Privacy Policy
Last updated: September 9, 2026
1. Who We Are
WireApps Ltd (company number 13117874) ("Meridian", "we", "us") operates the Meridian project management platform. For most of the personal data described below, Meridian acts as a data processor on behalf of the organisation that has an account ("Customer"), and the Customer is the data controller. Where Meridian collects data about the Customer itself (billing contact, account admin details) for its own business purposes, Meridian is the controller, see §4.
Registered office: 16 Eaton Road, Bowdon, Altrincham, England, WA14 3EH. Contact for privacy questions: info@meridian4pm.com.
2. Scope
This policy covers:
- Account and billing data, about the people and organisations that sign up for Meridian.
- Customer Data, the project management data a Customer's users put into Meridian on the Customer's behalf (projects, risks, RAID entries, change requests, stakeholder records, sprint and retrospective content, status reports, and time-tracking entries).
For Customer Data, this policy sits alongside the Data Processing Addendum (available to Customers on request), which governs the controller/processor relationship in more technical and contractual detail. Where they conflict for Customer Data specifically, the DPA controls.
3. What We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, work email, hashed password, organisation name, role | You, at signup or invite |
| Usage data | Login timestamps, feature usage, session activity | Automatically, via the Service |
| Customer Data | Project names, risk register entries, change requests, stakeholder names/roles, retrospective cards, status reports, time-tracking entries (start/end times, durations, task/project association) | You and your users, while using the Service |
| Communications | Support requests, beta programme feedback | You, when you contact us |
| Technical/log data | IP address, browser/device information, error logs | Automatically |
We do not currently collect payment card data directly. If card payments are enabled in future, our payment processor will become a subprocessor for that data and this section will be updated.
We also use a small number of cookies and similar browser-storage technologies to provide the Service; see our Cookie Policy for the complete list and what each one does.
4. Why We Process It (Lawful Basis)
| Purpose | Lawful basis |
|---|---|
| Providing the Service you signed up for | Performance of a contract |
| Billing | Performance of a contract / legal obligation (tax records) |
| Security, fraud prevention, abuse monitoring | Legitimate interests |
| Product improvement, aggregated/anonymised analytics | Legitimate interests |
| Marketing communications (if any) | Consent |
5. Who We Share It With (Subprocessors)
We use the following subprocessors to provide the Service. We will update this list as it changes; material changes affecting Customer Data are also governed by the subprocessor-notice clause in the Data Processing Addendum.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Managed PostgreSQL database hosting, where all account and Customer Data is stored | Meridian's production data is hosted in Supabase's ap-southeast-1 (Singapore) region. A separate Supabase project is used for Meridian's own internal development and testing and never holds real Customer Data. |
| Vercel | Application hosting, edge middleware, deployment | Vercel's infrastructure operates globally; Meridian does not currently commit to a specific data-residency region for application compute. |
| Resend | Transactional email delivery (signup confirmation, password reset, notifications) sent from the meridian4pm.com domain | Resend is a US-based email delivery provider; transactional email content passes through US infrastructure. |
We do not currently use any AI/LLM subprocessor for processing Customer Data. AI-assisted status report drafting is a planned, not-yet-built feature; if that ships, this table and the Data Processing Addendum's subprocessor list must be updated before the feature goes live to anyone other than internal WireApps users, since it would introduce a new subprocessor and a new data flow.
We do not sell personal data, and we do not share Customer Data with any third party except the subprocessors above, as required by law, or as instructed by the Customer.
6. Data Retention
- Account data: retained for as long as the account is active, plus 90 days after closure to allow reactivation, then deleted or anonymised, except where we must retain records for legal/tax purposes.
- Customer Data: retained for as long as the Customer's account is active. Following termination, retained and made available for download and extraction for 60 days (6 months where WireApps terminated for non-payment), per Terms of Service clause 20.4, and deleted thereafter, except where retention is legally required.
- Backups: Backups are retained per our database provider's standard backup policy; deleted data may persist in backups for a limited period before being purged.
7. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port your personal data, and to object to certain processing. If you are a user invited into a Customer's organisation, your organisation's Admin is normally the right first point of contact for correcting or exporting your account data, since they control your access, we will also respond directly to requests we receive.
To exercise these rights, contact info@meridian4pm.com.
8. Security
We maintain technical and organisational measures appropriate to the risk, including: application-layer tenant isolation (every database query is scoped to the requesting organisation), encrypted connections in transit, hashed password storage, and role-based access control within each organisation. Further technical detail is in the Data Processing Addendum (available to Customers on request).
No system is completely secure; if we become aware of a breach affecting your personal data, we will notify affected Customers without undue delay and in line with applicable law.
9. Children
Meridian is a business product not directed at children, and we do not knowingly collect personal data from anyone under 18 years old.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be notified to Customer Admins by email at least 30 days before taking effect.
11. Contact
info@meridian4pm.com · 16 Eaton Road, Bowdon, Altrincham, England, WA14 3EH
If you are in the UK/EU and believe we have not resolved a complaint satisfactorily, you have the right to complain to your local supervisory authority (in the UK, the ICO).
See also: Terms of Service. The Data Processing Addendum is available to Customers on request.