Skip to content

Data Processing Addendum

Effective date: August 20, 2026

Scope

This Data Processing Addendum (the “DPA”) applies whenever we process personal data on your behalf — in practice, whenever your bots collect anything from your end customers. It forms part of our Terms of Service when you accept them or otherwise enter into an order that incorporates them. No separate countersignature is required unless applicable law or a transfer mechanism requires one. Where this DPA conflicts with the rest of the Terms, this DPA governs for personal data.

1. Roles

For the data your bots collect from your end customers, you act as controller (or as processor for another controller) and we act as your processor. For your own account data we are the controller, and this DPA does not apply to it — our Privacy Policy covers that instead.

2. Documented instructions

We process that data only on your documented instructions, including as regards transfers, unless processing is required by Union or Member State law to which we are subject. In that case we will inform you of the legal requirement before processing, unless that law forbids us from telling you on important grounds of public interest.

Those instructions consist of this DPA, any applicable order, your authorised configuration and use of the Service — the bots, flows, channels and integrations you set up — and any further written instructions consistent with the Terms. Our Privacy Policy is a transparency notice: it explains processing, and does not itself widen your instructions. We will tell you if we think an instruction breaches applicable data-protection law. Apart from providing, securing, supporting and maintaining the Service, we do not use identifiable data your bots collect for our own purposes.

3. What you are responsible for

You warrant that you have a lawful basis for what your bots collect and the authority to give us these instructions, and that you have given your end customers whatever notices and choices they are owed. You are responsible for the content of your bots — the questions they ask, who receives the answers, and the workflows you build — and for the integrations and credentials you connect. You must not instruct us to do anything unlawful.

4. Confidentiality and security

Everyone we allow near the data is under confidentiality obligations, and we maintain the measures described below, which are designed to meet Article 32. We may change those measures as the Service evolves, provided the overall level of protection is not materially reduced.

5. Sub-processors

You give us general authorisation to engage the sub-processors identified in our Provider List. Each is bound by the same data-protection obligations as those required by Article 28(4), insofar as applicable to the processing that sub-processor performs. We will give the account administrator at least 15 calendar days’ written notice before a new sub-processor receives personal data, except where an urgent change is needed to protect the Service or avoid material disruption, in which case we will notify you as soon as reasonably practicable. You may object during the notice period on reasonable, documented data-protection grounds.

6. Services you connect

Where we engage a provider to process your data on our behalf, it is a sub-processor and section 5 applies to it. Where you contract with or instruct a provider directly — a messaging channel, a calendar, or another third-party service you switch on — that relationship is yours.

7. Assistance

Taking into account the nature of the processing and the information available to us, we provide reasonable assistance with requests from your end customers to access, correct, delete or receive their data, and with your obligations under Articles 32 to 36. The self-service tools in the dashboard are included at no extra charge. Non-standard work may be charged at reasonable documented rates, where law permits us to charge for it.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you. The first notice will contain the information reasonably available at the time, and we may add to it without undue delay as more becomes known.

9. Return and deletion

You can delete data from the dashboard at any time — conversations, contacts, bots, or the whole account. At the end of the Service, at your choice told to us before termination, we will return or delete the personal data we hold for you and delete remaining copies, except where law requires us to keep something, such as billing records. Section 8 of the Privacy Policy describes the timetable, including the limited records that persist for a short period after deletion.

10. Audits

We make available the information needed to demonstrate compliance with this DPA and will answer a reasonable written questionnaire once in any twelve-month period. Audits run on reasonable notice, in business hours, under confidentiality, and in a way that protects other customers’ data and the security of the Service.

11. International transfers

A “Restricted Transfer” is a transfer of personal data that requires an appropriate safeguard because no adequacy decision or other valid transfer mechanism applies. For a Restricted Transfer from a customer established in the EEA to Meerlume in Armenia, the European Commission’s 2021 Standard Contractual Clauses (the “EU SCCs”) are incorporated into this DPA by reference and automatically entered into as completed by the EEA transfer schedule below. The official, unmodified clauses are in the Annex to Commission Implementing Decision (EU) 2021/914. Acceptance of the Terms constitutes electronic execution of the EU SCCs and their Annexes by both parties. No email or separate countersignature is required.

If you are not established in the EEA, you must not use the Service to process personal data of people in the EEA where your relevant processing is subject to Article 3(2) GDPR, unless a different valid Chapter V mechanism has first been agreed in writing. This narrow restriction does not apply to a customer established in the EEA, or to transfers governed only by the UK or Swiss provisions below. It exists because the 2021 EU SCCs cannot be used where Meerlume, as importer, is itself directly subject to the GDPR for the same processing.

12. Liability

Liability under this DPA is subject to section 15 of the Terms, except where applicable law does not permit it to be limited.

Details of processing

  • Data subjects: the end customers who message your bots.
  • Categories of personal data: message content and conversation transcripts; whatever identifier the channel exposes (a WhatsApp phone number, a Telegram username or user ID, or a session identifier for website chat); names, contact details, booking times, and the structured answers your flows collect; and technical metadata such as IP addresses and timestamps.
  • Special categories: the Service is not designed or authorised for the deliberate collection of special-category or criminal-offence data unless we have agreed to it in writing. Because bots and live chat accept free text, an end customer may still volunteer such information, and it is then processed as part of the message content above. You must not configure a bot to solicit it without our written approval, a valid lawful basis, and appropriate safeguards.
  • Nature and purpose: hosting, storage, message routing, and execution of the conversational flows you configure, in order to deliver the Service.
  • Duration: the term of your account, plus the deletion windows in section 8 of the Privacy Policy.

