Loading...
Loading...
Ask about the schedule, get how-to help, or tap “Show me” for a guided walkthrough.
Meridyon provides workforce-scheduling software for physician and advanced-practice-provider teams. This policy explains what information Meridyon processes, why, and the rights and choices available to the people whose information we handle.
Draft — pending counsel review. This policy is a starting-point template published for transparency; it is not legal advice and will be finalized with counsel.
Meridyon is licensed by health systems, medical groups, and departments (“Customers”) to schedule their workforce. In that relationship the Customer is the data controller(or “business”): it determines what workforce data is entered and for what purposes. Meridyon is the data processor(or “service provider”): we process personal data only on the Customer’s documented instructions to provide the scheduling service.
The people whose personal data appears in Meridyon are the Customer’s workforce — clinicians, schedulers, and administrators. If you are one of these individuals and want to exercise a right over your data, please contact your organization’s Meridyon administrator first (see Section 8); we assist the Customer in responding. This policy also covers information collected through our public website and sign-in pages.
No patient data. No PHI. No clinical records. Meridyon has no patient-facing surface and stores no protected health information. No special categories of personal data are intended to be processed.
Authentication and session data (session identifiers; sign-in events including IP address, user agent, and timestamp for security and audit); and minimal, PHI-free error telemetry (via Sentry, when enabled) to keep the service reliable. See Section 11 on cookies.
We process the information above to:
We do not use workforce data for advertising, and we do not sell it.
AI-assisted features. Where a Customer enables it, Meridyon uses a sub-processor (Anthropic) to parse inbound scheduling-request emails into structured requests. No patient data is involved, and processing occurs in the United States.
Because Meridyon processes personal data as a processor, our lawful basis derives from the Customer’s instructions and the agreement between Meridyon and the Customer, including the Data Processing Addendum. The Customer, as controller, is responsible for establishing the appropriate legal basis and for any required notices to its workforce.
Customer data is stored and processed in the United States. Production runs on US-based infrastructure fronted by a US/global edge network for delivery and TLS. Meridyon does not transfer customer data outside the United States. Customers operating internationally should contact us before relying on the service for data subject to cross-border transfer requirements.
Meridyon relies on a limited set of vetted third-party sub-processors to operate the service. The authoritative list, with purposes and locations, is maintained in the Data Processing Addendum. As of the last-updated date it includes:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare | CDN, DNS, edge TLS, email routing | US / global edge |
| US hosting provider | Compute and database | United States |
| Stripe | Billing (no card data on Meridyon servers) | United States |
| Resend | Transactional email delivery | United States |
| Anthropic | AI parsing of inbound scheduling requests (no patient data) | United States |
| Sentry | Error telemetry (when enabled) | United States |
We remain responsible for our sub-processors’ performance and provide Customers notice of intended additions or replacements as set out in the DPA.
Because the Customer controls the workforce data in its Meridyon organization, requests to access, correct, or delete that data are primarily fulfilled by the Customer through its administrator console and Meridyon’s export tooling.
Where a data subject contacts Meridyon directly, we will generally refer the request to the relevant Customer (controller) and support the Customer’s response.
Meridyon retains data for the periods described in our Data Retention & Destruction Policy. In summary:
Meridyon applies technical and organizational measures appropriate to workforce-scheduling data: TLS 1.2+ in transit, role-based access control with MFA/passkey and SSO options, server-side tenant isolation, audit logging, security headers (CSP/HSTS/CSRF protections), rate limiting and account lockout, and daily plus off-site backups with tested restore.
We describe our security posture accurately, including work in progress: certain storage-layer protections (for example, encryption at rest) are on our hardening roadmap and are not represented as fully in place. No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
This section applies to California residents whose personal information Meridyon processes. In most cases Meridyon acts as a service providerto the Customer (the “business”), processing personal information only to perform the scheduling service under our contract.
We do not intentionally collect sensitive personal information, and we collect no patient/health information.
No sale, no sharing. Meridyon does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We do not process personal information for targeted advertising.
Consumer rights. Subject to verification and legal limits, California residents have the right to know/access, correct, and delete personal information, and to be free from discrimination for exercising these rights. Because Meridyon is a service provider, we direct verifiable consumer requests to the relevant business (Customer) and assist that business in responding.
How to exercise.Submit a request through your organization’s Meridyon administrator, or contact [email protected] and we will route it to the appropriate business and assist. We will not discriminate against you for exercising your rights.
Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and others as they take effect — may have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, sale, or certain profiling. Meridyon processes workforce data as a processor on behalf of the Customer (the controller) and does not sell personal data, share it for targeted advertising, or use it for profiling that produces legal or similarly significant effects. Individuals should direct requests to the Customer that controls their data; Meridyon assists the controller. Requests may also be sent to [email protected] for routing.
Meridyon is offered to US-based Customers and stores data only in the United States. It is not directed to individuals in the EU/UK or other regions, and we do not knowingly process such individuals’ data as a controller. Meridyon is a workplace tool for clinical staff, is not directed to children, and we do not knowingly collect personal information from anyone under 16.
We may update this policy to reflect changes in the service, our sub-processors, or applicable law. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying Customers. Continued use of the service after an update constitutes acceptance of the revised policy, subject to the governing agreement.
Questions or requests about this policy or your data:
For details on our security posture and workforce IT review, see the IT & Security Reference.
This page is a template pending counsel review and does not constitute legal advice. Meridyon build 2026.7.27.5.