, and bears the obligation to inform the data subjects. MARA LABS' commitments in that capacity are governed by a data processing agreement ("Data Processing Agreement" or "DPA"), available on the dpa.html page.
This Policy is intended to clarify both of these dimensions, it being specified that it primarily addresses processing for which MARA LABS acts as controller. For processing carried out as a processor, data subjects are invited to contact the responsible Client and to refer to the DPA.
This Policy is to be read together with the other contractual and informational documents published by MARA LABS, in particular the legal notice, the cookie and tracker policy, the terms of use, the terms of sale and the data processing agreement (DPA).
1. Data controller and contact
The controller of the personal data processing described in this Policy, when MARA LABS acts in that capacity, is the following company.
Company name: MARA LABS
Legal form: société par actions simplifiée (SAS)
Share capital: €100
Registered office: 41 rue Jacquemars Giélée, 59800 Lille, France
SIREN number: 104 321 104
Registration: RCS Lille Métropole 104 321 104
Host of the Service and the Site: Railway Corporation (United States of America)
How to contact us
For any question relating to this Policy, the exercise of your rights, or more generally the processing of your personal data, you may contact MARA LABS by postal mail addressed to its registered office:
MARA LABS — Data Protection — 41 rue Jacquemars Giélée, 59800 Lille, France.
Contact email address. As of the date this Policy is published, MARA LABS does not yet have a dedicated contact email address. A dedicated contact email address will be set up once the domain is opened and published here. In the meantime, the sole point of contact for any request relating to personal data remains postal mail addressed to the registered office.
Data Protection Officer
Given the nature, scope and purposes of its processing activities, MARA LABS has not appointed a Data Protection Officer (DPO), as such appointment is not mandatory under article 37 of the RGPD. The sole point of contact for any question relating to data protection remains postal mail addressed to the registered office, under the conditions set out above.
2. Definitions
For the proper understanding of this Policy, the terms below, when capitalized, have the following meaning. Definitions derived from the RGPD reproduce those set out in its Article 4.
Terms from the GDPR (Article 4)
- Personal data: any information relating to an identified or identifiable natural person, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to that person's identity.
- Processing: any operation or set of operations performed on personal data, such as collection, recording, organisation, storage, consultation, use, disclosure, erasure or destruction.
- Controller: the natural or legal person who determines the purposes and means of the processing.
- Processor: the natural or legal person who processes data on behalf of the controller.
- Data subject: the identified or identifiable natural person whose data is processed.
- Recipient: the individual or legal entity that receives the data.
- Consent: any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they agree to the processing of their data.
- Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, data.
Terms specific to the Service
- Service: the “nullbot” software, provided as Software as a Service, which orchestrates artificial intelligence Agents performing actions on behalf of Clients.
- Agent: a software entity driven by one or more artificial intelligence models, configured within the Service, which performs real tasks and actions according to the instructions and configuration defined by the Client.
- Output: the content, result or action generated by an Agent from the Client Content and the instructions provided.
- Client Content: all data, files, instructions, credentials, and information submitted by the Client to the Service or accessed by the Agents in the course of performing their tasks. Client Content may contain personal data for which the Client is responsible.
- Client: the legal entity or individual acting in a professional capacity that subscribes to the Service and on whose behalf the Agents perform tasks.
- Authorized User: the natural person authorized by the Client to access and configure the Service.
- Model Provider: the third-party provider supplying the artificial intelligence models used by the Agents (for example Anthropic or Google).
- BYO key (Bring Your Own Key): an option allowing the Client to use its own access key with a Model Provider, so that exchanges with that Provider take place under the Client’s own account and responsibility.
3. Scope of application
This Policy applies to all processing of personal data carried out by MARA LABS in connection with:
- the consultation and use of the Site by its visitors;
- the commercial and pre-contractual relations with prospects and potential Clients;
- the subscription, performance, and monitoring of the Service supply contract with Clients and their authorized users;
- the management of billing and payments;
- the security, oversight and improvement of the Service and the Site.
