Meridian Recruitment
Legal

Privacy policy

How Meridian Recruitment collects, uses, discloses, transfers, retains and protects personal data — and how you exercise your rights under the GDPR and the Estonian Personal Data Protection Act.

Last updated 17 August 2026

Controller
MeridianTechnologies OÜ, registry code 17576566
Version
1.0
Effective date
17 August 2026
Governing law
GDPR · Estonian Personal Data Protection Act (IKS)
Supervisory authority
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Review cycle
Annually, and on any material change to processing
Contents

Section 1

Introduction

1.1 About us

Meridian Recruitment ("Meridian", "we", "us", "our") is a recruitment and staffing business established in Estonia. We work with employers — primarily technology companies and other organisations hiring skilled professionals — and with candidates across Estonia, the European Union, the European Economic Area and, in some assignments, further afield.

Our services may include permanent recruitment and direct placement, executive search, talent sourcing and headhunting, candidate screening and introductions, recruitment consulting, temporary agency work, outstaffing and staff augmentation, contractor placement, talent-database and candidate-relationship management, and client-relationship management.

Recruitment is, by its nature, an information business. We cannot introduce the right professional to the right employer without handling personal data. This policy explains, in plain terms, what we do with that data and what rights you have.

1.2 Purpose of this policy

This Privacy Policy describes how Meridian collects, uses, discloses, transfers, retains and protects personal data, and how you can exercise your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) ("IKS").

It is written to satisfy our transparency obligations under Articles 13 and 14 GDPR, including in situations where we obtain information about you from someone other than you.

1.3 Our commitment

We aim to process only the personal data we genuinely need for professional recruitment and business purposes, to be open about where that data comes from, to keep it secure and accurate, to keep it no longer than we can justify, and to make it straightforward for you to object, correct the record, or ask us to stop.

1.4 Who this policy applies to

This policy applies to:

  • candidates who apply to us or to roles we are handling;
  • prospective and passive candidates whom we identify and approach, including people who have never contacted us;
  • contractors, temporary workers and individuals engaged through outstaffing or staff-augmentation arrangements;
  • referees and other individuals who provide information about a candidate;
  • client representatives — hiring managers, HR and talent-acquisition professionals, executives, procurement and finance contacts;
  • prospective clients and other business contacts;
  • suppliers, recruitment partners and business partners, and their personnel;
  • visitors to our website and people who contact us by any channel;
  • our own personnel and applicants for roles within Meridian, where a separate internal privacy notice does not already apply.

1.5 What this policy does not cover

This policy does not govern how our clients, prospective employers, job boards, professional networks or other third parties process your personal data under their own responsibility. Those organisations have their own privacy notices. Where we act on behalf of a client as a processor rather than in our own right, that client's notice governs the processing, and we describe that situation in section 2.4.

Section 2

Data controller and contact details

2.1 Controller

Unless stated otherwise in this policy or in a specific notice given to you at the time, the controller of your personal data is:

Legal entity
MeridianTechnologies OÜ, trading as Meridian Recruitment
Estonian registry code
17576566
Registered office
Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia
Privacy contact
[email protected]
General contact
[email protected] · +1 (555) 014-2280
Website
https://meridian-recruitment.com

2.2 Data protection officer

Meridian has assessed whether it is required to appoint a data protection officer under Article 37 GDPR. We have not appointed a data protection officer, as we are not required to do so; privacy matters are handled by our privacy contact, who can be reached at [email protected]. We keep this assessment under review as our processing activities develop.

2.3 When Meridian acts as an independent controller

In most of what we do, we decide for ourselves why and how personal data is processed, and we are therefore the controller. This includes:

  • identifying and researching potential candidates;
  • building and maintaining our candidate database and talent network;
  • deciding which candidates to approach and which to put forward;
  • our own notes, assessments and records of recruitment activity;
  • managing our client and business relationships;
  • operating our website, systems and accounts.

2.4 When our clients are separate controllers

Once we introduce a candidate to a client, or a client otherwise legitimately receives candidate information from us, that client processes the information for its own hiring purposes and under its own responsibility. In that situation, Meridian and the client are each independent controllers — not joint controllers, and not controller and processor. Each of us is responsible for our own compliance, and the client's own privacy notice applies to what it does with the information.

We say this deliberately, because recruitment relationships are frequently mislabelled. Meridian acts as a processor for a client only where the client genuinely determines the purposes and means of the processing — for example, where we operate a client's own applicant-tracking system, run a recruitment process end-to-end inside the client's systems, or handle applications on the client's behalf under its instructions. Where that is the case, we put a written Article 28 GDPR data processing agreement in place, we act only on the client's documented instructions, and the client's privacy notice — not this one — is the primary notice for that processing.

Section 3

Categories of personal data

We process different categories of data depending on your relationship with us. We aim to hold what is relevant to professional recruitment and to our business relationships, and not more.

3.1 Candidates and prospective candidates

  • Identity and contact data: name; email address; telephone number; city, region and country of residence; postal address where relevant to an assignment or contract; date of birth where necessary (for example for contracting or right-to-work purposes).
  • Professional profile: CV or résumé; employment history; job titles; employers; education; professional qualifications and certifications; skills and technical expertise; industry and domain experience; languages; publications, talks or portfolio work.
  • Online professional presence: LinkedIn profile information; GitHub or comparable code-hosting profiles; personal or professional websites; other publicly available professional profiles.
  • Search and matching data: current and target role; seniority; salary and rate expectations; availability and notice period; preferred employment type (permanent, contract, temporary, outstaffing); location and relocation preferences; remote, hybrid or on-site preference; interests, motivations and reasons for considering a move.
  • Eligibility data: work authorisation and right to work; visa or permit status and expiry where relevant; nationality where genuinely necessary for immigration or contracting purposes.
  • Recruitment process data: applications and submissions; recruiter notes and assessments; interview scheduling and interview notes; test or assignment results where a client uses them; feedback from clients; status within a process; offers, negotiations and outcomes; reasons for withdrawal or rejection.
  • References: the identity and contact details of referees and the content of references given.
  • Relationship data: history of our communications with you (email, telephone, messaging and video-call records where kept); consents, preferences and objections; suppression records; records of which roles you were considered for or introduced to and when.
  • Placement and engagement data: placement history; contract and assignment information; start and end dates; agreed remuneration or rates.

