Mrava AIMrava AI
← Back to Mrava AI

Table of Contents

Legal Document

Privacy Policy

Last Updated: January 2026 (Version 1.0)

Publishing URL: https://mrava.ai/legal/privacy

1. Introduction & Scope

1.1 Purpose of This Privacy Policy

1.1.1 Purpose. This Privacy Policy explains how Mrava UG (haftungsbeschränkt) ("Mrava", "we", "us") processes personal data in connection with the provision of the Mrava platform and related services (the "Platform").

1.1.2 Transparency Objective. This Privacy Policy is intended to provide transparency to users, customers, suppliers, and other affected individuals regarding:

  • (a) what personal data is processed,
  • (b) for what purposes,
  • (c) on what legal bases, and
  • (d) how such data is protected.

1.1.3 Legal Framework. This Privacy Policy is designed to comply with applicable data protection laws, including the EU General Data Protection Regulation ("GDPR").

1.2 Scope and Applicability

1.2.1 In-Scope Individuals. This Privacy Policy applies to the processing of personal data relating to:

  • (a) Authorized Users of the Platform acting on behalf of a customer or its Affiliates;
  • (b) users accessing the Platform via Free Trials, Beta, or Proof of Concept (POC) accounts;
  • (c) supplier and vendor contacts whose personal data appears in invoices, financial documents, or communications processed through the Platform;
  • (d) individuals whose personal data is contained in emails, attachments, records, or other content processed at the instruction of a customer; and
  • (e) visitors to Mrava's website and related online properties.

1.2.2 Processing Contexts. This Privacy Policy applies regardless of whether personal data is processed via:

  • (a) direct user input;
  • (b) automated ingestion of documents or communications;
  • (c) integrations with third-party services (including email providers, ERP systems, and banking or payment interfaces); or
  • (d) AI-assisted or automated workflows enabled within the Platform.

1.2.3 Customer-Controlled Processing. Where personal data is processed on behalf of a customer, such processing occurs in accordance with the customer's configuration, instructions, and enabled features within the Platform.

1.3 Relationship to the Master Services Agreement (MSA) and Data Processing Agreement (DPA)

1.3.1 Related Agreements. This Privacy Policy should be read together with:

  • (a) the Master Services Agreement ("MSA"), which governs the contractual relationship between Mrava and its customers; and
  • (b) the Data Processing Agreement ("DPA"), which governs the processing of personal data on behalf of customers where Mrava acts as a data processor.

1.3.2 Order of Precedence. In the event of any conflict:

  • (a) the DPA shall prevail with respect to the processing of personal data on behalf of a customer; and
  • (b) the MSA shall prevail with respect to contractual rights and obligations not related to data protection.

1.3.3 No Override. This Privacy Policy does not override or replace the MSA or the DPA. It is provided for transparency purposes to explain how personal data is processed in practice.

2. Roles & Responsibilities

2.1 Mrava as Data Controller (Account, Billing & Website Data)

2.1.1 Controller Role. Mrava acts as an independent data controller with respect to personal data processed for its own business purposes, including:

  • (a) account creation and administration;
  • (b) billing, invoicing, and payment management relating to Mrava's own fees;
  • (c) customer support and communications; and
  • (d) operation of Mrava's website and related online properties.

2.1.2 Controller Responsibilities. In its role as data controller, Mrava determines the purposes and means of processing such personal data and is responsible for complying with applicable data protection laws, including providing transparency and enabling data subject rights.

2.2 Mrava as Data Processor (Customer Financial Data, Emails & Content)

2.2.1 Processor Role. Mrava acts as a data processor when processing personal data on behalf of a customer in connection with the provision of the Platform, including:

  • (a) financial documents, invoices, and accounting records;
  • (b) emails, attachments, and communications processed via integrations with API-connected accounts (e.g., Gmail, Outlook);
  • (c) User Content (including chat messages, notes, and workflow annotations); and
  • (d) related usage and audit data generated through customer-configured workflows.

2.2.2 Processing on Instructions. In its role as data processor, Mrava processes personal data solely on documented instructions from the customer, as reflected in the customer's configuration, enabled features, and use of the Platform.

2.2.3 DPA Governance. Such processing is governed by the Data Processing Agreement (DPA) entered into between Mrava and the customer, which forms an integral part of the contractual relationship.

