Skip to content
nullbot ← Back to site
◍EN
Français English Español Português (Brasil) Português (Portugal) 简体中文 繁體中文 日本語 한국어 Deutsch Nederlands العربية

This translation is provided for information only. Only the French version of this document is legally binding.

Legal information

Data Processing Agreement (DPA)

Last updated: 29 June 2026 · Version 3.0

Legal NoticePrivacyCookiesTerms of UseTerms of SaleDPA

This Personal Data Processing Agreement (hereinafter the “Agreement” or the “DPA”) is entered into pursuant to Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “RGPD”).

Between the undersigned:

On the one hand, the Client, a natural or legal person having subscribed to the nullbot Service, acting as data controller within the meaning of Article 4(7) of the GDPR (hereinafter the “Controller” or the “Client”);

And on the other hand, the company MARA LABS, a simplified joint-stock company (société par actions simplifiée) with capital of €100, whose registered office is located at 41 rue Jacquemars Giélée, 59800 Lille, France, registered with the Trade and Companies Register of Lille Métropole under SIREN number 104 321 104 (RCS Lille Métropole 104 321 104), publisher of the nullbot Service, acting as data processor within the meaning of Article 4(8) of the GDPR (hereinafter the "Processor" or "MARA LABS");

The Controller and the Processor being hereinafter individually referred to as a « Party » and collectively as the « Parties ».

The following has been stated as background. In connection with the performance of the services agreement entered into between the Parties, the Processor makes available to the Client the SaaS software known as “nullbot”, which orchestrates artificial intelligence agents performing real actions on the Client's behalf. In the course of using the Service, the Client submits Client Content to the agents that may contain personal data, which the Processor processes on behalf of and under the instructions of the Client. This Agreement sets out the conditions under which the Processor carries out this processing, in accordance with the requirements of Article 28 of the GDPR.

This Agreement forms an integral part of the contract binding the Parties and operates alongside the General Terms and Conditions of Sale, the General Terms of Use and the Privacy Policy, which it supplements with regard to the protection of personal data.

Data protection contact. Any request, notification, or correspondence relating to this Agreement may be sent to the Processor by postal mail to the registered office: MARA LABS, 41 rue Jacquemars Giélée, 59800 Lille, France. A dedicated contact email address will be put into service as soon as the domain is live, and published here.

Table of contents

  1. 1. Purpose, scope and contractual structure
  2. 2. Definitions
  3. 3. Status and roles of the parties
  4. 4. Description and scope of the processing
  5. 5. Documented instructions from the Controller
  6. 6. Confidentiality of persons authorized to process data
  7. 7. Security measures (article 32)
  8. 8. Use of subsequent processors
  9. 9. Assistance with the exercise of data subjects' rights
  10. 10. Assistance regarding security, breaches, DPIAs and prior consultation
  11. 11. Notification of personal data breaches
  12. 12. Transfers outside the European Union
  13. 13. Audits and inspections
  14. 14. Fate of data at the end of the processing
  15. 15. Liability, warranty, and allocation between the parties
  16. 16. Term and termination of the agreement
  17. 17. Miscellaneous provisions
  18. 18. Appendix 1 — Description of the processing
  19. 19. Appendix 2 — Technical and organizational security measures
  20. 20. Appendix 3 — List of authorized sub-processors

1. Purpose, scope and contractual structure

Purpose of the Agreement. The purpose of this Agreement is to define the conditions under which the Processor undertakes to carry out, on behalf of the Controller, the personal data processing operations described in Annex 1, in connection with the provision of the nullbot Service. It sets out the respective obligations and rights of the Parties under Article 28 of the GDPR and, more broadly, the applicable provisions on the protection of personal data.

Legal framework. This Agreement falls within the framework of the GDPR, in particular its Articles 28 (processing), 32 (security of processing), 33 and 34 (data breaches), 35 (impact assessment), 36 (prior consultation) and 44 et seq. (transfers of data to third countries), as well as French Law No. 78-17 of 6 January 1978, as amended, on information technology, data files and civil liberties.

