M
Mellio pro
Agency Area

Create a partner account

Join our network of distributors and agencies.

1
Email
2
Verification
3
Profile & Address
or

Already have an account? Log in

✨ Agency & Freelancer Area

Become a Mellio pro distributor

Manage the loyalty programs of your merchant clients under your own brand or as a white label.

White label & custom branding

Configure your logos, colors and domain names.

Account management & international VAT

Manage your merchants' plans with strict application of VAT rules.

Built-in backup mechanism

In the event of a shutdown, your merchants can take back direct management of their card.

✨ SaaS Subscription Agreement

General Conditions of Service

Belgian governing law & GDPR.

Informative version – Reference language: French. In case of discrepancy, the French version prevails.
WHITE-LABEL SAAS SUBSCRIPTION AGREEMENT — Version 2.0
This agreement governs the rights and obligations of the Parties in connection with the provision of software services in SaaS mode.

Between: DS Solutions SRL, a company incorporated under Belgian law, with its registered office in Belgium, registered with the Crossroads Bank for Enterprises under the number indicated in its legal notices, hereinafter referred to as the "Service Provider",

and: Any legal entity or natural person acting within the scope of their professional activity and subscribing to the Services, hereinafter referred to as the "Client" or the "Agency",

Together referred to as the "Parties".

This Agreement constitutes a contract for the provision of remotely accessible software services ("Software as a Service" or SaaS) and governs the rights and obligations of the Parties.

Acceptance of this Agreement takes place upon subscription to the Services, by electronic validation, signature, or any other unequivocal manifestation of intent. This acceptance constitutes a binding contractual commitment.

ARTICLE 1 – DEFINITIONS

For the purposes of this Agreement, the following terms shall have the meanings set forth below.

  • 1.1 Service Provider:

    The company DS Solutions SRL, publisher, owner, and operator of the software platform subject to this Agreement.

  • 1.2 Agency:

    The professional Client subscribing to the Services in order to operate them under its own commercial identity, in particular within the framework of a white-label offer intended for its own clients.

  • 1.3 Merchant:

    Any business or professional to whom the Agency provides a sub-account of the platform in order to operate a digital loyalty program. The Merchant is not a party to this Agreement.

  • 1.4 Services:

    All online accessible software functionalities developed by the Service Provider, including in particular:

    • creation of digital loyalty programs;
    • management of digital cards;
    • management of end customers;
    • campaign administration;
    • white-label customization;
    • data hosting;
    • corrective and evolutionary maintenance;
    • technical support.

    The details of the functionalities are set out in the documentation and, where applicable, in Appendix A.

  • 1.5 Platform:

    The SaaS software developed and operated by the Service Provider, accessible via the Internet.

  • 1.6 Main Account:

    The administrator account belonging exclusively to the Agency. The Main Account allows in particular to:

    • create sub-accounts;
    • manage white-label settings;
    • administer subscriptions.
  • 1.7 Sub-account:

    An account created by the Agency for a Merchant. The Sub-account remains legally attached to the Main Account as long as this Agreement remains in force.

  • 1.8 Client Data:

    Any information imported, created, or generated by the Agency in connection with the use of the Services, including those relating to Merchants and their own users.

  • 1.9 Documentation:

    Any functional, technical, or user documentation made available by the Service Provider.

  • 1.10 Business Day:

    Any day from Monday to Friday, excluding statutory public holidays in Belgium.

ARTICLE 2 – PURPOSE OF THE AGREEMENT

The purpose of this Agreement is to set forth the terms and conditions under which the Service Provider grants the Client a right to access and use its SaaS platform in hosted mode.

The Service Provider makes the Services available exclusively on a SaaS model.

No local installation of the software, no delivery of the source code, and no transfer of intellectual property are granted to the Client.

ARTICLE 3 – DESCRIPTION OF SERVICES

The Services are provided exclusively online. They include in particular:

  • hosting of the Platform;
  • software updates;
  • security patches;
  • backups;
  • support as provided in this Agreement;
  • general platform enhancements.

The Service Provider remains free to evolve the Services in order to improve their operation, security, ergonomics, or performance. Such evolutions do not constitute a modification of the Agreement provided that they do not call into question the essential purpose of the Services.

The Service Provider may also remove a feature that has become obsolete or technically unsuitable when it is replaced by an equivalent or improved solution.

ARTICLE 4 – ACCESS CONDITIONS

Access to the Services is exclusively reserved for professionals.

The Client warrants:

  • possessing the necessary legal capacity;
  • acting within the scope of its professional activity;
  • providing accurate and up-to-date information;
  • maintaining the confidentiality of its credentials.

The Client remains solely responsible for any use made by means of its credentials. Any compromise or suspicion of fraudulent use must be reported without delay to the Service Provider.

ARTICLE 5 – USER LICENSE

Subject to full payment of the amounts due, the Service Provider grants the Client a license that is:

  • personal;
  • non-exclusive;
  • non-assignable;
  • non-transferable;
  • revocable;
  • limited to the duration of this Agreement.

This license exclusively authorizes the use of the Services within the normal scope of the Client's professional activity. It does not confer any ownership rights over the software.

In particular, the Client is prohibited from:

  • copying all or part of the Platform;
  • reproducing user interfaces;
  • performing any decompilation;
  • performing reverse engineering;
  • bypassing security mechanisms;
  • performing automated scraping;
  • developing or having developed a competing software from the Services;
  • attempting to obtain the source code or internal architecture of the software;
  • renting, reselling, or sub-licensing the Platform other than through the white-label mechanisms provided for in this Agreement.

Any violation of this clause constitutes a material breach authorizing the immediate suspension of the Services and, where appropriate, the termination of the Agreement exclusively at the Client's fault, without prejudice to any claim for damages.

ARTICLE 6 – WHITE LABEL

The Service Provider authorizes the Client to market the Services under its own visual identity. This authorization exclusively covers the customization options made available within the Platform, namely:

  • trade name;
  • logo;
  • colors;
  • graphic charter;
  • email templates;
  • custom domain or subdomain when this feature is available.

