Marya Labs / Legal

Legal document

Data Processing Addendum

If your studio, label, or organisation needs Article 28 processor terms on file, these are ours. Read the first section first — for most users of our software, we are not your processor at all, and this document does not apply.

Last updated 27 August 2026 · Governed by the laws of England and Wales

Contents

  1. 01When this actually applies
  2. 02Parties and scope
  3. 03Details of processing
  4. 04Our obligations
  5. 05Your obligations
  6. 06Retention and deletion
  7. 07International transfers
  8. 08Liability and execution

01When this actually applies

Read this before adopting this document

A DPA is only meaningful where we process personal data on your behalf. In most of what we do, we do not.

To be specific about the three situations:

Using DAWN or MeterStack — this DPA does not apply
Our software sends us nothing. There is no server, no account, and no telemetry in the shipped build. We process no personal data on your behalf, so there is nothing for a processor agreement to govern. Data you send to your own AI provider is governed by your agreement with them, not with us.
Your staff contacting us or downloading — we are a controller, not a processor
When someone from your organisation emails support or downloads our software, we handle their details as a controller in our own right, under the Privacy Policy. A DPA is not the right instrument for that either.
A specific engagement where we handle your data — this DPA applies
For example, if we take a project file containing personal data to diagnose a fault, or if we agree paid work involving your material. Here we act on your instructions and these terms apply.

We would rather tell you this than hand over a document that implies a relationship that does not exist. If your procurement process needs a DPA on file regardless, this one is genuine and we will sign it.

02Parties and scope

This Addendum is between you ("Controller") and Marya Labs ("Processor"). It forms part of the Terms of Service and applies where we process personal data on your behalf.

It is made under Article 28 of the UK GDPR. Terms such as "personal data", "processing", "data subject", and "personal data breach" carry their UK GDPR meanings.

Where this Addendum conflicts with any other agreement between us on data protection, this Addendum prevails.

03Details of processing

ItemDetail
Subject matterProviding support, diagnostics, or agreed services to the Controller
DurationFor as long as needed for the agreed purpose, subject to the retention terms below
Nature and purposeStorage, review, and analysis strictly for the agreed purpose
Types of personal dataTypically contact details and any personal data incidentally contained in material you send us, such as names inside a project file
Categories of data subjectYour staff, contractors, and collaborators
Special category dataNone. Please do not send us special category data. If you must, tell us in advance so we can agree appropriate measures.

04Our obligations

We will:

  1. Process personal data only on your documented instructions, unless required otherwise by law — in which case we will tell you first, unless the law prevents us.
  2. Ensure anyone we authorise to process the data is bound by confidentiality.
  3. Implement appropriate technical and organisational measures, as described in the Security Overview.
  4. Not engage another processor without your general written authorisation. Our current sub-processors are listed on the Sub-processors page; we will update it before adding one, and you may object on reasonable data protection grounds.
  5. Assist you, so far as we reasonably can, in responding to data subject requests under Articles 12–23.
  6. Assist you with your obligations under Articles 32–36, including security, breach notification, and impact assessments.
  7. Notify you without undue delay, and in any event within 48 hours, on becoming aware of a personal data breach affecting your data, with the information we have.
  8. Delete or return the data at the end of the engagement, as you choose, except where we must retain it by law.
  9. Make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits.

On audits, honestly

We are a very small studio. We will answer a security questionnaire, provide documentation, and discuss our practices with you in good faith. We do not hold ISO 27001, SOC 2, or any other certification, and we are not going to claim readiness for an on-site audit programme we could not support. If your compliance process requires certification, we are not currently able to meet that.

05Your obligations

  • You are responsible for the lawfulness of the data you give us, including having a lawful basis and having given the necessary privacy information to the people concerned.
  • Your instructions to us must comply with data protection law.
  • Send us only the personal data actually needed for the purpose. If a project file can be anonymised before you send it for diagnosis, please anonymise it.

06Retention and deletion

Material you send us for a specific purpose is deleted once that purpose is complete. Support correspondence follows the standard schedule in the Privacy Policy — currently 2 years.

You can ask us to delete anything sooner at any time, and we will unless we are legally required to keep it.

07International transfers

Where personal data is transferred outside the UK, we rely on UK adequacy regulations or on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Our infrastructure providers are currently in the EU / EEA.

08Liability and execution

Liability under this Addendum is subject to the limits in the Terms of Service and the Disclaimer, except where data protection law does not permit limitation.

This Addendum is governed by the laws of England and Wales. If you need a countersigned copy for your records, email support@maryalabs.io and we will arrange it.

Questions about this document? Email support@maryalabs.io.

See all documents in the legal index.

ML / DAWN · SYSTEM FOOTER NETWORK STABLE
Primary system

DAWN BY MARYA LABS

A first-of-its-kind AU/VST3 plugin with an AI agent inside it. It works Ableton Live and your Mac for you, while you keep the creative call.

Public beta · AU / VST3 · macOS
Explore
  • Capabilities↗
  • Provider Ecosystem↗
  • Autonomy & Trust↗
  • Provider Choice↗
  • DAWN Changelog↗
  • MeterStack Page↗
Access
  • Download DAWN↗
  • Download MeterStack↗
  • Support↗
  • support@maryalabs.io↗

Subscribe

Quiet DAWN beta notes and important release updates.

We use your address only to send these updates. Unsubscribe any time. See our Privacy Policy.

© 2026 Marya Labs
Terms·DAWN EULA·Privacy·Cookies·All legal
DAWN · An AI agent in your plugin slot.