Version 1 — Effective July 7, 2025
Effective date: 2026-05-12
These Terms of Service ("Terms") govern your access to and use of the Martez service. Please read them carefully. By creating an account, connecting a third-party account, or otherwise using the Service, you agree to be bound by these Terms.
These Terms are entered into between:
An individual person who accesses the Service under a Customer account is referred to as a "User".
The Data Processing Agreement attached to these Terms as Annex 1 (the "DPA") forms an integral part of these Terms and applies automatically to every Customer to the extent Martez processes Personal Data on Customer's behalf. No separate signature is required. In the event of any conflict between the body of these Terms and Annex 1 on any matter relating to the Processing of Personal Data, Annex 1 prevails. Capitalized data-protection terms used in these Terms and not otherwise defined have the meaning given in the DPA or, failing that, in the EU GDPR.
| Term | Meaning |
|---|---|
| Service | The Martez marketing-intelligence software-as-a-service offering, including the web application, APIs, integrations, and related documentation. |
| Customer Data | All data, content, and information that Customer or its Users submit to, generate within, or import into the Service, including data ingested from Third-Party Platforms on Customer's instruction. |
| Third-Party Platform | Any external service or platform — for example, Google Ads, Meta Ads, Matomo, Digistore24, KlickTipp — that the Customer connects to the Service to import data. |
| Connected Account | An account on a Third-Party Platform that Customer has authorized the Service to access on Customer's behalf, including via OAuth. |
| Project | A tenant boundary inside the Service. Customer Data, integrations, and User access permissions are scoped to a Project. |
3.1. To use the Service, Customer must register an account and provide accurate, current, and complete information, and keep that information up to date.
3.2. Customer is responsible for safeguarding credentials and for all activity that occurs under its account, including the actions of its Users.
3.3. The Service is organized into Projects. Each Project is a separate tenant. Data, integrations, and permissions are isolated per Project. User-level access is granted by adding a User to one or more Projects.
3.4. Customer must notify us promptly at office@performromance.com if it suspects any unauthorized access or use of the account.
Martez is a marketing-intelligence platform that ingests data from Third-Party Platforms that Customer connects, and provides analytics, attribution modelling, cost allocation (including the Dynamic ACpCT model), and return-on-ad-spend reporting on the basis of that data. The Service is delivered remotely as a hosted application.
5.1. Customer relationship with each Third-Party Platform. Customer is solely responsible for its relationship with each Third-Party Platform, including compliance with that platform's terms, having the rights to access the data Customer instructs the Service to import, and any fees the Third-Party Platform charges.
5.2. Google Ads. If you connect a Google Ads account to the Service, you agree to be bound by the Google Terms of Service and acknowledge the Google Privacy Policy. The Service's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We access Google user data only to provide the features you have requested. We do not use Google user data for advertising. We do not sell Google user data. We do not transfer Google user data to third parties except as necessary to operate or improve the Service in compliance with Google's policies, for legal compliance, or with your explicit consent. We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
5.3. Revocation. You may revoke the Service's access to your Google account at any time from your Google Account permissions page at https://myaccount.google.com/permissions, or by disconnecting the integration from inside the Service. When you disconnect, we revoke the associated OAuth refresh and access tokens and delete them from our records as described in our Privacy Policy.
5.4. No warranty as to Third-Party Platforms. Third-Party Platforms are not under our control. We do not warrant the accuracy, availability, completeness, or timeliness of any data made available through a Third-Party Platform, and we are not responsible for outages, rate limits, schema changes, or other behaviour of any Third-Party Platform. Charges that any Third-Party Platform levies on Customer are Customer's responsibility.
6.1. Ownership. As between the parties, Customer owns all right, title, and interest, including all intellectual property rights, in and to Customer Data. Nothing in these Terms transfers ownership of Customer Data to Martez.
6.2. Accuracy. Customer is responsible for the accuracy, quality, legality, and appropriateness of Customer Data, and for having all rights and lawful bases necessary to make Customer Data available to Martez through the Service.
6.3. Limited licence to Martez. Customer grants Martez a worldwide, non-exclusive, royalty-free licence to host, store, copy, process, transmit, display, and otherwise use Customer Data solely as required to: (a) provide and maintain the Service for Customer; (b) prevent or address technical or security issues; (c) comply with legal obligations; and (d) produce aggregated, de-identified statistical information that does not identify Customer, any User, or any individual.