Contractual structure and hierarchy of documents. This Agreement constitutes an appendix to the services contract entered into between the Parties and forms an integral part of it. It prevails over any conflicting provision of the other contractual documents solely with regard to the processing of personal data. In the event of a conflict between this Agreement and the Terms of Sale, the Terms of Use, or the Privacy Policy, the provisions of this Agreement shall prevail solely on matters relating to the protection of personal data.

Acceptance. Subscribing to and using the Service constitutes full and complete acceptance of this Agreement by the Client acting as Controller.

2. Definitions

The terms below, when capitalized in this Agreement, have the following meaning. The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” shall have the meaning given to them under Article 4 of the GDPR.

  • "Service" means the nullbot software provided as SaaS by the Processor, including its artificial intelligence agents, interfaces, features and associated components.
  • “Agent” means any artificial intelligence agent deployed within the Service to perform tasks and actions on behalf of the Client, according to the configurations and instructions defined by the Client.
  • « Client Content » means all data, files, instructions, requests, documents and information, including personal data, that the Client submits to the Agents or incorporates into the Service.
  • "Personal Data" means any information relating to an identified or identifiable natural person, processed by the Processor on behalf of the Controller under this Agreement.
  • “Processing” means any operation or set of operations performed on personal data, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
  • “Controller” or “Data Controller” means the Client, who determines the purposes and means of the processing.
  • “Processor” means MARA LABS, which processes personal data on behalf of the Controller.
  • “Sub-processor” means any third party engaged by the Processor to carry out, in whole or in part, specific processing activities on behalf of the Controller.
  • "Data subject" means the identified or identifiable natural person to whom the processed personal data relates.
  • “Personal data breach” or “Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
  • “SCC” means the Standard Contractual Clauses adopted by the European Commission by its Implementing Decision (EU) 2021/914 of 4 June 2021, governing transfers of personal data to third countries.
  • “RGPD” refers to Regulation (EU) 2016/679 of 27 April 2016.

3. Status and roles of the parties

Status of the Customer. The Customer acts as data controller within the meaning of Article 4(7) of the GDPR. It alone determines the purposes and means of the processing carried out in connection with the use of the Service. As such, it is responsible for ensuring the lawfulness of the processing it entrusts to the Processor, in particular for having an appropriate legal basis within the meaning of Article 6 of the GDPR and, where applicable, the safeguards provided for in Article 9, as well as for having fulfilled its information obligations towards data subjects.

Status of the Processor. MARA LABS acts as processor within the meaning of Article 4(8) of the GDPR. The Processor processes personal data solely on behalf of the Controller and on the basis of its documented instructions, in accordance with this Agreement.

Processor warranties. The Processor represents that it offers sufficient guarantees regarding the implementation of appropriate technical and organizational measures so that processing meets the requirements of the GDPR and ensures the protection of data subjects' rights, in accordance with Article 28(1) of the GDPR.

The Customer's own responsibilities. The Customer remains solely responsible for:

  • the lawfulness, fairness and transparency of the processing operations it carries out via the Service;
  • the accuracy, quality and relevance of the Client Content submitted to the Agents;
  • compliance with its information obligations and, where applicable, the collection of consent from the data subjects concerned;
  • defining the appropriate data retention period and minimizing the data submitted to the Service;
  • the configuration and oversight of the Agents, as well as the actions performed by them on its behalf.

4. Description and scope of processing

Scope. The Processor is authorized to process, on behalf of the Controller, the personal data necessary for the provision of the Service, within the limits and according to the terms described in Appendix 1 to this Agreement, which specifies the nature and purpose of the processing, its duration, the type of personal data concerned, and the categories of data subjects concerned, in accordance with Article 28(3) of the RGPD.

Determination by the Controller. The exact scope of the processing results from the configurations, settings, and uses that the Client implements within the Service, as well as from the Client Content it submits to the Agents. The Controller acknowledges that it is responsible for defining and limiting this scope, as the Processor has no control over the content of the data that the Client chooses to submit.

Evolution. Appendix 1 may be supplemented or updated to reflect the evolution of the Service or the Client's usage, provided that such update may not extend the processing beyond what is necessary for the provision of the Service agreed between the Parties.

5. Documented instructions from the Controller

Processing on documented instructions. Pursuant to Article 28(3)(a) of the RGPD, the Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless the law concerned prohibits such information on important grounds of public interest.

