This Privacy Policy applies to our websites (including meridianex.pro and related pages), our accounting software and related applications, APIs, demos, webinars, and other services that link to this Policy (collectively, the “Services”). By using the Services, you acknowledge the practices described here.
1. Who we are
Meridian Financial Systems, Inc. is a Delaware corporation with headquarters at 600 Congress Ave, Suite 400, Austin, TX 78701, United States, and an office at 14 Hatton Garden, London EC1N 8AT, United Kingdom.
For privacy inquiries: privacy@meridianex.pro
For security reports: security@meridianex.pro
General contact: support@meridianex.pro
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, Meridian Financial Systems, Inc. is the controller of personal data we collect through our marketing sites and as described below. When we process Customer Content on behalf of a business customer, we generally act as a processor (or service provider) under that customer’s instructions.
2. Information we collect
2.1 Information you provide
- Account and profile data: name, work email, password or SSO identifiers, job title, company name, phone number, billing address, and role within Meridian.
- Customer Content: financial and business data you or your organization upload or generate in Meridian, including general ledger entries, invoices, bills, bank transaction descriptions, contacts, receipts, documents, comments, and reports. Customer Content may include personal data about your employees, customers, vendors, and other third parties.
- Payment information: subscription billing details. Card payments are processed by our payment processors; we do not store full payment card numbers on Meridian servers.
- Communications: messages you send to sales, support, or security, including demo requests, tickets, call notes, and survey responses.
- Event and marketing data: webinar registrations, newsletter preferences, and form submissions on our websites.
2.2 Information collected automatically
- Usage and device data: IP address, browser type, device identifiers, operating system, referring URLs, pages viewed, feature usage, timestamps, and approximate location derived from IP.
- Log and diagnostic data: server logs, error reports, performance metrics, and security event logs.
- Cookies and similar technologies: see Section 8.
2.3 Information from third parties
- Integrations you connect: banks, payment processors, ecommerce platforms, payroll providers, CRM systems, and other tools you authorize. We receive data necessary to provide the connected features (for example, transaction feeds or payroll journals).
- Identity and authentication providers: if you sign in with SSO or similar services.
- Business partners and referrals: limited contact details when a partner introduces you to Meridian, consistent with applicable law.
- Public or commercial sources: company information used to qualify leads or prevent fraud, where permitted.
3. How we use information
We use personal information to:
- Provide, operate, maintain, and improve the Services;
- Create and manage accounts, authenticate users, and enforce access controls;
- Process subscriptions, invoices, and payments;
- Provide customer support, onboarding, and training;
- Send service-related notices (security alerts, product changes, billing);
- Send marketing communications where permitted (you may opt out at any time);
- Analyze usage to improve reliability, UX, and product roadmap;
- Detect, prevent, and respond to fraud, abuse, and security incidents;
- Comply with law, enforce our Terms of Use, and protect rights and safety;
- Perform research and aggregated/de-identified analytics that do not identify individuals.
We do not sell personal information for money. We do not use Customer Content to train third-party foundation models. We do not allow advertising networks to use Customer Content for targeted ads.
4. Legal bases (EEA/UK/Switzerland)
Where required, we process personal data on these bases:
- Contract: to deliver the Services you or your organization request;
- Legitimate interests: to secure, improve, and market the Services in a balanced way, and to operate our business;
- Consent: where we ask for it (for example, certain cookies or marketing emails);
- Legal obligation: to meet tax, accounting, and regulatory requirements.
5. How we share information
We may share personal information with:
- Service providers / subprocessors: cloud hosting, email delivery, customer support tools, analytics, payment processing, and security vendors who process data under contract and only on our instructions;
- Integration partners: when you choose to connect third-party services;
- Professional advisors: lawyers, auditors, and insurers under confidentiality obligations;
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate safeguards;
- Legal and safety: when we believe disclosure is required by law, legal process, or to protect Meridian, our users, or the public;
- With your direction: for example, when you invite teammates, grant accountant access, or export/share reports.
A current list of material subprocessors is available on request at privacy@meridianex.pro and is updated at least quarterly for enterprise customers under NDA where applicable.
6. Customer Content and roles
If your organization is a Meridian customer, your organization controls Customer Content. Your organization’s administrators decide who has access, how long data is retained within the product (subject to our retention features and backups), and how to respond to end-user requests relating to Customer Content. We process Customer Content to provide the Services and as described in our customer agreements and Data Processing Addendum (DPA), where executed.
Individuals whose data appears in Customer Content should contact the relevant Meridian customer to exercise privacy rights regarding that content. We will assist customers in responding as required by our agreements and applicable law.
7. International transfers
We are based in the United States and may process data in the U.S. and other countries where we or our subprocessors operate. Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we use appropriate safeguards such as the European Commission Standard Contractual Clauses (and UK/Swiss addenda as required), together with supplementary measures where appropriate. EU data residency options may be available on eligible plans.
8. Cookies and similar technologies
We use cookies, local storage, and similar technologies to:
- Keep you signed in and remember preferences (strictly necessary);
- Understand site and product performance (analytics);
- Support security and fraud prevention;
- Measure marketing campaign effectiveness where permitted.
You can control cookies through your browser settings. Blocking some cookies may affect Service functionality. Where required by law, we present a consent mechanism for non-essential cookies.
9. Data retention
We retain personal information for as long as needed to provide the Services and for legitimate business purposes, such as maintaining financial records, resolving disputes, enforcing agreements, and complying with legal obligations.
After account termination or a verified deletion request, we delete or de-identify production Customer Content within thirty (30) days, except where retention is required by law or needed for security, dispute resolution, or backups. Encrypted backups are aged out according to our backup retention schedule.
10. Security
We implement administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, access controls, monitoring, and employee training. No method of transmission or storage is completely secure; we cannot guarantee absolute security. Additional details are available on our Security page. Report vulnerabilities to security@meridianex.pro.
11. Your rights and choices
Depending on your location, you may have rights to:
- Access, correct, or delete personal information;
- Receive a portable copy of certain data;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent;
- Opt out of marketing emails (unsubscribe link in each message);
- Appeal a decision we make regarding a privacy request, where required by law.
To exercise rights regarding data Meridian controls directly (for example, marketing site data or your user account profile), email privacy@meridianex.pro. We may need to verify your identity. For Customer Content, contact your organization’s Meridian administrator first.
California (CCPA/CPRA) and similar U.S. state laws: We do not “sell” or “share” personal information as those terms are commonly defined for cross-context behavioral advertising with respect to Customer Content. We may use service providers for analytics and advertising on our public marketing site. You may request to know, delete, or correct personal information we hold about you as a consumer, subject to exceptions. We will not discriminate against you for exercising your rights.
EEA/UK residents may lodge a complaint with their local supervisory authority. We encourage you to contact us first so we can help.
12. Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe we have collected such information, contact privacy@meridianex.pro and we will take appropriate steps to delete it.
13. Third-party links and services
The Services may link to third-party websites or allow connections to third-party products. Their privacy practices are governed by their own policies. We are not responsible for third-party practices.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised “Last updated” date. If changes are material, we will provide additional notice as required by law (for example, email or in-product notice). Continued use of the Services after the effective date constitutes acceptance of the updated Policy, except where consent is required.
15. Contact us
Meridian Financial Systems, Inc.
Attn: Privacy Office
600 Congress Ave, Suite 400
Austin, TX 78701
United States
Email: privacy@meridianex.pro
For questions about this Policy, our DPA, or subprocessors, contact privacy@meridianex.pro. For product demos and sales, contact sales@meridianex.pro.