This customization does not confer any rights over the software itself.

The Service Provider remains the sole owner of:

  • the software;
  • its architecture;
  • its developments;
  • its interfaces;
  • its technical databases;
  • all intellectual property rights attached to the Services.

The Client acknowledges that customizing the Platform creates no ownership or co-ownership rights over the technical elements of the software.

ARTICLE 7 – SPECIFIC DEVELOPMENTS

  • 7.1 Principle:

    The Service Provider provides the Client with the Services described in this Agreement.

    Any request for a specific development, functional enhancement, particular integration, or adaptation not provided for in the standard features shall be subject to a preliminary study.

    The Service Provider remains entirely free to accept or refuse any request for specific development. No obligation to develop is imposed upon it.

  • 7.2 Prior Quote:

    Any specific development must obligatorily be subject to:

    • a preliminary analysis;
    • a written quote;
    • an estimated timeframe;
    • express acceptance by the Client.

    No development shall commence prior to the acceptance of the quote.

  • 7.3 Deadlines:

    The communicated deadlines are provided for informational purposes.

    The Service Provider commits to using reasonable means to meet these deadlines, without them constituting an obligation of result.

  • 7.4 Ownership of Developments:

    Unless agreed otherwise in writing, all developments carried out within the framework of this Agreement remain the exclusive property of the Service Provider.

    The Client solely benefits from a right to use the developments integrated into the Platform for the duration of the Agreement.

    The Service Provider is expressly authorized to reuse, modify, improve, and integrate all or part of the developments carried out for the Client into any other version of its software or for any other client.

    Payment for a specific development in no way entails an assignment of intellectual property.

ARTICLE 8 – INTELLECTUAL PROPERTY

  • 8.1 Software Ownership:

    The Client acknowledges that the Service Provider remains the exclusive holder of all intellectual property rights pertaining in particular to:

    • the software;
    • the graphical interfaces;
    • the source code;
    • the object code;
    • the algorithms;
    • the technical databases;
    • the documentation;
    • the data models;
    • the trademarks;
    • the Service Provider's logos;
    • the operating methods.

    No provision in this Agreement may be interpreted as effecting an assignment of these rights.

  • 8.2 Prohibitions:

    In particular, the Client is prohibited from:

    • decompiling the software;
    • disassembling the software;
    • performing reverse engineering;
    • analyzing the internal operation of the software in order to reproduce its functionalities;
    • copying the graphical interfaces;
    • automating the extraction of operating data from the Platform (scraping);
    • bypassing technical security measures;
    • attempting to access the source code;
    • removing intellectual property notices;
    • developing competing software based on an analysis of the Services.
  • 8.3 Documentation:

    Any documentation provided to the Client remains the property of the Service Provider. It is exclusively intended for the use of the Services and may not be reproduced or distributed without written authorization.

  • 8.4 Trademarks:

    The Client is not granted any rights to the Service Provider's trademarks. Use of the Service Provider's name or logo is prohibited unless authorized in writing or where necessary for the execution of the Agreement.

ARTICLE 9 – SERVICE PROVIDER OBLIGATIONS

The Service Provider agrees to:

  • provide the Services in accordance with this Agreement;
  • host the Platform;
  • maintain a level of security consistent with industry best practices;
  • perform the backups set out in the Agreement;
  • rectify anomalies within reasonable timeframes depending on their criticality;
  • ensure general updates to the Platform;
  • provide the support set out in the corresponding article.

The Service Provider's obligations constitute best-efforts obligations, unless expressly stated otherwise.

ARTICLE 10 – CLIENT OBLIGATIONS

The Client notably agrees to:

  • use the Services in accordance with this Agreement;
  • comply with applicable laws;
  • keep its information up to date;
  • protect its credentials;
  • train its own users;
  • provide primary-level support to its Merchants;
  • pay the subscriptions on the agreed due dates.

The Client remains solely responsible for configuring its programs, the campaigns it broadcasts, the content published, the data it imports, and the processing it carries out. The Service Provider exercises no prior control over these elements.

ARTICLE 11 – ACCEPTABLE USE OF SERVICES

The Client agrees not to use the Services:

  • for unlawful purposes;
  • to infringe upon the rights of third parties;
  • to disseminate content contrary to public order;
  • to send unsolicited communications (spam);
  • to host malicious content;
  • to distribute malicious software;
  • to compromise the security of the Platform;
  • to attempt to access other clients' data;
  • to disrupt the operation of the Services.

The Client also ensures that the Merchants for whom it opens a Sub-account comply with these same obligations. The Client remains responsible for their actions vis-à-vis the Service Provider.

ARTICLE 12 – PRIMARY-LEVEL SUPPORT

The Client acknowledges acting as a commercial intermediary with its own Merchants. In this capacity, it exclusively provides:

  • functional support;
  • user assistance;
  • requests relating to loyalty programs;
  • commercial inquiries;
  • training requests.

The Service Provider is not bound to provide any direct assistance to Merchants or their users. Any request received directly may be redirected to the Client without further processing. This separation constitutes an essential element of white-label operations.

ARTICLE 13 – SUSPENSION FOR ABUSIVE USE

The Service Provider may immediately suspend all or part of the Services when there is a serious risk to the security of the Platform, the integrity of the data, the availability of the Services, other Clients, or the Service Provider's infrastructure.

Such suspension may occur in particular in the event of:

  • intrusion attempt;
  • reverse engineering;
  • cyberattack;
  • fraudulent use;
  • distribution of malicious software;
  • non-compliance with contractual obligations;
  • manifest violation of the GDPR;
  • use likely to engage the Service Provider's liability.

Where the situation permits, the Service Provider shall inform the Client beforehand. In case of emergency, the suspension may occur immediately. The suspension gives rise to no compensation when justified by the protection of the Services, their users, or the Service Provider.

ARTICLE 14 – EVOLUTION OF SERVICES

The Client acknowledges that the Platform constitutes continuously evolving software. The Service Provider may freely:

  • fix anomalies;
  • modify the user interface;
  • improve performance;
  • strengthen security;
  • add new features;
  • remove obsolete features;
  • modify the internal organization of the Platform.

