Meridian holds sensitive information about real children. Protecting it isn't a feature bolted on at the end — it's the foundation the whole platform is built on.
Your data is hosted on secure cloud infrastructure within the European Union, in Ireland. It is stored and processed in the EU — it does not leave.
Every connection is encrypted in transit with TLS, and all data is encrypted at rest. Information is protected at every stage, end to end.
Every setting's data is logically separated at the database level. One school can never see, query or reach another school's pupils.
Staff only ever see what their role allows — class teacher, phase lead or senior leadership — with least-privilege access by default.
Designed around the UK GDPR and the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025), with your school as the data controller and Meridian as its processor.
Automated, regular backups and tested recovery processes keep pupil data both safe and available when you need it.
Hosted on enterprise-grade cloud infrastructure in the EU (Ireland). Pupil data is stored and processed within the European Union.
All traffic is served exclusively over HTTPS using TLS. Connections are encrypted between every browser and the platform.
The database and its backups are encrypted at rest using industry-standard AES-256 encryption.
PostgreSQL row-level security is enforced at the database layer, scoping every query to the authenticated school so data cannot cross between settings.
Secure sign-in with credentials stored only as salted hashes, managed session tokens, and per-setting sign-in for each portal.
Granular role-based access control determines exactly what each user can see and do, applied consistently across the application and the database.
Automated daily backups with tested restore procedures protect against loss and keep data recoverable.
Built on cloud platforms that maintain independent security certifications such as SOC 2 and ISO 27001.
Your school is the data controller; Meridian is your processor, handling pupil data only on your documented instructions under a Data Processing Agreement built around Article 28 of the UK GDPR.
We process pupil data only as you instruct, everyone with access is bound by confidentiality, and we will tell you if we ever believe an instruction conflicts with data protection law.
Only the data needed to track assessment and progress is held. We follow data-minimisation principles — nothing is collected that the platform doesn't need.
Access, rectification, erasure and portability are all supported, and we assist you in responding to requests from parents or staff quickly and fully.
In the unlikely event of a personal data breach, we notify you without undue delay — within 72 hours of becoming aware — with the details you need, and help you contain it.
Retention is configurable to your policy. On request, or at the end of our agreement, your data is returned and securely deleted.
We use a small, named set of providers — Supabase and Amazon Web Services (EU/Ireland) for the database, and Netlify for hosting — and we tell you before any sub-processor changes, so you can object.
Pupil data is stored and processed within the European Economic Area. We won't transfer it elsewhere except on your instructions and only under the safeguards data protection law requires.
AI-assisted reports and analysis process data securely. Pupil data is not used to train third-party AI models, and AI features can be turned off.
Children merit specific protection under data protection law, and Meridian is built to that higher standard. Data protection by design and by default isn't a slogan here — it shapes every access rule, every default setting, and every new feature we add. The most sensitive information we hold is data about children, and we treat it exactly that way.
You can export your full dataset at any time, in standard formats. We never sell your data, never use it for advertising, and never share it beyond the processors needed to run the service. No lock-in, no surprises.
A UK school will scrutinise any new system holding pupil data — rightly so. We make that straightforward, and we're happy to work directly with your leadership, IT or data protection team.
A Data Processing Agreement aligned to Article 28 of the UK GDPR.
Our current sub-processor list and data-residency details.
A written security overview for your IT team.
Support for your Data Protection Impact Assessment (DPIA).
We'll complete your own security or data-protection questionnaires.
Breach notification without undue delay, and full cooperation.
Email info@meridiantech.info and we'll send whatever your team needs.
We're happy to walk your leadership or IT team through exactly how Meridian protects pupil data, and to provide our Data Processing Agreement.
Talk to Us About Security