Legal information
Data Processing and DPA
MarketBase’s position as controller or potential processor and the technical services actually identified in the repository.
Last updated: September 30, 2026
1. Status of this document
This page is not automatically a signed Data Processing Addendum. In the current product, MarketBase mainly determines the purposes of accounts, benchmarks, publication and security, so it generally acts as controller for those operations.
A separate DPA may be needed where a customer documents a relationship in which MarketBase processes personal data only on the customer’s instructions, for a defined purpose and without its own reuse. No customer-specific signing workflow or processor register was found in the repository.
2. Subject matter and duration
Where a DPA is entered into, it should cover the processing needed for the subscribed service during the contract and the time strictly necessary for return, deletion or legal retention. Technical retention periods are not automated in the current implementation and must be set by contract and configuration.
3. Nature and purposes
- host an account, organisation, project, domain and related content;
- run an authorised GSC or Stripe synchronisation;
- calculate metrics, rankings, comparisons and reports;
- provide security, rate limiting, technical logging and job recovery;
- make a profile public only within the scope selected and exposed by the public layer.
4. Data and data-subject categories
Depending on the project and documented instructions, data may include account identifiers, professional contact details, business content, hostname, SEO data, aggregated financial metrics, technical identifiers, logs and consent information. Data subjects may include Users, organisation members, business representatives, customers or subscribers indirectly represented in Stripe counts. The repository does not import complete Stripe customer contact details into metric tables.
5. Instructions and confidentiality
Processing on behalf of a customer must be based on documented and lawful instructions. People authorised to access data must be subject to appropriate confidentiality duties. The observed routes restrict access by organisation and project.
6. Security
Observed measures include AES-256-GCM token encryption, HTTP-only cookies, signed and temporary OAuth state, access controls, input validation, PostgreSQL rate limiting, webhook signature verification, separation of public and private data, security headers and SSRF protection for the crawler. Measures are reviewed according to risk and are not a certification.
7. Observed subprocessors and services
| Service | Use | Data potentially sent | Status |
|---|---|---|---|
| Sign-in and Search Console | Identity, authorisation and requested SEO data | Active when configured | |
| Stripe | Checkout, webhooks and Connect | Technical payment data and authorised account signals | Active when configured |
| OpenAI | Project classification | Name and description; no GSC queries after the fix | Active in live mode |
| PostgreSQL / VPS | Database and worker | Persisted data and logs | Exact host to be confirmed |
| Cloudflare | Proxy/DNS according to deployment | Network requests and possible security data | Operator configuration to be confirmed |
| Resend | Transactional email | Recipient and template data if called | Adapter present; call not observed |
8. Assistance, incidents and audits
Cooperation for data-subject requests, incidents and security information should be organised by contract. The repository stores job errors and Stripe events but does not provide a complete breach-notification, customer-audit or export workflow.
9. International transfers
The regions and contractual safeguards for Google, Stripe, OpenAI, Cloudflare, Resend and the VPS are not determined by the repository. A DPA must identify transfers, countries or regions and the legal mechanism used.
10. End of contract, return and deletion
At the end of service, data should be returned, deleted or anonymised according to instructions and applicable duties. The current implementation has no deletion button, GSC/Stripe revocation flow or automatic purge; no immediate or absolute deletion promise should be read into this page.
11. Allocation of responsibilities
The customer remains responsible for the lawfulness of submitted data and instructions. MarketBase remains responsible for its own purposes, application and processing it determines. Google and Stripe apply their own terms and may act as independent controllers for their services. The final qualification depends on the concrete processing and contract.
12. DPA request
To assess a controller/processor relationship or request an addendum, email [email protected] with the product, data categories, data subjects, countries and proposed instructions.
For a question about this document or your data, email [email protected].