Form of instructions. The following constitute documented instructions from the Controller: this Agreement and its appendices, the service contract, the settings configured by the Customer within the Service, the Customer Content submitted to the Agents, as well as any additional instruction formalized in writing (including by email or via the Service interface) and addressed to the Processor.

Manifestly unlawful instructions. The Processor shall immediately inform the Controller if, in its opinion, an instruction constitutes a violation of the GDPR or other provisions of Union or Member State law relating to data protection. In such case, the Processor is entitled to suspend performance of the instruction concerned until it is confirmed or amended by the Controller.

No use for its own purposes. The Processor shall not process personal data for any purpose other than those necessary for the performance of this Agreement and the provision of the Service, and in particular shall not use it for its own account or on behalf of third parties.

6. Confidentiality of persons authorized to process data

Confidentiality commitment. In accordance with Article 28(3)(b) of the GDPR, the Processor ensures that persons authorized to process personal data commit to confidentiality or are subject to an appropriate statutory obligation of confidentiality.

Authorization and access limitation. The Processor ensures that access to personal data is strictly limited to members of its staff and authorized persons who need access to perform their duties, in accordance with the principle of need-to-know and least privilege.

Awareness and training. The Processor shall ensure that persons authorized to process personal data receive the necessary training and awareness-raising regarding the protection of personal data and information security.

Durability of the commitment. The confidentiality obligation survives the termination of the duties of the persons concerned and the expiry of this Agreement.

7. Security measures (Article 32)

Security obligation. In accordance with Article 28(3)(c) and Article 32 of the GDPR, the Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as well as the risks to the rights and freedoms of natural persons.

Assessment criteria. The measures implemented take into account, as necessary:

  • the pseudonymization and encryption of personal data;
  • means to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • means to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
  • a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organizational measures to ensure the security of the processing.

Details of the measures. The technical and organizational measures implemented by the Processor are described in Appendix 2 to this Agreement. These measures may evolve over time, provided that the level of security is not diminished.

Sharing of responsibilities. The Controller remains responsible for implementing the security measures within its own sphere of control, in particular managing the credentials and permissions of its users, securing its own information systems, and minimizing the data submitted to the Service.

8. Use of sub-processors

General authorization. Pursuant to Article 28(2) and (4) of the RGPD, the Controller grants the Processor general authorization to engage sub-processors for the performance of specific processing activities necessary for the provision of the Service. The list of sub-processors authorized as of the date of this Agreement is set out in Annex 3.

Prior notice and right to object. The Processor shall inform the Controller of any planned change concerning the addition or replacement of a sub-processor, by any appropriate means (in particular by publishing an update to Appendix 3 and providing notice on the site or within the Service), thereby giving the Controller the opportunity to raise objections to such changes within a reasonable period. In the event of a legitimate and reasoned objection from the Controller, the Parties shall endeavor to find a solution. Failing a solution, the Controller may terminate the part of the Service concerned by the use of the disputed sub-processor, under the conditions set out in the contract.

Obligations imposed on sub-processors. In accordance with Article 28(4) of the GDPR, where the Processor engages a sub-processor, it shall impose on that sub-processor, by way of a contract or other legal act, the same data protection obligations as those set out in this Agreement, including in particular the obligation to provide sufficient guarantees regarding the implementation of appropriate technical and organisational measures.

Liability. The Processor remains fully liable to the Controller for the performance, by the sub-processor, of its data protection obligations. Where the sub-processor fails to fulfil its obligations, the Processor remains fully liable to the Controller for the performance of those obligations by the sub-processor.

9. Assistance with the exercise of data subjects' rights

Duty to assist. In accordance with Article 28(3)(e) of the GDPR, the Processor shall assist the Controller, insofar as this is possible, by appropriate technical and organizational measures, in fulfilling its obligation to respond to requests made by data subjects seeking to exercise their rights.

Rights concerned. This assistance covers all the rights provided for in Chapter III of the GDPR, including the right of access, rectification, erasure, restriction of processing, data portability, and the right to object.