2.3 Customer as Data Controller (Responsibility for End Users)

2.3.1 Customer Controller Role. The customer acts as the data controller with respect to personal data of its Authorized Users, employees, contractors, and other individuals whose personal data is processed through the Platform at the customer's instruction.

2.3.2 Customer Obligations. As data controller, the customer is responsible for:

  • (a) determining the lawful basis for processing;
  • (b) providing required privacy notices to affected individuals and obtaining any necessary consents (e.g., for email monitoring);
  • (c) ensuring that instructions given to Mrava are lawful; and
  • (d) responding to data subject requests relating to such personal data.

2.3.3 Configuration Responsibility. The customer determines how the Platform is configured, including integrations, automation settings, and access controls, and remains responsible for the data protection implications of such configuration choices.

2.4 Processing of Third-Party Data (Suppliers) on Customer Instructions

2.4.1 Supplier Data as Customer-Controlled Data. Personal data relating to suppliers, vendors, or other third parties that appears in invoices, emails, contracts, or other documents processed through the Platform ("Supplier Data") is processed by Mrava solely on behalf of and at the instruction of the customer.

2.4.2 No Independent Relationship. Mrava has no direct or independent relationship with suppliers or vendors whose personal data is processed through the Platform and does not determine the purposes or means of processing such Supplier Data.

2.4.3 Processor Capacity. With respect to Supplier Data, Mrava acts exclusively as a data processor, and the customer remains the data controller responsible for ensuring a lawful basis for processing and for fulfilling applicable data protection obligations toward such suppliers.

3. Personal Data We Process

3.1 Account and Identity Data

3.1.1 Account Data. Personal data provided by customers and Authorized Users when creating or administering accounts, including name, business email address, role, organization, and account identifiers.

3.1.2 Contact Details. Business contact information used for account management, billing communications, and customer support interactions.

3.2 Authentication, Usage, and Security Log Data

3.2.1 Authentication Data. Data used to authenticate users and secure access to the Platform, including login timestamps, authentication events, IP addresses, device identifiers, and security tokens (e.g., OAuth access and refresh tokens).

3.2.2 Usage and Audit Logs. Records of user activity within the Platform, including actions taken, workflow events, approvals, configuration changes, and system interactions, generated for security, operational integrity, and auditability.

3.2.3 Security Monitoring. Log and telemetry data used to detect, prevent, and investigate security incidents, abuse, or unauthorized access.

3.3 Financial and Transaction-Related Data (Payment Metadata vs. Execution Data)

3.3.1 Financial Documents. Data contained in invoices, receipts, contracts, purchase orders, and related financial documents processed through the Platform, including supplier names, amounts, dates, tax information, and payment terms.

3.3.2 Payment Metadata. Transaction-related metadata, such as payment status, timestamps, references, and reconciliation indicators, retrieved via integrations with banking or payment service providers.

3.3.3 No Execution Credentials. Mrava does not process or store bank login credentials (usernames/passwords), payment authentication secrets, or execution credentials. While Mrava may store secure tokens to maintain connectivity, payment execution and authorization are performed exclusively by the customer's bank or payment service provider.

3.4 Communication Data (Email, Calendar, and Messaging Integrations)

3.4.1 Email Data. Emails, attachments, headers, and related metadata processed via authorized integrations with email services (e.g., Gmail or Outlook), for the purposes of invoice ingestion, workflow automation, and communications.

3.4.2 Calendar and Messaging Data. Where enabled by the customer, calendar entries or messages processed to support scheduling, notifications, or workflow coordination.

3.4.3 Scope of Access. Communication data is accessed and processed only within the scope authorized by the customer's configuration and enabled integrations.

3.5 Supplier and Vendor Contact Information

3.5.1 Supplier Contact Data. Business contact information of suppliers or vendors appearing in financial documents or communications, such as names, business email addresses, phone numbers, and postal addresses.

3.5.2 Non-User Data. Supplier and vendor contact information may relate to individuals who are not users of the Platform and is processed solely in connection with the customer's finance and procurement workflows.

3.6 User Content (Chat, Notes, Comments, Workflow Annotations)

3.6.1 Collaborative Content. Content created or entered by Authorized Users within the Platform, including internal comments, chat messages, notes, tags, and workflow annotations.

3.6.2 Operational Purpose. User Content is processed to enable collaboration, audit trails, workflow execution, and AI-assisted features as configured by the customer.