These evolutions do not constitute a material modification of the Agreement provided they do not deprive the Client of the essential functionalities that motivated their subscription.

The Service Provider shall inform the Client, as far as possible, of major evolutions likely to have a significant impact on the use of the Services.

ARTICLE 15 – SERVICE AVAILABILITY (SLA)

  • 15.1 Availability Commitment:

    The Service Provider implements the technical, human, and organizational means reasonably necessary to ensure a monthly availability of the Services of 99.8%, calculated over a calendar month.

    This commitment constitutes a contractual service level objective (SLA) and not an absolute guarantee of continuous operation. The Service Provider is bound by a reinforced best-efforts obligation.

  • 15.2 Exclusions from the Availability Calculation:

    Interruptions resulting notably from the following are not taken into account in calculating the availability rate:

    • planned maintenance;
    • emergency maintenance made necessary to preserve the security or integrity of the Services;
    • a force majeure event;
    • a failure of the hosting provider;
    • an interruption of Internet services independent of the Service Provider;
    • a general power outage;
    • a DNS failure;
    • an unavailability of Apple Wallet, Google Wallet, Mollie, or any other third-party provider services;
    • a cyberattack, in particular of the DDoS or ransomware type;
    • a security incident requiring a preventive interruption;
    • a malfunction caused by the Client or any third-party software used by them.

    These periods are excluded from the SLA calculation.

  • 15.3 Consequence of Non-Compliance with the SLA:

    When the availability rate is below 99.8% for two (2) consecutive calendar months, excluding the exclusions set out in this Agreement, the Client may:

    • request explanations from the Service Provider;
    • request the implementation of a reasonable improvement plan;
    • or terminate the Agreement without penalty, subject to written notification.

    In the event of termination under these conditions, the Service Provider shall only refund the portion of the subscriptions paid in advance corresponding to the remaining period. No other compensation is due.

ARTICLE 16 – HOSTING

The Platform is hosted with a professional provider selected by the Service Provider.

As of the date of signing this Agreement, hosting is provided by Clever Cloud, on infrastructures located in the Paris region (France).

The Service Provider may change the hosting provider at any time provided that:

  • the overall level of security is not decreased;
  • GDPR requirements remain respected;
  • the Services continue to be hosted within the European Economic Area, unless prior information is provided and applicable legal requirements are met.

A change of hosting provider does not constitute a material modification of this Agreement.

ARTICLE 17 – MAINTENANCE

  • 17.1 Corrective Maintenance:

    The Service Provider ensures the correction of anomalies affecting the Services. Interventions are prioritized according to their criticality. The Service Provider remains the sole judge of the technical means necessary for their resolution.

  • 17.2 Evolutionary Maintenance:

    The Service Provider regularly updates the Platform notably to improve its performance, enhance security, add new features, adapt the software to technological developments, and ensure compatibility with recent operating systems and browsers. These developments are included in the subscription unless otherwise stated.

  • 17.3 Planned Maintenance:

    Whenever reasonably possible, the Service Provider informs the Client of maintenance operations that may temporarily interrupt the Services. Maintenance is carried out, as far as possible, outside of normal business hours. The notice period is indicative and may be reduced when the security or stability of the Services requires it.

  • 17.4 Emergency Maintenance:

    The Service Provider may immediately interrupt the Services when intervention is necessary to patch a security vulnerability, prevent data loss, protect the integrity of the infrastructure, respond to a cyberattack, or apply a critical update. No prior notice is required in this scenario.

ARTICLE 18 – SECURITY OF SERVICES

The Service Provider implements appropriate technical and organizational measures to ensure a level of security consistent with industry best practices. These measures notably include:

  • the systematic use of the HTTPS protocol;
  • the encryption of communications using TLS 1.3 or an equivalent subsequent version;
  • the encryption of storage volumes using AES-256 (LUKS2) or equivalent technology;
  • the control of administrative accesses;
  • the monitoring of infrastructures;
  • regular updates of software components;
  • limiting access only to authorized personnel.

The Service Provider may evolve these measures in order to maintain a level of security adapted to the state of the art. The Client acknowledges that no computer system can guarantee absolute security.

ARTICLE 19 – BACKUPS

The Service Provider performs regular backups of the data necessary for the operation of the Services. As of the date of this Agreement, backups are performed daily. The Service Provider may adapt their frequency or operating mode to improve the security or reliability of the Services.

  • 19.1 Restoration:

    In the event of data loss resulting from a failure of the Service Provider, the hosting infrastructure, or a technical incident affecting the Services, the Service Provider implements reasonable means to restore the data available in the backups. However, the Service Provider guarantees neither a full restoration nor the total absence of data loss.

  • 19.2 Voluntary Deletion:

    The Service Provider is not bound by any restoration obligation when the deletion results from a voluntary action by the Client, an action carried out by an administrator of the Client, or a deletion carried out by an authorized user of the Client. The Client remains solely responsible for managing its data.

ARTICLE 20 – TECHNICAL SUPPORT

  • 20.1 Purpose:

    The Service Provider provides Level 2 technical support. The support is exclusively intended to assist the Agency in the technical use of the Services. It does not include training, functional configuration, Merchant support, or end-user support.

  • 20.2 Communication Channel:

    Support requests are exclusively processed by email. The Service Provider may, at its sole discretion, use any other means of communication when it deems it necessary.

  • 20.3 Single Point of Contact:

    The Client designates a primary contact person responsible for technical relations with the Service Provider. The Service Provider may refuse to process requests originating from unauthorized persons.

  • 20.4 Hours:

    Support is provided on Business Days from 08:00 to 16:00 (GMT+1). Outside these hours, no permanence is guaranteed.

  • 20.5 Response Time:

    The Service Provider agrees to acknowledge receipt of or respond to support requests within a maximum period of forty-eight (48) business hours. This timeframe constitutes a response commitment only. It does not constitute a resolution commitment. Resolution times depend, inter alia, on the complexity of the incident, its criticality, the potential intervention of third-party providers, and the information communicated by the Client.

