Data Processing Agreement
- Effective from
- Last updated
- Version
- 1.0
This agreement governs the processing of personal data your organization uploads to or receives in meruma. It forms part of the terms of service and applies automatically from the moment your organization starts using the platform: there is nothing separate to sign. If your organization needs a signed copy, write to us.
It is entered into between your organization (“the controller”) and HIPER DEVS LLC, a Florida company, United States (“meruma”, “the processor”).
Roles of the parties
Your organization is the controller of the personal data it uploads to or receives in the platform: it decides what data is processed, what for, and on what grounds.
meruma is the processor of that data: we process it solely on your organization’s behalf and on its instructions.
If your organization is itself a processor for a third party — an agency running a client’s account, say — this agreement applies all the same, and your organization warrants that it has the authority needed to engage us.
For the account’s own data — who its users are, how they use it, how it is billed — meruma acts as a controller, and that is governed by the privacy policy, not by this agreement.
Subject matter and scope
The details are in Annex A. In short, meruma processes the data to provide the service you signed up for: receiving and sending messages over the connected channels, storing them, organizing them into contacts and pipelines, and running whatever features your organization turns on.
Processing lasts as long as the service does, plus the agreed deletion periods.
Instructions
meruma processes personal data only in accordance with your organization’s documented instructions, which are these terms, the configuration the organization chooses inside the product, and any further instruction we agree in writing.
If a legal obligation required us to process the data otherwise, we will tell your organization before doing so, unless that same law prohibits it.
If we believe an instruction infringes data protection law, we will say so.
meruma does not sell the data, does not use it for advertising, does not disclose it to third parties beyond the published subprocessors, and does not use it to train artificial intelligence models.
Confidentiality
meruma personnel with access to personal data are bound by confidentiality, receive data protection training, and access only what their role requires, under access controls.
Security
meruma applies technical and organizational measures appropriate to the risk, described in Annex B and detailed on the security page.
Subprocessors
Your organization gives general written authorization for meruma to engage subprocessors to provide the service. The current list is published on the subprocessors page.
Before adding or replacing a subprocessor, we publish it there and give at least 30 days’ notice. Within that period, your organization may object on reasonable data-protection grounds; we will look for an alternative and, if there is none, it may drop the affected service without penalty.
meruma imposes on each subprocessor protection obligations equivalent to those in this agreement and remains liable to your organization for their performance.
Data subject rights
meruma makes available to your organization the functionality it needs to handle access, rectification, erasure, restriction, portability and objection requests itself: the application lets you view, edit, export and delete a contact’s data.
If we receive a request directly from a data subject that concerns your organization’s data, we will not answer it ourselves: we will route it to your organization without undue delay and assist if asked.
Further assistance
Taking into account the nature of the processing and the information available to us, meruma assists your organization in meeting its obligations on security, breach notification, impact assessments and prior consultation with the supervisory authority.
Personal data breaches
If meruma becomes aware of a security breach affecting your organization’s personal data, we will notify it without undue delay, describing the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed.
Return and deletion
While the service is active, your organization can export its data whenever it wants.
On termination, meruma deletes the personal data under the data deletion policy: active data within 30 days and backups by rotation within 90. We retain only what a legal obligation requires, isolated from operational use.
Audits
meruma makes available the information needed to demonstrate compliance with this agreement, and cooperates with audits conducted by your organization or an auditor it mandates, on reasonable notice, during business hours, without disrupting operations, and under confidentiality.
International transfers
meruma processes data in the United States. For transfers from the European Economic Area, the United Kingdom or Switzerland, the parties agree to the Standard Contractual Clauses approved by Implementing Decision (EU) 2021/914, controller-to-processor module, incorporated into this agreement by reference, with your organization as exporter and meruma as importer.
Annex A · Details of processing
Subject matter: provision of the meruma service.
Duration: for the term of the contract, plus the deletion periods.
Nature and purpose: receiving, sending, storing, organizing, retrieving, amending and deleting personal data, so that the organization can manage its conversations, its contacts and its sales processes.
Categories of data subjects: the organization’s contacts and customers, people who write to it on any channel, people who fill in its forms, recipients of its campaigns, signers of its documents and attendees of its appointments.
Categories of personal data:
- Identification and contact details: name, phone, email, per-platform identifiers.
- Communication content: messages, attachments, voice notes.
- Call recordings, where the organization turns recording on.
- E-signature data: name, email, signature image, IP address, timestamp and audit trail.
- Form responses and any files attached to them.
- Calendar data: appointments, attendees and descriptions.
- Custom fields defined freely by the organization.
Special categories: the service is not designed to process sensitive data. If the organization chooses to put it into free-form fields, it does so on its own responsibility and must ensure it has a legal basis and adequate measures.
Annex B · Security measures
- Encryption in transit (TLS) and at rest.
- Isolation of each organization at the database level, with row-level security.
- Authentication managed by Amazon Cognito, with two-factor available.
- Role-based access control, least privilege for personnel.
- Access and activity logs.
- Backups with rotation and restore testing.
- Vulnerability management and dependency updates.
- Incident response procedure with customer notification.
The current detail is on the security page.
Annex C · Subprocessors
Those published on the subprocessors page, which forms part of this agreement.