Processing as a processor. The processing of Client Content by the Agents constitutes processing on behalf of a controller within the meaning of Article 28 of the RGPD. In this respect, the Client remains the data controller and this Policy does not replace the information that the Client must provide to data subjects. MARA LABS's commitments as a processor are described in the dedicated article below and detailed in the DPA.
Links to third parties. This Policy does not apply to third-party sites, services, or platforms accessible from the Site or the Service via hyperlinks. MARA LABS invites data subjects to review the privacy policies specific to these third parties.
4. Categories of Data Collected
MARA LABS collects and processes various categories of personal data depending on the status of the data subject and the context of collection. The principle of minimisation (Article 5(1)(c) of the RGPD) is applied: only the data strictly necessary for the purposes pursued is collected.
Site visitor data
When a person browses the Site, MARA LABS may process:
- the browsing data: pages viewed, date and time of connection, duration of visit, navigation path on the Site;
- the technical data: IP address, browser type and version, operating system, device type, language, screen resolution;
- the identifiers placed by cookies and trackers, under the conditions described in the cookie policy.
Prospect data
When a person expresses interest in the Service (contact form, demo request, sales outreach, sign-up for a communication), MARA LABS may process:
- the professional identification data: first name, last name, job title, company, industry;
- the professional contact details: professional email address, professional phone number;
- the content of exchanges: nature of the request, needs expressed, contact history.
Data of Clients and authorized users
In connection with the subscription and performance of the contract, MARA LABS processes:
- the account identification data: first name, last name, job title, email address, login ID;
- the identification data of the client company: company name, address, registration number (SIREN/SIRET or equivalent), Intra-Community VAT number;
- the account management data: preferences, Agent settings, assigned access rights, configuration history;
- the data relating to the contractual relationship: contracts, orders, correspondence, support requests.
Payment data
For the processing of payments and billing, the following are processed:
- the billing data: company name, billing address, VAT number, amount and history of transactions;
- payment method data, collected and processed directly by the payment provider Stripe. MARA LABS does not store full card numbers; this sensitive data is processed by the provider in a certified PCI-DSS environment.
Client Content submitted to the Agents
In the course of the performance of tasks by the Agents, the Client submits Client Content that may contain personal data (for example data relating to the Client's employees, customers, suppliers, or contacts). With respect to that data:
- the Client is the data controller;
- MARA LABS acts as processor and processes this data solely on the Client's documented instructions and only for the purposes of performing the Service.
MARA LABS has no control over the content, nature, or sensitivity of the data contained in the Client Content. It is the Client's responsibility to ensure that it has a legal basis, that it has provided the required information to data subjects, and that it does not submit, absent appropriate safeguards, data falling within special categories within the meaning of Article 9 of the GDPR.
Technical data and logs
To ensure the operation, security and traceability of the Service, MARA LABS processes:
- the access and activity logs: timestamps of connections and actions, IP address, session identifier, actions performed by the Agents;
- technical and diagnostic logs: system events, errors, performance metrics;
- the security logs: access attempts, authentication events, security alerts.
5. Purposes and legal bases
Each processing operation carried out by MARA LABS as controller pursues one or more specific purposes, based on one of the legal bases listed in article 6 of the GDPR. The table below summarizes these processing operations.
