Terms of Service

Version 1Effective July 7, 2025

Effective date: 2026-05-12

These Terms of Service ("Terms") govern your access to and use of the Martez service. Please read them carefully. By creating an account, connecting a third-party account, or otherwise using the Service, you agree to be bound by these Terms.

1. Parties

These Terms are entered into between:

  • Martez — operated as a sole proprietorship by Raphael Kagermeier, doing business as Performromance, Neubaugasse 24, 8020 Graz, Austria, VAT ID ATU76150157, email office@performromance.com, phone +43 680 2200968 ("Martez", "we", "us", "our"); and
  • the legal entity or individual that registers for or uses the Service ("Customer", "you", "your").

An individual person who accesses the Service under a Customer account is referred to as a "User".

Incorporation of the Data Processing Agreement

The Data Processing Agreement attached to these Terms as Annex 1 (the "DPA") forms an integral part of these Terms and applies automatically to every Customer to the extent Martez processes Personal Data on Customer's behalf. No separate signature is required. In the event of any conflict between the body of these Terms and Annex 1 on any matter relating to the Processing of Personal Data, Annex 1 prevails. Capitalized data-protection terms used in these Terms and not otherwise defined have the meaning given in the DPA or, failing that, in the EU GDPR.

2. Definitions

| Term | Meaning |
|---|---|
| Service | The Martez marketing-intelligence software-as-a-service offering, including the web application, APIs, integrations, and related documentation. |
| Customer Data | All data, content, and information that Customer or its Users submit to, generate within, or import into the Service, including data ingested from Third-Party Platforms on Customer's instruction. |
| Third-Party Platform | Any external service or platform — for example, Google Ads, Meta Ads, Matomo, Digistore24, KlickTipp — that the Customer connects to the Service to import data. |
| Connected Account | An account on a Third-Party Platform that Customer has authorized the Service to access on Customer's behalf, including via OAuth. |
| Project | A tenant boundary inside the Service. Customer Data, integrations, and User access permissions are scoped to a Project. |

3. Account registration and authentication

3.1. To use the Service, Customer must register an account and provide accurate, current, and complete information, and keep that information up to date.

3.2. Customer is responsible for safeguarding credentials and for all activity that occurs under its account, including the actions of its Users.

3.3. The Service is organized into Projects. Each Project is a separate tenant. Data, integrations, and permissions are isolated per Project. User-level access is granted by adding a User to one or more Projects.

3.4. Customer must notify us promptly at office@performromance.com if it suspects any unauthorized access or use of the account.

4. The Service

Martez is a marketing-intelligence platform that ingests data from Third-Party Platforms that Customer connects, and provides analytics, attribution modelling, cost allocation (including the Dynamic ACpCT model), and return-on-ad-spend reporting on the basis of that data. The Service is delivered remotely as a hosted application.

5. Third-Party Platforms

5.1. Customer relationship with each Third-Party Platform. Customer is solely responsible for its relationship with each Third-Party Platform, including compliance with that platform's terms, having the rights to access the data Customer instructs the Service to import, and any fees the Third-Party Platform charges.

5.2. Google Ads. If you connect a Google Ads account to the Service, you agree to be bound by the Google Terms of Service and acknowledge the Google Privacy Policy. The Service's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data only to provide the features you have requested. We do not use Google user data for advertising. We do not sell Google user data. We do not transfer Google user data to third parties except as necessary to operate or improve the Service in compliance with Google's policies, for legal compliance, or with your explicit consent. We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.

5.3. Revocation. You may revoke the Service's access to your Google account at any time from your Google Account permissions page at https://myaccount.google.com/permissions, or by disconnecting the integration from inside the Service. When you disconnect, we revoke the associated OAuth refresh and access tokens and delete them from our records as described in our Privacy Policy.

5.4. No warranty as to Third-Party Platforms. Third-Party Platforms are not under our control. We do not warrant the accuracy, availability, completeness, or timeliness of any data made available through a Third-Party Platform, and we are not responsible for outages, rate limits, schema changes, or other behaviour of any Third-Party Platform. Charges that any Third-Party Platform levies on Customer are Customer's responsibility.

6. Customer Data

6.1. Ownership. As between the parties, Customer owns all right, title, and interest, including all intellectual property rights, in and to Customer Data. Nothing in these Terms transfers ownership of Customer Data to Martez.

6.2. Accuracy. Customer is responsible for the accuracy, quality, legality, and appropriateness of Customer Data, and for having all rights and lawful bases necessary to make Customer Data available to Martez through the Service.

