1. Who we are
Meridian-One (“we,” “us”) provides a specialty clinic operating platform and related websites (including www.meridian-one.io and product gallery pages). Contact: contact@meridian-one.io.
2. Scope
This Policy covers information we collect through our marketing sites, product application, support channels, and related services. It applies to business clients, their authorized users, and website visitors. It does not replace clinic privacy notices that your practice provides to patients.
3. Information we collect
- Account & organization data — business name, contacts, roles, billing details, and configuration settings.
- Usage data — log data, device/browser information, IP address, feature usage, and diagnostics.
- Communications — messages you send to support or sales, and content of demos or onboarding forms.
- Client-managed content — data you or your users enter into the Service (which may include patient or prospect information under your control).
- Cookies & similar tech — on our websites for functionality, analytics, and preferences where permitted.
4. How we use information
- Provide, secure, and improve the Service
- Authenticate users and manage accounts
- Process payments and prevent fraud
- Provide support and send service-related notices
- Communicate about product updates or marketing (with opt-out where required)
- Comply with law and enforce our Terms of Service
5. PHI and clinic customer data
When Meridian-One acts as a service provider or business associate to a clinic customer, we process Client Data (including PHI, if applicable) under that customer’s instructions and applicable agreements. We do not use PHI for our own marketing. Patients should contact their clinic for rights requests about clinical records held by that clinic.
6. Sharing
We may share information with:
- Subprocessors that help host, support, communicate, or process payments — under contractual confidentiality and security obligations
- Professional advisors under confidentiality
- Authorities when required by law
- A successor in connection with a merger, acquisition, or asset sale, subject to appropriate protections
We do not sell personal information as “sale” is commonly defined under U.S. state privacy laws.
7. Retention
We retain information for as long as needed to provide the Service, meet legal and accounting requirements, resolve disputes, and enforce agreements. Retention for PHI in customer environments is also subject to the BAA and customer instructions.
8. Security
We use administrative, technical, and physical safeguards designed to protect information. No method of transmission or storage is completely secure; please use strong credentials and notify us of suspected incidents.
9. Your choices & rights
Depending on your location, you may have rights to access, correct, delete, or export certain personal information, or to opt out of certain processing. Marketing emails include unsubscribe options. Authorized client admins can manage many account settings in-product. Contact contact@meridian-one.io for privacy requests. We may need to verify your identity and will respond as required by applicable law.
10. International transfers
We primarily operate in the United States. If you access the Service from elsewhere, you understand information may be processed in the U.S. and other locations where we or our subprocessors operate.
11. Children
The Service is directed to businesses, not children. We do not knowingly collect personal information from children under 13 (or the age defined by local law) through our marketing sites.
12. Changes
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice when appropriate.
13. Contact
Privacy questions: contact@meridian-one.io