Skip to content
MarginMeter

Data processing agreement

Last updated October 3, 2026 · Operated by MarginMeter

This agreement applies when you use MarginMeter to process personal data on behalf of your organization (for example, your end customers' names and emails imported from Stripe). You are the controller; MarginMeter is the processor.

Processing

We process personal data only to provide the service and according to your documented instructions — configuring connections and settings counts as instructions. Categories of data: end-customer identifiers, names and email addresses contained in provider records; workspace member account data.

Security measures

  • Encryption in transit (TLS) and at rest; provider credentials encrypted with AWS KMS envelope encryption.
  • PostgreSQL row-level security isolating every workspace; least-privilege database and cloud roles.
  • Access logging, audit logs of sensitive actions, and secrets excluded from logs.

Subprocessors

Our current subprocessors are listed on the subprocessors page. We will announce new subprocessors before they process your data.

Assistance and breaches

We assist with data subject requests and notify you without undue delay after becoming aware of a personal data breach affecting your data.

Deletion

On workspace deletion we delete personal data in stages; backups expire within 35 days.

Executed copies

For a countersigned copy, contact us through the contact page.