Legal
Privacy Policy
What personal data Meridian handles, why we handle it, how long we keep it, and the choices you have. Written for the data protection officer who has to review it.
Last updated:
Meridian Systems, Inc.
Template for evaluation; not legal advice.
On this page
Who we are
Meridian Systems, Inc. ("Meridian", "we", "us") is a Delaware corporation with offices in New York, London, and Dublin. We build narrow, governed AI agents for HR and finance operations.
This policy explains what personal data we handle, why we handle it, how long we keep it, and the choices you have. It covers this website, the Meridian product, and the events and correspondence we run alongside them.
Questions about this policy go to privacy@meridian.example. Our Data Protection Officer can be reached at the same address.
The two roles we play
Data protection law distinguishes between a controller, who decides why and how personal data is processed, and a processor, who processes it on a controller's documented instructions.
We are a controller for the data of website visitors, prospective customers, event attendees, job applicants, and the individual administrators who hold Meridian accounts. We decide what to collect and why, and this policy governs that data.
We are a processor for the HR and finance data a customer loads into or connects to their Meridian workspace. Employee records, payroll files, invoices, contracts, and support cases belong to the customer. They decide the purpose; we act on their instructions under the Data Processing Addendum. If you are an employee of a Meridian customer and want to exercise a right over that data, contact your employer. We will forward any request we receive directly to them.
Data we process as a controller
| Category | Examples | Source |
|---|---|---|
| Contact data | Name, work email, company, job title, country | You, through forms on this site |
| Account data | User ID, workspace membership, role, authentication events | Created when an account is provisioned |
| Correspondence | Demo requests, support tickets, sales and partner threads | You |
| Applicant data | Role applied for, résumé or portfolio link, interview notes | You, through the contact form |
| Usage data | Pages viewed, referrer, aggregate session duration, coarse region | Product analytics on this site |
| Technical data | IP address, user agent, request timestamps, security event logs | Automatically, when you use the site or product |
| Billing data | Company billing contact, plan, invoices, tax identifiers | You and our payment processor |
We do not buy contact lists, we do not use tracking pixels from advertising networks, and we do not run behavioural advertising.
Lawful bases
| Purpose | Data used | Lawful basis |
|---|---|---|
| Answering a demo, sales, or support request | Contact data, correspondence | Steps at your request before a contract (Art. 6(1)(b)) |
| Providing and securing the product | Account data, technical data | Performance of a contract (Art. 6(1)(b)) |
| Billing, tax, and statutory records | Billing data | Legal obligation (Art. 6(1)(c)) |
| Product improvement and aggregate analytics | Usage data | Legitimate interests (Art. 6(1)(f)) |
| Recruiting | Applicant data | Steps at your request before a contract (Art. 6(1)(b)) |
| Newsletter and product announcements | Contact data | Consent (Art. 6(1)(a)), withdrawable at any time |
| Detecting abuse, fraud, and security incidents | Technical data, account data | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that interest against your rights and recorded the outcome. You can ask us for a summary of that assessment.
Cookies and analytics
The site sets one strictly necessary cookie to keep your session and one to remember whether you dismissed the announcement bar. Neither is used for advertising.
Product analytics are first-party and aggregate. We record page paths, referrers, and coarse region derived from the IP address, then discard the IP address. We do not build cross-site profiles and we honour the Global Privacy Control signal.
Retention
| Data | Retention |
|---|---|
| Contact and correspondence | 24 months after the last interaction |
| Account data | For the life of the account, then 30 days |
| Applicant data | 12 months after a decision, unless you ask us to delete it sooner |
| Usage data | 14 months, in aggregate form |
| Security and audit logs | 12 months, then deleted |
| Billing records | 7 years, to meet tax and accounting obligations |
Customer data processed under the DPA follows the retention period the customer configures in their workspace, which can be set to zero-day retention for agent inputs and outputs.
Subprocessors
We use a small number of vendors to run the service. Each is bound by a written contract with confidentiality, security, and audit terms at least as protective as our own commitments. The current list, by category and region, is on the subprocessors page. Customers can subscribe there to receive 30 days' notice before a new subprocessor is added.
Your rights
Subject to local law, you can ask us to:
- confirm whether we process personal data about you, and give you a copy;
- correct data that is inaccurate or incomplete;
- delete data we no longer have a basis to keep;
- restrict or object to processing based on legitimate interests;
- port data you gave us to another provider in a structured, machine-readable format;
- withdraw consent, which does not affect processing that already happened.
Write to privacy@meridian.example. We verify the request, respond within 30 days, and tell you if we need a further 60 days for a complex request. We do not charge for the first request in any 12-month period.
Residents of California may exercise the equivalent rights under the CCPA as amended. We do not sell or share personal information as those terms are defined there, and we have not done so in the preceding 12 months. Residents of the EEA, the UK, and Switzerland may lodge a complaint with their supervisory authority; our lead authority in the EU is the Data Protection Commission in Ireland.
International transfers
Meridian operates production regions in the United States (US-East) and the European Union (EU-West). Customers choose their region at provisioning, and customer data stays in it.
Corporate data we hold as a controller may be transferred to the United States for support and administration. Those transfers rely on the European Commission's Standard Contractual Clauses (Module Two and, where relevant, Module Three), the UK International Data Transfer Addendum, and the Swiss addendum recognised by the Federal Data Protection and Information Commissioner. We complete a transfer impact assessment for each recipient, and we publish a summary of the supplementary measures on request.
Security
We hold SOC 2 Type II and ISO 27001 certifications. Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production follows least privilege, requires hardware-backed multi-factor authentication, and is logged. Agent actions are written to an immutable audit trail that customers can export.
Customer data is never used to train models, ours or a provider's. A full description of the controls is on the security page, and the technical and organisational measures are set out in Annex II of the DPA.
If you believe you have found a vulnerability, write to security@meridian.example. We acknowledge reports within one business day.
Changes to this policy
We update this policy when our processing changes. Material changes are announced by email to account administrators at least 30 days before they take effect, and the date at the top of this page always reflects the current version. Superseded versions are available on request.
Contact
Meridian Systems, Inc. Attn: Privacy privacy@meridian.example
For product questions, use the contact form. For a signed copy of the DPA or the SOC 2 report, ask your account team.