M
Mellio pro
Merchant Area

Create a business account

Create and manage your loyalty program.

1
Email
2
Verification
3
Profile & Address
or

Already have an account? Log in

✨ Business & Loyalty Area

Create your loyalty program

Build customer loyalty and boost sales in just a few clicks with our digital cards.

Apple Wallet & Google Pay cards

Your customers add their card in 10 seconds, without downloading any application.

Free local push notifications

Communicate directly on the lock screen of your nearby customers.

Boost your Google reviews by 45%

Automatically collect reviews from satisfied customers to climb Google Maps rankings.

✨ SaaS Subscription Agreement

General Conditions of Service

Belgian governing law & GDPR.

MERCHANT SAAS SUBSCRIPTION AGREEMENT — Version 1.0
This agreement governs the use of the Mellio loyalty platform by direct merchant clients.

Between: DS Solutions SRL, a company incorporated under Belgian law, having its registered office in Belgium, registered with the Crossroads Bank for Enterprises under the number indicated in its legal notices, hereinafter referred to as the "Provider",

and: Any natural or legal person acting within the scope of their commercial, industrial, craft, or professional activity who subscribes to Mellio Services, hereinafter referred to as the "Client" or the "Merchant",

Together referred to as the "Parties".

This Agreement constitutes an adhesion contract governing access to and use of the Mellio loyalty platform.

ARTICLE 1 – PURPOSE OF SERVICES

The purpose of this Agreement is to define the conditions under which the Provider makes the Mellio software platform available to the Merchant in SaaS (Software as a Service) mode to enable them to create, manage, and run their own digital loyalty program for their end customers.

ARTICLE 2 – ACCESS TO SERVICES

The Merchant accesses the Services using their confidential login credentials. They are solely responsible for the security and confidentiality of their access credentials. Any use of the Services with the Merchant's credentials is deemed to have been performed by the Merchant.

ARTICLE 3 – FINANCIAL TERMS

Access to the Services is granted subject to payment of a subscription, the price and frequency of which are defined upon subscription. Prices are indicated net of taxes (excl. VAT) and are subject to applicable taxes (in particular Belgian VAT of 21% or the reverse charge mechanism). Payment is made by direct debit or credit card via the secure payment provider Mollie.

ARTICLE 4 – DURATION AND TERMINATION

Unless otherwise specified, the subscription is contracted for an indefinite duration with tacit renewal. Either Party may terminate it at any time via the Mellio portal interface, subject to compliance with a notice period corresponding to the current billing period.

ARTICLE 5 – DATA PROTECTION (GDPR)

When using the platform, the Merchant acts as Data Controller for their end customers' data. The Provider acts as a Data Processor within the meaning of Article 28 of the GDPR. The conditions of this processing are governed by the Data Processing Agreement (DPA), which is incorporated by reference into this Agreement and accepted unreservedly by the Merchant.

ARTICLE 6 – LIABILITY

The Provider endeavors to ensure platform availability 24/7, but cannot be held liable for interruptions caused by maintenance or third-party network outages. The Provider's liability is strictly limited to the amount of subscription fees paid by the Merchant during the last twelve (12) months.

ARTICLE 7 – INTELLECTUAL PROPERTY

This Agreement does not confer any intellectual property rights on the Mellio platform, which remains the exclusive property of DS Solutions SRL. The Merchant benefits from a personal, non-exclusive, and temporary license to use the platform.

ARTICLE 8 – APPLICABLE LAW AND JURISDICTION

This Agreement is governed by Belgian law. Any dispute regarding its validity, interpretation, or execution shall be subject to the exclusive jurisdiction of the Enterprise Court of Liège, Marche-en-Famenne division.

✨ Data Protection

Privacy Policy

Strict GDPR compliance.

Informative Version – Reference Language: French
This document is a courtesy translation of the Privacy Policy of DS Solutions SRL, provided solely for the user's comfort and reading convenience. Only the original French version has binding legal value and binds the parties. In the event of any contradiction, dispute, or ambiguity in interpretation between this translation and the French version, the French version shall exclusively prevail.

