Data Processing Agreement
1. Roles
For personal data that reaches Melqart from your connected store — your customers' names, email addresses, order records and similar — you are the Controller and Melqart is your Processor under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. For the account data of the people who use Melqart on your behalf, Melqart is a Controller, as described in the Privacy Policy.
2. Subject matter, nature and purpose of processing
- Subject matter: the catalogue, order and customer data that your store platform returns to Melqart through its official API once you connect it.
- Nature: collection (read-only sync on a schedule you can see in the product), storage, comparison against competitor observations, aggregation into recommendations and reports, and deletion or return on termination.
- Purpose: operating the Service for you — competitor monitoring, pricing recommendations, outcome measurement and the reports you export. Melqart does not use your customers' personal data to train models, to market to those customers, or for any purpose of its own.
- Duration: the term of your account, plus the deletion window in section 9.
3. Categories of data subjects and personal data
- Data subjects: your customers (where your store exposes order data), and your staff who use Melqart.
- Personal data: customer name and email address and order line items as returned by your platform's orders endpoint; staff name, email and role. Competitor price observations are commercial data about storefronts and are not personal data.
- Special category data: none is requested or required. If your catalogue or orders contain such data, you must not connect that store without agreeing additional safeguards with us in writing.
4. Your instructions
Melqart processes personal data only on your documented instructions. Connecting a store, choosing which competitors to monitor, approving a recommendation, requesting an export and requesting deletion are each an instruction. We will tell you if, in our opinion, an instruction infringes UK GDPR. We will not process the data for any other purpose unless required by law, in which case we will inform you first unless the law prohibits it.
5. Confidentiality
Everyone we authorise to process your data is bound by a written confidentiality obligation and has access only to what their role requires. Production data access is limited, logged and reviewed.
6. Security
We maintain technical and organisational measures appropriate to the risk, including: tenant isolation enforced at the database layer (row-level security, forced on every merchant-scoped table); encryption in transit; encryption of platform credentials at rest; least-privilege application roles; an audit trail on every approval and every price change; monitoring and alerting on the sync pipeline; and an incident-response procedure. The controls we actually run are described on the Security page, which we keep aligned with the deployed system rather than with aspiration.
7. Sub-processors
You authorise Melqart to engage the following classes of sub-processor, each bound by a written contract meeting UK GDPR Article 28 requirements: cloud hosting and managed database infrastructure; transactional email; error monitoring; payment processing (billing data only, never store data); and AI model providers that receive catalogue and competitor text to produce recommendations and drafts, and that are contractually barred from training on it. We will give you at least 30 days' notice of a new sub-processor by email to your account owner; you may object on reasonable data-protection grounds, and if we cannot address the objection you may terminate the affected Service. The current list is available on request to [email protected].
8. Assistance and data subject rights
Taking into account the nature of the processing, we will assist you in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) and in meeting your obligations on security, breach notification and data protection impact assessments. You can export your workspace data and request deletion yourself from the product (Settings → Data); for anything the product does not yet cover, email [email protected] and we will action it within 30 days.
9. Deletion and return
On termination of your account, or on your written request at any time, we will delete or return the personal data we process for you and delete existing copies within 30 days, unless UK law requires us to retain some of it (in which case we will retain only what the law requires, for only as long as it requires, and continue to protect it under this DPA). Backups age out on their own retention cycle and are not restored to reintroduce deleted data.
10. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification obligations, and will cooperate with you in the investigation and remediation.
11. International transfers
Our infrastructure is in the United Kingdom and the European Economic Area, with some sub-processors in the United States. Where personal data leaves the UK we rely on an adequacy regulation or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with any supplementary measures a transfer risk assessment identifies. Details for a specific transfer are available on request.
12. Audit
We will make available the information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, no more than once in any twelve-month period unless a supervisory authority requires otherwise or a breach has occurred, on reasonable notice and subject to confidentiality.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms of Service, save that nothing limits liability that cannot be limited under UK GDPR. This DPA is governed by the laws of England and Wales.
14. Contact
Delivery Nation Limited, England and Wales. Data protection enquiries: [email protected]. This DPA was last updated on 13 September 2026; material changes are dated on the changelog.