Privacy and personal information

How Meridian Edge Global uses and protects personal data

This notice explains what personal information Meridian Edge Global Ltd collects, why we use it, how long we normally keep it and when authorised access or storage may take place outside the United Kingdom.

Last updated: 19 August 2026

At a glance UK data-protection framework
01

Defined purposes

We use personal data for enquiries, contracts, service delivery, support, billing, security and legal obligations.

02

Controlled access

Access is limited according to role, service requirement and authorised client instructions.

03

Retention and rights

We apply retention periods and respond to applicable individual-rights requests.

No sale of personal data
Purpose-based access
Documented retention periods
Overseas access explained
Who is responsible

The organisation covered by this notice

This notice applies when Meridian Edge Global Ltd decides why and how personal data is used, including through this website and our own business administration.

Data controller

Meridian Edge Global Ltd

Client-controlled data

When MEG acts for a client

For some digital or Dedicated Business Support engagements, a client determines the purposes and means of processing personal data and MEG processes it under the client’s documented instructions. In that situation, the client is normally the controller and MEG acts as its processor. The applicable contract or data-processing terms govern that work.

Information we may collect

Personal data connected with enquiries and services

We seek to collect only the information reasonably required for the relevant purpose.

Business and contact information

  • Name, job title and organisation
  • Business email address and telephone number
  • Postal, billing and account-contact information
  • Communication preferences

Enquiry and service information

  • Requirements submitted through Contact or Get Support
  • Correspondence, meeting notes and service instructions
  • Website, domain, provider and incident information
  • Project, support and service-delivery records

Commercial and transaction information

  • Proposals, contracts and service orders
  • Billing address, invoices and payment status
  • Transaction references supplied by payment providers
  • We do not intend to store complete payment-card numbers

Website and security information

  • IP address, browser, device and basic usage information
  • Cookie choices and analytics information where enabled
  • Authentication, access and security-event records
  • Information needed to prevent misuse and investigate incidents

Please do not send credentials through public forms

Do not enter passwords, authentication codes, private keys, complete payment-card details or unnecessary confidential client data in our Contact or Get Support forms. If controlled access is required for an accepted service, we will arrange an appropriate method separately.

Purposes and lawful bases

Why we process personal data

The lawful basis depends on the activity and our relationship with the individual or organisation.

Contract and pre-contract steps

Enquiries and service delivery

  • Responding to service enquiries and preparing proposals
  • Setting up, managing and delivering accepted services
  • Communicating about scope, access, progress and support
  • Billing, payment administration and client records
Legitimate interests

Operating and protecting the business

  • Managing business relationships and service quality
  • Securing systems and investigating suspected misuse
  • Maintaining appropriate operational and audit records
  • Establishing, exercising or defending legal claims
Legal obligation

Company, tax and regulatory requirements

  • Maintaining accounting and transaction records
  • Responding to valid legal or regulatory requirements
  • Meeting applicable company, employment and tax duties
  • Supporting the exercise of data-protection rights
Consent where required

Optional activities

  • Non-essential cookies or analytics where consent is required
  • Electronic marketing where consent is the appropriate basis
  • Other clearly explained optional processing
  • Consent may be withdrawn for future processing
Recipients and service providers

When personal data may be shared

We do not sell personal data. We disclose it only where reasonably necessary for an identified purpose or where required by law.

Technology and administration providers

Hosting, email, security, backup, analytics, CRM, accounting, communication and payment-service providers may process limited information to supply their services to us.

Professional advisers

Accountants, legal advisers, insurers and other professional advisers may receive information where reasonably necessary for advice, compliance or claims.

Authorities and legal recipients

We may disclose information to courts, regulators, law-enforcement bodies, tax authorities or other recipients where required or permitted by applicable law.

Business changes

Relevant information may be disclosed under appropriate confidentiality arrangements in connection with a proposed investment, reorganisation, sale or transfer of all or part of the business.

Islamabad access and overseas processing

How international access is managed

Our operating model includes a managed delivery office in Islamabad, Pakistan, and some technology providers may store or process information outside the United Kingdom.

