Merco

Merco · Legal

Privacy notice

Personal data at Merco: purposes, recipients, retention and your rights.

PREPARATION DRAFTPrepared for the intended Dutch operator. Incorporation and operational reviews are pending. These drafts are not effective contracts and do not authorise order funding.

Preparation draft · 27 September 2026 · 2026-09-27-draft-2

01Who is responsible

This notice covers merco.dev, the Merco business platform and Merco Studio. The operator is Merco Technologies B.V. (intended operator; registration pending). Its registered and business addresses, registration details and authorised representatives are in the legal notice. Privacy contact: Privacy email to be confirmed before publication.

Merco serves business customers. Business contact details, sole-trader records and information about employees, directors and beneficial owners can still be personal data. This notice concerns those individuals, including people whose details a business uploads. The GDPR applies where its territorial conditions are met; Swiss data-protection law also applies where relevant.

Merco controls account administration, billing, security, support and the purposes it determines for marketplace operations. When it processes customer-controlled workspace data solely on a business customer’s instructions, the customer is the controller and Merco is its processor under the Data Processing Agreement. Payment providers, banks, authorities and trading counterparties may act as independent controllers.

  • EU representative: assessment and any required appointment must be completed before publication.
  • Privacy enquiries go to the privacy contact. A DPO is appointed and identified here if legally required.

02Data and its sources

Sources include you, your organisation and invited teammates, trading counterparties, payment/logistics providers and business registers or public sources used for verification. Public-source processing is limited to relevant business and risk checks. Do not upload unnecessary sensitive personal data, children’s data or confidential material you are not authorised to share.

  • Accounts and enquiries: name, work email, telephone, organisation, role, access requests, correspondence, authentication records and account preferences.
  • Business and trade: addresses, company and tax identifiers, VAT/EORI details, capability records, factory locations, quotes, orders, invoice details and shipment references.
  • Workspace content: messages, uploaded documents, signatures, photographs, references, Studio briefs, specifications, generated visuals and files. These can contain personal data about you or other people.
  • Verification and payments: identity and beneficial-owner information, date of birth or identity documents where requested, bank beneficiary details, provider references, verification status and transaction/release records. The information requested depends on the applicable provider flow.
  • Technical and usage data: IP addresses, user agents, requests, security events, consent/acknowledgement records, searches and interaction signals used inside the product. Browser storage is explained in the cookie and storage notice.

03Why we process it

Where GDPR legitimate interests are used, we assess necessity and the impact on individuals and apply proportionate safeguards. You may object. Reading or acknowledging this notice is not consent to every processing activity. Data necessary for an account or requested feature must be provided to use that feature; optional fields and marketing choices remain optional.

  • Enquiries and account administration: answering requests and maintaining business relationships. GDPR basis: legitimate interests in providing and administering a B2B service; pre-contractual steps or contract performance where the individual is personally the contracting party.
  • Workspace services, Studio and order coordination: providing the requested features. For customer-controlled content we act on documented customer instructions. For our own business contact processing, our legitimate interest is delivering the organisation’s service; contract performance applies where you personally contract with us.
  • Security, fraud prevention and relevant counterparty checks: legitimate interests in protecting users and the platform. Applicable statutory duties are a separate basis only where they actually bind Merco.
  • Billing, accounting and required reporting: applicable legal obligations and administration of contracts. We do not treat every customer’s customs or compliance obligation as Merco’s own statutory obligation.
  • Optional marketing: consent where required, or a lawful existing-customer exception where available. You can unsubscribe or object. Refusing marketing does not prevent service access.

04Studio and AI processing

Merco uses AI to assist with references, documents, specifications, concept images, drafting and compliance work. Relevant prompts, files, images and conversation context can be sent to the AI provider to deliver the requested feature. The provider register identifies the services used. Limit uploads to material needed for the task.

Studio output is a working aid. A designer or factory must review dimensions, construction, material and fit before sampling or production. Automated matches or risk indicators can affect which information users see; they are not a substitute for a human assessment of the evidence.

