Privacy Policy
MeridianONE Technologies Inc. · Version Date July 20, 2026
This Privacy Policy describes how MeridianONE Technologies Inc. (“Meridian,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information in connection with our Products and our Website (each as defined in Section 1). This Privacy Policy applies to the Products and, as applicable, to the Website.
This Privacy Policy applies to individuals who interact with Meridian directly, including visitors, self-service subscribers, purchasers, trial users, support contacts, and authorized users. If you use the Products through an employer or other organization, that organization may control information in its account and Customer Content. For personal information that Meridian processes on behalf of a business customer, Meridian processes that information under the applicable customer agreement and data processing terms, and you should direct requests about that information to your organization.
This Privacy Policy is a notice about Meridian’s privacy practices. It does not create or limit contractual rights under the applicable Terms of Service and End User License Agreement, your Order and applicable Checkout Terms, or the Data Processing Terms in Section 26 of the Terms of Service, and it does not limit rights you may have under applicable law.
This Privacy Policy is also intended to serve as Meridian’s online privacy policy and, where applicable, as a notice at collection for personal information collected through the website, checkout flow, account portal, Products, and support interactions. Additional just-in-time notices, cookie notices, checkout notices, or product notices may supplement this Privacy Policy.
Quick summary
- Local use is different from cloud use. The Local Software is designed to process schedule content on your device. Schedule files and project data are not transmitted to Meridian merely because you use the Local Software locally. Customer Content is transmitted to Meridian only if you publish to the Cloud Services, submit files for support, or otherwise direct the data to Meridian.
- Microsoft authentication. The Products use Microsoft account and Microsoft Entra ID authentication. Meridian does not need to receive or store your Microsoft password.
- Restricted data is not permitted in standard cloud or support use. Do not submit classified information, CUI, ITAR-controlled data, HIPAA/PHI, consumer health data, payment-card account data, or other Restricted Data through the Products, Cloud Services, or support unless Meridian has expressly agreed in signed terms. Classified information is never permitted.
- No sale of Customer Content. Meridian does not sell Customer Content and does not use Customer Content to train or improve artificial-intelligence or machine-learning models without prior consent.
- U.S. self-service focus. Standard self-service use is intended for users in the United States unless Meridian agrees otherwise in writing.
1. DEFINITIONS
1.1 “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual or household. It does not include information excluded from the scope of applicable privacy laws, such as publicly available information, lawfully deidentified information, or aggregate information.
1.2 “Customer Content” means schedules, project data, files, text, dashboards, reports, task assignments, comments, and other content that you or your organization submits to, publishes through, or otherwise makes available to the Cloud Services or to Meridian for support.
1.3 “Operational Data” means account, entitlement, subscription, security, device, diagnostic, licensing, and technical information generated or received by Meridian in administering, operating, securing, updating, or supporting the Products. Operational Data does not include the substantive contents of your schedules or project files.
1.4 “Cloud Services” means Meridian’s hosted dashboard publishing, sharing, viewing, authentication, and related online services.
1.5 “Local Software” means Meridian software installed on a user-controlled device, including the Microsoft Project add-in and local dashboard components.
1.6 “Products” mean Meridian’s downloads, account portal, checkout, Local Software, Microsoft Project add-in, local dashboard, Cloud Services, support, and related products and services. The Products do not include the Website.
1.7 “Website” means Meridian’s websites, web pages, and online marketing and informational properties, as described in Meridian’s Terms of Service.
2. HOW THE PRODUCTS COLLECT INFORMATION
2.1 Local Software. The Local Software can operate in a local-only workflow. In that workflow, schedule content is processed on your device and a local dashboard may be presented through a browser on the same device. Local-only use may still involve limited Operational Data, such as authentication, license administration, entitlement checks, version/update information, security logs, and support-related information.
2.2 Cloud Services. If you or your organization uses Cloud Services features, Customer Content may be transmitted to Meridian-hosted infrastructure so that dashboards can be published, shared, viewed, secured, maintained, supported, exported, and deleted. The Cloud Services is multi-tenant unless Meridian signs terms stating otherwise.
