Mergelay Back to Mergelay
MERGELAY DATA PROCESSING

Data Processing Agreement

This agreement is the article 28 GDPR contract between you, as controller, and Mergelay, as your processor. It is an online annex to the Terms of service and applies automatically whenever Mergelay processes personal data on your behalf. No signature is needed; if your procurement process requires a countersigned copy, write to hello@mergelay.com.

Effective 31 August 2026

1. Parties and roles

The processor is Alexis Wychowaniak EI (entrepreneur individuel — sole trader under French law), 180 B rue de Charenton, 75012 Paris, France, SIREN 907 906 085, contact hello@mergelay.com. The controller is the customer whose workspace the data belongs to.

Mergelay is a processor for the content you connect or upload. Mergelay is an independent controller — not your processor — for your account holders’ identity and authentication records, billing status, support correspondence, service security and optional analytics; that processing is described in the privacy notice. Polar Software, Inc. is an independent controller for payment, invoicing and tax data and is not a sub-processor under this agreement.

2. Subject matter, duration, nature and purpose

Subject matter and purpose: providing the Mergelay service — analysing the changes you select in the repositories you connect, drafting and storing Updates, recording approvals, and delivering approved content to the destinations you configure.

Nature of processing: collection, structuring, storage, transmission to the model provider for analysis and drafting, transmission to the destinations you choose, retrieval, backup and erasure.

Duration: for as long as the Terms of service are in force and your workspace exists, plus the deletion window in clause 11.

3. Personal data and data subjects

Data subjectsCategories of personal data
Commit authors and pull-request participantsName, GitHub username, and any personal data appearing in commit messages, pull request titles and bodies or in the diff. Email addresses are redacted before any content reaches the model provider.
Recipients of Updates you sendEmail address, contact name, delivery outcome and time, and the content of the message delivered.
Contacts you importAccount name, contact name, email address, and any field you upload with them.
Your workspace members and reviewersIdentifier, role, approval and publication actions in the audit trail, and any text they write into a draft.

No special category data under art. 9 and no criminal-conviction data under art. 10 is requested or expected. Do not connect a repository or upload a list that carries such data; if you must, tell us first so we can assess it.

4. Documented instructions

Mergelay processes personal data only on your documented instructions, including for transfers to a third country. Your instructions are: these Terms and this agreement, the configuration you set in the product — connected repositories, destinations, recipients, sending domain, model behaviour — and any additional written instruction we accept. We tell you if an instruction appears to infringe the GDPR or another applicable data protection law, and may suspend the affected processing until it is resolved. Where an EU or Member State law requires us to process beyond your instructions, we inform you before processing unless that law prohibits it.

5. Confidentiality

Everyone authorised to process personal data under this agreement is bound by an obligation of confidentiality, contractual or statutory, that survives the end of their engagement. Access is limited to what each person needs to operate and support the service.

6. Security

Mergelay implements appropriate technical and organisational measures under art. 32 GDPR. In substance, and as currently implemented:

  • Encryption at rest for credentials. Posting credentials, webhook URLs, GitHub connections, OAuth states and queued webhook payloads are encrypted with AES-256-GCM under a versioned authenticated envelope, a fresh initialisation vector per write and additional authenticated data binding each file to its identity. OAuth tokens in the identity database are encrypted; provider ID tokens are discarded; agent access tokens are stored only as SHA-256 digests.
  • Encryption in transit. TLS everywhere, HSTS with preload in production, a strict content security policy, and no-referrer on review-link routes.
  • Integrity of inbound calls. GitHub webhooks are HMAC-signature verified with delivery-id replay protection; billing webhooks are signature verified; web-to-API calls carry a short-lived credential signed over method, path and workspace and compared in constant time.
  • Abuse limits. Rate limits on sign-in, sign-up, verification and reset, on unauthenticated review-link routes, on brand-asset reads and on agent access, metered against the edge-observed client address.
  • Redaction before model egress. Email addresses, credentials and high-entropy tokens are replaced and sensitive file paths and extensions excluded before any repository content leaves for the model provider. Analytics egress is restricted by a server-side allow-list of event names and low-cardinality properties.
  • Isolation and least privilege. One directory per workspace with path containment on every filename, an owner-only data directory, uploads restricted to image types verified by magic bytes, and configuration validated fail-closed before the service starts.
  • Resilience. The workspace file store is backed up as encrypted snapshots held off the application volume, with manifest verification and a periodic restore drill; the snapshot cadence published in the privacy notice is a target schedule, not a contractual commitment. The identity database is Railway-managed PostgreSQL, covered by the provider’s own backup and point-in-time recovery. Recovery objectives are engineering objectives, not a service level commitment.