1. PREAMBLE

This Privacy Policy (the "Policy") describes the conditions under which DS Solutions SRL (hereinafter the "Data Controller", "DS Solutions", "we" or "us") collects, uses, retains, protects and processes personal data within the framework of providing the Mellio SaaS platform (the "Services").

The protection of personal data is a priority for DS Solutions.

We are committed to processing personal data in accordance with:

  • Regulation (EU) 2016/679 of 27 April 2016 (GDPR);
  • applicable Belgian legislation;
  • as well as the recommendations of the Data Protection Authority (DPA).

This Policy is an integral part of our contractual environment but does not replace the SaaS Agreement or the Data Processing Agreement (DPA), which govern the processing carried out on behalf of our professional Clients.

2. SCOPE OF APPLICATION

This Policy applies to the processing of personal data carried out by DS Solutions when acting as Data Controller, particularly concerning:

  • website visitors;
  • prospects;
  • client agencies;
  • their representatives;
  • platform administrator users;
  • individuals contacting our support.

Conversely, when data is processed in the platform on behalf of an Agency (for example, data relating to merchants, end customers, loyalty cards, or loyalty programs), DS Solutions acts primarily as a Data Processor within the meaning of Article 28 of the GDPR.

These processing activities are governed by the Data Processing Agreement (DPA) concluded with each Agency.

3. DEFINITIONS

For the purposes of this Policy:

  • Agency The professional client who has subscribed to the Services.
  • Merchant The client of the Agency using a sub-account of the platform.
  • User Any natural person using the Services.
  • Personal Data Any information relating to an identified or identifiable natural person.
  • Processing Any operation performed on personal data (collection, consultation, retention, modification, deletion, etc.).
  • GDPR Regulation (EU) 2016/679 of the European Parliament and of the Council.

4. DATA CONTROLLER

The Data Controller is:

DS Solutions SRL
Registered office: [to be completed]
Belgium
CBE: [to be completed]
Email: privacy@...
Website: https://...

For any questions relating to the processing of personal data, you can contact us at this address.

If a Data Protection Officer (DPO) is subsequently appointed, their contact details will be published on our website.

5. WHEN ARE WE THE DATA CONTROLLER?

DS Solutions acts as Data Controller particularly for:

  • creating Agency accounts;
  • managing subscriptions;
  • invoicing;
  • accounting;
  • managing payments;
  • managing prospects;
  • demonstration requests;
  • requests addressed to support;
  • platform security;
  • technical logs;
  • legal obligations.

In these situations, DS Solutions determines the purposes and means of the processing itself.

6. WHEN DO WE ACT AS A DATA PROCESSOR?

When Agencies use Mellio to manage their own merchants and the end users of their loyalty programs, DS Solutions acts primarily as a Data Processor.

This particularly concerns:

  • merchant data;
  • merchant customer data;
  • digital loyalty cards;
  • point histories;
  • rewards;
  • loyalty campaigns;
  • information imported by the Agency.

In these processing activities:

  • the Agency remains the Data Controller;
  • DS Solutions acts exclusively on the documented instructions of the Agency, in accordance with the DPA.

DS Solutions never uses this data for its own commercial purposes.

7. OUR PROCESSING PRINCIPLES

DS Solutions applies the following principles to all of its processing activities: lawfulness, fairness, transparency, data minimization, accuracy, purpose limitation, storage limitation, integrity, confidentiality, and accountability.

We only collect data that is strictly necessary for the purposes pursued.

8. CATEGORIES OF DATA COLLECTED

Depending on the Services used, we may process the following categories of data.

8.1 Identification data

  • last name;
  • first name;
  • function/title;
  • company;
  • company number;
  • VAT number;
  • professional contact details.

8.2 Contact details

  • professional email address;
  • phone number;
  • professional postal address.

8.3 Contractual data

  • subscription;
  • order history;
  • quotes;
  • contracts;
  • invoices;
  • payments.

8.4 Connection data

We notably record:

  • IP address;
  • date and time of connection;
  • browser;
  • operating system;
  • user ID;
  • security logs;
  • administration logs;
  • technical information necessary for securing the Services.

This information is primarily used to:

  • ensure security;
  • detect fraud;
  • analyze incidents;
  • guarantee the stability of the Services.