  • 20.6 Exclusions:

    The support notably does not cover training, specific development requests, interventions on the Client's equipment, problems related to the Client's network, third-party software, obsolete browsers, the Client's hardware, and incidents resulting from improper use of the Services. These services may be subject to a separate quote.

ARTICLE 21 – THIRD-PARTY PROVIDERS

The Client acknowledges that certain Services rely on independent third-party providers. As of the date of this Agreement, these notably include:

  • Clever Cloud (hosting);
  • Mollie (payment);
  • Brevo (emails);
  • Google reCAPTCHA;
  • Apple Wallet;
  • Google Wallet.

The Service Provider cannot be held liable for interruptions, limitations, or malfunctions exclusively attributable to these third-party providers. The Service Provider, however, remains responsible for selecting them with the reasonable care expected of a professional.

✨ Data Protection

Privacy Policy

Strict GDPR compliance.

Informative Version – Reference Language: French
This document is a courtesy translation of the Privacy Policy of DS Solutions SRL, provided solely for the user's comfort and reading convenience. Only the original French version has binding legal value and binds the parties. In the event of any contradiction, dispute, or ambiguity in interpretation between this translation and the French version, the French version shall exclusively prevail.

1. PREAMBLE

This Privacy Policy (the "Policy") describes the conditions under which DS Solutions SRL (hereinafter the "Data Controller", "DS Solutions", "we" or "us") collects, uses, retains, protects and processes personal data within the framework of providing the Mellio SaaS platform (the "Services").

The protection of personal data is a priority for DS Solutions.

We are committed to processing personal data in accordance with:

  • Regulation (EU) 2016/679 of 27 April 2016 (GDPR);
  • applicable Belgian legislation;
  • as well as the recommendations of the Data Protection Authority (DPA).

This Policy is an integral part of our contractual environment but does not replace the SaaS Agreement or the Data Processing Agreement (DPA), which govern the processing carried out on behalf of our professional Clients.

2. SCOPE OF APPLICATION

This Policy applies to the processing of personal data carried out by DS Solutions when acting as Data Controller, particularly concerning:

  • website visitors;
  • prospects;
  • client agencies;
  • their representatives;
  • platform administrator users;
  • individuals contacting our support.

Conversely, when data is processed in the platform on behalf of an Agency (for example, data relating to merchants, end customers, loyalty cards, or loyalty programs), DS Solutions acts primarily as a Data Processor within the meaning of Article 28 of the GDPR.

These processing activities are governed by the Data Processing Agreement (DPA) concluded with each Agency.

3. DEFINITIONS

For the purposes of this Policy:

  • Agency The professional client who has subscribed to the Services.
  • Merchant The client of the Agency using a sub-account of the platform.
  • User Any natural person using the Services.
  • Personal Data Any information relating to an identified or identifiable natural person.
  • Processing Any operation performed on personal data (collection, consultation, retention, modification, deletion, etc.).
  • GDPR Regulation (EU) 2016/679 of the European Parliament and of the Council.

4. DATA CONTROLLER

The Data Controller is:

DS Solutions SRL
Registered office: [to be completed]
Belgium
CBE: [to be completed]
Email: privacy@...
Website: https://...

For any questions relating to the processing of personal data, you can contact us at this address.

If a Data Protection Officer (DPO) is subsequently appointed, their contact details will be published on our website.

5. WHEN ARE WE THE DATA CONTROLLER?

DS Solutions acts as Data Controller particularly for:

  • creating Agency accounts;
  • managing subscriptions;
  • invoicing;
  • accounting;
  • managing payments;
  • managing prospects;
  • demonstration requests;
  • requests addressed to support;
  • platform security;
  • technical logs;
  • legal obligations.

In these situations, DS Solutions determines the purposes and means of the processing itself.

6. WHEN DO WE ACT AS A DATA PROCESSOR?

When Agencies use Mellio to manage their own merchants and the end users of their loyalty programs, DS Solutions acts primarily as a Data Processor.

This particularly concerns:

  • merchant data;
  • merchant customer data;
  • digital loyalty cards;
  • point histories;
  • rewards;
  • loyalty campaigns;
  • information imported by the Agency.

In these processing activities:

  • the Agency remains the Data Controller;
  • DS Solutions acts exclusively on the documented instructions of the Agency, in accordance with the DPA.

DS Solutions never uses this data for its own commercial purposes.

7. OUR PROCESSING PRINCIPLES

DS Solutions applies the following principles to all of its processing activities: lawfulness, fairness, transparency, data minimization, accuracy, purpose limitation, storage limitation, integrity, confidentiality, and accountability.

We only collect data that is strictly necessary for the purposes pursued.

8. CATEGORIES OF DATA COLLECTED

Depending on the Services used, we may process the following categories of data.

8.1 Identification data

  • last name;
  • first name;
  • function/title;
  • company;
  • company number;
  • VAT number;
  • professional contact details.

8.2 Contact details

  • professional email address;
  • phone number;
  • professional postal address.

8.3 Contractual data

  • subscription;
  • order history;
  • quotes;
  • contracts;
  • invoices;
  • payments.

8.4 Connection data

We notably record:

  • IP address;
  • date and time of connection;
  • browser;
  • operating system;
  • user ID;
  • security logs;
  • administration logs;
  • technical information necessary for securing the Services.

This information is primarily used to:

  • ensure security;
  • detect fraud;
  • analyze incidents;
  • guarantee the stability of the Services.

8.5 Support data

When you contact our support, we may retain:

  • email exchanges;
  • transmitted screenshots;
  • diagnostic files;
  • information allowing us to resolve your request.

8.6 Payment data

Payments are processed by our specialized service provider.

DS Solutions never stores full bank card numbers.

We only retain the necessary information:

  • payment status;
  • transaction reference;
  • billing history.

8.7 Technical data

Depending on the features used:

  • technical identifiers;
  • configuration settings;
  • activity logs;
  • user preferences.