6.3. Limited licence to Martez. Customer grants Martez a worldwide, non-exclusive, royalty-free licence to host, store, copy, process, transmit, display, and otherwise use Customer Data solely as required to: (a) provide and maintain the Service for Customer; (b) prevent or address technical or security issues; (c) comply with legal obligations; and (d) produce aggregated, de-identified statistical information that does not identify Customer, any User, or any individual.

6.4. No training of third-party AI. We do not use Customer Data to develop, improve, train, or fine-tune any generalized or non-personalized AI or machine-learning models, whether operated by us or by any third party.

6.5. Personal data. The processing of personal data contained in Customer Data is governed by the Privacy Policy and, where applicable, a separate Data Processing Agreement.

7. Acceptable use

Customer and its Users shall not, and shall not permit any third party to:

  1. reverse-engineer, decompile, or attempt to derive the source code, models, or underlying ideas of the Service, except to the extent applicable mandatory law expressly permits;
  2. circumvent or attempt to circumvent any access controls, rate limits, or security mechanisms of the Service;
  3. scrape, harvest, or systematically extract data from the Service other than through documented features or APIs;
  4. use the Service to build, train, or benchmark a product that competes with the Service;
  5. resell, sublicense, or provide the Service to a third party except for use by Customer's Users for Customer's internal business purposes;
  6. upload, transmit, or store within the Service any content that is unlawful, defamatory, infringing, malicious, or that contains viruses, worms, or other harmful code;
  7. use the Service to process special categories of personal data under Article 9 GDPR (including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data, or data concerning a natural person's sex life or sexual orientation), payment-card data subject to PCI DSS, or government-issued identification numbers;
  8. use the Service from, or for the benefit of any party located in, any country or territory subject to comprehensive EU or US economic sanctions or embargoes;
  9. interfere with or disrupt the integrity or performance of the Service, including by submitting workloads that materially exceed normal usage patterns.

A material breach of this section is grounds for immediate suspension or termination under section 14.

8. Fees and billing

8.1. Fees, billing cycles, payment methods, and applicable taxes are set out in the order form or pricing page in effect at the time of subscription. Unless stated otherwise, fees are stated exclusive of VAT, which will be added where applicable.

8.2. Invoices are payable within the period stated on the invoice. Overdue amounts accrue statutory default interest under Austrian law.

8.3. Except where mandatory consumer law requires otherwise, fees are non-refundable once paid.

9. Service availability

9.1. We provide the Service on a commercially reasonable, best-effort basis. No specific uptime or service-level commitment is offered at this stage.

9.2. We may carry out planned maintenance from time to time and will make reasonable efforts to schedule disruptive maintenance outside ordinary business hours in Central European Time.

9.3. The Service depends on Third-Party Platforms and other upstream services. Availability or behaviour of the Service may be impacted by outages, rate limits, schema changes, or other actions of Third-Party Platforms that are outside our control. Such impacts are not a breach of these Terms.

10. Warranties and disclaimers

10.1. We warrant that we will provide the Service with reasonable care and skill consistent with prevailing industry standards for comparable software-as-a-service offerings.

10.2. EXCEPT AS EXPRESSLY SET OUT IN THESE TERMS, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE". TO THE FULLEST EXTENT PERMITTED BY LAW, MARTEZ DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, OR THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, OR THAT IT WILL PRODUCE ANY PARTICULAR RESULT.

10.3. The Service produces analytical estimates (including attribution and cost-allocation outputs such as the Dynamic ACpCT model) based on data Customer connects. These outputs are decision-support information, not guarantees of commercial outcomes. Customer is responsible for its own business decisions.

11. Limitation of liability

11.1. Excluded damages. To the fullest extent permitted by law, neither party will be liable to the other for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, loss of goodwill, business interruption, or loss or corruption of data, arising out of or related to these Terms or the Service, whether in contract, tort (including negligence), statutory duty, or otherwise, and whether or not the party was advised of the possibility of such damages.

11.2. Aggregate cap. Each party's total aggregate liability arising out of or related to these Terms in any twelve-month period will not exceed one hundred per cent (100%) of the fees paid by Customer to Martez during the twelve months immediately preceding the event giving rise to the liability.

11.3. Free use. Where any portion of the Service is provided to Customer free of charge (including any free tier, evaluation, beta, or trial offering Martez may from time to time make available), Martez's aggregate liability arising out of or related to that portion of the Service shall not exceed one hundred euros (EUR 100). Nothing in this section obliges Martez to offer any portion of the Service free of charge.

