This agreement complements the Terms of Service and governs the processing of personal data. It is automatically binding upon installing Margrow and does not require a separate signature.
Margrow processes data exclusively to deliver the Service:
No sensitive data (health, financial, ideological) is processed.
Margrow uses the following services to deliver the Service:
| Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting & storage | Riyadh · Ireland |
| SendGrid (Twilio) | Email delivery | EU |
| Postmark | Email delivery (backup) | EU |
| Cloudflare | Network protection & CDN | Global network |
| PostHog | Internal analytics | EU |
| Salla | Merchant store integration | Saudi Arabia |
Adding or changing a sub-processor is notified 30 days before it takes effect. You have the right to object.
Margrow implements appropriate technical and organizational security measures:
Full details on the Security page.
In the event of any data breach affecting your customers' data, we will notify you within 72 hours of detection, with details: nature of the breach, data affected, actions taken, and recommendations.
Enterprise-tier customers may request an annual audit of Margrow's security measures, with 30 days' prior notice.
Upon receiving a request from one of your customers (access, deletion, export, etc.), we will assist you in fulfilling it within 30 days of notification.
This agreement remains in effect for the duration of your use of the Service. Upon termination, your data is deleted within 30 days (except data legally required to be retained, such as billing records for ZATCA).
Data Protection Officer (DPO): dpo@margrow.com
Data subject rights enforcement: privacy@margrow.com