2.3 Support. If you submit a support request, screenshots, logs, schedule files, or other materials to Meridian, we process the information you provide to respond to the request, investigate the issue, improve reliability and security, maintain records, and comply with legal obligations. You are responsible for removing Restricted Data or sensitive information from support materials unless Meridian has expressly agreed in signed terms to receive it.
2.4 Website, checkout, and account interactions. When you visit our website, create an account, subscribe, purchase, renew, cancel, contact support, or communicate with Meridian, we collect information needed to operate those interactions, process transactions, send receipts and notices, secure accounts, and manage customer relationships.
3. NOTICE AT COLLECTION: CATEGORIES OF PERSONAL INFORMATION
The table below describes the categories of personal information Meridian may collect, the sources of that information, the purposes for collection and use, and the categories of recipients to whom the information may be disclosed. Not every category is collected from every user. Where applicable, this table is intended to operate as Meridian’s notice at collection. Meridian will not collect additional categories or use personal information for materially different purposes without providing any notice or consent required by law.
Examples: name, email address, username, account name, organization, title or role, billing address, business address, telephone number if provided, Microsoft tenant/domain/account identifiers, account IDs, and IP address.
Sources: you, your organization, Microsoft sign-in, checkout, support, and product administration.
Purposes: account creation, identity, authentication, subscriptions, support, notices, billing, security, and legal compliance.
Disclosures: service providers, payment processors, Microsoft and identity providers, your organization/account administrator where applicable, professional advisers, and legal authorities when required.
Examples: selected plan, product edition, seat type, quantity, modules, feature packages, add-ons, subscription term, renewal status, invoice/receipt records, payment status, taxes, discounts, support entitlements, order confirmations, and payment-processor transaction identifiers. Meridian does not need to receive or store full payment-card numbers for standard online checkout; those are handled by the payment processor.
Purposes: process purchases, administer subscriptions, renewals, cancellation, refunds, accounting, tax, fraud prevention, and customer support.
Disclosures: payment processors, tax/accounting providers, service providers, professional advisers, and legal authorities when required.
Examples: authorized domains, assigned users, permissions, entitlement records, usage limits, license status, product version, installation/update status, device type, operating system, browser, approximate location derived from IP address, diagnostic information, error/crash logs, authentication events, access logs, security logs, and support metadata.
Purposes: authenticate users, administer seats and add-ons, provide access, license administration, updates, security, fraud prevention, debugging, reliability improvement, incident response, and compliance.
Disclosures: cloud, identity, security, diagnostics, logging, support, and infrastructure service providers.
Examples: schedules, project data, files, text, dashboards, reports, task assignments, project roles, dates, dependencies, comments, support files, and project information that may be linked to an individual. Customer Content is transmitted to Meridian only when you or your organization publish it to the Cloud Services, submit it for support, or otherwise direct it to Meridian.
Purposes: host, publish, share, display, secure, maintain, troubleshoot, support, export, delete, and comply with lawful instructions or legal requirements.
Disclosures: cloud infrastructure and support providers, recipients you or your organization authorize, your organization/account administrator where applicable, professional advisers, and legal authorities when required.
Examples: emails, support tickets, support portal messages, issue descriptions, feedback, survey responses, call notes if created, and other communications with Meridian.
Purposes: respond to requests, provide support, improve reliability, document issues, manage customer relationships, send service notices, and maintain legal/business records.
Disclosures: support, email, customer relationship management, and professional service providers, and legal authorities when required.
Examples: cookie identifiers, session information, pages viewed, referring pages, browser/device data, approximate location derived from IP address, website analytics, consent preferences, and similar information.
Purposes: operate the website, maintain sessions, remember preferences, secure the site, understand website performance, improve website reliability, and, if enabled and disclosed, measure marketing effectiveness.
Disclosures: website hosting, security, analytics, cookie-management, and similar service providers.
Examples: employer, business unit, title, role, project team, and work contact details if provided by you, included in Customer Content, or supplied by your organization.
Purposes: account administration, access management, support, product permissions, and business communications.
Disclosures: service providers, your organization/account administrator where applicable, authorized dashboard recipients, and legal authorities when required.