3.7 AI Interaction and Automation Data

3.7.1 AI Inputs and Outputs. Prompts, instructions, contextual data, and resulting outputs are generated when Authorized Users interact with AI Agents within the Platform. Mrava retains records of these interactions for security, auditing, and product improvement purposes.

3.7.2 Automation Context. Data related to automated or semi-automated workflows, including configuration parameters, approval states, and execution results.

3.8 Derived and Inferred Data

3.8.1 Derived Data. Data generated by the Platform through automated processing, extraction, classification, or analysis of Customer Data, such as categories, summaries, suggested accounting codes, vector embeddings (numerical representations of text), or workflow recommendations.

3.8.2 Operational Use Only. Derived and inferred data is used solely to support finance workflows, automation, and user-facing functionality within the Platform and is not used for advertising, creditworthiness assessment, or profiling unrelated to the customer's internal operations.

3.9 Incidental Sensitive Data

3.9.1 Incidental Processing. Mrava does not actively solicit special categories of personal data (e.g., health data, trade union membership). However, Customer acknowledges that financial documents (e.g., medical invoices) may incidentally contain such data. Mrava processes such data solely as part of the document content in accordance with the Customer's instructions and security requirements.

4. How and Why We Process Personal Data

4.1 Provision and Operation of the Platform

4.1.1 Core Service Delivery. Mrava processes personal data to provide, operate, and maintain the Platform in accordance with the customer's configuration and instructions, including enabling access, processing documents, executing workflows, and displaying results to Authorized Users.

4.1.2 Role Alignment. Where Mrava acts as a data processor, such processing is performed solely on behalf of and at the instruction of the customer. Where Mrava acts as a data controller, processing is limited to its own account, billing, support, and website operations.

4.1.3 Lawful Basis.

  • (a) For Processor Activities: Processing of Customer Data is based on the Customer's documented instructions and the DPA.
  • (b) For Controller Activities: Processing of account and usage data is based on the performance of a contract with the customer or, where applicable, Mrava's legitimate interests in operating and maintaining the Platform.

4.2 Workflow Automation and AI Assistance

4.2.1 Automation Enablement. Mrava processes personal data to enable automated and semi-automated workflows configured by the customer, including extraction, classification, routing, drafting, and recommendation features supported by AI Agents.

4.2.2 Customer-Controlled Processing. The scope, level of automation, and Autonomy Modes are determined by the customer. Mrava does not independently decide how personal data is used within customer workflows.

4.2.3 No Independent Profiling. AI-assisted processing is performed solely to support the customer's internal finance and operational workflows and is not used for advertising, behavioral profiling, or decision-making unrelated to the customer's business processes.

4.3 Communications and Notifications

4.3.1 Operational Communications. Personal data is processed to enable communications initiated or configured by the customer, including drafting or sending emails, workflow notifications, and alerts to Authorized Users, suppliers, or other third parties.

4.3.2 Sender of Record. Communications sent via the Platform are transmitted on behalf of the customer, who remains the sender of record and determines the content, recipients, and appropriateness of such communications.

4.3.3 Service Communications. Mrava may process contact data to send service-related notices to customers and Authorized Users, such as account updates, security notifications, or changes to the Platform.

4.4 Security, Monitoring, and Abuse Prevention

4.4.1 Security Operations. Mrava processes personal data to secure the Platform, including monitoring authentication events, detecting suspicious activity, preventing abuse, and investigating potential security incidents.

4.4.2 Access Control and Auditing. Processing under this Section supports access management, audit trails, and compliance with internal security policies and customer requirements.

4.4.3 Legitimate Interests. Such processing is based on Mrava's legitimate interests in ensuring the confidentiality, integrity, and availability of the Platform and Customer Data (consistent with GDPR Recital 49).

4.5 Legal and Regulatory Compliance

4.5.1 Compliance Obligations. Mrava may process personal data as necessary to comply with applicable legal obligations, regulatory requirements, lawful requests from public authorities, or enforceable court orders.

4.5.2 Risk Management. Processing may also occur to establish, exercise, or defend legal claims, or to manage compliance risks relating to the use of the Platform.

4.6 Service Improvement & Product Analytics (Operational Metrics)

4.6.1 Operational Analytics. Mrava processes limited usage and performance data to understand how the Platform is used, diagnose issues, improve reliability, and optimize features and workflows.

