Data Processing Addendum.
This Data Processing Addendum (“DPA”) forms part of the commercial agreement between Mellovy AB and the customer that accepts or signs it (“Customer”). It applies only to the extent Mellovy processes Personal Data on Customer’s behalf as a processor. It does not apply to processing for which Mellovy acts as an independent controller, which is described in the applicable privacy notice.
This DPA is intended to satisfy Article 28 of Regulation (EU) 2016/679 (“GDPR”) where the GDPR applies. The parties’ actual roles are determined by their actual decisions about the purposes and means of processing, not only by the labels used in this DPA. Where the parties jointly determine those purposes and means, they will document their respective responsibilities as required by Article 26 GDPR before that processing begins.
1. Definitions and order of precedence
“Customer Personal Data” means Personal Data contained in Customer Data that Mellovy processes on Customer’s behalf in providing the services under the commercial agreement. “Data Protection Law” means the GDPR and any other applicable data protection law. “Subprocessor” means a processor engaged by Mellovy to process Customer Personal Data on Customer’s behalf. Terms not defined here have the meaning given in the commercial agreement or the GDPR.
If this DPA conflicts with the commercial agreement on the processing of Customer Personal Data, this DPA prevails. If it conflicts with a transfer instrument, the transfer instrument prevails for the relevant transfer.
2. Roles, instructions and processing description
Customer is the controller of Customer Personal Data, or the processor acting for its own controller, and will identify that controller to Mellovy when it acts as processor. Mellovy processes Customer Personal Data only on Customer’s documented instructions, including instructions in the commercial agreement, this DPA, the applicable order and Customer’s configuration of the Service. Customer instructs Mellovy to process Customer Personal Data as necessary to provide, secure, support and maintain the services ordered by Customer.
If Customer acts as a processor, Customer confirms that its controller has authorised Mellovy’s appointment and gives the instructions in this DPA on that controller’s behalf. Customer will pass down the obligations required by Data Protection Law. Mellovy will perform the processor obligations that apply to a subprocessor, and Customer will remain responsible to its controller for its own processor obligations.
Mellovy will tell Customer if an instruction appears to violate Data Protection Law. Mellovy may suspend the affected processing while the parties clarify or amend the instruction. If Mellovy is required by law to process Customer Personal Data otherwise, it will inform Customer before processing unless the law prohibits that notice.
The processing description is:
- Subject matter: operation of the AI-agent and related software services ordered by Customer, including support and security.
- Duration: the term of the commercial agreement and, after it ends, only for return or deletion of Customer Personal Data, compliance with law, or any limited retention specifically instructed by Customer.
- Nature and purposes: receiving, storing, organising, retrieving, transmitting, adapting, using and deleting data to provide configured agent features, process user instructions, connect systems selected by Customer, secure and troubleshoot the service, and provide support requested by Customer.
- Data subjects: Customer’s authorised users and other individuals whose information Customer or its authorised users submit, connect or otherwise make available through the services.
- Personal Data types: account and contact details, user identifiers and permissions, prompts and other user-provided content, documents and files, agent instructions and configuration, connected account content and metadata, and service/action logs, to the extent those contain information relating to an identified or identifiable person.
- Special categories and criminal-offence data: Customer determines whether any such data is included. The Service is not intended for such data unless Mellovy has expressly agreed in writing to support the relevant use and Customer has established a lawful basis and safeguards.
3. Customer responsibilities
Customer will comply with Data Protection Law, establish and document a lawful basis for the processing, provide required notices, respond to data-subject requests, and ensure its instructions are lawful. Customer will limit the Personal Data submitted to what is necessary, set appropriate permissions, and obtain any authority needed to connect third-party systems or instruct actions through them. Customer will not instruct Mellovy to process sensitive or regulated data through a feature that Mellovy has not agreed to support.
4. Mellovy’s processor obligations
Mellovy will:
- process Customer Personal Data only on documented instructions, unless applicable law requires otherwise;
- ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations;
- implement and maintain technical and organisational measures appropriate to the risk, as required by Article 32 GDPR;
- assist Customer, taking into account the nature of processing, with requests from data subjects under Chapter III GDPR;
- assist Customer, taking into account the nature of processing and information available to Mellovy, with Articles 32 to 36 GDPR, including security, breach response, data protection impact assessments and prior consultation;
- make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits in accordance with section 8; and
- notify Customer if Mellovy considers it unable to comply with a material obligation under this DPA.
