Data Processing Agreement.
Readable commitments on how we handle personal data on your behalf — the roles, the sub-processors, the security measures, the rights you can exercise, and what happens if something goes wrong.
This Data Processing Agreement (the "DPA") sits underneath the Marqee Terms of Service and the Marqee Privacy Notice, and describes how Marqee processes personal data on behalf of the people and organizations who use the service. It is the document a corporate procurement team, an HR partner, or a privacy-conscious member should be able to read in one sitting and know what we do with the information you hand us.
It applies to three groups. First, individual members — the job seekers who sign up for a weekly plan, a Sprint, or a pay-as-you-go order, and whose résumés, LinkedIn snapshots, and application records flow through the platform. Second, HR partners — employers, staffing groups, and outplacement providers who send us a bench of people to work with, and who act as the controller of that bench's data. Third, ambassador, creator, reseller, and recruiter partners — the individuals and small teams enrolled in the Marqee Partner Program, whose contact records and payout information we hold to run the program.
Nothing here is written to hide behind. If a paragraph doesn't match how the product actually works, that is a bug and we want to hear about it. Write to privacy@marqee.com and we will either explain the gap or fix the document. This DPA is effective July 11, 2026, replaces any prior data-processing terms, and remains in force for as long as Marqee is processing personal data on your behalf.
01Definitions
Six terms we use throughout this DPA, in the sense the GDPR and comparable regimes use them. If a regulation you're subject to uses a different label for the same concept, treat the definition below as controlling.
- Controller
- The party that decides why and how personal data is processed. For members, that is you. For HR partners, that is your organization for the bench you send us.
- Processor
- The party that processes personal data on behalf of the controller, under the controller's instructions. In this DPA, that is Marqee.
- Personal Data
- Any information relating to an identified or identifiable person — a name, email, résumé, phone number, calendar entry, IP address, or a record tying any of these to a specific human.
- Processing
- Anything we do with personal data — collecting, storing, tailoring a résumé, sending it to an employer, deleting it. If we touch the data, we are processing it.
- Sub-processor
- A third party we engage to help us process personal data on your behalf — a cloud host, an email sender, a video-conferencing platform. Each sub-processor is bound by contract to the same commitments we make to you.
- Data Subject
- The identifiable human the data is about. In our world that is nearly always a member, an HR-partner employee, or a program partner.
02Scope of processing
What personal data Marqee processes, and the specific job-search purpose each category is processed for.
Marqee is a human-led career concierge. To do that work — finding roles, tailoring materials, running recruiter outreach and referral discovery, submitting applications, and scheduling interviews — we hold a specific and limited set of information about you and, where applicable, the people your organization has enrolled with us. The categories below are the working list.
- Résumé content and career history — the roles, dates, employers, education, skills, and accomplishments you upload or that your strategist drafts on your behalf. We use it to produce tailored, ATS-ready résumés per application.
- LinkedIn profile snapshots — the public profile fields you point us to or paste in, and any refinements agreed with your strategist. We use it to reconcile résumé and profile positioning and to audit visibility to recruiters.
- Recruiter and referral contact information — email addresses, LinkedIn URLs, and job titles of the people your strategist reaches out to on your behalf. We use it to run outreach and to log responses in your application tracker.
- Application records — the roles targeted, the companies applied to, the versions of your materials submitted, and the status returned by each employer. We use it to run the search and to give you the weekly readout.
- Calendar and scheduling data — the availability windows and confirmed interview times you share for a booked call. We use it to schedule interviews and to hand the confirmation back to you.
- Account & billing data — the email, name, and payment token needed to run your subscription or one-time order. Card numbers themselves never touch Marqee servers; they are tokenized by our payment processor.
We do not sell personal data, we do not process it for advertising to third parties, and we do not build behavioral profiles about you for anyone other than your own dedicated strategist working your search.
03Roles & responsibilities
Who is the controller, who is the processor, and where the responsibility lines are drawn in each of the three relationships this DPA covers.
The default relationship is straightforward. When you as an individual member sign up for Marqee, you are the Data Subject and the Controller of your own data, and Marqee is the Processor. Your strategist acts on your instructions — the roles you target, the tone you want, the offers you approve — and Marqee holds and processes the data required to carry those instructions out.
When an HR partner — an employer offering outplacement, a staffing firm placing a bench, a program manager sponsoring cohorts — enrolls a group of members, the HR partner is the Controller for the bench-level data (who is enrolled, what tier, what target markets), and each enrolled individual remains the Data Subject for their own personal data. Marqee is the Processor for both layers. The HR partner cannot use Marqee's platform to access an individual member's search materials without that member's consent — the member's account is the member's account.
When a partner joins the Marqee Partner Program as an affiliate, ambassador, influencer, creator, reseller, or account executive, the partner is the Controller of their own contact and payout records, and Marqee is the Processor of that data for the purpose of running the program, paying out earnings, and issuing 1099s where required.