Security measures

  • Encryption in transit over public networks, and encryption at rest for channel credentials and access tokens.
  • Access to production data restricted on a least-privilege basis to the people who need it, with passwords stored hashed.
  • Logging of access and security events.
  • Controls designed to scope customer data to the owning account, and rate limiting on public endpoints.
  • Self-service deletion in the dashboard.

Sub-processor list

The authorised sub-processors are those identified as such in the Provider List in section 5 of the Privacy Policy, which is kept current and forms part of this DPA. That section also states how changes are notified.

EEA transfer schedule

This section completes the EU SCCs for every Restricted Transfer covered by section 11.

  • Modules. Module Two (controller to processor) applies where you are a controller. Module Three (processor to processor) applies where you process the data for another controller.
  • Clause 7. The optional docking clause does not apply.
  • Clause 9. Option 2, general written authorisation, applies. The notice period is the 15-calendar-day period in section 5.
  • Clause 11. The optional independent dispute resolution wording does not apply.
  • Clauses 17 and 18. Option 1 applies. German law governs the EU SCCs and disputes are resolved by the courts of Germany. This choice applies only to the EU SCCs; the rest of the Agreement remains governed as stated in the Terms.
  • Hierarchy. If this DPA or the Terms conflict with the EU SCCs, the EU SCCs prevail for the Restricted Transfer.

Annex I.A — parties. The data exporter is the customer identified by the name, business details and contact information associated with the account, order or other agreement, at its principal business address. Its role is controller for Module Two and processor for Module Three. The data importer is Meerlume LLC, a limited liability company registered in the Republic of Armenia, at the registered address shown on our Contact page, with privacy@meerlume.com as contact, acting as processor or sub-processor. The relevant activity is Meerlume’s provision and the customer’s use of the Service. Each party is deemed to have signed Annex I.A on the date the customer accepts the Terms or the date an order incorporating this DPA takes effect, whichever happens first.

Annex I.B — transfer. The categories of data subjects, personal data, special-category data, nature, purpose and duration are those in “Details of processing” above. Data originates from the customer, its configured integrations, and people who interact with its bots. The transfer occurs on a continuous basis while the Service is used. Primary storage and compute remain in the EU; the transfer to Armenia consists mainly of authorised remote access for operation, security, support and debugging. Onward recipients are the sub-processors in the Provider List, for the limited services described there.

Annex I.C. The competent supervisory authority is determined under Clause 13 of the EU SCCs, normally the authority responsible for the exporter’s EEA establishment. Annex II is the “Security measures” section above. Annex III is the authorised sub-processor list in the Provider List.

UK and Swiss transfers

For a Restricted Transfer governed by the UK GDPR, the parties incorporate the ICO’s International Data Transfer Addendum, version B1.0, including its mandatory clauses as revised by the ICO. Its start date and party details are those in Annex I.A above; the selected EU SCC modules and options are those in the EEA transfer schedule; and its Appendix Information is supplied by Annexes I to III above. For Table 4, both importer and exporter may end the Addendum when the ICO issues an approved revised addendum. Acceptance of the Terms constitutes execution by both parties.

For a Restricted Transfer governed by Switzerland’s Federal Act on Data Protection, the EU SCCs apply as completed above with references to the GDPR and EU law read as references to the Swiss Act and Swiss law where necessary; the competent authority is the Swiss Federal Data Protection and Information Commissioner; data subjects may enforce the clauses in Switzerland; and, for claims governed only by the Swiss Act, Swiss law and the relevant Swiss courts apply. Where the GDPR also governs the same transfer, German law and courts continue to apply to the GDPR claims while the Swiss provisions apply in parallel to the Swiss claims.

Transfer assessment and supplementary measures

For Clause 14 of the EU SCCs, the parties take into account that Armenia has no EU adequacy decision, but it has a personal-data protection law and supervisory agency, is a party to the Council of Europe’s Convention 108, and ratified Convention 108+ in 2022. Armenian operational-intelligence law provides for judicial control of interception measures, including court permission for the measures identified in that law, with a narrow emergency process subject to later court review. Those facts do not amount to an adequacy finding.

The particular transfer is limited by its architecture: customer data is hosted in the EU; access from Armenia is encrypted in transit, restricted to authorised personnel on a need-to-know basis, and logged; and Meerlume will not intentionally create persistent local copies in Armenia except where strictly necessary to resolve a documented support or security incident, after which the copy will be securely deleted. Taking those circumstances and the laws applicable to Meerlume into account, the parties have no reason at the time of contracting to believe that those laws prevent Meerlume from fulfilling the EU SCCs.

If an authority seeks customer data, Meerlume will, to the extent legally permitted, notify the customer, review the legality of the request, challenge it where there are reasonable grounds, seek to redirect the authority to the customer, and disclose only the minimum legally required. We will document the request and our response. If we can no longer comply with the EU SCCs, we will notify the customer and suspend the affected transfer as those clauses require.

The public sources used for this assessment include the Council of Europe’s Armenia status page, the Armenian Personal Data Protection Agency’s legislation page, and the official text of the Armenian Law on Operational Intelligence Activity. We will reassess if the processing, destination law or available transfer mechanisms materially change.

Contact

Questions about this DPA can be sent to privacy@meerlume.com. The processor is Meerlume LLC, a limited liability company registered in the Republic of Armenia.