5. Security incidents
Mellovy will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known at the time, the nature of the breach, the affected data and individuals, likely consequences, measures taken or proposed, and a contact point for follow-up. Mellovy may provide information in stages as its investigation proceeds. Mellovy will reasonably cooperate with Customer’s response and will not make a public statement naming Customer without Customer’s agreement unless the law requires it.
6. Subprocessors
Customer gives Mellovy general written authorisation to engage Subprocessors only after Mellovy has identified the Subprocessor, its processing function and the country or countries from which it will process Customer Personal Data in an order, written schedule or current list made available to Customer. A processing category alone does not authorise an unidentified Subprocessor. Before a Subprocessor is added or replaced, Mellovy will give Customer at least 30 days’ notice and a reasonable opportunity to object on data-protection grounds. If the parties cannot resolve a substantiated objection, either party may terminate the affected service without penalty.
Mellovy will impose data-protection obligations on each authorised Subprocessor that provide at least the protection required by this DPA for its processing activity. Under GDPR Article 28(4), Mellovy remains fully liable to Customer for the Subprocessor’s performance of its data-protection obligations. Nothing in the commercial agreement limits the rights of data subjects or the powers of a supervisory authority under applicable law.
Current service-provider schedule
This schedule identifies service providers that may process Customer Personal Data for the listed function. They receive only the data reasonably needed for that function. A provider may process data through the locations and subprocessors in its linked terms; those locations can include countries outside the EEA. The transfer terms below describe the safeguards applicable to those transfers. Mellovy will update this schedule before adding or replacing a Subprocessor, as stated in section 6.
| Provider and function | Customer Personal Data it may receive | Processing locations and transfer information |
|---|---|---|
| Hetzner Online GmbH — hosting and server operations | Data stored in or transmitted through Mellovy-hosted services, which may include account identifiers, prompts, files, connected-source content, outputs, workflow data, and service, usage or security logs. | Mellovy’s hosting configuration is in Germany (EEA). Any remote access, support processing or onward transfer is subject to the applicable contract and this DPA; Mellovy does not promise that all provider-side access or subprocessors are EEA-only. |
| Cloudflare, Inc. — content delivery, DNS and security | Network and request metadata, IP address, security events and, depending on the feature and route, request or response traffic passing through Cloudflare’s network. | Cloudflare’s network uses data centres around the world and may process traffic outside the EEA. Its DPA and subprocessor list describe its processing and transfer safeguards, including SCCs where required. |
| WorkOS, Inc. — authentication and organisation identity | User name, email address, organisation, authentication and access information, and related security logs; not prompts or agent content as part of the identity function. | WorkOS may transfer data to the United States and other locations used by its subprocessors. Its DPA applies SCC Module 2 or 3 according to the parties’ roles and links to its current subprocessor information. |
| HubSpot, Inc. — CRM and contact management | Business contact and account details, form submissions, communication preferences, and related CRM records. HubSpot does not need customer prompts, files or connected-source content for this function. | Mellovy's HubSpot portal is hosted in HubSpot's EU1 region (Germany). HubSpot affiliates and subprocessors may process or access data in the locations on its subprocessor page, including the United States and Singapore. Its DPA describes transfer safeguards, including the EU-U.S. Data Privacy Framework where available and Standard Contractual Clauses where required. |
| Anthropic, PBC — live AI-agent inference | Prompts and instructions, files or connected-source content, retrieved information, tool results, and earlier or generated outputs needed to complete the task. Mellovy does not include a direct account ID, user ID or email address in the Anthropic request by default; submitted content may itself identify a person. | Anthropic may process data in selected locations in the United States, Europe, Asia and Australia and stores data in the United States unless otherwise agreed. Its commercial terms and DPA include SCCs for transfers where required. |
| Stripe Payments Europe Limited or Stripe, Inc. — payment processing | Billing contact and transaction details, payment status, and payment identifiers. Card details are handled by Stripe; Mellovy does not receive full payment-card numbers where Stripe collects them directly. | Stripe may transfer data to the United States and other locations where its affiliates and subprocessors operate. Its DPA, Data Transfers Addendum and service-provider list set out the applicable transfer mechanism. |
