Privacy policy
How Meridian Recruitment collects, uses, discloses, transfers, retains and protects personal data — and how you exercise your rights under the GDPR and the Estonian Personal Data Protection Act.
Last updated 17 August 2026
- Controller
- MeridianTechnologies OÜ, registry code 17576566
- Version
- 1.0
- Effective date
- 17 August 2026
- Governing law
- GDPR · Estonian Personal Data Protection Act (IKS)
- Supervisory authority
- Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
- Review cycle
- Annually, and on any material change to processing
Contents
- 1Introduction
- 2Data controller and contact details
- 3Categories of personal data
- 4Sources of personal data
- 5Purposes of processing
- 6Legal bases under the GDPR
- 7Candidate sourcing and headhunting
- 8Sharing candidate information with clients
- 9Client, prospect and business contact information
- 10Temporary workers, contractors and outstaffing
- 11References and background checks
- 12Recruitment technology, automation and AI
- 13Recipients of personal data
- 14International data transfers
- 15Data retention
- 16Data security
- 17Your rights
- 18Recruitment communications and direct marketing
- 19Cookies and website technologies
- 20Social media and third-party websites
- 21Children
- 22Personal data breaches
- 23Complaints and the supervisory authority
- 24Changes to this privacy policy
- 25Contacting us
Section 1
Introduction
1.1 About us
Meridian Recruitment ("Meridian", "we", "us", "our") is a recruitment and staffing business established in Estonia. We work with employers — primarily technology companies and other organisations hiring skilled professionals — and with candidates across Estonia, the European Union, the European Economic Area and, in some assignments, further afield.
Our services may include permanent recruitment and direct placement, executive search, talent sourcing and headhunting, candidate screening and introductions, recruitment consulting, temporary agency work, outstaffing and staff augmentation, contractor placement, talent-database and candidate-relationship management, and client-relationship management.
Recruitment is, by its nature, an information business. We cannot introduce the right professional to the right employer without handling personal data. This policy explains, in plain terms, what we do with that data and what rights you have.
1.2 Purpose of this policy
This Privacy Policy describes how Meridian collects, uses, discloses, transfers, retains and protects personal data, and how you can exercise your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR") and the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus) ("IKS").
It is written to satisfy our transparency obligations under Articles 13 and 14 GDPR, including in situations where we obtain information about you from someone other than you.
1.3 Our commitment
We aim to process only the personal data we genuinely need for professional recruitment and business purposes, to be open about where that data comes from, to keep it secure and accurate, to keep it no longer than we can justify, and to make it straightforward for you to object, correct the record, or ask us to stop.
1.4 Who this policy applies to
This policy applies to:
- candidates who apply to us or to roles we are handling;
- prospective and passive candidates whom we identify and approach, including people who have never contacted us;
- contractors, temporary workers and individuals engaged through outstaffing or staff-augmentation arrangements;
- referees and other individuals who provide information about a candidate;
- client representatives — hiring managers, HR and talent-acquisition professionals, executives, procurement and finance contacts;
- prospective clients and other business contacts;
- suppliers, recruitment partners and business partners, and their personnel;
- visitors to our website and people who contact us by any channel;
- our own personnel and applicants for roles within Meridian, where a separate internal privacy notice does not already apply.
1.5 What this policy does not cover
This policy does not govern how our clients, prospective employers, job boards, professional networks or other third parties process your personal data under their own responsibility. Those organisations have their own privacy notices. Where we act on behalf of a client as a processor rather than in our own right, that client's notice governs the processing, and we describe that situation in section 2.4.
Section 2
Data controller and contact details
2.1 Controller
Unless stated otherwise in this policy or in a specific notice given to you at the time, the controller of your personal data is:
- Legal entity
- MeridianTechnologies OÜ, trading as Meridian Recruitment
- Estonian registry code
- 17576566
- Registered office
- Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia
- Privacy contact
- [email protected]
- General contact
- [email protected] · +1 (555) 014-2280
- Website
- https://meridian-recruitment.com
2.2 Data protection officer
Meridian has assessed whether it is required to appoint a data protection officer under Article 37 GDPR. We have not appointed a data protection officer, as we are not required to do so; privacy matters are handled by our privacy contact, who can be reached at [email protected]. We keep this assessment under review as our processing activities develop.
2.3 When Meridian acts as an independent controller
In most of what we do, we decide for ourselves why and how personal data is processed, and we are therefore the controller. This includes:
- identifying and researching potential candidates;
- building and maintaining our candidate database and talent network;
- deciding which candidates to approach and which to put forward;
- our own notes, assessments and records of recruitment activity;
- managing our client and business relationships;
- operating our website, systems and accounts.
2.4 When our clients are separate controllers
Once we introduce a candidate to a client, or a client otherwise legitimately receives candidate information from us, that client processes the information for its own hiring purposes and under its own responsibility. In that situation, Meridian and the client are each independent controllers — not joint controllers, and not controller and processor. Each of us is responsible for our own compliance, and the client's own privacy notice applies to what it does with the information.
We say this deliberately, because recruitment relationships are frequently mislabelled. Meridian acts as a processor for a client only where the client genuinely determines the purposes and means of the processing — for example, where we operate a client's own applicant-tracking system, run a recruitment process end-to-end inside the client's systems, or handle applications on the client's behalf under its instructions. Where that is the case, we put a written Article 28 GDPR data processing agreement in place, we act only on the client's documented instructions, and the client's privacy notice — not this one — is the primary notice for that processing.
Section 3
Categories of personal data
We process different categories of data depending on your relationship with us. We aim to hold what is relevant to professional recruitment and to our business relationships, and not more.
3.1 Candidates and prospective candidates
- Identity and contact data: name; email address; telephone number; city, region and country of residence; postal address where relevant to an assignment or contract; date of birth where necessary (for example for contracting or right-to-work purposes).
- Professional profile: CV or résumé; employment history; job titles; employers; education; professional qualifications and certifications; skills and technical expertise; industry and domain experience; languages; publications, talks or portfolio work.