9. DATA WE DO NOT COLLECT

DS Solutions does not voluntarily collect:

  • any sensitive data within the meaning of Article 9 of the GDPR;
  • any biometric data;
  • any health data;
  • any data relating to criminal convictions.

The Services are exclusively intended for professionals.

They are not designed to be used by minors under 18 years of age.

10. PURPOSES OF THE PROCESSING

DS Solutions processes personal data only for specified, explicit and legitimate purposes.

The main purposes pursued are as follows:

Purpose Legal basis
Creation and management of accounts Performance of the contract
Provision of SaaS Services Performance of the contract
Subscription management Performance of the contract
Payment management Performance of the contract
Billing management Legal obligation
Technical support Performance of the contract
Platform security Legitimate interest
Fraud detection Legitimate interest
Access logging Legitimate interest
Backups Legitimate interest
Compliance with accounting obligations Legal obligation
Management of contact requests Pre-contractual measures
Response to competent authorities Legal obligation
Defense of our legal rights Legitimate interest

We never process personal data for a purpose incompatible with those described above.

11. LEGAL BASES

In accordance with Article 6 of the GDPR, processing activities are based on one or more of the following legal bases.

11.1 Performance of the contract

The majority of the processing is necessary in order to:

  • create the Client account;
  • provide the Services;
  • provide support;
  • manage payments;
  • administer the subscription.

Without these processing activities, the Services could not be provided.

11.2 Legal obligations

Certain data is retained in order to satisfy in particular:

  • accounting obligations;
  • tax obligations;
  • obligations imposed by public authorities.

11.3 Legitimate interest

DS Solutions pursues several legitimate interests, including:

  • protecting the security of the Services;
  • preventing fraud;
  • ensuring platform stability;
  • detecting cyber attacks;
  • improving performance;
  • ensuring the continuity of the Services;
  • defending its rights in court.

When this legal basis is used, we ensure that we safeguard the rights and freedoms of the data subjects.

11.4 Consent

When consent is required by regulations, particularly for certain non-essential cookies or certain marketing communications, it is obtained beforehand.

Consent can be withdrawn at any time.

12. DATA RECIPIENTS

Personal data is only accessible to persons who need to know it as part of their duties.

This may include in particular:

  • authorized employees of DS Solutions;
  • subcontractors acting on our behalf;
  • public authorities when required by law;
  • legal or accounting advisors in the context of their missions.

We never sell, rent, or market personal data.

13. SUBCONTRACTORS

To ensure the operation of the Services, DS Solutions uses several specialized subcontractors.

As of the publication date of this Policy, the main subcontractors are as follows:

Subcontractor Main purpose
Clever Cloud Platform hosting
Mollie Payment processing
Brevo Sending transactional emails
Google reCAPTCHA Protection against automated abuse
Apple Wallet Generation and management of Wallet cards
Google Wallet Generation and management of Wallet cards

This list may evolve to reflect the evolution of the Services.

Any new subcontractor is selected with the level of diligence reasonably expected of a professional service provider.

When required by the GDPR, a contract compliant with Article 28 is concluded with each of them.

14. INTERNATIONAL TRANSFERS

The main production infrastructures are hosted within the European Union.

However, some of our subcontractors may be required to carry out processing involving a transfer of data outside the European Economic Area.

When such transfers exist, DS Solutions ensures that they are based on one of the mechanisms provided for by Chapter V of the GDPR, notably:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses;
  • any other appropriate safeguard provided by the GDPR.

We ensure that these transfers offer a level of protection substantially equivalent to that guaranteed within the European Union.

15. SECURITY MEASURES

DS Solutions implements technical and organizational measures designed to protect personal data against:

  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • unauthorized disclosure;
  • unauthorized access.

These measures include in particular:

  • encryption of communications via HTTPS and TLS 1.3;
  • encryption of storage volumes by AES-256 (LUKS2) or equivalent technology;
  • user authentication;
  • access control based on the principle of least privilege;
  • logging of administrator accesses;
  • daily backups;
  • infrastructure monitoring;
  • regular updates of software components;
  • limiting access to authorized persons only.

Security measures are regularly re-evaluated to account for changes in risks and the state of the art.

16. CONFIDENTIALITY

DS Solutions' employees and persons authorized to access personal data are subject to a confidentiality obligation.

Access to data is limited strictly to those persons whose duties require such access.

The subcontractors we use are also subject to contractual confidentiality obligations.

17. DATA BREACHES

In the event of a personal data breach likely to result in a risk to the rights and freedoms of the data subjects, DS Solutions implements the procedures provided by the GDPR.

When DS Solutions acts as Data Controller, it notifies, if applicable:

  • the competent Data Protection Authority within legal deadlines;
  • the data subjects when required by regulations.

When DS Solutions acts as a Data Processor, it informs the Data Controller as soon as possible after becoming aware of the breach, to enable them to comply with their own legal obligations.

18. AUTOMATED DECISION-MAKING

DS Solutions does not make any decisions producing legal effects based solely on automated processing within the meaning of Article 22 of the GDPR.

19. DATA RETENTION PERIOD

DS Solutions retains personal data only for the time necessary to fulfill the purposes pursued and comply with its legal obligations.

The main retention periods are as follows:

Category Duration
Agency account For the entire duration of the contract
Billing data 7 years (Belgian legal obligation)
Payments 7 years
Contracts and quotes 10 years after the end of the contractual relationship
Support tickets 3 years after closure
Technical logs 12 months maximum, unless required for security or legal obligations
Backups Rotation up to 30 days maximum, except for exceptional technical necessity
Prospect data 3 years after last contact, unless opposed or requested for deletion

When legal periods expire, the data is securely deleted or anonymized.

20. END OF CONTRACT

At the end of the contractual relationship:

  • accounts are deactivated in accordance with the SaaS Agreement;
  • data is retained during the contractual reversibility period (30 days), to allow the Client to organize the migration or deletion of their data;
  • at the end of this period, the data is deleted or anonymized, unless retention is required by law or necessary for the defense of DS Solutions' rights.

The modalities applicable to data processed on behalf of Agencies are detailed in the Data Processing Agreement (DPA).

