Data Processing Agreement
Last updated: 25 July 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the Customer (“Controller”) and Meritly (“Processor”) and applies where Meritly processes Personal Data on the Customer's behalf. It is intended to help you meet Article 28 GDPR and comparable requirements. It is a template that must be reviewed by your legal counsel and, where a signed agreement is required, completed and executed by both parties. Bracketed items must be filled in before use.
Contents
- Definitions
- Scope & roles
- Processing on documented instructions
- Confidentiality
- Security measures
- Sub-processors
- Assistance to the Controller
- Personal data breaches
- International transfers
- Return & deletion
- Audits & information
- US state privacy (CCPA/CPRA)
- Liability & term
- Annex A — Details of processing
- Annex B — Sub-processors
- Annex C — Technical & organizational measures
- How to execute this DPA
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms of Service. “Data Protection Laws” means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and US state privacy laws such as the California Consumer Privacy Act as amended (“CCPA/CPRA”). “Personal Data”, “processing”, “controller”, “processor”, “data subject”, and “personal data breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data contained in Customer Data that Meritly processes on the Customer's behalf. “Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission (Decision 2021/914) and, for the UK, the ICO's International Data Transfer Addendum.
2. Scope & roles
This DPA applies to Meritly's processing of Customer Personal Data to provide the Service. The Customer is the controller (or a processor acting for another controller) and Meritly is the processor (or sub-processor). Each party will comply with its obligations under Data Protection Laws. The Customer is responsible for the lawfulness of the Customer Personal Data and of the instructions it gives, including having a valid legal basis and any required consents for collecting End User data and sending communications through the Service.
3. Processing on documented instructions
Meritly will process Customer Personal Data only on the Customer's documented instructions — including as set out in the Terms, this DPA, and the configuration and use of the Service by the Customer — and as required by applicable law (in which case Meritly will, where legally permitted, inform the Customer). The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of data subjects are described in Annex A. Meritly will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4. Confidentiality
Meritly ensures that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and process the data only as necessary to provide the Service.
5. Security measures
Taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, Meritly implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Annex C. The Customer is responsible for the security of its own systems, credentials, and configuration, and for using the security features made available by the Service.
6. Sub-processors
The Customer provides general authorization for Meritly to engage the sub-processors listed in Annex B to process Customer Personal Data. Meritly imposes on each sub-processor data-protection obligations that are, in substance, no less protective than those in this DPA, and remains responsible for its sub-processors' performance. Meritly will make available the current list of sub-processors and will give the Customer reasonable notice of any intended addition or replacement so the Customer may object on reasonable data-protection grounds; if an objection cannot be resolved, the Customer may terminate the affected Service as its remedy.
7. Assistance to the Controller
Taking into account the nature of the processing, Meritly will assist the Customer with appropriate technical and organizational measures, insofar as possible, to: (a) respond to data subject requests to exercise their rights; (b) ensure compliance with security, breach notification, data protection impact assessment, and prior-consultation obligations (Articles 32–36 GDPR). Where an End User contacts Meritly directly, Meritly will, without undue delay, refer the request to the relevant Customer and will not respond directly except to confirm the referral, unless legally required or instructed by the Customer.
8. Personal data breaches
Meritly will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations. Meritly's notification is not an acknowledgment of fault or liability.
9. International transfers
The Customer authorizes Meritly and its sub-processors to transfer Customer Personal Data internationally as necessary to provide the Service. Where such transfers are subject to the GDPR or UK GDPR and are made to a country without an adequacy decision, they are made under the Standard Contractual Clauses (with the UK Addendum where applicable) or another valid transfer mechanism, which are incorporated by reference. For the SCCs: the module reflecting the parties' roles applies (controller-to-processor or processor-to-processor); the docking, redress, and governing-law options are as set out in [specify SCC options / Member State]; and Annexes A–C to this DPA populate the corresponding SCC annexes.
10. Return & deletion
On termination or expiry of the Service, and at the Customer's choice, Meritly will delete or return Customer Personal Data and delete existing copies, unless retention is required by applicable law. The Customer may also delete Customer Data within the Service during the term. Residual copies in routine backups are deleted in the ordinary course of Meritly's backup cycle and remain protected by this DPA until deleted.
11. Audits & information
Meritly will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To minimize disruption, the Customer will give reasonable prior notice, conduct audits during business hours no more than once per year (unless required by a supervisory authority or following a breach), and Meritly may satisfy audit requests by providing relevant documentation or third-party reports where available.
12. US state privacy (CCPA/CPRA)
To the extent the CCPA/CPRA applies, Meritly acts as the Customer's “service provider”. Meritly will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA; or (c) combine it with data from other sources except as permitted by the CCPA. Meritly certifies that it understands and will comply with these restrictions.
13. Liability & term
This DPA takes effect when the Customer begins using the Service (or on execution, if a signed copy is required) and continues while Meritly processes Customer Personal Data. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms on data-protection matters, this DPA controls; the SCCs control over this DPA to the extent of any conflict regarding restricted transfers.
Annex A — Details of processing
Subject matter: provision of the Meritly Service (AI lead capture, qualification, and multi-channel follow-up).
Duration: the term of the Service plus any period until deletion or return of Customer Personal Data.
Nature & purpose: hosting, storage, transmission, AI-assisted analysis and scoring, and delivery of messages, to provide the Service on the Customer's instructions.
Categories of data subjects: the Customer's leads, prospects, customers, and other contacts (End Users); and the Customer's authorized users.
Types of Personal Data: contact identifiers (name, email, phone, WhatsApp number); communications content (chat and, where enabled, voice input and transcripts); AI-derived inferences (intent, urgency, budget signals, decision stage, objections, preferences, lead score, priority, summaries); delivery and consent metadata (channel, direction, status, follow-up history, opt-out status); and account/authentication data for authorized users.
Special-category data: not intended or required. The Customer must not submit special-category or otherwise sensitive data unless it has a lawful basis and has notified Meritly.
Frequency: continuous, for the duration of the Service.
Annex B — Sub-processors
The following sub-processors are authorized to process Customer Personal Data:
- OpenAI — conversational AI and lead analysis/scoring.
- Anthropic — processing of uploaded knowledge-base content.
- ElevenLabs — voice synthesis for voice interactions.
- Twilio — SMS and WhatsApp message delivery.
- Resend (and, where configured by the Customer, the Customer's SMTP email provider) — email delivery.
- Supabase — database hosting and storage.
- Railway — backend application hosting.
- Vercel — website and dashboard hosting.
[Add each sub-processor's legal entity, processing location/region, and purpose, and keep this list current. Confirm each provider offers GDPR-compliant terms/SCCs.]
Annex C — Technical & organizational measures
Meritly maintains measures including, as applicable:
- encryption of data in transit (TLS/HTTPS);
- access controls, including row-level security on the database and least-privilege access;
- server-side handling of secrets and scoped API keys, kept out of client code;
- authentication controls for account access;
- logical separation of Customer accounts (tenant isolation) enforced server-side;
- constant-time credential checks and input sanitization on public endpoints;
- use of reputable infrastructure and sub-processors; and
- logging and monitoring to support detection and response.
[Expand with your current measures — data-at-rest encryption, backups, retention schedules, personnel training, incident-response procedures, and any certifications — and keep this annex accurate.]
How to execute this DPA
If you require a signed DPA (for example, to satisfy your own compliance obligations), contact us at hello@meritly.dev and we will provide a copy for signature. Absent a separate signed agreement, this DPA applies to your use of the Service as part of the Terms of Service. Operator: [Legal Entity Name, Registered business address].