- Online professional presence: LinkedIn profile information; GitHub or comparable code-hosting profiles; personal or professional websites; other publicly available professional profiles.
- Search and matching data: current and target role; seniority; salary and rate expectations; availability and notice period; preferred employment type (permanent, contract, temporary, outstaffing); location and relocation preferences; remote, hybrid or on-site preference; interests, motivations and reasons for considering a move.
- Eligibility data: work authorisation and right to work; visa or permit status and expiry where relevant; nationality where genuinely necessary for immigration or contracting purposes.
- Recruitment process data: applications and submissions; recruiter notes and assessments; interview scheduling and interview notes; test or assignment results where a client uses them; feedback from clients; status within a process; offers, negotiations and outcomes; reasons for withdrawal or rejection.
- References: the identity and contact details of referees and the content of references given.
- Relationship data: history of our communications with you (email, telephone, messaging and video-call records where kept); consents, preferences and objections; suppression records; records of which roles you were considered for or introduced to and when.
- Placement and engagement data: placement history; contract and assignment information; start and end dates; agreed remuneration or rates.
3.2 Contractors, temporary workers and outstaffed personnel
In addition to the above, and only where we place or engage you in this way, we may process contract documentation, assignment details, working time and timesheet data, invoicing and payment data, bank details, tax and social-security identifiers, work-authorisation documentation, assignment-related performance or conduct information, and absence information where it is legally relevant to the engagement. Section 10 explains this in more detail.
3.3 Client contacts, prospects, suppliers and partners
Name; job title and function; business email address and telephone number; employer and business address; areas of hiring responsibility; correspondence and meeting records; contractual and commercial information; billing and payment contacts; business-development notes; event and marketing preferences.
3.4 Referees
Name; job title; employer; business contact details; the relationship to the candidate; and the substance of the reference provided.
3.5 Website visitors
Technical and usage data such as IP address, device and browser information, pages viewed, referring source, and interactions with forms — as described in section 19.
3.6 Special categories of personal data
We do not seek special-category data (Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, data concerning health, sex life or sexual orientation) as part of ordinary recruitment, and we ask candidates not to include it in CVs or applications.
Nevertheless, it can arise incidentally — a candidate may mention a health condition when discussing accommodations or availability, a CV may reveal a religious affiliation through past employment or volunteering, or a client may operate a diversity-monitoring programme. Where special-category data is genuinely necessary, we rely on an appropriate Article 9(2) condition, most commonly:
- Article 9(2)(b) — necessary for carrying out obligations and exercising rights in the field of employment and social security law, as further provided under Estonian law (for example accessibility adjustments during a recruitment process, or obligations arising in an employment or agency-work relationship);
- Article 9(2)(a) — your explicit consent, where no other condition applies;
- Article 9(2)(f) — establishment, exercise or defence of legal claims.
Where special-category data reaches us unnecessarily, we will delete it or, where deletion is not practicable, restrict access to it.
3.7 Criminal conviction and offence data
We do not routinely process criminal-conviction or offence data (Article 10 GDPR). Under Article 10 GDPR and Estonian law, such data may only be processed where authorised by law or under the control of official authority.
Where a specific role carries a legal requirement or a genuine and proportionate need for a check — and only where Estonian or other applicable law permits it — any check will be arranged in accordance with the law of the relevant country, will be limited to what the role requires, and will normally be carried out by, or on the instruction of, the prospective employer rather than by Meridian. We do not build a criminal-records dataset, and we do not retain such information beyond the decision it was obtained for. See section 11.
3.8 Data minimisation
We apply Article 5(1)(c) GDPR in practice: information that is not reasonably relevant to a professional recruitment or business purpose should not be in our records. Recruiter notes are expected to be relevant, factual and professional, and to concern a person's suitability for work — not their private life.
Section 4
Sources of personal data
4.1 Information you give us
Directly from you when you apply for a role, send us your CV, register on our website, respond to an approach, speak with a consultant, attend an interview, complete a form, provide references, negotiate or enter into a contract, sign up to receive job alerts or updates, or contact us in any other way.
4.2 Information we obtain from other sources
We are a search business, and much of our work involves identifying professionals who have not contacted us. We may obtain personal data from:
- LinkedIn and other professional networking platforms, including recruiter and talent-search products offered by those platforms;
- job boards and CV databases, where a candidate has made a profile or CV available to recruiters;
- GitHub and comparable technical or portfolio platforms;
- company websites, conference and event listings, professional publications, industry directories and other publicly available professional sources;
- recruitment and talent-sourcing databases and tools licensed by us;
- referrals from other candidates, colleagues, clients or contacts in our network, including under any referral programme we operate;
- clients, who may pass on candidate details, interview feedback or the details of their own staff as points of contact;
- referees, former employers and (where applicable) educational institutions or certifying bodies, in each case with your knowledge;
- recruitment partners and subcontractors with whom we work on an assignment;
- background-screening and verification providers, where a check is lawfully carried out;
- payroll, accounting, banking and compliance providers, in connection with contracts and placements.
4.3 Transparency when we obtain your data indirectly (Article 14 GDPR)
Where we obtain your personal data from a source other than you, Article 14 GDPR requires us to tell you about it. In practice:
- If we contact you about an opportunity or about joining our network, we provide this privacy information in or with that first communication — normally by linking to this policy — and we tell you where we found your details if you ask.
- If we obtain your details but do not contact you, we provide this information within a reasonable period and in any event within one month of obtaining the data, or at the point of first communication if that comes sooner.
- If we intend to disclose your information to another recipient — for example by introducing you to a client — we provide this information at the latest when that disclosure is first made. In practice, we speak to you first (see section 8).
We may rely on the limited exemptions in Article 14(5) GDPR — for example where you already have the information, where providing it would involve disproportionate effort in the specific circumstances, or where disclosure is regulated by law. We do not treat "disproportionate effort" as a general excuse: our normal practice is to inform you.
