Meridian HR
PlatformCountriesPayrollAdaWhy Meridian
Sign in
/ legal — 01   privacy notice
Last updated · 2026-05-20

Your data. Your team's data.
Handled like a contract — not a feature.

This notice covers how Meridian HR Ltd processes personal data when an employer (our customer) runs people operations on our platform — including their employees, candidates, and contractors. We wrote it to be read, not skimmed-past. Where the law uses jargon, we say what we mean. The legally binding version is the English text below.

01Privacy Notice02Terms of Service03Data Processing Addendum

The version that fits on one screen.

/ at a glance — 06 points
01
We're a processor for employee data.
Your employer decides what to do with their team's data. We just run the rails — under their instructions, in writing.
02
Hosted in Africa, primarily.
Primary region: Cape Town (af-south-1). Failover: Frankfurt. Kenya production data stays within continental Africa absent your written approval.
03
We don't sell data. Ever.
No ad networks, no resale, no data brokers, no shadowy enrichment. Read every sub-processor below — the list is the list.
04
You can export everything, any time.
Full JSON + CSV export, signed audit log, copies of every payslip. You owe us nothing for it. Your data is never hostage.
05
AI features are opt-in, zero-retention.
Ada AI drafts memos and explains rules. Inputs aren't used to train any model. Endpoint zero-retention contract on file.
06
Rights honoured across six jurisdictions.
KE, UG, NG, CI, GH, ZA — we'll route your access / erasure / portability request to the right team in plain language.
In this document
01Who we are.02What we collect.03Why we collect it.04Who sees it.05Where it lives.06How long we keep it.07Your rights.08How we keep it safe.09When this changes.10Talk to a human.
Questions? dpo@meridianhr.co reaches a human in Nairobi, usually inside one business day.
01.

Who we are.

Meridian HR Ltd is a Kenyan limited company (CR No. ●●●●●●●), registered at Nyali Road, Westlands, Nairobi. We operate the platform that sits at meridianhr.co, the iOS and Android Meridian apps, and the partner APIs documented at developers.meridianhr.co.

For the personal data of our own customers and prospects — the people who sign contracts, hand over their credit card, or chat to us on a sales call — we are the controller.

For the personal data of your employees, contractors, candidates, and dependents, processed because your employer uses our platform — we are the processor, acting on documented instructions from your employer under our Data Processing Addendum. If that's you, the right place to start is usually your HR team — they decide what your data is for, how long it's kept, and who can see it inside their organisation. We honour those decisions and the rights you have under the law that applies to you.

In plainer words
If you bought Meridian, this notice describes our handling of your data. If you're an employee whose company uses Meridian, this describes how we handle data on your employer's behalf — and most of your questions are best directed to them first.

Data Protection Officer

Our DPO is registered with the Office of the Data Protection Commissioner of Kenya (reg. ODPC/DPO/●●●●). Reachable at dpo@meridianhr.co for any privacy question, large or small. We aim to acknowledge inside 48 hours; substantive replies inside 14 days.

02.

What we collect.

The categories below are the ceiling. Most customers use a fraction of them; the platform never collects fields you don't enable.

Customer data (employer-side)

Identity
Company name, registration number, tax IDs (KRA PIN, TIN, FIRS RC, etc.), registered address, signing authority.
Account
Admin email, hashed password (Argon2id), 2FA secret, session metadata, audit log of administrative actions.
Commercial
Subscription tier, headcount band, billing address, last four digits of card (full card is held only by Stripe).

Employee data (processed for your employer)

Identity
Legal name, preferred name, date of birth, national ID number, KRA PIN / NIN / SSNIT / etc., passport number where required, photograph.
Contact
Email, phone, next of kin, emergency contact, residential and postal addresses.
Employment
Job title, manager, department, employment type, contract start/end, probation status, performance ratings, leave balance and history.
Compensation
Salary, allowances, bonuses, deductions, garnishments, pension contributions, bank account or mobile money number, statutory filings.
Dependents
Spouse and child names + DOB only when needed for tax relief, medical cover, or statutory filings.
Sensitive
Medical certificates supporting sick leave (encrypted at rest, RBAC-restricted), disability accommodations, union membership where elected.
Device
IP, browser, device fingerprint hash, clock-in geolocation (where the attendance module is enabled — never silently).
A line we won't cross
Religion, sexual orientation, political affiliation, and biometric identifiers are not collected by Meridian, full stop. If a customer asks us to add fields like these, we will refuse.
03.

