Meridian Privacy Policy

How Meridian S.A. collects, uses, discloses, stores, transfers and protects personal data across the Meridian Platform.

Last updated: August 2026

Meridian S.A. ("Meridian", "Company", "we", "our", or "us") is committed to protecting the privacy and security of personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal data when you access or use the Meridian Platform.

The Policy applies to all Services offered by Meridian, including those made available through:

  • the Meridian Website
  • Telegram Bot
  • web applications
  • mobile applications
  • APIs
  • merchant interfaces
  • business accounts
  • customer support channels
  • and other official Meridian communication channels

By using the Platform, you acknowledge that you have read and understood this Privacy Policy.

2. Scope

This Privacy Policy applies to all personal data processed by Meridian in connection with the Services.

It covers information collected from:

  • prospective users
  • registered users
  • business customers
  • merchants
  • API users
  • website visitors
  • support requests
  • compliance procedures
  • recruitment where applicable
  • other lawful interactions with Meridian

This Policy does not apply to third-party websites, applications, or services that are not controlled by Meridian.

3. Data Controller

For purposes of this Privacy Policy, Meridian S.A. acts as the controller of personal data processed through the Platform, except where Meridian acts solely as a processor on behalf of another party.

Meridian determines the purposes and means of processing personal data in accordance with applicable law and this Privacy Policy.

4. Definitions

For purposes of this Policy:

  • Personal Data means any information relating to an identified or identifiable natural person.
  • Processing means any operation performed on Personal Data, including collection, recording, organization, storage, use, disclosure, transfer, deletion, or destruction.
  • User means any individual accessing or using the Platform.
  • Business Customer means any legal entity using Meridian's Services.
  • Platform means the Meridian ecosystem, including websites, applications, APIs, Telegram Bot, and related infrastructure.

5. Personal Data We Collect

The categories of Personal Data collected depend on the Services used.

We may collect:

  • full legal name
  • date of birth
  • nationality
  • residential address
  • postal address
  • email address
  • telephone number
  • government-issued identification details
  • tax residency information
  • tax identification numbers where required
  • photographs
  • biometric verification data processed through authorized identity verification providers
  • company information
  • beneficial ownership information
  • wallet addresses
  • blockchain transaction information
  • payment information
  • communication records
  • customer support requests
  • account preferences
  • login history
  • device identifiers
  • IP addresses
  • browser information
  • operating system information
  • API usage data
  • security logs
  • authentication records
  • risk assessment information

Meridian collects only the categories of information reasonably necessary for the operation of the Services and compliance with applicable legal obligations.

6. Information You Provide

You may provide Personal Data when you:

  • create an Account
  • complete identity verification
  • contact customer support
  • communicate with Meridian
  • submit compliance documentation
  • participate in surveys
  • report security incidents
  • request new Services
  • register as a business customer
  • use merchant functionality

You are responsible for ensuring that all information provided is accurate, complete, and up to date.

7. Information Collected Automatically

When you access the Platform, Meridian may automatically collect technical information, including:

  • IP address
  • device identifiers
  • browser type
  • operating system
  • application version
  • language settings
  • login timestamps
  • session identifiers
  • referral URLs
  • cookie identifiers
  • API request metadata
  • network diagnostics
  • crash reports
  • security logs

Such information assists Meridian in operating, securing, and improving the Platform.

8. Blockchain Information

Due to the nature of blockchain technology, certain information relating to Digital Asset Transactions may be publicly available.

Meridian may collect and process blockchain-related information, including:

  • wallet addresses
  • transaction hashes
  • blockchain timestamps
  • blockchain balances
  • transaction history
  • smart contract interactions
  • blockchain risk indicators
  • blockchain analytics results

Blockchain data may remain permanently accessible on public distributed ledger networks and cannot generally be modified or deleted by Meridian.

9. Information from Third Parties

Meridian may receive Personal Data from trusted third-party providers, including:

  • identity verification providers
  • blockchain analytics providers
  • sanctions screening providers
  • fraud prevention providers
  • payment processors
  • financial institutions
  • telecommunications providers
  • publicly available sources
  • government registries where permitted by law
  • business partners

Information received from third parties may be combined with information collected directly from Users where reasonably necessary to provide the Services, comply with legal obligations, or protect the Platform.

10. How We Use Personal Data

Meridian processes Personal Data only where it has a legitimate business purpose, a legal obligation, contractual necessity, or another lawful basis under applicable data protection laws.