4.6.2 Aggregated and De-Identified Data. Analytics and service improvement activities rely on aggregated and de-identified data wherever reasonably possible. Mrava personnel do not access or review raw customer content (e.g., email bodies or invoice details) for improvement purposes unless strictly required for support or troubleshooting and only with Customer's explicit temporary permission.

4.6.3 Explicit Exclusions. Mrava does not use personal data processed through the Platform for behavioral advertising, marketing profiling, or the sale of data to third parties.

5. Integrations & Third-Party Services

5.1 Scope of Integration Access (Read, Write, Send, Modify)

5.1.1 Integration Functionality. Subject to Customer authorization and configuration, the Platform may integrate with Third-Party Services (including email providers, ERP/accounting systems, and banking or payment services) to support finance workflows.

5.1.2 Permitted Access Types. Depending on the enabled integration and Customer settings, Mrava may process data to:

  • (a) read data (e.g., retrieve emails, documents, balances, or records);
  • (b) write or modify data (e.g., update statuses, create accounting entries, apply labels or metadata); and
  • (c) send data or communications (e.g., transmit emails or payment instructions on Customer's behalf).

5.1.3 No Excess Access. Mrava accesses and processes data from Third-Party Services only to the extent necessary to provide the user-facing features explicitly enabled by the Customer.

5.1.4 No Storage of Banking Credentials. For banking integrations, Mrava utilizes secure tokens (e.g., OAuth) or regulated Third-Party Providers (TPPs). Mrava does not store raw banking passwords or authentication secrets.

5.2 Customer Authorization and Configuration

5.2.1 Customer Authorization. Integrations are enabled only after explicit authorization by the Customer or its Authorized Users, typically via OAuth, API keys, or similar authorization mechanisms provided by the Third-Party Service.

5.2.2 Configuration Control. The scope of access, permitted actions, and level of automation are determined by the Customer's configuration choices within the Platform.

5.2.3 Revocation. Customers may revoke or modify integration access at any time through the Platform or the relevant Third-Party Service.

5.3 Sender of Record and Customer Responsibility

5.3.1 Sender of Record. For communications or actions executed via integrations (including emails or payment-related messages), the Customer remains the sender of record and the responsible party vis-à-vis third parties.

5.3.2 Customer Accountability. The Customer is responsible for the legality, accuracy, and appropriateness of all actions and communications performed via integrations, whether user-initiated or AI-assisted.

5.4 Purpose Limitation

5.4.1 Strict Purpose Limitation. Data accessed via integrations is processed solely to deliver the Platform's user-facing functionality as configured by the Customer, including finance automation, reconciliation, approvals, and communications.

5.4.2 No Secondary Use. Mrava does not process integration data for purposes unrelated to the Customer's use of the Platform, including unrelated analytics, monitoring, or external decision-making.

5.5 Prohibited Uses

5.5.1 No Sale or Advertising. Mrava does not sell personal data, use it for advertising purposes (including retargeting or personalized ads), or share it with third parties for marketing or promotional use.

5.5.2 No Creditworthiness or Profiling. Data accessed via integrations is not used to assess creditworthiness, perform consumer profiling, or make decisions about individuals unrelated to the Customer's internal finance workflows.

5.5.3 No Independent Enrichment. Mrava does not enrich integration data with external datasets for unrelated purposes.

5.6 Compliance with Platform-Specific Data Policies

5.6.1 Platform Policy Adherence. Mrava's use of data obtained via Third-Party Services complies with the applicable data protection, acceptable use, and developer policies of such services, including email providers, ERP vendors, and banking or open banking interfaces.

5.6.2 Google API Services User Data Policy (Limited Use). Mrava's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, regarding data obtained from Restricted Scopes (e.g., Gmail API):

  • (a) Usage: We use this data only to provide or improve user-facing features (e.g., invoice extraction, email drafting).
  • (b) Transfer: We do not transfer this data to others unless necessary to provide these features (e.g., to our cloud provider), for security purposes, to comply with law, or as part of a merger/acquisition.
  • (c) No Ads: We do not use or transfer this data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • (d) Human Access: We do not allow humans to read this data unless: (i) we have your specific consent for specific messages; (ii) it is necessary for security purposes (e.g., investigating a bug or abuse); (iii) it is necessary to comply with applicable law; or (iv) our use is limited to internal operations and the data have been aggregated and anonymized.

