/legal · Version 1 · Last updated May 4, 2026
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between LatentSpace Labs GmbH (“Processor” or “markoto”) and you, the workspace owner (“Controller”). It governs markoto’s processing of personal data on the Controller’s behalf in connection with the Service.
This DPA is required only for workspace customers. If you use markoto only on personal documents, this DPA does not apply to you.
1. Definitions
Capitalised terms not defined here have the meanings given in the General Data Protection Regulation (Regulation (EU) 2016/679 — “GDPR”).
2. Roles
- The Controller determines the purposes and means of processing personal data placed into its workspace by its members.
- The Processor processes that personal data on the Controller’s documented instructions, namely to operate the Service.
3. Subject matter, duration, nature and purpose of processing
The Processor processes personal data placed into the Controller’s workspace (document content, comments, knowledge-base files, member metadata, AI prompts and outputs) for the duration of the Service agreement and for the purpose of delivering the Service.
4. Categories of data subjects and personal data
- Data subjects: the Controller’s workspace members, third parties named in the Controller’s documents.
- Categories of data: identification (name, email, OAuth identifier), content (any personal data placed into documents/comments/knowledge files), usage (AI prompts, audit metadata).
5. Obligations of the Processor
The Processor will:
(a) process personal data only on the Controller’s documented instructions, including transfers outside the EEA, except where required by Union or Member State law; (b) ensure persons authorised to process the personal data are bound by confidentiality; © take appropriate technical and organisational measures (Article 32), including the security measures listed in Annex I; (d) engage sub-processors only with the Controller’s prior general authorisation, providing at least 30 days’ advance notice of new sub-processors with the right to object on reasonable data-protection grounds; (e) assist the Controller in fulfilling data-subject-rights requests (Articles 15–22) by providing self-service tooling and, where the tooling is insufficient, prompt manual support; (f) assist the Controller in meeting the obligations of Articles 32–36 (security, breach notification, DPIA, prior consultation); (g) notify the Controller without undue delay after becoming aware of a personal data breach; (h) at the choice of the Controller, delete or return all personal data after the end of the Service, and delete existing copies unless EU or Member State law requires retention; (i) make available all information necessary to demonstrate compliance and allow audits — including by an independent auditor — by the Controller, on reasonable notice and at the Controller’s expense.
6. Sub-processors
The Controller authorises the Processor to engage the sub-processors listed at /legal/sub-processors. The Processor will notify the Controller at least 30 days in advance of any new sub-processor. If the Controller objects on reasonable data-protection grounds, the Processor and Controller will work in good faith to resolve the objection; if no resolution is reached, the Controller may terminate the Service.
7. International transfers
Where the Processor or its sub-processors transfer personal data outside the EEA, transfers are governed by the EU-US Data Privacy Framework where applicable, or by Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as a fallback. The current transfer mechanism for each sub-processor is published at /legal/sub-processors.
8. Audit
The Processor will respond to reasonable Controller audit requests, no more frequently than annually except in case of a notified breach, on reasonable notice and during business hours, with the Controller bearing its own costs and reimbursing the Processor’s reasonable costs.
9. Liability
Each Party’s liability under this DPA is subject to the liability cap in the Terms of Service.
10. Term and termination
This DPA is co-terminous with the Terms of Service. Provisions that by their nature should survive termination — including audit and post-termination data return — survive.
Annex I — Technical and organisational measures
(See section “Security” of the Privacy Policy at /legal/privacy for the live security posture.)
Annex II — Sub-processors
(See /legal/sub-processors for the live list.)
This is version 1, effective 2026-05-04.