3.2 Contractors, temporary workers and outstaffed personnel

In addition to the above, and only where we place or engage you in this way, we may process contract documentation, assignment details, working time and timesheet data, invoicing and payment data, bank details, tax and social-security identifiers, work-authorisation documentation, assignment-related performance or conduct information, and absence information where it is legally relevant to the engagement. Section 10 explains this in more detail.

3.3 Client contacts, prospects, suppliers and partners

Name; job title and function; business email address and telephone number; employer and business address; areas of hiring responsibility; correspondence and meeting records; contractual and commercial information; billing and payment contacts; business-development notes; event and marketing preferences.

3.4 Referees

Name; job title; employer; business contact details; the relationship to the candidate; and the substance of the reference provided.

3.5 Website visitors

Technical and usage data such as IP address, device and browser information, pages viewed, referring source, and interactions with forms — as described in section 19.

3.6 Special categories of personal data

We do not seek special-category data (Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, data concerning health, sex life or sexual orientation) as part of ordinary recruitment, and we ask candidates not to include it in CVs or applications.

Nevertheless, it can arise incidentally — a candidate may mention a health condition when discussing accommodations or availability, a CV may reveal a religious affiliation through past employment or volunteering, or a client may operate a diversity-monitoring programme. Where special-category data is genuinely necessary, we rely on an appropriate Article 9(2) condition, most commonly:

  • Article 9(2)(b) — necessary for carrying out obligations and exercising rights in the field of employment and social security law, as further provided under Estonian law (for example accessibility adjustments during a recruitment process, or obligations arising in an employment or agency-work relationship);
  • Article 9(2)(a) — your explicit consent, where no other condition applies;
  • Article 9(2)(f) — establishment, exercise or defence of legal claims.

Where special-category data reaches us unnecessarily, we will delete it or, where deletion is not practicable, restrict access to it.

3.7 Criminal conviction and offence data

We do not routinely process criminal-conviction or offence data (Article 10 GDPR). Under Article 10 GDPR and Estonian law, such data may only be processed where authorised by law or under the control of official authority.

Where a specific role carries a legal requirement or a genuine and proportionate need for a check — and only where Estonian or other applicable law permits it — any check will be arranged in accordance with the law of the relevant country, will be limited to what the role requires, and will normally be carried out by, or on the instruction of, the prospective employer rather than by Meridian. We do not build a criminal-records dataset, and we do not retain such information beyond the decision it was obtained for. See section 11.

3.8 Data minimisation

We apply Article 5(1)(c) GDPR in practice: information that is not reasonably relevant to a professional recruitment or business purpose should not be in our records. Recruiter notes are expected to be relevant, factual and professional, and to concern a person's suitability for work — not their private life.

Section 4

Sources of personal data

4.1 Information you give us

Directly from you when you apply for a role, send us your CV, register on our website, respond to an approach, speak with a consultant, attend an interview, complete a form, provide references, negotiate or enter into a contract, sign up to receive job alerts or updates, or contact us in any other way.

4.2 Information we obtain from other sources

We are a search business, and much of our work involves identifying professionals who have not contacted us. We may obtain personal data from:

  • LinkedIn and other professional networking platforms, including recruiter and talent-search products offered by those platforms;
  • job boards and CV databases, where a candidate has made a profile or CV available to recruiters;
  • GitHub and comparable technical or portfolio platforms;
  • company websites, conference and event listings, professional publications, industry directories and other publicly available professional sources;
  • recruitment and talent-sourcing databases and tools licensed by us;
  • referrals from other candidates, colleagues, clients or contacts in our network, including under any referral programme we operate;
  • clients, who may pass on candidate details, interview feedback or the details of their own staff as points of contact;
  • referees, former employers and (where applicable) educational institutions or certifying bodies, in each case with your knowledge;
  • recruitment partners and subcontractors with whom we work on an assignment;
  • background-screening and verification providers, where a check is lawfully carried out;
  • payroll, accounting, banking and compliance providers, in connection with contracts and placements.

4.3 Transparency when we obtain your data indirectly (Article 14 GDPR)

Where we obtain your personal data from a source other than you, Article 14 GDPR requires us to tell you about it. In practice:

  • If we contact you about an opportunity or about joining our network, we provide this privacy information in or with that first communication — normally by linking to this policy — and we tell you where we found your details if you ask.
  • If we obtain your details but do not contact you, we provide this information within a reasonable period and in any event within one month of obtaining the data, or at the point of first communication if that comes sooner.
  • If we intend to disclose your information to another recipient — for example by introducing you to a client — we provide this information at the latest when that disclosure is first made. In practice, we speak to you first (see section 8).

We may rely on the limited exemptions in Article 14(5) GDPR — for example where you already have the information, where providing it would involve disproportionate effort in the specific circumstances, or where disclosure is regulated by law. We do not treat "disproportionate effort" as a general excuse: our normal practice is to inform you.

The categories of data we obtain indirectly are those set out in section 3.1, and the sources are those listed in section 4.2.

Section 5

Purposes of processing

We process personal data for the following purposes.

