Data Processing Agreement
Last updated: August 2026
Draft for review. This DPA is written in plain language and follows the
usual shape of GDPR Article 28 terms, but it has not been reviewed by a lawyer. Have one read it
before you rely on it or send it to a customer, and replace [LEGAL ENTITY] and
[REGISTERED ADDRESS] with your registered details.
This agreement applies whenever [LEGAL ENTITY] (“Meritan”, the processor) handles personal
data on behalf of a customer (“you”, the controller). It forms part of the
Terms of Service and takes effect when you start using Meritan.
If your organisation needs a signed copy, email
founders@meritan.team and we will sign it.
1. Roles
You are the controller of the candidate data your interviews produce: you decide who to
interview, what to ask, and how long to keep the result. Meritan is your processor and acts only
on your documented instructions, which include your use of the product’s features. For our own
customer account data, Meritan is the controller and our
privacy policy applies.
2. What we process for you
- Subject matter: running, recording and replaying coding interviews.
- Duration: for as long as your account is active, plus the retention window of your plan.
- Categories of people: candidates you invite, and your own interviewers and reviewers.
- Categories of data: name and email as entered by you, code written during the session
captured as periodic snapshots, chat and notes from the room, integrity signals (blocked paste
attempts and their size, tab focus changes and their duration, presence of a second display,
unusually large text insertions), scorecards, and technical data such as IP address and
browser type in server logs.
- Special categories: none are requested or required. Do not put special category data
into interview questions or notes.
3. Our obligations
- We process personal data only on your instructions, and we tell you if an instruction appears
to breach data protection law.
- Everyone with access is bound by confidentiality.
- We keep appropriate technical and organisational measures, described in section 7 and on the
security page.
- We do not sell personal data, and we do not use candidate data to train machine-learning
models.
4. Sub-processors
You give general authorisation for the sub-processors listed on the
sub-processors page. We impose data protection obligations
on each of them no less protective than these, and we remain responsible to you for their
performance. We give at least 30 days’ notice before adding one, and you may object on
reasonable data protection grounds as described on that page.
5. Helping you meet your own obligations
- Candidate requests. The product lets you act without us: every interview has a delete
button that erases the recording, its integrity events and the room contents, and owners can
export the workspace as JSON. If a candidate contacts us directly, we forward the request to
you rather than acting on it ourselves.
- Impact assessments. We provide the information reasonably needed for your DPIA and
prior consultations, on request.
- Breach notification. If we become aware of a personal data breach affecting your data,
we notify you without undue delay and in any event within 48 hours, with what we know,
what we are doing, and what we advise.
6. International transfers
Application data is stored in the EU. Where a sub-processor is outside the EEA, the transfer
relies on the European Commission’s Standard Contractual Clauses or an adequacy decision, with
supplementary measures where appropriate. The sub-processors
page states the location and mechanism for each one.
7. Security measures
- Encryption in transit (TLS) for all traffic, and encryption at rest for sensitive integration
credentials.
- Passwords stored as scrypt hashes. Sessions are signed tokens in HttpOnly cookies.
- Access to interview data is scoped to the owning workspace and enforced server-side, including
on the realtime connection.
- Candidate code executes in the candidate’s own browser, sandboxed, and never on our servers.
- Automated retention sweeps that delete data past its window permanently.
- Administrative access is limited to those who need it, protected by strong authentication.
8. Deletion and return
You can delete any interview at any time, and deletion is immediate and permanent. When your
account ends, we delete your workspace data within 30 days, except where law requires us
to keep something, in which case we keep only that and only for as long as required. Export your
data before you close the account; owners can do this from Settings at any time.
9. Audits
On reasonable notice, and no more than once a year unless an authority requires otherwise, we
will answer a written security questionnaire and provide the documentation we hold that
demonstrates compliance with this agreement. We are a small company: we favour real answers to
real questions over ceremony.
10. Liability and term
This agreement lasts as long as we process personal data for you. Liability is governed by the
Terms of Service. If a term here conflicts with those terms, this
agreement wins for matters of personal data processing.
Contact
founders@meritan.team. Ask for a signed copy any
time.