21. YOUR RIGHTS

In accordance with the GDPR, you have the following rights.

21.1 Right of access

Obtain confirmation that personal data concerning you is processed and a copy of it.

21.2 Right to rectification

Have any inaccurate or incomplete data corrected.

21.3 Right to erasure

Obtain the erasure of your data when the conditions provided by the GDPR are met.

However, this right is not absolute and may be limited by legal or contractual obligations.

21.4 Right to restriction of processing

Request the temporary suspension of certain processing in the cases provided by regulations.

21.5 Right to object

Object to certain processing based on our legitimate interest.

We will review each request in accordance with the GDPR.

21.6 Right to data portability

Receive the data you have provided to us in a structured, commonly used and machine-readable format when the conditions provided by the GDPR are met.

21.7 Withdrawal of consent

When the processing is based on your consent, it can be withdrawn at any time.

This withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

22. EXERCISING YOUR RIGHTS

Requests related to the exercise of your rights can be sent to:

DS Solutions SRL
Email: privacy@...

To protect personal data, DS Solutions may request additional information when reasonably necessary to verify the identity of the requester.

No systematic copy of an identity document is required.

Requests are processed within the time limits provided by the GDPR.

23. COMPLAINTS

If you believe that your personal data is not being processed in accordance with applicable regulations, you can file a complaint with the competent authority.

In Belgium:

Data Protection Authority (DPA)
Rue de la Presse 35
1000 Brussels
Belgium
https://www.autoriteprotectiondonnees.be

However, we invite you to contact us first in order to seek an amicable solution.

24. COOKIES AND SIMILAR TECHNOLOGIES

The website and platform may use cookies or similar technologies notably to:

  • ensure the technical functioning of the Services;
  • secure forms (Google reCAPTCHA);
  • maintain user sessions;
  • remember certain preferences.

Processing related to cookies is described in our , available on our website.

When regulations require it, your consent is obtained before depositing non-essential cookies.

25. ACCOUNT SECURITY

Each user is responsible for the confidentiality of their login credentials.

Voluntary sharing of a user account is not recommended and may engage the Client's responsibility.

Any suspicion of fraudulent use must be reported immediately to DS Solutions.

26. CHANGES TO THIS POLICY

DS Solutions may modify this Policy notably to:

  • take into account legislative changes;
  • integrate new Services;
  • reflect changes in its processing activities;
  • improve its compliance.

The applicable version is the one published on our website on the date of consultation.

In the event of a substantial modification, affected Clients will be informed by an appropriate means.

27. APPLICABLE LAW

This Policy is governed by Belgian law.

Any dispute relating to its interpretation or execution falls under the jurisdiction of the Belgian courts, subject to applicable mandatory rules on data protection.

✨ Data Processing

Data Processing Agreement (DPA)

GDPR Article 28 compliance.

This is a courtesy translation. In the event of any discrepancy or conflict between this translation and the original French version, the French version shall prevail.

Version 2.0 — Last updated: July 21, 2026

PREAMBLE

This Data Processing Agreement (hereinafter the "DPA") forms an integral part of the SaaS Subscription Agreement entered into between:

DS Solutions SRL, publisher of the Mellio platform, acting as a Processor,

and

the Client (Agency), acting as a Controller.

This DPA is entered into in accordance with Article 28 of Regulation (EU) 2016/679 ("GDPR").

In the event of a contradiction between the SaaS Agreement and this DPA regarding the processing of personal data, the provisions of this DPA shall prevail.

ARTICLE 1 – DEFINITIONS

The terms used in this DPA have the meaning given to them by the GDPR and the SaaS Agreement.

In particular:

  • Controller The person who determines the purposes and means of the processing. In the context of merchant and end-user data, the Agency is the Controller.
  • Processor The person who processes personal data on behalf of the Controller. DS Solutions acts as a Processor.
  • Data Subject Any identified or identifiable natural person whose data is processed.
  • Personal Data Breach Any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

ARTICLE 2 – PURPOSE

This DPA defines the conditions under which DS Solutions processes personal data on behalf of the Agency in connection with the provision of the SaaS Services.

ARTICLE 3 – DURATION

This DPA takes effect on the effective date of the SaaS Agreement.

It remains applicable for the duration of the processing carried out on behalf of the Agency.

Certain obligations (confidentiality, security, data deletion, cooperation with authorities, etc.) survive the termination of the Agreement for as long as DS Solutions retains data for legal reasons.

ARTICLE 4 – DESCRIPTION OF PROCESSING

The processing operations are described in detail in Appendix I of this DPA.

They include in particular:

  • data hosting;
  • storage;
  • backup;
  • consultation;
  • provision of the Services;
  • data securing;
  • technical operations necessary for the normal functioning of the platform.

DS Solutions never processes data for its own account, except when required by law or when acting as a Controller for its own processing operations (billing, customer management, etc.).

ARTICLE 5 – PROCESSOR'S OBLIGATIONS

DS Solutions undertakes to:

  • process data only on documented instructions from the Controller;
  • ensure the confidentiality of the data;
  • ensure that persons authorized to process data are subject to a confidentiality obligation;
  • implement appropriate technical and organizational measures;
  • assist the Controller where reasonably necessary;
  • inform the Controller when an instruction appears to infringe the GDPR.

ARTICLE 6 – CONTROLLER'S INSTRUCTIONS

The Controller instructs the Processor to process the data exclusively to provide the Services set out in the SaaS Agreement.

Any new instruction liable to incur a cost or a substantial change to the Services may be subject to an additional quote.

The Processor may refuse a manifestly unlawful or technically impossible instruction.

ARTICLE 7 – CONFIDENTIALITY

All persons authorized to access personal data are bound by a contractual duty of confidentiality.

This obligation remains applicable throughout their collaboration as well as after its termination.

The Processor ensures that access is limited only to those persons who need to know in order to carry out their duties.

