Skip to main content
Marchant
πŸ‡¬πŸ‡§β–Ύ

Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Appslab Ltd (trading as Marchant) and the Customer for use of the Marchant platform. It satisfies the requirements of Article 28 GDPR / UK GDPR.

Last updated: 15 August 2026

Article 28 GDPR

GDPR & UK GDPR compliant

AES-256 encrypted

At rest & in transit

72-hour breach notice

Within 72 hours where feasible

1

Definitions

"Controller" means the Customer. "Processor" means Appslab Ltd trading as Marchant. "Personal Data", "Data Subject", "Processing", "Supervisory Authority" have the meanings given in the GDPR.

2

Processing details

Subject matter
Provision of cloud accounting and finance management services via the Marchant platform.
Duration
For the term of the Customer's subscription plus any statutory retention period thereafter.
Nature and purpose
Storage, organisation, retrieval, and transmission of financial records, invoices, expense data, payroll records, and tax-related data to enable the Customer to manage their business finances.
Types of personal data
Contact details (name, email, address), financial transaction data, payroll and employment data, bank account details, VAT registration numbers, tax file references.
Categories of data subjects
Customer's employees, contractors, clients, suppliers, and other individuals whose data the Customer uploads to the platform.
3

Processor obligations

  • Process Personal Data only on documented instructions from the Controller (including those set out in this DPA and the Terms of Service), unless required to do so by applicable law.
  • Ensure persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
  • Implement and maintain appropriate technical and organisational security measures as set out in Section 6 below.
  • Not engage a sub-processor without prior written authorisation from the Controller (a general authorisation is given via acceptance of this DPA for the sub-processors listed in the Annex).
  • Assist the Controller in fulfilling its obligations to respond to data subject requests under Chapter III of the GDPR.
  • Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIA, prior consultation).
  • Delete or return all Personal Data upon termination of the agreement, and delete existing copies unless applicable law requires storage.
  • Make available all information necessary to demonstrate compliance and allow for and contribute to audits.
4

Sub-processors

The Controller grants general authorisation for the Processor to engage the following sub-processors. The Processor shall publish any intended changes to this list on this page at least 14 days before they take effect, giving the Controller the opportunity to object. Website analytics is not listed above. Vercel Analytics β€” and Google Analytics and Microsoft Clarity where enabled β€” relate to visitors to Marchant’s own website, which Marchant processes as a controller in its own right, not as Processor on the Controller’s Personal Data; that processing is described in the Cookie Policy.

ClerkUSA (SCC)

Authentication & user management

SupabaseEU (Stockholm)

Database hosting

StripeUSA (SCC)

Payment processing

GoCardlessUK / EU

Direct debit payments

TrueLayerUK / EU

Open banking connections

VercelUSA (SCC)

Web hosting

SentryUSA (SCC)

Error monitoring and session replay

ResendUSA (SCC)

Transactional email

OpenAIUSA (SCC)

Receipt & invoice OCR extraction

AnthropicUSA (SCC)

AI financial insights

PayPalUSA (SCC)

Payment processing

BrightPayUK / EU

UK payroll sync

CrispEU (France)

Live chat support

CalendlyUSA (SCC)

Demo scheduling (where enabled)

5

Data subject rights

The Processor will provide reasonable assistance to enable the Controller to fulfil data subject requests (access, rectification, erasure, portability, restriction, objection) within the timescales required by applicable law. The Processor will forward any data subject request it receives directly from a data subject to the Controller without undue delay.

6

Security measures

The Processor maintains the following technical and organisational security measures:

Encryption of data at rest (AES-256) and in transit (TLS 1.2+).
Role-based access controls and principle of least privilege for all staff.
Regular automated backups of the production database.
Application error and performance monitoring (Sentry, listed in Section 4).
Infrastructure provided by the sub-processors listed in Section 4, each of which maintains its own independent security certifications.
Independent security certification of the Marchant platform itself is on the roadmap; Marchant does not currently hold a SOC 2 or ISO 27001 report.
7

Data breach notification

72h

Maximum notice window

In the event of a Personal Data breach, the Processor will notify the Controller without undue delay and in any event within 72 hours of becoming aware of the breach (insofar as this is feasible). Notification will include the information required under Article 33(3) GDPR to the extent available at the time.

8

International data transfers

Where Personal Data is transferred to a country outside the UK or EEA that does not benefit from an adequacy decision, the transfer will be made on the basis of Standard Contractual Clauses (UK Addendum / EU SCCs) or another lawful transfer mechanism.

9

Audit rights

The Controller may, upon reasonable prior written notice of at least 30 days and no more than once per calendar year, conduct an audit of the Processor's processing activities covered by this DPA. The Processor may satisfy this right by providing documentation of the technical and organisational measures set out in Section 6, together with any independent audit report it holds at the time of the request.

10

Term and termination

This DPA is co-terminus with the agreement between the parties. Upon termination, the Processor will, at the Controller's election, delete or return all Personal Data within 90 days, unless applicable law requires the Processor to retain the data.

11

Governing law

This DPA is governed by the laws of England and Wales. The parties submit to the exclusive jurisdiction of the courts of England and Wales, subject to mandatory data protection laws in the Controller's jurisdiction.

Contact

For questions about this DPA or to exercise audit rights, contact us at privacy@getmarchant.com.