Meridian does not intend to collect sensitive personal information through standard self-service use of the Products. Do not submit Social Security numbers, government ID numbers, precise geolocation, biometric information, health information, consumer health data, payment-card account data, classified information, CUI, ITAR-controlled data, HIPAA/PHI, or other Restricted Data through the Products, Cloud Services, or support unless Meridian has expressly agreed in signed terms. If sensitive information is incidentally processed, Meridian uses it only as necessary to provide the Products, secure accounts, process transactions through providers, comply with law, or as otherwise permitted by applicable law.
4. HOW WE USE PERSONAL INFORMATION
Meridian uses personal information for the following purposes:
Meridian limits collection, use, disclosure, and retention of personal information to what is reasonably necessary and proportionate for the disclosed purposes or for compatible purposes, unless Meridian provides additional notice or obtains consent where required by law.
- Provide, operate, maintain, update, secure, and support the Products.
- Create and administer accounts, authenticate users, assign seats, manage permissions, activate license keys, and administer modules, feature packages, add-ons, and usage limits.
- Process purchases, subscriptions, renewals, cancellations, refunds, taxes, invoices, receipts, and payment-related communications.
- Host, publish, share, display, export, and delete Customer Content when you or your organization use Cloud Services features.
- Troubleshoot issues, respond to support requests, diagnose errors, prevent abuse, investigate security events, and improve Product security and reliability.
- Send service, security, legal, billing, renewal, cancellation, and administrative notices.
- Send marketing or product communications where permitted by law, subject to your opt-out choices.
- Enforce our agreements, protect Meridian, our users, and others, prevent fraud or misuse, and comply with law, legal process, tax/accounting obligations, and regulatory requests.
- Evaluate or complete a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar business transaction.
5. CUSTOMER CONTENT, ARTIFICIAL INTELLIGENCE, AND AUTOMATED DECISIONS
Meridian does not sell Customer Content. Meridian does not use Customer Content to train or improve artificial-intelligence or machine-learning models without prior consent. Meridian may use Operational Data to operate, secure, support, and improve the reliability of the Products.
The Products provide analytical, scheduling, reporting, dashboard, and decision-support tools. Meridian does not use personal information to make automated decisions that produce legal or similarly significant effects about individuals, such as decisions about employment, credit, housing, insurance, education, criminal justice, or access to essential goods or services.
If Meridian later offers AI-enabled or automated-decision features, Meridian will provide additional disclosures or terms where required by law.
6. HOW WE DISCLOSE PERSONAL INFORMATION
Meridian may disclose personal information to the following categories of recipients for the purposes described in this Privacy Policy:
| Purpose | Provider / recipient category |
|---|---|
| Cloud hosting, compute, storage, databases, networking, backups, logging, monitoring, and security | Microsoft Azure and related Microsoft infrastructure services |
| Identity and authentication | Microsoft Entra ID / Microsoft account sign-in and related authentication services |
| Support communications and files | Microsoft 365 |
| Payments, receipts, taxes, and subscription billing | Stripe, Xero |
| Website hosting, security, cookies, and analytics | Vercel Inc. |
| Email, customer communications, and marketing | Microsoft 365 |
| Professional advisers and compliance | Attorneys, accountants, auditors, insurers, and other professional advisers |
We may also disclose information to users and recipients you or your organization authorize, such as people invited to view dashboards or receive reports; to account administrators or organization contacts who manage subscriptions, users, permissions, billing, and support; to comply with law or legal process; to protect rights, safety, security, and integrity; with your consent or at your direction; or as part of a business transaction.
7. SALES, SHARING, TARGETED ADVERTISING, AND MARKETING
Meridian does not sell personal information as that term is defined under applicable privacy laws. As currently configured, Meridian does not share personal information or Customer Content for cross-context behavioral advertising, and Meridian does not process personal information for targeted advertising within the Products.
If Meridian later uses advertising cookies, retargeting pixels, or similar technologies that constitute a sale, sharing, or targeted advertising under applicable law, Meridian will update this Privacy Policy and provide required notices and opt-out mechanisms before or at the time those technologies are used. Where legally required, Meridian will provide a clear opt-out link or mechanism and honor recognized browser, device, or platform opt-out preference signals for sales, sharing, or targeted advertising.