8.5 Support data

When you contact our support, we may retain:

  • email exchanges;
  • transmitted screenshots;
  • diagnostic files;
  • information allowing us to resolve your request.

8.6 Payment data

Payments are processed by our specialized service provider.

DS Solutions never stores full bank card numbers.

We only retain the necessary information:

  • payment status;
  • transaction reference;
  • billing history.

8.7 Technical data

Depending on the features used:

  • technical identifiers;
  • configuration settings;
  • activity logs;
  • user preferences.

9. DATA WE DO NOT COLLECT

DS Solutions does not voluntarily collect:

  • any sensitive data within the meaning of Article 9 of the GDPR;
  • any biometric data;
  • any health data;
  • any data relating to criminal convictions.

The Services are exclusively intended for professionals.

They are not designed to be used by minors under 18 years of age.

10. PURPOSES OF THE PROCESSING

DS Solutions processes personal data only for specified, explicit and legitimate purposes.

The main purposes pursued are as follows:

Purpose Legal basis
Creation and management of accounts Performance of the contract
Provision of SaaS Services Performance of the contract
Subscription management Performance of the contract
Payment management Performance of the contract
Billing management Legal obligation
Technical support Performance of the contract
Platform security Legitimate interest
Fraud detection Legitimate interest
Access logging Legitimate interest
Backups Legitimate interest
Compliance with accounting obligations Legal obligation
Management of contact requests Pre-contractual measures
Response to competent authorities Legal obligation
Defense of our legal rights Legitimate interest

We never process personal data for a purpose incompatible with those described above.

11. LEGAL BASES

In accordance with Article 6 of the GDPR, processing activities are based on one or more of the following legal bases.

11.1 Performance of the contract

The majority of the processing is necessary in order to:

  • create the Client account;
  • provide the Services;
  • provide support;
  • manage payments;
  • administer the subscription.

Without these processing activities, the Services could not be provided.

11.2 Legal obligations

Certain data is retained in order to satisfy in particular:

  • accounting obligations;
  • tax obligations;
  • obligations imposed by public authorities.

11.3 Legitimate interest

DS Solutions pursues several legitimate interests, including:

  • protecting the security of the Services;
  • preventing fraud;
  • ensuring platform stability;
  • detecting cyber attacks;
  • improving performance;
  • ensuring the continuity of the Services;
  • defending its rights in court.

When this legal basis is used, we ensure that we safeguard the rights and freedoms of the data subjects.

11.4 Consent

When consent is required by regulations, particularly for certain non-essential cookies or certain marketing communications, it is obtained beforehand.

Consent can be withdrawn at any time.

12. DATA RECIPIENTS

Personal data is only accessible to persons who need to know it as part of their duties.

This may include in particular:

  • authorized employees of DS Solutions;
  • subcontractors acting on our behalf;
  • public authorities when required by law;
  • legal or accounting advisors in the context of their missions.

We never sell, rent, or market personal data.

13. SUBCONTRACTORS

To ensure the operation of the Services, DS Solutions uses several specialized subcontractors.

As of the publication date of this Policy, the main subcontractors are as follows:

Subcontractor Main purpose
Clever Cloud Platform hosting
Mollie Payment processing
Brevo Sending transactional emails
Google reCAPTCHA Protection against automated abuse
Apple Wallet Generation and management of Wallet cards
Google Wallet Generation and management of Wallet cards

This list may evolve to reflect the evolution of the Services.

Any new subcontractor is selected with the level of diligence reasonably expected of a professional service provider.

When required by the GDPR, a contract compliant with Article 28 is concluded with each of them.

14. INTERNATIONAL TRANSFERS

The main production infrastructures are hosted within the European Union.

However, some of our subcontractors may be required to carry out processing involving a transfer of data outside the European Economic Area.

When such transfers exist, DS Solutions ensures that they are based on one of the mechanisms provided for by Chapter V of the GDPR, notably:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses;
  • any other appropriate safeguard provided by the GDPR.

We ensure that these transfers offer a level of protection substantially equivalent to that guaranteed within the European Union.

