Privacy Policy (GDPR)
Last updated: September 2026
This privacy policy explains, in accordance with Articles 13 and 14 of the European Union's General Data Protection Regulation (GDPR), what personal data we process when you use Marlomag, for what purposes, on what legal basis, and what rights you have as a data subject.
1. Data controller
The data controller within the meaning of the GDPR is Maria Daoud, August-Bebel-Str. 105, 08393 Meerane, Germany (email: privacy@matorcis.de). For the data you enter into the platform yourself — for example your own clients', invoices' and expenses' data — you act as the data controller; Marlomag acts solely as a processor under Article 28 GDPR.
2. Data Protection Officer
We are not legally required to appoint a Data Protection Officer and have not currently appointed one. For any data-protection questions, you can reach us directly at privacy@matorcis.de.
3. Data we process
Account data (name, email address, encrypted password or Google sign-in credentials); firm and tax data you voluntarily provide in Settings (tax ID or VAT ID, address, bank account); the client, invoice, quote and expense data you record while using the platform, including data automatically extracted via OCR from the receipts you upload (merchant, amount, date, tax breakdown); the verification email we send to your account's address when you sign up (it contains only your name and a confirmation code, with no advertising and no tracking of any kind); payment data related to your subscription, processed by our payment provider Paddle; and technical usage data (IP address, timestamps, device and browser information) needed to provide and secure the service.
4. Purposes and legal bases
We process your data to perform the usage agreement (Art. 6(1)(b) GDPR) — for example to provide your account, send you the email that verifies your address, document scanning, invoicing and reports; to comply with statutory retention obligations, in particular applicable commercial and tax law (Art. 6(1)(c) GDPR); on the basis of our legitimate interest (Art. 6(1)(f) GDPR) to secure the platform (including checking that an email address belongs to the person creating the account), debug and improve it; and, where you sign in with your Google account or give a specific consent, on the basis of your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.
5. Recipients and processors
To provide the service we rely on carefully selected providers who process your data solely on our behalf: Convex (database and application hosting), Cloudflare (storage of the receipt files you upload), Mistral AI (automatic text recognition/OCR of your receipts and the answers of the AI assistant “Concierge”, which receives your questions and the account data it needs to answer them), Paddle (payment processing and invoicing for your subscription), Brevo (sending your account verification code by email, with no open or click tracking) and, if you sign in that way, Google (OAuth authentication). We have Article 28 GDPR data processing agreements in place with every provider acting as a processor. If you configure your own outgoing email server (SMTP) in Settings, that provider processes the relevant data under its own responsibility.
6. International data transfers
Some of our providers also process data outside the European Union or the European Economic Area, for example in the United States. In these cases we ensure an adequate level of protection, in particular through the European Commission's Standard Contractual Clauses or through the provider's certification under the EU-U.S. Data Privacy Framework.
7. Retention period
We store your account data for as long as your account exists. Invoicing and accounting-relevant data is additionally retained for the statutory retention periods that apply, which in Germany are generally ten years under Section 147 of the Fiscal Code (AO) and Section 257 of the Commercial Code (HGB); your own country may set different periods. Once the applicable period has elapsed, or after your account is deleted, the data is deleted or anonymized unless another legal retention obligation applies.
8. Your rights
As a data subject you have the right to: access the data we process about you (Art. 15 GDPR); request rectification of inaccurate data (Art. 16); request erasure of your data (Art. 17); request restriction of processing (Art. 18); data portability (Art. 20); object to processing (Art. 21); and withdraw, at any time with effect for the future, any consent you have given (Art. 7(3)). To exercise any of these rights, simply write to us at privacy@matorcis.de — no particular form is required.
9. Automated decision-making
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you. Automatic text recognition (OCR) of your receipts is used solely for data capture and does not replace any legally binding decision.
10. Whether providing data is required
Providing your account data is necessary to enter into a usage agreement with us; without it we cannot provide you with the service. Providing other data, such as your firm and tax data, is voluntary but necessary for the documents you generate to meet the legal requirements that apply to them.
11. Cookies
We use only strictly necessary cookies, for example to remember your preferred language and keep you signed in. Under EU cookie rules (Article 5(3) of Directive 2002/58/EC and its national implementation, such as Section 25(2) of the German TTDSG), this type of cookie does not require your consent. We do not use third-party analytics, advertising or tracking cookies.
12. Data security
We protect your data using technical and organizational measures appropriate to the state of the art, in particular encrypted transmission, access restrictions, and strict separation between different customers' data.
13. Changes to this policy
We will update this privacy policy whenever applicable law, our providers, or our processing activities change. The version in force at any given time is always available on this page.
14. Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Sächsische Datenschutz- und Transparenzbeauftragte (the Data Protection and Transparency Authority of the German federal state of Saxony), Postfach 11 01 32, 01330 Dresden, Germany, email: post@sdtb.sachsen.de. You may also contact the supervisory authority of your own country of residence or habitual workplace.