We may use Personal Data to:

  • provide and maintain the Platform
  • create and manage User Accounts
  • provide Custody Services
  • process Digital Asset Transactions
  • authenticate Users
  • perform identity verification
  • comply with legal and regulatory obligations
  • detect and prevent fraud
  • monitor Platform security
  • protect Users and Meridian
  • investigate suspicious activity
  • communicate with Users
  • respond to support requests
  • improve the Platform
  • develop new Services
  • perform analytics
  • conduct internal audits
  • maintain business continuity
  • enforce our legal agreements
  • protect our legal rights

Meridian does not sell Personal Data.

12. KYC, AML and Compliance Processing

Meridian is subject to legal and regulatory obligations relating to anti-money laundering, counter-terrorist financing, sanctions compliance, fraud prevention, and financial crime.

Accordingly, Meridian may process Personal Data for purposes including:

  • identity verification
  • customer due diligence
  • enhanced due diligence
  • politically exposed person (PEP) screening
  • sanctions screening
  • adverse media screening
  • blockchain analytics
  • wallet ownership verification
  • source of funds verification
  • source of wealth verification
  • transaction monitoring
  • suspicious activity detection
  • fraud investigations
  • regulatory reporting
  • ongoing customer monitoring

Certain Personal Data may be retained even after an Account is closed where required by applicable law.

13. Fraud Prevention and Security

Meridian processes Personal Data to protect the integrity and security of the Platform.

This includes processing for:

  • fraud detection
  • account security
  • cybersecurity monitoring
  • unauthorized access detection
  • phishing prevention
  • malware detection
  • transaction verification
  • suspicious login detection
  • abuse prevention
  • API protection
  • network monitoring
  • infrastructure security

Meridian may temporarily suspend access to certain Services while security investigations are conducted.

14. Artificial Intelligence and Automated Processing

Meridian may use automated technologies, including artificial intelligence and machine learning, to assist with:

  • fraud detection
  • blockchain analytics
  • transaction monitoring
  • sanctions screening
  • identity verification support
  • cybersecurity monitoring
  • operational analytics
  • service optimization
  • risk assessment

Automated processing assists Meridian in making operational decisions.

Where appropriate, material decisions affecting Users may be subject to human review.

Meridian does not rely solely upon automated processing where applicable law requires meaningful human involvement.

15. Cookies and Similar Technologies

Meridian uses cookies and similar technologies to improve the functionality, security, and performance of the Platform.

Depending upon the interface used, such technologies may include:

  • browser cookies
  • session cookies
  • authentication cookies
  • local storage
  • security tokens
  • software development kits (SDKs)
  • device identifiers
  • analytics technologies

Cookies may be used to:

  • maintain User sessions
  • authenticate Users
  • improve Platform performance
  • remember preferences
  • detect fraud
  • measure usage
  • enhance security

Additional information is available in the Meridian Cookie Policy.

16. Analytics

Meridian may use analytics technologies to understand how Users interact with the Platform.

Analytics may include information relating to:

  • page visits
  • navigation patterns
  • feature usage
  • application performance
  • API usage
  • device characteristics
  • system diagnostics
  • error reporting
  • crash analytics

Analytics information assists Meridian in improving the quality, reliability, and usability of the Services.

Where reasonably practicable, analytics information is aggregated or pseudonymized.

17. Marketing Communications

Meridian may send communications relating to:

  • Platform updates
  • new Services
  • security notifications
  • educational materials
  • product announcements
  • promotional campaigns
  • surveys
  • newsletters

Where required by applicable law, marketing communications will be sent only with the User's consent.

Users may opt out of marketing communications at any time by following the unsubscribe instructions contained within such communications or by updating their Account preferences.

Certain operational, legal, compliance, and security communications cannot be opted out of because they are necessary for the provision of the Services or compliance with legal obligations.

18. Sharing of Personal Data

Meridian may disclose Personal Data where reasonably necessary to provide the Services or comply with applicable law.

Recipients may include:

  • identity verification providers
  • blockchain analytics providers
  • sanctions screening providers
  • fraud prevention providers
  • cloud infrastructure providers
  • payment processors
  • banking partners
  • professional advisers
  • auditors
  • regulators
  • courts
  • law enforcement authorities
  • governmental agencies
  • affiliates within the Meridian group of companies
  • service providers acting on Meridian's behalf

Meridian requires service providers to process Personal Data only for authorized purposes and to implement appropriate security measures.

Meridian does not sell Personal Data to third parties.

19. International Data Transfers

Meridian operates an international technology platform and may transfer Personal Data across multiple jurisdictions where reasonably necessary to provide the Services.

Personal Data may be processed by Meridian, its affiliates, infrastructure providers, cloud service providers, compliance partners, identity verification providers, and other authorized service providers located in different countries.