Forwarding of requests. If a data subject sends a request to exercise their rights directly to the Processor, relating to processing carried out on behalf of the Controller, the Processor shall forward this request to the Controller without delay and shall refrain from responding to it directly, unless otherwise instructed by the Controller.

Resources Made Available. To the extent the Service allows, the Processor makes available to the Controller the features and tools enabling it to respond to data subjects' requests.

10. Assistance with security incidents, breaches, DPIA and prior consultation

General duty of assistance. In accordance with Article 28(3)(f) of the GDPR, the Processor helps the Controller ensure compliance with the obligations set out in Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to the Processor.

Security of processing (Article 32). The Processor assists the Controller in complying with the security requirements set out in Article 32 of the GDPR, in particular by providing information on the technical and organizational measures implemented.

Breach notification (Articles 33 and 34). The Processor assists the Controller in fulfilling its obligations to notify the supervisory authority of a personal data breach and, where applicable, to communicate that breach to data subjects, under the conditions set out in the “Notification of personal data breaches” section of this Agreement.

Data protection impact assessment (Article 35). The Processor assists the Controller, where necessary and to the extent of the information available to it, in carrying out a data protection impact assessment (DPIA) concerning the processing operations performed by means of the Service.

Prior consultation (Article 36). The Processor assists the Controller, where applicable, in the context of the prior consultation of the supervisory authority provided for in Article 36 of the GDPR.

Cost of Assistance. The assistance provided for under this section is furnished in light of the nature of the processing and the information available to the Processor. Where requests for assistance exceed what is reasonably included in the Service, the Processor may charge the Controller the reasonable costs incurred in this respect, following prior notice.

11. Notification of personal data breaches

Notification to the Controller. The Processor shall notify the Controller of any personal data breach without undue delay after becoming aware of it, in order to enable the Controller to fulfil, where applicable, its obligation to notify the supervisory authority within the seventy-two (72) hour period provided for in Article 33 of the RGPD.

Content of the notification. To the extent of the information available to it, the Processor shall communicate to the Controller, where applicable in stages:

  • a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects concerned and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to remedy the breach and, where applicable, mitigate its negative consequences;
  • the contact details of a point of contact from whom further information can be obtained.

Cooperation. The Processor cooperates with the Controller and takes reasonable measures to assist with the investigation, containment and resolution of the breach. Unless otherwise required by law, the Processor shall not notify the supervisory authority or the data subjects on behalf of the Controller, except upon the Controller's express instruction.

12. Transfers Outside the European Union

Principle. The Processor shall not transfer any personal data to a country outside the European Union or to an international organization without having informed the Controller and without having implemented the appropriate safeguards provided for in Chapter V of the GDPR.

Appropriate safeguards. Certain sub-processors engaged by the Processor are established outside the European Economic Area, in particular in the United States. Transfers to these sub-processors are governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission in its Implementing Decision (EU) 2021/914 of 4 June 2021 and, where applicable, by any other transfer mechanism recognised as valid (in particular an adequacy decision or certification under a recognised data protection framework).

Supplementary measures. Where necessary, the Processor implements, or ensures that the relevant sub-processors implement, appropriate supplementary measures (technical, organizational, and contractual) to ensure a level of protection for personal data substantially equivalent to that guaranteed within the European Union.

Information to the Controller. Upon request, the Processor shall provide the Controller with information regarding the safeguards implemented to govern transfers. The list of sub-processors and their location is set out in Appendix 3.

13. Audits and inspections

Provision of information. In accordance with Article 28(3)(h) of the GDPR, the Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and to enable audits, including inspections, to be carried out by the Controller or another auditor mandated by it, and shall contribute to such audits.

Audit terms. The Controller may, at its own expense, have an audit carried out of the Processor's compliance with its obligations under this Agreement, under the following conditions:

  • the audit is carried out on the basis of reasonable prior written notice, which may not be less than thirty (30) calendar days, except in the event of a confirmed data breach or a request from a supervisory authority;
  • the audit takes place during business hours and business days and in a manner that does not disproportionately disrupt the Processor's activity;
  • the audit is limited to once (1) per twelve (12) month period, except in exceptional circumstances (proven breach, request from a supervisory authority);
  • the auditor appointed by the Controller must not be a competitor of the Processor and must be subject to a confidentiality obligation;
  • the findings and information obtained during the audit are strictly confidential.

