GDPR Compliance
Last updated: September 2026
Our commitment
GDPR compliance is a baseline requirement of the Marketplay platform. All handling of client-provided customer data follows the practices described below.
Roles
Your agency is the data controller for the customer data you import on behalf of your clients. Marketplay acts as processor, generating and maintaining digital twins on your instructions and for your account only.
Lawful bases
Processing is based on performance of the contract with your agency, legitimate interests in operating and securing the platform, and consent where applicable. Responsibility for the lawful basis of the underlying client data rests with the agency that imports it.
Data subject rights
End customers whose data appears in imported datasets may exercise access, rectification, erasure, restriction, and portability rights through the agency controlling that data. Erasure requests are handled through Marketplay support, including permanent deletion of personas and their source data.
Hard client isolation
Each client’s imported data and generated personas are isolated from every other client at the database and access-control level. The sole cross-client feature is the persona reuse suggestion you explicitly trigger, which names the source client.
International transfers
Data is processed within the European Economic Area or in jurisdictions with an adequacy decision. If this changes, we will provide appropriate safeguards and update this page.
Security measures
We apply access controls, encryption in transit, and per-client data partitioning. Access to client data is limited to what is required to operate the service.
Data processing agreement
Standard data processing terms are available on request. For the current product phase, no additional heavyweight data-processing-agreement step is required at client creation; responsibility for having rights to imported data rests with the agency, per our Terms of Service.
Contact
Privacy and compliance questions: contact@marketplay.cloud.