This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Merdial and the customer. It governs Merdial’s processing of personal data on the customer’s behalf and reflects Article 28 of the GDPR and the UK GDPR. It applies automatically — you do not need to sign a copy for it to be in force.
Need it signed?
Customers who need a countersigned PDF, an amended DPA, the Standard Contractual Clauses on their own paper, or a completed security questionnaire can request one at team@merdial.com.1. Definitions
Controller, Processor, Data Subject, Personal Data, Processing and Personal Data Breach have the meanings given in the GDPR. Customer Personal Data means personal data contained in Customer Data as defined in the Terms. Data Protection Law means the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss FADP, the CCPA as amended by the CPRA, and every other applicable privacy law.
2. Roles of the parties
For Customer Personal Data the customer is the Controller and Merdial is the Processor. Where Merdial processes data for its own purposes — account administration, billing, security and platform integrity — it acts as a Controller, and that processing is governed by the Privacy Policy, not by this DPA. Under US state privacy law, Merdial is a “service provider” / “processor” and does not sell or share Customer Personal Data or retain, use or disclose it outside the direct business relationship.
3. Processing on documented instructions
Merdial processes Customer Personal Data only on the customer’s documented instructions, which comprise this DPA, the Terms, the configuration the customer sets in the product, and any further written instruction the parties agree. Merdial will not process Customer Personal Data for its own purposes.
Merdial will immediately inform the customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is resolved. Where a law requires Merdial to process beyond the customer’s instructions, Merdial will inform the customer before processing unless that law forbids it.
The customer warrants that it has a lawful basis for the personal data it puts into the Service, that it has given every required notice to data subjects — including its own staff and the people it calls — and that its instructions comply with Data Protection Law.
4. Confidentiality of personnel
Merdial ensures that every person authorised to process Customer Personal Data is bound by a written confidentiality obligation that survives their engagement, has been trained on data protection, and has access only to what their role requires. Access to production data follows least privilege, is logged, and is revoked on role change or departure.
5. Security (Article 32)
Merdial implements and maintains the technical and organisational measures set out in Annex II below and in the Security Overview. Measures may be updated as the state of the art moves, provided the level of protection is not reduced.
6. Sub-processors
The customer grants Merdial general written authorisation to engage sub-processors. The current list, with each vendor’s function and location, is published at Sub-processors.
- Merdial imposes on every sub-processor, by written contract, data protection obligations no less protective than those in this DPA.
- Merdial remains fully liable to the customer for a sub-processor’s performance.
- Notice and objection. Merdial gives at least 30 days’ notice before a new sub-processor starts processing, by email to subscribed administrators and by updating the sub-processor page. The customer may object on reasonable data-protection grounds within that window. If the parties cannot resolve the objection, the customer may terminate the affected subscription and receive a pro-rated refund of prepaid fees for the unused term.
7. Assistance with data-subject rights
The Service gives the customer the ability to access, correct, export and delete Customer Personal Data itself, which is the primary way this obligation is met. If a data subject contacts Merdial directly, Merdial will not respond substantively but will forward the request to the customer without undue delay. Merdial will provide reasonable additional assistance, taking into account the nature of processing, and may charge for assistance that is disproportionate.
8. Breach notification, DPIAs and prior consultation
- Merdial notifies the customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware, with what is known at the time: nature of the breach, categories and approximate number of records and data subjects, likely consequences, and the measures taken or proposed.
- Merdial will provide reasonable assistance with the customer’s obligations under Articles 32 to 36, including data protection impact assessments and prior consultation with a supervisory authority.
- Merdial will not notify a supervisory authority or data subject on the customer’s behalf unless the customer asks it to.
9. Return and deletion
On termination, and at the customer’s election, Merdial deletes or returns Customer Personal Data. Customers may export through the Service for 30 days after termination; Merdial then deletes or irreversibly anonymises within 90 days. Encrypted backups age out on a rolling 35-day cycle. Merdial may retain data where law requires, in which case it remains subject to this DPA and is processed only for that purpose.
10. Audit
Merdial makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits. In the first instance this is satisfied by Merdial’s security documentation and a completed security questionnaire. A customer with a genuine regulatory need may conduct an on-site or remote audit no more than once in any twelve months, on 30 days’ notice, during business hours, subject to confidentiality, at the customer’s cost, and without disrupting the service or exposing another customer’s data. A supervisory authority’s audit right is not limited by this clause.
11. International transfers
Where Merdial transfers Customer Personal Data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the transfer is governed by:
- The EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), incorporated by reference — Module 2 where the customer is a controller and Merdial a processor, and Module 3 where the customer is itself a processor. Docking clause applies; the optional independent dispute-resolution clause does not; the governing law and forum are those in the Terms; the audit and sub-processor terms above supply the SCC options.
- The UK International Data Transfer Addendum (version B1.0) for UK transfers, and the SCCs as amended by the Swiss FDPIC for Swiss transfers.
- A documented transfer impact assessment, with encryption in transit and at rest and tenant isolation as supplementary measures.
Where a conflict arises between this DPA and the SCCs, the SCCs prevail.
Annex I — The processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Merdial AI revenue-operations platform. |
| Duration | The subscription term, plus the deletion window in §9. |
| Nature and purpose | Recording, storage, transcription, analysis, scoring, generation of live coaching and lead-qualification output, workflow, delivery and reporting — and improvement of Merdial’s own models on de-identified content, as described in Privacy §5. |
| Categories of data subject | The customer’s staff (agents, managers, owners, administrators); the customer’s end clients and their staff; the individuals the customer calls or who call the customer (prospects, leads, callers). |
| Types of personal data | Name, work and personal contact details, employer and job title; voice recordings and transcripts of calls; the content of what a person said; performance, attendance and payroll records for the customer’s staff; qualification answers; appointment details; account identifiers and IP address. |
| Special categories | Not requested, and not required by the Service. Call content is free-form speech and may incidentally contain special-category data; the customer must not deliberately submit it, and must configure retention accordingly. |
| Frequency | Continuous, for the duration of the subscription. |
| Sub-processor transfers | As listed at /docs/sub-processors. |
| Competent supervisory authority | That of the customer’s EU/UK establishment or its Art. 27 representative. |
Annex II — Technical and organisational measures
Contact
DPA and privacy contracting: team@merdial.com. Data protection enquiries: team@merdial.com. This DPA is effective 6 September 2026.