The short version: if the data is about you, you own the instructions. If the data is about a bench you enrolled, you own the instructions at the bench level, and each individual owns the instructions at the personal level. Marqee runs the work.
04Sub-processors
The categories of third-party services we rely on to run the platform, and how we tell you before that list changes.
Running a managed job search requires a small stack of infrastructure vendors. We keep the list short on purpose, prefer vendors with a defensible privacy posture, and bind every one of them by contract to the same commitments we make to you in this DPA. Categories are stable; the specific vendor within a category may change over time.
| Category | Purpose |
|---|---|
| Cloud hosting & storage | Application servers, databases, encrypted object storage for résumés and generated materials. |
| Transactional email | Sending platform-generated emails to you — sign-in links, receipts, weekly readouts, notification of strategist activity. |
| Calendar integration | Reading availability and writing interview holds into the calendar you connected, only for the events you approve. |
| Video conferencing | Hosting the strategy sessions, kickoff calls, and interview-prep calls booked through the platform. |
| Error & performance monitoring | Capturing anonymized stack traces and page-load metrics to keep the product working. Personal data in traces is scrubbed before storage. |
| Product analytics | Understanding first-party usage patterns to improve the product — always aggregated where possible, never sold or shared with advertisers. |
| Payments & billing | Tokenizing your card, running the subscription or one-time charge, and issuing refunds. Card details never reach Marqee servers. |
A live, versioned list of the specific vendors in each category — including the entity name, the country of primary processing, and the date each vendor was added — is maintained at marqee.com/sub-processors. When we intend to add, replace, or materially change a sub-processor, we post a notice on that page and inform affected controllers at least thirty (30) days in advance. If a controller reasonably objects to a proposed change on data-protection grounds, we will work in good faith to find an alternative or offer a clean termination with a prorated refund of unused fees.
05Security measures
The technical and organizational measures Marqee applies to keep personal data safe in the ordinary course of running the service.
We do not publish a laundry list of certifications we don't hold. Instead, here is the concrete set of controls we operate today, and which we will maintain or improve for the life of this DPA.
- Encryption in transit. All traffic between your browser, the Marqee app, and our services is encrypted using TLS 1.2 or higher, with modern cipher suites and HTTP Strict Transport Security applied at the edge.
- Encryption at rest. Databases and object storage holding personal data — including résumés, LinkedIn snapshots, and application records — are encrypted at rest using AES-256 with keys managed by our cloud provider's key-management service.
- Least-privilege access. Internal access to personal data is granted on a need-to-know basis, scoped to the strategist or engineer who actually needs it, and revoked automatically when the role that grants it ends.
- Biometric or SSO login for internal staff. Every Marqee employee and contractor authenticates to production systems through single sign-on with hardware-backed second factor (a physical security key or platform biometric); shared passwords are not permitted.
- Audit logs. Reads and writes to personal-data stores are logged with the acting identity, timestamp, and the record touched. Logs are retained for at least twelve months and are reviewed on incident investigation.
- Quarterly access reviews. Every ninety days, the security lead reviews the full list of internal accounts with access to personal data and removes anything that is no longer justified by role.
- Vulnerability management. Dependencies and container images are scanned continuously; critical patches are applied within seventy-two hours of a fix being available, and a written record of the response is kept.
- Employee training & confidentiality. Every Marqee employee and contractor signs a confidentiality agreement covering personal data, and completes annual security and privacy training before renewing production access.
06Data-subject rights
The rights any data subject can exercise over their personal data held by Marqee, and the timelines we commit to.
You have real rights over the data we hold about you. As a processor, we help controllers respond to data-subject requests and, where you as a data subject are also the controller of your own data (nearly every member scenario), we act on your requests directly. The list below applies whether you are a member, an HR-partner enrollee, or a program partner.
- Access. Ask for a copy of the personal data we hold about you. We will produce a machine-readable export within thirty (30) days of a verified request.
- Correction. Correct anything that is inaccurate or incomplete. In most cases you can do this yourself in the dashboard; where you cannot, we will correct it on request within thirty (30) days.
- Deletion. Ask us to delete your account and the personal data we hold about you. See the termination section below for the retention window that follows.
- Portability. Receive your data in a common, structured, machine-readable format — JSON for account and application records, PDF or DOCX for materials.
- Restriction. Ask us to pause certain processing while a dispute is resolved — for example, pausing outreach while you evaluate whether to continue the search.
- Objection. Object to processing where the legal basis allows objection. We will stop that processing unless we have a lawful override and can explain it.
To exercise any of these rights, email privacy@marqee.com from the address on your account, or use the equivalent in-app control where one exists. We respond within thirty (30) days for a standard request. For requests that are complex or involve reconciling data across multiple systems, we may extend the response window by up to a further fifteen (15) days, for a maximum of forty-five (45) days, and will tell you the reason for the extension in writing before the initial window closes. We do not charge for a first request in a rolling twelve-month period; excessive or repetitive requests may incur a reasonable administrative fee, disclosed before we invoice.
