Data Processing Agreement

Last updated: 30 August 2026

Controller-processor terms incorporated into the Marklet Terms and Conditions. Effective: 22 August 2026. This Data Processing Agreement (DPA) forms part of the agreement between Levered AI Ltd trading as Marklet and the Customer. It applies whenever Marklet processes Customer Personal Data as processor or sub-processor.

1. Parties and effect

(a) The Processor is Levered AI Ltd (company number 17149630), trading as Marklet, of 167-169 Great Portland Street, 5th Floor, London, W1W 5PF.

(b) The Customer identified in the Order is the Controller where it determines the purposes and means of processing Customer Personal Data.

(c) Where the Customer is itself a processor acting for an RMC, RTM company or other controller, Marklet is a Sub-processor and references to Controller obligations include the Customer's obligation to pass instructions and protections through the processing chain.

(d) This DPA becomes binding when the Customer accepts the Marklet Terms, signs or accepts an Order that incorporates them, begins using an evaluation account, or continues to use the Service after receiving this DPA. It applies to Customer Personal Data processed during evaluation use as well as under a free or paid Plan. A countersigned copy may be requested.

(e) If this DPA conflicts with the Terms concerning Customer Personal Data, this DPA prevails. The Order prevails only where it expressly identifies a provision of this DPA to be varied and the variation complies with Data Protection Law.

2. Definitions

Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Category Data and Supervisory Authority have the meanings in Data Protection Law. Customer Personal Data means Personal Data contained in Customer Data that Marklet processes for the Customer. Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications (EC Directive) Regulations 2003 and other UK law applying to the processing, each as amended including by the Data (Use and Access) Act 2025. Sub-processor means another processor appointed by Marklet to process Customer Personal Data. Terms means the Marklet Terms and Conditions; Order and Business Day have the meanings given in the Terms.

3. Scope and processing details

The subject matter, duration, nature and purpose of processing, types of Personal Data and categories of Data Subject are set out in Schedule 1. The technical and organisational measures are set out in Schedule 2. Authorised Sub-processors are listed in Schedule 3 or in the current list notified by Marklet.

4. Customer obligations and authority

(a) The Customer must comply with Data Protection Law and is responsible for the lawfulness, fairness and transparency of the processing; the accuracy and minimisation of Customer Personal Data; lawful instructions; Data Subject requests; retention decisions; role and permission settings; and any required records, assessments and consultations.

(b) The Customer warrants that it has all notices, lawful bases, Article 9 conditions, consents and authority required to provide Customer Personal Data and instruct Marklet.

(c) A managing agent or other processor warrants that the relevant Controller has authorised its instructions and Marklet's appointment as Sub-processor, and that its contract permits it to impose this DPA.

(d) The Customer must not instruct Marklet to process unlawfully. If Marklet believes an instruction infringes Data Protection Law, it will inform the Customer unless law prohibits that information, and may suspend the affected processing pending clarification.

(e) The Customer determines who may receive a handover export and is responsible for verifying the recipient, lawful disclosure, transparency, security and the recipient's controller or processor arrangements.

5. Documented instructions

(a) Marklet will process Customer Personal Data only on documented instructions from the Customer, including for transfers, unless UK law requires processing. If so, Marklet will inform the Customer before processing unless that law prohibits it on important grounds of public interest.

(b) The Terms, Order, this DPA, the Customer's configuration and authenticated use of features constitute documented instructions.

(c) Instructions outside the agreed Service require prior written agreement and may be subject to reasonable charges.

(d) Marklet may process aggregated or anonymised information that no longer identifies a Data Subject or Customer, provided the anonymisation is not reversed.

6. Personnel and confidentiality

Marklet will ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, receive access only where needed for their functions and are informed of relevant data-protection and security responsibilities. Access will be withdrawn when no longer required.

7. Security

(a) Taking account of the state of the art, implementation cost, nature, scope, context and purposes of processing and risks to individuals, Marklet will maintain appropriate technical and organisational measures under Article 32, including the measures in Schedule 2.