15. SECURITY MEASURES

DS Solutions implements technical and organizational measures designed to protect personal data against:

  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • unauthorized disclosure;
  • unauthorized access.

These measures include in particular:

  • encryption of communications via HTTPS and TLS 1.3;
  • encryption of storage volumes by AES-256 (LUKS2) or equivalent technology;
  • user authentication;
  • access control based on the principle of least privilege;
  • logging of administrator accesses;
  • daily backups;
  • infrastructure monitoring;
  • regular updates of software components;
  • limiting access to authorized persons only.

Security measures are regularly re-evaluated to account for changes in risks and the state of the art.

16. CONFIDENTIALITY

DS Solutions' employees and persons authorized to access personal data are subject to a confidentiality obligation.

Access to data is limited strictly to those persons whose duties require such access.

The subcontractors we use are also subject to contractual confidentiality obligations.

17. DATA BREACHES

In the event of a personal data breach likely to result in a risk to the rights and freedoms of the data subjects, DS Solutions implements the procedures provided by the GDPR.

When DS Solutions acts as Data Controller, it notifies, if applicable:

  • the competent Data Protection Authority within legal deadlines;
  • the data subjects when required by regulations.

When DS Solutions acts as a Data Processor, it informs the Data Controller as soon as possible after becoming aware of the breach, to enable them to comply with their own legal obligations.

18. AUTOMATED DECISION-MAKING

DS Solutions does not make any decisions producing legal effects based solely on automated processing within the meaning of Article 22 of the GDPR.

19. DATA RETENTION PERIOD

DS Solutions retains personal data only for the time necessary to fulfill the purposes pursued and comply with its legal obligations.

The main retention periods are as follows:

Category Duration
Agency account For the entire duration of the contract
Billing data 7 years (Belgian legal obligation)
Payments 7 years
Contracts and quotes 10 years after the end of the contractual relationship
Support tickets 3 years after closure
Technical logs 12 months maximum, unless required for security or legal obligations
Backups Rotation up to 30 days maximum, except for exceptional technical necessity
Prospect data 3 years after last contact, unless opposed or requested for deletion

When legal periods expire, the data is securely deleted or anonymized.

20. END OF CONTRACT

At the end of the contractual relationship:

  • accounts are deactivated in accordance with the SaaS Agreement;
  • data is retained during the contractual reversibility period (30 days), to allow the Client to organize the migration or deletion of their data;
  • at the end of this period, the data is deleted or anonymized, unless retention is required by law or necessary for the defense of DS Solutions' rights.

The modalities applicable to data processed on behalf of Agencies are detailed in the Data Processing Agreement (DPA).

21. YOUR RIGHTS

In accordance with the GDPR, you have the following rights.

21.1 Right of access

Obtain confirmation that personal data concerning you is processed and a copy of it.

21.2 Right to rectification

Have any inaccurate or incomplete data corrected.

21.3 Right to erasure

Obtain the erasure of your data when the conditions provided by the GDPR are met.

However, this right is not absolute and may be limited by legal or contractual obligations.

21.4 Right to restriction of processing

Request the temporary suspension of certain processing in the cases provided by regulations.

21.5 Right to object

Object to certain processing based on our legitimate interest.

We will review each request in accordance with the GDPR.

21.6 Right to data portability

Receive the data you have provided to us in a structured, commonly used and machine-readable format when the conditions provided by the GDPR are met.

21.7 Withdrawal of consent

When the processing is based on your consent, it can be withdrawn at any time.

This withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

22. EXERCISING YOUR RIGHTS

Requests related to the exercise of your rights can be sent to:

DS Solutions SRL
Email: privacy@...

To protect personal data, DS Solutions may request additional information when reasonably necessary to verify the identity of the requester.

No systematic copy of an identity document is required.

Requests are processed within the time limits provided by the GDPR.

23. COMPLAINTS

If you believe that your personal data is not being processed in accordance with applicable regulations, you can file a complaint with the competent authority.

In Belgium:

Data Protection Authority (DPA)
Rue de la Presse 35
1000 Brussels
Belgium
https://www.autoriteprotectiondonnees.be

However, we invite you to contact us first in order to seek an amicable solution.

