Privacy policy
What Merivex collects, why, how long it is kept, and the rights you can exercise over it.
Effective date: 10 September 2026 Last updated: 10 September 2026
1. Who we are
Merivex ("Merivex", "we", "us") provides an AI quality-intelligence platform for customer-operations teams (the "Service").
Merivex is an independent software product and is operated by its founder. A company has not yet been incorporated for it. When one is formed, the registered entity name and address will be published here and the change notified as described in Section 11. We would rather leave this section incomplete than name an entity or an address that does not yet exist.
For most data we process, our role depends on whose data it is:
- We are a controller for data about the people who hold Merivex accounts and
administer an organization's workspace: names, work email addresses, authentication data, and product-usage records.
- We are a processor for the customer-operations data an organization
connects to the Service, namely customer interaction transcripts, workforce records and everything derived from them. The organization that connects that data is the controller. Our handling of it is governed by the Data Processing Agreement between us and that organization, not by this policy.
Privacy questions and requests: privacy@merivex.ai. That mailbox is monitored and is the correct route for any question about this policy or any request described in Section 8.
2. The data we process
2.1 Account and administrator data (Merivex as controller)
- Identity and contact: name, work email address, and the organization you
belong to.
- Authentication: a scrypt-derived verifier for your password (never the
password itself), email-verification and password-reset token digests, and active session records.
- Product usage: actions you take in the Service, administrative events,
approximate device and browser metadata, and log data needed to operate and secure the Service.
- Billing contact data where your organization subscribes to a paid plan:
billing name, billing email, and subscription status. Payment-card data is handled by our payment processor and does not reach Merivex.
2.2 Connected organization data (Merivex as processor)
When an organization connects a data source or uploads data, we process on its behalf:
- Customer interaction content: transcripts and messages from the
organization's own customer conversations.
- Workforce records: identifiers, names, work contact details, team and role
information for the organization's agents and employees.
- Derived data: evaluations, scores, findings, review tasks, coaching plans,
quality patterns, intent classifications, and the memory the Service builds from the above. Derived data can itself contain personal data.
We process this category only to provide the Service to the controlling organization and on its documented instructions. Individuals whose data appears here should contact the organization that operates the workspace; we will support that organization in responding.
3. Why we process it, and our legal bases
| Purpose | Data | Legal basis (controller data) |
|---|---|---|
| Create and secure accounts; authenticate users | Account, authentication | Contract; legitimate interests in security |
| Operate, maintain and support the Service | Account, product usage, logs | Contract; legitimate interests |
| Bill for paid plans and prevent payment fraud | Billing contact, subscription | Contract; legal obligation |
| Send service and transactional messages | Identity, contact | Contract |
| Send product or marketing email | Identity, contact | Consent, or legitimate interests where permitted; opt-out always available |
| Detect, investigate and prevent abuse or security incidents | Account, usage, logs | Legitimate interests; legal obligation |
| Comply with law and enforce our terms | As relevant | Legal obligation; legitimate interests |
For connected organization data, the legal basis is determined by the controlling organization, not by Merivex.
4. AI processing
Evaluating an interaction requires analysing its content. Where an AI inference provider is configured for the deployment (currently Groq, United States), interaction content is sent to that provider for analysis and returned to the Service. This is the most important disclosure in this policy for a regulated operation.
- Merivex does not itself train, fine-tune or adapt any model on customer
data. Content is sent to the inference provider for inference only.
- Whether the inference provider may use submitted content for its own purposes
is governed by that provider's own terms, not by Merivex. We do not control, and do not make representations about, the provider's retention or training practices. The provider is named in our subprocessor register so that an organization can assess it directly.
- The inference provider can be pointed at any OpenAI-compatible endpoint,
including a self-hosted or in-tenant model, at the deployment level.
- AI agents in the Service operate inside the same tenant isolation and
authorization model as a human user, with no bypass, and each agent is limited to an explicit set of tools and memory scopes.