11.4. Carve-outs. Nothing in these Terms limits or excludes either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) gross negligence or willful misconduct; (d) Customer's payment obligations; (e) either party's indemnification obligations under section 12; or (f) any other liability that cannot be limited or excluded under mandatory applicable law.

11.5. Consumers. If Customer is a consumer within the meaning of the Austrian Consumer Protection Act (KSchG), the limitations and exclusions in this section apply only to the extent permitted by mandatory consumer-protection law. Mandatory consumer rights remain unaffected.

12. Indemnification

12.1. By Martez. Martez will defend Customer against any third-party claim alleging that the Service, as provided by Martez and used in accordance with these Terms, infringes such third party's intellectual property rights, and will pay damages and reasonable costs finally awarded against Customer by a court of competent jurisdiction or agreed in settlement. This obligation does not apply to claims arising from: (a) Customer Data; (b) use of the Service in combination with materials not provided by Martez where the claim would not have arisen but for such combination; (c) modifications to the Service not made by Martez; or (d) use of the Service in breach of these Terms.

12.2. By Customer. Customer will defend Martez against any third-party claim arising out of or related to: (a) Customer Data, including any claim that Customer Data infringes a third party's rights or violates applicable law; or (b) Customer's breach of section 7 (Acceptable use), and will pay damages and reasonable costs finally awarded against Martez by a court of competent jurisdiction or agreed in settlement.

12.3. Procedure. The indemnified party will (i) promptly notify the indemnifying party of the claim, (ii) give the indemnifying party sole control of the defence and settlement (provided no settlement admits fault or imposes non-monetary obligations on the indemnified party without its consent), and (iii) provide reasonable cooperation at the indemnifying party's expense.

13. Confidentiality

13.1. "Confidential Information" means non-public information disclosed by one party to the other that is identified as confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. Customer Data is Customer's Confidential Information.

13.2. The receiving party will: (a) use Confidential Information only to perform its obligations or exercise its rights under these Terms; (b) protect Confidential Information with at least the same degree of care it uses for its own confidential information, and in no event less than reasonable care; and (c) not disclose Confidential Information to any third party except to its employees, contractors, and agents who need to know it and who are bound by confidentiality obligations no less protective than those in this section.

13.3. Confidential Information does not include information that is or becomes publicly available without breach, is independently developed without use of the other party's Confidential Information, or is rightfully received from a third party without a duty of confidentiality. The receiving party may disclose Confidential Information to the extent required by law, provided it gives the disclosing party reasonable prior notice where lawful.

14. Term and termination

14.1. Term. These Terms apply from the date Customer first accepts them and continue for so long as Customer holds an account with the Service, unless terminated as set out below.

14.2. Termination for convenience. Customer may terminate at any time by closing its account and ceasing use of the Service. We may terminate any free account for convenience on thirty (30) days' notice.

14.3. Termination for cause. Either party may terminate these Terms immediately on written notice if the other party: (a) commits a material breach that is not cured within thirty (30) days of written notice of the breach; or (b) becomes insolvent, files for or has filed against it any petition under any insolvency law that is not dismissed within sixty (60) days, makes a general assignment for the benefit of creditors, or ceases business operations.

14.4. Immediate termination. We may suspend or terminate Customer's access immediately and without prior notice if Customer materially breaches section 5.2 (Google Ads binding), section 7 (Acceptable use), or infringes our or a third party's intellectual property rights.

14.5. Effect of termination. On termination, all rights granted to Customer under these Terms cease. Sections that by their nature should survive (including sections 6.1, 10, 11, 12, 13, 15, 19, and 20) survive termination.

15. Data handling on termination

15.1. Tokens. OAuth access and refresh tokens for any Connected Account are revoked and deleted from our records immediately on disconnect of the integration or on termination of these Terms. For deletion of Google-derived data on disconnect of a Google Ads integration, or in response to a written deletion request from a Data Subject, see Privacy Policy §3.7 and §9.

15.2. Retrieval window. For thirty (30) days after termination, Customer may request export of Customer Data in a commonly used format. After this thirty-day window, we will delete or anonymize Customer Data from active production systems within a further thirty (30) days, so that complete purge from active systems occurs within sixty (60) days of termination.