24. COOKIES AND SIMILAR TECHNOLOGIES

The website and platform may use cookies or similar technologies notably to:

  • ensure the technical functioning of the Services;
  • secure forms (Google reCAPTCHA);
  • maintain user sessions;
  • remember certain preferences.

Processing related to cookies is described in our , available on our website.

When regulations require it, your consent is obtained before depositing non-essential cookies.

25. ACCOUNT SECURITY

Each user is responsible for the confidentiality of their login credentials.

Voluntary sharing of a user account is not recommended and may engage the Client's responsibility.

Any suspicion of fraudulent use must be reported immediately to DS Solutions.

26. CHANGES TO THIS POLICY

DS Solutions may modify this Policy notably to:

  • take into account legislative changes;
  • integrate new Services;
  • reflect changes in its processing activities;
  • improve its compliance.

The applicable version is the one published on our website on the date of consultation.

In the event of a substantial modification, affected Clients will be informed by an appropriate means.

27. APPLICABLE LAW

This Policy is governed by Belgian law.

Any dispute relating to its interpretation or execution falls under the jurisdiction of the Belgian courts, subject to applicable mandatory rules on data protection.

✨ Data Processing

Data Processing Agreement (DPA)

GDPR Article 28 compliance.

This is a courtesy translation. In the event of any discrepancy or conflict between this translation and the original French version, the French version shall prevail.

Version 2.0 — Last updated: July 21, 2026

PREAMBLE

This Data Processing Agreement (hereinafter the "DPA") forms an integral part of the SaaS Subscription Agreement entered into between:

DS Solutions SRL, publisher of the Mellio platform, acting as a Processor,

and

the Client (Agency), acting as a Controller.

This DPA is entered into in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").

In the event of a contradiction between the SaaS Agreement and this DPA regarding the processing of personal data, the provisions of this DPA shall prevail.

ARTICLE 1 – DEFINITIONS

The terms used in this DPA have the meaning given to them by the GDPR and the SaaS Agreement.

In particular:

  • Controller The person who determines the purposes and means of the processing. In the context of merchant and end-user data, the Agency is the Controller.
  • Processor The person who processes personal data on behalf of the Controller. DS Solutions acts as a Processor.
  • Data Subject Any identified or identifiable natural person whose data is processed.
  • Personal Data Breach Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

ARTICLE 2 – PURPOSE

This DPA defines the conditions under which DS Solutions processes personal data on behalf of the Agency in connection with the provision of the SaaS Services.

ARTICLE 3 – DURATION

This DPA takes effect on the effective date of the SaaS Agreement.

It remains applicable for the duration of the processing carried out on behalf of the Agency.

Certain obligations (confidentiality, security, data deletion, cooperation with authorities, etc.) survive the termination of the Agreement for as long as DS Solutions retains data for legal reasons.

ARTICLE 4 – DESCRIPTION OF PROCESSING

The processing operations are described in detail in Appendix I of this DPA.

They include in particular:

  • data hosting;
  • storage;
  • backup;
  • consultation;
  • provision of the Services;
  • data securing;
  • technical operations necessary for the normal functioning of the platform.

DS Solutions never processes data for its own account, except when required by law or when acting as a Controller for its own processing operations (billing, customer management, etc.).

ARTICLE 5 – PROCESSOR'S OBLIGATIONS

DS Solutions undertakes to:

  • process data only on documented instructions from the Controller;
  • ensure the confidentiality of the data;
  • ensure that persons authorized to process data are subject to a confidentiality obligation;
  • implement appropriate technical and organizational measures;
  • assist the Controller where reasonably necessary;
  • inform the Controller when an instruction appears to infringe the GDPR.

ARTICLE 6 – CONTROLLER'S INSTRUCTIONS

The Controller instructs the Processor to process the data exclusively to provide the Services set out in the SaaS Agreement.

Any new instruction liable to incur a cost or a substantial change to the Services may be subject to an additional quote.

The Processor may refuse a manifestly unlawful or technically impossible instruction.

ARTICLE 7 – CONFIDENTIALITY

All persons authorized to access personal data are bound by a contractual duty of confidentiality.

This obligation remains applicable throughout their collaboration as well as after its termination.

