Revenue Contract Agent is in early access.
Meridian

Legal

Data Processing Addendum

The processing terms that sit alongside the Terms of Service, with the security annex and the Standard Contractual Clauses that cover transfers out of the EEA.

Last updated:

Meridian Systems, Inc.

Template for evaluation; not legal advice.

On this page

1. Scope

This Data Processing Addendum ("DPA") forms part of the agreement between Meridian Systems, Inc. ("Processor") and the customer named in the order form ("Controller") for the Meridian platform. It applies wherever Processor handles personal data on Controller's behalf.

Where Controller is itself acting as a processor for a third party, this DPA applies on a back-to-back basis and Processor acts as a subprocessor. In case of conflict, this DPA prevails over the Terms of Service in respect of the processing of personal data.

2. Definitions

Applicable Data Protection Law means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended, each to the extent it applies.

Customer Personal Data means personal data contained in Customer Data that Processor processes under the Agreement.

Data Subject, Personal Data, Processing, Controller, Processor, and Supervisory Authority have the meanings given in the GDPR.

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.

SCCs means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914.

Subprocessor means a third party engaged by Processor to process Customer Personal Data.

3. Roles and instructions

Controller is the controller and Processor is the processor of Customer Personal Data. Controller is responsible for the lawfulness of the data it provides and of the instructions it gives.

Processor will process Customer Personal Data only on Controller's documented instructions, which comprise the Agreement, this DPA, the configuration Controller sets in the workspace, and any further written instruction the parties agree. Processor will tell Controller if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend the affected processing until the instruction is withdrawn or amended.

Where Processor is required by law to process beyond those instructions, it will inform Controller before processing, unless that law prohibits the notice on important grounds of public interest.

Processor will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Agreement, and will not combine it with personal data from another source except as instructed. Processor does not use Customer Personal Data to train, fine-tune, or evaluate models, and imposes the same restriction on every model provider it engages.

4. Confidentiality of personnel

Processor grants access to Customer Personal Data only to personnel who need it to deliver the Service. Those personnel are bound by written confidentiality obligations that survive their engagement, receive data protection and security training on joining and annually, and are subject to background checks where local law permits.

5. Security measures

Processor will implement and maintain the technical and organisational measures set out in Annex II, taking account of the state of the art, the cost of implementation, and the risks to data subjects. Processor may update those measures, provided the level of protection is not reduced.

6. Subprocessors

Controller gives general authorisation for Processor to engage Subprocessors. The current list, by category and region, is published at meridian.example/legal/subprocessors.

Processor will give at least 30 days' notice before adding or replacing a Subprocessor, by email to the addresses Controller has subscribed and by updating that page. Controller may object on reasonable data protection grounds within the notice period. The parties will work in good faith to find an alternative; if none is available within 30 days, Controller may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

Processor imposes on each Subprocessor, by written contract, data protection obligations at least as protective as those in this DPA, and remains fully liable to Controller for the Subprocessor's performance.

7. Data subject requests

Processor will not respond to a request from a data subject relating to Customer Personal Data except on Controller's instruction or as required by law. If Processor receives such a request directly, it will inform Controller without undue delay and forward the request.

Taking account of the nature of the processing, Processor will assist Controller with appropriate technical and organisational measures, insofar as possible, in meeting its obligations to respond to requests for access, rectification, erasure, restriction, portability, and objection. The product provides self-service export and deletion for records in a workspace; assistance beyond that is provided at no additional charge for requests within normal volumes.

8. Personal data breach

Processor will notify Controller without undue delay and in any case within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the full picture is not yet available, Processor will provide information in phases.

Processor will assist Controller with its obligations under Articles 32 to 36 GDPR, including notifications to supervisory authorities and data subjects, and will not make a public statement identifying Controller without Controller's consent, unless legally required.

9. Audit rights

Processor will make available to Controller all information reasonably necessary to demonstrate compliance with this DPA. Controller's audit right is satisfied in the first instance by Processor's current SOC 2 Type II report and ISO 27001 certificate, and by its completed standard security questionnaire, each provided under confidentiality within 10 business days of a request.