5.1 Recruitment and search

  • Identifying and researching professionals who may be suitable for current or future roles.
  • Contacting individuals about specific opportunities, or about being included in our network.
  • Assessing suitability, seniority, skills and fit against a role specification.
  • Screening, qualifying and interviewing candidates.
  • Arranging and coordinating interviews, assessments and technical tests with clients.
  • Presenting and introducing candidates to clients, and managing the introduction process.
  • Managing applications received directly by us or through a client's process.
  • Advising candidates on roles, market conditions, compensation and process.
  • Obtaining and passing on references.
  • Managing offers, negotiations, counter-offers and start dates.
  • Recording outcomes, including unsuccessful outcomes and the reasons for them.

5.2 Talent network and future opportunities

  • Maintaining a structured candidate database so that we can match professionals with relevant roles over time rather than starting from zero for every assignment.
  • Keeping profiles current, including through periodic contact and profile-refresh requests.
  • Matching candidates against new assignments as they arise.
  • Sending job alerts and role notifications where you have asked for them or where it is within the scope of our legitimate interests as described in section 18.

5.3 Client and commercial relationships

  • Managing recruitment assignments, mandates and terms of business.
  • Communicating with hiring managers, HR contacts and other client personnel.
  • Business development, including contacting organisations that may need recruitment support.
  • Account management, reporting, invoicing and credit control.
  • Market intelligence, salary and market benchmarking, and hiring-trend analysis (which we carry out on an aggregated or de-identified basis wherever practicable).

5.4 Contract, placement and workforce administration

  • Preparing and administering candidate, contractor, temporary-worker and outstaffing contracts.
  • Managing assignments, timesheets, working time, invoicing, payroll and payments where we are the engaging or paying party.
  • Verifying work authorisation and satisfying immigration, tax and employment obligations.
  • Managing assignment performance, issues and terminations.

5.5 Operations, compliance and protection of our business

  • Operating, maintaining, securing and improving our website, systems and services.
  • Website analytics and service improvement.
  • Information security, access control, logging, fraud prevention and prevention of misuse of our systems.
  • Quality assurance, training and internal review of recruitment practice.
  • Accounting, tax, statutory reporting and audit.
  • Compliance with legal and regulatory obligations, including responding to lawful requests from authorities.
  • Handling complaints and data-subject requests.
  • Establishing, exercising or defending legal claims, including claims under our Terms of Business.
  • Maintaining suppression records so that people who have asked not to be contacted are not contacted again (see section 7.7).

Section 7

Candidate sourcing and headhunting

This section is central to how Meridian works, and we set it out separately.

7.1 What sourcing means

A significant part of our work is search: identifying professionals whose experience matches a client's requirement, and approaching them directly. Most of the people we identify have not applied to us and may never have heard of us. We call these passive candidates, and they have the same rights as anyone else.

7.2 Where we look

We identify potential candidates through LinkedIn and other professional networks; job boards and CV databases; GitHub and similar technical platforms; company websites and public professional profiles; conference programmes, publications and industry research; licensed recruitment databases and sourcing tools; and referrals from our network.

We look at professional sources for professional information. We do not trawl personal social media, private accounts or personal life for information about candidates, and we do not collect information about your private circumstances, opinions or beliefs.

7.3 Our legal basis

We rely on legitimate interests under Article 6(1)(f) GDPR, as explained in section 6.1. The interest is in operating a recruitment service that connects skilled professionals with relevant opportunities — an activity that both employers and candidates rely on, and that professionals who publish their experience on professional platforms can reasonably anticipate.

7.4 Why we may contact you

We contact you because we believe a specific role, or the type of role we recruit for, may be relevant to your experience and career. We aim for approaches to be targeted, honest about who we are and what the opportunity is, and easy to decline.

7.5 What we retain at the initial stage

Before you respond to us, we typically hold only a limited professional record: your name; the professional contact details available to us; your current or recent role and employer; a summary of your skills and experience; the public professional profile or source we identified you from; and a note of what we contacted you about and when.

If you engage with us, we build on that record with the information described in section 3.1. If you do not respond at all, we keep the record only for as long as our retention criteria in section 15 support, and then delete it.

7.6 Your rights when you have been sourced

You may, at any time and without giving a reason:

  • ask where we obtained your details and what we hold (Article 15);
  • correct anything inaccurate (Article 16);
  • object to our processing (Article 21) — including our holding you in our database at all;
  • ask us to delete your record (Article 17);
  • ask us simply to stop contacting you.

Write to [email protected], reply to the recruiter who approached you, or use any opt-out link we provide. We do not require you to justify the request, and we do not treat a request to stop as an invitation to try again later.

7.7 If you ask us not to contact you — suppression records

If you object to further contact or ask us to erase your data, we act on that request. But there is a practical problem: if we delete every trace of you, nothing prevents a consultant from finding your public profile again next month and approaching you a second time.

To prevent that, we keep a minimal suppression record — normally your name and the specific contact identifiers we must be able to recognise (such as an email address or LinkedIn profile URL, which we may hold in hashed form where technically feasible), together with the date and the fact that you asked not to be contacted. We hold no CV, no notes, no assessments and no other profile content.

We rely on legitimate interests, and on our obligation under Article 5(1) GDPR to process fairly and to honour objections effectively, as the basis for this minimal record. It exists solely to protect you from unwanted contact and is never used to contact you, to build a profile or for any other purpose. We keep it for as long as the risk of inadvertent re-contact persists. If you would prefer us to delete even this record — accepting that we may then be unable to recognise you if your details resurface — tell us and we will do so.

7.8 If you decline a particular opportunity

Declining a specific role is not the same as asking us to stop entirely, and we do not treat it as such. Unless you tell us otherwise, we may keep your details and contact you about materially different opportunities in future. If you would rather we did not, say so and we will apply section 7.7.