6.4. No training of third-party AI. We do not use Customer Data to develop, improve, train, or fine-tune any generalized or non-personalized AI or machine-learning models, whether operated by us or by any third party.
6.5. Personal data. The processing of personal data contained in Customer Data is governed by the Privacy Policy and, where applicable, a separate Data Processing Agreement.
Customer and its Users shall not, and shall not permit any third party to:
A material breach of this section is grounds for immediate suspension or termination under section 14.
8.1. Fees, billing cycles, payment methods, and applicable taxes are set out in the order form or pricing page in effect at the time of subscription. Unless stated otherwise, fees are stated exclusive of VAT, which will be added where applicable.
8.2. Invoices are payable within the period stated on the invoice. Overdue amounts accrue statutory default interest under Austrian law.
8.3. Except where mandatory consumer law requires otherwise, fees are non-refundable once paid.
9.1. We provide the Service on a commercially reasonable, best-effort basis. No specific uptime or service-level commitment is offered at this stage.
9.2. We may carry out planned maintenance from time to time and will make reasonable efforts to schedule disruptive maintenance outside ordinary business hours in Central European Time.
9.3. The Service depends on Third-Party Platforms and other upstream services. Availability or behaviour of the Service may be impacted by outages, rate limits, schema changes, or other actions of Third-Party Platforms that are outside our control. Such impacts are not a breach of these Terms.
10.1. We warrant that we will provide the Service with reasonable care and skill consistent with prevailing industry standards for comparable software-as-a-service offerings.
10.2. EXCEPT AS EXPRESSLY SET OUT IN THESE TERMS, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE". TO THE FULLEST EXTENT PERMITTED BY LAW, MARTEZ DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, OR THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, OR THAT IT WILL PRODUCE ANY PARTICULAR RESULT.
10.3. The Service produces analytical estimates (including attribution and cost-allocation outputs such as the Dynamic ACpCT model) based on data Customer connects. These outputs are decision-support information, not guarantees of commercial outcomes. Customer is responsible for its own business decisions.
11.1. Excluded damages. To the fullest extent permitted by law, neither party will be liable to the other for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, loss of goodwill, business interruption, or loss or corruption of data, arising out of or related to these Terms or the Service, whether in contract, tort (including negligence), statutory duty, or otherwise, and whether or not the party was advised of the possibility of such damages.
11.2. Aggregate cap. Each party's total aggregate liability arising out of or related to these Terms in any twelve-month period will not exceed one hundred per cent (100%) of the fees paid by Customer to Martez during the twelve months immediately preceding the event giving rise to the liability.
11.3. Free use. Where any portion of the Service is provided to Customer free of charge (including any free tier, evaluation, beta, or trial offering Martez may from time to time make available), Martez's aggregate liability arising out of or related to that portion of the Service shall not exceed one hundred euros (EUR 100). Nothing in this section obliges Martez to offer any portion of the Service free of charge.
11.4. Carve-outs. Nothing in these Terms limits or excludes either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) gross negligence or willful misconduct; (d) Customer's payment obligations; (e) either party's indemnification obligations under section 12; or (f) any other liability that cannot be limited or excluded under mandatory applicable law.
11.5. Consumers. If Customer is a consumer within the meaning of the Austrian Consumer Protection Act (KSchG), the limitations and exclusions in this section apply only to the extent permitted by mandatory consumer-protection law. Mandatory consumer rights remain unaffected.
12.1. By Martez. Martez will defend Customer against any third-party claim alleging that the Service, as provided by Martez and used in accordance with these Terms, infringes such third party's intellectual property rights, and will pay damages and reasonable costs finally awarded against Customer by a court of competent jurisdiction or agreed in settlement. This obligation does not apply to claims arising from: (a) Customer Data; (b) use of the Service in combination with materials not provided by Martez where the claim would not have arisen but for such combination; (c) modifications to the Service not made by Martez; or (d) use of the Service in breach of these Terms.
12.2. By Customer. Customer will defend Martez against any third-party claim arising out of or related to: (a) Customer Data, including any claim that Customer Data infringes a third party's rights or violates applicable law; or (b) Customer's breach of section 7 (Acceptable use), and will pay damages and reasonable costs finally awarded against Martez by a court of competent jurisdiction or agreed in settlement.