ARTICLE 8 – SECURITY MEASURES

The Processor implements security measures appropriate to the risks, including:

  • encryption of communications (TLS 1.3 or equivalent);
  • encryption of storage volumes (AES-256 / LUKS2 or equivalent);
  • daily backups;
  • access control;
  • logging of administrator access;
  • segmentation of environments;
  • regular updates of software components;
  • infrastructure monitoring.

Detailed measures are set out in Appendix II.

The Processor may modify these measures in order to maintain a level of security in line with the state of the art.

ARTICLE 9 – SUB-PROCESSORS

The Controller authorizes the use of the sub-processors listed in Appendix III, in particular:

  • Clever Cloud;
  • Mollie;
  • Brevo;
  • Google reCAPTCHA;
  • Apple Wallet;
  • Google Wallet.

The Processor may replace or add a sub-processor provided that:

  • it maintains an equivalent level of protection;
  • it informs the Controller where required by regulations.

The Processor remains fully liable for the performance of the obligations placed on its own sub-processors.

ARTICLE 10 – ASSISTANCE

Taking into account the nature of the processing, the Processor reasonably assists the Controller to enable it to fulfill its legal obligations, particularly regarding:

  • requests to exercise data subjects' rights;
  • Data Protection Impact Assessments (DPIA) where necessary;
  • prior consultations with competent authorities.

This assistance is provided to the extent technically possible and proportionate.

ARTICLE 11 – REQUESTS TO EXERCISE RIGHTS

When a data subject exercises a right provided by Articles 15 to 22 of the GDPR concerning data processed on behalf of the Controller, the Processor:

  • informs the Controller as soon as possible;
  • does not directly respond to the request, unless otherwise instructed in writing or legally obliged to do so.

The Processor makes available to the Controller the information reasonably necessary to enable it to respond to the request.

The Controller remains solely responsible for the response provided to the data subject.

ARTICLE 12 – PERSONAL DATA BREACHES

In the event of a personal data breach concerning processing carried out on behalf of the Controller, the Processor:

  • immediately takes reasonable steps to mitigate the consequences of the incident;
  • analyzes the nature and extent of the breach;
  • informs the Controller without undue delay after becoming aware of it;
  • communicates the information available to it allowing the Controller to fulfill its own legal obligations.

Where all information is not immediately available, it is communicated progressively as soon as it can reasonably be established.

The Processor is not obliged to directly notify data subjects, unless legally required.

ARTICLE 13 – COOPERATION

The Processor cooperates reasonably with the Controller to enable it to comply with its GDPR obligations, particularly regarding:

  • impact assessments (DPIA);
  • requests from the supervisory authority;
  • compliance audits;
  • data breach notifications.

Any assistance exceeding the Processor's normal obligations or requiring specific development may be subject to additional billing based on a prior quote accepted by the Controller.

ARTICLE 14 – AUDITS

The Controller may verify compliance with this DPA.

This verification is primarily carried out by providing documents demonstrating the Processor's compliance, including:

  • internal policies;
  • procedures;
  • available certificates or attestations;
  • relevant technical documentation;
  • responses to a reasonable questionnaire.

An on-site audit may only be requested in the event of serious grounds reasonably suggesting a substantial breach of this DPA.

Any audit:

  • is conducted during business days;
  • is announced at least thirty (30) days in advance;
  • must not disrupt the normal operation of the Services;
  • is subject to a confidentiality undertaking.

The costs associated with the audit are borne by the Controller, unless a serious breach by the Processor is established.

The Processor may refuse any audit that is manifestly abusive, repetitive, or liable to compromise the security of its infrastructure or other clients' data.

ARTICLE 15 – RETURN AND DELETION OF DATA

At the end of the SaaS Agreement, the Controller has the reversibility period provided in the Agreement to export or recover the data it wishes to keep.

At the end of this period, the Processor proceeds with the deletion or anonymization of personal data, unless their retention is:

  • required by a legal obligation;
  • necessary for the establishment, exercise, or defense of legal claims;
  • made temporarily necessary by security backups.

Data in backups are automatically deleted at the end of the normal backup rotation cycle.

The Processor confirms, upon reasonable request, that the deletion or anonymization has been completed.

ARTICLE 16 – INTERNATIONAL TRANSFERS

The Processor favors data processing within the European Economic Area.

When an international transfer is necessary, it relies on one of the mechanisms provided by Chapter V of the GDPR, notably:

  • an adequacy decision;
  • Standard Contractual Clauses adopted by the European Commission;
  • any other safeguard recognized by the regulation.

The Processor ensures that transfers provide a level of protection substantially equivalent to that guaranteed within the European Union.

ARTICLE 17 – LIABILITY

Each Party is responsible for the obligations incumbent on it under the GDPR.

The Processor is liable for processing carried out in breach of its own obligations.

The Controller remains solely responsible for:

  • the lawfulness of the processing it decides upon;
  • the information provided to data subjects;
  • determining the purposes of the processing;
  • the applicable legal bases;
  • the compliance of the data it collects.

The Processor cannot be held liable for an unlawful instruction or a processing decided by the Controller.

ARTICLE 18 – PROOF OF COMPLIANCE

The Processor maintains reasonable documentation concerning the implemented security measures.

When relevant, this documentation may be communicated to the Controller, subject to information covered by trade secrets or liable to compromise infrastructure security.

ARTICLE 19 – AMENDMENT OF THE DPA

This DPA may be amended to:

  • reflect changes in regulations;
  • integrate new sub-processors;
  • adapt security measures;
  • reflect changes to the Services.

In the event of a material change, the Controller will be informed by appropriate means.

ARTICLE 20 – APPLICABLE LAW AND JURISDICTION

This DPA is governed by Belgian law.

Any dispute relating to its interpretation or execution falls under the competent courts designated in the SaaS Agreement, subject to mandatory rules of the GDPR.