5.6.3 Microsoft and Other Providers. Data obtained via Microsoft Graph APIs (Outlook/365) or other ecosystem providers is processed in strict compliance with the respective Terms of Use and is not used for any purpose other than providing the agreed Services.

6. Artificial Intelligence & Automated Processing

6.1 Use of AI Agents and Automation

6.1.1 AI-Enabled Features. The Platform uses AI Agents and Generative AI models to support finance and operational workflows, including document extraction, data classification, summarization, drafting of communications, recommendations, and workflow automation, as enabled and configured by the Customer.

6.1.2 Contextual Processing. AI Agents process personal data only within the context of the specific task or workflow initiated or configured by the Customer and do not operate independently of the Platform's defined functionality.

6.1.3 Processor Alignment. Where Mrava acts as a data processor, AI-assisted processing is performed solely on behalf of and at the instruction of the Customer, in accordance with the DPA and the Customer's configuration.

6.1.4 No Training on Customer Prompts. Mrava ensures that inputs, prompts, and data submitted to AI Agents by customers are not used to train or improve Mrava's own foundational AI models. Processing by third-party model providers is subject to Section 7.3.2 of the MSA and the respective provider's standard API terms regarding data retention and model improvement.

6.2 Human-in-the-Loop and Oversight

6.2.1 Human Oversight. The Platform is designed to ensure meaningful human oversight of AI-assisted processing. Customers control when AI outputs require review, confirmation, or approval by an Authorized User.

6.2.2 Configurable Controls. Customers may enable, limit, or disable AI features, Autonomy Modes, and automation thresholds at any time through the Platform settings.

6.2.3 Responsibility for Oversight. Customers are responsible for establishing appropriate internal controls, approval processes, and review mechanisms for AI-assisted actions in accordance with their risk tolerance and compliance obligations.

6.3 No Fully Automated Legal or Financial Decisions

6.3.1 No Solely Automated Decisions. The Platform does not perform decisions that produce legal effects or similarly significant effects on individuals based solely on automated processing within the meaning of Article 22 GDPR.

6.3.2 Mandatory Human Approval. Actions with potential legal, financial, or material impact (such as payment execution, binding communications, or ledger changes) require human review or approval as configured by the Customer and cannot be executed solely by AI Agents.

6.3.3 Customer Configuration. Customers remain responsible for ensuring that their use of automation features complies with applicable laws and internal governance requirements.

6.4 Accuracy Limitations and Verification Responsibility

6.4.1 Probabilistic Nature of AI. Customers acknowledge that AI-generated outputs are based on probabilistic models and may occasionally be incomplete, inaccurate, or misleading (often referred to as "hallucinations").

6.4.2 Verification Obligation. Customers and Authorized Users are responsible for reviewing and verifying AI outputs before relying on them for financial, accounting, legal, or operational decisions.

6.4.3 No Guarantee of Accuracy. Mrava does not guarantee the accuracy, completeness, or suitability of AI-generated outputs and disclaims liability for decisions made in reliance on such outputs, except as required by applicable law.

6.5 AI Transparency

6.5.1 Disclosure of AI Interaction. The Platform clearly identifies when a user is interacting with an AI Agent or viewing AI-generated content. Customer acknowledges that it is responsible for ensuring its Authorized Users are aware they are interacting with an AI system.

7. Data Sharing, Transfers & Retention

7.1 Subprocessors and Service Providers

7.1.1 Use of Subprocessors. Mrava may engage carefully selected third-party service providers ("Subprocessors") to support the provision of the Platform, including infrastructure hosting, data storage, security monitoring, AI model providers (e.g., for LLM processing), and customer support tooling.

7.1.2 Processor Alignment. Where Mrava acts as a data processor, Subprocessors process personal data solely on behalf of Mrava and are subject to written agreements imposing data protection obligations consistent with this Privacy Policy and the DPA (Article 28 GDPR).

7.1.3 Transparency. A current list of Subprocessors, including their functions and locations, is made available to customers upon request.

7.1.4 No Sale or Independent Use. Subprocessors are not permitted to use personal data for their own purposes, including advertising, analytics unrelated to the Services, or resale.

7.2 International Data Transfers and Safeguards

7.2.1 Primary Processing Location. Mrava processes Customer Data within the European Economic Area (EEA) (specifically, utilizing data centers located in Germany where available).