Section 8

Sharing candidate information with clients

8.1 Internal consideration versus disclosure

There is an important distinction between two things:

  • Internal matching. We may consider you against a role, search our database, and discuss internally whether your background fits, without disclosing anything about you to anyone outside Meridian. Sometimes we discuss a profile with a client in anonymised terms — for example "a senior backend engineer with eight years in payments infrastructure, currently at a large marketplace" — without identifying you.
  • Disclosure. Sending your CV, name or other identifying details to a client is a disclosure of your personal data to a separate controller. It is a different act with different consequences, and we treat it as such.

8.2 We speak to you before we introduce you

Our practice is that we do not submit an identifiable candidate profile to a specific employer without first informing you of the role and the employer and obtaining your agreement to be put forward. This is standard good practice in professional recruitment, and it protects you: an unwanted submission can affect your current employment, your relationship with an employer you have already approached directly, and your position in other processes.

Where you have applied directly to a role we are handling for a named client, your application is itself your instruction to us to submit you for that role.

Your agreement to be introduced is an instruction from you, not a GDPR consent that we use as the legal basis for the underlying processing — that remains Article 6(1)(b) or 6(1)(f) as set out in section 6. This matters because it means the safeguard applies to you regardless of which legal basis is engaged.

8.3 What we share

We share what the client needs to evaluate you, which normally means your CV or a profile summary, your experience, skills, qualifications and languages, your availability and notice period, your location and work-authorisation position, your compensation expectations where relevant to the process, and interview and assessment information generated during the process. We provide references only where you have agreed and where the process has reached the appropriate stage.

We do not send irrelevant information, private information, or information that the client has no need for.

8.4 How we handle CVs

We do not circulate CVs speculatively. Your CV is not sent to employers you have not agreed to, is not used as a marketing tool, is not shared with other candidates, and is not distributed within our network of clients "in case someone is interested".

8.5 What happens after disclosure

Once a client legitimately receives your information, it processes that information as an independent controller for its own hiring purposes, under its own privacy notice and its own retention rules. Our Terms of Business require clients to use candidate information only for the role for which the introduction was made, to keep it confidential, and to comply with data protection law — but we cannot control their processing, and requests about what a client does with your data (including erasure) need to go to that client. We will tell you which client received your details and help you make contact.

8.6 Other candidate-related disclosures

We may also share candidate information with recruitment partners where we work jointly on an assignment and you have been informed; with our service providers as described in section 13; and with authorities where legally required.

8.7 "Candidate ownership" is a commercial concept, not a data right

Recruitment contracts often refer to candidate "ownership" or introduction rights — commercial arrangements between Meridian and a client about who is entitled to a fee if a candidate is hired. These arrangements concern money between businesses. They say nothing about you and confer no ownership of you or of your personal data on anyone. Nobody owns your personal data. Your GDPR rights are unaffected by our Terms of Business, and we will never cite a commercial introduction right as a reason for refusing a data-protection request.

Section 9

Client, prospect and business contact information

9.1 Whose data

We process personal data about individuals in their professional capacity at client and prospective client organisations, suppliers, recruitment partners and other business contacts — including hiring managers, HR and talent-acquisition professionals, executives and founders, procurement, legal and finance contacts.

9.2 What we process

Name; job title and function; business contact details; employer and business address; hiring responsibilities and areas of interest; records of our correspondence, calls and meetings; contract and commercial terms; billing and payment contacts; event attendance; communication preferences; and business-development notes.

9.3 Why, and on what basis

We process this data to manage assignments and contracts, to communicate about live roles and candidates, to administer accounts and invoicing, and to develop our business — including contacting organisations we believe may need recruitment support.

Our legal basis is legitimate interests (Article 6(1)(f)): maintaining commercial relationships and promoting a B2B service to organisations likely to have a use for it. Where processing is necessary to perform a contract with you personally, or to comply with a legal obligation such as invoicing and accounting, we rely on Articles 6(1)(b) and 6(1)(c) respectively.

B2B contact data is professional information used for professional purposes, and business contacts generally expect to be approached about relevant services. We keep our outreach relevant and proportionate, we identify ourselves clearly, and every business communication includes a means of opting out. Electronic marketing is also subject to the rules described in section 18.

9.4 Your rights as a business contact

You have the same rights as anyone else, including the right to object to our processing for business-development purposes at any time. If you object, we will stop, and we may keep a minimal suppression record on the same basis as section 7.7.

Section 10

Temporary workers, contractors and outstaffing

This section applies where Meridian places you as a temporary agency worker, engages you as a contractor, or provides your services to a client under an outstaffing or staff-augmentation arrangement.

10.1 Additional data

In these arrangements we may additionally process: contract documentation and signature records; assignment details, including the client, project, role and duration; working hours, timesheets and leave records; rates, remuneration, expenses and invoices; bank account and payment details; tax and social-security identifiers and residence status; work-authorisation and permit documentation; equipment and system-access records; assignment-related performance, conduct and incident information; absence and sickness information where it is legally relevant to the engagement or to pay; and compliance and audit documentation.

10.2 Legal bases

  • Article 6(1)(b) — negotiating and performing your contract with us, administering assignments, timesheets and payment.
  • Article 6(1)(c) — tax, social-security, accounting, employment, working-time and immigration obligations.
  • Article 6(1)(f) — managing assignments and client relationships, protecting our systems and business, and handling claims.
  • Article 9(2)(b) and, where relevant, Article 9(2)(f) — health-related information where it is necessary for employment or social-security law purposes or for legal claims. We process only what is needed (for example the fact and duration of an absence), not clinical detail beyond that.

10.3 Sharing with the client

Where you work on a client assignment, the client will necessarily receive information such as your name, role, contact details, working arrangements and, in some cases, timesheet or attendance data. The client processes that information as an independent controller for its own purposes.

10.4 Additional notices

Where Meridian directly employs or contracts with you, a further and more detailed privacy notice covering the employment or contractor relationship will be provided to you at or before the start of the engagement. That notice supplements this policy, and prevails over it in the event of a conflict in relation to that relationship.

