Data Processing Agreement
Effective / last updated 2026-08-25 · Version 2026-08-25
This document is a drafted template and has not been reviewed by an attorney. It should be reviewed by qualified legal counsel before being relied on commercially.
This Data Processing Agreement ("DPA") supplements the Terms of Service between you ("Controller") and Meridian ("Processor") whenever you enter personal data about tenants or applicants ("Tenant Data") into the service on their behalf.
1. Roles
You are the data controller for Tenant Data you enter into Meridian. Meridian is a data processor, processing Tenant Data only on your documented instructions (as expressed through your use of the product's features) and for the purpose of providing the service.
2. Subprocessors
You authorize Meridian's use of the subprocessors listed in the Privacy Policy. Meridian will provide notice of new subprocessors and a reasonable opportunity to object before they process Tenant Data.
3. Security measures
Meridian maintains administrative and technical safeguards appropriate to the risk, including encrypted transport, hashed credentials, access-scoped database queries, and rate-limited authentication endpoints.
4. Assistance and data subject requests
Meridian will provide reasonable assistance to help you respond to data subject requests concerning Tenant Data (access, deletion, portability), consistent with the self-service tools available in the product and via direct request to [email protected].
5. Breach notification
Meridian will notify you without undue delay after becoming aware of a personal data breach affecting Tenant Data, and will provide information reasonably necessary for you to meet your own notification obligations.
6. Deletion on termination
On account deletion or termination, Meridian deletes Tenant Data in accordance with the retention terms in the Privacy Policy.