Data Processing Agreement
Last Updated: January 2026 (Version 1.0)
Publishing URL: https://mrava.ai/legal/dpa
1. Scope & Relationship
1.1 Purpose of the Data Processing Agreement
1.1.1 Purpose. This Data Processing Agreement ("DPA") sets out the terms under which Mrava processes personal data on behalf of the Customer in connection with the provision of the Services.
1.1.2 Compliance & Laws. This DPA is intended to satisfy the requirements of Article 28 of the Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws governing processor obligations (collectively, "Applicable Data Protection Laws").
1.1.3 Processor Activities Only. This DPA applies solely to processing activities where Mrava acts as a data processor on behalf of the Customer. Processing carried out by Mrava as an independent data controller (e.g., for billing or account management) is governed by the Privacy Policy.
1.2 Relationship to the Master Services Agreement and Privacy Policy
1.2.1 Incorporation by Reference. This DPA forms an integral part of, and is incorporated by reference into, the Master Services Agreement ("MSA") between the parties.
1.2.2 Application to Affiliates. The obligations and rights set forth in this DPA extend to any Authorized Affiliates of the Customer accessing the Services under the MSA. Customer enters into this DPA on its own behalf and on behalf of such Affiliates.
1.2.3 Privacy Policy. The Privacy Policy describes, for transparency purposes, how personal data is processed in practice. It does not replace or modify the binding obligations set out in this DPA.
1.2.4 Consistent Interpretation. The MSA, this DPA, and the Privacy Policy shall be interpreted in a manner that is consistent and avoids conflict wherever reasonably possible.
1.3 Order of Precedence
1.3.1 Data Protection Matters. In the event of any conflict or inconsistency between this DPA and the MSA or Privacy Policy with respect to the processing of personal data on behalf of the Customer, this DPA shall prevail.
1.3.2 Other Matters. For all matters not relating to data protection or data processing (e.g., commercial terms, liability caps), the MSA shall prevail.
1.3.3 Annexes. The annexes to this DPA form an integral part of this DPA and are subject to the same order of precedence.
1.4 Definitions
1.4.1 GDPR Definitions. Terms such as "Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Personal Data Breach" shall have the meanings given to them in the GDPR.
1.4.2 Capitalized Terms. Capitalized terms not defined herein shall have the meanings ascribed to them in the MSA.
1.5 Duration
1.5.1 Term. This DPA shall remain in effect for the duration of the MSA and for as long as Mrava retains or processes Personal Data on behalf of the Customer (including during any post-termination data export or retention period).
2. Roles & Instructions
2.1 Customer as Data Controller
2.1.1 Controller Role. The Customer acts as the data controller with respect to all personal data processed by Mrava on the Customer's behalf in connection with the Services.
2.1.2 Controller Responsibilities. The Customer is responsible for: (a) determining the purposes and means of processing; (b) ensuring a lawful basis for processing under applicable data protection laws; (c) providing required notices to data subjects and obtaining any necessary consents; and (d) issuing lawful and documented instructions to Mrava.
2.2 Mrava as Data Processor
2.2.1 Processor Role. Mrava acts solely as a data processor when processing personal data on behalf of the Customer under this DPA.
2.2.2 No Independent Purposes. Mrava shall not process personal data for its own purposes or determine the purposes or means of processing such data, except as required to comply with applicable law or as expressly permitted in the MSA (e.g., for security or product improvement purposes where compatible with Processor obligations).
2.2.3 Personnel Authorization. Mrava ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
2.3 Processing on Documented Instructions
2.3.1 Documented Instructions. Mrava shall process personal data only on documented instructions from the Customer, including instructions reflected in the Customer's configuration and use of the Services, unless required to do otherwise by applicable law.
2.3.2 Unlawful Instructions. If Mrava reasonably believes that an instruction infringes applicable data protection law, Mrava shall inform the Customer without undue delay and may suspend the execution of such instruction until the Customer confirms or modifies it.
2.3.3 Required by Law. Where processing is required by applicable law to which Mrava is subject, Mrava shall inform the Customer of such requirement prior to processing, unless prohibited by law (e.g., on important grounds of public interest).
2.4 Compliance with Laws
2.4.1 Processor Compliance. Mrava shall comply with all data protection laws applicable to it in its role as a data processor, including the GDPR and any applicable national implementing legislation.
2.4.2 Regulatory Cooperation. Mrava shall reasonably cooperate with the Customer to demonstrate compliance with this DPA and applicable data protection laws, as further set out herein.
