Mercury Social Media Copilot

Privacy Notice

This notice explains how Mercury International GmbH processes personal data in Mercury Social Media Copilot (the “Copilot”), an access-controlled workspace for product data, content creation, review, publishing and performance analysis. It supplements, but does not replace, privacy information supplied by connected platforms.

1. Controller and contact

Mercury International GmbH
Sinserstrasse 65
6330 Cham
Switzerland
UID: CHE-277.689.874
Commercial register number: CH-170.4.024.585-6

Submit a privacy request through Mercury’s contact form and select “Privacy request”, or write to the postal address above. Do not send passwords, access tokens or sensitive documents through the form. The form is a separate website service covered by the Mercury website Privacy Notice.

2. Scope and sources

This notice covers data relating to authorized users and other identifiable people whose information is included in products, media, rights records, connected business accounts, finance documents or published content. We receive data directly from authorized users, Mercury’s business systems and files, connected Shopify, Meta, TikTok, Google, Google Ads and Bexio accounts, the relevant platforms’ APIs, and service-generated security, backup and audit records.

3. Data we process

The current Shopify synchronization does not request customer, order or payment data.

Login credentials and fields marked as required are necessary to use the relevant function. Optional editorial, analytics and rights fields are voluntary, but omitting them may limit review, traceability or publishing readiness.

4. Why we process data

We process data to authenticate and protect the workspace; synchronize authorized product and account data; create editable content and media; support human review and rights checks; submit explicitly approved content to connected channels; maintain schedules, audit evidence and deletion receipts; measure content performance; troubleshoot services; and meet legal, regulatory and contractual obligations.

Under Swiss data-protection law, processing follows the principles of lawfulness, proportionality, transparency, purpose limitation and security. Where the EU or UK GDPR applies, the legal basis depends on the context and may be performance of a contract or pre-contractual steps, compliance with a legal obligation, or Mercury’s legitimate interests in secure and accountable business communications and channel operations. Where a specific activity requires consent, we request it separately; consent can be withdrawn prospectively.

5. AI assistance and human control

Copilot functions may send the data described above to Google AI services, OpenAI or Higgsfield to suggest text, campaign plans, design settings, images or videos. The configured router prefers Google AI for supported text tasks and may use OpenAI as a fallback or for supported media functions; Higgsfield may be used for connected image and video workflows. Generative outputs can be incomplete, inaccurate or alter visual details. They are proposals, not legal, rights, safety or platform-compliance determinations. Authorized people must compare media with the source, verify claims, select required disclosures and give final approval before publication.

OpenAI states that API content is not used to train its models by default. The Copilot sends store: false for Responses API text requests. OpenAI may still retain limited abuse-monitoring data for up to 30 days unless stricter account controls apply. Video jobs can remain available for download for up to 48 hours and are subject to the provider’s documented abuse-monitoring retention. Do not enter secrets or unnecessary sensitive personal data in an AI field.

The Copilot does not use AI to make decisions that produce legal or similarly significant effects about individuals without meaningful human involvement.

6. Recipients and service providers

Access is limited to authorized Mercury personnel and service providers that need the data for the stated purposes. Depending on the function used, recipients include:

Mercury does not sell Copilot personal data or use it for third-party behavioral advertising. A connected platform processes data under its own terms and privacy information once content or an authorization request is sent to it.

7. International transfers

Processing takes place in Switzerland and the EEA, including configured services in Germany or Ireland, and may also take place in the United States and other countries in which a provider or its subprocessors operate. For each restricted transfer, Mercury relies on the safeguard applicable to the provider and service, which may include an adequacy decision or recognized standard contractual clauses with any required Swiss or EU adaptations and supplementary technical and organizational measures. You may request information about the relevant destination country and safeguard.

8. Publishing and external media

When an authorized user submits content for publication, the selected caption, media and settings are sent to the chosen platform and may become public according to the selected audience. Channel-ready derivatives may be made available through a public HTTPS address so a platform can retrieve them; uploaded source originals are restricted to authenticated Copilot users. If a user registers media hosted on an external website, opening that media can disclose normal connection data, such as the user’s IP address, to that host.

9. Cookies and similar technology

The Copilot sets one strictly necessary first-party session cookie named mercury_session. It contains a random session identifier, is not accessible to browser scripts, uses SameSite=Strict, is marked Secure in production and expires after eight hours. Failed login attempts are temporarily associated with an IP address for up to 15 minutes to limit abuse. The Copilot does not set optional analytics or advertising cookies; infrastructure providers may apply strictly necessary security mechanisms.

10. Retention

Mercury reviews retention using purpose, sensitivity, contractual commitments, platform requirements and legal limitation or record-keeping periods. Data is deleted or anonymized when it is no longer required, subject to technically necessary backup cycles and lawful retention exceptions. A verified privacy request can trigger an earlier case-specific review.

11. Security

Mercury applies tenant- and role-based access, server-side credential handling, encrypted transport, AES-256-GCM encryption for provider credentials in active application state, login throttling, review and publishing controls, audit records, restricted source-media access and browser security policies. Operational database backups are encrypted and access-controlled; credentials and secret values are excluded from repository backups. Encryption keys are held separately as deployment secrets. Historical infrastructure backups expire under the applicable retention and deletion cycle. No system can be guaranteed completely secure. Authorized users must keep credentials confidential, avoid entering unnecessary personal or sensitive data, and report suspected misuse promptly.

12. Your rights

Subject to applicable law and any lawful exceptions, you may request information and access, correction, deletion or destruction, restriction, data portability, or object to processing. You may also withdraw consent where processing relies on it. We may request proportionate information to verify identity and authority. We generally respond within 30 days, or inform you if more time is lawfully required.

Submit a request through Mercury’s contact form by selecting “Privacy request”. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, your competent EU or UK supervisory authority.

13. Changes

We update this notice when the Copilot, its providers or legal requirements materially change. The date above identifies the current version. Material changes are communicated through an appropriate internal channel.