15.3. Backups. Customer Data may persist in routine encrypted backups after deletion from active systems. Backups are retained per our documented backup-retention schedule and are then purged. Pending such purge, Customer Data in backups remains subject to the confidentiality and security obligations of these Terms and is not actively processed.

15.4. Legal-hold exception. We may retain Customer Data beyond the periods above to the extent required by applicable law or to defend, exercise, or establish legal claims, in which case the data continues to be protected as described above and is processed only for those purposes.

16. Changes to these Terms

16.1. We may update these Terms from time to time. The current version is always available at the same URL as these Terms with an updated effective date.

16.2. For material changes, we will give at least thirty (30) days' prior notice by email to the administrator address on the account and by a banner inside the Service. Continued use of the Service after the effective date of a change constitutes acceptance of the updated Terms.

16.3. If Customer does not accept a material change, Customer's sole remedy is to terminate under section 14.2 before the change takes effect. We will refund any pre-paid fees covering the period after termination on a pro-rata basis.

17. Changes to the Service

17.1. We continuously improve the Service. We may add, change, or remove features at any time. For material removals of features that Customer is actively using, we will give reasonable prior notice through the Service or by email.

17.2. Beta or preview features may be offered separately and are provided "as is" without warranty of any kind.

18. Notices, assignment, miscellaneous

18.1. Notices. Notices to Martez must be sent to office@performromance.com or to the postal address in section 1. Notices to Customer are sent to the administrator email address on the account.

18.2. Assignment. Customer may not assign or transfer these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, on notice to Customer.

18.3. No partnership. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties.

18.4. Force majeure. Neither party is liable for failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control, including acts of God, war, terrorism, civil unrest, governmental actions, labour disputes, internet or telecommunications failures, or failures of upstream Third-Party Platforms.

18.5. Severability and waiver. If any provision of these Terms is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be replaced by an enforceable provision that comes closest to the parties' original intent. Failure to enforce any right is not a waiver of that right.

18.6. Entire agreement. These Terms, together with the Privacy Policy and any order form or written agreement signed by the parties, constitute the entire agreement between the parties on the subject matter and supersede any prior agreements or understandings.

19. Governing law and venue

19.1. These Terms and any dispute or claim arising out of or in connection with them are governed by the substantive laws of the Republic of Austria, excluding its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG).

19.2. For disputes between businesses (B2B), the parties submit to the exclusive jurisdiction of the courts competent for 8010 Graz, Austria.

19.3. If Customer is a consumer with habitual residence in the European Union, mandatory consumer protection rules of the law of Customer's country of residence remain unaffected, and the choice of venue in section 19.2 does not deprive Customer of jurisdiction it has under those mandatory rules.

19.4. The European Commission provides an online dispute resolution platform at https://ec.europa.eu/consumers/odr. We are not obliged and not willing to participate in dispute-resolution proceedings before a consumer arbitration board.

20. Contact

For questions about these Terms, please contact:

Raphael Kagermeier (dba Performromance)
Neubaugasse 24, 8020 Graz, Austria
Email: office@performromance.com
Phone: +43 680 2200968
VAT ID: ATU76150157


Annex 1 — Data Processing Agreement

Effective date: 2026-05-12
Version: 1.0

This Data Processing Agreement ("DPA") forms an integral part of, and is incorporated by reference into, the Martez Terms of Service (the "Terms") between Martez and Customer. It governs the Processing of Personal Data by Martez on Customer's behalf in the course of providing the Service. Where the body of the Terms and this DPA conflict on any matter relating to the Processing of Personal Data, this DPA prevails.

This DPA applies automatically to every Customer; no separate signature is required.

A1.1 Definitions

A1.1.1. Capitalized data-protection terms used in this DPA — including "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" — have the meanings given in Article 4 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and are adopted into this DPA by reference.

A1.1.2. "Applicable Data Protection Law" means the GDPR, the EU ePrivacy Directive 2002/58/EC as transposed into national law, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and any other data-protection or privacy law applicable to the Processing under this DPA.

A1.1.3. "EU SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

A1.1.4. "Sub-processor" means any Processor engaged by Martez to Process Personal Data in connection with the Service.

A1.1.5. "Customer Personal Data" means Personal Data contained in Customer Data that Martez Processes on Customer's behalf in providing the Service.

A1.1.6. Other capitalized terms used in this DPA have the meaning given in the Terms.

