Security, compliance, and transparency — by design.
We believe trust is earned through documented practices, not marketing claims. Everything below is verifiable, specific, and kept up to date.
Our approach to trust
Marotino operates as a software engineering company with clients across fintech, e-commerce, and enterprise software. We handle sensitive business data, integrate with financial APIs, and build infrastructure that underpins real transactions.
Because of this, we hold ourselves to a high standard: data protection is a core engineering requirement, not a compliance checkbox. Every project we deliver includes access control review, secret management practices, and data minimization by default.
What we cover
Click any section for the full documentation.
GDPR Compliance
Data controller identity, legal bases for processing, your rights as a data subject, DPA commitments, and breach notification procedures for EU/EEA residents.
- Legal bases for processing (Art. 6)
- Data subject rights (Art. 15–22)
- International transfers & SCCs
- 72-hour breach notification (Art. 33)
- Data Processing Agreements
CCPA / CPRA
California Consumer Privacy Act compliance, categories of personal information collected, your opt-out rights, and how to submit privacy requests.
- Categories of personal information
- Right to Know, Delete, Opt-Out
- No sale of personal information
- Annual privacy notice
- Agent authorization process
Security Practices
How we secure the software we build and our own infrastructure — access control, encryption standards, dependency management, and vulnerability disclosure.
- HTTPS everywhere, TLS 1.2+
- Secrets management & rotation
- Dependency vulnerability scanning
- Access control & least privilege
- Responsible disclosure policy
Legal Entities
Marotino operates through two registered legal entities to serve global clients. Find the right entity for contracts, invoices, and data processing agreements.
- Marotino CY LTD — Limassol, Cyprus (EU)
- Marotino INC — Miami, FL (Americas)
- VAT & registration details
- Which entity handles your data
- Invoice & contract routing
Additional policies & documents
Questions about your data?
If you have a question about how we process your data, want to exercise a data subject right, or need a Data Processing Agreement for your contract — reach our DPO directly.
We respond to all data protection enquiries within 5 business days. Formal data subject requests are processed within 30 days as required by the GDPR.
Our standing commitment
We review this Trust Center at minimum once per quarter. Any material changes to our data handling practices, legal structure, or security posture are reflected here before going into effect. The last review was April 2026.