Privacy Policy
What we collect, why we collect it, how long we keep it, and what you can ask us to do about it.
Last updated: 4 August 2026
1. Who we are
Meridian is the AI automation and software engineering practice of Auverant Solutions Ltd, a company registered in England and Wales, with its registered office at 17 Salisbury Street, Swindon, SN1 2AN, United Kingdom.
Auverant Solutions Ltd is the data controller for personal information collected through this website and for information you provide when enquiring about our services. Where we process personal data on behalf of a client as part of a delivery engagement, we act as a data processor and the client remains the controller.
This policy explains what we collect, why we collect it, and what you can ask us to do about it. It is written to comply with the UK General Data Protection Regulation and the Data Protection Act 2018.
2. Information we collect
Information you give us
- Enquiry details — your name, organisation, email address, telephone number, industry, indicative budget, and whatever you tell us about the process you would like to improve.
- Engagement correspondence — emails, call notes, meeting records and documents shared with us while we scope or deliver work.
- Billing information — the details required to raise and settle invoices. We do not store card numbers; payments are handled by our payment provider.
Information collected automatically
- Technical data — IP address, browser type and version, device type, operating system and referring page.
- Server logs — the standard request records our hosting provider keeps to serve pages and prevent abuse. We run no analytics and set no cookies on this site; see our cookie policy.
We do not knowingly collect special category data through this website, and we ask that you do not include health, biometric or similarly sensitive information in an enquiry form. If such data is required for an engagement, it is handled under a separate written agreement.
3. How we use your information
- To respond to your enquiry and arrange a discovery call.
- To prepare proposals, scopes of work and fixed-price quotations.
- To deliver, support and improve the systems we build for you.
- To administer contracts, invoices and our own accounting obligations.
- To maintain the security and performance of this website.
- To send occasional updates about our services, where you have asked for them or where we have a legitimate interest in contacting an existing business client. Every message includes an unsubscribe link.
We do not sell personal information, and we do not share it with third parties for their own marketing.
4. Lawful bases for processing
| Purpose | Lawful basis |
|---|---|
| Responding to enquiries and preparing quotations | Steps taken at your request prior to entering a contract |
| Delivering and supporting an engagement | Performance of a contract |
| Invoicing, accounting and statutory records | Legal obligation |
| Website security and abuse prevention | Legitimate interests |
| Marketing emails | Consent, withdrawable at any time |
5. Client data during an engagement
Delivery work often requires access to systems containing personal data belonging to our clients — customer records, patient administration data, candidate details and similar. In those circumstances we act as a processor under written instruction from the client, governed by a data processing agreement executed before access is granted.
Our standard commitments during an engagement are that we take the minimum access necessary and remove it at completion; that named individuals are recorded against each access grant; that we use test or anonymised data wherever the work allows; and that we notify the client without undue delay, and in any case within 24 hours, of becoming aware of a personal data breach affecting their data.
6. AI systems and your data
Some of the systems we build use large language models and other AI services. Where they process personal data, we apply the following rules.
- We use enterprise API tiers whose terms exclude customer content from being used to train the underlying models.
- We do not submit personal data to consumer AI tools, and we do not paste client information into public chat interfaces.
- Where a client’s governance requires it, models are deployed within the client’s own cloud tenancy so that data does not leave their environment.
- Automated outputs that materially affect an individual are reviewed by a person before action is taken. We do not deploy solely automated decision-making with legal or similarly significant effects.
- Data flows, retention and the specific model providers used are documented and reviewed with the client’s security team before deployment.
7. Who we share information with
We share information only with service providers who help us operate, each under contract and only to the extent needed. These currently fall into the following categories: cloud hosting and infrastructure providers; email, calendar and document collaboration platforms; customer relationship and support tooling; accounting and payment processing; and AI and automation platform providers used within a delivery engagement.
We may also disclose information where we are legally required to do so, or where necessary to establish, exercise or defend legal claims. If our business is restructured or acquired, information may transfer to the acquiring entity under the same protections described here.
8. How long we keep information
| Category | Retention period |
|---|---|
| Enquiries that do not become engagements | 24 months from last contact |
| Client engagement records and correspondence | 6 years from completion |
| Invoices and financial records | 6 years, per HMRC requirements |
| Server logs | Retained by our hosting provider on a rolling short-term basis |
| Marketing subscriptions | Until you unsubscribe |
9. Security
We apply access control on a least-privilege basis, enforce multi-factor authentication across our systems, encrypt data in transit and at rest, keep audit logs of system access, and review supplier security before onboarding. Devices used for client work are encrypted and centrally managed.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours and will contact affected individuals where the risk is high.
10. International transfers
Our infrastructure is hosted in the United Kingdom and the European Economic Area wherever possible. Where a supplier processes data outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Addendum to the European Commission’s standard contractual clauses, together with a transfer risk assessment.
11. Your rights
Under UK data protection law you have the right to be informed about how your data is used; to request a copy of it; to have inaccurate data corrected; to request erasure; to restrict or object to processing; to data portability; and to withdraw consent at any time where consent is the basis for processing.
To exercise any of these, email hello@auverant-solutions.co.uk. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
If you are unhappy with our response, you may complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to resolve it with you first.
12. Changes to this policy
We update this policy when our practices change. The date at the top of the page reflects the most recent revision. Material changes affecting existing clients are communicated directly rather than left to be discovered here.
13. Contacting us
Privacy enquiries: hello@auverant-solutions.co.uk
Post: Data Protection, Auverant Solutions Ltd, 17 Salisbury Street, Swindon, SN1 2AN, United Kingdom
Telephone: +44 7826 404235