Privacy
Last updated: 28 September 2026
1. Controller
Under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the protection of personal data and digital rights (LOPDGDD), the controllers of the data collected through this site are:
- Controllers: Mayda Morales Viera and Samuel Suárez Rodríguez, trading as North Meridian
- Contact email: mayda.morales@north-meridian.dev and samuel.suarez@north-meridian.dev
2. What data we process
We only process data the person provides and what the site strictly needs in order to work:
- Identity and contact data entered in the request form: name, company, email and, if you want, phone.
- The content of the enquiry: the sector and a description of the problem you want solved. Do not include other people’s personal data or confidential information there: that belongs in the assessment phase, which is covered by a contract.
- Commercial relationship data, if the enquiry becomes an engagement: billing details and whatever is needed to deliver the service.
- Technical connection data logged by the hosting provider (IP address, date and time, pages served, browser type), solely to keep the service running and secure.
We do not process special-category data (health, political opinions, trade-union membership and the rest of article 9 of the GDPR), we do not build profiles, and we do not take automated decisions with legal effects on people.
3. Why we process it
- To handle the request we receive and reply with a proposed call or piece of work.
- To manage the pre-contractual and contractual relationship with clients and suppliers.
- To meet the legal, accounting and tax obligations that apply.
- To send messages about our own services, only to someone who has expressly agreed, and with the option to opt out at any time.
- To keep the website secure and available.
The data is not used for any purpose other than those above.
4. Legal basis
- Consent (article 6.1.a of the GDPR) to reply to an enquiry sent through the form or by email, and for commercial messages where they have been accepted. It can be withdrawn at any time, without affecting the lawfulness of processing already carried out.
- Performance of a contract or pre-contractual steps (article 6.1.b) to prepare a proposal and deliver the services engaged.
- Legal obligation (article 6.1.c) to keep invoices and commercial and tax records.
- Legitimate interest (article 6.1.f) in keeping the site secure and in retaining correspondence for as long as liability could arise from it.
5. How long we keep it
- Enquiries that do not become a contract: 12 months from the last message, then deleted.
- Client data: for the life of the contract and, once it ends, blocked for the limitation periods of any legal claims that could arise.
- Tax and accounting data: for the periods set by commercial and tax law.
6. International transfers
The intention is that data is hosted and processed inside the European Economic Area. If a provider involves an international transfer, it will be stated here together with the safeguard it relies on (a European Commission adequacy decision, standard contractual clauses, or another safeguard in chapter V of the GDPR).
7. Your rights
Anyone can exercise the following rights free of charge by writing to mayda.morales@north-meridian.dev and identifying themselves sufficiently:
- Access: to know which of your data is being processed.
- Rectification: to correct data that is inaccurate or incomplete.
- Erasure: to ask for it to be deleted when it is no longer needed.
- Objection: to object to processing based on legitimate interest.
- Restriction: to ask that data be kept but not used while a complaint is resolved.
- Portability: to receive the data in a structured, commonly used format.
- Withdrawal of consent, at any time and without retroactive effect.
The request will be answered within one month of receipt.
8. Complaint to the supervisory authority
If you believe your data has not been handled properly, you can write first to mayda.morales@north-meridian.dev so we can try to resolve it. In any case, you have the right to lodge a complaint with the Spanish Data Protection Agency, the supervisory authority in Spain, through its online office at www.aepd.es (opens in a new tab).
9. Security of the data
Technical and organisational measures proportionate to the risk are in place: encryption of the site in transit, access to information only for people who need it for their work, backups, and processor contracts with every provider. No system is infallible, but any incident that affects personal data will be handled under articles 33 and 34 of the GDPR.
10. Children
This site is aimed at professionals and companies. It is not intended for children under fourteen and their data is not knowingly collected. If we find that it has been provided, it will be deleted.
11. Changes to this policy
This policy may be updated if the services, the providers or the applicable law change. The current version is always the one published on this page, with its review date. Cookie use is set out separately in the cookie policy.