Data Processing Addendum
Meridian Studios Ltd as processor · EU GDPR, UK GDPR, Israeli Privacy Protection Law, US state privacy laws · Version 1.0
1. Scope and applicable law
This Data Processing Addendum ("DPA") forms part of the Master Subscription Agreement (the "Principal Agreement") between Meridian Studios Ltd ("Meridian") and the Customer. Capitalised terms not defined here have the meaning given in the Principal Agreement.
"Applicable DP Law" means, to the extent each applies: the EU General Data Protection Regulation (Regulation (EU) 2016/679); the UK GDPR together with the Data Protection Act 2018; the Israeli Privacy Protection Law 5741-1981 and its regulations, including the Privacy Protection (Data Security) Regulations 5777-2017 and the Law as amended by Amendment 13; and US state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act.
"Controller", "Processor", "Personal Data", "Processing", "Data Subject" and "Personal Data Breach" bear the meanings given in Applicable DP Law. Under the California Consumer Privacy Act the equivalent concepts are Business, Service Provider and Personal Information.
2. Roles
The Customer is the Controller of Personal Data contained in Customer Content, or is itself a processor acting for its own controller. Meridian is the Processor. Meridian processes that Personal Data only to provide the Service and only on the Customer's documented instructions, which comprise the Principal Agreement, this DPA, and the Customer's configuration and use of the Service.
Meridian will inform the Customer if, in its opinion, an instruction infringes Applicable DP Law, and may pause the relevant processing until the instruction is resolved.
Meridian acts as a Controller in respect of account, billing, usage and support data processed for its own purposes. That processing is governed by the Privacy Policy and not by this DPA.
3. Nature and purpose of processing
Annex 1 sets out the subject-matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subject, as required by Article 28(3) of the GDPR.
4. Personnel and confidentiality
Access to Customer Content is limited to Meridian personnel who require it to provide, support or secure the Service. All such persons are bound by written confidentiality obligations that survive the end of their engagement, and access is granted on a least-privilege, need-to-know basis.
As at the date of this DPA, the only individual with access to Customer Content is Meridian's sole director, operating from Israel. Meridian maintains a current record of authorised persons and will impose equivalent confidentiality obligations on any additional personnel or contractors before granting access.
5. Security measures
Meridian implements and maintains technical and organisational measures appropriate to the risk, as required by Article 32 of the GDPR and by the Israeli Data Security Regulations. Those measures are described in Annex 2, which is the Security & Trust Overview. Meridian will not materially reduce the overall level of security during the term of the Principal Agreement.
6. Sub-processors
The Customer gives general written authorisation for Meridian to engage the sub-processors listed in the Sub-Processor List, which forms Annex 3, and to engage replacements and additions in accordance with this clause.
Meridian imposes on each sub-processor data-protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for each sub-processor's performance.
Meridian will give the Customer at least thirty (30) days' prior notice of any new or replacement sub-processor by updating the Sub-Processor List and notifying subscribers to it. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid Fees.
7. International transfers
Customer Content is stored exclusively in the European Union, in Railway's EU West region in Amsterdam, Netherlands, on Google Cloud Platform infrastructure. Meridian does not transfer Customer Content outside the European Economic Area for storage.
Meridian accesses Customer Content from Israel for the purposes of providing and supporting the Service. Israel benefits from a European Commission adequacy decision, so this access does not require an additional transfer mechanism.
Where a sub-processor is established outside the European Economic Area or the United Kingdom, Meridian implements: (a) for transfers from the European Economic Area, the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Three (processor to sub-processor), supplemented by a transfer impact assessment where required; (b) for transfers from the United Kingdom, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; and (c) for transfers from Israel, reliance on Israel's recognised-adequacy list and, for destinations that are not adequate, contractual safeguards consistent with the Privacy Protection (Transfer of Data Abroad) Regulations 5761-2001.
If Israel's adequacy decision is suspended, amended or revoked, the EU Standard Contractual Clauses at Annex 4 apply automatically to transfers from the European Economic Area to Meridian in Israel with effect from the date of that change, without further action by either party.
8. Assistance to the Customer
Taking into account the nature of the processing and the information available to it, Meridian will assist the Customer with: (a) responding to Data Subject requests, including access, rectification, erasure, restriction, portability and objection, to the extent the Customer cannot do so itself through the Service; (b) the security of processing under Article 32; (c) notification of Personal Data Breaches under Articles 33 and 34; and (d) data protection impact assessments and prior consultation under Articles 35 and 36.