12.3. Procedure. The indemnified party will (i) promptly notify the indemnifying party of the claim, (ii) give the indemnifying party sole control of the defence and settlement (provided no settlement admits fault or imposes non-monetary obligations on the indemnified party without its consent), and (iii) provide reasonable cooperation at the indemnifying party's expense.
13.1. "Confidential Information" means non-public information disclosed by one party to the other that is identified as confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. Customer Data is Customer's Confidential Information.
13.2. The receiving party will: (a) use Confidential Information only to perform its obligations or exercise its rights under these Terms; (b) protect Confidential Information with at least the same degree of care it uses for its own confidential information, and in no event less than reasonable care; and (c) not disclose Confidential Information to any third party except to its employees, contractors, and agents who need to know it and who are bound by confidentiality obligations no less protective than those in this section.
13.3. Confidential Information does not include information that is or becomes publicly available without breach, is independently developed without use of the other party's Confidential Information, or is rightfully received from a third party without a duty of confidentiality. The receiving party may disclose Confidential Information to the extent required by law, provided it gives the disclosing party reasonable prior notice where lawful.
14.1. Term. These Terms apply from the date Customer first accepts them and continue for so long as Customer holds an account with the Service, unless terminated as set out below.
14.2. Termination for convenience. Customer may terminate at any time by closing its account and ceasing use of the Service. We may terminate any free account for convenience on thirty (30) days' notice.
14.3. Termination for cause. Either party may terminate these Terms immediately on written notice if the other party: (a) commits a material breach that is not cured within thirty (30) days of written notice of the breach; or (b) becomes insolvent, files for or has filed against it any petition under any insolvency law that is not dismissed within sixty (60) days, makes a general assignment for the benefit of creditors, or ceases business operations.
14.4. Immediate termination. We may suspend or terminate Customer's access immediately and without prior notice if Customer materially breaches section 5.2 (Google Ads binding), section 7 (Acceptable use), or infringes our or a third party's intellectual property rights.
14.5. Effect of termination. On termination, all rights granted to Customer under these Terms cease. Sections that by their nature should survive (including sections 6.1, 10, 11, 12, 13, 15, 19, and 20) survive termination.
15.1. Tokens. OAuth access and refresh tokens for any Connected Account are revoked and deleted from our records immediately on disconnect of the integration or on termination of these Terms. For deletion of Google-derived data on disconnect of a Google Ads integration, or in response to a written deletion request from a Data Subject, see Privacy Policy §3.7 and §9.
15.2. Retrieval window. For thirty (30) days after termination, Customer may request export of Customer Data in a commonly used format. After this thirty-day window, we will delete or anonymize Customer Data from active production systems within a further thirty (30) days, so that complete purge from active systems occurs within sixty (60) days of termination.
15.3. Backups. Customer Data may persist in routine encrypted backups after deletion from active systems. Backups are retained per our documented backup-retention schedule and are then purged. Pending such purge, Customer Data in backups remains subject to the confidentiality and security obligations of these Terms and is not actively processed.
15.4. Legal-hold exception. We may retain Customer Data beyond the periods above to the extent required by applicable law or to defend, exercise, or establish legal claims, in which case the data continues to be protected as described above and is processed only for those purposes.
16.1. We may update these Terms from time to time. The current version is always available at the same URL as these Terms with an updated effective date.
16.2. For material changes, we will give at least thirty (30) days' prior notice by email to the administrator address on the account and by a banner inside the Service. Continued use of the Service after the effective date of a change constitutes acceptance of the updated Terms.
16.3. If Customer does not accept a material change, Customer's sole remedy is to terminate under section 14.2 before the change takes effect. We will refund any pre-paid fees covering the period after termination on a pro-rata basis.
17.1. We continuously improve the Service. We may add, change, or remove features at any time. For material removals of features that Customer is actively using, we will give reasonable prior notice through the Service or by email.
17.2. Beta or preview features may be offered separately and are provided "as is" without warranty of any kind.
18.1. Notices. Notices to Martez must be sent to office@performromance.com or to the postal address in section 1. Notices to Customer are sent to the administrator email address on the account.
18.2. Assignment. Customer may not assign or transfer these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets, on notice to Customer.
