Privacy Policy

Effective Date: April 4, 2026

Last Updated: April 4, 2026

Table of Contents

  1. Introduction
  2. Information We Collect
  3. How We Use Information
  4. Data Sharing
  5. Data Storage and Security
  6. Data Retention
  7. Canadian Privacy Law Compliance
  8. AI-Specific Disclosures
  9. Cookies and Tracking
  10. Children's Privacy
  11. International Data Transfers
  12. Your Rights
  13. Changes to This Policy
  14. Contact Information

1. Introduction

Meridian Legal Technologies Inc. ("Meridian," "we," "us," or "our") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (meridianlegal.ca) and our AI-powered embeddable chat widget platform (collectively, the "Service").

Meridian is a B2B SaaS provider that delivers AI-powered chat widgets to Canadian immigration law firms. Our Service enables law firm clients to deploy conversational AI on their websites to assist visitors with immigration-related inquiries. This Privacy Policy covers personal information we collect from two categories of users:

Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Service. By accessing or using Meridian, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy.

Important Note: This Privacy Policy is governed by the laws of British Columbia and Canada. We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and applicable provincial privacy laws.

2. Information We Collect

We collect information in several ways to provide, improve, and protect our Service. The types of information we collect depend on how you interact with Meridian.

2.1 Information From Law Firm Clients

When you register for a Meridian account or subscribe to our Service, we collect the following information:

2.2 Information From End Users (Website Visitors)

When website visitors interact with a Meridian widget deployed on a law firm's website, we collect the following information:

2.3 Information Collected Automatically

We automatically collect certain information about your device and how you interact with the Service:

2.4 Information From Third Parties

We may receive information about you from third-party service providers:

2.5 Sensitive Information

Meridian does not intentionally collect sensitive personal information such as health information, racial or ethnic origin, religious beliefs, sexual orientation, criminal history, or biometric data. However, because our Service handles immigration-related inquiries, conversations may incidentally contain sensitive information disclosed by end users. We treat such information with appropriate care and security measures (see Section 5).

3. How We Use Information

We use the information we collect for various lawful purposes, always in accordance with Canadian privacy laws and with your consent where required.

3.1 Service Delivery and Improvement

3.2 Payment Processing and Billing

3.3 AI Processing and Content Generation

3.4 Analytics and Usage Tracking

3.5 Customer Support and Communication

3.6 Security and Fraud Prevention

3.7 Legal and Regulatory Compliance

3.8 Aggregated and De-identified Data

We may use aggregated or de-identified information (that cannot be directly associated with you) for research, analytics, marketing, and other business purposes without restriction.

4. Data Sharing

Meridian does not sell, rent, or lease your personal information to third parties for their marketing purposes. However, we do share information with certain service providers and in specific circumstances as described below.

4.1 Data Sharing With Law Firm Clients

If you are an end user interacting with a Meridian widget deployed on a law firm's website, the law firm client who deployed that widget will have access to your conversation data, IP address, browser information, and engagement metrics. The law firm is responsible for disclosing this practice to you and obtaining your consent where required by law.

Important: Law firms are independent data controllers responsible for their own privacy obligations regarding end user data. We recommend reviewing the law firm's privacy policy for information about how they handle your data.

4.2 Data Sharing With AI Subprocessors

When you or an end user submits a question to the Meridian widget, the conversation text is transmitted to our AI Subprocessor's servers for processing. Our AI Subprocessor may process this data in the United States.

Legal Basis: This sharing is necessary to provide the core functionality of the Service and is covered under the Data Processing Addendum (DPA) executed between Meridian and customers.

4.3 Data Sharing With Third-Party Payment Processor (Payment Processing)

If you are a law firm client, we share your billing information with our Third-Party Payment Processor to process subscription payments.

4.4 Data Sharing With Infrastructure and AI Processors

To deliver the Service, Meridian utilizes enterprise-grade cloud infrastructure and advanced third-party artificial intelligence processors.

Cloud Infrastructure:

Your data is securely hosted and processed on distributed, enterprise-grade cloud networks. These providers act strictly as data subprocessors and are legally bound by Data Processing Addendums (DPAs) to maintain security standards equivalent to or exceeding Canadian legal requirements.

AI Processing:

Conversation data is transmitted via encrypted API to secure, industry-leading large language model (LLM) providers to generate responses. Our AI subprocessors are strictly prohibited from using your conversation data or client inputs to train their baseline models without your explicit opt-in consent. Data processed by these APIs is retained only for the minimum duration required for security monitoring (typically 30 days) before being permanently deleted.

4.5 Data Sharing for Legal Compliance

We may disclose your personal information if required by law or if we have a good-faith belief that disclosure is necessary to:

We will provide notice of such disclosure when legally permissible, except where prohibited by law.

