Meridian Data Exchange
Legal centerTerms of ServiceRefund PolicyPrivacy PolicyData Processing AddendumService providers
Back to site

Legal documents

Terms of ServiceRefund PolicyPrivacy PolicyData Processing AddendumService providers
Current operating modeGlobal sandbox · synthetic data only

Privacy notice

Privacy Policy

This notice explains Meridian's own processing of visitor, account, communication, security, and sandbox activity data.

Effective 3 August 2026Version 1.0English controlling version
Pre-production notice. Meridian is operated by Milos Topic as an individual operator in Serbia and currently runs as a global sandbox with synthetic data. No production data exchange, participant payout, or paid production service is activated. Correspondence address: Kosmajska 002, 11036 Belgrade, Serbia.

1. Scope and controller

This Policy applies to meridiandataexchange.com and the Meridian sandbox. Milos Topic, an individual operator in Serbia trading as Meridian Data Exchange, is the controller for operating the website, accounts, communications, security, and business relationship. Correspondence address: Kosmajska 002, 11036 Belgrade, Serbia. Contact: office@meridiandataexchange.com.

Where an organizational customer controls real data and instructs Meridian to process it, that customer is the controller and Meridian acts as processor under the DPA and order form. Paddle separately determines processing required for transactions where it acts as merchant of record.

2. Data we process

  • Account data: provider user ID, verified email signal, display name, role, country, language, eligibility attestation, and security state.
  • Organization data: application details, role, authority, and synthetic verification records.
  • Usage and evidence: pages and features used, consent decisions, workflow actions, audit events, request identifiers, and timestamps.
  • Technical and security data: IP-derived rate-limit fingerprint, request metadata, device/browser information made available by HTTP, alerts, and incident evidence.
  • Communications: messages sent to office@, notification preferences, encrypted email contact and delivery status.
  • Billing metadata, when enabled: Paddle customer, subscription and transaction IDs, status, currency, amount, price ID, and event time. Meridian does not receive or store full card details.

The sandbox must contain synthetic content only. Do not submit real personal or special-category data in offer, connector, delivery, or governance demonstrations.

3. Purposes and legal bases

  • Provide requested website, account, sandbox, and support functions: performance of a contract or steps requested before a contract.
  • Secure, monitor, debug, prevent abuse, and preserve audit evidence: legitimate interests in operating a safe and accountable service and, where applicable, legal obligations.
  • Send service and workflow messages: contract performance and legitimate interests; optional marketing requires consent where law requires it.
  • Administer billing and records: contract performance and legal obligations. Paddle processes checkout and payment data under its own notices.
  • Respond to rights, legal claims, and regulators: legal obligations and legitimate interests.

We do not sell personal data, use it for cross-context behavioral advertising, or make solely automated legal or similarly significant decisions.

4. Sharing and recipients

We share only what is necessary with service providers listed in the provider register, professional advisers under confidentiality, an organization you intentionally interact with, or authorities where legally required. Providers receive role-appropriate information and contractual restrictions where required.

5. International transfers

Providers may process data outside Serbia or the EEA. Before production use Meridian will document data locations and use an adequacy decision, approved standard contractual clauses, or another lawful safeguard where required, together with transfer-risk review. Current sandbox content is synthetic, but account and technical data can still be personal data and receives the same transfer assessment.

6. Retention

  • Account and organization records: while the account is active and normally up to 24 months afterward unless law or claims require longer.
  • Security, request, and audit evidence: normally up to 24 months; confirmed incident or legal evidence may be retained through the applicable limitation period.
  • Support communications: normally 24 months after resolution.
  • Email delivery events: normally 12 months.
  • Billing and tax records: for the statutory period applicable to Meridian or Paddle.
  • Rate-limit buckets: automatically expire shortly after the protection window.

Production order forms may define shorter or more specific periods. Data is deleted or irreversibly anonymized when no longer needed.

7. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent. You may also complain to the competent supervisory authority. Serbian residents may contact the Commissioner for Information of Public Importance and Personal Data Protection; EEA/UK residents may contact their local authority. Withdrawal does not affect earlier lawful processing.

Use the in-product Privacy Center or email office@meridiandataexchange.com. We may verify identity and authority before acting. We respond within the legally required period and explain any lawful refusal or extension.

8. Cookies, local storage, and analytics

Meridian currently uses only provider/session mechanisms needed for sign-in, security, language, and interface preferences. First-party pseudonymous events record trial start, scheduled reminders, expiry, and paid activation so service reliability and aggregate conversion can be measured. Meridian does not use advertising trackers, cross-site profiles, or third-party behavioral analytics. If non-essential analytics are introduced, this notice and the consent controls will be updated before activation.

9. Security

Controls include provider-managed authentication, server-side roles, tenant checks, same-origin writes, encrypted email contacts, pseudonymous actor keys, signed webhooks, rate limiting, security headers, audit evidence, restricted delivery, and operational monitoring. Access is limited by role and purpose. Report concerns to office@meridiandataexchange.com.

10. Children

The sandbox is not directed to children and does not knowingly accept their personal data. Production access for minors will remain disabled unless a selected jurisdiction, verified age/guardian process, and specific legal review approve it.

11. Updates and contact

We will post material changes with a new effective date and provide additional notice where required. Privacy questions and requests: office@meridiandataexchange.com.

Meridian Data Exchange office@meridiandataexchange.com
文