Data processing annex (DPA) — Marto.AI
Last updated: October 9, 2026
An annex to the Terms, applicable to every professional Organization. It gives effect to Article 28 GDPR: when a firm uploads data about its own clients to the Service, the firm is the controller and the Publisher is its processor.
The French version prevails. This English text is provided for convenience only. In the event of any discrepancy, the French version (version française) is the authoritative one (Terms, art. 16).
1. Purpose and roles
For inventory Content (photographs, lots, documents, data concerning Data Subjects), the Organization is the controller and the Publisher acts as processor, on the Organization's documented instructions — the Terms and this annex, together with the use of the Service's features, constituting those instructions.
Exception, described in article 8 of the Terms and in section 4 of the Privacy policy: for improving the Service and training its own AI models, as well as for producing De-identified Data, the Publisher acts as a separate controller. The Organization authorises this by accepting the Terms; it may object at any time to the improvement and training uses (opt-out, Terms art. 8.3). The production of De-identified Data and aggregated data (Terms art. 8.4) is not covered by that withdrawal, as such data cannot be linked to any person.
2. Description of the processing carried out as processor
- Nature: hosting, storage, structuring, display, backup, export, deletion; at the user's request, processing by the artificial intelligence assistant of the text the user dictates or types and of the relevant inventory context (Privacy policy, §4a).
- Purpose: the production of inventories by the Organization.
- Categories of data: identity and contact details of Data Subjects, asset-related circumstances connected with the goods inventoried, photographs liable to reveal elements of private life (home interiors, the incidental presence of individuals).
- Data Subjects concerned: the Organization's clients, deceased persons and their heirs, debtors, third parties appearing incidentally.
- Duration: for as long as the Organization exists on the Service, plus the backup purge period (90 days at most). Conversations held with the inventory assistant follow this same duration: they form part of the Organization's data. After 90 days without a new message they are removed from their author's list without being deleted; the deletion of their author's account erases them. The assistant's audit journal — a copy of each message, each reply and each action, with the confirmation given or refused — follows the main duration instead: it serves to explain any change made by the assistant, and the deletion of its author's account only stops linking it to them. The resulting inventory and report (constat) also follow the main duration set out above.
3. Obligations of the Publisher (processor)
The Publisher undertakes to:
- process the data only on the Organization's documented instructions, including as regards transfers of personal data to a third country, save where required by law — in which case it shall inform the Organization unless prohibited from doing so;
- guarantee confidentiality: persons authorised to process the data are bound by an obligation of confidentiality;
- implement the security measures of Article 32 GDPR: encryption in transit and at rest, per-organization isolation enforced at database level and tested automatically, logging, secrets management, backups;
- assist the Organization, so far as possible, in responding to requests from Data Subjects exercising their rights and in meeting its obligations under Articles 32 to 36 GDPR;
- notify the Organization of any data breach affecting it as soon as possible after becoming aware of it;
- at the end of the contract, delete the data or return it through the export functions, at the Organization's choice, and then destroy the copies (subject to statutory retention obligations);
- make available the information necessary to demonstrate its compliance and allow for reasonable audits (at most once a year, on thirty days' notice, at the Organization's expense, without access to other organizations' data);
- immediately inform the Organization if, in its opinion, an instruction infringes the GDPR or other data protection provisions.
4. Sub-processors
The Organization gives general authorisation for the use of the sub-processors listed in the Privacy policy, §5. The Publisher shall give notice of any addition or replacement at least thirty (30) days in advance; the Organization may object on legitimate grounds — failing agreement, it may terminate and export its data. The Publisher imposes on its sub-processors obligations equivalent to those set out herein and remains liable for their failures.
They include the provider of the assistant's artificial intelligence models: Mistral AI (France, European Union). The following are transmitted to it for the duration of the processing: the text the user dictates or types; the inventory context relevant to the answer; the list of the organization's inventories (title, status, number of lots) and, when the assistant looks for a report, the list of reports (title, location, status); the client records the assistant looks up, creates or edits (name, contact details, addresses, date of birth); and, when a report (constat) is open in the assistant or the observations of one of its rooms are reworded, its content (title, type and location, rooms, observations and transcribed text of the dictations, annex labels, names and roles of the parties). No photograph is transmitted to it.
5. Transfers outside the EU
Framed by the EU–United States adequacy decision (Data Privacy Framework) where the recipient is certified under it and, failing that, by the European Commission's standard contractual clauses (see Privacy policy, §6).
6. Obligations of the Organization
The Organization warrants that it has a legal basis for the data it uploads to the Service and that it provides Data Subjects with the required information (Articles 13 and 14 GDPR), mentioning the use of a digital inventory tool, its sub-processors, and the improvement and training processing described in section 4 of the Privacy policy, for which the Publisher acts as a separate controller. It configures the roles and access rights of its Members and remains responsible for compliance with its own professional secrecy obligations.