Where those materials are not sufficient to demonstrate compliance, Controller or an independent auditor it appoints, who is not a competitor of Processor, may audit Processor's processing. Audits take place on at least 30 days' written notice, during business hours, no more than once in any 12-month period unless a Personal Data Breach or a supervisory authority requires otherwise, and subject to confidentiality. Each party bears its own costs; Controller reimburses Processor's reasonable costs for audits beyond the annual allowance.

10. International transfers

Controller selects a production region, US-East or EU-West, and Customer Personal Data is stored and processed in that region.

Where Processor transfers Customer Personal Data out of the EEA, the UK, or Switzerland to a country without an adequacy decision, the SCCs are incorporated into this DPA and apply: Module Two where Controller is a controller, and Module Three where Controller is itself a processor. Clause 7 (docking) applies; Clause 9 uses option 2 with the notice period in Section 6; Clause 11 does not use the optional independent dispute body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland. Annex I and Annex II of this DPA populate the corresponding SCC annexes. The UK International Data Transfer Addendum and the Swiss amendments apply where relevant, with the UK Information Commissioner and the Swiss Federal Data Protection and Information Commissioner as the competent authorities.

Processor will notify Controller if it becomes subject to a legally binding request for disclosure by a public authority, unless prohibited, and will challenge requests that appear unlawful or overbroad.

11. Deletion and return

Controller may export Customer Personal Data at any time during the term through the product or the API.

On termination or expiry, Processor will, at Controller's election, return or delete Customer Personal Data. Absent an election, Processor deletes it. Deletion of production data completes within 30 days of the end of the term; encrypted backups age out and are deleted within a further 35 days. Processor certifies deletion in writing on request.

Processor may retain Customer Personal Data to the extent required by law, in which case it continues to protect it under this DPA and processes it only for the purpose that requires retention.

Annex I — Description of the processing

ItemDetail
Data exporterThe customer named in the order form, acting as controller
Data importerMeridian Systems, Inc., acting as processor
Subject matterProvision of governed AI agents for HR and finance operations
DurationThe subscription term, plus the deletion periods in Section 11
Nature and purposeStorage, retrieval, analysis, generation of drafts and recommendations, routing for human approval, and logging
Categories of data subjectController's employees, contractors, candidates, customers, suppliers, and their representatives
Categories of personal dataIdentification and contact data, employment and payroll data, compensation and benefits data, case and correspondence content, financial transaction and invoice data, contract terms, system identifiers and logs
Special category dataOnly where Controller chooses to load it; Processor applies the measures in Annex II and does not process it for any other purpose
FrequencyContinuous, for the duration of the term
Competent supervisory authorityThe Data Protection Commission, Ireland

Annex II — Technical and organisational measures

Control areaMeasures
EncryptionTLS 1.3 in transit; AES-256 at rest; customer-managed keys available on Enterprise
Access controlLeast privilege, role-based access, hardware-backed MFA for all production access, quarterly access reviews, automated deprovisioning within 24 hours of a leaver event
Tenant isolationLogical separation per workspace, enforced at the Gateway; region pinning for storage and compute
Human approvalConsequential agent actions require an approval from a named person before they take effect; the approver is recorded
Logging and auditImmutable audit trail of inputs, model version, tool calls, approver, and outcome; export to the customer's SIEM; 12-month retention by default
Model governanceNo training on customer data; model providers contractually bound to zero retention; model versions pinned and recorded per run
Network securitySegmented VPCs, no public database endpoints, WAF and rate limiting, DDoS protection at the edge
Vulnerability managementContinuous dependency scanning, critical patches within 7 days, annual third-party penetration test with a summary available to customers
Secure developmentPeer review on every change, static analysis and secret scanning in CI, evaluation gates before an agent release, staged rollout with rollback
Business continuityPoint-in-time recovery for 35 days, RPO 15 minutes, RTO 4 hours, restore tested twice a year
Physical securityProcessing in accredited data centres operated by the cloud infrastructure subprocessors listed on the subprocessors page; no Meridian-operated data centres
Incident response24/7 on-call, documented runbooks, breach notification within 48 hours, post-incident review published to affected customers
PersonnelBackground checks where lawful, confidentiality agreements, annual security and privacy training
CertificationsSOC 2 Type II, ISO 27001; reports available under NDA

Annex III — Subprocessors

The authorised Subprocessors, by category, purpose, and location, are listed at meridian.example/legal/subprocessors, which forms part of this DPA and is updated in line with Section 6.