Where a Data Subject contacts Meridian directly regarding Personal Data in Customer Content, Meridian will not respond substantively but will refer the individual to the Customer and notify the Customer without undue delay.
9. Personal Data Breach
Meridian will notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting Customer Content.
The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. Where information is not available at the time, Meridian will provide it in phases without undue further delay.
Meridian will assist the Customer in meeting its own notification obligations, including the 72-hour deadline to the supervisory authority under the GDPR, notification to the Israeli Privacy Protection Authority for severe security incidents, and US state breach-notification laws, and will cooperate with investigations and remediation.
Meridian maintains a documented incident and breach response plan.
10. Audit
Meridian will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including the Security & Trust Overview, completed security questionnaires, and third-party reports obtained by Meridian or its infrastructure providers, including Railway's SOC 2 Type 2 report, available under confidentiality.
Where that information is insufficient, the Customer may conduct an audit no more than once in any twelve (12) month period, on thirty (30) days' written notice, during business hours, subject to confidentiality, without unreasonable disruption, and at the Customer's cost. A regulator may audit where required by law. Meridian will contribute to audits by making relevant personnel and documentation available.
11. Return and deletion
During the Subscription Term and for thirty (30) days after its expiry or termination, the Customer may export Customer Content through the Service in Markdown, JSON, HTML or PDF format, as provided in the Principal Agreement.
After that period, Meridian will delete Customer Content from live systems within thirty (30) days, and from backups on the ordinary rotation cycle and in any event within thirty-five (35) days thereafter. Meridian may retain Personal Data where required by law, in which case it will continue to protect it under this DPA and will process it only for the purpose requiring retention. Meridian will certify deletion in writing on the Customer's request.
12. California Consumer Privacy Act — Service Provider terms
For Personal Information subject to the California Consumer Privacy Act, Meridian acts as a Service Provider. Meridian: (a) processes Personal Information only to perform the Service under the Principal Agreement, which is a business purpose; (b) will not sell or share Personal Information; (c) will not retain, use or disclose Personal Information outside the direct business relationship with the Customer or for any purpose other than performing the Service; (d) will not combine Personal Information with data from other sources except as the Act permits; and (e) certifies that it understands and will comply with these restrictions.
Meridian will notify the Customer if it determines that it can no longer meet these obligations, and will cooperate with the Customer to remediate or cease the processing.
13. Liability, governing law and precedence
Liability under this DPA is subject to the limitations in the Principal Agreement, including the separate data-protection cap in its limitation-of-liability clause. This DPA is governed by the law and forum of the Principal Agreement, save that mandatory Applicable DP Law applies regardless.
In the event of conflict, the EU Standard Contractual Clauses prevail where they apply, then this DPA, then the Principal Agreement.
Annex 1 — Description of processing
| Item | Detail |
|---|---|
| Subject-matter | Provision of the Meridian engineering-documentation platform. |
| Duration | The term of the Principal Agreement, plus the retrieval and deletion periods in clause 11. |
| Nature and purpose | Hosting, storage, transmission, display, indexing, search and synchronisation of Customer Content in order to provide the Service, together with support and security operations. |
| Types of Personal Data | Authorised User account data, comprising name, work email, role and GitHub account identifier; usage and log data including IP address; and any personal data the Customer's users include in engineering documentation, typically names, work email addresses and business-context references to colleagues. |
| Categories of Data Subject | The Customer's Authorised Users, and individuals referenced in Customer Content, typically the Customer's own personnel. |
| Special categories | None. The Acceptable Use Policy prohibits the uploading of special-category data, payment-card data and sector-regulated data. |
| Frequency | Continuous, for the duration of the Subscription Term. |
| Storage location | European Union — Amsterdam, Netherlands. |
| Access location | Israel, under a European Commission adequacy decision. |
Annex 2 — Technical and organisational measures
The Security & Trust Overview forms Annex 2 to this DPA and describes the measures in force.
Annex 3 — Sub-processors
The Sub-Processor List forms Annex 3 and is maintained at meridianide.com/legal/subprocessors.
Annex 4 — Standard Contractual Clauses
The EU Standard Contractual Clauses (Commission Decision 2021/914), with the applicable modules, docking clause and annexes completed, together with the UK Addendum where relevant, are attached and apply as provided in clause 7.