Makli ← Back to makli.com

Legal

Data Processing Agreement and Standard Contractual Clauses

Last updated: 23 September 2026 · Provonic, 172 Stamford Street, Manchester, United Kingdom

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Provonic (“Makli”, the “Processor”) and the customer (the “Controller”). It applies whenever Makli processes personal data on the customer’s behalf, and incorporates the transfer mechanisms in section 9. A countersigned copy is available on request.

Roles and scope

The customer is the controller of the personal data held in the helpdesk, billing and control-panel systems it connects to Makli, and of any other personal data it instructs Makli to process. Makli is the processor and will process that data only to provide the service and as documented in the Terms, this DPA and the customer’s configuration of the service. The customer’s configuration — which systems are connected and which actions are enabled — constitutes its documented instructions.

Details of the processing

Subject matterAutomated handling of customer-support tickets and chats and the account actions needed to resolve them.
DurationThe term of the customer’s subscription, plus the deletion period in section 11.
Nature and purposeReading tickets and connected account data; generating replies; performing actions the controller has enabled (for example changing PHP settings, updating DNS, issuing refunds within policy); recording an audit log; preparing drafts for the controller’s staff.
Categories of data subjectsThe controller’s customers and their end users; the controller’s staff who use Makli.
Categories of personal dataNames, email addresses and other contact details; account, service, domain and billing information; the content of tickets, chats and attachments; technical data such as IP addresses and server settings. Special-category data is not sought and is processed only where it appears in ticket content.

Processor obligations

Makli will:

Controller obligations

The controller is responsible for the lawfulness of the personal data it makes available to Makli, for providing any notices and obtaining any consents required from its own customers and end users, for the instructions it gives — including which actions it enables — and for reviewing Makli’s drafts and audit logs.

Confidentiality of personnel

Makli restricts access to personal data to personnel who need it to provide the service, requires them to keep it confidential, and logs their access.

Sub-processors

The controller gives Makli general authorisation to engage sub-processors for hosting, AI model inference, email delivery and payment processing. Makli maintains a list of current sub-processors and will supply it on request to sam@makli.com. Makli will give the controller at least 30 days’ notice before adding or replacing a sub-processor; the controller may object on reasonable data-protection grounds within that period, and if the parties cannot resolve the objection the controller may terminate the affected service without penalty. Makli imposes data-protection obligations on each sub-processor equivalent to those in this DPA and remains liable for their performance.

Security measures

Makli implements and maintains at least the following measures, and will not reduce them during the term:

Audits and information

On written request, and no more than once a year unless required by a supervisory authority or following a personal data breach, Makli will make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of its most recent third-party audit reports. Where that information is insufficient, the controller or an independent auditor bound by confidentiality may audit Makli’s relevant processing on reasonable notice, during business hours and without unreasonable disruption.

International transfers

Makli is established in the United Kingdom. Where Makli or a sub-processor transfers personal data to a country without an adequacy decision, the parties rely on the following, which are incorporated into this DPA by reference:

Makli will carry out and document transfer risk assessments where required and apply supplementary measures where necessary.

Personal data breaches

Makli will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data, and will provide the information reasonably available to help the controller meet its own notification obligations, including the nature of the breach, the categories and approximate numbers of data subjects and records affected, the likely consequences, and the measures taken or proposed.

Deletion and return

On termination or expiry of the service, Makli will, at the controller’s choice, return the controller’s personal data in a commonly used format or delete it, and will delete existing copies within 90 days unless UK or EU law requires longer retention. Connected third-party systems remain the controller’s own and are unaffected.

Data-subject requests

If Makli receives a request from a data subject relating to personal data it processes for the controller, it will not respond on the merits but will promptly forward the request to the controller and assist as described in section 3.

Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails on matters of data protection. If the Standard Contractual Clauses or UK transfer instruments conflict with this DPA, those instruments prevail.

Governing law

This DPA is governed by the laws of England and Wales, except that the Standard Contractual Clauses and UK transfer instruments are governed as provided within them.

Obtaining a signed copy

Customers who need a countersigned DPA, or executed transfer clauses with their details completed, can request them from sam@makli.com. Provonic, 172 Stamford Street, Manchester, United Kingdom.