Privacy Policy
How Meridian Studios Ltd collects and uses personal data · Version 1.0 · Last updated 25 September 2026
1. Who we are
Meridian Studios Ltd (Israeli company number 517352225), of 6 Yitzhak Sadeh Street, Tel Aviv–Yafo 6777506, Israel ("Meridian", "we", "us") is the controller of the personal data described in this policy, except where we act as a processor for our business customers (see clause 3).
Privacy contact: privacy@meridianide.com. The person responsible for privacy at Meridian is Adam Brett Goldberg, Director.
2. The personal data we collect as controller
| Category | Examples | Source |
|---|---|---|
| Account and contact data | Name, work email, role, employer, GitHub account identifier | You, on sign-up or invitation |
| Billing data | Billing contact, company details, tax identifiers, payment-processor references | You, and our payment processor |
| Usage and device data | Log data, IP address, browser and device information, feature usage, diagnostics | Automatically, as you use the Service |
| Support data | The content of support correspondence | You |
| Marketing and business-contact data | Business contact details, event and demonstration enquiries, preferences | You, or public business sources |
We do not knowingly collect special-category personal data about you as a controller, and we ask that you do not send it to us in support correspondence or free-text fields.
We do not handle payment-card data. Payments are processed by Airwallex on its own hosted checkout; card details are entered directly with Airwallex and never reach Meridian's systems.
3. Customer Content — where we act as processor
When your organisation uses Meridian, its authorised users upload, create and synchronise engineering documentation ("Customer Content"), which may contain personal data — for example the names or work email addresses of colleagues referenced in a document. For that data your organisation is the controller and Meridian is the processor, acting only on your organisation's documented instructions under our Data Processing Addendum.
The controller decides why and how personal data is used; the processor only handles it on the controller's instructions. This Privacy Policy does not govern Customer Content — the Data Processing Addendum does.
If you are an individual whose personal data appears in a customer's Customer Content, please contact that customer, who is the controller. We will assist them in responding to you.
We do not use Customer Content to train any artificial-intelligence or machine-learning model, and we operate no artificial-intelligence features that read Customer Content.
4. Why we use your data, and our legal bases
| Purpose | GDPR and UK GDPR basis | Israeli and US position |
|---|---|---|
| Providing, securing and supporting the Service and website | Performance of a contract; legitimate interests | Israel: necessary for the service requested. US: a business purpose. |
| Billing, collections and financial record-keeping | Performance of a contract; legal obligation | Retention periods are driven by Israeli tax and companies legislation. |
| Security, fraud prevention and abuse detection | Legitimate interests; legal obligation | — |
| Service improvement and diagnostics | Legitimate interests, kept proportionate | We do not combine this data with Customer Content. |
| Marketing to business prospects | Consent where required; otherwise legitimate interests | Israel: the Communications Law (Amendment 40) requires prior consent for commercial messages, with limited exceptions. Opt-out is honoured in all cases. |
| Complying with law and enforcing our terms | Legal obligation; legitimate interests | — |
5. Cookies and similar technologies
We use only strictly necessary cookies — those required for login, session management, security and load balancing. We do not operate analytics, advertising or cross-site tracking technologies on our website or in the Service, and we therefore do not display a consent banner.
If we introduce non-essential cookies we will publish a cookie policy, deploy a consent mechanism for EU and UK visitors, and update this policy before those cookies are set.
6. Who we share data with
We share personal data with: (a) the service providers and sub-processors listed in our Sub-Processor List, under written contract; (b) our professional advisers, including legal and accounting advisers; (c) authorities where legally required; and (d) an acquirer or investor in connection with a merger, financing or sale of assets, subject to confidentiality.
We do not sell personal data, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other US state privacy laws.
7. Where your data is held, and international transfers
The Service is hosted on Railway (Railway Corporation), which operates on Google Cloud Platform infrastructure. All Customer Content and production data are stored in Railway's EU West region — Amsterdam, Netherlands. Compute and database run in the same region.
Personal data may be accessed from Israel, where Meridian is established and operates. Israel benefits from a European Commission adequacy decision, which means transfers from the European Economic Area to Israel do not require additional safeguards such as Standard Contractual Clauses.
A limited number of our sub-processors are established outside the European Economic Area. Where that is so, transfers are made under the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for United Kingdom data, the UK International Data Transfer Addendum, or under an adequacy decision or certification where one applies. Details are set out in the Sub-Processor List and the Data Processing Addendum.
8. How long we keep data
| Data | Retention |
|---|---|
| Account and contact data | For the life of the account, plus 12 months |
| Billing and financial records | 7 years, as required by Israeli tax and accounting law |
| Logs and diagnostics | 12 months |
| Support correspondence | 24 months after the matter is closed |
| Marketing data | Until you opt out, after which suppression-list data only |
| Customer Content | Governed by the Data Processing Addendum and the retrieval window in the Master Subscription Agreement |
9. Your rights
Depending on where you are, you may have rights to access, correct, delete, port or restrict your personal data, to object to processing, to withdraw consent, and to complain to a regulator. Residents of the European Union and the United Kingdom have the full set of GDPR rights. Residents of California and other US states have rights of access, deletion, correction, and to opt out of sale, sharing and certain profiling, none of which we carry out. Israeli residents have rights of access and correction under the Privacy Protection Law.
To exercise a right, contact privacy@meridianide.com. We will respond within the period the law requires — one month under the GDPR and UK GDPR, and 45 days under the California Consumer Privacy Act. We may need to verify your identity. We will not discriminate against you for exercising a privacy right.
If your request concerns personal data inside a customer's Customer Content, we will direct you to that customer, who is the controller.
10. Security
We apply technical and organisational measures appropriate to the risk, described in our Security & Trust Overview. Our infrastructure provider, Railway, holds SOC 2 Type 2, SOC 3 and GDPR certifications. No system is perfectly secure and we cannot guarantee absolute security.
11. Children
The Service is sold to organisations for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16.
12. Changes, contact and complaints
We will post changes to this policy here and update the date shown above, and we will notify you of material changes.
Questions or complaints: privacy@meridianide.com, Meridian Studios Ltd, 6 Yitzhak Sadeh Street, Tel Aviv–Yafo 6777506, Israel.
Users in the European Union and the United Kingdom may also contact their local supervisory authority. Israeli users may contact the Israeli Privacy Protection Authority.