The Processor ensures that access is limited only to those persons who need to know in order to carry out their duties.

ARTICLE 8 – SECURITY MEASURES

The Processor implements security measures appropriate to the risks, including:

  • encryption of communications (TLS 1.3 or equivalent);
  • encryption of storage volumes (AES-256 / LUKS2 or equivalent);
  • daily backups;
  • access control;
  • logging of administrator access;
  • segmentation of environments;
  • regular updates of software components;
  • infrastructure monitoring.

Detailed measures are set out in Appendix II.

The Processor may modify these measures in order to maintain a level of security in line with the state of the art.

ARTICLE 9 – SUB-PROCESSORS

The Controller authorizes the use of the sub-processors listed in Appendix III, in particular:

  • Clever Cloud;
  • Mollie;
  • Brevo;
  • Google reCAPTCHA;
  • Apple Wallet;
  • Google Wallet.

The Processor may replace or add a sub-processor provided that:

  • it maintains an equivalent level of protection;
  • it informs the Controller where required by regulations.

The Processor remains fully liable for the performance of the obligations placed on its own sub-processors.

ARTICLE 10 – ASSISTANCE

Taking into account the nature of the processing, the Processor reasonably assists the Controller to enable it to fulfill its legal obligations, particularly regarding:

  • requests to exercise data subjects' rights;
  • Data Protection Impact Assessments (DPIA) where necessary;
  • prior consultations with competent authorities.

This assistance is provided to the extent technically possible and proportionate.

ARTICLE 11 – REQUESTS TO EXERCISE RIGHTS

When a data subject exercises a right provided by Articles 15 to 22 of the GDPR concerning data processed on behalf of the Controller, the Processor:

  • informs the Controller as soon as possible;
  • does not directly respond to the request, unless otherwise instructed in writing or legally obliged to do so.

The Processor makes available to the Controller the information reasonably necessary to enable it to respond to the request.

The Controller remains solely responsible for the response provided to the data subject.

ARTICLE 12 – PERSONAL DATA BREACHES

In the event of a personal data breach concerning processing carried out on behalf of the Controller, the Processor:

  • immediately takes reasonable steps to mitigate the consequences of the incident;
  • analyzes the nature and extent of the breach;
  • informs the Controller without undue delay after becoming aware of it;
  • communicates the information available to it allowing the Controller to fulfill its own legal obligations.

Where all information is not immediately available, it is communicated progressively as soon as it can reasonably be established.

The Processor is not obliged to directly notify data subjects, unless legally required.

ARTICLE 13 – COOPERATION

The Processor cooperates reasonably with the Controller to enable it to comply with its GDPR obligations, particularly regarding:

  • impact assessments (DPIA);
  • requests from the supervisory authority;
  • compliance audits;
  • data breach notifications.

Any assistance exceeding the Processor's normal obligations or requiring specific development may be subject to additional billing based on a prior quote accepted by the Controller.

ARTICLE 14 – AUDITS

The Controller may verify compliance with this DPA.

This verification is primarily carried out by providing documents demonstrating the Processor's compliance, including:

  • internal policies;
  • procedures;
  • available certificates or attestations;
  • relevant technical documentation;
  • responses to a reasonable questionnaire.

An on-site audit may only be requested in the event of serious grounds reasonably suggesting a substantial breach of this DPA.

Any audit:

  • is conducted during business days;
  • is announced at least thirty (30) days in advance;
  • must not disrupt the normal operation of the Services;
  • is subject to a confidentiality undertaking.

The costs associated with the audit are borne by the Controller, unless a serious breach by the Processor is established.

The Processor may refuse any audit that is manifestly abusive, repetitive, or liable to compromise the security of its infrastructure or other clients' data.

ARTICLE 15 – RETURN AND DELETION OF DATA

At the end of the SaaS Agreement, the Controller has the reversibility period provided in the Agreement to export or recover the data it wishes to keep.

At the end of this period, the Processor proceeds with the deletion or anonymization of personal data, unless their retention is:

  • required by a legal obligation;
  • necessary for the establishment, exercise, or defense of legal claims;
  • made temporarily necessary by security backups.

