Controller and processor roles
For customer content placed inside a workspace, the customer generally acts as controller and decides why and how personal data is used; Mercestack generally acts as processor to deliver the configured service. Mercestack acts as controller for its own account administration, billing, website, support and security data. The exact role always depends on the processing context.
Data protection principles
Our product direction follows the GDPR principles of lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Workspace controls such as permissions, module activation, audit history and retention are intended to help customers apply those principles.
Data-subject rights
GDPR rights can include being informed, access, rectification, erasure, restriction, portability, objection and protections relating to solely automated decisions. Requests concerning data controlled by a Mercestack customer should be made to that customer first. We will support verified customer instructions and respond to requests for which Mercestack is controller.
Security and access
Mercestack applies workspace scoping, permission checks, encrypted provider credentials, signed webhook verification and attributable audit history. Customers remain responsible for assigning suitable roles, reviewing agent permissions and configuring connected providers.
Subprocessors and transfers
Infrastructure, payment, delivery, storage and AI providers may process data to deliver customer-selected functionality. Before serving regulated production workloads, the applicable subprocessor list, processing locations and transfer safeguards should be confirmed in the customer agreement or data processing addendum.
Requests, complaints and response time
Send verified requests to privacy@mercestack.com. We aim to respond without undue delay and within the period required by applicable law. Individuals may also lodge a complaint with the relevant supervisory authority.
Regulatory references
For authoritative guidance, review the European Commission’s information for individuals and the European Data Protection Board’s controller and processor guidance.