Your Privacy Choices — opt out of sale, sharing, and targeted advertising. Even though Meridian does not currently sell or share personal information or use it for targeted advertising, the following opt-out mechanisms are in place so that they apply automatically if any analytics tool, website tag, pixel, or advertising technology Meridian later uses qualifies as a sale, sharing, or targeted advertising under applicable law: a “Your Privacy Choices” link and cookie-preferences tool at meridianone.app/privacy-choices, where you can opt out of non-essential cookies and of any sale, sharing, or targeted advertising; recognized opt-out preference signals, such as the Global Privacy Control (GPC), which Meridian will treat as a valid opt-out request for the browser or device that sends it; and the email and portal options in Section 12. Opting out will not deny you the Products or change their price or quality, and an authorized agent may submit an opt-out request on your behalf where permitted by law.
You may unsubscribe from marketing emails by using the unsubscribe link in the email or by contacting us. Even if you opt out of marketing, we may still send transactional, service, security, legal, billing, renewal, and administrative notices.
8. COOKIES, SIMILAR TECHNOLOGIES, AND DO-NOT-TRACK SIGNALS
Meridian websites and online services may use cookies, pixels, local storage, SDKs, log files, and similar technologies to operate the website and Products, maintain sessions, remember preferences, secure services, prevent fraud, understand website performance, and improve reliability.
Meridian uses only the categories of technologies that are active on its website at a given time, grouped as follows:
- Strictly necessary — required to run the website and Products, maintain sessions, authenticate you, and keep services secure. These are always active and cannot be switched off.
- Functional or preference — remember your settings and choices to improve your experience.
- Analytics or performance — help Meridian understand how the website and Products are used and improve their reliability.
- Advertising or targeting — used to measure or deliver advertising, including across different websites and services. If Meridian enables these, they may constitute a sale, sharing, or targeted advertising under applicable law, and the opt-out choices in Section 7 apply.
Where required by law, Meridian obtains your consent for, or provides an opt-out from, non-essential cookies (functional, analytics, and advertising or targeting) through its cookie or consent tool at meridianone.app/privacy-choices before or at the time those technologies are used. You can change your choices at any time through that tool or your browser settings.
You can control cookies through browser settings and, where available, Meridian’s cookie or consent tools. Blocking some cookies may affect website or Product functionality.
Some browsers transmit “Do Not Track” signals. Because there is not a uniform industry or legal standard for responding to Do Not Track signals, Meridian does not respond to them. Where required by applicable law, Meridian will honor recognized opt-out preference signals, such as Global Privacy Control, for sales, sharing, or targeted advertising. Because Meridian does not currently sell or share personal information or process it for targeted advertising, such signals should not affect core Product functionality.
Other parties may collect information about your online activities over time and across different websites or online services when you use Meridian websites or services if Meridian uses third-party analytics, embedded content, marketing pixels, chat widgets, or similar providers. Meridian will identify material providers and provide choices where required by law.
9. RETENTION
Meridian retains personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Products, maintain accounts, administer subscriptions, comply with legal, tax, accounting, and audit obligations, resolve disputes, enforce agreements, protect security, and maintain business records.
Retention periods vary based on the nature of the information and the purpose for which it is processed. Meridian uses the following retention criteria:
- Account, subscription, entitlement, and billing records are retained while the account or subscription is active and for the period reasonably necessary for accounting, tax, audit, legal, and dispute-resolution purposes.
- Customer Content in the Cloud Services is retained during the applicable subscription and available 30-day post-termination export period described in the Terms, then deleted or deidentified unless law or legitimate business needs require retention. Routine backups are deleted or overwritten in the ordinary course.
- Support communications and support files are retained as needed to provide support, document issues, improve reliability and security, maintain records, and comply with law. Meridian may delete or return support files sooner where appropriate.
- Security, diagnostic, and operational logs are retained for periods appropriate to security, fraud prevention, debugging, service reliability, and legal/compliance needs.
- Marketing contact information is retained until you unsubscribe or request deletion, subject to Meridian maintaining suppression records to honor your opt-out.
When Meridian no longer needs personal information, it will delete, deidentify, aggregate, or retain it only as permitted or required by law.
