Legal document
Data Processing Addendum
If your studio, label, or organisation needs Article 28 processor terms on file, these are ours. Read the first section first — for most users of our software, we are not your processor at all, and this document does not apply.
Last updated 27 August 2026 · Governed by the laws of England and Wales
01When this actually applies
To be specific about the three situations:
- Using DAWN or MeterStack — this DPA does not apply
- Our software sends us nothing. There is no server, no account, and no telemetry in the shipped build. We process no personal data on your behalf, so there is nothing for a processor agreement to govern. Data you send to your own AI provider is governed by your agreement with them, not with us.
- Your staff contacting us or downloading — we are a controller, not a processor
- When someone from your organisation emails support or downloads our software, we handle their details as a controller in our own right, under the Privacy Policy. A DPA is not the right instrument for that either.
- A specific engagement where we handle your data — this DPA applies
- For example, if we take a project file containing personal data to diagnose a fault, or if we agree paid work involving your material. Here we act on your instructions and these terms apply.
We would rather tell you this than hand over a document that implies a relationship that does not exist. If your procurement process needs a DPA on file regardless, this one is genuine and we will sign it.
02Parties and scope
This Addendum is between you ("Controller") and Marya Labs ("Processor"). It forms part of the Terms of Service and applies where we process personal data on your behalf.
It is made under Article 28 of the UK GDPR. Terms such as "personal data", "processing", "data subject", and "personal data breach" carry their UK GDPR meanings.
Where this Addendum conflicts with any other agreement between us on data protection, this Addendum prevails.
03Details of processing
| Item | Detail |
|---|---|
| Subject matter | Providing support, diagnostics, or agreed services to the Controller |
| Duration | For as long as needed for the agreed purpose, subject to the retention terms below |
| Nature and purpose | Storage, review, and analysis strictly for the agreed purpose |
| Types of personal data | Typically contact details and any personal data incidentally contained in material you send us, such as names inside a project file |
| Categories of data subject | Your staff, contractors, and collaborators |
| Special category data | None. Please do not send us special category data. If you must, tell us in advance so we can agree appropriate measures. |
04Our obligations
We will:
- Process personal data only on your documented instructions, unless required otherwise by law — in which case we will tell you first, unless the law prevents us.
- Ensure anyone we authorise to process the data is bound by confidentiality.
- Implement appropriate technical and organisational measures, as described in the Security Overview.
- Not engage another processor without your general written authorisation. Our current sub-processors are listed on the Sub-processors page; we will update it before adding one, and you may object on reasonable data protection grounds.
- Assist you, so far as we reasonably can, in responding to data subject requests under Articles 12–23.
- Assist you with your obligations under Articles 32–36, including security, breach notification, and impact assessments.
- Notify you without undue delay, and in any event within 48 hours, on becoming aware of a personal data breach affecting your data, with the information we have.
- Delete or return the data at the end of the engagement, as you choose, except where we must retain it by law.
- Make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits.
05Your obligations
- You are responsible for the lawfulness of the data you give us, including having a lawful basis and having given the necessary privacy information to the people concerned.
- Your instructions to us must comply with data protection law.
- Send us only the personal data actually needed for the purpose. If a project file can be anonymised before you send it for diagnosis, please anonymise it.
06Retention and deletion
Material you send us for a specific purpose is deleted once that purpose is complete. Support correspondence follows the standard schedule in the Privacy Policy — currently 2 years.
You can ask us to delete anything sooner at any time, and we will unless we are legally required to keep it.
07International transfers
Where personal data is transferred outside the UK, we rely on UK adequacy regulations or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Our infrastructure providers are currently in the EU / EEA.
08Liability and execution
Liability under this Addendum is subject to the limits in the Terms of Service and the Disclaimer, except where data protection law does not permit limitation.
This Addendum is governed by the laws of England and Wales. If you need a countersigned copy for your records, email support@maryalabs.io and we will arrange it.