Legal
Data Processing Addendum
Effective immediately. Email dpa@mercury.example.com for a countersigned PDF.
1. Definitions
"Controller" means the customer. "Processor" means Mercury Labs, Inc. "Personal Data" has the meaning given in Article 4 of GDPR.
2. Scope
This DPA applies to the processing of Personal Data that the Controller submits to the Mercury API. The Controller instructs the Processor to process such Personal Data only for the purpose of providing email verification services.
3. Subprocessors
The Processor engages Cloudflare (hosting, KV, D1, email), Dodo Payments (billing) and Better-auth (session) as sub-processors. The Processor will notify the Controller of changes to subprocessors with 30 days' notice.
4. Security
The Processor implements TLS 1.3, SHA-256 hashed API keys, tenant-isolated D1 queries, audit logging of every key creation and revocation, and quarterly penetration tests.
5. Data subject requests
The Processor will assist the Controller in responding to data subject requests, including access, rectification and erasure, within 7 days of the Controller's request.
6. International transfers
The Processor relies on Standard Contractual Clauses (SCCs) for transfers from the EU/EEA to third countries. EU-only storage is available on request.
7. Audit
The Processor will make its SOC 2 Type II report available to the Controller under NDA within 30 days of publication.
8. Termination
On termination, the Processor will delete all Personal Data within 30 days, except where retention is required by law.