Requests to the current OpenAI API use business services, whose default policy excludes API data from model training unless the customer opts in. Provider retention and abuse-monitoring arrangements are separate from training. Merco does not promise zero retention or that data stays exclusively in Europe. Any change enabling model-training use of identifiable customer content requires an appropriate legal basis and a separate, clear disclosure.

You can ask for correction or human review of an inaccurate personal-data assessment. A materially significant decision about an individual must receive the safeguards required by applicable law; business-level scoring does not automatically remove those obligations.

05Who receives data

Relevant information is shared with your organisation’s authorised users and with counterparties or service partners where your workflow requires it. For example, a sourcing brief sent to factories includes the relevant reference files and contact information; an order shares documents needed by its buyer, supplier and authorised logistics/compliance participants. Review recipients before sharing.

Infrastructure, AI, email, mapping, search and verification vendors receive data needed for their service. Payment providers receive identity, business, bank and transaction data for the applicable account or transaction. Authorities receive information where required by law or properly authorised. A corporate transaction can involve limited due-diligence disclosure subject to confidentiality and lawful safeguards. We do not sell personal data for third-party advertising.

06Countries and safeguards

The service can involve access or processing in the Netherlands, Switzerland, the EEA, the United States and countries where your counterparties or requested providers operate. The provider register must identify the actual contracted entities, processing/support locations and relevant safeguards before this notice becomes effective. Database region alone does not determine every data location.

For transfers subject to GDPR or Swiss restrictions, we use a relevant adequacy decision, or appropriate contractual safeguards such as the applicable European Commission standard clauses with Swiss adaptations where needed, alongside an assessment of the transfer and any necessary supplementary measures. A Data Privacy Framework certification can be used only for an eligible, currently certified recipient and the relevant transfer. Ask the privacy contact for information or a copy of the applicable safeguards, with confidential details redacted where justified.

07How long data is held

We keep data for the purpose that justified collecting it, then delete or anonymise it unless a documented legal obligation or claim requires retention. Account and workspace data are generally needed during the relationship. After termination, export, deletion and retained records are handled under the contract and DPA; necessary accounting and dispute records are kept separately with restricted access.

Retention is decided by record type and applicable law, not a blanket “five years for everything”. The existing operational pruning rules target finished AI runs after 90 days, search-intent vectors after 60 days, read notifications after 45 days and audit logs after 180 days; expired compliance records use their recorded expiry date. Cookie-choice evidence expires after twelve months. A legal hold can override deletion. Production scheduling, backup expiry and deletion of accounts/files must be verified before publication.

Payment providers keep records under their own obligations. Public blockchain entries, where a feature creates them, may be irreversible. Hashes or identifiers can remain personal data when linkable to an individual. Do not publish personal information on a public ledger; the feature and its consequences require specific disclosure before use.

08Your rights and requests

Use Settings → Privacy or contact Privacy email to be confirmed before publication to request access, correction, deletion, restriction, portability where applicable, or to object. You can withdraw consent without affecting earlier lawful processing. We may ask for proportionate identity verification. For GDPR requests we respond within one month, with a permitted extension explained within that period where necessary. Rights can be limited by applicable law, third-party rights and justified retention.

If we hold the data as a processor for your organisation, we assist its controller with the request. You may complain to the competent regulator, including the Dutch Autoriteit Persoonsgegevens, a regulator in your EEA place of residence/work, or the Swiss FDPIC where relevant. Contacting Merco first is optional.

09Security and updates

We apply security measures appropriate to the processing risk, including access restrictions, protected communications, authentication controls and controlled handling of files. No service can guarantee absolute security. The DPA describes the agreed controls for customer data. Significant changes to this notice are announced through an appropriate channel; a new controller is identified explicitly if the operator changes.

Legal centre

Your browser choice

Sign-in and security work without optional storage. Choose whether this browser remembers interface preferences and animation state. No advertising tracking.

Cookies & storage notice · Privacy notice