The categories of data we obtain indirectly are those set out in section 3.1, and the sources are those listed in section 4.2.
Section 5
Purposes of processing
We process personal data for the following purposes.
5.1 Recruitment and search
- Identifying and researching professionals who may be suitable for current or future roles.
- Contacting individuals about specific opportunities, or about being included in our network.
- Assessing suitability, seniority, skills and fit against a role specification.
- Screening, qualifying and interviewing candidates.
- Arranging and coordinating interviews, assessments and technical tests with clients.
- Presenting and introducing candidates to clients, and managing the introduction process.
- Managing applications received directly by us or through a client's process.
- Advising candidates on roles, market conditions, compensation and process.
- Obtaining and passing on references.
- Managing offers, negotiations, counter-offers and start dates.
- Recording outcomes, including unsuccessful outcomes and the reasons for them.
5.2 Talent network and future opportunities
- Maintaining a structured candidate database so that we can match professionals with relevant roles over time rather than starting from zero for every assignment.
- Keeping profiles current, including through periodic contact and profile-refresh requests.
- Matching candidates against new assignments as they arise.
- Sending job alerts and role notifications where you have asked for them or where it is within the scope of our legitimate interests as described in section 18.
5.3 Client and commercial relationships
- Managing recruitment assignments, mandates and terms of business.
- Communicating with hiring managers, HR contacts and other client personnel.
- Business development, including contacting organisations that may need recruitment support.
- Account management, reporting, invoicing and credit control.
- Market intelligence, salary and market benchmarking, and hiring-trend analysis (which we carry out on an aggregated or de-identified basis wherever practicable).
5.4 Contract, placement and workforce administration
- Preparing and administering candidate, contractor, temporary-worker and outstaffing contracts.
- Managing assignments, timesheets, working time, invoicing, payroll and payments where we are the engaging or paying party.
- Verifying work authorisation and satisfying immigration, tax and employment obligations.
- Managing assignment performance, issues and terminations.
5.5 Operations, compliance and protection of our business
- Operating, maintaining, securing and improving our website, systems and services.
- Website analytics and service improvement.
- Information security, access control, logging, fraud prevention and prevention of misuse of our systems.
- Quality assurance, training and internal review of recruitment practice.
- Accounting, tax, statutory reporting and audit.
- Compliance with legal and regulatory obligations, including responding to lawful requests from authorities.
- Handling complaints and data-subject requests.
- Establishing, exercising or defending legal claims, including claims under our Terms of Business.
- Maintaining suppression records so that people who have asked not to be contacted are not contacted again (see section 7.7).
Section 6
Legal bases under the GDPR
Every processing activity we carry out has a legal basis under Article 6(1) GDPR. This section maps the main activities to those bases. Where special-category or criminal-offence data is involved, sections 3.6 and 3.7 apply in addition.
6.1 Legitimate interests — Article 6(1)(f)
Much of our recruitment activity relies on legitimate interests. This is the basis recognised across the recruitment sector for professional talent sourcing, and it is reflected in Recital 47 GDPR. We rely on legitimate interests for:
| Activity | Our legitimate interest |
|---|---|
| Identifying potential candidates from professional and public sources | Operating a search-based recruitment business; serving client mandates; connecting professionals with relevant opportunities |
| Contacting professionals about genuine, relevant career opportunities | Fulfilling assignments; the mutual interest of candidates and employers in being made aware of relevant openings |
| Maintaining a candidate database and talent network | Delivering an effective service over time; avoiding repeated collection of the same information; matching people to future roles |
| Assessing suitability and preparing candidate summaries | Providing a competent professional service to clients and candidates |
| Candidate and client relationship management | Maintaining continuity, accuracy and quality of service |
| B2B business development and communications with organisational contacts | Growing and sustaining our business; offering services to organisations likely to need them |
| Market and salary benchmarking | Advising clients and candidates accurately |
| Service improvement, analytics and quality assurance | Improving the service we provide |
| Information security, logging, fraud prevention and system protection | Protecting our business, our data and the people whose data we hold |
| Maintaining suppression records | Respecting objections effectively; preventing unwanted re-contact |
| Establishing, exercising or defending legal claims | Protecting our legal position |
Balancing. Before relying on legitimate interests we consider the effect on you. The factors that support our assessment are that we process professional rather than private information, obtained from professional contexts; that the purpose — connecting skilled people with relevant work — is one that professionals commonly expect from recruiters and often welcome; that the volume of data we hold about any individual is modest and role-relevant; that we do not sell personal data; that we do not use automated decision-making with legal or similarly significant effects; that our approaches are targeted rather than indiscriminate; and that we make it easy to object, and act on objections promptly and permanently.
Where our interests do not outweigh yours in a particular case, we do not proceed on this basis. You have an absolute right to object to processing for direct marketing, and a qualified right to object to other legitimate-interest processing — see section 17.6. You may ask us for further information about our legitimate-interests assessment.
6.2 Contract and pre-contractual steps — Article 6(1)(b)
We rely on this basis where processing is necessary for a contract with you, or to take steps at your request before entering into one:
- progressing your application or candidacy at your request, including screening, interview arrangements, submission to a client and offer management;
- negotiating, concluding and performing a contractor, temporary-work, outstaffing or employment agreement with you;
- administering assignments, timesheets, invoicing and payment under such an agreement;
- providing services you have asked us for, such as registration on our website or job alerts you have requested.
Where an activity relates to a contract between Meridian and a client organisation rather than with you personally, we rely on legitimate interests (section 6.1) for the processing of that organisation's contacts, not Article 6(1)(b).
6.3 Legal obligation — Article 6(1)(c)
We rely on this basis where processing is required by law, including:
- accounting and record-keeping under the Estonian Accounting Act (Raamatupidamise seadus);
- tax, social-security and payroll reporting obligations;
- employment and agency-work obligations where we are the employer or engaging entity, including under the Estonian Employment Contracts Act (Töölepingu seadus);
- verification of the right to work and immigration-related obligations;
- responding to lawful requests from courts, supervisory authorities and other public bodies;
- data protection obligations themselves, including handling your requests and notifying breaches.
