Privacy Policy
Last updated 2026-10-02 · English version; a German version (Datenschutzerklärung) is available on request and takes precedence for users in Germany, Austria and Switzerland.
1. Controller
The controller for personal data processed on meridian-move.io and in the Meridian Move platform is:
SarvanX FZ-LLC (trading as Meridian Move)Free Zone Limited Liability Company · Trade Licence No. 47005793
Licensed activity: Information Technology Consultants
Shed No. 19 – Al Hulaila FZ S19W0616
Al Hulaila Industrial Free Zone
Ras Al Khaimah, United Arab Emirates
Contact for all privacy matters, including every request under section 8: privacy@meridian-move.io. We answer within 30 days. No data protection officer and no Art. 27 GDPR representative in the Union has been formally appointed; use the address above for all data protection matters.
2. What we process, why, and on which legal basis
- Website usage (first-party, cookieless): page path, event type (e.g. page view, pricing view, tool use), referrer host, and a daily-rotating, non-reversible visitor hash derived from IP address and browser string. No cookies, no cross-site tracking, no IP or user-agent stored in clear. Purpose: measuring which content and products are useful. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). We honour Do-Not-Track and Global Privacy Control.
- Account and profile data (candidates, employers): e-mail, name, the profile and documents you enter (e.g. CV text, skills, target roles), tool results you generate. Purpose: providing the service you signed up for. Legal basis: contract (Art. 6(1)(b)).
- Payments: handled by Stripe; we store the plan, purchase and settlement status, never card details. Legal basis: contract and legal obligations (Art. 6(1)(b),(c)).
- Business contacts (employers, partners): company name, role, business e-mail, correspondence. Purpose: offers, delivery and support. Legal basis: contract or legitimate interest. We only contact you for marketing with consent or an existing customer relationship, always with an opt-out.
- Public job postings and open statistics: we aggregate public employer job postings (Greenhouse, Lever, Arbeitnow, Remotive, Jobicy, The Muse, Bundesagentur für Arbeit) and open statistics (Eurostat, ESCO, edX catalogue). These contain no candidate data; each record carries its source and retrieval date.
3. AI agents and automated decisions
Parts of Meridian Move are operated by AI agents (research, content, analysis). No automated decision with legal or similarly significant effect is made about you: there is no automated hiring, rejection, ranking or employment decision. Candidate tools (CV check, skill gap, learning path, interview preparation) produce feedback for you only and are never used to rank you for employers. You can request human review of any assessment at any time.
4. Talent Discovery
Talent Discovery is an optional candidate-only feature. Before a file is selected or CV text is processed, the screen names the two exact, independently configured AI providers and models used for generation and adjudication, the purpose, the filtered data sent, each provider retention setting, and the consent version. If those configured facts, either data-processing agreement, training-disabled status, either role-specific budget, taxonomy manifest or storage safeguards cannot be verified, the feature stays unavailable.
- Purpose and legal basis: forming three provisional talent hypotheses for the account holder alone from separately written, self-reported and owner-attested structured work examples, based on explicit consent (Art. 6(1)(a) GDPR). Meridian does not verify the truth of those examples. The result is not psychometric or predictive, is not an assessment for employers and is not used for employability, ranking, matching or hiring.
- Data and recipients: A CV is optional. Meridian processes CV text ephemerally on its server only to return advisory reflection lines. It never creates countable evidence; the application does not persist or intentionally log it, and it is not sent to an AI provider. The account holder must separately write at least six achievement records, classify each with controlled action and context fields, select each one and attest that it accurately reflects their experience. Those statements are also sent transiently to Meridian's server solely for format validation and a keyed digest; Meridian does not verify their truth. The application does not persist or intentionally log their prose and does not send it to an AI provider. Infrastructure logs and retention are governed by the deployed processor configuration and data-processing agreements; the feature remains unavailable unless those boundaries are verified. A preview or record refresh does not read or write the application database, use quota or contact a provider. The short-lived signed token contains canonical action/context values, keyed one-way digests of the owner-authored statements, a hashed account binding, the selected evidence language, consent/configuration/parser/taxonomy versions, timestamps and a random nonce; it contains no account UUID, CV prose, achievement prose or contact data. Only the individually selected and confirmed canonical records may then be sent to the separately configured generation and adjudication provider/models disclosed immediately before consent. Results describe these as self-reported, user-confirmed work examples, not CV quotes or verified facts. Training must be disabled for both recipients; both configured retention periods are shown before consent. Where a recipient is outside the EEA, the transfer safeguards described in section 6 apply.