Documentation and certifications. The Processor may satisfy its obligation to demonstrate compliance by making available to the Controller the relevant documentation, audit reports, attestations, or certifications it holds, where these elements reasonably substantiate compliance with its obligations.

Costs. The costs of carrying out the audit are borne by the Controller. The time reasonably spent by the Processor assisting and supporting the audit may be invoiced to the Controller, after prior notice, when it exceeds what is reasonably included in the Service.

14. Fate of data at the end of processing

Controller's choice. In accordance with article 28(3)(g) of the GDPR, at the end of the provision of services relating to the processing, the Processor, as chosen by the Controller, shall delete or return all personal data to the Controller and destroy existing copies, unless European Union or Member State law requires that the personal data be retained.

Timeframes. The Controller has a reasonable period, which may not be less than thirty (30) calendar days from the end of the service, to exercise its choice of return or deletion. In the absence of instructions from the Controller upon expiry of this period, the Processor shall proceed to delete the personal data.

Return terms. In the event of return, the data is provided back to the Controller in a structured, commonly used format, to the extent of the Service's export capabilities.

Deletion. Deletion takes place within a reasonable period, including at the relevant sub-processors, and covers existing copies, subject to legal retention obligations and backups that are subject to an automatic erasure cycle on a set rotation.

Certification. At the Controller's request, the Processor shall certify in writing that the personal data has been effectively deleted.

15. Liability, warranty, and allocation between the parties

Principle of liability. Each Party is liable for damage caused by processing where it has not complied with the GDPR obligations specifically incumbent upon it, or where it has acted outside of, or contrary to, the Controller's lawful instructions, in accordance with Article 82 of the GDPR.

Processor's liability. The Processor shall only be liable for damage caused by processing that results from a breach of its own obligations under this Agreement or of the obligations specifically incumbent upon it as a processor within the meaning of the GDPR.

Controller liability. The Controller indemnifies the Processor against any claim, action, or demand from a third party, including data subjects and supervisory authorities, resulting from a breach by the Controller of its own obligations, in particular regarding the lawfulness of processing, information provided to data subjects, legal basis, data minimization, and the lawfulness of the Client Content submitted to the Agents.

Limitation of liability. The limitations and exclusions of liability provided for in the Terms and Conditions of Sale apply to this Agreement, to the extent permitted by applicable law and subject to the mandatory provisions of the GDPR relating to compensation for damage suffered by data subjects.

16. Term and termination of the agreement

Term. This Agreement takes effect on the date of acceptance by the Customer and remains in force for the entire duration of the services contract under which the Processor processes personal data on behalf of the Controller.

Ancillary nature. This Agreement is ancillary to the services contract. It automatically terminates upon expiry of the services contract, without prejudice to the provisions governing the fate of data at the end of the processing and to obligations whose nature implies that they survive termination of the Agreement (in particular confidentiality).

Survival of certain obligations. The obligations of confidentiality, deletion or return of data, and cooperation in the event of a request from a supervisory authority survive the termination of this Agreement for the period necessary for their performance.

17. Miscellaneous provisions

Order of precedence. In the event of a conflict between the provisions of this Agreement and those of other contractual documents relating to the processing of personal data, the provisions of this Agreement shall prevail. For any question not related to data protection, the Terms and Conditions of Sale and the Terms of Use remain applicable.

Partial invalidity. If one or more provisions of this Agreement were declared null, unlawful or unenforceable, the other provisions would retain their full force and effect. The Parties would endeavour to replace the invalid provision with a valid provision pursuing an equivalent objective.

Amendment. The Processor may update this Agreement, in particular to reflect changes in applicable regulations, guidance from supervisory authorities, or the Service. The Controller shall be informed by any appropriate means.

Governing law and jurisdiction. This Agreement is governed by French law and European Union law. Any dispute relating to its interpretation or performance falls within the jurisdiction of the courts determined in accordance with the Terms of Sale, subject to mandatory jurisdiction rules, in particular those protecting data subjects.

