Meridian S.A. ("Meridian", "Company", "we", "our", or "us") is committed to protecting the privacy and security of personal information entrusted to us.
This Privacy Policy explains how we collect, use, disclose, store, transfer, and protect personal data when you access or use the Meridian Platform.
The Policy applies to all Services offered by Meridian, including those made available through:
- the Meridian Website
- Telegram Bot
- web applications
- mobile applications
- APIs
- merchant interfaces
- business accounts
- customer support channels
- and other official Meridian communication channels
By using the Platform, you acknowledge that you have read and understood this Privacy Policy.
2. Scope
This Privacy Policy applies to all personal data processed by Meridian in connection with the Services.
It covers information collected from:
- prospective users
- registered users
- business customers
- merchants
- API users
- website visitors
- support requests
- compliance procedures
- recruitment where applicable
- other lawful interactions with Meridian
This Policy does not apply to third-party websites, applications, or services that are not controlled by Meridian.
3. Data Controller
For purposes of this Privacy Policy, Meridian S.A. acts as the controller of personal data processed through the Platform, except where Meridian acts solely as a processor on behalf of another party.
Meridian determines the purposes and means of processing personal data in accordance with applicable law and this Privacy Policy.
4. Definitions
For purposes of this Policy:
- Personal Data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on Personal Data, including collection, recording, organization, storage, use, disclosure, transfer, deletion, or destruction.
- User means any individual accessing or using the Platform.
- Business Customer means any legal entity using Meridian's Services.
- Platform means the Meridian ecosystem, including websites, applications, APIs, Telegram Bot, and related infrastructure.
5. Personal Data We Collect
The categories of Personal Data collected depend on the Services used.
We may collect:
- full legal name
- date of birth
- nationality
- residential address
- postal address
- email address
- telephone number
- government-issued identification details
- tax residency information
- tax identification numbers where required
- photographs
- biometric verification data processed through authorized identity verification providers
- company information
- beneficial ownership information
- wallet addresses
- blockchain transaction information
- payment information
- communication records
- customer support requests
- account preferences
- login history
- device identifiers
- IP addresses
- browser information
- operating system information
- API usage data
- security logs
- authentication records
- risk assessment information
Meridian collects only the categories of information reasonably necessary for the operation of the Services and compliance with applicable legal obligations.
6. Information You Provide
You may provide Personal Data when you:
- create an Account
- complete identity verification
- contact customer support
- communicate with Meridian
- submit compliance documentation
- participate in surveys
- report security incidents
- request new Services
- register as a business customer
- use merchant functionality
You are responsible for ensuring that all information provided is accurate, complete, and up to date.
7. Information Collected Automatically
When you access the Platform, Meridian may automatically collect technical information, including:
- IP address
- device identifiers
- browser type
- operating system
- application version
- language settings
- login timestamps
- session identifiers
- referral URLs
- cookie identifiers
- API request metadata
- network diagnostics
- crash reports
- security logs
Such information assists Meridian in operating, securing, and improving the Platform.
8. Blockchain Information
Due to the nature of blockchain technology, certain information relating to Digital Asset Transactions may be publicly available.
Meridian may collect and process blockchain-related information, including:
- wallet addresses
- transaction hashes
- blockchain timestamps
- blockchain balances
- transaction history
- smart contract interactions
- blockchain risk indicators
- blockchain analytics results
Blockchain data may remain permanently accessible on public distributed ledger networks and cannot generally be modified or deleted by Meridian.
9. Information from Third Parties
Meridian may receive Personal Data from trusted third-party providers, including:
- identity verification providers
- blockchain analytics providers
- sanctions screening providers
- fraud prevention providers
- payment processors
- financial institutions
- telecommunications providers
- publicly available sources
- government registries where permitted by law
- business partners
Information received from third parties may be combined with information collected directly from Users where reasonably necessary to provide the Services, comply with legal obligations, or protect the Platform.
10. How We Use Personal Data
Meridian processes Personal Data only where it has a legitimate business purpose, a legal obligation, contractual necessity, or another lawful basis under applicable data protection laws.