| Purpose | Categories of data | Legal basis (Art. 6 RGPD) |
|---|---|---|
| Provision and proper functioning of the Site | Browsing data, technical data | Legitimate interest (Art. 6.1.f) — ensuring a functional and secure Site |
| Audience measurement and Site improvement | Browsing data, cookie identifiers | Consent (Art. 6.1.a) for non-strictly necessary trackers |
| Management of contact requests and prospects | Identification data and professional contact details, content of exchanges | Pre-contractual measures (art. 6.1.b) or legitimate interest (art. 6.1.f) — develop business activity |
| B2B business prospecting | Business contact details, exchange history | Legitimate interest (art. 6.1.f), subject to the right to object; consent (art. 6.1.a) where required by law |
| Subscription to and performance of the Service contract | Account data, client company data, configuration data | Performance of the contract (art. 6.1.b) |
| Management of billing and payments | Billing data, data relating to the payment method | Performance of the contract (Art. 6.1.b) and legal obligation (Art. 6.1.c) — accounting |
| Provision of support and assistance to Clients | Account data, content of requests | Performance of the contract (art. 6.1.b) |
| Security, fraud and abuse prevention | Access logs, security logs, technical data | Legitimate interest (art. 6.1.f) and legal obligation (art. 6.1.c) |
| Compliance with legal and regulatory obligations | Accounting, contractual and security data | Legal obligation (Art. 6.1.c) |
| Establishment, exercise, or defense of legal claims | Contractual data, logs, correspondence | Legitimate interest (Art. 6.1.f) — protecting its rights |
Explanation of legitimate interests and balancing test
Where MARA LABS bases a processing operation on its legitimate interest (Article 6(1)(f) of the RGPD), it carries out a balancing test between that interest and the fundamental rights and freedoms of the data subjects.
Interests pursued. The legitimate interests invoked include: ensuring the security and integrity of the Service and the Site; preventing fraud and misuse; developing and promoting business activity in a professional (B2B) context; improving the quality of the Service; protecting MARA LABS's rights in the event of a dispute.
Reasonableness. This processing is limited to what is necessary, primarily concerns professional data, and does not give rise to a disproportionate infringement of privacy. Data subjects can reasonably expect such processing in the context of a professional relationship.
Guarantees. Data subjects have, at all times, a right to object on grounds relating to their particular situation (Article 21 of the GDPR) and, with regard to direct marketing, an unconditional right to object. The procedures for exercising this right are described in the article relating to rights.
6. The Service and artificial intelligence
The Service relies on Agents driven by artificial intelligence models provided by third-party Model Providers. MARA LABS places particular importance on transparency regarding how this technology works.
Transmission of content to Model Providers
To generate the Outputs, the content and instructions processed by the Agents (including, where applicable, Customer Content) are transmitted to the Model Providers. This transmission is carried out solely for the purpose of generating the requested Outputs and in the context of performing the Service.
Professional interfaces, no training on your data
Exchanges with Model Providers take place via professional interfaces (APIs) governed by enterprise terms of use. Under these terms, the content transmitted is not used to train or retrain the Providers' models. The data is used solely to produce the Output corresponding to the request.
"BYO key" option
The Service offers a “BYO key” (Bring Your Own Key) option allowing the Client to use its own access key with a Model Provider. In this case, exchanges with that Provider take place directly under the Client's account and responsibility, in accordance with the Provider's terms accepted by the Client.
Probabilistic nature of the Outputs
Outputs produced by the Agents are based on probabilistic models. As such, they may contain inaccuracies, approximations or errors. Outputs do not constitute professional advice or a guarantee of accuracy. The Client remains responsible for verifying, validating and using the Outputs, particularly when they trigger real-world actions.
7. Automated individual decisions
Pursuant to Article 22 of the RGPD, every data subject has the right not to be subject to a decision based exclusively on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
Processing carried out by MARA LABS as controller. In connection with processing for which MARA LABS acts as controller (management of the Site, of prospects, of Clients, of billing), MARA LABS does not implement any decision producing legal or similarly significant effects based solely on automated processing within the meaning of Article 22.
Actions performed by Agents. Agents may perform actions in an automated manner on the Client's behalf. Where such actions are liable to constitute automated decisions producing legal or similarly significant effects on data subjects, it is the Client, in its capacity as controller of the Client Content, who must assess their lawfulness, put in place the safeguards required under article 22 (in particular human intervention, the ability to express one's point of view and to contest the decision) and provide the required information. MARA LABS, as processor, provides the configuration and supervision features enabling the Client to ensure this human oversight.
8. MARA LABS as processor (Article 28 GDPR)
For the processing of Customer Content, MARA LABS acts as a processor within the meaning of Article 28 of the GDPR, the Customer retaining the status of controller. This relationship is governed by a data processing agreement (DPA) available on the dpa.html page, which prevails for such processing.
