Merco · Legal
Data Processing Agreement
Preparation draft · 27 September 2026 · 2026-09-27-draft-2
01Parties, scope and instructions
This DPA forms part of an accepted service agreement between the Customer and Merco Technologies B.V. (intended operator; registration pending). It applies only where Merco processes personal data on the Customer’s behalf. It does not reclassify Merco’s own controller activities or independent payment-provider processing. This draft has no contractual effect until incorporated into the parties’ agreement.
The Customer determines its lawful purposes and instructions. Merco processes only on documented instructions, including agreed feature use, authorised sharing and international transfers, unless law requires otherwise; it informs the Customer of such a requirement unless prohibited. Merco promptly flags an instruction it considers unlawful. Merco does not use processor data for unrelated marketing, resale or model training.
02Processing description — Annex 1
- Subject matter and duration: hosting and operating the contracted workspace for the agreement term, followed by the return/deletion period and any lawful restricted retention.
- Nature and purposes: collection, storage, retrieval, analysis, generation, communication and authorised disclosure for sourcing, Studio, documents, order management and support.
- Individuals: customer personnel, invited users, designers, supplier personnel, business contacts, signatories and other individuals in authorised customer documents.
- Data: business contact details, role/access data, identifiers, communications, design/reference files and order/document information containing personal data. Special-category data is not an intended input; any necessary sensitive-data processing requires a specific written instruction and safeguards.
- Instructions and contacts: the accepted agreement, workspace choices and written authorised requests; Customer’s designated administrator and Merco’s privacy contact. The Customer supplies its legal identity and authorised contact in the agreement.
03Confidentiality and safeguards — Annex 2
Merco binds authorised personnel to confidentiality and restricts access to their responsibilities. The agreed minimum controls are protected transport, access control and authentication, separation of organisations, controlled private-file access, logging appropriate to risk, change management, backup/recovery, vulnerability handling and deletion procedures. Measures are reviewed as risks change; material protection is not reduced without notice and an appropriate contractual remedy.
The operational register identifies evidence for these controls and the actual hosting/storage settings. It must be completed before the DPA is offered as effective. This draft does not assert ISO certification, universal field encryption, a penetration test or a tested recovery target.
04Subprocessors and transfers — Annex 3
The provider register, once approved for the contracted service, is the initial authorised subprocessor list. Merco imposes materially equivalent relevant obligations and remains responsible for its subprocessors’ performance under this DPA. Independent controllers are identified separately.
Under general written authorisation, Merco gives at least thirty days’ notice of a new or replacement subprocessor where practicable. The Customer may object on substantiated data-protection grounds. The parties seek an alternative; if none is reasonable, the Customer may end the affected service and recover unused prepaid fees for it. An urgent replacement requires prompt notice and equivalent protection.
Restricted international transfers require an applicable safeguard. Any standard contractual clauses must use their official unmodified text with the correct modules and completed annexes; this DPA does not itself replace those clauses. Swiss transfers receive necessary Swiss adaptations.
05Rights, incidents and oversight
Merco assists with data-subject requests, security obligations, DPIAs and regulator consultations, taking account of the information available to it. It forwards a request about processor data to the Customer and does not independently expand its purpose. Reasonable assistance charges can apply only if agreed and must not obstruct statutory duties.
Merco notifies the Customer without undue delay after becoming aware of a personal-data breach affecting processor data, provides available nature/scope/impact/remediation information in stages and cooperates in response. Notification is not delayed until every fact is known; the Customer controls its regulator/data-subject notifications unless law requires Merco to act.
Merco provides information needed to demonstrate compliance and permits reasonable audits/inspections under proportionate confidentiality, security and scheduling safeguards. Contractual limits cannot prevent mandatory regulator access or investigation of a credible material incident.
06Return, deletion and priority
On termination the Customer may request return/export or deletion of processor data. The proposed operational target is a thirty-day retrieval window followed by deletion from active systems within thirty further days and backup expiry within ninety days of active deletion. These targets must be validated and included in the accepted order form before effectiveness; statutory switching rights override a conflicting shorter window.
Data required by law or a documented legal hold is isolated, access-restricted and retained only for that purpose. Merco confirms completion on request. Merco’s separate controller records follow the privacy notice. The DPA prevails over conflicting service terms for its subject matter; mandatory law and applicable standard contractual clauses prevail over both.