7.2.2 Transfers Outside the EEA. Where personal data is transferred or accessed outside the EEA (e.g., to Subprocessors in the US), Mrava ensures appropriate safeguards are in place, such as:

  • (a) The EU-US Data Privacy Framework (DPF) for certified US recipients;
  • (b) Standard Contractual Clauses (SCCs) approved by the European Commission; or
  • (c) Binding Corporate Rules (BCRs).

7.2.3 Security and Minimization. International transfers are limited to what is necessary to provide the Services and are subject to technical and organizational measures designed to protect personal data against unauthorized access.

7.3 Data Retention, Deletion, and Post-Termination Handling

7.3.1 Retention During the Subscription. Personal data processed on behalf of a customer is retained for the duration of the customer's subscription or as otherwise instructed by the customer through the Platform.

7.3.2 Post-Termination Export. Upon termination or expiration of the Services, customers may request export of their Customer Data within the timeframe specified in the MSA and DPA.

7.3.3 Deletion. Following the expiration of the applicable data export period, Mrava will delete or anonymize Customer Data in accordance with its retention policies and the DPA, unless retention is required by applicable law. Anonymized data (which can no longer be linked to an individual) may be retained for statistical or product improvement purposes.

7.3.4 Legal Retention. Mrava may retain limited personal data where required to comply with legal, regulatory, accounting, or tax obligations, or to establish, exercise, or defend legal claims.

7.4 Audit Logs and Compliance Records

7.4.1 Immutable Audit Logs. The Platform generates security, access, and audit logs to ensure system integrity, traceability, and compliance. Such logs may include user actions, authentication events, configuration changes, and approval records.

7.4.2 Separate Retention Logic. Audit logs and compliance records are retained for longer periods than general Customer Data where necessary to meet security, audit, or regulatory requirements (e.g., to reconstruct the details of a financial approval for tax audits).

7.4.3 Restricted Use. Audit logs are used solely for security monitoring, compliance, incident investigation, and audit purposes and are not used for analytics, profiling, or customer-facing features.

7.4.4 Access Controls. Access to audit and security logs is strictly limited to authorized personnel and protected by enhanced access controls.

8. Security Measures

8.1 Technical and Organizational Measures

8.1.1 Security Program. Mrava implements appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature of the processing.

8.1.2 Security Controls. Such measures include, as appropriate:

  • (a) encryption of data in transit and at rest;
  • (b) logical tenant isolation to prevent data commingling;
  • (c) secure development and change management practices;
  • (d) monitoring and logging of system activity; and
  • (e) regular review of security controls.

8.1.3 Risk-Based Approach. Security measures are implemented using a risk-based approach, taking into account the nature of the data processed, the scope of processing, and the potential impact on data subjects.

8.2 Access Controls and Authentication

8.2.1 Least Privilege. Access to personal data is restricted to authorized personnel on a need-to-know basis and governed by role-based access controls.

8.2.2 Authentication Controls. Mrava supports secure authentication mechanisms, including strong password requirements and multi-factor authentication (MFA). MFA is enforced for all Mrava administrative access to production environments.

8.2.3 Personnel Obligations. Mrava personnel with access to personal data are subject to confidentiality obligations and receive appropriate training regarding data protection and security.

8.3 Incident Detection, Notification, and Cooperation with Customers

8.3.1 Incident Detection. Mrava maintains procedures to detect, assess, and respond to security incidents affecting the confidentiality, integrity, or availability of personal data.

8.3.2 Customer Notification. Where Mrava becomes aware of a personal data breach involving Customer Data, Mrava will notify the affected customer without undue delay, in accordance with the DPA and applicable law.

8.3.3 Cooperation and Assistance. Mrava will reasonably cooperate with the customer to:

  • (a) investigate the incident;
  • (b) assess potential impact;
  • (c) support the customer's compliance with applicable breach notification obligations; and
  • (d) implement appropriate remediation measures.

8.3.4 No Admission of Fault. Notification of a security incident does not constitute an admission of fault or liability by Mrava.

8.4 Vulnerability Management & Penetration Testing

8.4.1 Regular Testing. Mrava conducts regular vulnerability scanning and periodic penetration testing of the Platform to identify and remediate potential security weaknesses.

8.4.2 Responsible Disclosure. Mrava maintains a process for security researchers and users to securely report vulnerabilities. Reports can be sent to security@mrava.ai.