A1.2 Roles and responsibilities

A1.2.1. Customer is Controller. With respect to Customer Personal Data, Customer is the Controller (or, where applicable, a Joint Controller or Processor acting on behalf of its own customers, in which case Customer warrants that it has the authority to instruct Martez under this DPA). Martez is Customer's Processor.

A1.2.2. Martez is Controller for limited purposes. Notwithstanding section A1.2.1, Martez is the Controller of Personal Data it Processes about Customer's own Users (account holders, administrators, billing contacts) for the purposes of authenticating Users, administering the account, billing, communicating about the Service, and complying with Martez's own legal obligations. The Processing of such data is described in the Privacy Policy and is not governed by this DPA.

A1.2.3. Compliance responsibility. Each party is responsible for its own compliance with Applicable Data Protection Law in respect of its role.

A1.3 Scope, subject matter, nature, purpose, duration

A1.3.1. Subject matter. Martez Processes Customer Personal Data solely to provide the Service to Customer in accordance with the Terms.

A1.3.2. Nature and purpose. The Processing is described in Annex I to this DPA.

A1.3.3. Duration. Martez Processes Customer Personal Data for the term of the Customer's subscription to the Service plus the additional retrieval and deletion periods set out in section A1.13.

A1.3.4. Categories of Data Subjects and Personal Data. Set out in Annex I to this DPA.

A1.4 Customer instructions

A1.4.1. Documented instructions. Martez Processes Customer Personal Data only on the documented instructions of Customer, including with regard to transfers of Personal Data to a third country or an international organization, unless Martez is required to do so by Union or Member State law to which Martez is subject. In such a case, Martez will inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.

A1.4.2. Form of instructions. Customer's instructions are set out in the Terms, this DPA, the Privacy Policy, the Service configuration (including the integrations Customer activates and the data sources Customer connects), and any subsequent written instruction Customer gives to office@performromance.com. Customer's use of the Service constitutes an instruction to Martez to Process Customer Personal Data in accordance with the Service's documented functionality.

A1.4.3. Unlawful instructions. If Martez believes an instruction infringes Applicable Data Protection Law, it will notify Customer without undue delay and may suspend execution of the instruction.

A1.5 Confidentiality

A1.5.1. Martez ensures that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality. Confidentiality survives termination of personnel engagements.

A1.5.2. Access to Customer Personal Data is limited to personnel who need access to perform the Service.

A1.6 Security

A1.6.1. Martez implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures are described in Annex II — Technical and Organizational Measures (TOMs) to this DPA and include, at minimum: encryption of Customer Personal Data at rest and in transit; access controls and tenancy isolation; logging and monitoring; backup; personnel training; and incident response.

A1.6.2. Martez reviews the TOMs at least annually and may update them, provided that the overall level of protection is not materially reduced.

A1.7 Sub-processors

A1.7.1. General authorization. Customer grants Martez a general authorization to engage Sub-processors to Process Customer Personal Data in connection with the Service. The Sub-processors engaged as of the effective date of this DPA are listed in Annex III — Approved Sub-processors to this DPA.

A1.7.2. Notice of changes. Martez will give Customer at least thirty (30) days' prior notice of the intended addition or replacement of a Sub-processor that Processes Customer Personal Data. Notice is given by (a) updating Annex III at the published URL of this DPA and (b) email notification to the administrator email address on Customer's account where Customer has subscribed to sub-processor change notifications.

A1.7.3. Right to object. Customer may object to the addition or replacement of a Sub-processor on reasonable data-protection grounds by written notice to office@performromance.com within the 30-day notice period. The parties will work together in good faith to address Customer's concerns. If no resolution is reached, Customer may terminate the affected portion of the Service with a pro-rated refund of any pre-paid fees covering the period after termination.

A1.7.4. Flow-down. Martez imposes, by written contract, data-protection obligations on each Sub-processor that are no less protective than those in this DPA and that meet the requirements of Article 28(4) GDPR. Martez remains fully liable to Customer for the performance of its Sub-processors' obligations.

A1.8 Data Subject requests

A1.8.1. Martez will, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as possible, for the fulfilment of Customer's obligation to respond to requests for exercising Data Subjects' rights under Chapter III GDPR.

A1.8.2. If Martez receives a request from a Data Subject directly in respect of Customer Personal Data, Martez will, without undue delay, forward the request to Customer's administrator and will not respond to the request itself except on Customer's documented instructions or as required by law.

A1.9 Personal Data Breach notification

A1.9.1. Martez notifies Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within forty-eight (48) hours of becoming aware of the breach. This timeframe is intentionally tighter than the 72-hour Controller obligation in Article 33 GDPR to give Customer sufficient lead time to fulfil its own notification duties.