6.4 Consent — Article 6(1)(a)
We use consent only where it is the appropriate basis, and not as a substitute for the bases above. Ordinary recruitment processing does not depend on your consent. We rely on consent principally for:
- non-essential cookies and similar technologies, where consent is required (section 19);
- electronic marketing communications where applicable law requires prior consent (section 18);
- processing special-category data where no other Article 9 condition applies (section 3.6);
- specific optional activities, such as retaining your details in our network for a materially longer period than our standard retention criteria would support, or sharing your profile in circumstances that go beyond the practice described in section 8.
Where we rely on consent, you may withdraw it at any time by contacting us at [email protected] or by using the mechanism provided (for example an unsubscribe link or the cookie settings interface). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it does not affect processing that rests on a different legal basis.
6.5 Vital interests and public interest
We do not normally rely on Articles 6(1)(d) or 6(1)(e). In an emergency affecting someone's life — for example an incident involving a contractor on assignment — we may rely on vital interests.
Section 7
Candidate sourcing and headhunting
This section is central to how Meridian works, and we set it out separately.
7.1 What sourcing means
A significant part of our work is search: identifying professionals whose experience matches a client's requirement, and approaching them directly. Most of the people we identify have not applied to us and may never have heard of us. We call these passive candidates, and they have the same rights as anyone else.
7.2 Where we look
We identify potential candidates through LinkedIn and other professional networks; job boards and CV databases; GitHub and similar technical platforms; company websites and public professional profiles; conference programmes, publications and industry research; licensed recruitment databases and sourcing tools; and referrals from our network.
We look at professional sources for professional information. We do not trawl personal social media, private accounts or personal life for information about candidates, and we do not collect information about your private circumstances, opinions or beliefs.
7.3 Our legal basis
We rely on legitimate interests under Article 6(1)(f) GDPR, as explained in section 6.1. The interest is in operating a recruitment service that connects skilled professionals with relevant opportunities — an activity that both employers and candidates rely on, and that professionals who publish their experience on professional platforms can reasonably anticipate.
7.4 Why we may contact you
We contact you because we believe a specific role, or the type of role we recruit for, may be relevant to your experience and career. We aim for approaches to be targeted, honest about who we are and what the opportunity is, and easy to decline.
7.5 What we retain at the initial stage
Before you respond to us, we typically hold only a limited professional record: your name; the professional contact details available to us; your current or recent role and employer; a summary of your skills and experience; the public professional profile or source we identified you from; and a note of what we contacted you about and when.
If you engage with us, we build on that record with the information described in section 3.1. If you do not respond at all, we keep the record only for as long as our retention criteria in section 15 support, and then delete it.
7.6 Your rights when you have been sourced
You may, at any time and without giving a reason:
- ask where we obtained your details and what we hold (Article 15);
- correct anything inaccurate (Article 16);
- object to our processing (Article 21) — including our holding you in our database at all;
- ask us to delete your record (Article 17);
- ask us simply to stop contacting you.
Write to [email protected], reply to the recruiter who approached you, or use any opt-out link we provide. We do not require you to justify the request, and we do not treat a request to stop as an invitation to try again later.
7.7 If you ask us not to contact you — suppression records
If you object to further contact or ask us to erase your data, we act on that request. But there is a practical problem: if we delete every trace of you, nothing prevents a consultant from finding your public profile again next month and approaching you a second time.
To prevent that, we keep a minimal suppression record — normally your name and the specific contact identifiers we must be able to recognise (such as an email address or LinkedIn profile URL, which we may hold in hashed form where technically feasible), together with the date and the fact that you asked not to be contacted. We hold no CV, no notes, no assessments and no other profile content.
We rely on legitimate interests, and on our obligation under Article 5(1) GDPR to process fairly and to honour objections effectively, as the basis for this minimal record. It exists solely to protect you from unwanted contact and is never used to contact you, to build a profile or for any other purpose. We keep it for as long as the risk of inadvertent re-contact persists. If you would prefer us to delete even this record — accepting that we may then be unable to recognise you if your details resurface — tell us and we will do so.
7.8 If you decline a particular opportunity
Declining a specific role is not the same as asking us to stop entirely, and we do not treat it as such. Unless you tell us otherwise, we may keep your details and contact you about materially different opportunities in future. If you would rather we did not, say so and we will apply section 7.7.
Section 9
Client, prospect and business contact information
9.1 Whose data
We process personal data about individuals in their professional capacity at client and prospective client organisations, suppliers, recruitment partners and other business contacts — including hiring managers, HR and talent-acquisition professionals, executives and founders, procurement, legal and finance contacts.
9.2 What we process
Name; job title and function; business contact details; employer and business address; hiring responsibilities and areas of interest; records of our correspondence, calls and meetings; contract and commercial terms; billing and payment contacts; event attendance; communication preferences; and business-development notes.
9.3 Why, and on what basis
We process this data to manage assignments and contracts, to communicate about live roles and candidates, to administer accounts and invoicing, and to develop our business — including contacting organisations we believe may need recruitment support.
Our legal basis is legitimate interests (Article 6(1)(f)): maintaining commercial relationships and promoting a B2B service to organisations likely to have a use for it. Where processing is necessary to perform a contract with you personally, or to comply with a legal obligation such as invoicing and accounting, we rely on Articles 6(1)(b) and 6(1)(c) respectively.
B2B contact data is professional information used for professional purposes, and business contacts generally expect to be approached about relevant services. We keep our outreach relevant and proportionate, we identify ourselves clearly, and every business communication includes a means of opting out. Electronic marketing is also subject to the rules described in section 18.
9.4 Your rights as a business contact
You have the same rights as anyone else, including the right to object to our processing for business-development purposes at any time. If you object, we will stop, and we may keep a minimal suppression record on the same basis as section 7.7.
