Mendli — Jobs Made Simple
Legal centreBack to Mendli
ARTICLE 28

Data Processing Addendum

Controller–processor terms and processing details for situations where Mendli is expressly appointed to process personal data on another organisation’s behalf.

Privacy PolicyPrivacy at a glanceTerms & ConditionsCookies & TrackingData Processing AddendumSecurity & Minimisation
When this DPA applies

This addendum applies only where a written Mendli agreement expressly states that Mendli processes personal data on a customer’s documented instructions as a processor. For ordinary marketplace account/job data, Mendli will usually act as a controller instead.

Provider agreements

The provider DPA links below are published for transparency. Mendli must also ensure any provider DPA that requires account-level acceptance or execution is accepted in the relevant Supabase, Cloudflare or OpenAI account. Publishing this page does not itself sign a third-party provider agreement.

1. Processing instructions

Mendli will process covered personal data only on the controller’s documented instructions, including instructions contained in the applicable agreement and configured use of the service, unless UK law requires otherwise.

2. Confidentiality and security

Mendli will ensure people authorised to process covered personal data are subject to confidentiality obligations and will maintain appropriate technical and organisational measures proportionate to risk. See Data Security & Minimisation.

3. Sub-processors

Mendli may use vetted service providers to provide infrastructure or support. Mendli will require equivalent data-protection obligations where Article 28 requires them and will remain responsible for selecting processors that provide sufficient guarantees.

ProviderPurposeProvider DPA / safeguards
SupabaseDatabase, authentication, storage and server-side platform services.Supabase DPA
CloudflareWeb hosting/delivery, edge services and security.Cloudflare DPA
OpenAIOptional Mendli AI support assistant when a user chooses to use that feature.OpenAI DPA

4. Data-subject rights and assistance

Taking into account the nature of processing, Mendli will provide reasonable assistance for access, correction, deletion, restriction, portability, objection and other valid rights requests relating to processor data, and will forward requests where the controller must respond.

5. Breach, DPIA and regulator assistance

Mendli will notify the controller without undue delay after becoming aware of a personal-data breach affecting covered processor data and will provide reasonable information and assistance required for breach assessment, DPIAs and regulator consultation where applicable.

6. End of processing

At the end of the relevant service, Mendli will delete or return covered processor data as required by the controller’s documented instructions, unless applicable law requires retention.

7. Audits and information

Mendli will provide information reasonably necessary to demonstrate compliance with applicable Article 28 obligations and will support proportionate audits or inspections subject to appropriate confidentiality, security and operational safeguards.

Schedule 1 — Processing details

Subject matterHosting and operating agreed Mendli marketplace/support functionality on behalf of the controller where Mendli is expressly appointed as processor.
DurationFor the term of the relevant agreement plus any limited return/deletion period or lawful retention period.
Nature and purposeStorage, retrieval, transmission, organisation, security, support and deletion of data necessary to provide the agreed service.
Data typesIdentity/contact data, account/profile data, marketplace/job content, messages/uploads, support content, transaction references and technical/security data as configured by the controller.
Data subjectsThe controller’s authorised users, workers/customers or other individuals whose data the controller lawfully provides through the service.
Controller rights/obligationsProvide lawful instructions and notices, establish lawful bases, minimise data, manage rights requests and ensure data submitted to Mendli is lawful.

Schedule 2 — International transfers

Where a restricted transfer occurs, the parties will use a lawful transfer mechanism applicable to the transfer, which may include an adequacy decision, the UK IDTA/Addendum or another legally recognised safeguard.

© 2026 Mendli · Last updated 12 September 2026
PrivacyTermsCookiesDPASecurity