Section 11

References and background checks

11.1 References

We contact referees only at the appropriate stage of a process, and only where you have provided or agreed to the referee, or where a client requires references as a condition of an offer. We tell you before references are taken up.

We ask about matters relevant to the role: the dates and nature of your engagement, your responsibilities, performance and conduct, and eligibility for re-engagement. We do not ask about health, private life or other irrelevant matters.

Reference content is treated as confidential, is shared with the client for whom it was obtained, and is retained with the recruitment record.

Legal bases: Article 6(1)(b) (steps at your request in a recruitment or engagement process) and Article 6(1)(f) (providing a competent service to clients and verifying information). For the referee's own data, our basis is legitimate interests in obtaining and recording the reference.

11.2 Background and pre-employment checks

Checks are carried out only where they are lawful in the relevant country, genuinely relevant to the role, proportionate to it, and necessary — never as a routine step applied to everyone.

Where a check is appropriate, we tell you in advance what will be checked and by whom, we limit it to what the role requires, and we use reputable providers under written data-processing terms. Identity and right-to-work verification, and verification of qualifications or professional registrations where a role depends on them, are the most common examples.

Criminal-record checks are subject to section 3.7: they are undertaken only where Estonian or other applicable law permits, are normally the responsibility of the prospective employer, and are limited to information relevant to the specific role. We do not retain criminal-record information beyond the decision it was obtained for.

Credit, social-media and other intrusive checks are not part of our standard process and would be undertaken only where a specific legal or role-based justification exists.

Section 12

Recruitment technology, automation and AI

12.1 What we use technology for

Modern recruitment relies on software, and we use it to work efficiently. Our systems and tools may:

  • store and organise candidate and client records in an applicant-tracking system or CRM;
  • search and filter our database and external sources by criteria such as skills, seniority, location, languages or availability;
  • parse CVs into structured fields;
  • identify and rank profiles for relevance against a role specification;
  • suggest candidates a recruiter may wish to consider;
  • summarise CVs, notes, calls or correspondence to assist a consultant;
  • draft communications for a consultant to review, edit and send;
  • support scheduling, workflow, reporting and administration.

Some of these tools use machine learning or generative AI. Where they do, we select providers that offer appropriate contractual and security protections, we do not permit them to use our data to train their general models unless we have specifically agreed to it, and we assess them before use.

12.2 Human decision-making

Meridian does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Decisions about whether to approach you, whether to progress your candidacy, and whether to present you to a client are made by our consultants. Automated tools may surface, rank or summarise information; a person evaluates it, can and does look beyond it, and takes the decision.

If we ever adopt a system that would make such decisions solely automatically, we will inform affected individuals beforehand, explain the logic involved and the consequences, identify the legal basis under Article 22 GDPR, and provide the safeguards Article 22(3) requires — including the ability to obtain human intervention, to express your point of view, and to contest the decision.

12.3 Client-side automation

Clients may use their own assessment tools, automated screening or AI in their hiring processes. Those are the client's systems and the client's responsibility as a controller. If you have concerns about how a specific employer assesses candidates, we will help you raise them with that employer.

12.4 Profiling

Matching a candidate profile against a role specification involves an element of profiling in the GDPR sense. It is limited to professional attributes, it informs rather than determines outcomes, and you may object to it under Article 21 GDPR.

Section 13

Recipients of personal data

We do not sell personal data. We disclose it only to the following categories of recipient, and only as far as necessary:

  • Meridian personnel — consultants, researchers, delivery, operations and administrative staff, on a need-to-know basis under access controls and confidentiality obligations.
  • Clients and prospective employers — as described in section 8, as independent controllers.
  • Recruitment partners and subcontracted researchers or sourcers — where we work jointly on an assignment, under written confidentiality and data-protection terms.
  • Applicant-tracking, CRM and recruitment-platform providers — as processors hosting our candidate and client records.
  • Cloud hosting and infrastructure providers — as processors.
  • Email, calendar, video-conferencing, messaging, telephony and document-collaboration providers — as processors.
  • Sourcing, enrichment and search-tool providers — as processors or, where they act in their own right, as independent controllers under their own notices.
  • Background-screening and verification providers — as processors, where a lawful check is carried out.
  • Payroll, accounting, invoicing and bookkeeping providers, and banks and payment providers — for placements, contractor engagements and our own administration.
  • Professional advisers — lawyers, accountants, auditors, tax advisers and insurers, bound by professional confidentiality.
  • IT support, security and analytics providers — as processors.
  • Public authorities, courts and regulators — where required by law or necessary to establish, exercise or defend legal claims, including the Estonian Tax and Customs Board, the Estonian Data Protection Inspectorate and equivalent bodies in other countries.
  • Acquirers or investors — in the context of a merger, acquisition, financing or reorganisation, subject to confidentiality undertakings and, on completion, to the successor's obligations as controller.

13.1 Contractual protections

Where a recipient acts as a processor, we put a written agreement in place meeting Article 28 GDPR, requiring the processor to act only on our instructions, to keep the data confidential, to apply appropriate security measures, to engage sub-processors only under equivalent terms and with our authorisation, to assist us with data-subject requests and breach notification, and to delete or return the data at the end of the engagement. We assess providers before engaging them and keep that assessment under review.

Where a recipient acts as an independent controller — most importantly our clients — we rely on contractual commitments in our Terms of Business regarding confidentiality, permitted use and data protection compliance, but the recipient is responsible for its own processing.

Section 14

International data transfers

Meridian operates in an international market. Candidates, clients and technology providers may be located outside the European Economic Area, and we do not claim that your data will never leave the EEA. It may, in the following situations:

  • where a client, prospective employer or group company that you have agreed to be introduced to is located outside the EEA — for example a US or UK employer hiring for a remote or relocated role;
  • where a candidate, contractor or business contact is themselves located outside the EEA;
  • where a technology provider we use processes or stores data outside the EEA, or provides support from outside the EEA;
  • where our advisers or auditors are located outside the EEA;
  • where a legal obligation or legal claim requires it.