10. SECURITY
Meridian uses commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, use, alteration, disclosure, loss, or destruction. These safeguards may include role-based access controls, least-privilege access, privileged-access multi-factor authentication, encrypted transport, encryption at rest using hosting-platform capabilities, logging, monitoring, backup and recovery procedures, provider security controls, and confidentiality obligations for personnel and service providers.
No method of transmission or storage is completely secure. You are responsible for maintaining the security of your devices, Microsoft account, Microsoft tenant, identity settings, users, permissions, credentials, local files, and backups. Notify Meridian promptly if you believe your account or Product access has been compromised.
11. BUSINESS CUSTOMERS, ACCOUNT ADMINISTRATORS, AND ORGANIZATIONAL USERS
If you use the Products through an employer, client, project team, or other organization, that organization may control the account, subscription, users, permissions, authorized domains, Customer Content, and Cloud Services sharing. Organization administrators may be able to access, disclose, restrict, export, or delete information associated with the organization account.
For personal information in Customer Content that Meridian processes on behalf of a business customer, Meridian generally acts as a processor, service provider, contractor, or subprocessor, and the business customer is responsible for providing notices, obtaining rights and consents, and responding to privacy requests. The Data Processing Terms in Section 26 of Meridian’s Terms of Service govern Meridian’s processing of that personal data as a processor, service provider, or contractor. Direct requests about organization-controlled Customer Content to your organization unless Meridian instructs otherwise.
12. YOUR CHOICES AND PRIVACY RIGHTS
12.1 Account, correction, and deletion choices.
You may update certain account information through your account settings or by contacting Meridian. You may request correction, deletion, access, or export of personal information by contacting us using the methods in Section 18. We may retain information where permitted or required by law, including for security, legal, tax, accounting, dispute-resolution, fraud-prevention, and contractual purposes.
12.2 State privacy rights.
Depending on where you live and whether an applicable privacy law applies to Meridian, you may have rights to:
- confirm whether Meridian processes your personal information, access that information, and, where applicable, know the categories and specific pieces of personal information Meridian has collected about you;
- obtain a copy of personal information in a portable and, where technically feasible, readily usable format;
- obtain a list of the categories of third parties, or where required and available, the specific third parties, to which Meridian has disclosed personal information;
- correct inaccurate personal information;
- delete personal information;
- opt out of sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, and profiling in furtherance of decisions that produce legal or similarly significant effects, if applicable;
- limit certain uses or disclosures of sensitive personal information, if applicable;
- withdraw consent where processing is based on consent;
- appeal a refusal to act on a privacy request, where applicable; and
- not be discriminated against for exercising privacy rights.
To exercise privacy rights, email privacy@meridianone.app or use meridianone.app/privacy-request. Please include enough information for Meridian to verify your identity and understand your request. You do not need to create a new account to submit a privacy request, but Meridian may require you to use an existing account or provide information reasonably necessary to authenticate the request where permitted by law. Meridian may decline or limit requests where allowed by law, including where it cannot verify the request, the information is organization-controlled Customer Content, the request conflicts with legal obligations, or an exception applies.
Authorized agents may submit requests where permitted by law. Meridian may require proof that the agent is authorized and may ask you to verify your identity directly, except where law provides otherwise. Meridian will respond within the time required by applicable law, for example within 45 days where that response period applies, and may extend the response period where allowed. If Meridian denies a request, you may appeal by emailing privacy@meridianone.app with the subject line “Privacy Appeal” or by using meridianone.app/privacy-request.
12.3 California-specific disclosures.
This Section 12.3 supplements the rest of this Privacy Policy for California residents. The categories of personal information Meridian may collect, and the categories Meridian may disclose for business purposes, are described in Section 3. The categories of sources, purposes, and disclosure recipients are described in Sections 3, 4, and 6. The retention criteria are described in Section 9.
Meridian does not knowingly sell or share personal information of consumers under 16. Meridian does not currently sell personal information or share personal information for cross-context behavioral advertising. Meridian does not use or disclose sensitive personal information to infer characteristics or for other purposes that would require a right to limit under California law. Meridian will honor recognized opt-out preference signals, such as Global Privacy Control, where required by applicable law, although those signals do not affect core Product functionality when Meridian is not selling, sharing, or using personal information for targeted advertising. Meridian does not offer financial incentives or price/service differences in exchange for the collection, sale, sharing, or retention of personal information unless disclosed at the time of the offer.
