Data Processing Agreement
Last updated: June 22, 2026
This Data Processing Agreement (DPA) describes how Markly processes personal data on behalf of business customers when they use the platform.
Markly is in a pilot phase. This DPA describes our current approach and will be formalized as our product and legal structure mature.
Roles of the parties
The business owner (our customer) is the data controller for the personal data of its own customers and staff. Markly acts as the data processor for that data.
Markly is an independent controller for account, billing, and platform-operations data that we collect directly from business users.
Purpose and duration of processing
Markly processes personal data to provide the booking and business-management platform, for the duration of the customer's use of the service.
Categories of data subjects
- The business's customers.
- The business's staff members.
- The business owner and authorized users.
Categories of personal data
- Names and contact details (email and phone).
- Appointment details, intake answers, and notes.
- Calendar availability and event data for connected calendars.
- AI conversation content and stored AI summaries.
- Communication and message logs.
- Limited technical and diagnostic data.
Processing instructions
Markly processes personal data in accordance with the customer's use of the product and documented instructions, and as needed to provide and secure the service.
Subprocessors
Markly uses the subprocessors listed on the Subprocessors page to operate the platform. The customer authorizes the use of these subprocessors, and Markly remains responsible for their performance of data-processing obligations.
Security commitments
Markly maintains the technical and organizational measures described on the Security page, appropriate to the pilot stage of the product.
Assistance obligations
Taking into account the nature of processing, Markly will provide reasonable assistance to the customer in responding to data-subject requests and in relation to security incidents.
Deletion and return of data
Upon termination, Markly will delete or return personal data within a reasonable period, subject to legal and operational retention requirements. Businesses can also edit or remove much of the data they enter within the product.
International transfers
Subprocessors may process data in different countries in accordance with their applicable legal and contractual obligations.
No certifications
Markly does not currently hold SOC 2, ISO 27001, HIPAA, or similar certifications, and this DPA does not represent any such certification.
Contact
For DPA inquiries, contact imark3020@gmail.com.