We may use Personal Data to:
- provide and maintain the Platform
- create and manage User Accounts
- provide Custody Services
- process Digital Asset Transactions
- authenticate Users
- perform identity verification
- comply with legal and regulatory obligations
- detect and prevent fraud
- monitor Platform security
- protect Users and Meridian
- investigate suspicious activity
- communicate with Users
- respond to support requests
- improve the Platform
- develop new Services
- perform analytics
- conduct internal audits
- maintain business continuity
- enforce our legal agreements
- protect our legal rights
Meridian does not sell Personal Data.
11. Legal Bases for Processing
Where applicable under data protection laws, Meridian processes Personal Data on one or more of the following legal bases:
- performance of a contract
- compliance with legal obligations
- protection of vital interests
- legitimate business interests
- User consent, where required
- establishment, exercise, or defense of legal claims
- fraud prevention and security
Where processing is based upon consent, Users may withdraw consent at any time, subject to applicable legal limitations.
Withdrawal of consent does not affect processing already lawfully carried out before such withdrawal.
12. KYC, AML and Compliance Processing
Meridian is subject to legal and regulatory obligations relating to anti-money laundering, counter-terrorist financing, sanctions compliance, fraud prevention, and financial crime.
Accordingly, Meridian may process Personal Data for purposes including:
- identity verification
- customer due diligence
- enhanced due diligence
- politically exposed person (PEP) screening
- sanctions screening
- adverse media screening
- blockchain analytics
- wallet ownership verification
- source of funds verification
- source of wealth verification
- transaction monitoring
- suspicious activity detection
- fraud investigations
- regulatory reporting
- ongoing customer monitoring
Certain Personal Data may be retained even after an Account is closed where required by applicable law.
13. Fraud Prevention and Security
Meridian processes Personal Data to protect the integrity and security of the Platform.
This includes processing for:
- fraud detection
- account security
- cybersecurity monitoring
- unauthorized access detection
- phishing prevention
- malware detection
- transaction verification
- suspicious login detection
- abuse prevention
- API protection
- network monitoring
- infrastructure security
Meridian may temporarily suspend access to certain Services while security investigations are conducted.
14. Artificial Intelligence and Automated Processing
Meridian may use automated technologies, including artificial intelligence and machine learning, to assist with:
- fraud detection
- blockchain analytics
- transaction monitoring
- sanctions screening
- identity verification support
- cybersecurity monitoring
- operational analytics
- service optimization
- risk assessment
Automated processing assists Meridian in making operational decisions.
Where appropriate, material decisions affecting Users may be subject to human review.
Meridian does not rely solely upon automated processing where applicable law requires meaningful human involvement.
16. Analytics
Meridian may use analytics technologies to understand how Users interact with the Platform.
Analytics may include information relating to:
- page visits
- navigation patterns
- feature usage
- application performance
- API usage
- device characteristics
- system diagnostics
- error reporting
- crash analytics
Analytics information assists Meridian in improving the quality, reliability, and usability of the Services.
Where reasonably practicable, analytics information is aggregated or pseudonymized.
17. Marketing Communications
Meridian may send communications relating to:
- Platform updates
- new Services
- security notifications
- educational materials
- product announcements
- promotional campaigns
- surveys
- newsletters
Where required by applicable law, marketing communications will be sent only with the User's consent.
Users may opt out of marketing communications at any time by following the unsubscribe instructions contained within such communications or by updating their Account preferences.
Certain operational, legal, compliance, and security communications cannot be opted out of because they are necessary for the provision of the Services or compliance with legal obligations.
19. International Data Transfers
Meridian operates an international technology platform and may transfer Personal Data across multiple jurisdictions where reasonably necessary to provide the Services.
Personal Data may be processed by Meridian, its affiliates, infrastructure providers, cloud service providers, compliance partners, identity verification providers, and other authorized service providers located in different countries.
Where required by applicable law, Meridian implements appropriate safeguards designed to protect Personal Data during international transfers.