Why we collect it.

Every field above maps to a specific lawful basis. We keep the mapping current; the short version is:

PurposeLawful basis (GDPR / KE DPA)Examples
Running the platformContractAuthentication, payroll calculation, payslip delivery
Statutory complianceLegal obligationPAYE returns, NSSF / NHIF, NDPR audit, KRA iTax filing
Security & abuseLegitimate interest2FA, anomaly detection, audit logs, fraud screens
Product improvementLegitimate interestAggregated, de-identified usage analytics — opt-out available
Marketing emailsConsentCustomer newsletters only; one click to unsubscribe
Ada AI featuresConsent (per-user)Drafting, summaries, expression help; off by default

We do not engage in automated decision-making with legal or similarly significant effects. Payroll math is automated; firing people is not.

04.

Who sees it.

Inside your employer's tenant, access is governed by role and by audit. Inside Meridian, the engineers on duty for site-reliability have a break-glass path to production — every use is logged, alerted to the DPO, and reviewed weekly. The rest of the company sees aggregate dashboards only.

Outside Meridian, the data flows below are the complete list. We commit to publishing material changes to this table at least 30 days before they take effect.

Sub-processorPurposeRegion
Amazon Web Services (AWS)Application hosting, primary storage, encryption keysCape Town (af-south-1) · Frankfurt (eu-central-1) failover
CloudflareEdge delivery, DDoS protection, bot filteringGlobal edge, no data at rest
PostmarkTransactional email (payslips, approvals, alerts)United States
TwilioSMS one-time codes, WhatsApp business messagesIreland · United States
StripeCard payments for SaaS subscription onlyIreland
OnfidoIdentity verification at onboarding (optional)United Kingdom
AnthropicAda AI features — drafting, summaries, expression help; no training on Customer DataUnited States (zero-retention endpoint)
SentryError monitoring (pseudonymised, no payload data)Frankfurt
05.

Where it lives.

Primary production is Cape Town (AWS af-south-1). Encrypted nightly snapshots replicate to Frankfurt (eu-central-1) for disaster recovery only — never for routine reads. Backups are encrypted with customer-isolated keys, rotated every 90 days.

For customers whose home jurisdiction requires data residency, we honour it. Kenyan customers can elect to keep production data inside continental Africa with no failover to Europe; ask your CSM to enable the AFRICA-ONLY region flag at provisioning.

Transfers outside your region

A small number of operational tools (transactional email, SMS) sit outside Africa, as the sub-processor table shows. For those flows, we use Standard Contractual Clauses and the European Commission's 2021 module 3, plus the supplementary measures the EDPB recommends (encryption in transit and at rest, key separation, no plaintext payload in logs).

06.

How long we keep it.

Two clocks. Customer Data follows the controller's instruction — your employer chooses retention windows inside their tenant settings, and we honour them. Records we keep on our own clock are these:

RecordRetentionWhy
Payroll calculations & payslips7 years post-terminationKenya Tax Procedures Act, Income Tax Act equivalents in other jurisdictions
Statutory filings7 yearsTax authority lookback periods
Application audit logs2 years rollingSecurity investigations, dispute resolution
Customer support tickets3 years from closePattern review, dispute trail
Marketing contactsUntil unsubscribed, then 30 daysHonouring withdrawal of consent
Backups35 days rollingRecovery — overwritten in normal course

When a customer leaves the platform, we offer a 30-day export window, then return or delete all Customer Data per the DPA. Statutory records are retained in cold storage for the periods above, then irretrievably erased.

07.

Your rights.

If you're an employee whose company uses Meridian, your starting point for most rights requests is your HR team — they control the data, and we are obligated to act on their lawful instructions. If they can't help you, or you'd rather come to us first, email dpo@meridianhr.co and we'll route appropriately, in writing, inside seven working days.