Islamabad delivery office

Authorised, purpose-limited access

  • Authorised personnel may remotely access personal data where required for an agreed service or business function
  • Access is assigned according to role, client instructions and the minimum information reasonably required
  • Personnel are subject to confidentiality and data-handling obligations
  • Access may be removed when it is no longer required
Other countries

Hosting and service providers

Our website hosting provider may process website and server information in the United States. Other suppliers may process information in the countries in which they or their approved subprocessors operate.

Where the UK GDPR restricted-transfer rules apply, we use an applicable lawful transfer mechanism and assess the circumstances of the transfer. Depending on the arrangement, this may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another mechanism permitted by UK law, together with additional technical or organisational measures where appropriate.

Access is not granted automatically

The location of our delivery office does not give every member of personnel access to every client system or record. Access must be connected with an authorised role or accepted service and remains subject to the applicable contractual and security arrangements.

Retention

How long we normally keep personal data

We may retain information for a shorter or longer period where required by law, a contract, a dispute, a security investigation or a documented client instruction.

General enquiries

Normally up to 24 months after the last meaningful contact where the enquiry does not become a client engagement.

Client and contract records

Normally for the engagement and up to six years after it ends, where needed for contractual, operational or legal-record purposes.

Invoices and accounting records

Normally six years after the end of the relevant financial year, or longer where applicable law requires.

Support and technical records

Normally up to 24 months after closure, unless incorporated into a longer contractual, security or legal record.

Recruitment information

Normally up to 12 months after the recruitment activity ends, unless a longer period is agreed for a future-opportunity record or required for an employment relationship.

Website and security records

Periods vary by record type. Routine server and security logs are normally retained for up to 12 months unless needed for an active investigation, claim or legal obligation.

Marketing preferences

Active marketing records are retained while relevant. A minimal suppression record may be kept for as long as reasonably necessary to respect an opt-out.

Client-controlled information

Where MEG acts as a processor, retention and deletion follow the client’s documented instructions and the applicable service agreement.

Security

Measures appropriate to the processing risk

No internet or storage system is completely risk-free, but we use technical and organisational measures intended to reduce unauthorised access, loss, alteration or disclosure.

01 · ACCESS

Role-based and purpose-limited access

02 · PEOPLE

Confidentiality and handling obligations

03 · SYSTEMS

Authentication, updates and protective controls

04 · RECORDS

Backup, logging and incident review where appropriate

05 · SUPPLIERS

Service-provider and contractual review

Your rights

Requests about your personal data

Rights apply subject to the circumstances and any exemptions in UK data-protection law.

Access and information

You may ask whether we process your personal data and request a copy together with relevant information about the processing.

Correction

You may ask us to correct inaccurate personal data or complete information that is incomplete.

Erasure and restriction

You may ask us to erase personal data or restrict its use in circumstances where those rights apply.

Objection

You may object to processing based on legitimate interests. You may object to direct marketing at any time.

Portability

Where the legal conditions apply, you may request eligible data in a structured, commonly used and machine-readable format.

Consent

Where we rely on consent, you may withdraw it for future processing without affecting processing already carried out lawfully.

How to make a request

Email inquiry@meridianedgeglobal.co.uk. We may ask for information reasonably needed to confirm identity and locate the relevant records. We normally respond within the period required by applicable law.

Cookies and other sources

How information reaches us

Most information is provided directly by an individual, a client organisation or a person acting for that organisation.

Website and cookies

We may collect limited technical information through website logs and cookies. Non-essential cookies are used only in accordance with the applicable consent requirements. See our Cookie Policy.

Other sources

Information may also come from an individual’s employer, a client, an authorised representative, a service provider, publicly available professional sources or another party involved in the relevant enquiry or service.

Questions and complaints

Contact us first so we can review the concern

You also have the right to complain to the UK Information Commissioner’s Office if you are dissatisfied with how personal data has been handled.

Supervisory authority

Information Commissioner’s Office

Current contact and complaint information is available directly from the ICO.

Visit the ICO complaints page
Privacy question or rights request?

Contact Meridian Edge Global Ltd

Provide enough information for us to identify the issue or relevant records. Do not send passwords, authentication codes or unnecessary confidential information.

Scroll to Top