Section 10
Temporary workers, contractors and outstaffing
This section applies where Meridian places you as a temporary agency worker, engages you as a contractor, or provides your services to a client under an outstaffing or staff-augmentation arrangement.
10.1 Additional data
In these arrangements we may additionally process: contract documentation and signature records; assignment details, including the client, project, role and duration; working hours, timesheets and leave records; rates, remuneration, expenses and invoices; bank account and payment details; tax and social-security identifiers and residence status; work-authorisation and permit documentation; equipment and system-access records; assignment-related performance, conduct and incident information; absence and sickness information where it is legally relevant to the engagement or to pay; and compliance and audit documentation.
10.2 Legal bases
- Article 6(1)(b) — negotiating and performing your contract with us, administering assignments, timesheets and payment.
- Article 6(1)(c) — tax, social-security, accounting, employment, working-time and immigration obligations.
- Article 6(1)(f) — managing assignments and client relationships, protecting our systems and business, and handling claims.
- Article 9(2)(b) and, where relevant, Article 9(2)(f) — health-related information where it is necessary for employment or social-security law purposes or for legal claims. We process only what is needed (for example the fact and duration of an absence), not clinical detail beyond that.
10.3 Sharing with the client
Where you work on a client assignment, the client will necessarily receive information such as your name, role, contact details, working arrangements and, in some cases, timesheet or attendance data. The client processes that information as an independent controller for its own purposes.
10.4 Additional notices
Where Meridian directly employs or contracts with you, a further and more detailed privacy notice covering the employment or contractor relationship will be provided to you at or before the start of the engagement. That notice supplements this policy, and prevails over it in the event of a conflict in relation to that relationship.
Section 11
References and background checks
11.1 References
We contact referees only at the appropriate stage of a process, and only where you have provided or agreed to the referee, or where a client requires references as a condition of an offer. We tell you before references are taken up.
We ask about matters relevant to the role: the dates and nature of your engagement, your responsibilities, performance and conduct, and eligibility for re-engagement. We do not ask about health, private life or other irrelevant matters.
Reference content is treated as confidential, is shared with the client for whom it was obtained, and is retained with the recruitment record.
Legal bases: Article 6(1)(b) (steps at your request in a recruitment or engagement process) and Article 6(1)(f) (providing a competent service to clients and verifying information). For the referee's own data, our basis is legitimate interests in obtaining and recording the reference.
11.2 Background and pre-employment checks
Checks are carried out only where they are lawful in the relevant country, genuinely relevant to the role, proportionate to it, and necessary — never as a routine step applied to everyone.
Where a check is appropriate, we tell you in advance what will be checked and by whom, we limit it to what the role requires, and we use reputable providers under written data-processing terms. Identity and right-to-work verification, and verification of qualifications or professional registrations where a role depends on them, are the most common examples.
Criminal-record checks are subject to section 3.7: they are undertaken only where Estonian or other applicable law permits, are normally the responsibility of the prospective employer, and are limited to information relevant to the specific role. We do not retain criminal-record information beyond the decision it was obtained for.
Credit, social-media and other intrusive checks are not part of our standard process and would be undertaken only where a specific legal or role-based justification exists.
Section 12
Recruitment technology, automation and AI
12.1 What we use technology for
Modern recruitment relies on software, and we use it to work efficiently. Our systems and tools may:
- store and organise candidate and client records in an applicant-tracking system or CRM;
- search and filter our database and external sources by criteria such as skills, seniority, location, languages or availability;
- parse CVs into structured fields;
- identify and rank profiles for relevance against a role specification;
- suggest candidates a recruiter may wish to consider;
- summarise CVs, notes, calls or correspondence to assist a consultant;
- draft communications for a consultant to review, edit and send;
- support scheduling, workflow, reporting and administration.
Some of these tools use machine learning or generative AI. Where they do, we select providers that offer appropriate contractual and security protections, we do not permit them to use our data to train their general models unless we have specifically agreed to it, and we assess them before use.
12.2 Human decision-making
Meridian does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing. Decisions about whether to approach you, whether to progress your candidacy, and whether to present you to a client are made by our consultants. Automated tools may surface, rank or summarise information; a person evaluates it, can and does look beyond it, and takes the decision.
If we ever adopt a system that would make such decisions solely automatically, we will inform affected individuals beforehand, explain the logic involved and the consequences, identify the legal basis under Article 22 GDPR, and provide the safeguards Article 22(3) requires — including the ability to obtain human intervention, to express your point of view, and to contest the decision.
12.3 Client-side automation
Clients may use their own assessment tools, automated screening or AI in their hiring processes. Those are the client's systems and the client's responsibility as a controller. If you have concerns about how a specific employer assesses candidates, we will help you raise them with that employer.
12.4 Profiling
Matching a candidate profile against a role specification involves an element of profiling in the GDPR sense. It is limited to professional attributes, it informs rather than determines outcomes, and you may object to it under Article 21 GDPR.
Section 13
Recipients of personal data
We do not sell personal data. We disclose it only to the following categories of recipient, and only as far as necessary:
- Meridian personnel — consultants, researchers, delivery, operations and administrative staff, on a need-to-know basis under access controls and confidentiality obligations.
- Clients and prospective employers — as described in section 8, as independent controllers.
- Recruitment partners and subcontracted researchers or sourcers — where we work jointly on an assignment, under written confidentiality and data-protection terms.
- Applicant-tracking, CRM and recruitment-platform providers — as processors hosting our candidate and client records.
- Cloud hosting and infrastructure providers — as processors.
- Email, calendar, video-conferencing, messaging, telephony and document-collaboration providers — as processors.
- Sourcing, enrichment and search-tool providers — as processors or, where they act in their own right, as independent controllers under their own notices.
- Background-screening and verification providers — as processors, where a lawful check is carried out.
- Payroll, accounting, invoicing and bookkeeping providers, and banks and payment providers — for placements, contractor engagements and our own administration.