5. Sharing and subprocessors
We do not sell personal data. We share it with:
- Service providers ("subprocessors") that process data to help us run the
Service. The current register is published at www.merivex.ai/trust#subprocessors and today comprises: Neon (managed PostgreSQL database, Frankfurt, Germany), Cloudflare (application hosting, static site and application delivery, and object storage configured for the European Union jurisdiction), Groq (AI inference, United States), Resend (transactional email, United States), and Polar (subscription billing). Each is bound by a written contract with data-protection terms.
- Professional advisers, auditors, and authorities where required by law or
to establish, exercise or defend legal claims.
- A successor entity in connection with a merger, acquisition, or sale of
assets, subject to this policy.
We give organizations advance notice of new subprocessors that would process connected organization data, and an opportunity to object, as set out in the DPA.
6. International transfers
Merivex stores its primary relational database in Frankfurt, Germany, within the European Union. Transcript archive objects are stored in Cloudflare R2 configured for the European Union jurisdiction. Some subprocessors are located in the United States (currently the AI inference provider and the transactional email provider) or operate global edge networks. Where personal data protected by EEA, UK or Swiss law is transferred to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum / Swiss addendum as applicable), together with supplementary measures where needed. A copy of the transfer mechanism is available on request at privacy@merivex.ai.
7. Retention
- Account data is kept for as long as the account is active. When an account
or a workspace is closed, deletion is executed rather than queued behind a fixed waiting period, and the data is removed or anonymised. Records we are required to keep for longer, such as billing and tax records, are retained for the period the applicable law requires and for no other purpose.
- Connected organization data is retained under the controlling
organization's configuration. The Service supports a configurable retention policy per category (interactions, derived evaluations, AI history, audit history) and enforces a plan-level ceiling on the age of interaction and evaluation data, currently 12 months on the Starter plan and 24 months on the Growth plan, with custom periods on Enterprise plans.
- Backups. The managed database platform provides point-in-time recovery.
Deletion from the live database does not rewrite existing recovery snapshots; those age out on the platform's cycle, and a restore from an older snapshot is reconciled against the deletion record. Merivex also maintains tooling for an independent off-platform backup layer, but automated execution of that layer is currently disabled while it is being re-enabled on the current infrastructure.
- Audit logs are minimised (they never contain deleted content or request
selectors) and are retained under the organization's audit-retention setting or our default operational period.
8. Your rights
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. You also have the right to lodge a complaint with your local data-protection supervisory authority. In the EEA this is the authority for the country where you live or work, or where the issue arose; in the UK it is the Information Commissioner's Office.
For account data, contact privacy@merivex.ai. We will respond within the period required by applicable law (and in any event without undue delay). We may need to verify your identity before acting.
For connected organization data, the controlling organization is responsible for responding. The Service gives that organization self-service tools to search by stable identifier, export a structured archive, and carry out real deletion (not a reversible flag) down to a single individual. Direct your request to the organization that operates the workspace; we will assist them.
9. Security
We maintain technical and organizational measures appropriate to the risk, including: passwords stored with scrypt and per-user salts; datasource credentials encrypted with AES-256-GCM and never returned to the browser; TLS for data in transit with certificate verification on outbound database connections; per-organization tenant isolation covered by mandatory automated tests; parameterised database access; rate limiting on sensitive endpoints; and startup configuration validation that fails closed. A fuller description is in our security overview at www.merivex.ai/security and the self-assessment at www.merivex.ai/trust, which also states plainly what we do not yet have (for example, multi-factor authentication and third-party certifications).
10. Children
The Service is a business tool sold to organizations, is not directed to children, and is not intended to be used by anyone under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child's personal data has reached us through an account, write to privacy@merivex.ai and we will delete it.
11. Changes to this policy
We will post any changes on this page and update the "last updated" date. For material changes we will give reasonable advance notice by email to account administrators or in the Service before the change takes effect.
12. Contact
Privacy questions, data-subject requests and anything else arising from this policy: privacy@merivex.ai.
A postal address will be published here once a company is incorporated for Merivex. Until then, the mailbox above is the contact route of record.