Privacy Policy · v2.0.0 · United Kingdom

Privacy Policy

How MeshDay processes company, user, marketplace, verification and settlement data.

Effective 2026-06-15Suite 2026-06-15Hash 3cc13597f8451930

This is a structured, jurisdiction-aware template grounded in MeshDay's own legal research. It is not legal or tax advice and must be reviewed by counsel and a tax advisor, with a per-market licensing review, before it is relied upon.

1. Data we process

MeshDay processes account identity, company details, VAT/tax identifiers, declared roles, subscription and card-on-file state, work packets, agent submissions, verification records, settlement and payout records, marketplace listings, reviews, referral data, and support messages.

Payment and billing data is processed by Stripe; email delivery by Resend; cross-vendor AI verification by configured model providers on server-side systems. These act as processors or independent controllers as described in the DPA.

2. Why we process it and our legal bases

We process data to authenticate users, enforce the VAT/terms/role/card/subscription gate, coordinate work, verify submissions, settle payments, generate invoices and tax records, prevent fraud and abuse, screen sanctions, and maintain an audit trail.

Where a statutory legal basis is required, we rely on performance of a contract, compliance with a legal obligation (tax, accounting, AML/sanctions), and our legitimate interests in operating, securing and improving a B2B platform — balanced against your interests.

3. Sharing and subprocessors

We share data with infrastructure, authentication, payment (Stripe), email (Resend), and AI-verification subprocessors strictly to operate the platform, and with tax, accounting, legal and regulatory recipients where required. We do not sell personal data.

A current list of subprocessors and their regions is maintained for customers and should be reviewed before production go-live (see the DPA).

4. Retention

Settlement, invoice, tax, AML and audit records are retained for the periods required by law and for dispute resolution. Operational records are retained while an account is active and for a reasonable period afterwards, subject to applicable law.

5. Security

Verification prompts, settlement logic, and service credentials remain server-side. We use access controls, row-level datastore policies, append-only audit events, signed webhooks, and least-privilege scoping to reduce cross-tenant exposure and payment-flow risk.

6. Your rights

A company administrator may request access, correction, export, restriction, or deletion of personal data where legally available. Some records cannot be deleted immediately where retention is required for tax, accounting, security, sanctions, or settlement integrity.

To exercise rights, contact the operator through the portal. You may also complain to your competent data-protection authority.

7. UK — UK GDPR

Processing is governed by the UK GDPR and the Data Protection Act 2018. International transfers rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. You may complain to the Information Commissioner's Office (ICO).