- Professional advisers — lawyers, accountants, auditors, tax advisers and insurers, bound by professional confidentiality.
- IT support, security and analytics providers — as processors.
- Public authorities, courts and regulators — where required by law or necessary to establish, exercise or defend legal claims, including the Estonian Tax and Customs Board, the Estonian Data Protection Inspectorate and equivalent bodies in other countries.
- Acquirers or investors — in the context of a merger, acquisition, financing or reorganisation, subject to confidentiality undertakings and, on completion, to the successor's obligations as controller.
13.1 Contractual protections
Where a recipient acts as a processor, we put a written agreement in place meeting Article 28 GDPR, requiring the processor to act only on our instructions, to keep the data confidential, to apply appropriate security measures, to engage sub-processors only under equivalent terms and with our authorisation, to assist us with data-subject requests and breach notification, and to delete or return the data at the end of the engagement. We assess providers before engaging them and keep that assessment under review.
Where a recipient acts as an independent controller — most importantly our clients — we rely on contractual commitments in our Terms of Business regarding confidentiality, permitted use and data protection compliance, but the recipient is responsible for its own processing.
Section 14
International data transfers
Meridian operates in an international market. Candidates, clients and technology providers may be located outside the European Economic Area, and we do not claim that your data will never leave the EEA. It may, in the following situations:
- where a client, prospective employer or group company that you have agreed to be introduced to is located outside the EEA — for example a US or UK employer hiring for a remote or relocated role;
- where a candidate, contractor or business contact is themselves located outside the EEA;
- where a technology provider we use processes or stores data outside the EEA, or provides support from outside the EEA;
- where our advisers or auditors are located outside the EEA;
- where a legal obligation or legal claim requires it.
14.1 Safeguards
Where we transfer personal data outside the EEA, we rely on one of the following mechanisms under Chapter V GDPR:
- an adequacy decision of the European Commission under Article 45 GDPR, where the destination country or framework benefits from one;
- Standard Contractual Clauses adopted by the European Commission under Article 46(2)(c) GDPR, supplemented where necessary by a transfer impact assessment and by additional technical, organisational and contractual measures such as encryption in transit and at rest, access restrictions, and commitments on handling government access requests;
- binding corporate rules or another approved mechanism under Article 46 GDPR, where a provider offers one;
- a derogation under Article 49 GDPR, in limited situations — most relevantly where a transfer is necessary for the performance of a contract with you or for pre-contractual steps taken at your request, or where it is necessary for the establishment, exercise or defence of legal claims. Introducing you to an employer outside the EEA, at your request and with your agreement, is the typical example.
You may request further information about the safeguards applied to a specific transfer, and a copy of the relevant Standard Contractual Clauses (redacted as to commercial terms), by contacting [email protected].
Section 15
Data retention
15.1 Principles
We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires. When it is no longer needed, we delete it or irreversibly anonymise it. Where deletion is not immediately possible — for example in backups — we isolate the data and delete it as part of our normal backup cycle.
15.2 Criteria we apply
We determine retention by reference to:
- the purpose the data was collected for, and whether that purpose is still live;
- the nature and current state of our relationship with you, including recency of contact and whether you remain open to opportunities;
- the realistic likelihood of relevant future opportunities in your field;
- the length of applicable limitation periods for legal claims;
- contractual obligations, including to clients;
- statutory retention obligations, including accounting, tax and employment law;
- any objection, erasure request or restriction you have made;
- the sensitivity of the data and the risk that continued retention would present.
15.3 Indicative retention periods
The periods below are our operating baseline. They may be shortened where data is no longer relevant, or extended where a live legal claim, a statutory obligation or your explicit request requires it.
| Category | Indicative period | Reasoning |
|---|---|---|
| Candidate database / talent network profiles | Review at 24 months from the last meaningful interaction; delete unless there is a demonstrable reason to keep the record, with a further review no later than every 24 months thereafter | Professional careers move on a multi-year cycle, and a profile older than two years without contact is usually stale. Periodic review, rather than open-ended retention, is what storage limitation requires. |
| Sourced candidates who never responded | 12 months from the approach | If there has been no engagement at all, we cannot justify holding the record longer. |
| Active candidates in a live process | For the duration of the process, then as per the applicable category below | Necessary to run the process. |
| Unsuccessful candidates (applied or introduced, not placed) | 12 months from the conclusion of the process, unless the candidate remains in the talent network under the row above | Covers limitation periods for discrimination or recruitment-related claims, allows us to explain decisions, and preserves the record of what was considered. |
| Placed candidates (permanent placements) | For the duration of any guarantee or rebate period plus the applicable limitation period for claims under the client contract, typically up to 3 years thereafter; core placement records may be kept longer where an accounting or contractual obligation applies | Necessary to administer fees, guarantees and disputes. |
| Contractors, temporary workers and outstaffed personnel | For the engagement plus the longer of the applicable employment-law limitation period and any statutory retention requirement; documents forming part of accounting records for 7 years from the end of the financial year | Employment, tax and accounting obligations. |
| Payroll, invoicing, tax and accounting records | 7 years from the end of the financial year in which the transaction was recorded | Estonian Accounting Act (Raamatupidamise seadus) source-document retention requirement. |
| Client and business contacts | For the duration of the relationship plus 24 months from the last meaningful interaction; contract-related records for the term plus the applicable limitation period | Commercial relationships are periodic, and dormant contacts should be removed. |
| Client contracts and Terms of Business | Term plus the applicable limitation period, generally up to 10 years where a longer contractual limitation period applies | Establishing and defending claims. |
| Recruitment correspondence | With the associated candidate, client or engagement record | Correspondence has no independent purpose. |
| References | With the associated recruitment or placement record | Only relevant in the context of the decision it supported. |
| Criminal-record and background-check outcomes | Deleted once the relevant decision is made and any appeal window has closed; normally we record only the outcome and the date, not the underlying detail | Data minimisation and Article 10 GDPR. |
| Suppression records | For as long as necessary to prevent inadvertent re-contact, subject to periodic review | Honouring your objection effectively (section 7.7). |
| Website analytics | In line with the retention settings of the analytics tool in use, and no longer than 26 months | Analytics loses value quickly and should not be kept indefinitely. |
| Cookies | As set out in our Cookie Policy / cookie settings interface | See section 19. |
| Security and access logs | Up to 12 months, unless required longer for an investigation | Security monitoring and incident response. |
| Data-subject requests and complaints | 3 years from resolution | Demonstrating accountability under Article 5(2) GDPR. |
15.4 No indefinite retention
We do not claim a right to hold candidate data indefinitely. Being in our talent network is not a permanent state: records are reviewed, and records we cannot justify are deleted. You can ask at any time to be removed, and we will not require a reason.
