merce.STACK
merce.STACK
Skip to content
ProductsPricingAboutSecurityContact
Log inGet started
Open navigation menu
ProductsPricingAboutSecurityContact
Log inGet started

Data protection

GDPR readiness

Mercestack is designed to support responsible processing and customer obligations under the General Data Protection Regulation. This page describes our operating approach and is not a claim of certification.

Last updated

14 September 2026

Questions or privacy requests:

privacy@mercestack.com

Controller and processor roles

For customer content placed inside a workspace, the customer generally acts as controller and decides why and how personal data is used; Mercestack generally acts as processor to deliver the configured service. Mercestack acts as controller for its own account administration, billing, website, support and security data. The exact role always depends on the processing context.

Data protection principles

Our product direction follows the GDPR principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Workspace controls such as permissions, module activation, audit history and retention are intended to help customers apply those principles.

Data-subject rights

GDPR rights can include being informed, access, rectification, erasure, restriction, portability, objection and protections relating to solely automated decisions. Requests concerning data controlled by a Mercestack customer should be made to that customer first. We will support verified customer instructions and respond to requests for which Mercestack is controller.

Security and access

Mercestack applies workspace scoping, permission checks, encrypted provider credentials, signed webhook verification and attributable audit history. Customers remain responsible for assigning suitable roles, reviewing agent permissions and configuring connected providers.

Subprocessors and transfers

Infrastructure, payment, delivery, storage and AI providers may process data to deliver customer-selected functionality. Before serving regulated production workloads, the applicable subprocessor list, processing locations and transfer safeguards should be confirmed in the customer agreement or data processing addendum.

Requests, complaints and response time

Send verified requests to privacy@mercestack.com. We aim to respond without undue delay and within the period required by applicable law. Individuals may also lodge a complaint with the relevant supervisory authority.

Regulatory references

For authoritative guidance, review the European Commission’s information for individuals and the European Data Protection Board’s controller and processor guidance.

The operating system for companies that want structure, context and accountable automation in one workspace.

© 2026 Mercestack. All rights reserved.

Company

  • About
  • Products
  • Pricing
  • Security
  • Contact
  • Create workspace

Legal

  • Privacy
  • Terms
  • Cookie policy
  • GDPR
  • Privacy contact