14.1 Safeguards

Where we transfer personal data outside the EEA, we rely on one of the following mechanisms under Chapter V GDPR:

  • an adequacy decision of the European Commission under Article 45 GDPR, where the destination country or framework benefits from one;
  • Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, supplemented where necessary by a transfer impact assessment and by additional technical, organisational and contractual measures such as encryption in transit and at rest, access restrictions, and commitments on handling government access requests;
  • binding corporate rules or another approved mechanism under Article 46 GDPR, where a provider offers one;
  • a derogation under Article 49 GDPR, in limited situations — most relevantly where a transfer is necessary for the performance of a contract with you or for pre-contractual steps taken at your request, or where it is necessary for the establishment, exercise or defence of legal claims. Introducing you to an employer outside the EEA, at your request and with your agreement, is the typical example.

You may request further information about the safeguards applied to a specific transfer, and a copy of the relevant Standard Contractual Clauses (redacted as to commercial terms), by contacting [email protected].

Section 15

Data retention

15.1 Principles

We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires. When it is no longer needed, we delete it or irreversibly anonymise it. Where deletion is not immediately possible — for example in backups — we isolate the data and delete it as part of our normal backup cycle.

15.2 Criteria we apply

We determine retention by reference to:

  • the purpose the data was collected for, and whether that purpose is still live;
  • the nature and current state of our relationship with you, including recency of contact and whether you remain open to opportunities;
  • the realistic likelihood of relevant future opportunities in your field;
  • the length of applicable limitation periods for legal claims;
  • contractual obligations, including to clients;
  • statutory retention obligations, including accounting, tax and employment law;
  • any objection, erasure request or restriction you have made;
  • the sensitivity of the data and the risk that continued retention would present.

15.3 Indicative retention periods

The periods below are our operating baseline. They may be shortened where data is no longer relevant, or extended where a live legal claim, a statutory obligation or your explicit request requires it.

CategoryIndicative periodReasoning
Candidate database / talent network profilesReview at 24 months from the last meaningful interaction; delete unless there is a demonstrable reason to keep the record, with a further review no later than every 24 months thereafterProfessional careers move on a multi-year cycle, and a profile older than two years without contact is usually stale. Periodic review, rather than open-ended retention, is what storage limitation requires.
Sourced candidates who never responded12 months from the approachIf there has been no engagement at all, we cannot justify holding the record longer.
Active candidates in a live processFor the duration of the process, then as per the applicable category belowNecessary to run the process.
Unsuccessful candidates (applied or introduced, not placed)12 months from the conclusion of the process, unless the candidate remains in the talent network under the row aboveCovers limitation periods for discrimination or recruitment-related claims, allows us to explain decisions, and preserves the record of what was considered.
Placed candidates (permanent placements)For the duration of any guarantee or rebate period plus the applicable limitation period for claims under the client contract, typically up to 3 years thereafter; core placement records may be kept longer where an accounting or contractual obligation appliesNecessary to administer fees, guarantees and disputes.
Contractors, temporary workers and outstaffed personnelFor the engagement plus the longer of the applicable employment-law limitation period and any statutory retention requirement; documents forming part of accounting records for 7 years from the end of the financial yearEmployment, tax and accounting obligations.
Payroll, invoicing, tax and accounting records7 years from the end of the financial year in which the transaction was recordedEstonian Accounting Act (Raamatupidamise seadus) source-document retention requirement.
Client and business contactsFor the duration of the relationship plus 24 months from the last meaningful interaction; contract-related records for the term plus the applicable limitation periodCommercial relationships are periodic, and dormant contacts should be removed.
Client contracts and Terms of BusinessTerm plus the applicable limitation period, generally up to 10 years where a longer contractual limitation period appliesEstablishing and defending claims.
Recruitment correspondenceWith the associated candidate, client or engagement recordCorrespondence has no independent purpose.
ReferencesWith the associated recruitment or placement recordOnly relevant in the context of the decision it supported.
Criminal-record and background-check outcomesDeleted once the relevant decision is made and any appeal window has closed; normally we record only the outcome and the date, not the underlying detailData minimisation and Article 10 GDPR.
Suppression recordsFor as long as necessary to prevent inadvertent re-contact, subject to periodic reviewHonouring your objection effectively (section 7.7).
Website analyticsIn line with the retention settings of the analytics tool in use, and no longer than 26 monthsAnalytics loses value quickly and should not be kept indefinitely.
CookiesAs set out in our Cookie Policy / cookie settings interfaceSee section 19.
Security and access logsUp to 12 months, unless required longer for an investigationSecurity monitoring and incident response.
Data-subject requests and complaints3 years from resolutionDemonstrating accountability under Article 5(2) GDPR.

15.4 No indefinite retention

We do not claim a right to hold candidate data indefinitely. Being in our talent network is not a permanent state: records are reviewed, and records we cannot justify are deleted. You can ask at any time to be removed, and we will not require a reason.

Where you ask us to retain your details for longer than our criteria would otherwise support — for example because you expect to be looking again in three years — we can do so on the basis of your consent, which you may withdraw at any time.

Section 16

Data security

We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. Depending on the system, these include:

  • role-based access control, so that consultants and staff can reach only the data they need;
  • individual named accounts, strong authentication requirements and multi-factor authentication on key systems;
  • encryption in transit, and encryption at rest where our systems and providers support it;
  • reputable cloud infrastructure and business applications, hosted in the EEA wherever practicable;
  • confidentiality obligations in every employment, contractor and supplier agreement;
  • data-protection and security training for personnel who handle candidate and client data;
  • policies covering acceptable use, device security, remote working and secure disposal;
  • logging and monitoring of access to systems containing personal data;
  • backups and tested restoration procedures;
  • security and privacy assessment of vendors before engagement, and written processing terms with each processor;
  • a documented incident-response and breach-assessment procedure (section 22);
  • periodic review of access rights, retention and the measures above.