These measures evolve with the service. We may replace a measure with one that offers an equivalent or higher level of protection.

7. Sub-processors

You give Mergelay a general authorisation to engage sub-processors. The current list, with each provider’s legal entity, purpose, data, location and transfer mechanism, is published and versioned at mergelay.com/subprocessors.

We give at least 30 days’ notice before a new sub-processor starts processing, by updating that page and emailing workspace owners. You may object on reasonable data-protection grounds within that period by writing to hello@mergelay.com; we will work with you on an alternative, and if none is workable you may terminate the affected part of the service and receive a pro-rata refund of prepaid, unused fees for it. Each sub-processor is bound by written terms imposing obligations equivalent to this agreement, and Mergelay remains fully liable to you for its performance.

8. International transfers

Some sub-processors are established outside the European Economic Area. Those transfers rely on the European Commission’s adequacy decision of 10 July 2023 for the EU–U.S. Data Privacy Framework where the importer is certified to it, and otherwise, or in addition, on the standard contractual clauses of Commission Implementing Decision (EU) 2021/914 with a transfer impact assessment and supplementary measures. Where those clauses are needed for a transfer under this agreement, module three (processor to processor) is incorporated by reference, with Mergelay as data exporter — acting on your instructions as controller — and the sub-processor as data importer. The optional clause 7 (the docking clause) applies; clause 9 is taken at option 2, general written authorisation, with the 30 days’ notice stated in section 7 of this agreement; clause 11 is taken without the independent dispute resolution option; clause 17 is governed by French law; and clause 18(b) designates France as the Member State whose courts resolve disputes arising from the clauses. Disputes arising from this agreement itself stay with the courts of Paris, France, under the Terms of service. The transfer mechanism per provider is stated at /subprocessors. A copy of the safeguards is available on request.

9. Assistance

Data subject requests. Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures to answer requests under chapter III GDPR. If a data subject contacts us directly about data we hold for you, we do not answer on the merits: we tell them to contact you and forward the request without undue delay.

Personal data breach. We notify you without undue delay and in any event within 48 hours of confirming a personal data breach affecting personal data processed for you, with the information available at that point — nature of the breach, categories and approximate number of data subjects and records, likely consequences and the measures taken — completing it as the investigation progresses. We do not notify a supervisory authority or data subjects on your behalf unless you ask us to in writing.

Impact assessments. We provide the information reasonably needed for your data protection impact assessments and prior consultations under art. 35 and 36.

10. Audit

On written request, and no more than once per calendar year unless a supervisory authority or a confirmed breach requires otherwise, we make available the information necessary to demonstrate compliance with art. 28 — this agreement, the sub-processor list, our security description and answers to a reasonable security questionnaire. If that is not sufficient for your obligations, an audit or inspection may be carried out by you or an independent auditor you mandate, on at least 30 days’ notice, during business hours, without disrupting the service, subject to confidentiality and to the security of other customers’ data, and at your cost unless the audit reveals a material breach by Mergelay.

11. Return and deletion

At the end of the service, at your choice, we return or delete the personal data processed for you. On request made within 30 days of termination we export your workspace content in a machine-readable form. We delete workspace content within 60 days of termination, or sooner on request, and confirm the deletion in writing. Backups are not selectively edited: workspace file-store snapshots expire on the target schedule stated in the privacy notice, and the identity database is covered by Railway’s managed backup and point-in-time recovery. Taking both together, a deleted workspace can persist in backups for up to twelve months; data in an expiring backup is not restored into the live service. We retain what EU or Member State law requires us to keep, for as long as it requires.

Deletion and export are handled manually by the operator today; there is no self-serve button yet. Requests go to hello@mergelay.com.

12. Liability, precedence and changes

Liability under this agreement is subject to the limitations and exclusions in the Terms of service, to the extent permitted by law. In case of conflict, this agreement prevails over the Terms on matters of personal data protection, and the standard contractual clauses prevail over both. We may update this agreement to reflect a change in law, in the service or in our security measures; a change that materially reduces your rights takes effect no sooner than 30 days after notice, on the same terms as clause 7.

© 2026 Mergelay · Alexis Wychowaniak EI · Paris, FranceLegal noticePrivacyTermsSub-processors