APPENDIX I – DESCRIPTION OF PROCESSING

  • Controller The Client Agency.
  • Processor DS Solutions SRL.
  • Purpose Provision of the Mellio SaaS platform.
  • Nature of Processing
    • hosting;
    • storage;
    • consultation;
    • modification;
    • backup;
    • deletion;
    • securing;
    • technical transmission of data.
  • Purposes
    • management of loyalty programs;
    • management of merchants;
    • management of users;
    • issuance of Apple Wallet and Google Wallet cards;
    • technical operation of the platform.
  • Categories of Data Subjects Agency administrators; merchants; merchant employees; end-users of loyalty programs (to the extent registered by the Agency).
  • Categories of Data Identification data; contact details; loyalty histories; account information; technical data; connection logs.

APPENDIX II – TECHNICAL AND ORGANIZATIONAL MEASURES

DS Solutions implements, in particular:

  • hosting with Clever Cloud (France);
  • servers located in the European Union;
  • secure communications HTTPS/TLS 1.3;
  • AES-256 volume encryption (LUKS2);
  • daily backups;
  • role-based access control;
  • logging of administrator access;
  • regular security updates;
  • infrastructure monitoring;
  • limitation of administrator privileges;
  • internal incident management procedures.

These measures may evolve to reflect the state of the art.

APPENDIX III – AUTHORIZED SUB-PROCESSORS

As of the signature date of this DPA:

Sub-processor Purpose Primary Location
Clever Cloud Hosting France
Mollie Payment European Union
Brevo Transactional Emails European Union
Google reCAPTCHA Bot Protection Per Google infrastructure
Apple Wallet Wallet Card Management Per Apple infrastructure
Google Wallet Wallet Card Management Per Google infrastructure

This list may be updated in accordance with Article 9 of this DPA.

✨ Cookies

Cookie Policy

How we use cookies and similar technologies.

Version 1.0 — Last updated: July 21, 2026

1. PURPOSE

This Cookie Policy (the "Policy") explains how DS Solutions SRL, publisher of the Mellio platform, uses cookies and similar technologies when you visit its website and Services.

This Policy complements our Privacy Policy.

2. WHAT IS A COOKIE?

A cookie is a small text file stored on your terminal (computer, tablet, or smartphone) when visiting a website.

Cookies specifically allow:

  • ensuring the technical operation of a website;
  • maintaining a user session;
  • securing exchanges;
  • remembering certain preferences.

Cookies do not, by themselves, allow you to be personally identified.

3. COOKIES USED

As of the publication date of this Policy, the website and the Mellio platform exclusively use a technical session cookie.

Cookie Name Purpose Duration Type
__boost_session User session maintenance and proper technical operation of the site Browser session Strictly necessary cookie

This cookie is essential for the normal operation of the site and platform.

It specifically enables:

  • maintaining your browsing session;
  • ensuring continuity of exchanges between your browser and the server;
  • guaranteeing the proper technical operation of the Services.

This cookie is automatically deleted when you close your browser.

4. NO ADVERTISING COOKIES

DS Solutions currently uses no cookies intended for:

  • targeted advertising;
  • user profiling;
  • remarketing;
  • cross-site ad tracking.

5. NO ANALYTICS COOKIES

As of the publication date of this Policy, no audience measurement or statistical analysis cookies (Google Analytics, Matomo, Plausible, or equivalent) are used.

Should this situation change, this Policy will be updated and, where regulation requires, your prior consent will be collected.

6. LEGAL BASIS

The cookie used is strictly necessary for the operation of the site and platform.

In accordance with GDPR and applicable cookie rules, its use is based on our legitimate interest in ensuring the secure operation of the Services and does not require prior consent.

7. MANAGING COOKIES

Since the session cookie is essential to the operation of the site, disabling it via your browser settings may result in malfunctions or prevent access to certain features.

You can nevertheless delete this cookie at any time by clearing your browser's browsing data.

8. MODIFICATIONS TO THIS POLICY

DS Solutions may modify this Policy to take into account:

  • technical developments of the platform;
  • regulatory changes;
  • the potential addition of new cookies or similar technologies.

The applicable version is the one published on our website.

In the event of a material change, affected Clients will be notified by appropriate means.

9. CONTACT

For any questions regarding this Policy or the use of cookies, you can contact us:

DS Solutions SRL
Email: privacy@mellio-pro.fr
Website: https://www.mellio-pro.fr

RELATED DOCUMENTS

This Policy should be read in conjunction with:

  • the Mellio SaaS Subscription Agreement;
  • the Privacy Policy;
  • the Data Processing Agreement (DPA);
  • the Legal Notice.
✨ Legal Notice

Legal Notice

Mandatory company identification information.

Version 1.0 — Last updated: July 21, 2026

1. Website Publisher

Company name: DS Solutions SRL

Legal form: Private limited liability company (SRL)

Registered office: Rue Edmond Debatty 3, 6900 Marche-en-Famenne, Belgium

Company registration number (BCE/KBO): 0777.755.601

VAT number: BE 0777.755.601

Registry (RPM): Enterprise Court of Liège, Marche-en-Famenne division

Email: privacy@mellio-pro.fr

Website: https://www.mellio-pro.fr

2. Publication Director

The Managing Director of DS Solutions SRL

3. Hosting Provider

Host: Clever Cloud SAS

Registered office: 3 rue de l'Allier, 44000 Nantes, France

Website: https://www.clever-cloud.com

Servers are located within the European Union (France)

4. Intellectual Property

  • All site content (texts, images, logos, software, databases) is the exclusive property of DS Solutions SRL or its partners.
  • Any unauthorized reproduction, representation, or exploitation is strictly prohibited.

5. Liability

  • DS Solutions endeavors to ensure the accuracy of information, but cannot guarantee its completeness.
  • DS Solutions shall not be held liable for damages resulting from the use of the website.
  • DS Solutions reserves the right to modify content at any time.

6. Hyperlinks

  • The website may contain links to third-party sites.
  • DS Solutions does not control these sites and disclaims all liability.

7. Personal Data

8. Applicable Law

  • This legal notice is governed by Belgian law.
  • Any dispute falls under the jurisdiction of competent Belgian courts.

9. Contact

DS Solutions SRL

Rue Edmond Debatty 3, 6900 Marche-en-Famenne, Belgium

Email: privacy@mellio-pro.fr

Website: https://www.mellio-pro.fr