2.4.3 No Assumption of Controller Duties. Nothing in this DPA shall be construed as requiring Mrava to assume the Customer's responsibilities as data controller.
3. Processing Description
3.1 Subject Matter, Duration, Nature & Purpose of Processing
3.1.1 Subject Matter. The processing concerns personal data contained in financial documents, communications, records, and related content submitted to or processed within the Platform by or on behalf of the Customer.
3.1.2 Duration. Processing shall continue for the duration of the Services under the MSA, unless otherwise instructed by the Customer or required by applicable law, and is subject to post-termination handling as set out in this DPA.
3.1.3 Nature of Processing. Processing activities may include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, restriction, erasure, or destruction of personal data, including automated processing and AI-assisted operations (including generation of vector embeddings and inference) as configured by the Customer.
3.1.4 Purpose of Processing. Processing is performed solely to provide the Services, including finance workflow automation, document ingestion and extraction, approvals, reconciliation, communications, auditability, security, and related operational support, in accordance with the Customer's documented instructions.
3.2 Categories of Data Subjects
3.2.1 Primary Data Subjects. The categories of data subjects include: (a) the Customer's Authorized Users (e.g., employees, contractors, agents of Customer and its Affiliates); and (b) individuals whose personal data is included in Customer Data processed through the Platform.
3.2.2 Third-Party Data Subjects. Data subjects may also include suppliers, vendors, counterparties, and other third parties whose personal data appears in invoices, contracts, emails, or other documents processed at the Customer's instruction.
3.3 Categories of Personal Data
3.3.1 Personal Data Categories. Depending on the Customer's use of the Services, the categories of personal data processed may include: (a) identification and contact data (e.g., names, business email addresses, phone numbers, postal addresses); (b) account and authentication data (e.g., user identifiers, roles, access logs); (c) financial and transaction-related data (e.g., invoice details, amounts, payment references, tax information); (d) communications data (e.g., email content, attachments, metadata); (e) User Content (e.g., internal notes, comments, chat messages); and (f) technical and usage data (e.g., audit logs, configuration records).
3.4 Incidental Special Categories of Data
3.4.1 No Intentional Processing. Mrava does not intentionally process special categories of personal data (as defined in Article 9 GDPR).
3.4.2 Incidental Inclusion. The Customer acknowledges that Customer Data may incidentally include special categories of personal data (e.g., health-related information appearing on invoices or receipts).
3.4.3 Processor Handling. Any such incidental special category data is processed solely as part of the document content, in accordance with the Customer's instructions and subject to the safeguards set out in this DPA.
4. Processor Obligations & Security
4.1 Confidentiality of Personnel
4.1.1 Authorized Personnel. Mrava ensures that all personnel authorized to process personal data on behalf of the Customer are bound by appropriate confidentiality obligations, whether by contract or statutory duty.
4.1.2 Scope of Access. Access to personal data is limited to personnel who require such access for the performance of their duties in connection with the Services.
4.2 Technical and Organizational Measures (TOMs)
4.2.1 Security Measures. Mrava implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
4.2.2 Documentation. A description of Mrava's current technical and organizational measures is set out in Annex B (Technical and Organizational Measures), which forms an integral part of this DPA.
4.3 Evolution of Security Measures
4.3.1 Continuous Improvement. The Customer acknowledges that security threats and technologies evolve over time. Mrava may update, enhance, or replace its technical and organizational measures to maintain or improve the overall security posture of the Services.
4.3.2 No Material Degradation. Any such updates shall not materially reduce the overall level of protection provided to personal data as compared to the measures described in Annex B at the time of execution of this DPA.
4.3.3 No Amendment Required. Updates to security measures in accordance with this Section shall not require an amendment to this DPA or additional consent from the Customer.
4.4 Assistance with Controller Obligations (DPIAs & Prior Consultation)
4.4.1 Regulatory Assistance. Taking into account the nature of processing and the information available to Mrava, Mrava shall provide reasonable assistance to the Customer in complying with its obligations under applicable data protection laws, including:
- (a) conducting data protection impact assessments (DPIAs); and
- (b) prior consultation with supervisory authorities, where required.
4.4.2 Scope of Assistance. Assistance under this Section shall be limited to information reasonably available to Mrava and related to the Services.
4.4.3 Cost Allocation. To the extent permitted by law, Mrava may charge reasonable fees for assistance that requires substantial effort or resources beyond the ordinary provision of the Services.
