GDPR Compliance
Last updated: August 29, 2026
Our Commitment to GDPR
Marathoon is committed to protecting the privacy and security of personal data in compliance with the General Data Protection Regulation (GDPR). This page outlines how we handle personal data for users in the European Economic Area (EEA).
Data Controller
The data controller is [RAISON SOCIALE], [FORME JURIDIQUE] registered under number [SIREN], with registered office at [SIÈGE SOCIAL]. For data processed on behalf of our customers (such as pipeline inputs and outputs), we act as a data processor.
Legal Basis for Processing
We process personal data based on:
- Contract: Processing necessary to provide our services
- Legitimate Interest: For security, fraud prevention, and service improvement
- Consent: For marketing communications and optional features
- Legal Obligation: To comply with applicable laws
Your Rights Under GDPR
As an EEA resident, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data
- Right to Restriction: Limit how we use your data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
Data Transfers
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission. The current list of sub-processors is published in our Privacy Policy.
Data Protection Officer
For GDPR-related inquiries, you can contact our Data Protection Officer ([NOM DU DPO]) at dpo@marathoon.io
Self-Service Tools
You do not need to open a ticket to exercise your core rights: export all your personal data (GET /api/v1/auth/me/export) and delete your account (DELETE /api/v1/auth/me) directly from your profile or the API.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at privacy@marathoon.io. We will respond to your request within 30 days.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. In France, this is the CNIL (Commission nationale de l'informatique et des libertés, www.cnil.fr); elsewhere in the EEA, contact your local authority.