Legal information

Data Processing and DPA

MarketBase’s position as controller or potential processor and the technical services actually identified in the repository.

Last updated: September 30, 2026

1. Status of this document

This page is not automatically a signed Data Processing Addendum. In the current product, MarketBase mainly determines the purposes of accounts, benchmarks, publication and security, so it generally acts as controller for those operations.

A separate DPA may be needed where a customer documents a relationship in which MarketBase processes personal data only on the customer’s instructions, for a defined purpose and without its own reuse. No customer-specific signing workflow or processor register was found in the repository.

2. Subject matter and duration

Where a DPA is entered into, it should cover the processing needed for the subscribed service during the contract and the time strictly necessary for return, deletion or legal retention. Technical retention periods are not automated in the current implementation and must be set by contract and configuration.

3. Nature and purposes

  • host an account, organisation, project, domain and related content;
  • run an authorised GSC or Stripe synchronisation;
  • calculate metrics, rankings, comparisons and reports;
  • provide security, rate limiting, technical logging and job recovery;
  • make a profile public only within the scope selected and exposed by the public layer.

4. Data and data-subject categories

Depending on the project and documented instructions, data may include account identifiers, professional contact details, business content, hostname, SEO data, aggregated financial metrics, technical identifiers, logs and consent information. Data subjects may include Users, organisation members, business representatives, customers or subscribers indirectly represented in Stripe counts. The repository does not import complete Stripe customer contact details into metric tables.

5. Instructions and confidentiality

Processing on behalf of a customer must be based on documented and lawful instructions. People authorised to access data must be subject to appropriate confidentiality duties. The observed routes restrict access by organisation and project.

6. Security

Observed measures include AES-256-GCM token encryption, HTTP-only cookies, signed and temporary OAuth state, access controls, input validation, PostgreSQL rate limiting, webhook signature verification, separation of public and private data, security headers and SSRF protection for the crawler. Measures are reviewed according to risk and are not a certification.

7. Observed subprocessors and services

ServiceUseData potentially sentStatus
GoogleSign-in and Search ConsoleIdentity, authorisation and requested SEO dataActive when configured
StripeCheckout, webhooks and ConnectTechnical payment data and authorised account signalsActive when configured
OpenAIProject classificationName and description; no GSC queries after the fixActive in live mode
PostgreSQL / VPSDatabase and workerPersisted data and logsExact host to be confirmed
CloudflareProxy/DNS according to deploymentNetwork requests and possible security dataOperator configuration to be confirmed
ResendTransactional emailRecipient and template data if calledAdapter present; call not observed

8. Assistance, incidents and audits

Cooperation for data-subject requests, incidents and security information should be organised by contract. The repository stores job errors and Stripe events but does not provide a complete breach-notification, customer-audit or export workflow.

9. International transfers

The regions and contractual safeguards for Google, Stripe, OpenAI, Cloudflare, Resend and the VPS are not determined by the repository. A DPA must identify transfers, countries or regions and the legal mechanism used.

10. End of contract, return and deletion

At the end of service, data should be returned, deleted or anonymised according to instructions and applicable duties. The current implementation has no deletion button, GSC/Stripe revocation flow or automatic purge; no immediate or absolute deletion promise should be read into this page.

11. Allocation of responsibilities

The customer remains responsible for the lawfulness of submitted data and instructions. MarketBase remains responsible for its own purposes, application and processing it determines. Google and Stripe apply their own terms and may act as independent controllers for their services. The final qualification depends on the concrete processing and contract.

12. DPA request

To assess a controller/processor relationship or request an addendum, email [email protected] with the product, data categories, data subjects, countries and proposed instructions.

For a question about this document or your data, email [email protected].