At Merge, data protection is top priority — and has been from the beginning.
While the GDPR only governs data protection in the EU, Merge recognizes that the obligations set by the GDPR are the world’s strongest set of data protection directives and as such, Merge chooses to implement these for all data transfers, regardless of geography.

Trusted to power integrations at top European companies



Merge puts in place a DPA (data processing agreement) with all customers, whereby Merge commits to processing data transfers in accordance with GDPR’s Standard Contractual Clauses. In addition, Merge offers customers control over where their data is stored.

If the customer selects our EU multi-tenant environment, data will only be stored in the EU in Stockholm
Receive your own servers and databases that are fully separated from other Merge customers
Meaningfully control and limit what data is shared
Set precise scopes to sync only what’s needed, respecting your customers’ data privacy
Redact data from third-party unmapped fields to hide sensitive data from logs and remote data
Seamlessly delete any data at any time
Exclude accessing specific individuals' personal data, while continuing to pull others
When a Linked Account is deleted, all data associated with that account is also deleted from Merge
Automatically keep detailed records of data processing activities and easily restrict access to Merge
Full transparency and accountability for all user actions in the Merge Dashboard
Compatible with Single Sign-On (SSO) with Security Assertion Markup Language (SAML), control access to the Merge dashboard and enforce organizational policies
Restrict what type of access Merge users have based on their assigned role
“Through Merge, we’ve been able to provide HRIS integrations that exceed our European-based customers’ security requirements.”