Markaz Chat

Data Processing Addendum

Effective: July 17, 2026

This Data Processing Addendum (DPA) forms part of the Markaz Chat Terms between the merchant or workspace owner (Controller) and Markaz Digital (Processor). It applies when Markaz Chat processes personal data for the Controller.

1. Instructions and purpose

Markaz Digital processes personal data only on documented instructions expressed through the Controller's configuration and use of Markaz Chat, to provide messaging, customer support, CRM, automation, commerce, security, billing, and related service operations. Markaz Digital does not sell personal data.

2. Data and people

Data may include names, contact details, account identifiers, messages, attachments, order and delivery information, support records, consent status, and technical/security events relating to the Controller's customers, prospects, staff, and authorized users.

3. Confidentiality and security

Access is limited to authorized personnel under confidentiality duties. Markaz Digital uses workspace authorization, transport encryption, encrypted secrets, private media controls, audit logs, backup safeguards, retention jobs, and incident-response procedures appropriate to the service.

4. Subprocessors and transfers

The Controller authorizes subprocessors needed to provide hosting, messaging, AI, email, payment, monitoring, and connected-platform services. Markaz Digital remains responsible for appropriate contractual safeguards and will provide material subprocessor information on request.

5. Requests and incidents

Markaz Digital assists with access, correction, export, deletion, and platform privacy requests using information available to it. Markaz Digital will notify the Controller of a confirmed personal-data incident without undue delay where required by contract or law and will provide reasonable investigation information.

6. Retention and return

Personal data is retained only for the service period and documented operational or legal retention periods. Workspace deletion has a seven-day safety window before deletion begins. Shopify order metadata is retained up to 365 days, abandoned-checkout data up to 90 days, fulfilled privacy-request records up to 90 days, and encrypted database backups up to 14 days, unless a documented legal hold applies.

7. Controller duties

The Controller is responsible for lawful instructions, notices, consent, connected-account authority, user access, and the accuracy and legality of data submitted to Markaz Chat.

8. Audit and deletion

Markaz Digital will provide reasonable evidence of these controls subject to confidentiality and security restrictions. On termination or verified instruction, Markaz Digital deletes or returns personal data according to the service's deletion process, except data required by law or isolated in time-limited backups.

9. Contact

Privacy and DPA requests: info@markazdigital.net.