Data processing addendum
You decide. We process on your instructions, in writing. The processing commitments that form part of every Mercleo agreement: purpose limits, confidentiality, subprocessors, breach notice, assistance with rights requests, export and deletion.
Scope
Last updated: 6 September 2026.
This addendum forms part of the Terms of service between Mercleo Technologies Inc. ("Mercleo") and the customer organization ("Customer"). It applies whenever Mercleo processes personal information that Customer puts into the Services about Customer's own people: contacts, members, donors, attendees, applicants, employees and learners ("Customer Personal Information").
Roles
Customer decides why and how Customer Personal Information is collected and used, and is the organization accountable for it under PIPEDA, Quebec's private-sector privacy act, and any other law that applies to Customer. Mercleo processes it on Customer's documented instructions to provide the Services. Customer's instructions are the Terms, this addendum, and the settings Customer configures in the product.
For information Mercleo collects in its own right (account holders, billing contacts, website visitors) Mercleo is accountable directly, and the Privacy policy governs.
What Mercleo will do
- Process Customer Personal Information only to provide, secure and support the Services, and never for Mercleo's own marketing.
- Keep it confidential, and limit access to personnel who need it to do their job and are bound by confidentiality obligations.
- Protect it with safeguards appropriate to its sensitivity, as described at /trust/security, including encryption in transit and at rest and access logging for sensitive fields.
- Use only the subprocessors listed at /trust/subprocessors, flow down equivalent obligations to them, and update that page when the list changes. Customer may ask for email notice of changes and may object to a new subprocessor; if the objection cannot be resolved, Customer may cancel the affected Services and receive a refund of unused prepaid fees.
- Assist Customer in responding to access, correction and deletion requests from individuals, and pass to Customer any such request that reaches Mercleo directly.
- Notify Customer without unreasonable delay after confirming a breach of security safeguards affecting Customer Personal Information, with what Mercleo knows about its nature, the information involved, and the steps taken.
- Make an export of Customer Personal Information available on request during the term and for 30 days after termination, and delete it from live systems on a verified deletion request, within 30 days of that request, except copies Mercleo must retain by law. Copies in encrypted backups age out on the backup schedule.
- Answer reasonable written questions about these commitments so Customer can meet its own accountability obligations.
What Customer will do
- Have the consents, notices and legal bases its collection requires, including for tracking on its own websites and for messages it sends through the Services (see CASL in the Terms).
- Configure the product's consent, privacy-link and retention settings for its own obligations.
- Not put into the Services information the Services are not designed to hold, such as government identifiers or health information, except in fields marked sensitive.
Where processing happens
Some subprocessors process data in the United States. The jurisdictional picture is stated at /trust/data-residency. Customer is responsible for any assessment its own law requires before transferring personal information outside its province or country, and Mercleo will supply the information needed for it.
Term and precedence
This addendum applies for as long as Mercleo holds Customer Personal Information. If it conflicts with the Terms on the handling of Customer Personal Information, this addendum governs. Organizations whose own obligations need different or additional terms should write to legal@mercleo.com before purchase.