4.6 Data Sharing in Business Transactions

If Meridian is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your personal information may be transferred as part of that transaction. We will notify you of such change and any choices you may have regarding your information.

4.7 Consent-Based Sharing

We may share your information with other third parties when you provide explicit consent to such sharing, such as integrations with third-party tools you authorize.

4.8 No Data Sales or Sharing for Marketing

Meridian does not sell, rent, lease, or share personal information with third parties for their marketing, advertising, or promotional purposes. We do not participate in data broker networks or sell customer lists.

4.9 Subprocessor Changes

Meridian currently engages the following subprocessors for the delivery of its services:

Meridian shall provide law firm clients with no less than thirty (30) days' prior written notice before adding or replacing any subprocessor that processes conversation data or personal information. Such notice shall be provided via email to the Client's registered account email address and shall include:

If the Client objects to a new subprocessor, the Client may terminate their subscription without penalty within thirty (30) days of receiving such notice.

5. Data Storage and Security

Meridian implements comprehensive technical, administrative, and physical security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction.

5.1 Infrastructure and Storage

Hosting: Meridian's platform is hosted on highly secure, geographically distributed cloud infrastructure.

Data Residency: Data is primarily stored and processed in North American data centers.

Compliance: Our infrastructure is designed to assist Canadian legal professionals in complying with provincial Law Society and College of Immigration and Citizenship Consultants (CICC) cloud computing guidelines. All client conversation data is secured using AES-256-GCM encryption at rest and TLS 1.3 encryption in transit.

5.2 Encryption

5.3 Password Security

5.4 Access Controls

5.5 Audit Logging and Monitoring

5.6 Employee Training and Confidentiality

5.7 Security Reviews and Assessments

5.8 Data Breach Notification

In the event of a confirmed security breach involving personal information that poses a real risk of significant harm (RROSH) as defined under PIPEDA, Meridian shall notify affected law firm clients within seventy-two (72) hours of confirming the breach. Notification shall include:

This notification timeline is designed to enable law firm clients to fulfill their own regulatory obligations to notify affected individuals, the Office of the Privacy Commissioner of Canada, and any applicable provincial privacy commissioners or Law Society regulatory bodies.

5.9 Limitations of Security

While we implement strong security measures, no security system is completely impenetrable. Meridian cannot guarantee absolute security of your information. If you have any concerns about the security of your personal information, please contact our Privacy Officer at the contact information provided in Section 14.

6. Data Retention

We retain personal information only for as long as necessary to provide the Service, comply with legal obligations, and resolve disputes. Retention periods vary based on data type and subscription tier.

6.1 Conversation Data

Retention of conversation data between end users and the Meridian widget depends on the law firm's subscription tier:

After the retention period expires, conversation data is automatically and permanently deleted from our systems.

6.2 Law Firm Account Data

6.3 Billing and Financial Records

6.4 Analytics and Usage Data

6.5 Security and Access Logs

6.6 Deletion Upon Request

Subject to legal obligations and contractual requirements, you may request deletion of your personal information. We will process deletion requests within 30 days, except where:

To request deletion of your information, contact our Privacy Officer (see Section 14).

6.7 Archival and Backups

Even after deletion, your information may exist in backup copies for a limited period. Backup copies are retained for disaster recovery purposes (typically 90 days) and are subject to the same access controls and security measures as production systems.

7. Canadian Privacy Law Compliance

Meridian complies with all applicable Canadian federal and provincial privacy laws. This section outlines our compliance with the key privacy regimes that apply to our business.

7.1 Personal Information Protection and Electronic Documents Act (PIPEDA)

PIPEDA is the federal privacy law governing how private sector organizations collect, use, and disclose personal information in Canada.

7.2 Canada's Anti-Spam Legislation (CASL)

CASL regulates commercial electronic messages (email, SMS, social media) sent to individuals in Canada.

7.3 Alberta Personal Information Protection Act (PIPA)

Alberta PIPA governs personal information handling by private sector organizations in Alberta.

7.4 British Columbia Personal Information Protection Act (BCPIPA)

BC PIPA is similar to Alberta PIPA and governs personal information handling in British Columbia.

7.5 Quebec Law 25 (Loi 25)

Quebec Law 25 modernizes Quebec's privacy law and introduces stricter requirements for personal information handling.

7.6 Law Society Cloud Computing Compliance

Meridian's data architecture is designed to assist lawyers and regulated immigration consultants in complying with provincial Law Society guidelines on cloud computing and data sovereignty, including but not limited to the Law Society of British Columbia's guidance on cloud computing, the Law Society of Ontario's technology guidelines, and the College of Immigration and Citizenship Consultants (CICC) requirements for technology use. Specifically, Meridian provides:

Law firm clients retain full control over and responsibility for ensuring their use of Meridian complies with their specific Law Society's cloud computing and technology guidelines.