A1.9.2. The notification includes, to the extent then known: (a) the nature of the breach, including, where possible, the categories and approximate numbers of Data Subjects and of records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its adverse effects; and (d) a single point of contact at Martez. Where, and to the extent that, it is not possible to provide the information at the same time, the information may be provided in phases without further undue delay.

A1.9.3. Martez will document each Personal Data Breach and the remedial action taken, and provide that documentation to Customer on request.

A1.10 DPIAs and prior consultation

Martez will, taking into account the nature of the Processing and the information available to it, provide reasonable assistance to Customer with data-protection impact assessments (Article 35 GDPR) and prior consultations with Supervisory Authorities (Article 36 GDPR) where required.

A1.11 International transfers

A1.11.1. EU/EEA transfers. Where Martez transfers Customer Personal Data from the EEA to a Sub-processor in a country that has not been the subject of an adequacy decision by the European Commission under Article 45 GDPR, the parties incorporate the EU SCCs, Module 2 (Controller-to-Processor) by reference. Customer (or its controller, where Customer is itself a Processor) is the data exporter; the recipient Sub-processor is the data importer. Martez acts as Customer's data importer where Martez itself receives Personal Data outside the EEA, and as facilitator in all other cases.

A1.11.2. SCC docking and choices. Where the EU SCCs apply by virtue of section A1.11.1: (a) Clause 7 (Docking clause) is included; (b) Clause 9 Option 2 (general authorization for Sub-processors) applies, with the 30-day notice period in section A1.7.2 of this DPA; (c) Clause 11(a) (independent dispute resolution body) is not opted in; (d) the supervisory authority under Clause 13 is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde); (e) the governing law under Clause 17 (Option 1) is the law of the Republic of Austria; (f) the forum under Clause 18 is the courts of Graz, Austria. Annexes I.A, I.B, I.C, II and III to the EU SCCs are populated by Annexes I, II and III to this DPA respectively.

A1.11.3. UK transfers. Where Customer Personal Data is subject to the UK GDPR, the UK International Data Transfer Addendum ("UK IDTA") to the EU SCCs (issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018) is incorporated by reference, with the EU SCCs forming the Approved EU SCCs under the IDTA. The competent authority is the UK Information Commissioner's Office.

A1.11.4. Swiss transfers. Where Customer Personal Data is subject to the Swiss FADP, the EU SCCs apply with the following adaptations consistent with the Swiss Federal Data Protection and Information Commissioner's guidance: references to the GDPR are read as references to the FADP where appropriate; the competent authority is the Swiss FDPIC; and the term "Member State" is read so as not to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.

A1.12 Audit rights

A1.12.1. Customer may, no more than once every twenty-four (24) months, audit Martez's compliance with this DPA. The once-per-24-months frequency limit does not apply to (a) audits required by a competent Supervisory Authority, (b) audits in response to a confirmed Personal Data Breach, or (c) any audit the Customer is itself obliged to perform under Article 28(3)(h) GDPR in connection with a documented controller-side investigation. The 30-day prior-notice requirement is waived in cases (a) and (b).

A1.12.2. Customer must give Martez at least thirty (30) days' prior written notice of an audit, and must conduct the audit in a manner that does not unreasonably interfere with Martez's business operations. The auditor must agree in writing to reasonable confidentiality obligations before being given access.

A1.12.3. Third-party reports. Martez may satisfy its audit obligations under this DPA by making available to Customer relevant third-party audit reports (for example, AWS SOC 2 or ISO 27001 reports covering the underlying infrastructure), penetration-test summaries, and Martez's own security documentation, where these reasonably address the matters Customer wishes to audit.

A1.12.4. Costs. Each party bears its own costs of the audit. If the audit reveals a material breach by Martez of this DPA, Martez will reimburse Customer's reasonable audit costs.

A1.13 Return and deletion

A1.13.1. Customer election. On termination of the Terms or earlier on Customer's written request, Customer may elect, by written notice to office@performromance.com within thirty (30) days of termination, to have Martez (a) return Customer Personal Data to Customer in a commonly used machine-readable format, or (b) destroy Customer Personal Data.

A1.13.2. Default. If Customer makes no election within the thirty (30) day window, Martez will destroy Customer Personal Data within a further thirty (30) days.

