Who operates Durin
Durin is operated by Marathon Digital Pte Ltd., a Singapore company (UEN 202023814G). John Rocela, Founder, runs the business and is accountable for security, privacy, and supplier decisions.
Read how Durin handles website and application analytics, support chat, account data, and governed gateway capture, including retention limits and privacy contacts.
Reviewed September 19, 2026. This notice describes our current processing boundaries and the commitments that still require customer-specific agreement and operational evidence. It does not replace a customer data-processing agreement or establish complete legal compliance.
Durin is operated by Marathon Digital Pte Ltd., a Singapore company (UEN 202023814G). John Rocela, Founder, runs the business and is accountable for security, privacy, and supplier decisions.
We are committed to meeting applicable GDPR and Singapore PDPA obligations and aligning our security programme with ISO/IEC 27001 principles. These are management commitments, not certification or independent assurance that every obligation has been fulfilled.
We use Sentry for error diagnostics and PostHog for website and application analytics. PostHog can record sessions depending on project settings; its browser configuration masks text and element attributes and disables heatmaps and performance capture. Application analytics can associate events with a user and organisation. Diagnostic filtering reduces sensitive fields but does not guarantee that every error message is free of personal data.
Global Privacy Control or Do Not Track disables PostHog collection on the public website. This is not a service-wide opt-out and does not stop Sentry or Crisp. Crisp chat loads on the website and application and can process browser information and messages you submit. Analytics and chat may use cookies or browser storage. Do not submit passwords, access tokens, or sensitive customer content in chat.
We process identity and membership information to manage access, account and subscription information for billing, and correspondence to respond to enquiries. The service integrates Cloudflare for hosting and storage, WorkOS for identity, Stripe for billing, Sentry for diagnostics, PostHog for analytics, and Crisp for chat. Customer-selected upstream systems and export destinations have their own processing boundaries. This inventory is not an executed subprocessor schedule.
Durin records the requester, client, connection, policy decision, approval where required, and execution outcome. Metadata can itself be personal or confidential data. Tool requests and results can pass through Durin even when content is not retained. Durin does not host or train AI models; results returned to an external client can reach that client’s model provider.
Conversation capture defaults to metadata only: submitted message content is discarded before persistence. An administrator can enable redacted message capture for 1–30 days. Expired messages become unreadable and scheduled cleanup removes retained payload objects. This period does not cover all audit metadata, account records, billing, backups, analytics, or support messages. Redaction is pattern-based and is not complete data-loss prevention.
For customer-directed processing, Durin would ordinarily act as a GDPR processor or Singapore PDPA data intermediary; for purposes we determine, we may act as controller or organisation. The actual processing and agreement determine the role. No EU-only or Singapore-only residency guarantee is offered. Complete retention schedules, legal holds, backup expiry, tenant deletion, and international-transfer safeguards require further operational and contractual evidence.
Send privacy questions to privacy@getdurin.com and include the public page, product route, or evaluation context involved. Do not email secrets, tokens, regulated payloads, or customer content. Tenant deletion, legal hold, residency, backup, and provider-processing commitments are handled through customer-specific review.
Create an account to inspect the governed request path and review what metadata, payload, and telemetry boundaries apply.
Create an accountProduction connections use provider setup and trust review.