California’s “Shine the Light” law allows California residents to request certain information about disclosures of personal information to third parties for their direct marketing purposes. Meridian does not disclose personal information to third parties for their own direct marketing purposes without consent. You may send Shine the Light requests to privacy@meridianone.app.
12.4 Deidentified and aggregated information.
Meridian may create or use deidentified or aggregated information for security, analytics, reliability, research, reporting, and business purposes. Where Meridian maintains information as deidentified, it will maintain and use the information in deidentified form and will not attempt to reidentify it except as permitted by law, such as to determine whether deidentification processes are adequate.
13. CHILDREN
The Products are intended for adults and professional or business users. They are not directed to children under 13, and Meridian does not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to Meridian, contact privacy@meridianone.app and Meridian will take appropriate steps to delete the information as required by law.
14. INTERNATIONAL TRANSFERS
Meridian is based in the United States. Personal information may be processed in the United States and in other locations where Meridian and its service providers operate. These locations may have privacy laws different from those in your location. Standard self-service use is intended for users in the United States unless Meridian agrees otherwise in writing.
15. EUROPEAN ECONOMIC AREA, UNITED KINGDOM, AND SWITZERLAND
15.1 Scope and roles.
This Section applies where the EU General Data Protection Regulation (GDPR), the UK GDPR, or Swiss data protection law applies to Meridian’s processing of your personal information. Where those laws apply and Meridian determines the purposes and means of processing (for example, account, billing, website, security, and support information that Meridian handles for its own purposes), Meridian acts as a controller. Where Meridian instead processes personal data in Customer Content on behalf of a business customer, Meridian acts as a processor and the business customer is the controller; that processing is governed by the Data Processing Terms in Section 26 of Meridian’s Terms of Service, and you should direct requests to that organization.
15.2 Legal bases.
When Meridian acts as a controller, it processes personal information where necessary to perform a contract with you or to take steps at your request before entering into one, such as creating an account, processing a purchase, or providing support; where necessary for Meridian’s legitimate interests in operating, securing, and improving the Products and Website, provided those interests are not overridden by your rights; to comply with a legal obligation; or with your consent, which you may withdraw at any time.
15.3 Your rights.
Subject to applicable law, you may request access to, and rectification or erasure of, your personal information; restrict or object to certain processing; and receive personal information you provided to Meridian in a portable format. Where processing is based on consent, you may withdraw that consent without affecting processing carried out before withdrawal. Meridian will respond within the time required by law. You may also lodge a complaint with your local data protection supervisory authority, although Meridian encourages you to contact it first, using the details in Section 18 (Contact Meridian), so it can address your concern.
15.4 International transfers.
Meridian is based in the United States and may process personal information there and in other countries whose laws may differ from those where you live. Where Meridian transfers personal information that is protected by the GDPR, UK GDPR, or Swiss law out of those jurisdictions, it relies on an approved transfer mechanism (such as the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum or the Swiss addendum where applicable) or on another lawful basis for the transfer. You may request more information about these safeguards using the contact details in Section 18 (Contact Meridian).
16. THIRD-PARTY PRODUCTS, LINKS, AND SERVICES
The Products may rely on or integrate with third-party products and services, including Microsoft Project, Microsoft 365, Microsoft Entra ID, Microsoft Azure, payment processors, browsers, operating systems, and other tools. Third-party services are governed by their own terms and privacy notices. Meridian is not responsible for third-party privacy or security practices.
17. CHANGES TO THIS PRIVACY POLICY
Meridian reviews this Privacy Policy periodically and may update it from time to time. The “Last Updated” date above shows when it was last revised. If Meridian makes material changes, Meridian will provide notice through the website, account portal, email, Product notice, or another reasonable method as required by law. The updated Privacy Policy will apply prospectively as of the effective date stated in the updated version, unless law permits otherwise.
18. CONTACT MERIDIAN
MeridianONE Technologies Inc.
Privacy Email: privacy@meridianone.app
Privacy Request Portal: meridianone.app/privacy-request
Support: support@meridianone.app
For organization-controlled Customer Content, contact your organization administrator first. For business customer data-processing terms, contact Meridian at legal@meridianone.app.