MARA LABS' commitments as data processor
Pursuant to Article 28(3) of the GDPR, MARA LABS undertakes in particular to:
- Process data only on the Client's documented instructions, including for transfers outside the European Union, unless otherwise required by law;
- Ensure the confidentiality of data by ensuring that persons authorized to process it are subject to a confidentiality obligation;
- Implement appropriate technical and organizational measures in accordance with Article 32 of the RGPD;
- Comply with the conditions for engaging sub-processors (prior authorisation, notification of changes, equivalent obligations passed down by contract);
- Assist the Client, through appropriate measures, in responding to requests from data subjects to exercise their rights;
- Assist the Customer in complying with its obligations regarding security, breach notification, impact assessment, and prior consultation of the supervisory authority;
- Delete or return the data at the end of the engagement, as chosen by the Client, and destroy existing copies unless a legal retention obligation applies;
- Make available to the Customer all information necessary to demonstrate compliance with its obligations and to enable audits to be carried out.
Notification of breaches to the Client. As processor, MARA LABS notifies the Client of any data breach affecting the Client Content without undue delay after becoming aware of it, in order to enable the Client to fulfill its own notification obligations.
9. Data recipients
Personal data is intended for the authorized internal departments of MARA LABS, within the limits of their respective duties, as well as for the following categories of recipients:
- the authorized personnel of MARA LABS involved in commercial management, operation of the Service, support, billing and security;
- the subsequent processors acting on behalf of MARA LABS, listed in the dedicated article (hosting, Model Providers, payment, content distribution);
- the payment provider, for the processing of transactions;
- MARA LABS's advisors and service providers (accountants, lawyers, auditors) bound by a confidentiality obligation;
- the competent administrative or judicial authorities, where required by law or for the defense of MARA LABS’ rights.
MARA LABS does not sell any personal data. No data is disclosed to third parties for prospecting purposes without complying with the applicable legal bases.
10. Subsequent processors
To provide the Service, MARA LABS uses third-party providers acting as sub-processors. Each is selected for its data protection guarantees and is bound by a contract imposing obligations consistent with Article 28 of the GDPR. The table below sets out the main sub-processors.
| Provider | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Railway Corporation | Hosting of the Service and the Site, infrastructure | United States | Standard Contractual Clauses (SCC) under Decision 2021/914 |
| Anthropic, PBC | Provision of the “Claude” AI model to generate Outputs | United States | Standard Contractual Clauses (SCCs) |
| Google Ireland Limited / Google LLC | Provision of the “Gemini” AI model (optional, where applicable) | European Union / United States | Standard Contractual Clauses (SCCs) for transfers outside the EU |
| Stripe Payments Europe, Limited | Processing of payments and billing | European Union / United States | Standard Contractual Clauses (SCCs) for transfers outside the EU |
| jsDelivr | Content delivery network (CDN) for distributing Site resources | International | Contractual framework and appropriate safeguards for transfers |
Changes to the list and right to object
MARA LABS may update the list of its sub-processors for the needs of the Service. Any modification (addition or replacement) will be reflected in this Policy and, where applicable, communicated to the Client in accordance with the DPA. The Client has the right, under the conditions set out in the DPA, to object on legitimate grounds to the addition of a new sub-processor.
11. Transfers outside the European Union
Some of MARA LABS' sub-processors are located outside the European Union, in particular in the United States. Any transfer of data to a third country is governed in accordance with Chapter V of the RGPD.
Standard contractual clauses
In the absence of an applicable adequacy decision, transfers are based on the standard contractual clauses (SCC) adopted by the European Commission through Implementing Decision (EU) 2021/914 of 4 June 2021. These clauses impose on the recipient protection obligations equivalent to those of the GDPR.
Supplementary measures
Where necessary to ensure a substantially equivalent level of protection, MARA LABS, in addition to the SCCs, implements or ensures the implementation of appropriate supplementary measures, in particular: encryption of data in transit and at rest, pseudonymization where possible, strict access controls, and an assessment of the legislation of the destination country as well as the remedies available to data subjects.