18.3. No partnership. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties.
18.4. Force majeure. Neither party is liable for failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control, including acts of God, war, terrorism, civil unrest, governmental actions, labour disputes, internet or telecommunications failures, or failures of upstream Third-Party Platforms.
18.5. Severability and waiver. If any provision of these Terms is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be replaced by an enforceable provision that comes closest to the parties' original intent. Failure to enforce any right is not a waiver of that right.
18.6. Entire agreement. These Terms, together with the Privacy Policy and any order form or written agreement signed by the parties, constitute the entire agreement between the parties on the subject matter and supersede any prior agreements or understandings.
19.1. These Terms and any dispute or claim arising out of or in connection with them are governed by the substantive laws of the Republic of Austria, excluding its conflict-of-laws rules and excluding the United Nations Convention on Contracts for the International Sale of Goods (CISG).
19.2. For disputes between businesses (B2B), the parties submit to the exclusive jurisdiction of the courts competent for 8010 Graz, Austria.
19.3. If Customer is a consumer with habitual residence in the European Union, mandatory consumer protection rules of the law of Customer's country of residence remain unaffected, and the choice of venue in section 19.2 does not deprive Customer of jurisdiction it has under those mandatory rules.
19.4. The European Commission provides an online dispute resolution platform at https://ec.europa.eu/consumers/odr. We are not obliged and not willing to participate in dispute-resolution proceedings before a consumer arbitration board.
For questions about these Terms, please contact:
Raphael Kagermeier (dba Performromance)
Neubaugasse 24, 8020 Graz, Austria
Email: office@performromance.com
Phone: +43 680 2200968
VAT ID: ATU76150157
Effective date: 2026-05-12
Version: 1.0
This Data Processing Agreement ("DPA") forms an integral part of, and is incorporated by reference into, the Martez Terms of Service (the "Terms") between Martez and Customer. It governs the Processing of Personal Data by Martez on Customer's behalf in the course of providing the Service. Where the body of the Terms and this DPA conflict on any matter relating to the Processing of Personal Data, this DPA prevails.
This DPA applies automatically to every Customer; no separate signature is required.
A1.1.1. Capitalized data-protection terms used in this DPA — including "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" — have the meanings given in Article 4 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and are adopted into this DPA by reference.
A1.1.2. "Applicable Data Protection Law" means the GDPR, the EU ePrivacy Directive 2002/58/EC as transposed into national law, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and any other data-protection or privacy law applicable to the Processing under this DPA.
A1.1.3. "EU SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
A1.1.4. "Sub-processor" means any Processor engaged by Martez to Process Personal Data in connection with the Service.
A1.1.5. "Customer Personal Data" means Personal Data contained in Customer Data that Martez Processes on Customer's behalf in providing the Service.
A1.1.6. Other capitalized terms used in this DPA have the meaning given in the Terms.
A1.2.1. Customer is Controller. With respect to Customer Personal Data, Customer is the Controller (or, where applicable, a Joint Controller or Processor acting on behalf of its own customers, in which case Customer warrants that it has the authority to instruct Martez under this DPA). Martez is Customer's Processor.
A1.2.2. Martez is Controller for limited purposes. Notwithstanding section A1.2.1, Martez is the Controller of Personal Data it Processes about Customer's own Users (account holders, administrators, billing contacts) for the purposes of authenticating Users, administering the account, billing, communicating about the Service, and complying with Martez's own legal obligations. The Processing of such data is described in the Privacy Policy and is not governed by this DPA.
A1.2.3. Compliance responsibility. Each party is responsible for its own compliance with Applicable Data Protection Law in respect of its role.
A1.3.1. Subject matter. Martez Processes Customer Personal Data solely to provide the Service to Customer in accordance with the Terms.
A1.3.2. Nature and purpose. The Processing is described in Annex I to this DPA.
A1.3.3. Duration. Martez Processes Customer Personal Data for the term of the Customer's subscription to the Service plus the additional retrieval and deletion periods set out in section A1.13.
A1.3.4. Categories of Data Subjects and Personal Data. Set out in Annex I to this DPA.