A1.13.3. Backups. Customer Personal Data may persist in routine encrypted backups after deletion from active systems. Backups are retained per the schedule set out in Annex II to this DPA and are then purged. Pending such purge, Customer Personal Data in backups remains subject to the confidentiality and security obligations of this DPA and is not actively Processed.

A1.13.4. Legal-hold exception. Martez may retain Customer Personal Data beyond the periods above to the extent required by Union or Member State law, in which case the data continues to be protected as described above and is Processed only for those purposes.

A1.14 Liability

A1.14.1. Each party's liability under this DPA is subject to the limitation and exclusion provisions of the Terms, including section 11 (Limitation of liability) of the Terms.

A1.14.2. Notwithstanding section A1.14.1, where liability under this DPA arises out of or in connection with the Processing of Personal Data, the aggregate cap in section 11.2 of the Terms is doubled with respect to claims under this DPA, so that the aggregate cap is two hundred per cent (200%) of the fees paid by Customer to Martez during the twelve months immediately preceding the event giving rise to the liability. The carve-outs in section 11.4 of the Terms remain in full effect.

A1.15 Governing law and venue

A1.15.1. This DPA is governed by the substantive laws of the Republic of Austria, excluding its conflict-of-laws rules and excluding the UN Convention on Contracts for the International Sale of Goods (CISG).

A1.15.2. The parties submit to the exclusive jurisdiction of the courts competent for 8010 Graz, Austria, subject to the mandatory consumer-protection rules referenced in section 19.3 of the Terms.

A1.15.3. The choice of law and venue in this section A1.15 is without prejudice to the governing law and venue provisions of the EU SCCs, the UK IDTA, or any Swiss equivalent, where these apply by virtue of section A1.11.

A1.16 Miscellaneous

A1.16.1. Save as expressly amended by this DPA, the Terms remain in full force and effect.

A1.16.2. If any provision of this DPA is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be replaced by an enforceable provision that comes closest to the parties' original intent.


Annex I to the DPA — Subject Matter, Nature, Purpose and Duration of the Processing; Categories of Data Subjects and Personal Data

A. Subject matter and duration

The subject matter of the Processing is Martez's provision of the marketing-intelligence Service to Customer in accordance with the Terms, including ingestion of data from Third-Party Platforms that Customer connects, attribution modelling, cost-allocation (including the Dynamic ACpCT model), and return-on-ad-spend reporting.

The duration of the Processing is the term of Customer's subscription to the Service plus the retrieval and deletion periods in section A1.13 of this DPA.

B. Nature and purpose of the Processing

  • Collection, structuring, storage and reorganization of data ingested from the Third-Party Platforms Customer connects;
  • Normalization and enrichment of the ingested data (for example, normalizing cost_micros to spend, joining campaign hierarchies);
  • Attribution modelling, ACpCT/ROAS calculation and reporting;
  • Display of analytical outputs to Users in the Service;
  • Backup and disaster-recovery operations;
  • Security, abuse-prevention, and operational logging.

C. Categories of Data Subjects

  • Customer's own Users (account holders, administrators, billing contacts);
  • End users / website visitors / leads / customers of Customer whose interactions with Customer's marketing properties produce records imported into the Service through the Customer's connected integrations.

D. Categories of Personal Data

The categories vary by integration. Indicatively:

| Integration | Categories of Personal Data |
|---|---|
| Google Ads | Customer-level identifiers (customer ID, descriptive name, currency, time zone), campaign / ad-group / ad metadata (ID, name) and performance metrics (cost_micros, impressions, clicks). Data is aggregated at campaign level and does not, in normal operation, identify individual end users. |
| Meta Ads | Campaign / ad-set / ad metadata, cost, impressions, clicks. |
| Matomo | Visitor IDs (pseudonymous), pageview events, goal/conversion events, UTM parameters, referrer URLs, IP-derived geolocation as configured in the Customer's Matomo instance. |
| Digistore24 | Order/transaction records, payment status, gross/net amounts, and the order metadata returned by the Digistore24 API (may include buyer email and address depending on the Customer's Digistore24 configuration). |
| KlickTipp | Subscriber identifiers, tag/list membership, event timestamps, and other subscriber attributes returned by the KlickTipp API. |
| Account-holder data (Martez as Processor on Customer's instruction, e.g. inviting team members) | Name, email address, role/permissions. |

E. Sensitive data

Customer agrees not to use the Service to Process special categories of Personal Data under Article 9 GDPR, payment-card data subject to PCI DSS, or government-issued identification numbers. See section 7 of the Terms.