(b) Marklet may update measures to reflect risk and technology, provided the overall level of protection is not materially reduced.

(c) The Customer is responsible for secure configuration of permissions, users, integrations and endpoints under its control and for assessing whether the Service is appropriate for its processing.

(d) Marklet achieved Cyber Essentials certification at the basic tier on 4 August 2026. Marklet does not represent that it holds Cyber Essentials Plus, has commissioned third-party penetration testing or has undergone an accredited security audit.

8. Administrator access and resident fire-safety documents

(a) Authorised Marklet administrators may access Customer Personal Data where reasonably necessary for support, maintenance, security, incident response or compliance, subject to role controls, confidentiality and logging.

(b) Resident fire-safety documents in the designated category are excluded from ordinary administrator access, search, comments, flat association and AI features. The uploader's filename is replaced with a generated non-identifying name.

(c) Exceptional access to that category requires a break-glass grant limited to one named administrator, one building, one written reason and 15 minutes. The grant and access are recorded in the Customer's audit trail; expired grant records may be retained as security evidence.

9. Sub-processors

(a) The Customer gives general written authorisation for Marklet to use the Sub-processors in Schedule 3 and to appoint replacements.

(b) Marklet will enter a written contract with each Sub-processor imposing data-protection obligations no less protective in substance than those required by Article 28, so far as relevant to the services.

(c) Marklet remains responsible to the Customer for performance of the Sub-processor's obligations to the extent required by Data Protection Law and this DPA.

(d) Marklet will give at least 30 days' notice before a new Sub-processor begins material processing, except where an urgent change is reasonably necessary for security, continuity or law, in which case notice will be given as soon as practicable.

(e) The Customer may object within 15 days on reasonable data-protection grounds, explaining the concern. The parties will work in good faith on a reasonable solution. If none is available, either party may terminate the affected feature or Service on written notice, and Marklet will refund prepaid charges for the unused terminated period.

(f) A third-party accounting or other service selected and engaged directly by the Customer is not a Sub-processor appointed by Marklet merely because the Customer connects that service to Marklet. Its role and obligations are governed by its arrangement with the Customer. Marklet remains responsible for processing Customer Personal Data after it is received into Marklet's systems.

10. International transfers

(a) Marklet will not make a restricted transfer of Customer Personal Data except on the Customer's instructions and using a lawful transfer mechanism.

(b) Where no adequacy regulation applies, Marklet will use an appropriate safeguard, which may include the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, and will complete a transfer risk assessment and adopt supplementary measures where required.

(c) Where a Sub-processor's standard lawful mechanism changes, the replacement recognised under Data Protection Law will apply, provided protection is not materially reduced.

(d) On request, Marklet will provide information reasonably necessary for the Customer to understand the applicable mechanism, subject to confidentiality and permitted redactions.

11. Data Subject requests

(a) Taking account of the nature of processing, Marklet will provide reasonable technical and organisational assistance for the Customer to respond to requests to exercise Data Subject rights.

(b) If Marklet receives a request concerning Customer Personal Data, it will refer the requester to the Customer or forward the request and will not respond substantively unless instructed or legally required.

(c) The Customer should provide sufficient details and use available account, search, correction, export and deletion functions before requesting manual assistance.

(d) Marklet will aim to acknowledge a complete assistance request within five Business Days. Statutory deadlines remain the Customer's responsibility.

12. Personal Data Breaches

(a) Marklet will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where reasonably practicable, within 48 hours.

(b) The notice will include information reasonably available concerning the nature of the breach, affected data and people, likely consequences, measures taken or proposed, and a contact point. Information may be supplied in phases.

(c) Marklet will take reasonable steps to contain, investigate and mitigate the breach and preserve relevant evidence.

(d) The Customer is responsible for deciding whether and how to notify the ICO, Data Subjects or others. Marklet will not make a notification identifying the Customer unless legally required, where practicable consulting the Customer first.

