Scope and order of precedence#
This Addendum applies only when MEGA acts as a processor or service provider for Customer Personal Data submitted to the hosted service. It does not apply to information MEGA processes as an independent controller, which is covered by the Privacy Policy. If this Addendum conflicts with the Terms of Service on protection or processing of Customer Personal Data, this Addendum controls for that conflict.
Definitions and parties#
"Customer" means the account or organization that accepted the agreement. "MEGA" means the MEGA service and the team responsible for operating it. "Customer Personal Data" means personal data MEGA processes on Customer's behalf through the service. "Data Protection Law" includes applicable privacy and data-protection law, including the EU General Data Protection Regulation where it applies. "Controller," "processor," "data subject," and "personal data" have the meanings assigned by applicable Data Protection Law.
Roles and documented instructions#
Customer is the controller or a processor authorized by the relevant controller. MEGA is Customer's processor or subprocessor. Customer instructs MEGA to process Customer Personal Data to provide, secure, support, and improve the contracted service; prevent fraud and abuse; comply with law; and carry out settings, API calls, support requests, and other documented instructions submitted through authorized use of MEGA.
MEGA will process Customer Personal Data only on those documented instructions unless law requires otherwise. If legally permitted, MEGA will notify Customer before required processing. MEGA will promptly inform Customer if it reasonably believes an instruction violates applicable Data Protection Law.
Processing details#
The subject matter is hosting and operating repositories, datasets, models, Spaces, MCPs, storage, jobs, inference, organization controls, and related support. Processing lasts for the agreement term and the limited deletion, backup, security, or legal-retention period described in this Addendum and the Privacy Policy.
- Processing operations: collecting, transmitting, storing, organizing, retrieving, displaying according to access settings, analyzing for requested functionality, securing, backing up, deleting, and returning data.
- Purposes: providing and protecting the features Customer chooses.
- Data categories: identifiers, contact details, account and organization attributes, repository or dataset content, prompts and inputs, configuration, usage and audit events, support communications, and other personal data Customer elects to submit.
- Data subjects: Customer's users, personnel, contractors, collaborators, end users, repository contributors, dataset subjects, support contacts, or other people represented in Customer content.
Customer obligations#
Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its processing; for providing required notices and obtaining required consents; for ensuring its instructions comply with law; for configuring visibility and access; and for avoiding unnecessary or prohibited personal data.
Customer must not submit regulated or sensitive data that the service is not designed or expressly agreed to process. Customer will respond to data-subject and authority requests for which it is the controller and will use available MEGA controls before requesting additional assistance.
Confidentiality and security#
MEGA will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and receive access only as needed for their responsibilities.
Taking account of the nature, scope, context, purposes, and risks of processing, MEGA maintains appropriate technical and organizational measures. These include encrypted transport, identity and access controls, scoped authorization, credential and secret handling, tenant or repository isolation controls, audit and security records, rate limiting, vulnerability and incident response processes, and backup or recovery measures appropriate to the service.
Customer is responsible for secure endpoint and credential management, least-privilege configuration, lawful content, appropriate backups or export, and evaluating whether MEGA's documented measures meet Customer's requirements.
Subprocessors#
Customer gives MEGA general authorization to engage subprocessors needed to provide the service. Core cloud processing uses Cloudflare and is subject to Cloudflare's Data Processing Addendum. Other subprocessors may support identity, storage, compute, inference, communication, or a feature Customer selects. Payment and optional public-site analytics providers generally process controller data rather than Customer Personal Data and are described in the Privacy Policy.
MEGA will impose data-protection obligations appropriate to the services a subprocessor performs and remains responsible for its subprocessors to the extent required by this Addendum and applicable law. MEGA will provide reasonable notice of a material new subprocessor where practicable. Customer may object on reasonable data-protection grounds; the parties will work in good faith on a reasonable alternative, and if none is available, either party may discontinue the affected feature.
International transfers#
Customer authorizes processing wherever MEGA or an authorized subprocessor operates, subject to applicable transfer requirements. For restricted transfers, the parties will use a valid mechanism such as an adequacy decision or the European Commission's Standard Contractual Clauses, including the appropriate controller-to-processor or processor-to-processor module and supplementary measures where required. Customer-selected provider regions or integrations can determine the destination of a particular request.
Data-subject requests#
Taking account of the nature of processing, MEGA will provide reasonable assistance for Customer to respond to requests to access, correct, delete, restrict, object to, or port Customer Personal Data where required by law. If MEGA receives a request concerning Customer Personal Data, MEGA will direct the requester to Customer or notify Customer when legally permitted and will not respond on Customer's behalf unless authorized or legally required.
Customer should first use available account, repository, API, export, visibility, and deletion controls. Additional assistance may be subject to reasonable fees when law permits and when the request requires substantial work beyond ordinary service functionality.
Incidents and compliance assistance#
MEGA will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the breach, affected data or people, likely consequences, mitigation, and a contact point. MEGA's notice is not an admission of fault.
Taking account of the processing and information available to MEGA, MEGA will provide reasonable assistance with Customer's security, breach notification, data-protection impact assessment, and regulator-consultation obligations. Customer remains responsible for deciding whether and when it must notify a regulator or data subject.
Return, deletion, and retention#
During the agreement term, Customer may retrieve Customer Personal Data through available service, API, Git, or export functions. Customer should complete any needed export before deleting content, closing an account, or ending the affected service.
After termination or a valid deletion instruction, MEGA will delete or de-identify Customer Personal Data within a commercially reasonable period unless law requires retention or Customer requests return where available. Limited copies may remain until overwritten in protected backups, caches, security or fraud records, dispute preservation, or legal holds. Retained data remains protected and is not used for unrelated purposes.
Information and audits#
MEGA will make information reasonably necessary to demonstrate compliance with this Addendum available to Customer. Where that information is insufficient and applicable law requires an audit, Customer may request one audit in a 12-month period, or more often after a material incident or regulator requirement.
Audits require reasonable advance notice, must be limited to relevant systems and processing, must protect other customers and confidential information, and must avoid unreasonable disruption. MEGA may satisfy a request with current third-party reports, certifications, questionnaires, or a qualified independent auditor. Customer bears reasonable audit costs unless the audit identifies a material breach by MEGA.
Liability, term, and changes#
The liability provisions in the Terms of Service or applicable signed agreement apply to this Addendum, except to the extent Data Protection Law prohibits a limitation. Each party remains responsible for damage caused by its own violation to the extent required by law.
This Addendum begins when its scope first applies and continues while MEGA processes Customer Personal Data. Confidentiality, protection, deletion, audit, and liability obligations survive only as long as needed to fulfill their purpose.
MEGA may update this Addendum to reflect changes in law, subprocessors, or processing. Material changes will receive reasonable notice through the service or account contact information when practicable. Use the Contact control in the site footer for DPA questions, audit requests, or data-protection notices.

