Skip to content
MMEERISYSTEMS
WebsitesOnline bookingGoogle + AI visibilityAI Search NEWProofAbout
Talk to Meeri
WebsitesOnline bookingGoogle + AI visibilityAI Search Visibility · NewProofAboutTalk to Meeri

Legal · Client data

DATA PROCESSING

MEERI SYSTEMS LTDPLAIN-ENGLISH LEGAL INFORMATIONLast updated 7 August 2026

These terms form the Article 28 processing agreement when Meeri handles personal data on a Client's behalf.

These pages work together. Website use is covered by the website terms. Paid work is covered by the accepted proposal and client terms.

Ask a legal or privacy question →
01

When these terms apply

These data-processing terms (“DPT”) apply where Meeri Systems Ltd processes personal data as a processor for the Client under an accepted proposal or order. They supplement the client terms. The Client is the controller and Meeri is the processor unless a project schedule correctly identifies a different role.

“Data Protection Law” means the UK GDPR, Data Protection Act 2018 and applicable Privacy and Electronic Communications Regulations, each as amended. Other data-protection expressions have the meanings given by that law.

02

Scope and documented instructions

The accepted proposal, service configuration, these DPT and the Client's lawful written directions are the Client's documented instructions. Meeri will process Client Personal Data only to deliver, secure, support and end the agreed services, or as required by UK law. If law requires other processing, Meeri will inform the Client before it occurs unless the law prohibits that notice.

Meeri will tell the Client if, in its reasonable view, an instruction infringes Data Protection Law and may pause that processing while the parties resolve it. Instructions outside the agreed service may require a written scope and reasonable additional fee.

03

Meeri's processor duties

Meeri will:

  • ensure people authorised to process Client Personal Data are bound by confidentiality;
  • apply the technical and organisational measures described below, taking account of risk, current technology, implementation cost and the nature of processing;
  • help the Client respond to data-subject requests, taking account of the nature of processing;
  • provide reasonable assistance with security, breach notification, data-protection impact assessments and regulator consultation relevant to Meeri's processing;
  • maintain records and information needed to demonstrate compliance with these DPT; and
  • not sell Client Personal Data, use it for advertising, or use it to train a public AI model.
04

Sub-processors

The Client gives general authorisation for Meeri to use the sub-processors listed below and any project-specific provider identified in the proposal or processing schedule. Meeri will impose written data-protection obligations offering materially equivalent protection for the relevant processing and remains responsible for a sub-processor's performance of those obligations.

ProviderServiceLikely processing location or safeguard
Cloudflare, Inc.Website delivery, hosting, network security and logsGlobal infrastructure; UK adequacy where applicable, including active UK Extension certification, or contractual safeguards
Resend, Inc.Transactional and website-form email deliveryUnited States; active Data Privacy Framework participation and contractual safeguards
Google LLC / Google WorkspaceBusiness email, documents and controlled working recordsGlobal infrastructure; UK adequacy where applicable, including active UK Extension certification, or contractual safeguards

Meeri will give at least 14 calendar days' written notice before adding or replacing a sub-processor of Client Personal Data, and the Client may object within that period on reasonable, documented data-protection grounds. The parties will try to resolve the objection; if no reasonable solution is available, either party may end the affected service before the change applies, without a cancellation penalty. General suppliers that do not process Client Personal Data are not sub-processors and are not covered by this clause.

05

International transfers

Meeri will not make a restricted transfer of Client Personal Data unless the transfer is covered by UK adequacy regulations or an appropriate safeguard under Data Protection Law. Depending on the provider and transfer, this may include an active UK Extension to the EU–US Data Privacy Framework certification, the UK International Data Transfer Agreement, or the UK Addendum to approved standard contractual clauses, together with any assessment and supplementary measures reasonably required.

Meeri will periodically verify material certification relied on and use an alternative lawful safeguard if that certification no longer applies.

06

Security measures

Measures appropriate to the standard service include:

  • encrypted HTTPS connections and encryption used by approved providers in transit and at rest where supported;
  • role-based and least-privilege access, strong authentication and multi-factor authentication where available;
  • managed infrastructure, dependency maintenance, malware and abuse controls, and security logging;
  • separation of Client environments or logical access boundaries where relevant;
  • resilience, backup and restoration arrangements proportionate to the service;
  • staff confidentiality, access review, provider due diligence and incident procedures; and
  • secure deletion or anonymisation when information is no longer required.

