Privacy notice
Privacy Policy
This notice explains Meridian's own processing of visitor, account, communication, security, and sandbox activity data.
1. Scope and controller
This Policy applies to meridiandataexchange.com and the Meridian sandbox. Milos Topic, an individual operator in Serbia trading as Meridian Data Exchange, is the controller for operating the website, accounts, communications, security, and business relationship. Correspondence address: Kosmajska 002, 11036 Belgrade, Serbia. Contact: office@meridiandataexchange.com.
Where an organizational customer controls real data and instructs Meridian to process it, that customer is the controller and Meridian acts as processor under the DPA and order form. Paddle separately determines processing required for transactions where it acts as merchant of record.
2. Data we process
- Account data: provider user ID, verified email signal, display name, role, country, language, eligibility attestation, and security state.
- Organization data: application details, role, authority, and synthetic verification records.
- Usage and evidence: pages and features used, consent decisions, workflow actions, audit events, request identifiers, and timestamps.
- Technical and security data: IP-derived rate-limit fingerprint, request metadata, device/browser information made available by HTTP, alerts, and incident evidence.
- Communications: messages sent to office@, notification preferences, encrypted email contact and delivery status.
- Billing metadata, when enabled: Paddle customer, subscription and transaction IDs, status, currency, amount, price ID, and event time. Meridian does not receive or store full card details.
The sandbox must contain synthetic content only. Do not submit real personal or special-category data in offer, connector, delivery, or governance demonstrations.
3. Purposes and legal bases
- Provide requested website, account, sandbox, and support functions: performance of a contract or steps requested before a contract.
- Secure, monitor, debug, prevent abuse, and preserve audit evidence: legitimate interests in operating a safe and accountable service and, where applicable, legal obligations.
- Send service and workflow messages: contract performance and legitimate interests; optional marketing requires consent where law requires it.
- Administer billing and records: contract performance and legal obligations. Paddle processes checkout and payment data under its own notices.
- Respond to rights, legal claims, and regulators: legal obligations and legitimate interests.
We do not sell personal data, use it for cross-context behavioral advertising, or make solely automated legal or similarly significant decisions.
5. International transfers
Providers may process data outside Serbia or the EEA. Before production use Meridian will document data locations and use an adequacy decision, approved standard contractual clauses, or another lawful safeguard where required, together with transfer-risk review. Current sandbox content is synthetic, but account and technical data can still be personal data and receives the same transfer assessment.
6. Retention
- Account and organization records: while the account is active and normally up to 24 months afterward unless law or claims require longer.
- Security, request, and audit evidence: normally up to 24 months; confirmed incident or legal evidence may be retained through the applicable limitation period.
- Support communications: normally 24 months after resolution.
- Email delivery events: normally 12 months.
- Billing and tax records: for the statutory period applicable to Meridian or Paddle.
- Rate-limit buckets: automatically expire shortly after the protection window.
Production order forms may define shorter or more specific periods. Data is deleted or irreversibly anonymized when no longer needed.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. You may also complain to the competent supervisory authority. Serbian residents may contact the Commissioner for Information of Public Importance and Personal Data Protection; EEA/UK residents may contact their local authority. Withdrawal does not affect earlier lawful processing.
Use the in-product Privacy Center or email office@meridiandataexchange.com. We may verify identity and authority before acting. We respond within the legally required period and explain any lawful refusal or extension.
9. Security
Controls include provider-managed authentication, server-side roles, tenant checks, same-origin writes, encrypted email contacts, pseudonymous actor keys, signed webhooks, rate limiting, security headers, audit evidence, restricted delivery, and operational monitoring. Access is limited by role and purpose. Report concerns to office@meridiandataexchange.com.
10. Children
The sandbox is not directed to children and does not knowingly accept their personal data. Production access for minors will remain disabled unless a selected jurisdiction, verified age/guardian process, and specific legal review approve it.
11. Updates and contact
We will post material changes with a new effective date and provide additional notice where required. Privacy questions and requests: office@meridiandataexchange.com.