Where required by applicable law, Meridian implements appropriate safeguards designed to protect Personal Data during international transfers.

Such safeguards may include:

  • contractual data protection obligations
  • technical security measures
  • encryption
  • organizational controls
  • access restrictions
  • other lawful transfer mechanisms

20. Data Retention

Meridian retains Personal Data only for as long as reasonably necessary to:

  • provide the Services
  • comply with Applicable Law
  • satisfy regulatory requirements
  • resolve disputes
  • enforce legal agreements
  • protect the security of the Platform
  • prevent fraud
  • maintain business records

Retention periods vary depending upon:

  • the type of Personal Data
  • the Services used
  • legal obligations
  • operational requirements
  • regulatory expectations

Where retention is no longer required, Personal Data will be securely deleted, anonymized, or otherwise rendered inaccessible, unless continued retention is required by Applicable Law.

21. Information Security

Meridian maintains a comprehensive information security program designed to protect Personal Data against unauthorized access, disclosure, alteration, destruction, or loss.

Security measures may include:

  • encryption of data in transit
  • encryption of data at rest
  • Hardware Security Modules (HSM)
  • Multi-Party Computation (MPC)
  • role-based access controls
  • multi-factor authentication
  • network segmentation
  • continuous monitoring
  • vulnerability management
  • penetration testing
  • disaster recovery procedures
  • business continuity planning
  • audit logging
  • employee security training

Although Meridian applies commercially reasonable safeguards, no system can guarantee absolute security.

Users also play an important role in protecting their Personal Data by safeguarding their devices, passwords, authentication methods, and communication channels.

22. Your Privacy Rights

Depending upon your jurisdiction, you may have certain rights regarding your Personal Data.

These rights may include:

  • the right to access your Personal Data
  • the right to request correction of inaccurate information
  • the right to request deletion where permitted by law
  • the right to restrict certain processing
  • the right to object to certain processing activities
  • the right to data portability
  • the right to withdraw consent where processing is based upon consent
  • the right to lodge a complaint with a competent supervisory authority

Certain rights may be limited where Meridian is required to retain information for legal, regulatory, fraud prevention, security, or compliance purposes.

Meridian may request additional information to verify the identity of any person submitting a privacy request.

23. Children's Privacy

The Platform is not intended for individuals under the age of eighteen (18), or such higher age as may be required under Applicable Law.

Meridian does not knowingly collect Personal Data from children.

If Meridian becomes aware that Personal Data relating to a child has been collected without appropriate authorization, Meridian will take reasonable steps to delete such information where permitted by Applicable Law.

Parents or legal guardians who believe that a child has provided Personal Data should contact Meridian using the contact information provided below.

24. Third-Party Websites and Services

The Platform may contain links to third-party websites, applications, services, or software.

Meridian does not control and is not responsible for the privacy practices, security practices, content, availability, or policies of third-party services.

Users should review the privacy policies of third-party providers before providing Personal Data to such providers.

25. Changes to this Privacy Policy

Meridian may update this Privacy Policy from time to time to reflect:

  • changes in Applicable Law
  • regulatory guidance
  • technological developments
  • security improvements
  • new Services
  • operational changes
  • business developments

The updated Privacy Policy becomes effective upon publication unless a later effective date is specified.

Where required by Applicable Law, Meridian will provide reasonable notice of material changes.

Continued use of the Platform after the effective date constitutes acceptance of the revised Privacy Policy.

26. Contact Us

Questions regarding this Privacy Policy or the processing of Personal Data may be submitted through Meridian's official communication channels published on the Platform.

Privacy requests, data protection inquiries, regulatory communications, and complaints should be directed to the designated contact information made available by Meridian.

Meridian will make reasonable efforts to respond within the timeframes required by Applicable Law.

27. Language

This Privacy Policy may be translated into languages other than English.

In the event of any inconsistency between translated versions, the English language version shall prevail to the fullest extent permitted by Applicable Law.

28. Relationship with Other Policies

This Privacy Policy should be read together with the following Meridian legal documents:

  • Terms of Service
  • AML & Compliance Policy
  • KYC Policy
  • Custody Policy
  • Cookie Policy
  • Fees Policy
  • Risk Disclosure
  • Legal Requests Policy
  • Prohibited Use Policy
  • Complaints Policy

Where another Meridian policy specifically governs a particular subject matter, that policy shall apply in conjunction with this Privacy Policy.

29. Effective Date

This Privacy Policy is effective from the date stated above and remains in force until amended or replaced by Meridian S.A.

© Meridian S.A. All Rights Reserved.