Data Processing Addendum
Controller–processor terms and processing details for situations where Mendli is expressly appointed to process personal data on another organisation’s behalf.
This addendum applies only where a written Mendli agreement expressly states that Mendli processes personal data on a customer’s documented instructions as a processor. For ordinary marketplace account/job data, Mendli will usually act as a controller instead.
The provider DPA links below are published for transparency. Mendli must also ensure any provider DPA that requires account-level acceptance or execution is accepted in the relevant Supabase, Cloudflare or OpenAI account. Publishing this page does not itself sign a third-party provider agreement.
1. Processing instructions
Mendli will process covered personal data only on the controller’s documented instructions, including instructions contained in the applicable agreement and configured use of the service, unless UK law requires otherwise.
2. Confidentiality and security
Mendli will ensure people authorised to process covered personal data are subject to confidentiality obligations and will maintain appropriate technical and organisational measures proportionate to risk. See Data Security & Minimisation.
3. Sub-processors
Mendli may use vetted service providers to provide infrastructure or support. Mendli will require equivalent data-protection obligations where Article 28 requires them and will remain responsible for selecting processors that provide sufficient guarantees.
| Provider | Purpose | Provider DPA / safeguards |
|---|---|---|
| Supabase | Database, authentication, storage and server-side platform services. | Supabase DPA |
| Cloudflare | Web hosting/delivery, edge services and security. | Cloudflare DPA |
| OpenAI | Optional Mendli AI support assistant when a user chooses to use that feature. | OpenAI DPA |
4. Data-subject rights and assistance
Taking into account the nature of processing, Mendli will provide reasonable assistance for access, correction, deletion, restriction, portability, objection and other valid rights requests relating to processor data, and will forward requests where the controller must respond.
5. Breach, DPIA and regulator assistance
Mendli will notify the controller without undue delay after becoming aware of a personal-data breach affecting covered processor data and will provide reasonable information and assistance required for breach assessment, DPIAs and regulator consultation where applicable.
6. End of processing
At the end of the relevant service, Mendli will delete or return covered processor data as required by the controller’s documented instructions, unless applicable law requires retention.
7. Audits and information
Mendli will provide information reasonably necessary to demonstrate compliance with applicable Article 28 obligations and will support proportionate audits or inspections subject to appropriate confidentiality, security and operational safeguards.
Schedule 1 — Processing details
| Subject matter | Hosting and operating agreed Mendli marketplace/support functionality on behalf of the controller where Mendli is expressly appointed as processor. |
|---|---|
| Duration | For the term of the relevant agreement plus any limited return/deletion period or lawful retention period. |
| Nature and purpose | Storage, retrieval, transmission, organisation, security, support and deletion of data necessary to provide the agreed service. |
| Data types | Identity/contact data, account/profile data, marketplace/job content, messages/uploads, support content, transaction references and technical/security data as configured by the controller. |
| Data subjects | The controller’s authorised users, workers/customers or other individuals whose data the controller lawfully provides through the service. |
| Controller rights/obligations | Provide lawful instructions and notices, establish lawful bases, minimise data, manage rights requests and ensure data submitted to Mendli is lawful. |
Schedule 2 — International transfers
Where a restricted transfer occurs, the parties will use a lawful transfer mechanism applicable to the transfer, which may include an adequacy decision, the UK IDTA/Addendum or another legally recognised safeguard.
