Global Privacy Policy
MERIT SUPER PLATFORM - DATA PROTECTION AGREEMENT
This Data Protection Agreement (the “DPA”) explains how Merit, including its direct or indirect subsidiaries, Affiliates, and related entities worldwide (collectively, “Merit”, “we”, “us”, or “our”), processes Personal Data solely in its capacity as a Data Processor (regardless of the geographic location from which the Platform is accessed) on your behalf in connection with access to and use of the Merit Super Platform and the products and services offered through it (collectively, the “Platform”).
This DPA forms an integral part of, and is incorporated by reference into, the agreement governing your access to and use of the Platform and any associated products, features, or services made available through it (the “ Platform Agreement”).
This DPA applies automatically where Merit processes Personal Data on behalf of You in the course of providing the Services. No separate execution of DPA is required.
For the avoidance of doubt:
This DPA does not apply to Personal Data processed by Merit in its capacity as an independent Data Controller for purposes such as account administration, billing, compliance, platform operations, or Platform-level security. Such processing is governed by the Privacy Policy.
Where Merit acts as a Data Processor, it processes Personal Data strictly on your documented instructions and in compliance with applicable data protection laws, including the Saudi Personal Data Protection Law (“PDPL”).
This DPA, together with the Platform Agreement and the Privacy Policy, ensures that Personal Data processed through the Platform is handled in a lawful, fair, transparent, and secure manner, with appropriate technical and organizational measures in place to protect the rights of Data Subjects.
Capitalised terms used but not defined in this Data Processing Addendum shall have the meanings given to them in the Platform Terms of Use or, where applicable, the relevant Product Terms.
“Merit” – defined as Merit, including its direct or indirect subsidiaries, affiliates, and related entities worldwide.
“Platform / Merit Super Platform” – defined as the Merit Super Platform and the products, services, tools, and functionalities offered through it.
“DPA” – defined as this Data Protection Agreement.
“Platform Agreement” – defined as the agreement governing your access to and use of the Platform and any associated products, features, or services made available through it.
“Personal Data” – defined consistent with PDPL: any information relating to an identified or identifiable natural person, including data provided to or generated within the Platform in connection with your use of the Platform.
“You / Customer” – defined as the entity or person accessing or using the Platform and instructing Merit to process Personal Data on its behalf.
“Services” – defined as the Platform services and any associated products, tools, modules, or functionalities provided by Merit to You under the Platform Agreement.
“Data Processor / Processor” – defined as Merit, when processing Personal Data on your documented instructions and not determining the purposes or means of processing.
“Data Controller / Controller” – defined as the party determining the purposes and means of processing Personal Data, which may be You or Merit depending on the processing context.
“Joint Controllers” – defined as Merit and You, where both determine the purposes and means of processing Personal Data jointly.
“Applicable Data Protection Laws / PDPL” – defined as the Saudi Personal Data Protection Law and any other data protection or privacy laws applicable to the processing of Personal Data.
“Privacy Policy / Platform Privacy Policy” – defined as the policy published by Merit governing Personal Data processed by Merit in its capacity as an independent Controller, including Platform administration, security, and operations.
“Sub-processor / Sub-processors” – defined as third-party service providers engaged by Merit to process Personal Data on behalf of You under documented instructions.
“Data Subject” – defined as an identified or identifiable natural person whose Personal Data is processed under this DPA.
“Sensitive Personal Data” – defined as Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, health, sex life, sexual orientation, biometric or genetic data, or any other category deemed sensitive under Applicable Data Protection Laws.
“B2B / B2B2C Use Cases” – defined in context as business-to-business and business-to-business-to-consumer use cases supported by the Platform.
“Documentation / Documented Instructions” – defined as instructions provided by You in writing, via the Platform, or through agreed operational workflows for the processing of Personal Data.
“Personal Data Breach” – defined as a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
The Platform enables you to subscribe to and use different services, products, tools, and functional modules through a single unified environment. Depending on the nature of the subscribed service or product and the specific processing activity, Merit’s role under applicable data protection laws may vary. Accordingly:
Where Merit determines the purposes and means of processing Personal Data in connection with a service or functionality, Merit acts as a Data Controller.
Where Merit processes Personal Data strictly on documented instructions received from you, and you determine the purposes and means of processing (for example, where you upload, manage, or operate Personal Data relating to your own end users, employees, or loyalty program users), Merit acts as a Data Processor on behalf of you.
Where Merit and you jointly determine the purposes and means of processing in relation to a specific service or functionality, Merit and you act as Joint Controllers, and your and/or Merit's respective responsibilities are allocated in accordance with applicable law.
All such processing activities are governed by this DPA, together with the Platform Agreement arrangement between Merit and you.
Merit processes only those categories of Personal Data that are necessary, relevant, and proportionate to operate, secure, deliver, and administer the Platform and the services, products, tools, and functionalities made available through it, in accordance with this DPA and applicable Data Protection Laws. The Platform is a business-to-business (B2B) platform that may support business-to-business-to-consumer (B2B2C) use cases. Accordingly, Merit processes Personal Data relating to:
your authorised users and representatives; and
where applicable, end users or loyalty program participants, whose Personal Data is provided to or generated within the Platform by you in connection with your use of the Platform.