A1.4.1. Documented instructions. Martez Processes Customer Personal Data only on the documented instructions of Customer, including with regard to transfers of Personal Data to a third country or an international organization, unless Martez is required to do so by Union or Member State law to which Martez is subject. In such a case, Martez will inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
A1.4.2. Form of instructions. Customer's instructions are set out in the Terms, this DPA, the Privacy Policy, the Service configuration (including the integrations Customer activates and the data sources Customer connects), and any subsequent written instruction Customer gives to office@performromance.com. Customer's use of the Service constitutes an instruction to Martez to Process Customer Personal Data in accordance with the Service's documented functionality.
A1.4.3. Unlawful instructions. If Martez believes an instruction infringes Applicable Data Protection Law, it will notify Customer without undue delay and may suspend execution of the instruction.
A1.5.1. Martez ensures that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality. Confidentiality survives termination of personnel engagements.
A1.5.2. Access to Customer Personal Data is limited to personnel who need access to perform the Service.
A1.6.1. Martez implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures are described in Annex II — Technical and Organizational Measures (TOMs) to this DPA and include, at minimum: encryption of Customer Personal Data at rest and in transit; access controls and tenancy isolation; logging and monitoring; backup; personnel training; and incident response.
A1.6.2. Martez reviews the TOMs at least annually and may update them, provided that the overall level of protection is not materially reduced.
A1.7.1. General authorization. Customer grants Martez a general authorization to engage Sub-processors to Process Customer Personal Data in connection with the Service. The Sub-processors engaged as of the effective date of this DPA are listed in Annex III — Approved Sub-processors to this DPA.
A1.7.2. Notice of changes. Martez will give Customer at least thirty (30) days' prior notice of the intended addition or replacement of a Sub-processor that Processes Customer Personal Data. Notice is given by (a) updating Annex III at the published URL of this DPA and (b) email notification to the administrator email address on Customer's account where Customer has subscribed to sub-processor change notifications.
A1.7.3. Right to object. Customer may object to the addition or replacement of a Sub-processor on reasonable data-protection grounds by written notice to office@performromance.com within the 30-day notice period. The parties will work together in good faith to address Customer's concerns. If no resolution is reached, Customer may terminate the affected portion of the Service with a pro-rated refund of any pre-paid fees covering the period after termination.
A1.7.4. Flow-down. Martez imposes, by written contract, data-protection obligations on each Sub-processor that are no less protective than those in this DPA and that meet the requirements of Article 28(4) GDPR. Martez remains fully liable to Customer for the performance of its Sub-processors' obligations.
A1.8.1. Martez will, taking into account the nature of the Processing, assist Customer by appropriate technical and organizational measures, insofar as possible, for the fulfilment of Customer's obligation to respond to requests for exercising Data Subjects' rights under Chapter III GDPR.
A1.8.2. If Martez receives a request from a Data Subject directly in respect of Customer Personal Data, Martez will, without undue delay, forward the request to Customer's administrator and will not respond to the request itself except on Customer's documented instructions or as required by law.
A1.9.1. Martez notifies Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within forty-eight (48) hours of becoming aware of the breach. This timeframe is intentionally tighter than the 72-hour Controller obligation in Article 33 GDPR to give Customer sufficient lead time to fulfil its own notification duties.
A1.9.2. The notification includes, to the extent then known: (a) the nature of the breach, including, where possible, the categories and approximate numbers of Data Subjects and of records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its adverse effects; and (d) a single point of contact at Martez. Where, and to the extent that, it is not possible to provide the information at the same time, the information may be provided in phases without further undue delay.
A1.9.3. Martez will document each Personal Data Breach and the remedial action taken, and provide that documentation to Customer on request.
Martez will, taking into account the nature of the Processing and the information available to it, provide reasonable assistance to Customer with data-protection impact assessments (Article 35 GDPR) and prior consultations with Supervisory Authorities (Article 36 GDPR) where required.
A1.11.1. EU/EEA transfers. Where Martez transfers Customer Personal Data from the EEA to a Sub-processor in a country that has not been the subject of an adequacy decision by the European Commission under Article 45 GDPR, the parties incorporate the EU SCCs, Module 2 (Controller-to-Processor) by reference. Customer (or its controller, where Customer is itself a Processor) is the data exporter; the recipient Sub-processor is the data importer. Martez acts as Customer's data importer where Martez itself receives Personal Data outside the EEA, and as facilitator in all other cases.