13. DPIAs, prior consultation and compliance assistance

Taking account of the nature of processing and information available, Marklet will provide reasonable assistance with the Customer's security obligations, breach notifications, data protection impact assessments and prior consultation with the ICO. The Customer remains responsible for determining whether a DPIA, Appropriate Policy Document, legitimate-interests assessment or consultation is required and for completing it. Assistance beyond standard information and Service functionality may be charged at an agreed rate.

14. Records, information and audits

(a) Marklet will make available information reasonably necessary to demonstrate compliance with Article 28 and will maintain records required of it by Data Protection Law.

(b) The Customer must first use available documentation, a reasonable information request or security questionnaire. Marklet may provide relevant third-party reports or certifications held by Sub-processors, subject to their terms.

(c) If that information is insufficient, the Customer may conduct one audit in any 12-month period on at least 30 days' written notice. Additional audits are permitted where a Personal Data Breach materially affecting the Customer has occurred or a Supervisory Authority requires one.

(d) Audits will be remote by default and conducted during normal business hours without disrupting operations or exposing another customer's data, confidential information or security-sensitive material.

(e) An on-site audit is permitted only where remote review cannot reasonably provide necessary assurance, at a location nominated by Marklet. Private residences, the registered office where no processing occurs, and Sub-processor facilities are excluded. Assurance for Sub-processors will be provided through contractual information and their available reports or certifications.

(f) The Customer bears its audit costs and Marklet's reasonable costs unless the audit identifies a material breach by Marklet. Auditors must be independent, suitably qualified, non-competitive and bound by confidentiality.

15. Return and deletion

(a) During the Service, the Customer may use available export and deletion functions. Removing a member or their access does not itself delete the unit's historical record of that person's name, email address, role, association or occupancy period. The Customer remains responsible for deciding whether that history must be retained, corrected, restricted or deleted and may use available functions or request Marklet's assistance. Before deleting a building or ending access, the Customer must export records it wishes or is legally required to retain.

(b) At the end of the processing services, Marklet will, at the Customer's choice, return or securely delete Customer Personal Data and existing copies within a reasonable period, unless UK law applicable to Marklet requires storage.

(c) Deleting a building destroys its customer-specific encryption key, making encrypted files and email bodies unreadable. Deletion is irreversible.

(d) Deleted data may persist in restricted backups for up to seven days and will be overwritten on the normal backup cycle. It will not be processed except for disaster recovery and will remain protected by this DPA.

(e) Audit records may be retained where necessary for security, fraud prevention, evidential integrity, legal claims or compliance, with personal data minimised where reasonably practicable.

(f) A legal duty imposed on the Customer to retain building records does not authorise Marklet to retain them after the Customer ends processing. The Customer must export and retain them in its own lawful system.

16. Liability and general terms

The liability provisions, notices, assignment, waiver, severance, third-party rights, governing law and jurisdiction provisions in the Terms apply to this DPA. Nothing limits Data Subjects' rights or either party's liability to a Supervisory Authority to the extent it cannot lawfully be limited. No amendment to this DPA is effective if it reduces mandatory protection under Data Protection Law.

Schedule 1 - Details of processing

Subject matter

Provision and evaluation of the Marklet block-management platform, including hosting, permissions, workflows, communications, document storage, search, audit, export, integrations, AI-assisted functions and support.

Duration

For the term of the Service and the limited deletion/backup period afterwards, unless law applicable to Marklet requires longer retention.

Nature and purpose

Collecting, receiving, recording, organising, structuring, storing, retrieving, consulting, displaying, analysing, summarising, extracting, transmitting, exporting, restricting, encrypting and deleting data to provide and secure the Service on the Customer's instructions.

Data Subjects

Authorised Users; directors and officers; current and former residents, tenants and leaseholders; landlords and agents; individual payees; estate accountants and other professional advisers; contractors and suppliers; correspondents, complainants and requesters; meeting attendees; payers and other persons represented in Customer Data.

