Privacy Policy

Last updated: 21 July 2026. This policy explains how Mehro, Switzerland, processes personal data when you use Meridian GRC. We comply with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR.

1. Controller and contact

Mehro, Switzerland — contact: no-reply@mehro.ch. For customer tenants, the customer is the controller of the content they store; we act as processor.

2. Data we process

  • Account data — name, email, job title, role assignments, hashed passwords (bcrypt; we never see plaintext).
  • Tenant content — the risks, controls, policies, documents, and other records your organization creates.
  • Security logs — sign-in events, IP-derived rate-limiting keys, and an audit trail of actions, kept for security and accountability.

3. Purposes and legal bases

We process data to provide the Service (contract), to secure it (legitimate interest / legal obligation), and to communicate service messages such as password resets (contract). We do not sell personal data and we do not use tenant content for advertising or for training AI models.

4. AI processing

The built-in copilot analyses only data within the requesting user's permission scope. If the optional Claude enhancement is enabled by your organization, scoped analysis summaries are processed by Anthropic under their data-processing terms; otherwise all analysis runs locally on our servers.

5. Hosting and transfers

The Service is hosted in Switzerland (Infomaniak). Data is not transferred outside Switzerland/EEA except where an optional integration your organization enables requires it.

6. Retention

Tenant data is retained for the life of the subscription plus a 30-day grace period. Security logs are retained for 12 months. Evidence files follow the retention dates your organization sets.

7. Your rights

You may request access, rectification, deletion, or a copy of your personal data. Where we act as processor, we will refer requests to your organization's administrator. Contact: no-reply@mehro.ch.

8. Security

Measures include tenant isolation enforced at the query layer, role- and attribute-based access control, hashed session tokens and passwords, TLS in transit, rate limiting, security headers, and an append-only audit trail. See our security documentation for details.

© 2026 Mehro · Contact: no-reply@mehro.ch