Data subjects may obtain further information about the transfers and a copy of the safeguards put in place by sending a request by post to MARA LABS's registered office.
12. Retention periods
Personal data is retained for a period not exceeding what is necessary in view of the purposes for which it is processed, increased where applicable by statutory limitation and archiving periods. The table below sets out the periods applied.
| Category of data | Retention period |
|---|---|
| Browsing data and cookies | Depending on the purpose, within the limits set out in the cookie policy (a maximum of 13 months for audience-measurement trackers subject to consent) |
| Prospect data (no contractual relationship) | Up to 3 years from the prospect's last contact |
| Data of Clients and authorized users | For the entire duration of the contractual relationship, then intermediate archival storage for the applicable statute of limitations period |
| Billing data and accounting records | 10 years from the close of the financial year (statutory obligation) |
| Client Content processed by Agents | Retained for the period necessary to perform the Service; deleted or returned at the end of the engagement in accordance with the Client’s instructions and the DPA |
| Access, technical, and security logs | Up to 12 months, unless longer retention is required for security or litigation purposes |
| Data related to rights management (proof of requests) | For as long as necessary to process the request, then in accordance with the applicable statute of limitations |
Beyond these periods, data is irreversibly deleted or anonymized. Certain data may be retained for a longer period in archival storage where required by law or for the establishment, exercise, or defense of legal claims.
13. Data security
In accordance with Article 32 of the GDPR, MARA LABS implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of the processing.
Technical measures
- Encryption of data in transit (TLS protocols) and, where applicable, at rest;
- Access control based on the principle of least privilege and authentication of authorized users;
- Segregation of environments and data between Clients;
- Logging and traceability of access and sensitive actions;
- Regular backups and restoration procedures;
- Monitoring and detection of security incidents.
Organizational measures
- Awareness training and confidentiality commitment of authorized personnel;
- Access rights management and periodic review of access rights;
- Selection of sub-processors offering sufficient guarantees, with contractual oversight;
- Management procedures for incidents and data breaches.
As no information system can guarantee absolute security, MARA LABS undertakes to implement measures proportionate to the risk and to adapt them in line with the state of the art and identified threats.
14. Data Breaches
MARA LABS has implemented procedures for detecting, qualifying and managing personal data breaches.
Where MARA LABS acts as controller
In the event of a data breach likely to result in a risk to the rights and freedoms of the data subjects, MARA LABS notifies the breach to the CNIL as soon as possible and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk, the data subjects concerned are also informed as soon as possible, in accordance with Article 34 of the GDPR.
When MARA LABS acts as a processor
In the event of a breach affecting Client Content, MARA LABS informs the Client without undue delay after becoming aware of it, in accordance with Article 33(2) of the GDPR, so as to enable the Client, as data controller, to fulfil its own obligations to notify the supervisory authority and, where applicable, the data subjects.
Any breach is subject to internal documentation setting out the facts, the effects, and the corrective measures taken, in accordance with the obligation to maintain a breach register.
15. Your Rights
In accordance with the GDPR and the French Data Protection Act, every data subject has the following rights over their data processed by MARA LABS as controller.
Right of access (Art. 15)
You may obtain confirmation as to whether or not data concerning you is being processed and, where applicable, obtain a copy of it as well as information on the purposes, categories of data, recipients, and retention period.
Right to rectification (Art. 16)
You may request the correction of inaccurate data and the completion of incomplete data concerning you.
Right to erasure (Art. 17)
You may request the erasure of your data in the cases provided for by the GDPR, subject to statutory retention obligations and to needs related to the defense of legal rights.
Right to restriction of processing (Art. 18)
You may request the temporary suspension of the use of your data, in particular in the event of a dispute regarding its accuracy or the lawfulness of the processing.
Right to object (Art. 21)
You may object to processing based on MARA LABS' legitimate interest for reasons relating to your particular situation, as well as, unconditionally, to processing for direct marketing purposes.