| Twilio Segment — product analytics and event routing | Usage and diagnostic events, event properties and pseudonymous account or user identifiers sent with those events. Prompts, files and connected source content are not required for this function and are not intended to be included in analytics events. | Twilio offers EU regional processing for Segment, but its corporate affiliates and subprocessors operate internationally. Processing and transfers are governed by Twilio’s Data Protection Addendum and subprocessor list, including SCCs or other permitted mechanisms where required. |
| ClickHouse, Inc. — usage and operational data store | Usage measurements, service events, diagnostic and security records, and any identifiers or event fields included in those records. Customer prompts and files are not required for this function and are not intended to be stored there. | If Mellovy uses ClickHouse Cloud for this service, its published subprocessor schedule lists control-plane processing in the United States, Germany and Singapore and additional locations for ingestion and support. The actual Mellovy deployment and region must be identified in the applicable order or processing record. ClickHouse’s DPA and subprocessor schedule describe the applicable safeguards and locations. A selected EU storage region does not mean all support or control-plane processing is EEA-only. |
| GitHub, Inc. — code repository and development collaboration | Repository content, source code, issues, pull requests, developer account information and technical logs. Customer Personal Data may be present if it is included in materials placed in those repositories or support records; Mellovy does not use GitHub as the routine store for prompts or agent conversations. | GitHub states that it stores and processes personal data in multiple locations, including the United States and other countries where its affiliates and subprocessors operate. Its privacy statement, subprocessor list and applicable Data Protection Agreement describe its processing and transfers, including SCCs where required. |
7. International transfers
Mellovy will not transfer Customer Personal Data to a country outside the EEA unless the transfer is covered by a valid mechanism under Chapter V GDPR and the recipient and destination country have been identified to Customer in the applicable order, written schedule or current list. Where the transfer relies on the European Commission’s standard contractual clauses, the relevant module will apply according to the parties’ roles and the parties will complete the required annexes and implement any supplementary measures needed for that transfer. A transfer will not be authorised by this DPA until the required recipient, destination and mechanism have been documented.
8. Audits and compliance information
On reasonable written request, Mellovy will provide information reasonably necessary to demonstrate compliance with this DPA. Customer may audit the processing of its Customer Personal Data, including through an independent auditor bound by confidentiality, on reasonable notice and during normal business hours. The parties will agree the scope and safeguards in advance; an audit must protect other customers’ data, security and confidential information. A current independent audit report or security documentation may be used to avoid repeating equivalent checks. These conditions do not restrict an audit required by a supervisory authority or by law.
9. Return and deletion
When the services end, Mellovy will, at Customer’s choice, return or delete Customer Personal Data and delete existing copies, unless applicable law requires retention. If Customer does not give an instruction, Mellovy will delete Customer Personal Data after the end of the service, subject to legal retention requirements. Any retained data remains protected under this DPA and will not be processed for another purpose. This section does not set a separate retention period for data processed as Mellovy’s own controller; that processing is described in the applicable privacy notice.
10. Model training and service improvement
This DPA does not authorise Mellovy or a Subprocessor to use Customer Personal Data for general model training or unrelated product development. Any optional training use requires a separate, explicit written instruction or opt-in that identifies the data, purpose, recipients and retention and is supported by a lawful basis, required notices and permissions for the individuals concerned. The parties must document any change in controller roles before that processing begins. Disabling an opt-in stops future use after the applicable technical processing period; it does not promise that a model can be reversed or that parameters already trained can be unlearned.
11. Term, liability and contact
This DPA starts when the commercial agreement takes effect or Mellovy first processes Customer Personal Data for Customer, whichever occurs first, and continues until the relevant processing ends and Customer Personal Data is returned or deleted. Liability under this DPA is governed by the liability terms in the commercial agreement, subject to any non-excludable rights or obligations under Data Protection Law.
Controller: the Customer identified in the commercial agreement. Processor: Mellovy AB, Swedish company registration number 559598-6257 and VAT number SE559598625701, Lyngavägen 15G, 305 64 Gullbrandstorp, Sweden.
Contact Mellovy at [email protected] or by post to the address above. The Customer must provide its own privacy contact to affected data subjects.