Data in backups are automatically deleted at the end of the normal backup rotation cycle.

The Processor confirms, upon reasonable request, that the deletion or anonymization has been completed.

ARTICLE 16 – INTERNATIONAL TRANSFERS

The Processor favors data processing within the European Economic Area.

When an international transfer is necessary, it relies on one of the mechanisms provided by Chapter V of the GDPR, notably:

  • an adequacy decision;
  • Standard Contractual Clauses adopted by the European Commission;
  • any other safeguard recognized by the regulation.

The Processor ensures that transfers provide a level of protection substantially equivalent to that guaranteed within the European Union.

ARTICLE 17 – LIABILITY

Each Party is responsible for the obligations incumbent on it under the GDPR.

The Processor is liable for processing carried out in breach of its own obligations.

The Controller remains solely responsible for:

  • the lawfulness of the processing it decides upon;
  • the information provided to data subjects;
  • determining the purposes of the processing;
  • the applicable legal bases;
  • the compliance of the data it collects.

The Processor cannot be held liable for an unlawful instruction or a processing decided by the Controller.

ARTICLE 18 – PROOF OF COMPLIANCE

The Processor maintains reasonable documentation concerning the implemented security measures.

When relevant, this documentation may be communicated to the Controller, subject to information covered by trade secrets or liable to compromise infrastructure security.

ARTICLE 19 – AMENDMENT OF THE DPA

This DPA may be amended to:

  • reflect changes in regulations;
  • integrate new sub-processors;
  • adapt security measures;
  • reflect changes to the Services.

In the event of a material change, the Controller will be informed by appropriate means.

ARTICLE 20 – APPLICABLE LAW AND JURISDICTION

This DPA is governed by Belgian law.

Any dispute relating to its interpretation or execution falls under the competent courts designated in the SaaS Agreement, subject to mandatory rules of the GDPR.

APPENDIX I – DESCRIPTION OF PROCESSING

  • Controller The Client Agency.
  • Processor DS Solutions SRL.
  • Purpose Provision of the Mellio SaaS platform.
  • Nature of Processing
    • hosting;
    • storage;
    • consultation;
    • modification;
    • backup;
    • deletion;
    • securing;
    • technical transmission of data.
  • Purposes
    • management of loyalty programs;
    • management of merchants;
    • management of users;
    • issuance of Apple Wallet and Google Wallet cards;
    • technical operation of the platform.
  • Categories of Data Subjects Agency administrators; merchants; merchant employees; end-users of loyalty programs (to the extent registered by the Agency).
  • Categories of Data Identification data; contact details; loyalty histories; account information; technical data; connection logs.

APPENDIX II – TECHNICAL AND ORGANIZATIONAL MEASURES

DS Solutions implements, in particular:

  • hosting with Clever Cloud (France);
  • servers located in the European Union;
  • secure communications HTTPS/TLS 1.3;
  • AES-256 volume encryption (LUKS2);
  • daily backups;
  • role-based access control;
  • logging of administrator access;
  • regular security updates;
  • infrastructure monitoring;
  • limitation of administrator privileges;
  • internal incident management procedures.

These measures may evolve to reflect the state of the art.

APPENDIX III – AUTHORIZED SUB-PROCESSORS

As of the signature date of this DPA:

Sub-processor Purpose Primary Location
Clever Cloud Hosting France
Mollie Payment European Union
Brevo Transactional Emails European Union
Google reCAPTCHA Bot Protection Per Google infrastructure
Apple Wallet Wallet Card Management Per Apple infrastructure
Google Wallet Wallet Card Management Per Google infrastructure

This list may be updated in accordance with Article 9 of this DPA.

✨ Cookies

Cookie Policy

How we use cookies and similar technologies.

Version 1.0 — Last updated: July 21, 2026

1. PURPOSE

This Cookie Policy (the "Policy") explains how DS Solutions SRL, publisher of the Mellio platform, uses cookies and similar technologies when you visit its website and Services.

This Policy complements our Privacy Policy.

2. WHAT IS A COOKIE?

A cookie is a small text file stored on your terminal (computer, tablet, or smartphone) when visiting a website.