Right to data portability (art. 20)
For processing based on consent or the performance of a contract and carried out by automated means, you may receive your data in a structured, commonly used and machine-readable format, and transmit it to another controller.
Right to withdraw consent
Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Post-mortem guidelines
In accordance with Article 85 of the French Data Protection Act (loi Informatique et Libertés), you may define directives regarding the fate of your data after your death (retention, erasure, communication), whether general or specific, and designate a person responsible for carrying them out.
Right to lodge a complaint
You have the right to lodge a complaint with the CNIL if you believe that the processing of your data does not comply with applicable regulations (see the dedicated article).
How to exercise your rights
Your rights may be exercised by postal mail addressed to: MARA LABS — Data Protection — 41 rue Jacquemars Giélée, 59800 Lille, France. A dedicated contact email address will be put into service as soon as the domain is opened, and will be published here.
Proof of identity. In order to prevent any unauthorized access, MARA LABS may ask you to prove your identity by any appropriate means where there is reasonable doubt as to the requester's identity.
Response times. MARA LABS responds within one month of receiving the request. This period may be extended by two months in view of the complexity and number of requests; you will be informed accordingly.
Customer Content. For data contained in the Customer Content, since MARA LABS acts as processor, requests must be addressed to the Customer, as controller. MARA LABS will assist the Customer in handling such requests in accordance with the DPA.
16. Data of Minors
The Service is professional (B2B) software that is neither intended nor offered to minors. MARA LABS does not knowingly collect data concerning minors in connection with its processing as a controller.
If MARA LABS were to learn that it had mistakenly collected data relating to a minor without the appropriate legal basis, it would delete such data as soon as possible. Anyone aware of such a situation is invited to report it by mail to the registered office.
17. Commercial prospecting and right to object
MARA LABS may send commercial prospecting communications to professionals, within the context of a B2B relationship, in accordance with the rules applicable to professional prospecting.
Where required by law, prospecting is subject to the individual's prior consent; failing that, it is based on MARA LABS' legitimate interest in developing its business, provided the subject matter relates to the recipient's professional function.
You may object at any time and free of charge to receiving marketing communications:
- by using the unsubscribe link included in each electronic communication, where available;
- by sending a request by post to MARA LABS' registered office.
18. Cookies and trackers
The Site may use cookies and other trackers. Trackers strictly necessary for the operation of the Site are based on the legitimate interest of MARA LABS, while non-essential trackers (in particular non-exempt audience measurement) are subject to your prior consent.
The precise terms (categories of trackers, purposes, retention periods, arrangements for managing consent and withdrawal) are described in detail in the cookie and tracker policy, to which this Policy expressly refers.
19. Origin and accuracy of data
Source of data. Data processed by MARA LABS is, in the vast majority of cases, collected directly from the data subjects (forms, account creation, business exchanges, use of the Service). Certain technical data is automatically generated by use of the Site and the Service. Where applicable, professional data may come from publicly accessible sources (registers, professional websites) as part of B2B prospecting.
Accuracy of data. MARA LABS strives to keep data accurate and up to date. You are invited to report any inaccuracy so that your data can be updated, by exercising your right of rectification.
20. Changes to the policy
MARA LABS may be required to amend this Policy in order to adapt it to legal, regulatory, case-law, technical or organizational developments, or in the event of changes to the Service or to the list of subsequent processors.
The applicable version is the one published on the Site as of the date of consultation. In the event of a substantial change, MARA LABS will endeavor to inform the persons concerned by any appropriate means. It is recommended to consult this page regularly.
21. Complaint to the supervisory authority
If, after contacting us, you believe that your rights are not being respected or that the processing of your data does not comply with applicable regulations, you have the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), the supervisory authority with jurisdiction in France.
Commission nationale de l'informatique et des libertés (CNIL)
3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France
Phone: 01 53 73 22 22
Website: www.cnil.fr
However, MARA LABS invites you, prior to any claim, to contact it by post at its registered office in order to seek an amicable solution.