Legal
Subprocessors
The categories of vendor behind the service, what each one is used for, and where it processes data. Thirty days' notice before anything on this list changes.
Last updated:
Meridian Systems, Inc.
Template for evaluation; not legal advice.
On this page
How we use subprocessors
Meridian runs on a deliberately small set of vendors. Each one is engaged under a written contract with confidentiality, security, and audit terms at least as protective as the commitments in our Data Processing Addendum, and we remain fully responsible to customers for their performance.
Before a vendor is added, it goes through a security review covering its certifications, its own subprocessors, where it processes data, its breach history, and its deletion commitments. The review is repeated annually and whenever the scope of processing changes.
Current subprocessors
Categories are listed rather than vendor names because the specific entity differs by region and by the model a customer selects. Customers under contract receive the named list, with entity, registered address, and transfer mechanism, on request from their account team or at privacy@meridian.example.
| Category | Purpose | Processing location |
|---|---|---|
| Cloud infrastructure (US) | Compute, storage, and networking for the US-East production region | United States |
| Cloud infrastructure (EU) | Compute, storage, and networking for the EU-West production region | Ireland and Germany |
| Model providers | Inference for agent reasoning and drafting. Customer-selected: each workspace chooses which providers are enabled, and can restrict inference to models hosted inside its own region | Customer-selected, within the workspace region |
| Email delivery | Transactional email: approval requests, alerts, digests, and account notifications | United States and European Union |
| Product analytics | Aggregate usage measurement for the website and the product console | European Union |
Model providers are engaged on zero-retention terms and are contractually prohibited from training on customer data. A workspace can be configured to allow no external providers at all, in which case inference runs only on models Meridian hosts inside the selected region.
What subprocessors do not receive
Analytics and email delivery subprocessors receive account metadata, not HR or finance records. No subprocessor receives the contents of a workspace except the cloud infrastructure provider for the selected region and the model providers the customer has enabled.
Change notice
We give at least 30 days' notice before adding or replacing a subprocessor. Notice is published on this page and sent by email to the addresses each customer has subscribed. To subscribe, or to change the addresses, write to privacy@meridian.example with your workspace name.
Customers may object on reasonable data protection grounds within the notice period. We will work with you to find an alternative; if none is available within 30 days, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees, as set out in Section 6 of the DPA.
Affiliates
Meridian Systems, Inc. processes data with the support of its wholly owned subsidiaries in the United Kingdom and Ireland. Those entities are bound by an intragroup agreement incorporating the Standard Contractual Clauses and the measures in Annex II of the DPA. They are not listed as third-party subprocessors.
Questions
Write to privacy@meridian.example for the named list, a signed DPA, or a copy of the current SOC 2 Type II report. Details of the controls behind these arrangements are on the security page.