Data processing agreement
Effective: August 2025.
This agreement applies where Merki processes personal data on behalf of a customer, typically for Enterprise use.
1. Roles
The customer is the controller. Merki is the processor. Merki runs inference on its own infrastructure and does not route requests to third-party inference providers. Where a customer uses BYOK, the provider the customer selects is a separate controller or processor under the customer's own agreement with that provider, not a Merki subprocessor.
2. Scope
The agreement covers personal data processed to provide the service: account data, billing data, verification results for the age-assured and identity-verified tiers, and operational data. Prompt and completion content is not retained except for per-account cache entries (24h), which are processed only to serve the customer's own repeat requests. Merki processes personal data only on the customer's documented instructions, keeps it confidential, and ensures staff access is limited to what the service requires. If Merki believes an instruction violates applicable law, it will inform the customer and suspend the affected processing until the instruction is clarified.
3. Data handling
Prompt and completion content is not retained, except for caching. See Zero data retention and the retention matrix. Cache entries are per-account, never shared, and evicted after 24 hours or when superseded.
4. Subprocessors
Verification is processed by Sumsub as Merki's processor for that purpose only. No subprocessor handles request data, and Merki does not route inference to third-party inference providers. See Subprocessors. If that changes, customers will be notified at least 30 days before a new subprocessor is engaged, and may object within that window; an unresolved objection is handled by suspending the affected processing or terminating the enterprise relationship with a pro-rata refund of unused paid credits.
5. Security measures
Access controls, encryption in transit and at rest, per-account cache isolation, logging with 90-day retention (security logs 1 year), and automatic revocation of exposed credentials. See API keys and Security.
6. International transfers
Cross-border transfers (including to Sumsub for verification) use appropriate safeguards: data-minimization to the check result, contractual protections, and necessity for the service. Customers may request transfer details from dpd@merki.dev.
7. Audit and assistance
Merki will provide the information reasonably needed to demonstrate compliance, and assist with data subject requests, within 30 days. Enterprise customers may request an annual security summary. Breach notification: without undue delay and within 72 hours of becoming aware, to the customer contact on file.
8. Term
The agreement runs with the service relationship and ends when processing ends. On termination, request data needs no return (none retained beyond cache lifetime); account, billing, and verification records follow the retention matrix.
9. Contact
Data protection contact: dpd@merki.dev. Privacy: privacy@merki.dev.