Personal Data

Names, contact and address details, roles, current and former unit associations and occupancy periods, unit and leasehold information, estate accountant names and email addresses, correspondence, issue and complaint records, photographs, documents, meeting and resolution records, contractor and vendor data, company officer details retrieved from Companies House, service-charge and payment records, bank account details of individual payees stored as reference information only and not used to initiate payments, authentication and permission data, audit events, and AI inputs and outputs.

Special Category Data

Not ordinarily required, but may appear incidentally in free text, emails or documents. The designated resident fire-safety category may contain health, disability and evacuation information deliberately uploaded by the Customer.

Criminal-offence data

Not intended or required, but may appear incidentally in complaints, correspondence or uploaded records. The Customer must not upload it unless necessary and lawful.

Frequency

Continuous or intermittent according to Customer use of the Service.

Customer instructions

The Terms, Order, account configuration, feature use, authenticated actions and any additional lawful written instructions accepted by Marklet.

Schedule 2 - Technical and organisational measures

Access and identity

Passwordless authentication using email one-time codes, magic links or single sign-on with Google or Microsoft, with no passwords stored by Marklet; role-based access; Customer-configurable permission matrix; access removal processes; restricted administrator privileges.

Tenant separation

Logical separation between customer environments and permission-controlled visibility by estate, building, unit, document audience and role.

Encryption

Stored files and email bodies encrypted using customer-specific keys; encryption in transit using current transport security; cryptographic erasure when a building key is destroyed.

Sensitive documents

Resident fire-safety category excluded from ordinary administrator access, search, comments, flat association and AI; generated non-identifying filename; access logging; time-limited break-glass process.

Audit and logging

Append-only, tamper-evident customer audit trail for relevant actions; security and operational logging; access and exceptional grants recorded where applicable.

Availability and recovery

Cloud-hosted infrastructure; daily backups retained for seven days; recovery and continuity procedures proportionate to the Service.

Secure operation

Change and access controls, dependency and vulnerability management, incident triage and response, least-privilege practices, and documented internal security review. Marklet achieved Cyber Essentials certification at the basic tier on 4 August 2026. This does not represent Cyber Essentials Plus, third-party penetration testing or an accredited security audit.

Data minimisation

Plan and permission controls; Customer-controlled retention and deletion; exclusion of designated sensitive material from AI; limited support access; aggregation or anonymisation for service statistics where used.

Sub-processors

Due diligence appropriate to risk, written data-processing terms, transfer safeguards where required and access limited to the service supplied.

Personnel

Confidentiality obligations, role-appropriate awareness, access granted according to function and withdrawn when no longer required.

Deletion

Customer deletion and export functions; customer-specific key destruction; backup expiry within seven days; controlled handling of surviving audit evidence.

Schedule 3 - Current Sub-processors

Supabase

Purpose: Database, authentication and file storage

Primary location: Ireland / EEA; provider is US-established

Transfer position: Adequacy for EEA hosting; appropriate safeguard where a restricted transfer occurs

Railway

Purpose: Application hosting and infrastructure

Primary location: Netherlands / EEA; provider is US-established

Transfer position: Adequacy for EEA hosting; appropriate safeguard where a restricted transfer occurs

Google Cloud

Purpose: AI inference and processing

Primary location: European Union; contracting entity in Ireland

Transfer position: Adequacy for EEA processing

Resend

Purpose: Transactional email delivery

Primary location: United States

Transfer position: Applicable adequacy or appropriate safeguard under provider contract

Cloudflare

Purpose: Edge network, security and Turnstile bot protection

Primary location: Global

Transfer position: Applicable adequacy or appropriate safeguard under provider contract

Google, Apple and Mozilla

Purpose: Optional browser push notification delivery

Primary location: Global

Transfer position: Applicable adequacy or appropriate safeguard under the relevant provider terms

Sub-processor notices and queries: privacy@marklet.io. The current notified list is maintained at marklet.io/sub-processors.