No system, and no organisation, can be completely secure, and we do not claim otherwise. What we can commit to is applying measures proportionate to the risk, reviewing them as risks change, and acting promptly and transparently if something goes wrong.

Section 17

Your rights

Subject to the conditions and exceptions in the GDPR, you have the following rights.

17.1 Right of access (Article 15)

You may ask whether we process your personal data and, if so, receive a copy of it together with information about the purposes, categories, recipients, retention, the source of the data and your rights. Where providing a copy would adversely affect the rights and freedoms of others — for example a referee's identity, confidential client information, or another candidate's data in the same document — we will provide the information in a way that protects those rights, and explain what we have withheld and why.

17.2 Right to rectification (Article 16)

You may have inaccurate data corrected and incomplete data completed. This is a practical right that matters in recruitment: if our record of your seniority, technology stack, salary expectation or availability is wrong, it affects the roles you hear about. Tell us and we will fix it.

17.3 Right to erasure (Article 17)

You may ask us to delete your personal data, including where it is no longer necessary for the purposes it was collected for, where you have withdrawn consent and no other basis applies, or where you have successfully objected under Article 21.

We may be unable to delete everything where we must keep records to comply with a legal obligation (for example accounting records), to establish, exercise or defend legal claims, or where we retain a minimal suppression record under section 7.7. Where that applies, we will tell you what remains and why.

If you were introduced to a client, deletion by us does not delete the copy held by that client. We will tell you which clients received your information so that you can approach them directly, and we will notify recipients of your erasure or rectification request where required under Article 19 GDPR.

17.4 Right to restriction (Article 18)

You may ask us to restrict processing — for example while we verify the accuracy of data you dispute, or while we assess an objection you have made. Restricted data is stored but not otherwise used.

17.5 Right to data portability (Article 20)

Where processing is based on consent or on a contract with you and is carried out by automated means, you may receive the data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible. This right does not extend to our own assessments, notes or analysis about you.

17.6 Right to object (Article 21)

This right matters most in recruitment, so we set it out in full.

Direct marketing. You have an absolute right to object to processing for direct marketing purposes, including any profiling related to it. If you object, we stop. No balancing, no exceptions.

Legitimate-interest processing. You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) — including:

  • our contacting you about roles and opportunities;
  • our holding your profile in our candidate database at all;
  • our sourcing and research activities concerning you;
  • business-development communications, if you are a business contact;
  • profiling and matching against role specifications.

When you object, we stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is needed for legal claims. In practice, for objections to recruitment contact and database retention, we will normally simply comply — a candidate who does not want to be in a recruiter's database is unlikely to be a candidate we can usefully help, and we do not consider it appropriate to argue the point. We assess each objection on its facts and explain the outcome to you.

17.7 Right to withdraw consent (Article 7(3))

Where we rely on consent, you may withdraw it at any time, as easily as you gave it. Withdrawal is not retrospective and does not affect processing under another legal basis.

17.8 Rights relating to automated decision-making (Article 22)

As set out in section 12, we do not make decisions producing legal or similarly significant effects solely by automated means. If that changes, you will have the right to obtain human intervention, express your point of view and contest the decision.

17.9 Right to lodge a complaint

See section 23.

17.10 How to exercise your rights

Contact [email protected], or write to us at the address in section 2.1. Please tell us what you want and, where you can, which recruiter or process the request relates to — it helps us find your records.

We respond within one month. Where a request is complex or where you have made a number of requests, we may extend this by up to two further months, and we will tell you within the first month if we do, together with the reasons.

We may need to verify your identity before acting, particularly where a request concerns deletion or a copy of your data. We will ask only for what is proportionate, and we will not use identity documents for any other purpose or keep them beyond verification.

Exercising your rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if we ever do.

Section 18

Recruitment communications and direct marketing

Not every message from a recruiter is marketing, and treating them as identical serves nobody. We distinguish three things.

18.1 Recruitment communications about specific opportunities

An approach about a particular role that appears relevant to your experience, or a discussion of a live process you are part of. This is our core recruitment activity, carried out under Article 6(1)(f) or, where you are already in a process, Article 6(1)(b). It is not generic advertising, and it is directed at you because of your specific professional background.

You may stop these at any time under section 17.6 and we will apply section 7.7. We also apply judgement: we do not send repeated approaches to someone who has not responded, and we do not re-approach about substantially the same role.

18.2 Candidate relationship communications

Job alerts you have signed up for, updates on a process you are in, market and salary information, requests to refresh your profile, and administrative messages. Where you have asked for these, we rely on your request; otherwise we rely on legitimate interests. Every such message includes a means of opting out.

18.3 Commercial marketing

Newsletters, service promotion, event invitations, thought-leadership content and business-development campaigns aimed at organisations that may buy our services.

For electronic marketing we comply with the applicable ePrivacy rules, which in Estonia are implemented principally through the Electronic Communications Act (Elektroonilise side seadus), as well as with equivalent rules in other countries where recipients are located. In practice this means:

  • we obtain prior consent for electronic marketing to individuals where the law requires it;
  • where we contact business contacts on the basis of legitimate interests, we do so only in relation to services relevant to their professional role, and only where permitted in their country;
  • every marketing message identifies Meridian clearly and includes a working, one-click unsubscribe mechanism;
  • we act on opt-outs promptly and record them so they persist;
  • we do not send marketing to anyone who has objected, and we do not use recruitment contact as a route to marketing someone who has opted out of it.