7.7 Right to Access

Subject to legal exceptions, you have the right to request access to your personal information. We will provide a copy of your information within 30 days of your request. A reasonable fee may be charged for access requests.

7.8 Right to Correction and Rectification

You have the right to request correction of inaccurate personal information. We will update your information within 30 days and notify any third parties who received the inaccurate information (where feasible).

7.9 Right to Deletion

Subject to legal retention requirements, you have the right to request deletion of your personal information. We will delete your information within 30 days unless we have a legal obligation to retain it.

7.10 Right to Withdraw Consent

You may withdraw consent to our collection, use, or disclosure of your personal information at any time. Upon withdrawal, we will cease collecting and using your information going forward (with limited exceptions where we have a legal obligation to continue processing).

7.11 Right to Complain

If you have concerns about Meridian's privacy practices, you have the right to lodge a complaint with the Privacy Commissioner of Canada or the applicable provincial privacy commissioner.

7.12 Privacy Officer Contact

Meridian's Privacy Officer is responsible for receiving and responding to privacy inquiries and complaints. Contact information is provided in Section 14.

8. AI-Specific Disclosures

Meridian's platform uses artificial intelligence to generate responses to immigration-related questions. This section explains how our AI system works and how your data is handled in the context of AI processing.

8.1 AI Model and Technology

8.2 AI Subprocessor Disclosure

The identity of our current AI Subprocessors is available to law firm clients upon request and is disclosed as part of our enterprise onboarding process. Meridian maintains strict Data Processing Agreements with all AI Subprocessors that prohibit the use of client data for model training without explicit consent.

8.3 AI Limitations and Disclaimers

Important limitations and disclaimers regarding our AI system:

8.4 Conversation Data and Model Training

8.5 Data Transmission to AI Subprocessors

When a conversation is submitted to the AI:

8.6 Automated Decision-Making

8.7 Bias Monitoring and Mitigation

8.8 Right to Explanation

You have the right to request an explanation of how the AI generated a particular response. We will make reasonable efforts to explain the reasoning behind AI-generated content, though complex AI systems may not provide perfect explainability.

8.9 AI Transparency and Disclosure to End Users

9. Cookies and Tracking

Meridian uses cookies and similar tracking technologies to enhance your experience and gather information about how you use our Service.

9.1 What Are Cookies?

Cookies are small files stored on your device that contain information about your browsing activity. They allow websites to remember your preferences and track your activity over time.

9.2 Essential Cookies

Essential cookies are required for the Service to function properly. They are not subject to consent requirements as they are strictly necessary for service delivery.

9.3 Analytics Cookies

Analytics cookies help us understand how users interact with the Service. These are considered non-essential and require your consent (unless you are in an exempt category).

9.4 No Advertising Cookies

Meridian does not use advertising or tracking cookies to profile you for targeted advertising. We do not participate in behavioral advertising networks.

9.5 Cookie Consent Mechanism

Upon first visit to the Meridian website, you will see a cookie consent banner. You may:

You can change your cookie preferences at any time in the cookie management center (typically accessible via a link in the footer).

9.6 Similar Tracking Technologies

In addition to cookies, we may use similar technologies including:

9.7 Third-Party Cookies

The Meridian website may contain links to third-party services that set their own cookies. Meridian is not responsible for third-party cookies. We recommend reviewing third-party privacy policies.

9.8 Do Not Track Signals

Some browsers include a "Do Not Track" feature. Meridian does not currently respond to Do Not Track signals, but you can disable cookies in your browser settings to limit tracking.

9.9 Cookie Duration

9.10 Disabling Cookies

Most browsers allow you to control cookies through your settings. You can typically:

Note: Disabling essential cookies may impair the functionality of the Service.

10. Children's Privacy

Meridian's Service is not directed to children under the age of 18, and we do not knowingly collect personal information from children under 18.

10.1 Age Restrictions

10.2 Parental Involvement

If a parent or guardian believes a child has provided information to Meridian, please contact our Privacy Officer immediately (see Section 14). We will investigate and delete the child's information upon verification of parental consent requirements.

10.3 Parent/Guardian Responsibilities

Parents and guardians are responsible for supervising children's online activities and preventing unauthorized disclosure of personal information.

11. International Data Transfers

While Meridian is a Canadian company and primarily processes data in Canada, our data may be transferred to and processed in the United States or other jurisdictions in certain circumstances.

11.1 Data Processing Locations

11.2 Legal Basis for Transfers

11.3 US Legal System Access

Please be aware that data transferred to the United States may be subject to access by US government agencies under US law (including the USA PATRIOT Act). We are not able to prevent such access but will notify you of legal demands where permitted by law.

