Controller–processor terms
Data Processing Addendum
This DPA is a ready-to-sign framework for production organizational customers. It is not activated by sandbox browsing alone.
1. Parties and priority
The “Customer” is the entity identified in the applicable order. “Meridian” is Milos Topic, an individual operator in Serbia trading as Meridian Data Exchange, correspondence address Kosmajska 002, 11036 Belgrade, Serbia. Customer is controller and Meridian is processor for Customer Personal Data, except where either party acts as an independent controller under applicable law. This DPA prevails over conflicting service terms on personal-data processing; mandatory standard contractual clauses prevail over this DPA.
2. Definitions
“Applicable Data Protection Law” means laws governing the processing, security, breach notification, or rights relating to personal data, including where applicable the Serbian Law on Personal Data Protection, EU GDPR, UK GDPR, and US state privacy laws. “Customer Personal Data” means personal data Meridian processes for Customer under documented instructions. “Subprocessor”, “personal data”, “controller”, “processor”, “data subject”, and “processing” have their statutory meanings.
3. Instructions and compliance
Meridian will process Customer Personal Data only to provide the ordered Service, on Customer's documented instructions, or as law requires. The agreement, order form, configuration, approved API calls, and authorized support requests are documented instructions. Meridian will notify Customer before legally required processing unless prohibited. Customer is responsible for the lawfulness, transparency, minimization, accuracy, and instructions relating to Customer Personal Data.
4. Confidentiality and access
Meridian will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed for their duties. Access is reviewed and can be revoked. Meridian will not sell Customer Personal Data or use it for advertising.
5. Security measures
Taking account of risk, Meridian will maintain appropriate measures including: provider-managed authentication; role and tenant authorization; least privilege; encryption in transit; encrypted sensitive contact data at rest; secrets outside source code; pseudonymous actor identifiers; signed and replay-protected webhooks; request size limits and rate limiting; security headers; audit logging and integrity evidence; vulnerability and dependency review; incident management; backup/recovery procedures; data minimization; aggregate delivery controls; and change/release review.
Specific production measures, regions, recovery objectives, and assurance reports will be recorded in the order or security schedule. Customer acknowledges that the public sandbox is not approved for Customer Personal Data.
6. Subprocessors
Customer gives general authorization to use the providers in the provider register. Meridian will impose data-protection obligations appropriate to each processing role and remains responsible for processor subprocessors as required by law. Meridian will give at least 14 days' notice of a new material subprocessor where practicable. Customer may object on reasonable data-protection grounds; the parties will seek a practical alternative, and Customer may terminate the affected ordered service if no reasonable alternative exists.
7. Data-subject requests
Taking account of the processing, Meridian will provide reasonable technical and organizational assistance for Customer to answer requests for access, correction, deletion, restriction, portability, objection, or consent withdrawal. Meridian will notify Customer of a request concerning Customer Personal Data and will not respond except on Customer's instruction or as law requires.
8. Personal-data breach
Meridian will notify Customer without undue delay after becoming aware of a confirmed breach of Customer Personal Data. Available notice will describe the nature, affected data and people, likely consequences, mitigation, and contact point. Meridian will investigate, contain, remediate, preserve evidence, and reasonably assist Customer with legally required notifications. Notice is not an admission of fault.
9. DPIAs, consultations, and compliance evidence
Meridian will reasonably assist with security obligations, data-protection impact assessments, and regulator consultation related to the ordered processing. On reasonable request it will provide information necessary to demonstrate compliance. Audits should first use current independent evidence where available; an on-site audit may occur no more than annually unless a breach, regulator, or substantiated concern requires more, with reasonable notice, confidentiality, limited scope, and avoidance of disruption.
10. Return and deletion
At the end of the Service, Meridian will, at Customer's choice and where technically feasible, return Customer Personal Data and delete remaining copies within 30 days after the agreed export window, unless law requires retention. Retained data remains protected and is used only for the required purpose. Backup copies are deleted on the normal secure rotation cycle.
11. International transfers
Restricted transfers require a lawful mechanism. Where EU personal data is transferred to a country without an adequacy decision, the 2021 EU Standard Contractual Clauses are incorporated with the module appropriate to the parties' roles, supplemented by the order form and transfer assessment. Equivalent UK or other addenda apply where required. The parties will add the exporter/importer identity, competent authority, law, forum, categories, locations, and safeguards before production processing.
Schedule 1 — Details of processing
- Subject matter
- Permissioned data-request, consent, metadata wallet, controlled delivery, evidence, privacy-rights, and organizational workflow services described in the order.
- Duration
- For the term of the ordered Service plus the deletion/export period.
- Nature and purpose
- Hosting, organizing, securing, querying, aggregating, evidencing, supporting, and deleting data solely to provide the configured Service.
- Data subjects
- Customer personnel, authorized users, individual participants, applicants, and people represented in Customer-authorized data.
- Data types
- Account and professional contact data, identifiers, permissions, provenance/metadata, request and consent records, audit events, support communications, and only the production categories expressly approved in the order.
- Excluded by default
- Raw special-category data, children's data, precise credentials, full payment-card data, and any data not expressly approved.
- Frequency
- Continuous or event-driven as configured.
- Retention
- As stated in the order and Customer configuration, subject to legal retention.
Schedule 2 — Contacts and signatures
Meridian contact: Milos Topic, individual operator in Serbia, Kosmajska 002, 11036 Belgrade, Serbia; office@meridiandataexchange.com. Customer identity, privacy/security contacts, effective date, governing agreement, selected hosting region, approved categories, and transfer annexes must be completed in the signed order.