A1.11.2. SCC docking and choices. Where the EU SCCs apply by virtue of section A1.11.1: (a) Clause 7 (Docking clause) is included; (b) Clause 9 Option 2 (general authorization for Sub-processors) applies, with the 30-day notice period in section A1.7.2 of this DPA; (c) Clause 11(a) (independent dispute resolution body) is not opted in; (d) the supervisory authority under Clause 13 is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde); (e) the governing law under Clause 17 (Option 1) is the law of the Republic of Austria; (f) the forum under Clause 18 is the courts of Graz, Austria. Annexes I.A, I.B, I.C, II and III to the EU SCCs are populated by Annexes I, II and III to this DPA respectively.
A1.11.3. UK transfers. Where Customer Personal Data is subject to the UK GDPR, the UK International Data Transfer Addendum ("UK IDTA") to the EU SCCs (issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018) is incorporated by reference, with the EU SCCs forming the Approved EU SCCs under the IDTA. The competent authority is the UK Information Commissioner's Office.
A1.11.4. Swiss transfers. Where Customer Personal Data is subject to the Swiss FADP, the EU SCCs apply with the following adaptations consistent with the Swiss Federal Data Protection and Information Commissioner's guidance: references to the GDPR are read as references to the FADP where appropriate; the competent authority is the Swiss FDPIC; and the term "Member State" is read so as not to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.
A1.12.1. Customer may, no more than once every twenty-four (24) months, audit Martez's compliance with this DPA. The once-per-24-months frequency limit does not apply to (a) audits required by a competent Supervisory Authority, (b) audits in response to a confirmed Personal Data Breach, or (c) any audit the Customer is itself obliged to perform under Article 28(3)(h) GDPR in connection with a documented controller-side investigation. The 30-day prior-notice requirement is waived in cases (a) and (b).
A1.12.2. Customer must give Martez at least thirty (30) days' prior written notice of an audit, and must conduct the audit in a manner that does not unreasonably interfere with Martez's business operations. The auditor must agree in writing to reasonable confidentiality obligations before being given access.
A1.12.3. Third-party reports. Martez may satisfy its audit obligations under this DPA by making available to Customer relevant third-party audit reports (for example, AWS SOC 2 or ISO 27001 reports covering the underlying infrastructure), penetration-test summaries, and Martez's own security documentation, where these reasonably address the matters Customer wishes to audit.
A1.12.4. Costs. Each party bears its own costs of the audit. If the audit reveals a material breach by Martez of this DPA, Martez will reimburse Customer's reasonable audit costs.
A1.13.1. Customer election. On termination of the Terms or earlier on Customer's written request, Customer may elect, by written notice to office@performromance.com within thirty (30) days of termination, to have Martez (a) return Customer Personal Data to Customer in a commonly used machine-readable format, or (b) destroy Customer Personal Data.
A1.13.2. Default. If Customer makes no election within the thirty (30) day window, Martez will destroy Customer Personal Data within a further thirty (30) days.
A1.13.3. Backups. Customer Personal Data may persist in routine encrypted backups after deletion from active systems. Backups are retained per the schedule set out in Annex II to this DPA and are then purged. Pending such purge, Customer Personal Data in backups remains subject to the confidentiality and security obligations of this DPA and is not actively Processed.
A1.13.4. Legal-hold exception. Martez may retain Customer Personal Data beyond the periods above to the extent required by Union or Member State law, in which case the data continues to be protected as described above and is Processed only for those purposes.
A1.14.1. Each party's liability under this DPA is subject to the limitation and exclusion provisions of the Terms, including section 11 (Limitation of liability) of the Terms.
A1.14.2. Notwithstanding section A1.14.1, where liability under this DPA arises out of or in connection with the Processing of Personal Data, the aggregate cap in section 11.2 of the Terms is doubled with respect to claims under this DPA, so that the aggregate cap is two hundred per cent (200%) of the fees paid by Customer to Martez during the twelve months immediately preceding the event giving rise to the liability. The carve-outs in section 11.4 of the Terms remain in full effect.
A1.15.1. This DPA is governed by the substantive laws of the Republic of Austria, excluding its conflict-of-laws rules and excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
A1.15.2. The parties submit to the exclusive jurisdiction of the courts competent for 8010 Graz, Austria, subject to the mandatory consumer-protection rules referenced in section 19.3 of the Terms.