The proposal must state any higher or sector-specific standard, recovery objective, penetration test, certification or hosting-location commitment required by the Client.

07

Incidents and requests

After becoming aware of a personal data breach affecting Client Personal Data, Meeri will notify the Client without undue delay and provide available information reasonably needed for the Client's assessment and notification duties. Meeri's notice is not an admission of fault.

If Meeri receives a rights request or regulator communication relating to Client Personal Data, it will not respond substantively except on the Client's instructions or where law requires. It will pass the matter to the Client without undue delay and provide reasonable technical assistance. The Client remains responsible for the legal response and identity checks.

08

Return, deletion and audit

At the end of the affected service, Meeri will, at the Client's choice and subject to agreed export formats, return or delete Client Personal Data held by Meeri. The Client should request or complete any available export within 30 calendar days after the service ends; after that window Meeri securely deletes remaining active copies unless UK law requires retention, and copies in inaccessible backups expire through the normal secure deletion cycle. Data in accounts the Client owns directly is not controlled or deleted by Meeri.

On reasonable request, Meeri will first provide written information needed to demonstrate compliance with these DPT. If that is not enough, the Client may arrange one routine audit in any 12-month period on at least 20 working days' written notice, during normal business hours, using an independent auditor bound by confidentiality, with a reasonable agreed scope and safeguards for other clients' information. These limits do not prevent a regulator exercising its powers, an audit required by law, proportionate investigation after a personal-data breach, investigation where credible evidence indicates material non-compliance, or an urgent audit that cannot reasonably wait. The Client normally bears its own audit costs; Meeri will not charge the Client for reasonable additional cooperation made necessary by Meeri's established material breach or incident.

09

Responsibility and order of terms

The Client is responsible for the lawfulness, fairness and transparency of its processing; its lawful basis; notices and consent where needed; data minimisation; accuracy; retention instructions; and the legality of data and instructions supplied to Meeri. Meeri is responsible for compliance with obligations applying directly to it as processor.

The liability provisions in the client terms apply to these DPT. If these DPT conflict with the client terms on protection of Client Personal Data, these DPT take priority. A project-specific processing schedule takes priority over the standard processing description below where it expressly says so.

10

Standard processing description

Subject and purposeOperating, hosting, securing, supporting and ending the website, enquiry, booking, quote or related digital service described in the proposal.
DurationFor the service term plus the agreed export, retention and secure-deletion period.
ActivitiesCollection, transmission, organisation, storage, retrieval, display to authorised users, support, export, backup and deletion, as needed for the service.
PeopleThe Client's prospective and actual customers, website users, staff, contractors, suppliers and business contacts.
DataNames, business and contact details, enquiry or booking information, service preferences, correspondence, technical identifiers, security logs, payment status and other fields expressly agreed. Meeri does not need full payment-card data for the standard service.
Sensitive dataSpecial-category data, criminal-offence data and children's data are excluded unless a signed project schedule, risk assessment and suitable controls expressly permit them.
Controller instructionsThe accepted proposal, configured fields and workflows, retention settings, support requests and other lawful written directions from an authorised Client contact.

Before a Conversion Booking System launches, the proposal should confirm the actual fields, integrations, retention, authorised users, sub-processors, incident contacts and exit format for that Client.

MMEERISYSTEMS

Built in Newcastle. Working across the UK.

WEBSITES BUILT FOR GOOGLE AND AI SEARCH.

ServicesWebsitesOnline bookingGoogle + AI visibilityAI Search Visibility
ExploreStarting a businessZero TransportAbout Meeri
Contacthq@meerisystems.co.uk07791 447423WhatsApp MeeriStart a project
LegalPrivacy noticeCookie noticeWebsite termsClient termsData processingCancellation & exit

Meeri Systems Ltd · Registered in England and Wales · Company No. 17339290 · Registered office: 59 Wingrove Road, Newcastle upon Tyne, NE4 9BS · © 2026

PrivacyCookiesClient terms