Cookies specifically allow:

  • ensuring the technical operation of a website;
  • maintaining a user session;
  • securing exchanges;
  • remembering certain preferences.

Cookies do not, by themselves, allow you to be personally identified.

3. COOKIES USED

As of the publication date of this Policy, the website and the Mellio platform exclusively use a technical session cookie.

Cookie Name Purpose Duration Type
__boost_session User session maintenance and proper technical operation of the site Browser session Strictly necessary cookie

This cookie is essential for the normal operation of the site and platform.

It specifically enables:

  • maintaining your browsing session;
  • ensuring continuity of exchanges between your browser and the server;
  • guaranteeing the proper technical operation of the Services.

This cookie is automatically deleted when you close your browser.

4. NO ADVERTISING COOKIES

DS Solutions currently uses no cookies intended for:

  • targeted advertising;
  • user profiling;
  • remarketing;
  • cross-site ad tracking.

5. NO ANALYTICS COOKIES

As of the publication date of this Policy, no audience measurement or statistical analysis cookies (Google Analytics, Matomo, Plausible, or equivalent) are used.

Should this situation change, this Policy will be updated and, where regulation requires, your prior consent will be collected.

6. LEGAL BASIS

The cookie used is strictly necessary for the operation of the site and platform.

In accordance with GDPR and applicable cookie rules, its use is based on our legitimate interest in ensuring the secure operation of the Services and does not require prior consent.

7. MANAGING COOKIES

Since the session cookie is essential to the operation of the site, disabling it via your browser settings may result in malfunctions or prevent access to certain features.

You can nevertheless delete this cookie at any time by clearing your browser's browsing data.

8. MODIFICATIONS TO THIS POLICY

DS Solutions may modify this Policy to take into account:

  • technical developments of the platform;
  • regulatory changes;
  • the potential addition of new cookies or similar technologies.

The applicable version is the one published on our website.

In the event of a material change, affected Clients will be notified by appropriate means.

9. CONTACT

For any questions regarding this Policy or the use of cookies, you can contact us:

DS Solutions SRL
Email: privacy@mellio-pro.fr
Website: https://www.mellio-pro.fr

RELATED DOCUMENTS

This Policy should be read in conjunction with:

  • the Mellio SaaS Subscription Agreement;
  • the Privacy Policy;
  • the Data Processing Agreement (DPA);
  • the Legal Notice.
✨ Legal Notice

Legal Notice

Mandatory company identification information.

Version 1.0 — Last updated: July 21, 2026

1. Website Publisher

Company name: DS Solutions SRL

Legal form: Private limited liability company (SRL)

Registered office: Rue Edmond Debatty 3, 6900 Marche-en-Famenne, Belgium

Company registration number (BCE/KBO): 0777.755.601

VAT number: BE 0777.755.601

Registry (RPM): Enterprise Court of Liège, Marche-en-Famenne division

Email: privacy@mellio-pro.fr

Website: https://www.mellio-pro.fr

2. Publication Director

The Managing Director of DS Solutions SRL

3. Hosting Provider

Host: Clever Cloud SAS

Registered office: 3 rue de l'Allier, 44000 Nantes, France

Website: https://www.clever-cloud.com

Servers are located within the European Union (France)

4. Intellectual Property

  • All site content (texts, images, logos, software, databases) is the exclusive property of DS Solutions SRL or its partners.
  • Any unauthorized reproduction, representation, or exploitation is strictly prohibited.

5. Liability

  • DS Solutions endeavors to ensure the accuracy of information, but cannot guarantee its completeness.
  • DS Solutions shall not be held liable for damages resulting from the use of the website.
  • DS Solutions reserves the right to modify content at any time.

6. Hyperlinks

  • The website may contain links to third-party sites.
  • DS Solutions does not control these sites and disclaims all liability.

7. Personal Data

8. Applicable Law

  • This legal notice is governed by Belgian law.
  • Any dispute falls under the jurisdiction of competent Belgian courts.

9. Contact

DS Solutions SRL

Rue Edmond Debatty 3, 6900 Marche-en-Famenne, Belgium

Email: privacy@mellio-pro.fr

Website: https://www.mellio-pro.fr