4.5 Record-Keeping and Compliance
4.5.1 Records of Processing. Mrava shall maintain records of processing activities carried out on behalf of the Customer, as required by applicable data protection laws.
4.5.2 Demonstration of Compliance. Upon reasonable request, Mrava shall make available information necessary to demonstrate compliance with this DPA, subject to appropriate confidentiality and security safeguards.
4.5.3 No Excess Disclosure. Nothing in this Section requires Mrava to disclose confidential information, trade secrets, or information that would compromise the security of the Services.
5. Subprocessing & International Transfers
5.2 Subprocessor Obligations & Liability
5.2.1 Flow-Down Obligations. Mrava shall enter into a written agreement with each Subprocessor imposing data protection obligations that are no less protective than those set out in this DPA, including appropriate confidentiality, security, and processing limitations.
5.2.2 Processor Accountability. Mrava remains fully responsible and liable to the Customer for the performance of its Subprocessors' obligations under this DPA, to the same extent as if the processing were carried out directly by Mrava.
5.2.3 No Independent Use. Subprocessors are prohibited from processing personal data for their own purposes or outside the scope of Mrava's instructions.
5.3 Objection Rights
5.3.1 Notice of Changes. Mrava will provide the Customer with reasonable prior notice of any intended addition or replacement of a Subprocessor.
5.3.2 Right to Object. The Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice to Mrava within a reasonable period following receipt of such notice.
5.3.3 Resolution. If the Customer raises a valid objection that cannot be reasonably resolved, the Customer may suspend or terminate the affected Services in accordance with the MSA, without penalty for the remaining term of the affected Services.
5.4 International Data Transfers and Safeguards
5.4.1 Transfer Mechanisms. Where personal data is transferred outside the European Economic Area, Mrava shall ensure that appropriate safeguards are in place in accordance with applicable data protection laws, such as Standard Contractual Clauses or other legally recognized transfer mechanisms.
5.4.2 Adequacy Decisions. Where applicable, Mrava may rely on adequacy decisions or equivalent frameworks recognized under applicable law.
5.4.3 Supplementary Measures. Mrava implements appropriate technical and organizational measures to protect personal data transferred internationally against unauthorized access or disclosure.
5.4.4 Transparency. Information regarding applicable transfer safeguards is made available to the Customer upon request.
6. Security Incidents & Data Subject Rights
6.1 Security Incident Detection and Breach Notification
6.1.1 Security Incident Detection. Mrava shall implement appropriate technical and organizational measures to detect, investigate, and respond to security incidents affecting personal data processed under this DPA.
6.1.2 Personal Data Breach Notification. In the event Mrava becomes aware of a personal data breach affecting Customer Data, Mrava shall notify the Customer without undue delay after becoming aware of the breach (to enable the Customer to fulfill its notification obligations within the statutory timeline).
6.1.3 Content of Notification. Such notification shall include, to the extent reasonably available at the time (in accordance with Article 33(3) GDPR): (a) a description of the nature of the personal data breach; (b) the categories and approximate number of affected data subjects and records; (c) the likely consequences of the breach; and (d) measures taken or proposed to address and mitigate the breach.
6.1.4 No Public Notification Obligation. Mrava shall not notify data subjects or supervisory authorities of a personal data breach unless required by applicable law or expressly instructed by the Customer in writing.
6.2 Cooperation and Mitigation
6.2.1 Incident Response Cooperation. Mrava shall reasonably cooperate with the Customer in investigating, containing, mitigating, and remediating any personal data breach, taking into account the nature of the processing and the information available to Mrava.
6.2.2 Mitigation Measures. Such cooperation may include providing relevant logs, technical information, and reasonable assistance necessary for the Customer to: (a) comply with its breach notification obligations; and (b) assess and mitigate risks to data subjects.
6.2.3 Cost Allocation. Assistance provided under this Section shall be included in the Services, except where the incident is caused by Customer misconfiguration, misuse of the Platform, or violation of the MSA, in which case Mrava may charge reasonable costs for additional support.
6.3 Assistance with Data Subject Requests
6.3.1 Controller Responsibility. The Customer remains responsible for responding to data subject requests relating to personal data processed under this DPA.
6.3.2 Processor Assistance. Taking into account the nature of the processing, Mrava shall provide reasonable assistance to the Customer by appropriate technical and organizational measures to enable compliance with data subject rights requests, including access, rectification, erasure, restriction, objection, and portability (as required by Article 28(3)(e) GDPR).
