Legal

Data Processing Agreement

Last updated: July 9, 2026 · Effective: July 9, 2026

1. Purpose and Roles

This Data Processing Agreement (“DPA”) supplements the Marech Terms of Service between Marech (“Processor”, “we”) and the customer using the Service (“Customer”, “you”). It applies whenever Marechprocesses personal data of Customer’s website visitors on Customer’s behalf while providing bot detection and blocking.

For that visitor data, Customer is the data controller and Marech is the data processor, acting only on Customer’s documented instructions (this DPA, the Terms, and Customer’s dashboard configuration, e.g. policies). This DPA does not cover Marech’s processing of Customer’s own account and billing data, where Marech acts as controller — see the Privacy Policy.

2. Incorporation and Precedence

This DPA is incorporated into and forms part of the Terms of Service for Customers on a paid or trial plan. If you require a countersigned copy for procurement purposes, email mohamed@muhsinai.com. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls.

3. Subject Matter and Details of Processing (GDPR Art. 28(3))

Subject matter

Detection and blocking of automated bot / AI-scraper traffic on Customer’s website.

Duration

For as long as Customer maintains an active account with Marech (i.e. the term of the Terms of Service), and until deletion per Section 9 below.

Nature and purpose

Real-time analysis of individual HTTP requests to classify likely bot traffic, enforcement of Customer’s configured policies (allow / block / log), and generation of the traffic logs and analytics shown on Customer’s dashboard.

Categories of data subjects

Visitors to Customer’s website (including human visitors, and automated clients/bots).

Categories of personal data

IP address, User-Agent string, requested URL path, request timestamp, and the limited set of HTTP headers used for bot-signal scoring (e.g. Accept-Language, Accept-Encoding, Connection). No special-category data is intentionally processed.

4. Processor Obligations

Marech shall:

  • Process personal data only on Customer’s documented instructions (including as set via the dashboard), unless required otherwise by law, in which case Marech will inform Customer unless legally prohibited from doing so;
  • Ensure personnel authorized to process the data are bound by confidentiality obligations;
  • Implement the technical and organizational measures described in Section 7;
  • Not engage a sub-processor without authorization as described in Section 5;
  • Assist Customer, taking into account the nature of the processing, in responding to data subject requests (Section 6) and in meeting Customer’s obligations regarding security, breach notification, and data protection impact assessments, to the extent Marech has relevant information;
  • At Customer’s choice, delete or return personal data at the end of the engagement (Section 9);
  • Make available information reasonably necessary to demonstrate compliance with this Section, and allow for audits as described in Section 8.

5. Sub-processors

Customer authorizes Marech to engage the following sub-processors, each engaged under a written agreement imposing data protection obligations materially equivalent to this DPA:

  • Amazon Web Services (AWS) — cloud hosting & database (United States)
  • Vercel — hosting for the marketing site and customer dashboard (United States)
  • Stripe — payment processing
  • Google — “Sign in with Google” authentication, where Customer’s account uses it
  • Resend — transactional email delivery

Marech will notify Customer of any new sub-processor materially involved in processing visitor data (e.g. via email or an in-app notice) before granting it access, giving Customer an opportunity to object on reasonable data-protection grounds.

6. Data Subject Rights

Marech will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures in fulfilling requests from data subjects to exercise their rights under applicable law. Because Marechdoes not have a direct relationship with Customer’s website visitors, Marech will forward any such request it receives directly to Customer and will not respond to the data subject except to do so, unless legally required.

7. Technical and Organizational Measures

Marech implements the security measures described in the Privacy Policy, including:

  • Encryption in transit (TLS) and industry-standard hashing of passwords, API keys, and verification tokens (never stored in plaintext)
  • Access controls limiting who can reach production systems and data
  • Rate limiting and abuse protections on the API
  • Security response headers and regular review of dependencies and configuration

See the Privacy Policy, Security section, for the current, authoritative description — this DPA does not duplicate it so the two documents cannot drift out of sync.

8. Audits

Marech will make available information reasonably necessary to demonstrate compliance with this DPA (e.g. summaries of security practices) upon written request, no more than once per 12-month period absent a security incident or regulatory requirement, subject to reasonable confidentiality restrictions and advance notice.

9. Deletion or Return of Data

Marechholds Customer’s account data and visitor traffic logs for as long as Customer maintains an active account — there is no separate fixed retention period for traffic logs. Upon termination of the underlying subscription or deletion of Customer’s account, Marech deletes that data at that time, unless applicable law requires retention of specific records (e.g. billing records). Customer may request deletion at any time via the dashboard or by emailing mohamed@muhsinai.com.

10. International Transfers

Marechand its sub-processors listed in Section 5 are located in, and process personal data in, the United States. Where this DPA covers a transfer of personal data originating in the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of data protection, the parties incorporate by reference the European Commission’s Standard Contractual Clauses (Module Two: Controller to Processor), Annex to Implementing Decision (EU) 2021/914 (“SCCs”), available at eur-lex.europa.eu/eli/dec_impl/2021/914, with:

  • Annex I.A/B (parties & description of transfer) as set out in Section 3 above and Customer’s account details;
  • Annex II (technical and organizational measures) as set out in Section 7 above;
  • the UK Addendum to the SCCs issued by the UK Information Commissioner, where the transfer originates in the UK.

Marech separately relies on the SCCs (or equivalent transfer mechanisms) that AWS, Stripe, and Google have in place as part of their own standard terms, as the basis for onward transfer to those sub-processors.

11. Liability

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

12. Contact

Questions about this DPA, or to request a countersigned copy: mohamed@muhsinai.com