Legal
What we hold, why we hold it, who we share it with, and how you take it with you.
Last updated 30 July 2026
This Privacy Policy describes how Merco (“Merco”, “we”, “us”) processes personal data when you use merco.dev and the Merco platform (together, the “Platform”). It applies to suppliers, buyers and the users of compliance workspaces who access the Platform.
Merco is established in Switzerland and processes personal data in line with the Swiss Federal Act on Data Protection (revFADP) and, for data concerning individuals in the European Economic Area, the General Data Protection Regulation (GDPR). We do not collect special categories of personal data (Article 9 GDPR) through the Platform, other than identity documents that may be processed by our identity-verification provider as described below.
This policy does not describe the practices of payment, identity, shipping or other third-party services that have their own terms. Where those services process your data, they do so as controllers or processors in their own right under their own policies, which you should also read.
Merco is the controller responsible for your personal data. You can reach us at the address and contact details published in the imprint. For data-protection questions and to exercise any right in this policy, contact us through the access form or at [privacy@merco.dev — to be inserted].
Where required by law, Merco will designate a data protection officer and, for individuals located in the EU, an Article 27 GDPR representative in the European Union. Their contact details will be published here when appointed. Until then, the contact route above serves all data-protection enquiries.
We process the following categories of personal data, depending on how you use the Platform:
We process personal data for the following purposes, on the legal bases indicated:
Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms and limited the processing to what is necessary. You have the right to object to processing based on legitimate interests (see “Your rights”).
We share personal data only with the categories of recipients needed to operate the Platform:
The current list of processors, the data they receive and the countries in which they operate is set out under “International transfers”. We bind our processors by contract and disclose data only as necessary for the service.
Your data is processed in Switzerland, in the EU and in other countries — including the United States — because several processors we rely on are established there. The following processors may receive personal data and are located outside Switzerland and the EEA:
The database (Neon) is hosted in the EU (Frankfurt). We transfer personal data outside Switzerland and the EEA only where an adequate level of protection is assured: under the Swiss–US and EU–US Data Privacy Framework where a processor is certified under it, or otherwise under the European Commission's Standard Contractual Clauses and their Swiss-law equivalents, supplemented by transfer impact assessments where appropriate. We will provide a copy of the safeguards on request where you are entitled to one.
Merco uses automated processing to support compliance and marketplace decisions — for example to assess and score supplier compliance, to rank suppliers and products, and to suggest matches in the marketplace. These are tools that support, and do not replace, human judgement.
We do not take decisions producing legal or similarly significant effects concerning you based solely on automated processing, except where necessary to enter into or perform a contract with you, where authorised by law, or where you have consented. Where such automated decision-making takes place, you have the right to obtain human intervention, to express your point of view and to contest the decision. To do so, contact us as set out under “Controller & contact”.
To create a tamper-evident, independently verifiable record, Merco anchors a digest of compliance decisions and due-diligence documents to a public blockchain (Polygon). The data published is a one-way cryptographic hash of the underlying record, together with a short identifier of the record type.
Because a public blockchain is immutable, anything anchored to it cannot be altered or removed. We therefore publish only digests and minimal identifiers, never the contents of documents or your personal data. Where a feature publishes a record identifier on-chain, that identifier is a non-descriptive reference to a transaction, not your personal data on its own. This means that, for the specific records that have been anchored, the right to erasure is limited by the technical impossibility of removing a public, immutable entry, which we consider to fall within the legal-obligation and legitimate-interest bases described above. All substantive personal data remains in our controlled systems, where your rights apply in full.
When identity verification is required — typically for higher-value transactions — we use Stripe Identity. Stripe collects and verifies your government identity document and a facial image, and holds that data as the controller of the verification process under its own terms. Merco receives and stores only the outcome and a reference to the verification, not the underlying documents.
We keep personal data only as long as necessary for the purposes set out in this policy and to meet our legal and contractual obligations. In particular:
When data is no longer needed, we delete it or anonymise it so that it can no longer be linked to you, subject to any legal retention obligation.
Subject to applicable law, you have the right to:
To exercise any of these rights, contact us through the access form or at the privacy address above. We respond within the time the law requires (usually one month, which may be extended for complex requests). Where your records are exportable, you can also obtain them directly from within the Platform.
If you believe we have not handled your data correctly, you have the right to complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, if you are in the EU, to your local data-protection authority.
We protect personal data with measures appropriate to the risk, including encryption of data in transit, access controls limited to authorised personnel, secure password storage and optional two-factor authentication, segregation of roles, logging of sensitive actions, and access controls over uploaded documents. We cannot guarantee absolute security, but we work to meet our obligations and to notify you and the authorities where the law requires it in the event of a personal-data breach.
The Platform is a business service and is not directed at children. We do not knowingly collect personal data from anyone under the age of sixteen. If you believe we have collected personal data from a child, contact us and we will delete it.
We may update this policy to reflect changes in our practices, the law or the Platform. We will publish the updated policy here with the date above and, where a change is material, we will give you notice. Continued use of the Platform after a change takes effect constitutes acceptance of the updated policy, to the extent permitted by law.
This policy is published by Merco. Operator-specific particulars (entity details, the privacy email address, and the identity of any appointed representative) are shown as fields to be completed on incorporation and should be confirmed by a qualified lawyer before launch. It does not constitute legal advice.