- Meridian retention: validated hypotheses, their canonical confirmed evidence summaries, corrections and version provenance remain private in the account until the person deletes them, withdraws consent or deletes the account. Run/reservation metadata contains no CV content and is deleted after 48 hours. The preview token expires after 15 minutes and its one-way digest is used only to prevent replay.
- Withdrawal: consent can be withdrawn in Talent Discovery at any time. Withdrawal deletes saved results and invalidates pending reservations. A provider request already dispatched cannot be recalled, but Meridian does not retry or save its answer after withdrawal.
5. Sunny services
Sunny is an AI-generated service persona with two technically separate areas. Signed-in talent accounts can use Career Orientation. Signed-in employer accounts can submit a client inquiry. Employer inquiries never provide access to talent conversations or candidate data.
- Talent processing and purpose: Career Orientation asks eleven fixed, optional questions about work experience, strengths and work preferences. Answers, deliberate skips and a locally composed summary are stored under the talent account to provide the requested orientation conversation (Art. 6(1)(b) GDPR). The active release does not send those answers to an external AI provider, rank a person, make employment decisions or expose the conversation to employers through the product.
- Choice and minimisation: every question may be skipped. Users are warned not to enter health, political, union, family, identity-document, contact or other sensitive information. Browser dictation is optional; a browser or its speech vendor may process audio, while Meridian receives only the transcript the user chooses to submit.
- Employer client intake: an employer may submit a topic, free-text business request, contact name and, optionally, a callback number. The purpose is to record and display the employer's requested recruiting, commercial or support enquiry in its workspace (Art. 6(1)(b) or steps requested before a contract). A phone number is accepted only after explicit callback consent. Do not submit candidate documents or special-category personal data. The employer can see only its own requests; authorised support may access them only to operate, secure or respond to the service.
- Access and retention: employers and other members cannot read talent Sunny sessions. Talent sessions remain in the account until the user deletes the Sunny history or deletes the account; deleting the history removes its conversations, turns and summaries. To prevent abuse, start-event timestamps remain for the rolling 24-hour limit even when conversation content is deleted. A database retention job runs every 15 minutes and deletes events older than 24 hours (maximum normal retention: 24 hours 15 minutes). Employer intake records are scheduled for deletion 90 days after receipt; an hourly job may take up to one additional hour. Account deletion also removes the account's Sunny records.
6. Social media and LinkedIn
Meridian Move publishes company updates on its own LinkedIn company page. When our operator connects that page through LinkedIn’s Community Management API, we process:
- the operator’s LinkedIn authorisation (OAuth access and refresh tokens) — stored encrypted at rest, server-side only, used solely to publish and read statistics for the Meridian Move company page, and deleted/revoked when the connection is removed;
- the company page’s own identifiers and aggregated page statistics (impressions, clicks, follower counts).
We do not collect, store or scrape LinkedIn member profiles, connections or messages; we send no direct messages and do not automate engagement (likes, comments, follows) on other members’ content. LinkedIn data is used only for the purposes permitted by LinkedIn’s API terms and is not sold or shared with third parties. LinkedIn’s own processing is governed by the LinkedIn Privacy Policy. If you interact with our posts on LinkedIn, that interaction is visible to us only as LinkedIn shows it on our page.
7. Processors and recipients
- Supabase (database and authentication, EU region where available)
- Vercel (hosting)
- Stripe (payments)
- Anthropic or OpenAI (only the exact configured AI provider/model disclosed at the point of consent; inputs are minimised and never include payment data)
- Resend (transactional e-mail, once enabled)
- LinkedIn (company-page publishing, see section 6)
Transfers outside the EU/EEA rely on adequacy decisions or the EU Standard Contractual Clauses. We do not sell personal data.
8. Retention
Account data: for the life of the account and up to 30 days after deletion. Usage events: 13 months, then aggregated. Public job postings: refreshed continuously and expired when no longer listed at the source. Social-media tokens: until disconnected or expired; revoked on disconnect. Payment records: as required by tax law. Audit logs of automated actions: 24 months.
9. Your rights
You have the right to access, rectify, erase, restrict and port your data, to object to processing based on legitimate interest, to withdraw consent at any time, and to lodge a complaint with a supervisory authority (for EU residents, the authority of your member state). Write to privacy@meridian-move.io; we answer within 30 days. Account deletion is available in your profile settings.
10. Security
Transport encryption (TLS), encrypted storage of credentials and tokens, least-privilege service roles, row-level security in the database, kill switches for automated actions, and audit trails for every external action performed by an agent.
11. Changes
We update this policy when our processing changes and show the date at the top. Material changes are announced on the platform.