The catalogue of rights varies by where you sit, but in practice we honour the union of them across our footprint:

  • Access — a copy of the personal data we hold about you, in a portable format.
  • Rectification — correction of inaccurate fields, with a note in the audit trail.
  • Erasure — deletion where law allows; statutory records are exempt.
  • Restriction & Objection — to processing not strictly required to run your employment relationship.
  • Portability — JSON or CSV export of the records held on the platform.
  • Withdraw consent — for anything we collect on a consent basis (e.g. Ada AI, marketing); the unsubscribe link in every email also works.
  • Complain — to your supervisory authority: ODPC in Kenya, NDPC in Nigeria, NITA-U in Uganda, CNDP in Côte d'Ivoire, DPC in Ghana, Information Regulator in South Africa.
A note on identity checks
We will verify that you are who you say you are before we act on a rights request — usually a signed letter and a copy of an ID. We will never charge for a first request inside a 12-month window.
08.

How we keep it safe.

We are SOC 2 Type II audited (Q4 2025 report; the next observation window closes Q3 2026) and ISO/IEC 27001 certified (cert. ●●●●●●●●). Our security programme is not a marketing page — the controls below are the load-bearing ones:

  • Encryption: TLS 1.3 in transit; AES-256-GCM at rest; customer-isolated KMS keys; envelope encryption for sensitive fields (NID, salary, bank).
  • Identity: SAML 2.0 and SCIM for enterprise SSO; mandatory 2FA for admins; Yubikey support; session binding to device fingerprint.
  • Engineering: pull-request reviews required on every change; CodeQL + dependabot in CI; signed commits; reproducible builds; cosigned containers.
  • Access: production access via SSO + Yubikey + just-in-time approval, logged centrally, reviewed weekly by the DPO and quarterly by the board.
  • Network: private VPC, no public databases, mTLS between services, egress allowlist, no SSH (all access via session-recorded SSM).
  • Backups: encrypted, immutable, tested quarterly via full-restore drill against a clean account.
  • People: background checks at hire, annual security training, instant access-revocation on offboard (median ≤ 12 minutes), zero-trust laptops.
  • Incident response: 24×7 on-call, four-tier severity ladder, customer notification within 72 hours of detection of any incident affecting personal data — usually much sooner.

The full SOC 2 Type II report and ISO 27001 certificate are available under NDA. Ask your CSM.

09.

When this changes.

Material changes are emailed to every account admin and posted on this page with a 30-day notice period before they take effect. Non-material changes (typo fixes, link maintenance) are noted in the version log at the bottom of this page without separate notice. The full revision history is public.

Where a change requires it, we will re-collect consent before the new processing begins.

10.

Talk to a human.

Privacy is not a ticket queue at Meridian. Email the DPO and you're emailing a person — usually answered the same business day in Nairobi.

DPO
dpo@meridianhr.co · response in 48 hours, substantive reply in 14 days
EU representative
Meridian HR EU OÜ, Sepapaja 6, Tallinn, Estonia · eu-rep@meridianhr.co
Postal
Attn: Data Protection, Meridian HR Ltd, Westlands, P.O. Box ●●●●●–00100, Nairobi, Kenya
/ revision log — 4 entries
Date
Version
Change
2026-05-20
v3.1
Added Anthropic to sub-processors for opt-in Ada AI features. Zero-retention endpoint contracted.
2026-02-04
v3.0
Restructured for clarity. Added the at-a-glance summary. Extended retention table.
2025-10-12
v2.3
Added Ghana DPA, Côte d'Ivoire CNDP supervisory authorities. New EU representative.
2025-07-01
v2.0
Kenya ODPC registration renewed. Cape Town primary region. Africa-only flag launched.
/ talk to a person — not a ticket queue

Privacy is a conversation, not a form.

DPO
dpo@meridianhr.co
Security
security@meridianhr.co
Legal
legal@meridianhr.co
Postal
Nyali Road, Westlands · P.O. Box ●●●●●–00100, Nairobi, Kenya
Meridian HR
People operations for modern African teams. Live in Kenya, Uganda, Nigeria, Côte d'Ivoire, Ghana, and South Africa.

Platform

  • CoreHR
  • Leave
  • Payroll
  • Performance
  • Attendance

Countries

  • Kenya
  • Uganda
  • Nigeria
  • Côte d'Ivoire
  • Ghana
  • South Africa

Company

  • About
  • Customers
  • Security
  • Changelog
  • Careers

Developers

  • API
  • Expression engine
  • Webhooks
  • Status
  • Docs
© 2026 MERIDIAN HR LTD · NAIROBI · KENYA
ENFR·PRIVACYTERMSDPA