Data Processing Addendum
Last updated: August 10, 2026
This Data Processing Addendum (DPA) applies when Mercur processes Customer Personal Data on behalf of a customer as a processor or subprocesser under applicable data protection laws.
This DPA is incorporated into the Terms of Service unless the parties sign a separate written agreement.
1. Definitions
"Customer Personal Data" means personal data that a customer submits to Mercur or makes available through tunnel traffic, request logs, proxy configuration, support requests, or other use of the service, where Mercur processes that data on behalf of the customer.
"Data Protection Laws" means GDPR, UK GDPR, ePrivacy rules, US state privacy laws, and other privacy or data protection laws that apply to the processing.
"Process" and related terms have the meanings given under applicable Data Protection Laws.
"Subprocessor" means a third party engaged by Mercur to process Customer Personal Data on behalf of the customer in connection with the service.
2. Roles
For Customer Personal Data, the customer is the controller or processor, and Mercur is the processor or subprocesser. For account, billing, security, website analytics, and business operations data, Mercur may act as an independent controller as described in the Privacy Policy.
3. Processing Instructions
Mercur will process Customer Personal Data only to provide, secure, support, maintain, and improve the service; comply with the Terms and this DPA; follow documented customer instructions; and comply with law.
Customer instructions include the Terms, product settings, API or dashboard actions, agent configuration, startup modes, and written instructions accepted by Mercur.
4. Details of Processing
- Subject matter: relay, tunneling, request inspection, endpoint configuration, agent connection, metrics, support, security, and account operations.
- Duration: for the term of the customer relationship and for retention periods described in the Privacy Policy or product settings.
- Data subjects: customer personnel, developers, end users, webhook senders, endpoint callers, support contacts, and other individuals whose data appears in customer traffic.
- Data categories: identifiers, contact data, IP addresses, device data, request metadata, headers, body previews, user agents, tokens, endpoint configuration, logs, metrics, and support content.
- Sensitive data: not intentionally required. Customers should not send sensitive personal data, secrets, payment card data, health data, or special-category data through logged traffic unless legally authorized and appropriately protected.
5. Confidentiality and Security
Mercur will use reasonable technical and organizational measures designed to protect Customer Personal Data against unauthorized access, loss, alteration, disclosure, and destruction.
Personnel and contractors with access to Customer Personal Data must be subject to confidentiality obligations. Access should be limited based on operational need.
- Encryption of data in transit using TLS/HTTPS for service connections.
- Authentication and access controls for the dashboard, APIs, and agent connections.
- Primary application and relay infrastructure hosted in the European Union (DigitalOcean Frankfurt — FRA1), including self-hosted Postgres, MongoDB, and Redis.
- Deletion of Customer Personal Data in accordance with product retention settings, plan limits, and account-closure processes described in the Privacy Policy.
6. Subprocessors
Customer provides general authorization for Mercur to engage subprocessors to assist in providing the service, including hosting, networking, databases, caching, storage, security, support, billing, analytics, and related operations.
A current list of subprocessors is published at /subprocessors. Mercur will notify customers of changes to that list by updating the Subprocessors page. Customers who want email notice of changes may contact Mercur using the address in the Contact section.
Mercur remains responsible for subprocessors that process Customer Personal Data on Mercur's behalf and will impose data protection obligations on those subprocessors that are no less protective than those in this DPA.
7. Data Subject Requests
The customer is responsible for responding to data subject requests relating to Customer Personal Data. Mercur will provide reasonable assistance through available product controls and cooperation appropriate to the nature of the service.
If Mercur receives a request relating to Customer Personal Data, Mercur may direct the requester to the customer unless legally required to respond directly.
8. Security Incidents
Mercur will notify affected customers without undue delay after confirming a personal data breach affecting Customer Personal Data, where required by law.
Notices will include, to the extent reasonably available at the time, a general description of the nature of the breach and the measures taken or proposed to address it. Additional information may follow as it becomes reasonably available.
The customer remains responsible for notifying relevant supervisory authorities and affected data subjects where required under applicable Data Protection Laws, and for determining whether a breach is notifiable.
9. Deletion and Return
Upon account closure or written request, Mercur will delete or return Customer Personal Data where feasible, subject to product functionality, legal obligations, security needs, backups, billing records, and legitimate business records.
10. International Transfers
Mercur's primary application and relay infrastructure and associated self-hosted data stores are located in the European Union (DigitalOcean Frankfurt — FRA1).
Where Customer Personal Data is transferred outside the EEA through a subprocessor or another lawful processing activity, Mercur will ensure appropriate safeguards are in place, such as an adequacy decision (including the EU-US Data Privacy Framework where applicable) or Standard Contractual Clauses adopted by the European Commission.
11. Audits and Information
Mercur satisfies its obligation to make available information necessary to demonstrate compliance with this DPA through the publication of this DPA, the Privacy Policy, the Security page, and the Subprocessors page.
Because Mercur is an early-stage startup, no SOC 2, ISO 27001, or similar certification is promised unless separately stated in writing. On-site audits, custom questionnaires, and individual compliance assessments are not available on self-serve plans. Enterprise customers needing expanded audit rights should contact Mercur to discuss a custom agreement.
12. Customer Obligations
Customer is responsible for lawful instructions, notices, consents, endpoint configuration, security of exposed services, token management, and deciding whether request logging is appropriate for the data being processed.
13. Contact
Data protection questions may be sent to development@mercur.sh. Operator: Mercur, Khreschatyk St, 1, Kyiv, Ukraine.