F. Frequency of the Processing

Continuous (synchronous) for User-initiated reads and writes; periodic (typically daily) for integration syncs.


Annex II to the DPA — Technical and Organizational Measures (TOMs)

The following measures are in force as of the effective date of this DPA. Martez may update them from time to time, provided the overall level of protection is not materially reduced.

II.1 Encryption

  • In transit. TLS 1.2 or higher is enforced for all connections to the Service, between the Service and its sub-processors, and between the Service and the Third-Party Platform APIs it calls.
  • At rest. OAuth tokens and other sensitive integration credentials are encrypted at the application layer using Laravel's encrypted casts, keyed by the application's APP_KEY. The underlying database (AWS RDS PostgreSQL) and object storage (AWS S3) volumes are encrypted at rest by AWS (AES-256).

II.2 Access control and authentication

  • Role-based access control inside the Service; project-level tenancy scoping enforced at the ORM and query layer.
  • Production database and infrastructure access is restricted to the operator and authorized maintainers, over SSH/IAM, with multi-factor authentication required.
  • Principle of least privilege; access reviews are performed at least annually.

II.3 Tenancy isolation

  • Every record in the Service is scoped to a Martez Project. Cross-project queries are blocked at the ORM (global scope) and database (query-builder) layers.

II.4 Logging and monitoring

  • Application errors are tracked in Sentry (retention 90 days); Lambda execution logs are stored in AWS CloudWatch.
  • Access to production infrastructure is logged at the AWS account level (CloudTrail).
  • Operational alerts are routed to an internal Slack channel.

II.5 Backups, business continuity and disaster recovery

  • Automated, encrypted database backups on a rolling 35-day schedule (AWS RDS automated backups).
  • Backups are periodically tested for restore integrity.
  • The Service runs in AWS eu-central-1 (Frankfurt) using Lambda's multi-AZ execution surface; static assets are delivered via AWS CloudFront with origin failover.

II.6 Software development lifecycle

  • Source code reviewed before deployment.
  • Dependency management with automated security advisories (Dependabot, GitHub security alerts).
  • Operating-system, runtime and library dependencies are patched on a regular cadence; security advisories are reviewed on receipt.

II.7 Personnel

  • All personnel with access to Customer Personal Data are bound by written confidentiality obligations.
  • Annual data-protection and security awareness training.

II.8 Vendor management

  • Sub-processors are listed in Annex III to this DPA, are bound by written data-processing agreements that flow down obligations no less protective than this DPA, and are reviewed periodically.

II.9 Incident response

  • Documented incident-response procedure covering detection, triage, containment, eradication, recovery, and post-incident review.
  • Personal Data Breach notification to Customer within 48 hours of awareness (see DPA section A1.9).

II.10 Certifications

  • Martez has not obtained SOC 2, ISO 27001 or any equivalent third-party certification at the entity level. Underlying infrastructure (AWS, CloudFront) carries the AWS-side certifications published at https://aws.amazon.com/compliance/.

Annex III to the DPA — Approved Sub-processors

This list mirrors Section 7 of the Privacy Policy and is the authoritative list of Sub-processors approved under section A1.7 of this DPA as of the effective date.

| Provider | Role | Hosting region | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS Lambda, RDS PostgreSQL, S3) | Application compute, database, file storage | eu-central-1 (Frankfurt, Germany) | EU hosting; AWS EU Data Boundary; EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) for any incidental support access from outside the EEA |
| Amazon CloudFront | Content delivery network for public static assets | Global edge network | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); no Google user data is served via CDN |
| Resend (Resend.com Inc.) | Transactional email delivery | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) |
| Sentry (Functional Software Inc.) | Application error and exception tracking | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); Google user data is excluded from error payloads |
| Slack Technologies LLC | Internal health-alert notifications | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); only operational metadata (e.g. "sync failed for project X"), no Google user data, is sent |
| Matomo (InnoCraft Ltd. / self-hosted instance) | Marketing-site analytics (consent-gated) and Customer-connectable in-app integration | EU (self-hosted on AWS eu-central-1 for the marketing-site instance; Customer-controlled location for Customer-connected instances) | EU hosting for the marketing-site instance; for Customer-connected instances, the Customer determines the location and any transfer mechanism. EU SCCs (Art. 46 GDPR) apply to any incidental support access from outside the EEA. |

Customer may subscribe to sub-processor change notifications by writing to office@performromance.com.