Legal
B2B DATA PROCESSING ADDENDUM (DPA)
Access legal documents required for service cooperation and payment terms.: active · FINAL EFFECTIVE VERSION · ACTIVE
Last update: 2026-08-03 · Locale: English
FINAL EFFECTIVE VERSION Version 2026-08-03.2
Version: 2026-08-03.2
- Source SHA-256
- 077d249def251d5fdb7dcffc0fce561e7ffb19c7001533783f6fed54bdc061d7
- Public PDF SHA-256
- c1de82baa16a85bfe235f22ec361d0ad11a91945898cf44aa0f4e9ffc87c01cd
Legal Documents
Sections: 15
FINAL EFFECTIVE VERSION
Version 2026-08-03.2
10.1 Roles and scope
This DPA applies where the Customer determines the purposes and essential means of personal-data processing and MYRQELON processes that data on the Customer's behalf. For MYRQELON's own contracting, payment, accounting, security and compliance records, MYRQELON acts as a separate controller/owner.
10.2 Processing details
The subject matter, duration, nature, purposes, data types and data-subject categories are set out in the Specification and Schedule A. Processing continues for the Services and the limited deletion/backup period.
10.3 Instructions and compliance
MYRQELON processes data only on documented lawful instructions, including international transfers, unless required by law. If an instruction appears unlawful, MYRQELON notifies the Customer and may suspend it. The Customer is responsible for lawful basis, transparency, accuracy, minimisation, retention and data-subject rights.
10.4 Confidentiality and personnel
Persons with access are bound by confidentiality, appropriately instructed and granted least-privilege access.
10.5 Security
Risk-appropriate measures may include access control and logging, MFA where appropriate, encryption in transit and secret management, production/test separation, masking, backup and recovery, vulnerability/patch management, incident response, supplier assessment and secure deletion. Project-specific measures are listed in Schedule B.
10.6 Subprocessors
The Customer gives general authorisation for subprocessors in the maintained register. MYRQELON imposes materially equivalent processing obligations and remains responsible for appropriate selection and management. New relevant subprocessors are notified in advance where required. The Customer may object on documented data-protection grounds and the parties will seek a practical alternative.
10.7 International transfers
Where a transfer requires a mechanism, the parties use applicable standard contractual clauses, adequacy decisions, local addenda or another lawful mechanism, together with supplementary measures where risk assessment requires.
10.8 Data-subject requests
Taking account of the nature of processing, MYRQELON reasonably assists with access, correction, deletion, restriction, objection and portability. Direct requests are forwarded to the Customer unless law requires otherwise.
10.9 Personal-data breach
MYRQELON notifies the Customer without undue delay after confirming a personal-data breach in systems under MYRQELON's control. Available information includes nature, categories, approximate scale, likely consequences, measures and contact. The Customer remains responsible for regulator/data-subject notification unless separately instructed.
10.10 DPIA, regulator and audit
MYRQELON provides reasonable information for a DPIA, regulator consultation and compliance demonstration concerning its processing. It may provide policies, certificates or questionnaires. An audit is normally limited to once per year with reasonable notice, during working hours, subject to confidentiality and protection of other customers' data, except after an incident or regulatory request. Additional work may be chargeable unless caused by MYRQELON's breach.
10.11 Return and deletion
At the end of Services, MYRQELON returns or deletes Customer personal data at the Customer's choice, except lawful retention. Backups are deleted in the ordinary cycle and isolated from normal use meanwhile.
10.12 Priority
This DPA prevails for processing on behalf of the Customer. The main contract remains in effect for other commercial matters.
Schedule A - processing description
- the service, duration and processing purpose are defined in the relevant Order, Specification or technical brief;
- operations are limited to the access, collection, storage, organisation, migration, testing, support and deletion necessary to perform the Order;
- data-subject categories and data types are limited to information lawfully supplied by the Customer and described in the Specification;
- special-category data is prohibited unless separately agreed in writing, supported by a lawful basis and protected by additional measures;
- processing is one-off or continuous as required by the Order;
- deletion timing is governed by section 10.11, the Specification and mandatory retention periods;
- processing locations are Ukraine and the countries or regions stated in the current subprocessor register or Specification.
Schedule B - technical and organisational measures
- the system, environment, hosting and region are defined in the technical description for the Order and the current subprocessor register;
- encryption, IAM/MFA, logging, backup/restore, retention and vulnerability management are applied under section 10.5 and the risk of the particular project;
- production and test environments are separated, and test data is minimised or masked where reasonably practicable;
- incident contacts are support@myrqelon.com and the Customer contact stated in the Order;
- approved subprocessors are listed in the current register available on the Website or on request.
---
Verified public contacts
Use the address assigned to the subject of your request.
General enquiries
hello@myrqelon.comTechnical and existing-client support
support@myrqelon.comPrivacy and personal-data requests
privacy@myrqelon.com