9. Data Subject Rights

9.1 Rights of Access, Rectification, and Erasure

9.1.1 Data Subject Rights. Individuals whose personal data is processed have the right, subject to applicable law, to request:

  • (a) access to their personal data;
  • (b) rectification of inaccurate or incomplete personal data; and
  • (c) erasure of personal data in certain circumstances.

9.1.2 Controller Context. Where Mrava acts as a data controller, Mrava will assess and respond to such requests in accordance with applicable data protection laws.

9.1.3 Processor Context. Where Mrava acts as a data processor on behalf of a customer, such requests are handled in accordance with the DPA and the customer's instructions.

9.1.4 Identity Verification. To protect the confidentiality of your information, we may ask you to verify your identity before proceeding with any request you make under this Privacy Policy.

9.2 Restriction, Objection, and Portability

9.2.1 Additional Rights. Depending on the applicable legal basis and processing context, data subjects may also have the right to:

  • (a) restrict processing of their personal data;
  • (b) object to processing based on legitimate interests; and
  • (c) receive a copy of certain personal data in a structured, commonly used, and machine-readable format, or have it transmitted to another controller.

9.2.2 Limitations. These rights may be subject to limitations or exceptions under applicable law, including where processing is necessary for compliance with legal obligations or the establishment, exercise, or defense of legal claims.

9.3 Exercising Rights via the Customer

9.3.1 Primary Point of Contact. Where personal data is processed on behalf of a customer, data subjects should direct their requests to the relevant customer, who acts as the data controller.

9.3.2 Assistance by Mrava. Upon reasonable request, Mrava will assist customers in fulfilling data subject rights requests in accordance with the DPA and applicable law.

9.3.3 No Direct Response Without Instruction. Mrava will not respond directly to data subject requests relating to Customer Data unless legally required to do so or instructed by the customer.

9.3.4 Non-User Data Subjects (e.g., Suppliers). If you are a supplier, vendor, or third party whose data may be processed within the Platform but you are not a direct user, please contact the Customer (the company that inputted your data) directly. If you contact Mrava, we will forward your request to the relevant Customer where identifiable.

10. Cookies, Updates & Contact

10.1 Cookies and Tracking Technologies

10.1.1 Use of Cookies. Mrava uses cookies and similar technologies on its website and, where applicable, within the Platform to ensure functionality, security, and performance.

10.1.2 Types of Cookies. Cookies may include:

  • (a) strictly necessary cookies required for the operation and security of the website or Platform;
  • (b) functional cookies that support user preferences and settings; and
  • (c) limited analytics cookies used to understand website usage and improve performance.

10.1.3 No Advertising Cookies. Mrava does not use cookies or tracking technologies for behavioral advertising, cross-site tracking, or third-party advertising purposes.

10.1.4 Cookie Management. Where required by applicable law, users are provided with information about cookies and may manage their preferences via cookie settings or browser controls. Additional details may be provided in a separate Cookies Policy.

10.2 Updates to This Privacy Policy

10.2.1 Policy Updates. Mrava may update this Privacy Policy from time to time to reflect changes in the Platform, applicable law, or data processing practices.

10.2.2 Material Changes. Material changes that affect how personal data is processed will be communicated to customers through appropriate channels, such as email or in-Platform notifications, prior to becoming effective where required by law.

10.2.3 Effective Date. The effective date of the current version of this Privacy Policy is indicated at the top of the document.

10.3 Contact Information & Data Protection Officer

10.3.1 Contact Details. Questions, concerns, or requests relating to this Privacy Policy or the processing of personal data may be directed to:

Email:

privacy@mrava.ai

10.3.2 Data Protection Officer. Where required by applicable law, Mrava has appointed a Data Protection Officer. Contact details for the DPO are available upon request or via the contact information above.

Back to Home
Mrava AIMrava AI

The AI agent platform for finance operations.

Copied
Solutions
The platform

One agent for every step of AP

Accounts Payable

The AP lifecycle, inbox to settled payment

Resources
Use cases

Capture, matching, approvals, payments

FAQ

ERP fit, security, guardrails, onboarding

Videos

Tours and walkthroughs

Docs & guides

Setup, API reference, best practices

Company
About

Who we are and what we're building

Careers

Berlin and remote across the EU

Contact

Book a call or ask us anything

© 2026 Mrava UG. All rights reserved.

Imprint·Privacy Policy·MSA·DPA