Such safeguards may include:
- contractual data protection obligations
- technical security measures
- encryption
- organizational controls
- access restrictions
- other lawful transfer mechanisms
20. Data Retention
Meridian retains Personal Data only for as long as reasonably necessary to:
- provide the Services
- comply with Applicable Law
- satisfy regulatory requirements
- resolve disputes
- enforce legal agreements
- protect the security of the Platform
- prevent fraud
- maintain business records
Retention periods vary depending upon:
- the type of Personal Data
- the Services used
- legal obligations
- operational requirements
- regulatory expectations
Where retention is no longer required, Personal Data will be securely deleted, anonymized, or otherwise rendered inaccessible, unless continued retention is required by Applicable Law.
21. Information Security
Meridian maintains a comprehensive information security program designed to protect Personal Data against unauthorized access, disclosure, alteration, destruction, or loss.
Security measures may include:
- encryption of data in transit
- encryption of data at rest
- Hardware Security Modules (HSM)
- Multi-Party Computation (MPC)
- role-based access controls
- multi-factor authentication
- network segmentation
- continuous monitoring
- vulnerability management
- penetration testing
- disaster recovery procedures
- business continuity planning
- audit logging
- employee security training
Although Meridian applies commercially reasonable safeguards, no system can guarantee absolute security.
Users also play an important role in protecting their Personal Data by safeguarding their devices, passwords, authentication methods, and communication channels.
22. Your Privacy Rights
Depending upon your jurisdiction, you may have certain rights regarding your Personal Data.
These rights may include:
- the right to access your Personal Data
- the right to request correction of inaccurate information
- the right to request deletion where permitted by law
- the right to restrict certain processing
- the right to object to certain processing activities
- the right to data portability
- the right to withdraw consent where processing is based upon consent
- the right to lodge a complaint with a competent supervisory authority
Certain rights may be limited where Meridian is required to retain information for legal, regulatory, fraud prevention, security, or compliance purposes.
Meridian may request additional information to verify the identity of any person submitting a privacy request.
23. Children's Privacy
The Platform is not intended for individuals under the age of eighteen (18), or such higher age as may be required under Applicable Law.
Meridian does not knowingly collect Personal Data from children.
If Meridian becomes aware that Personal Data relating to a child has been collected without appropriate authorization, Meridian will take reasonable steps to delete such information where permitted by Applicable Law.
Parents or legal guardians who believe that a child has provided Personal Data should contact Meridian using the contact information provided below.
24. Third-Party Websites and Services
The Platform may contain links to third-party websites, applications, services, or software.
Meridian does not control and is not responsible for the privacy practices, security practices, content, availability, or policies of third-party services.
Users should review the privacy policies of third-party providers before providing Personal Data to such providers.
25. Changes to this Privacy Policy
Meridian may update this Privacy Policy from time to time to reflect:
- changes in Applicable Law
- regulatory guidance
- technological developments
- security improvements
- new Services
- operational changes
- business developments
The updated Privacy Policy becomes effective upon publication unless a later effective date is specified.
Where required by Applicable Law, Meridian will provide reasonable notice of material changes.
Continued use of the Platform after the effective date constitutes acceptance of the revised Privacy Policy.
26. Contact Us
Questions regarding this Privacy Policy or the processing of Personal Data may be submitted through Meridian's official communication channels published on the Platform.
Privacy requests, data protection inquiries, regulatory communications, and complaints should be directed to the designated contact information made available by Meridian.
Meridian will make reasonable efforts to respond within the timeframes required by Applicable Law.
27. Language
This Privacy Policy may be translated into languages other than English.
In the event of any inconsistency between translated versions, the English language version shall prevail to the fullest extent permitted by Applicable Law.
28. Relationship with Other Policies
This Privacy Policy should be read together with the following Meridian legal documents:
- Terms of Service
- AML & Compliance Policy
- KYC Policy
- Custody Policy
- Cookie Policy
- Fees Policy
- Risk Disclosure
- Legal Requests Policy
- Prohibited Use Policy
- Complaints Policy
Where another Meridian policy specifically governs a particular subject matter, that policy shall apply in conjunction with this Privacy Policy.
29. Effective Date
This Privacy Policy is effective from the date stated above and remains in force until amended or replaced by Meridian S.A.
© Meridian S.A. All Rights Reserved.