Revenue Contract Agent is in early access.
Meridian

Legal

Privacy Policy

What personal data Meridian handles, why we handle it, how long we keep it, and the choices you have. Written for the data protection officer who has to review it.

Last updated:

Meridian Systems, Inc.

Template for evaluation; not legal advice.

On this page

Who we are

Meridian Systems, Inc. ("Meridian", "we", "us") is a Delaware corporation with offices in New York, London, and Dublin. We build narrow, governed AI agents for HR and finance operations.

This policy explains what personal data we handle, why we handle it, how long we keep it, and the choices you have. It covers this website, the Meridian product, and the events and correspondence we run alongside them.

Questions about this policy go to privacy@meridian.example. Our Data Protection Officer can be reached at the same address.

The two roles we play

Data protection law distinguishes between a controller, who decides why and how personal data is processed, and a processor, who processes it on a controller's documented instructions.

We are a controller for the data of website visitors, prospective customers, event attendees, job applicants, and the individual administrators who hold Meridian accounts. We decide what to collect and why, and this policy governs that data.

We are a processor for the HR and finance data a customer loads into or connects to their Meridian workspace. Employee records, payroll files, invoices, contracts, and support cases belong to the customer. They decide the purpose; we act on their instructions under the Data Processing Addendum. If you are an employee of a Meridian customer and want to exercise a right over that data, contact your employer. We will forward any request we receive directly to them.

Data we process as a controller

CategoryExamplesSource
Contact dataName, work email, company, job title, countryYou, through forms on this site
Account dataUser ID, workspace membership, role, authentication eventsCreated when an account is provisioned
CorrespondenceDemo requests, support tickets, sales and partner threadsYou
Applicant dataRole applied for, résumé or portfolio link, interview notesYou, through the contact form
Usage dataPages viewed, referrer, aggregate session duration, coarse regionProduct analytics on this site
Technical dataIP address, user agent, request timestamps, security event logsAutomatically, when you use the site or product
Billing dataCompany billing contact, plan, invoices, tax identifiersYou and our payment processor

We do not buy contact lists, we do not use tracking pixels from advertising networks, and we do not run behavioural advertising.

Lawful bases

PurposeData usedLawful basis
Answering a demo, sales, or support requestContact data, correspondenceSteps at your request before a contract (Art. 6(1)(b))
Providing and securing the productAccount data, technical dataPerformance of a contract (Art. 6(1)(b))
Billing, tax, and statutory recordsBilling dataLegal obligation (Art. 6(1)(c))
Product improvement and aggregate analyticsUsage dataLegitimate interests (Art. 6(1)(f))
RecruitingApplicant dataSteps at your request before a contract (Art. 6(1)(b))
Newsletter and product announcementsContact dataConsent (Art. 6(1)(a)), withdrawable at any time
Detecting abuse, fraud, and security incidentsTechnical data, account dataLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that interest against your rights and recorded the outcome. You can ask us for a summary of that assessment.

Cookies and analytics

The site sets one strictly necessary cookie to keep your session and one to remember whether you dismissed the announcement bar. Neither is used for advertising.

Product analytics are first-party and aggregate. We record page paths, referrers, and coarse region derived from the IP address, then discard the IP address. We do not build cross-site profiles and we honour the Global Privacy Control signal.

Retention

DataRetention
Contact and correspondence24 months after the last interaction
Account dataFor the life of the account, then 30 days
Applicant data12 months after a decision, unless you ask us to delete it sooner
Usage data14 months, in aggregate form
Security and audit logs12 months, then deleted
Billing records7 years, to meet tax and accounting obligations

Customer data processed under the DPA follows the retention period the customer configures in their workspace, which can be set to zero-day retention for agent inputs and outputs.

Subprocessors

We use a small number of vendors to run the service. Each is bound by a written contract with confidentiality, security, and audit terms at least as protective as our own commitments. The current list, by category and region, is on the subprocessors page. Customers can subscribe there to receive 30 days' notice before a new subprocessor is added.

Your rights

Subject to local law, you can ask us to:

  • confirm whether we process personal data about you, and give you a copy;
  • correct data that is inaccurate or incomplete;
  • delete data we no longer have a basis to keep;
  • restrict or object to processing based on legitimate interests;
  • port data you gave us to another provider in a structured, machine-readable format;
  • withdraw consent, which does not affect processing that already happened.

Write to privacy@meridian.example. We verify the request, respond within 30 days, and tell you if we need a further 60 days for a complex request. We do not charge for the first request in any 12-month period.

Residents of California may exercise the equivalent rights under the CCPA as amended. We do not sell or share personal information as those terms are defined there, and we have not done so in the preceding 12 months. Residents of the EEA, the UK, and Switzerland may lodge a complaint with their supervisory authority; our lead authority in the EU is the Data Protection Commission in Ireland.

International transfers

Meridian operates production regions in the United States (US-East) and the European Union (EU-West). Customers choose their region at provisioning, and customer data stays in it.

Corporate data we hold as a controller may be transferred to the United States for support and administration. Those transfers rely on the European Commission's Standard Contractual Clauses (Module Two and, where relevant, Module Three), the UK International Data Transfer Addendum, and the Swiss addendum recognised by the Federal Data Protection and Information Commissioner. We complete a transfer impact assessment for each recipient, and we publish a summary of the supplementary measures on request.

Security

We hold SOC 2 Type II and ISO 27001 certifications. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production follows least privilege, requires hardware-backed multi-factor authentication, and is logged. Agent actions are written to an immutable audit trail that customers can export.

Customer data is never used to train models, ours or a provider's. A full description of the controls is on the security page, and the technical and organisational measures are set out in Annex II of the DPA.

If you believe you have found a vulnerability, write to security@meridian.example. We acknowledge reports within one business day.

Changes to this policy

We update this policy when our processing changes. Material changes are announced by email to account administrators at least 30 days before they take effect, and the date at the top of this page always reflects the current version. Superseded versions are available on request.

Contact

Meridian Systems, Inc. Attn: Privacy privacy@meridian.example

For product questions, use the contact form. For a signed copy of the DPA or the SOC 2 report, ask your account team.