18.4 Opting out

Use the unsubscribe link in any message, reply to the sender, or write to [email protected]. Tell us what you want to stop — all contact, marketing only, or job approaches only — and we will apply exactly that.

Section 19

Cookies and website technologies

19.1 What we use

Our website may use:

  • Strictly necessary cookies — required for the site to function, for security, for load balancing and for remembering your cookie choices. These do not require consent.
  • Analytics cookies and similar technologies — to understand how the site is used and to improve it.
  • Preference cookies — to remember settings such as language.
  • Marketing and advertising technologies — where we use them, for example to measure campaign effectiveness or to reach relevant audiences.

19.2 Consent

Non-essential cookies and similar technologies (including local storage, pixels and tags) are used only where legally permitted and, where consent is required, only after you have given it through our cookie banner or settings interface. You may change or withdraw your choices at any time through that interface, and through your browser settings.

Where consent is the basis, the legal basis for the associated personal-data processing is Article 6(1)(a) GDPR; for strictly necessary technologies it is Article 6(1)(f) — operating and securing our website.

19.3 Further detail

A separate Cookie Policy and cookie-management interface set out the specific cookies and technologies in use, their purposes, their providers and their durations, and are updated when those change. We have not named specific analytics or advertising providers in this policy because they are listed and kept current in the Cookie Policy.

19.4 Do Not Track and global privacy signals

Where our website recognises a browser-level opt-out signal that applicable law requires us to honour, we will treat it as an objection to the relevant processing.

Section 20

Social media and third-party websites

We maintain profiles on professional and social platforms, including LinkedIn, where we publish roles, share content and communicate with candidates and clients. If you interact with us there — by following, messaging, commenting or applying through the platform — the platform processes your data under its own terms and privacy policy, and it may act as a controller or joint controller in relation to insights and analytics it generates. We do not control those practices.

We also use professional platforms as sourcing tools, as described in section 7.

Our website may link to third-party sites, including client career pages, job boards and application systems. Those sites are outside our control, and this policy does not apply to them. We encourage you to read the privacy notice of any site you provide information to.

Section 21

Children

Our services are directed at working professionals, and our website and recruitment services are not intended for children. We do not knowingly recruit for roles requiring candidates below the minimum working age, and we do not knowingly maintain profiles of children in our talent network.

We recognise that in Estonia and elsewhere young people above the applicable minimum working age may lawfully apply for employment, and we do not exclude them from applying for a role for which they are legally eligible. Where an applicant is a minor, we process only what the specific application requires, we apply the additional protections that Estonian employment law provides for minors, and we obtain the consent or authorisation of a parent or legal guardian where the law requires it.

Under the Estonian Personal Data Protection Act, consent to the processing of a child's personal data in the context of information society services offered directly to a child is valid from age 13; below that age, a legal representative must give or authorise the consent.

If you believe we hold data about a child in circumstances that are not appropriate, contact us at [email protected] and we will review it and delete it where it should not be held.

Section 22

Personal data breaches

We maintain a documented procedure for identifying, containing, assessing and recording personal-data breaches. All personnel are instructed to report suspected incidents immediately, and our processors are contractually required to notify us without undue delay.

Every incident is assessed for the risk it poses to the rights and freedoms of the individuals affected, and recorded in our internal breach register regardless of whether it is notifiable.

Where a breach is likely to result in a risk to your rights and freedoms, we notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR.

Where a breach is likely to result in a high risk to your rights and freedoms, we notify affected individuals without undue delay, in clear language, describing what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself — in accordance with Article 34 GDPR.

Where we act as a processor for a client, we notify that client without undue delay so that it can meet its own obligations.

Section 23

Complaints and the supervisory authority

23.1 Contact us first

If you are unhappy with how we have handled your personal data or your request, please tell us at [email protected]. We would rather hear about a problem and fix it than have you take it elsewhere first, and most issues can be resolved quickly and directly. Raising it with us does not affect your right to complain to a supervisory authority at any time.

23.2 Estonian Data Protection Inspectorate

You have the right under Article 77 GDPR to lodge a complaint with a supervisory authority. Meridian's lead supervisory authority is:

Authority
Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Address
Tatari 39, 10134 Tallinn, Estonia
Website
www.aki.ee

Please check the Inspectorate's website for its current contact details and complaint procedures, which it updates from time to time.

23.3 Other supervisory authorities

You may instead complain to the supervisory authority in the EU or EEA country where you live, where you work, or where the alleged infringement took place. A list of European supervisory authorities is maintained by the European Data Protection Board at www.edpb.europa.eu.

23.4 Judicial remedies

You also have the right to an effective judicial remedy against a supervisory authority or against Meridian under Articles 78 and 79 GDPR, and to seek compensation for damage suffered as a result of an infringement under Article 82 GDPR.

Section 24

Changes to this privacy policy

We review this policy periodically and update it when our processing, our systems or the law change. The "Last updated" date at the top shows when the current version took effect, and we keep previous versions on file.

Where a change is material — for example a new purpose, a new category of recipient, or a change in legal basis — we will take reasonable steps to bring it to your attention before it takes effect, which may include emailing candidates and contacts we are in touch with, or displaying a notice on our website. Minor clarifications will simply be published here.

Where a change requires your consent under the GDPR, we will obtain it before relying on the change.

Section 25

Contacting us

For any question about this policy, about how we handle your personal data, or to exercise your rights:

Privacy enquiries
[email protected]
Postal address
MeridianTechnologies OÜ, Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia
General enquiries
[email protected] · +1 (555) 014-2280

We aim to acknowledge privacy enquiries within five working days and to resolve them within the timeframes set out in section 17.10.

© 2026 MeridianTechnologies OÜ. Meridian Recruitment is a trading name of MeridianTechnologies OÜ, registered in the Estonian Commercial Register (Äriregister) under code 17576566, with its registered office at Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia.