Last Updated: 20.08.2026 (Version 1.0.7)

Subprocessors

Subcontracting relationships pursuant to § 9 of the data processing agreement

MARA currently cooperates with the following subcontractors in the fulfilment of the order, with whose assignment the Customer agrees.

If the data processing takes place outside the European Economic Area, the following overview also lists the measures and guarantees which ensure an adequate level of data protection in the processing in accordance with Art. 44 et seq. of the European Data Protection Act. GDPR (e.g. EU standard contract clauses, or adequacy decision of the EU Commission).

01

Amazon Web Services

Name/Company: Amazon Web Services EMEA SARL
‍Function/activity: Hosting Provider
‍Type of data: All personal data processed under this DPA
‍Location of data processing: European Union
‍Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, ISO 27017, ISO 27018, SOC 2. See https://aws.amazon.com/compliance/programs/

02

DeepL

Name/Company: DeepL SE
Function/activity: Translation Services
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001, SOC 2 Type II, BSI C5 Type 2. See https://www.deepl.com/en/pro-data-security

03

Grepture

Name/Company: Grepture UG
Function/activity: AI Gateway, PII Redaction & Logging/Monitoring
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: All infrastructure hosted exclusively within the EU. No data transfers outside the European Union. Also see: https://grepture.com/de/subprocessors

04

Sentry

Name/Company: Functional Software, Inc. dba Sentry
Function/activity: Logging and Monitoring
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001, SOC 2 Type II. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://sentry.io/trust/

05

OpenAI

Name/Company: OpenAI, L.L.C.
Function/activity: Modelhosting
Type of data: All personal data processed under this DPA
Location of data processing: United States
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, ISO 27017, ISO 27018, SOC 2 Type II. Customer data is not used for model training. EU Standard Contractual Clauses (2021/914). Also see: https://openai.com/security-and-privacy/

06

Intercom (UI only)

Name/Company: Intercom, Inc.
Function/activity: Customer support chat
Type of data: All personal data processed under this DPA
Location of data processing: United States
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001, ISO 27018, ISO 27701, SOC 2 Type II. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://trust.intercom.com/

07

Customer.io (UI only)

Name/Company: Peaberry Software Inc.
Function/activity: Notifications and emails
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001, SOC 2 Type II. See https://docs.customer.io/accounts-and-workspaces/security-certifications/

08

Pusher.com

Name/Company: MessageBird B.V.
Function/activity: Streaming / Live Writing
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, SOC 2 Type II. See https://pusher.com/security/

09

Vercel

Name/Company: Vercel Inc.
Function/activity: Hosting Provider
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, SOC 2 Type II. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://security.vercel.com/

10

Google Cloud Platform

Name/Company: Google Ireland Limited
Function/activity: Translation Services
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, ISO 27017, ISO 27018, SOC 2. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://cloud.google.com/security/compliance/iso-27001

11

Azure

Name/Company: Microsoft Corporation
Function/activity: Modelhosting
Type of data: All personal data processed under this DPA
Location of data processing: European Union
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, ISO 27018, ISO 27701, SOC 2. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://azure.microsoft.com/en-us/explore/security

12

Anthropic

Name/Company: Anthropic, PBC
Function/activity: Modelhosting
Type of data: All personal data processed under this DPA
Location of data processing: United States
Measures/guarantees to ensure an adequate level of data protection: Certified under ISO 27001:2022, ISO 42001:2023, SOC 2 Type II. Customer data is not used for model training. EU Standard Contractual Clauses (2021/914). Also see: https://trust.anthropic.com/

13

PostHog

Name/Company: PostHog, Inc.
Function/activity:
Product Analytics, Session Replay
Type of data:
All personal data processed under this DPA
Location of data processing:
European Union
Measures/guarantees to ensure an adequate level of data protection:
Certified under SOC 2 Type II. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://posthog.com/docs/privacy/soc2

14

Resend

Name/Company: Resend Inc.
Function/activity:
Transactional Email Delivery
Type of data:
All personal data processed under this DPA
Location of data processing:
United States
Measures/guarantees to ensure an adequate level of data protection:
Certified under SOC 2 Type II. EU Standard Contractual Clauses (2021/914). Certified under the EU-US Data Privacy Framework (DPF) - see https://www.dataprivacyframework.gov/list. Also see: https://resend.com/security

Ready to see your reviews answered for you?

Connect your reviews and watch MARA draft replies in your voice. Free to start.