11.4 Data Localization

For law firms that require data to remain within Canadian borders, Meridian offers Enterprise tier with Canada-only data storage. Contact our sales team for details.

11.5 Compliance With Applicable Laws

All international data transfers comply with PIPEDA, provincial privacy laws, and other applicable Canadian and international data protection laws.

12. Your Rights

Under Canadian privacy laws, you have the following rights regarding your personal information. These rights may vary depending on your province of residence and jurisdiction.

12.1 Right to Access

You have the right to access your personal information. You may request a copy of all personal information Meridian holds about you. We will provide this information in a clear and understandable format within 30 days of your request. A reasonable fee (not to exceed $25-50) may be charged for processing your access request.

How to Request: Contact our Privacy Officer (see Section 14) with your full name and account email address.

12.2 Right to Correction and Rectification

You have the right to correct inaccurate or incomplete personal information. If you identify information that is incorrect, outdated, or incomplete, you may request that we correct it. We will update your information and notify any third parties who received the inaccurate information (where feasible and practicable).

Common Corrections: You can often correct your information directly in your account dashboard (name, email, firm address). For other corrections, contact our Privacy Officer.

12.3 Right to Deletion

You have the right to request deletion of your personal information, subject to legal and contractual exceptions. We will delete your information within 30 days unless:

How to Request: Submit a deletion request to our Privacy Officer. We may ask you to verify your identity before processing the request.

12.4 Right to Data Portability

You have the right to receive your personal information in a portable format. We will provide your data in a commonly used, machine-readable format (such as CSV or JSON) that allows you to transfer it to another service. This right applies to information you have provided to us.

What's Included: Account information, billing history, and usage analytics are generally portable. Real-time conversation data and AI-generated responses may be subject to technical limitations.

12.5 Right to Withdraw Consent

You have the right to withdraw consent to our processing of your personal information. This applies to any processing that relies on your consent (such as marketing emails or analytics cookies). Upon withdrawal, we will cease processing your information for that purpose going forward (though prior processing remains valid).

How to Withdraw: You can withdraw consent by:

12.6 Right to Explain Automated Decision-Making

You have the right to request an explanation of automated decision-making. If Meridian uses automated processes to make significant decisions affecting you, you may request an explanation of the decision and the factors considered.

Note: Meridian does not currently make automated decisions affecting legal rights or benefits. AI responses are informational only and do not determine eligibility for services.

12.7 Right to Complain to Privacy Authorities

You have the right to lodge a formal complaint with Canadian privacy authorities if you believe Meridian has violated your privacy rights.

12.8 Right to Not Be Discriminated Against

You have the right not to be discriminated against for exercising your privacy rights. Meridian will not deny services, increase fees, or provide inferior service as retaliation for requesting access to, correcting, or deleting your personal information.

12.9 Exercise of Rights

To exercise any of the above rights, contact our Privacy Officer (see Section 14) with:

We will acknowledge your request within 5 business days and respond substantively within 30 days (extendable to 60 days for complex requests).

13. Changes to This Policy

Meridian may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We encourage you to review this policy periodically to stay informed about how we protect your information.

13.1 How We Notify You

When we make material changes to this Privacy Policy, we will notify you by:

13.2 Your Acceptance

Your continued use of the Service after policy changes become effective constitutes your acceptance of the updated Privacy Policy. If you do not accept the changes, you may discontinue use of the Service and request deletion of your account.

13.3 Significant Changes

For significant changes (such as new data sharing practices or changes to fundamental data handling), we will provide notice at least 30 days in advance and may request explicit consent.

13.4 Archival of Past Policies

We maintain archival copies of previous versions of this Privacy Policy. You may request access to the policy that was in effect at a specific time by contacting our Privacy Officer.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact our Privacy Officer:

Meridian Legal Technologies Inc.

Privacy Officer: privacy@meridianlegal.ca
General Inquiries: info@meridianlegal.ca
Mailing Address: Meridian Legal Technologies Inc.
Abbotsford, British Columbia
Canada
Website: meridianlegal.ca
Response Time: We will respond to privacy inquiries within 5 business days of receipt and provide substantive responses within 30 days.

Canadian Privacy Authorities

If you wish to lodge a formal complaint about our privacy practices, you may contact the applicable privacy authority:

Acknowledgment

By using Meridian's Service, you acknowledge that you have read and understood this Privacy Policy and agree to our privacy practices as described herein.

Disclaimer: This Privacy Policy is provided for informational purposes and reflects current privacy practices as of the Effective Date. This policy should be reviewed by legal counsel for your specific jurisdiction and circumstances. Meridian reserves the right to modify this policy at any time in accordance with applicable law.