Meridian Data Exchange
Legal centerTerms of ServiceRefund PolicyPrivacy PolicyData Processing AddendumService providers
Back to site

Legal documents

Terms of ServiceRefund PolicyPrivacy PolicyData Processing AddendumService providers
Current operating modeGlobal sandbox · synthetic data only

Controller–processor terms

Data Processing Addendum

This DPA is a ready-to-sign framework for production organizational customers. It is not activated by sandbox browsing alone.

Effective 3 August 2026Version 1.0English controlling version
Pre-production notice. Meridian is operated by Milos Topic as an individual operator in Serbia and currently runs as a global sandbox with synthetic data. No production data exchange, participant payout, or paid production service is activated. Correspondence address: Kosmajska 002, 11036 Belgrade, Serbia.
How this becomes binding. This DPA forms part of a signed Meridian order form or service agreement that identifies the Customer, production service, and exact processing. Sandbox browsing alone does not activate it.

1. Parties and priority

The “Customer” is the entity identified in the applicable order. “Meridian” is Milos Topic, an individual operator in Serbia trading as Meridian Data Exchange, correspondence address Kosmajska 002, 11036 Belgrade, Serbia. Customer is controller and Meridian is processor for Customer Personal Data, except where either party acts as an independent controller under applicable law. This DPA prevails over conflicting service terms on personal-data processing; mandatory standard contractual clauses prevail over this DPA.

2. Definitions

“Applicable Data Protection Law” means laws governing the processing, security, breach notification, or rights relating to personal data, including where applicable the Serbian Law on Personal Data Protection, EU GDPR, UK GDPR, and US state privacy laws. “Customer Personal Data” means personal data Meridian processes for Customer under documented instructions. “Subprocessor”, “personal data”, “controller”, “processor”, “data subject”, and “processing” have their statutory meanings.

3. Instructions and compliance

Meridian will process Customer Personal Data only to provide the ordered Service, on Customer's documented instructions, or as law requires. The agreement, order form, configuration, approved API calls, and authorized support requests are documented instructions. Meridian will notify Customer before legally required processing unless prohibited. Customer is responsible for the lawfulness, transparency, minimization, accuracy, and instructions relating to Customer Personal Data.

4. Confidentiality and access

Meridian will ensure that persons authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed for their duties. Access is reviewed and can be revoked. Meridian will not sell Customer Personal Data or use it for advertising.

5. Security measures

Taking account of risk, Meridian will maintain appropriate measures including: provider-managed authentication; role and tenant authorization; least privilege; encryption in transit; encrypted sensitive contact data at rest; secrets outside source code; pseudonymous actor identifiers; signed and replay-protected webhooks; request size limits and rate limiting; security headers; audit logging and integrity evidence; vulnerability and dependency review; incident management; backup/recovery procedures; data minimization; aggregate delivery controls; and change/release review.

Specific production measures, regions, recovery objectives, and assurance reports will be recorded in the order or security schedule. Customer acknowledges that the public sandbox is not approved for Customer Personal Data.

6. Subprocessors

Customer gives general authorization to use the providers in the provider register. Meridian will impose data-protection obligations appropriate to each processing role and remains responsible for processor subprocessors as required by law. Meridian will give at least 14 days' notice of a new material subprocessor where practicable. Customer may object on reasonable data-protection grounds; the parties will seek a practical alternative, and Customer may terminate the affected ordered service if no reasonable alternative exists.

7. Data-subject requests

Taking account of the processing, Meridian will provide reasonable technical and organizational assistance for Customer to answer requests for access, correction, deletion, restriction, portability, objection, or consent withdrawal. Meridian will notify Customer of a request concerning Customer Personal Data and will not respond except on Customer's instruction or as law requires.

8. Personal-data breach

Meridian will notify Customer without undue delay after becoming aware of a confirmed breach of Customer Personal Data. Available notice will describe the nature, affected data and people, likely consequences, mitigation, and contact point. Meridian will investigate, contain, remediate, preserve evidence, and reasonably assist Customer with legally required notifications. Notice is not an admission of fault.

9. DPIAs, consultations, and compliance evidence

Meridian will reasonably assist with security obligations, data-protection impact assessments, and regulator consultation related to the ordered processing. On reasonable request it will provide information necessary to demonstrate compliance. Audits should first use current independent evidence where available; an on-site audit may occur no more than annually unless a breach, regulator, or substantiated concern requires more, with reasonable notice, confidentiality, limited scope, and avoidance of disruption.

10. Return and deletion

At the end of the Service, Meridian will, at Customer's choice and where technically feasible, return Customer Personal Data and delete remaining copies within 30 days after the agreed export window, unless law requires retention. Retained data remains protected and is used only for the required purpose. Backup copies are deleted on the normal secure rotation cycle.

11. International transfers

Restricted transfers require a lawful mechanism. Where EU personal data is transferred to a country without an adequacy decision, the 2021 EU Standard Contractual Clauses are incorporated with the module appropriate to the parties' roles, supplemented by the order form and transfer assessment. Equivalent UK or other addenda apply where required. The parties will add the exporter/importer identity, competent authority, law, forum, categories, locations, and safeguards before production processing.

Schedule 1 — Details of processing

Subject matter
Permissioned data-request, consent, metadata wallet, controlled delivery, evidence, privacy-rights, and organizational workflow services described in the order.
Duration
For the term of the ordered Service plus the deletion/export period.
Nature and purpose
Hosting, organizing, securing, querying, aggregating, evidencing, supporting, and deleting data solely to provide the configured Service.
Data subjects
Customer personnel, authorized users, individual participants, applicants, and people represented in Customer-authorized data.
Data types
Account and professional contact data, identifiers, permissions, provenance/metadata, request and consent records, audit events, support communications, and only the production categories expressly approved in the order.
Excluded by default
Raw special-category data, children's data, precise credentials, full payment-card data, and any data not expressly approved.
Frequency
Continuous or event-driven as configured.
Retention
As stated in the order and Customer configuration, subject to legal retention.

Schedule 2 — Contacts and signatures

Meridian contact: Milos Topic, individual operator in Serbia, Kosmajska 002, 11036 Belgrade, Serbia; office@meridiandataexchange.com. Customer identity, privacy/security contacts, effective date, governing agreement, selected hosting region, approved categories, and transfer annexes must be completed in the signed order.

Meridian Data Exchange office@meridiandataexchange.com
文