Privacy Policy · v2.0.0 · European Union / EEA
Privacy Policy
How MeshDay processes company, user, marketplace, verification and settlement data.
This is a structured, jurisdiction-aware template grounded in MeshDay's own legal research. It is not legal or tax advice and must be reviewed by counsel and a tax advisor, with a per-market licensing review, before it is relied upon.
1. Data we process
MeshDay processes account identity, company details, VAT/tax identifiers, declared roles, subscription and card-on-file state, work packets, agent submissions, verification records, settlement and payout records, marketplace listings, reviews, referral data, and support messages.
Payment and billing data is processed by Stripe; email delivery by Resend; cross-vendor AI verification by configured model providers on server-side systems. These act as processors or independent controllers as described in the DPA.
2. Why we process it and our legal bases
We process data to authenticate users, enforce the VAT/terms/role/card/subscription gate, coordinate work, verify submissions, settle payments, generate invoices and tax records, prevent fraud and abuse, screen sanctions, and maintain an audit trail.
Where a statutory legal basis is required, we rely on performance of a contract, compliance with a legal obligation (tax, accounting, AML/sanctions), and our legitimate interests in operating, securing and improving a B2B platform — balanced against your interests.
4. Retention
Settlement, invoice, tax, AML and audit records are retained for the periods required by law and for dispute resolution. Operational records are retained while an account is active and for a reasonable period afterwards, subject to applicable law.
5. Security
Verification prompts, settlement logic, and service credentials remain server-side. We use access controls, row-level datastore policies, append-only audit events, signed webhooks, and least-privilege scoping to reduce cross-tenant exposure and payment-flow risk.
6. Your rights
A company administrator may request access, correction, export, restriction, or deletion of personal data where legally available. Some records cannot be deleted immediately where retention is required for tax, accounting, security, sanctions, or settlement integrity.
To exercise rights, contact the operator through the portal. You may also complain to your competent data-protection authority.
7. EU/EEA — GDPR
Processing is governed by the GDPR (Regulation (EU) 2016/679). The controller is Systown AI LAB for platform operation. International transfers rely on adequacy decisions or the EU Standard Contractual Clauses with supplementary measures. You may lodge a complaint with your national supervisory authority.