The categories of Personal Data that may be processed include, but are not strictly limited to, the following:
Account, Identity, and Business Contact Data
Personal Data processed in connection with the registration for, access to, and administration of Platform accounts and user access, including:
legal business name, commercial registration details, and other registered entity information;
corporate documentation and information submitted for Know Your Business (KYB), sanctions screening, or compliance verification;
names, job titles, and business contact details of administrators and other authorised users or representatives;
business email addresses, telephone numbers, and associated professional contact identifiers;
assigned user roles, permissions, access scopes, and entitlements; and
login credentials, authentication factors, and authentication-related metadata (such as login timestamps, access status, and session identifiers).
Information relating solely to legal entities does not constitute Personal Data. However, where such information relates to an identified or identifiable natural person (such as a director, signatory, authorised user, end user or company representative), it constitutes Personal Data and is processed in accordance with this DPA and the Privacy Policy.
Your Data and End-User Data (B2B2C Use Cases)
Depending on the services, products, or modules subscribed to by you, the Platform may process Personal Data uploaded to, generated through, or otherwise made available via the Platform by you, which may include Personal Data relating to:
Taking into account the nature of the processing and the information available to it, Merit shall provide You with reasonable assistance to enable You to respond to requests from data subjects exercising their rights under Applicable Data Protection Laws in accordance with the procedures described in the Platform Privacy Policy, including rights of access, correction, or deletion, where applicable and to the extent such Personal Data is processed by Merit on behalf of the You.
Merit shall not respond directly to any data subject request unless required to do so under applicable Data Protection Laws or expressly instructed by you.
Any assistance provided by Merit under this Clause shall be subject to applicable Data Protection Laws and shall not require Merit to take actions that are unlawful, technically infeasible, or disproportionate in light of the nature of the services.
Confidentiality of Personal Data. Merit shall ensure that any personnel authorised to process Personal Data are subject to appropriate confidentiality obligations, whether arising under contractual arrangements or statutory duties, and that such personnel receive appropriate training in relation to the protection and handling of Personal Data.
Customer Responsibilities and Lawful Instructions. You represent and warrant that You have provided all notices and obtained all rights, consents, and authorisations required under Applicable Data Protection Laws for the processing of Personal Data through the Platform. You shall ensure that its instructions to Merit are lawful and compliant with Applicable Data Protection Laws. Merit shall promptly inform You if it becomes aware that an instruction from You infringe applicable Data Protection Laws.
Government, Regulatory, and Law Enforcement Requests. If Merit receives a legally binding request from a competent governmental, regulatory, or law enforcement authority requiring the disclosure of Personal Data, Merit shall, to the extent permitted by applicable law, notify You without undue delay and provide reasonable assistance to enable You to respond to such request or seek appropriate protective measures.
minimises disruption to Merit's operations, protects the confidentiality of other customers' data and ensures that access is limited to personnel and records relevant to Your Personal Data.
Merit may fulfil its obligations under this clause through the provision of reports, certifications, or remote inspection tools, at its discretion, provided that such measures reasonably enable you to verify compliance.
For privacy inquiries or rights requests related to this Agreement:
Email:
loyalty program members, points balance, reward recipients, or participants;
end customers, users, or beneficiaries of program operated by you;
employees, contractors, or your agents; and
transactional, engagement, or activity data generated through your-defined program rules, APIs, integrations, or your-configured workflows.
In respect of such Personal Data, Merit acts as a data processor or service provider (as applicable) and processes the data on behalf of and in accordance with the documented instructions received from you, you the data controller, unless otherwise expressly agreed in writing.
Operational, Security, and Audit Data
Data generated or collected to ensure the security, integrity, availability, performance, and auditability of the Platform and its services. Such data constitutes Personal Data only to the extent that it relates to an identified or identifiable natural person, and may include, where applicable:
user activity records associated with named or identifiable user accounts;
access logs, login events, and session information linked to individual users;
role, permission, entitlement, and configuration changes attributable to specific users; and
system-generated logs, audit trails, or security alerts that include user-identifiable information (such as user IDs or IP addresses).
Aggregated, anonymised, or purely technical data that cannot reasonably be linked to an identifiable individual does not constitute Personal Data and falls outside the scope of applicable Data Protection Laws.
Commercial, Subscription, and Billing Data
Personal Data processed for subscription management, billing, and commercial administration of the Platform, including:
subscribed services, products, plans, and service entitlements;
invoicing information, payment status, transaction references, and billing contacts; and
contractual usage limits, thresholds, consumption metrics, and entitlement records.
Payment transactions are processed through certified third-party payment service providers. Merit does not store full payment card numbers or sensitive authentication data.
Sensitive Personal Data
The Platform is not designed or intended to process sensitive or special category Personal Data, as defined under applicable data protection laws (including the Saudi PDPL). Where the processing of such data is strictly required by applicable law (including, where relevant, regulatory or KYB obligations), such processing shall:
be limited to what is legally required;
be subject to enhanced technical and organisational safeguards; and
be carried out in compliance with all additional conditions and protections mandated by applicable Data Protection Laws.