6.3.3 Instruction-Based Processing. Mrava shall act on documented instructions from the Customer when assisting with data subject requests and shall not respond directly to data subjects unless legally required to do so.
6.3.4 Fees for Assistance. Where requests require disproportionate technical effort or non-standard data extraction, Mrava may charge reasonable fees, provided such fees are communicated to the Customer in advance.
7. Data Return, Deletion & Audit
7.1 Data Retention During the Term
7.1.1 Retention for Service Provision. During the term of the Agreement, Mrava shall retain and process personal data only for as long as necessary to provide the Services in accordance with the MSA, this DPA, and the Customer's documented instructions.
7.1.2 Configuration-Driven Retention. Where supported by the Platform, retention periods for certain data categories may be configurable by the Customer. The Customer remains responsible for selecting retention settings consistent with its legal and regulatory obligations.
7.1.3 Audit and Security Logs. Notwithstanding the foregoing, Mrava may retain immutable security, audit, and access logs for a limited period necessary for security monitoring, fraud prevention, compliance, and dispute resolution.
7.2 Data Return and Deletion After Termination
7.2.1 Data Return. Upon termination or expiration of the Agreement, and upon Customer's written request made within the period specified in the MSA, Mrava shall make personal data processed on behalf of the Customer available for return in a commercially reasonable and commonly used format.
7.2.2 Deletion of Personal Data. Following the data return period, Mrava shall render Personal Data inaccessible and subsequently delete or anonymize Personal Data processed on behalf of the Customer in accordance with its standard maintenance schedules and this DPA, unless retention is required under Section 7.3.
7.2.3 Backups. Personal data may remain in backup systems for a limited period as part of standard backup and disaster recovery practices, provided such data is put beyond use (i.e., not actively processed), secured, and eventually overwritten in accordance with Mrava's backup rotation policy.
7.3 Legal Retention Requirements
7.3.1 Mandatory Retention. Mrava may retain personal data to the extent required by applicable law, regulatory obligations, or binding orders from competent authorities.
7.3.2 Limited Processing. Where data is retained under this Section, processing shall be strictly limited to the purposes required by law and subject to appropriate safeguards.
7.4 Audit and Information Rights
7.4.1 Audit Principle. Customer may verify Mrava's compliance with this DPA through information requests and audits, subject to the conditions set out below.
7.4.2 Priority of Certifications and Reports. Where available, Mrava shall make relevant third-party certifications, audit reports, or summaries (such as ISO 27001, SOC 2, or equivalent) available to the Customer. Such materials shall be the primary means of demonstrating compliance.
7.4.3 On-Site Audits as Last Resort. Customer may request an on-site audit only where: (a) the provided certifications or reports are insufficient to demonstrate compliance; (b) there is a documented and reasonable concern regarding Mrava's compliance with this DPA; or (c) such audit is strictly required by a competent Supervisory Authority.
7.4.4 Audit Conditions. Any audit shall: (a) be limited in scope to matters relevant to this DPA; (b) be conducted during normal business hours with reasonable prior notice; (c) not unreasonably interfere with Mrava's operations; (d) be subject to appropriate confidentiality obligations; and (e) be conducted by the Customer or an independent third party who is not a competitor of Mrava.
7.4.5 Costs. Customer shall bear its own costs of any audit. Mrava may charge reasonable costs for audits that require significant internal resources or are requested more than once in any twelve (12) month period (unless such audit reveals a material breach by Mrava).
8. Liability & Final Provisions
8.1 Allocation and Limitation of Liability
8.1.1 MSA Governs Liability. The allocation and limitation of liability applicable to this Data Processing Agreement are governed by the liability provisions set out in the Master Services Agreement ("MSA").
8.1.2 No Separate or Unlimited Liability. Nothing in this DPA shall be construed to create additional or independent liability for either party beyond the liability caps, exclusions, and mandatory liability provisions agreed in the MSA. Any liability arising under this DPA shall count towards and be limited by the aggregate liability caps set forth in the MSA.
8.1.3 Mandatory Liability Preserved. Notwithstanding the foregoing, nothing in this DPA shall exclude or limit either party's liability to the extent such liability cannot be excluded or limited under applicable law (e.g., for fraud or willful misconduct).