18. Appendix 1 — Description of the processing

This Appendix specifies the elements of processing required by Article 28(3) of the GDPR. The actual scope of processing depends on the Customer's use and configuration, as well as the Customer Content submitted to the Agents.

Purpose of the processingProvision of the nullbot Service, SaaS software orchestrating artificial intelligence Agents that perform real actions on behalf of the Client.
Nature of the processingCollection, recording, storage, structuring, consultation, use, transmission, disclosure to subsequent processors (AI model providers, hosting, payment), deletion, and any operation necessary to the functioning of the Service and to the performance of the actions entrusted to the Agents.
Purposes of the processingEnable the Agents to carry out the tasks and actions configured by the Client; provide, maintain, and secure the Service; provide Client support; manage billing and subscriptions.
Duration of processingDuration of the services contract, plus the return or deletion periods provided for in this Agreement and the retention periods required by law.
Type of personal dataIdentification and contact data (first name, last name, email address, job title); connection and usage data (credentials, technical logs, IP addresses); billing data (managed via the payment provider); any personal data contained in the Client Content freely submitted to the Agents by the Client. The Client is advised not to submit special categories of data (Article 9 of the GDPR) without an appropriate legal basis, and to minimize the data submitted.
Categories of data subjectsCustomer Users and representatives; the Customer's clients, prospects, suppliers, and partners; any individual whose data appears in the Customer Content submitted to the Agents.
Obligations and rights of the ControllerThe Controller determines the purposes and means of processing, guarantees the lawfulness of the processing and its legal basis, informs the data subjects, exercises a right of instruction, control and audit over the Processor, and decides on the fate of the data at the end of the processing.

19. Appendix 2 — Technical and organizational security measures

The Processor implements the following technical and organizational measures, in accordance with Article 32 of the GDPR. These measures may evolve, without any reduction in the level of security.

EncryptionEncryption of data in transit (TLS protocols) and, where applicable, encryption of data at rest.
Access controlManagement of access rights according to the principle of least privilege and need-to-know; user authentication; segregation of administrator access.
PrivacyConfidentiality commitment from persons authorized to process the data; awareness-raising and training on data protection.
Integrity and availabilityMeasures to ensure data integrity and system resilience; redundancy and backups provided at the hosting infrastructure level.
Continuity and restorationBackup and restoration procedures enabling the availability of and access to data to be restored within appropriate timeframes in the event of an incident.
Partitioning and isolationLogical separation of data between clients (multi-tenant) to prevent any unauthorized access by one client to another client's data.
LoggingMaintaining technical logs enabling traceability of access and sensitive operations, in compliance with data minimization principles.
Incident managementProcedure for the detection, assessment, handling and notification of personal data breaches.
Security of sub-processorsSelection of providers offering sufficient guarantees; contractual arrangements imposing equivalent data protection obligations.
AssessmentProcedures for regularly testing, assessing and evaluating the effectiveness of the security measures implemented.

The Controller remains responsible for the security measures within its own sphere, in particular the management of its credentials and the security of its own systems.

20. Appendix 3 — List of authorized sub-processors

The Controller authorizes recourse to the following sub-processors, as of the date of this Agreement. Any modification to this list shall be notified to the Controller in advance, who has a right to object under the conditions set out in this Agreement.

Sub-processorPurposeLocationTransfer safeguards
Railway CorporationHosting of the Service infrastructureUnited StatesStandard Contractual Clauses (SCCs)
Anthropic, PBCProvision of the Claude artificial intelligence modelUnited StatesStandard Contractual Clauses (SCCs)
Google Ireland Limited / Google LLCProvision of the Gemini artificial intelligence model (optional)European Union / United StatesStandard Contractual Clauses (SCCs)
Stripe Payments Europe, LimitedProcessing of payments and billingEuropean Union / United StatesStandard Contractual Clauses (SCCs)

For any additional information regarding sub-processors and the safeguards governing transfers, the Controller may send a request by post to the Processor's registered office. A dedicated contact email address will be activated as soon as the domain is opened and published here.

SecurityLegal NoticePrivacyCookiesTerms of UseTerms of SaleDPA Manage my cookies

© 2026 MARA LABS — nullbot. All rights reserved. Société par actions simplifiée (SAS) au capital de 100 € · 104 321 104