07International transfers
Where the data actually sits, and the legal mechanism we rely on when it crosses a border.
Marqee's primary hosting region is the United States. Personal data processed on your behalf is stored on infrastructure operated in US-East and US-West availability zones, with encrypted backups replicated across regions for disaster recovery. A subset of vendors — for example, the video-conferencing platform used for coaching sessions — may process data in other regions depending on where the participants are located.
Where a transfer of personal data leaves a jurisdiction whose export controls require it — most notably the European Economic Area, the United Kingdom, and Switzerland — Marqee relies on the European Commission's Standard Contractual Clauses (SCCs) as the transfer mechanism. The SCCs are incorporated by reference into this DPA and take effect automatically for any transfer that requires them. For controllers established in the United Kingdom, the UK International Data Transfer Addendum to the SCCs applies. For controllers established in Switzerland, the Swiss Federal Data Protection and Information Commissioner's guidance is followed and the SCCs are read with the Swiss adjustments the FDPIC has published.
An EU/UK addendum and a copy of our executed SCC template are available on request from privacy@marqee.com. Enterprise controllers procuring Marqee for a workforce that includes EU, UK, or Swiss data subjects should request these documents during procurement — they will be sent within five business days.
08Breach notification
What we do if something goes wrong, and how quickly we tell you.
If Marqee becomes aware of a personal-data breach — a security incident that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data we process on your behalf — we will notify affected controllers without undue delay and no later than seventy-two (72) hours after becoming aware of it. The initial notice will describe, to the extent known at that point, the nature of the incident, the categories of data subjects and records involved, the likely consequences, and the measures taken or proposed to address it.
Where a controller is required by law to notify the individuals whose data was affected, Marqee will provide the information reasonably needed to do so. Where affected data subjects are members whose relationship with us is direct, we will also issue a readable member notice written by a human — describing what happened, what was and was not affected, what we did, and what the member should do next. We do not send templated regulatory boilerplate to individuals whose data was touched.
After every incident that meets the notification threshold, we publish an incident post-mortem to a controllers-only page and, where the incident is material, a redacted public summary. The post-mortem covers root cause, timeline, containment, and the concrete changes we are making to reduce the chance of a recurrence.
09Termination & return of data
What happens to your data when the relationship ends.
When you cancel your Marqee account, when an HR partner ends the engagement, or when a program partner exits the Partner Program, we retain personal data for thirty (30) days after the effective date of termination. That window exists for one reason: restore-in-case-of-mistake. It is not uncommon for a cancellation to be reversed inside the first week, and it would be worse than useless to make people rebuild a search from zero because a button was clicked in haste.
On the thirty-first day, personal data is permanently deleted from our production databases and object storage. Encrypted backups roll off according to their retention schedule, which does not exceed ninety (90) days from the deletion date. Aggregated, anonymized statistics — for example, counts of applications processed by tier in a month — do not include personal data and may be retained beyond that window.
Enterprise controllers who require a paper trail can request a signed data-destruction certificate once deletion is complete. The certificate is issued by the Marqee Data Protection lead, is countersigned by the security lead, and confirms the effective date of deletion, the scope covered, and the systems from which the data has been removed. Ask for it by writing to privacy@marqee.com.
10Governing law & amendments
The legal frame this DPA sits inside, and how it can be updated.
This DPA is governed by the laws of the State of New Jersey, USA, without regard to conflict-of-laws principles, except where an applicable data-protection regime requires otherwise — in which case the mandatory provisions of that regime take precedence over any conflicting provision here. Any dispute arising out of or in connection with this DPA is subject to the jurisdiction and venue provisions of the Marqee Terms of Service.
Marqee may amend this DPA from time to time to reflect changes in law, changes in the product, or improvements in the commitments we are able to make. Non-material amendments — clarifications, typo fixes, updates to a sub-processor category description — take effect on posting. Material amendments — anything that reduces a commitment made to a controller — take effect no earlier than thirty (30) days after we post the change and notify controllers by email. If a material amendment is not acceptable to a controller, that controller may terminate the underlying service for cause during the notice period, with a prorated refund of any unused fees.
How this DPA is agreed to.
This DPA is countersigned automatically when you accept the Marqee Terms of Service — either as an individual member at sign-up, as an HR partner at engagement onboarding, or as a program partner when you accept your partner track. Acceptance of the Terms constitutes acceptance of this DPA, and the two documents should be read together.
A separately signed version — countersigned by the Marqee Data Protection lead on company letterhead, with your organization named as the controller — is available on request. Write to privacy@marqee.com from a verifiable business address and we will return a signature-ready PDF within five business days.
Related legal documents: Terms of Service · Privacy Notice · Sub-processor list · Cookie policy · Editorial standards. Questions or a report about how your data is being handled? privacy@marqee.com.