8.2 Governing Law and Jurisdiction
8.2.1 Governing Law. This DPA shall be governed by and construed in accordance with the governing law specified in the MSA. However, where the Standard Contractual Clauses (SCCs) apply, they shall be governed by the law of the EU Member State in which the Customer is established (or otherwise Germany).
8.2.2 Jurisdiction. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts specified in the MSA.
8.3 Amendments and Severability
8.3.1 Amendments. Except for updates to the Annexes as expressly permitted in this DPA (e.g., updates to Security Measures under Section 4.3 or Subprocessors under Section 5), this DPA may be amended only in accordance with the amendment provisions of the MSA or as required to comply with changes in applicable data protection laws.
8.3.2 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the invalid or unenforceable provision shall be replaced by a valid provision that most closely reflects the original intent.
Annexes to the Data Processing Agreement
Annex A – Description of Processing
A.1 Subject Matter of Processing
Processing of personal data as necessary to provide the Mrava Platform, including finance automation, document processing, workflow execution, communications, and integrations with third-party services (email, ERP, banking).
A.2 Duration of Processing
For the duration of the Agreement and any applicable post-termination retention period as set out in the MSA and this DPA.
A.3 Nature and Purpose of Processing
- Ingestion, extraction, and structuring of financial documents
- Workflow automation (approvals, reconciliation, postings)
- Processing of emails and attachments for finance operations
- AI-assisted classification, summarization, drafting, and generation of vector embeddings (inference)
- Audit logging, security monitoring, and compliance reporting
A.4 Categories of Data Subjects
- Customer employees and Authorized Users
- Customer suppliers, vendors, and counterparties
- Other individuals whose personal data appears in Customer Data
A.5 Categories of Personal Data
- Account and identity data (name, business email, role)
- Financial and transaction-related data (invoices, payment metadata)
- Communication data (emails, attachments, metadata)
- User Content (chat, notes, comments, annotations)
- Authentication, usage, and audit log data
A.6 Special Categories of Data
Not intentionally processed. Special categories of data may be processed incidentally if contained within Customer-provided documents (e.g., medical invoices), strictly on Customer instructions and subject to security controls (Article 9 GDPR).
Annex B – Technical and Organizational Measures (TOMs)
Mrava implements appropriate technical and organizational measures to protect personal data, including:
B.1 Security Measures
- Encryption in transit (TLS 1.3, with TLS 1.2 fallback) and at rest (encrypted volumes and object storage)
- Logical tenant isolation between customers
- Role-based access control (RBAC) and least-privilege access
- Secure authentication mechanisms (including MFA where supported)
B.2 Operational Security
- Audit logging of access and critical actions
- Monitoring for unauthorized access and abuse
- Incident response procedures and escalation paths
- Regular security reviews and updates
B.3 Availability & Resilience (Backups)
- Regular automated backups of Customer Data
- Disaster Recovery (DR) and Business Continuity plans tested at least annually
- Redundant infrastructure to ensure high availability
B.4 Personnel & Confidentiality
- Access to personal data limited to authorized personnel
- Personnel subject to confidentiality obligations (surviving termination of employment)
- Security awareness and training measures
B.5 Testing & Verification
- Regular vulnerability scanning
- Periodic penetration testing
B.6 Evolution of Measures
Mrava may update and enhance its security measures over time to reflect technological developments, emerging threats, and regulatory expectations, provided that overall security is not materially reduced.
Annex C – Subprocessors
C.1 General Authorization
Customer grants Mrava general authorization to engage subprocessors for the provision of the Services.
C.2 Subprocessor Categories
Mrava may use subprocessors for:
- Cloud infrastructure and hosting
- AI and document processing services
- Email, ERP, and banking connectivity
- Monitoring, logging, and security tooling
C.3 Obligations
All subprocessors are bound by data protection obligations no less protective than those set out in this DPA. Mrava remains fully responsible for the performance of its subprocessors.
C.4 Current List & Updates
A current list of subprocessors, including their functions and locations, is available upon request.
Annex D – Standard Contractual Clauses
D.1 Incorporation
Where personal data is transferred outside the European Economic Area (EEA) to a country not recognized by the European Commission as providing an adequate level of protection, the Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) are hereby incorporated by reference.
D.2 Modules
The following Modules apply based on the parties' roles:
- Module Two: Transfer controller to processor (C-to-P)
- Module Three: Transfer processor to processor (P-to-P) (where applicable)
D.3 Governing Law
For the purposes of the SCCs, the governing law shall be the law of Germany, and the supervisory authority shall be the Berlin Commissioner for Data Protection.