Where you ask us to retain your details for longer than our criteria would otherwise support — for example because you expect to be looking again in three years — we can do so on the basis of your consent, which you may withdraw at any time.
Section 16
Data security
We implement technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. Depending on the system, these include:
- role-based access control, so that consultants and staff can reach only the data they need;
- individual named accounts, strong authentication requirements and multi-factor authentication on key systems;
- encryption in transit, and encryption at rest where our systems and providers support it;
- reputable cloud infrastructure and business applications, hosted in the EEA wherever practicable;
- confidentiality obligations in every employment, contractor and supplier agreement;
- data-protection and security training for personnel who handle candidate and client data;
- policies covering acceptable use, device security, remote working and secure disposal;
- logging and monitoring of access to systems containing personal data;
- backups and tested restoration procedures;
- security and privacy assessment of vendors before engagement, and written processing terms with each processor;
- a documented incident-response and breach-assessment procedure (section 22);
- periodic review of access rights, retention and the measures above.
No system, and no organisation, can be completely secure, and we do not claim otherwise. What we can commit to is applying measures proportionate to the risk, reviewing them as risks change, and acting promptly and transparently if something goes wrong.
Section 17
Your rights
Subject to the conditions and exceptions in the GDPR, you have the following rights.
17.1 Right of access (Article 15)
You may ask whether we process your personal data and, if so, receive a copy of it together with information about the purposes, categories, recipients, retention, the source of the data and your rights. Where providing a copy would adversely affect the rights and freedoms of others — for example a referee's identity, confidential client information, or another candidate's data in the same document — we will provide the information in a way that protects those rights, and explain what we have withheld and why.
17.2 Right to rectification (Article 16)
You may have inaccurate data corrected and incomplete data completed. This is a practical right that matters in recruitment: if our record of your seniority, technology stack, salary expectation or availability is wrong, it affects the roles you hear about. Tell us and we will fix it.
17.3 Right to erasure (Article 17)
You may ask us to delete your personal data, including where it is no longer necessary for the purposes it was collected for, where you have withdrawn consent and no other basis applies, or where you have successfully objected under Article 21.
We may be unable to delete everything where we must keep records to comply with a legal obligation (for example accounting records), to establish, exercise or defend legal claims, or where we retain a minimal suppression record under section 7.7. Where that applies, we will tell you what remains and why.
If you were introduced to a client, deletion by us does not delete the copy held by that client. We will tell you which clients received your information so that you can approach them directly, and we will notify recipients of your erasure or rectification request where required under Article 19 GDPR.
17.4 Right to restriction (Article 18)
You may ask us to restrict processing — for example while we verify the accuracy of data you dispute, or while we assess an objection you have made. Restricted data is stored but not otherwise used.
17.5 Right to data portability (Article 20)
Where processing is based on consent or on a contract with you and is carried out by automated means, you may receive the data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible. This right does not extend to our own assessments, notes or analysis about you.
17.6 Right to object (Article 21)
This right matters most in recruitment, so we set it out in full.
Direct marketing. You have an absolute right to object to processing for direct marketing purposes, including any profiling related to it. If you object, we stop. No balancing, no exceptions.
Legitimate-interest processing. You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) — including:
- our contacting you about roles and opportunities;
- our holding your profile in our candidate database at all;
- our sourcing and research activities concerning you;
- business-development communications, if you are a business contact;
- profiling and matching against role specifications.
When you object, we stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or unless the processing is needed for legal claims. In practice, for objections to recruitment contact and database retention, we will normally simply comply — a candidate who does not want to be in a recruiter's database is unlikely to be a candidate we can usefully help, and we do not consider it appropriate to argue the point. We assess each objection on its facts and explain the outcome to you.
17.7 Right to withdraw consent (Article 7(3))
Where we rely on consent, you may withdraw it at any time, as easily as you gave it. Withdrawal is not retrospective and does not affect processing under another legal basis.
17.8 Rights relating to automated decision-making (Article 22)
As set out in section 12, we do not make decisions producing legal or similarly significant effects solely by automated means. If that changes, you will have the right to obtain human intervention, express your point of view and contest the decision.
17.9 Right to lodge a complaint
See section 23.
17.10 How to exercise your rights
Contact [email protected], or write to us at the address in section 2.1. Please tell us what you want and, where you can, which recruiter or process the request relates to — it helps us find your records.
We respond within one month. Where a request is complex or where you have made a number of requests, we may extend this by up to two further months, and we will tell you within the first month if we do, together with the reasons.
We may need to verify your identity before acting, particularly where a request concerns deletion or a copy of your data. We will ask only for what is proportionate, and we will not use identity documents for any other purpose or keep them beyond verification.
Exercising your rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if we ever do.
Section 18
Recruitment communications and direct marketing
Not every message from a recruiter is marketing, and treating them as identical serves nobody. We distinguish three things.
18.1 Recruitment communications about specific opportunities
An approach about a particular role that appears relevant to your experience, or a discussion of a live process you are part of. This is our core recruitment activity, carried out under Article 6(1)(f) or, where you are already in a process, Article 6(1)(b). It is not generic advertising, and it is directed at you because of your specific professional background.