A1.15.3. The choice of law and venue in this section A1.15 is without prejudice to the governing law and venue provisions of the EU SCCs, the UK IDTA, or any Swiss equivalent, where these apply by virtue of section A1.11.
A1.16.1. Save as expressly amended by this DPA, the Terms remain in full force and effect.
A1.16.2. If any provision of this DPA is held unenforceable, the remaining provisions remain in full force, and the unenforceable provision will be replaced by an enforceable provision that comes closest to the parties' original intent.
The subject matter of the Processing is Martez's provision of the marketing-intelligence Service to Customer in accordance with the Terms, including ingestion of data from Third-Party Platforms that Customer connects, attribution modelling, cost-allocation (including the Dynamic ACpCT model), and return-on-ad-spend reporting.
The duration of the Processing is the term of Customer's subscription to the Service plus the retrieval and deletion periods in section A1.13 of this DPA.
cost_micros to spend, joining campaign hierarchies);The categories vary by integration. Indicatively:
| Integration | Categories of Personal Data |
|---|---|
| Google Ads | Customer-level identifiers (customer ID, descriptive name, currency, time zone), campaign / ad-group / ad metadata (ID, name) and performance metrics (cost_micros, impressions, clicks). Data is aggregated at campaign level and does not, in normal operation, identify individual end users. |
| Meta Ads | Campaign / ad-set / ad metadata, cost, impressions, clicks. |
| Matomo | Visitor IDs (pseudonymous), pageview events, goal/conversion events, UTM parameters, referrer URLs, IP-derived geolocation as configured in the Customer's Matomo instance. |
| Digistore24 | Order/transaction records, payment status, gross/net amounts, and the order metadata returned by the Digistore24 API (may include buyer email and address depending on the Customer's Digistore24 configuration). |
| KlickTipp | Subscriber identifiers, tag/list membership, event timestamps, and other subscriber attributes returned by the KlickTipp API. |
| Account-holder data (Martez as Processor on Customer's instruction, e.g. inviting team members) | Name, email address, role/permissions. |
Customer agrees not to use the Service to Process special categories of Personal Data under Article 9 GDPR, payment-card data subject to PCI DSS, or government-issued identification numbers. See section 7 of the Terms.
Continuous (synchronous) for User-initiated reads and writes; periodic (typically daily) for integration syncs.
The following measures are in force as of the effective date of this DPA. Martez may update them from time to time, provided the overall level of protection is not materially reduced.
APP_KEY. The underlying database (AWS RDS PostgreSQL) and object storage (AWS S3) volumes are encrypted at rest by AWS (AES-256).eu-central-1 (Frankfurt) using Lambda's multi-AZ execution surface; static assets are delivered via AWS CloudFront with origin failover.This list mirrors Section 7 of the Privacy Policy and is the authoritative list of Sub-processors approved under section A1.7 of this DPA as of the effective date.
| Provider | Role | Hosting region | Transfer mechanism |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS Lambda, RDS PostgreSQL, S3) | Application compute, database, file storage | eu-central-1 (Frankfurt, Germany) | EU hosting; AWS EU Data Boundary; EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) for any incidental support access from outside the EEA |
| Amazon CloudFront | Content delivery network for public static assets | Global edge network | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); no Google user data is served via CDN |
| Resend (Resend.com Inc.) | Transactional email delivery | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor) |
| Sentry (Functional Software Inc.) | Application error and exception tracking | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); Google user data is excluded from error payloads |
| Slack Technologies LLC | Internal health-alert notifications | United States | EU SCCs (Art. 46 GDPR), Module 2 (Controller-to-Processor); only operational metadata (e.g. "sync failed for project X"), no Google user data, is sent |
| Matomo (InnoCraft Ltd. / self-hosted instance) | Marketing-site analytics (consent-gated) and Customer-connectable in-app integration | EU (self-hosted on AWS eu-central-1 for the marketing-site instance; Customer-controlled location for Customer-connected instances) | EU hosting for the marketing-site instance; for Customer-connected instances, the Customer determines the location and any transfer mechanism. EU SCCs (Art. 46 GDPR) apply to any incidental support access from outside the EEA. |
Customer may subscribe to sub-processor change notifications by writing to office@performromance.com.