You may stop these at any time under section 17.6 and we will apply section 7.7. We also apply judgement: we do not send repeated approaches to someone who has not responded, and we do not re-approach about substantially the same role.
18.2 Candidate relationship communications
Job alerts you have signed up for, updates on a process you are in, market and salary information, requests to refresh your profile, and administrative messages. Where you have asked for these, we rely on your request; otherwise we rely on legitimate interests. Every such message includes a means of opting out.
18.3 Commercial marketing
Newsletters, service promotion, event invitations, thought-leadership content and business-development campaigns aimed at organisations that may buy our services.
For electronic marketing we comply with the applicable ePrivacy rules, which in Estonia are implemented principally through the Electronic Communications Act (Elektroonilise side seadus), as well as with equivalent rules in other countries where recipients are located. In practice this means:
- we obtain prior consent for electronic marketing to individuals where the law requires it;
- where we contact business contacts on the basis of legitimate interests, we do so only in relation to services relevant to their professional role, and only where permitted in their country;
- every marketing message identifies Meridian clearly and includes a working, one-click unsubscribe mechanism;
- we act on opt-outs promptly and record them so they persist;
- we do not send marketing to anyone who has objected, and we do not use recruitment contact as a route to marketing someone who has opted out of it.
18.4 Opting out
Use the unsubscribe link in any message, reply to the sender, or write to [email protected]. Tell us what you want to stop — all contact, marketing only, or job approaches only — and we will apply exactly that.
Section 21
Children
Our services are directed at working professionals, and our website and recruitment services are not intended for children. We do not knowingly recruit for roles requiring candidates below the minimum working age, and we do not knowingly maintain profiles of children in our talent network.
We recognise that in Estonia and elsewhere young people above the applicable minimum working age may lawfully apply for employment, and we do not exclude them from applying for a role for which they are legally eligible. Where an applicant is a minor, we process only what the specific application requires, we apply the additional protections that Estonian employment law provides for minors, and we obtain the consent or authorisation of a parent or legal guardian where the law requires it.
Under the Estonian Personal Data Protection Act, consent to the processing of a child's personal data in the context of information society services offered directly to a child is valid from age 13; below that age, a legal representative must give or authorise the consent.
If you believe we hold data about a child in circumstances that are not appropriate, contact us at [email protected] and we will review it and delete it where it should not be held.
Section 22
Personal data breaches
We maintain a documented procedure for identifying, containing, assessing and recording personal-data breaches. All personnel are instructed to report suspected incidents immediately, and our processors are contractually required to notify us without undue delay.
Every incident is assessed for the risk it poses to the rights and freedoms of the individuals affected, and recorded in our internal breach register regardless of whether it is notifiable.
Where a breach is likely to result in a risk to your rights and freedoms, we notify the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR.
Where a breach is likely to result in a high risk to your rights and freedoms, we notify affected individuals without undue delay, in clear language, describing what happened, the likely consequences, what we are doing about it, and what you can do to protect yourself — in accordance with Article 34 GDPR.
Where we act as a processor for a client, we notify that client without undue delay so that it can meet its own obligations.
Section 23
Complaints and the supervisory authority
23.1 Contact us first
If you are unhappy with how we have handled your personal data or your request, please tell us at [email protected]. We would rather hear about a problem and fix it than have you take it elsewhere first, and most issues can be resolved quickly and directly. Raising it with us does not affect your right to complain to a supervisory authority at any time.
23.2 Estonian Data Protection Inspectorate
You have the right under Article 77 GDPR to lodge a complaint with a supervisory authority. Meridian's lead supervisory authority is:
- Authority
- Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
- Address
- Tatari 39, 10134 Tallinn, Estonia
- [email protected]
- Website
- www.aki.ee
Please check the Inspectorate's website for its current contact details and complaint procedures, which it updates from time to time.
23.3 Other supervisory authorities
You may instead complain to the supervisory authority in the EU or EEA country where you live, where you work, or where the alleged infringement took place. A list of European supervisory authorities is maintained by the European Data Protection Board at www.edpb.europa.eu.
23.4 Judicial remedies
You also have the right to an effective judicial remedy against a supervisory authority or against Meridian under Articles 78 and 79 GDPR, and to seek compensation for damage suffered as a result of an infringement under Article 82 GDPR.
Section 24
Changes to this privacy policy
We review this policy periodically and update it when our processing, our systems or the law change. The "Last updated" date at the top shows when the current version took effect, and we keep previous versions on file.
Where a change is material — for example a new purpose, a new category of recipient, or a change in legal basis — we will take reasonable steps to bring it to your attention before it takes effect, which may include emailing candidates and contacts we are in touch with, or displaying a notice on our website. Minor clarifications will simply be published here.
Where a change requires your consent under the GDPR, we will obtain it before relying on the change.
Section 25
Contacting us
For any question about this policy, about how we handle your personal data, or to exercise your rights:
- Privacy enquiries
- [email protected]
- Postal address
- MeridianTechnologies OÜ, Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia
- General enquiries
- [email protected] · +1 (555) 014-2280
We aim to acknowledge privacy enquiries within five working days and to resolve them within the timeframes set out in section 17.10.
© 2026 MeridianTechnologies OÜ. Meridian Recruitment is a trading name of MeridianTechnologies OÜ, registered in the Estonian Commercial Register (Äriregister) under code 17576566, with its registered office at Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia.
Section 20
Social media and third-party websites
We maintain profiles on professional and social platforms, including LinkedIn, where we publish roles, share content and communicate with candidates and clients. If you interact with us there — by following, messaging, commenting or applying through the platform — the platform processes your data under its own terms and privacy policy, and it may act as a controller or joint controller in relation to insights and analytics it generates. We do not control those practices.
We also use professional platforms as sourcing tools, as described in section 7.
Our website may link to third-party sites, including client career pages, job boards and application systems. Those sites are outside our control, and this policy does not apply to them. We encourage you to read the privacy notice of any site you provide information to.