Effective date: August 30, 2026
This Privacy Policy describes how Meidly (SASU, SIREN 989 292 016) collects, uses and protects your personal data when you use the meidly.com platform. Meidly is a suite of tools designed to help you analyze the signals that really matter, prioritize what comes next, and activate the right experts at the right time. By using our service, you agree to the practices described below.
Meidly processes your personal data solely to operate its tools. Content you submit through the platform's features is transmitted to AI sub-processors for analysis and then deleted according to our retention policy. You remain the owner of your content at all times, and you can exercise your GDPR rights whenever you like by writing to contact@meidly.com.
The entity responsible for processing your personal data is:
When you create your account, we collect:
If you sign up via Google (OAuth), we only retrieve the email address and name that Google provides us. No other information is accessed.
To use the service, you create projects and interact with the platform's tools, which may involve submitting files or other types of content. We process the following data:
This content may include data relating to third parties such as prospects, customers or partners. You are solely responsible for ensuring you have the necessary authorizations before uploading and submitting any recording for analysis.
The messages of a conversation are never stored. Our Chrome extension reads them only on the page you have open, and only when you click to request a suggestion. They are transmitted to our AI provider to produce that suggestion, then discarded at the end of the processing. Neither the messages nor the suggestion produced are kept on our servers.
We do, however, keep a summary of the exchange, attached to the prospect concerned and to the channel used. It describes where the relationship stands (what was asked, what was promised, the next step) rather than what was said, contains no quotation of the messages, and is replaced by an updated version each time you request a new suggestion. It is deleted with the prospect it belongs to.
We automatically collect certain data when you use the platform:
Transactions are processed entirely by Stripe, which means Meidly never stores any bank card data. We only retain the billing information required for accounting purposes, namely the amount, date, transaction status and Stripe identifier.
At your initiative, our browser extension lets you import into your workspace professional profiles from a social network (for example LinkedIn). For these profiles, we collect the following publicly available professional data:
These profiles are third parties. When you import them, you act as the data controller and must ensure you have a valid legal basis for this processing, typically your legitimate interest in B2B prospecting. This data is used to identify, among your imported profiles, the prospects most relevant to your offer, which may involve transmitting it to the AI sub-processors listed in section 4. It also joins the shared base described in section 2.6. The import only ever runs at your explicit request, from your own page on the network, and you can delete this data at any time from your workspace or by writing to contact@meidly.com.
The professional profiles imported into Meidly join a base that the customers of the platform can search, on the same terms for everyone: importing is what puts a profile there, and searching it is open in return. A search runs on the name and the headline only, by keyword comparison, and it is always started by a customer, never by Meidly on its own initiative. Nothing identifying is shown before a customer unlocks a profile: until then they see a count, never a name, a photo or a link. For this base, Meidly acts as data controller, on the legal basis of its legitimate interest in providing a B2B prospecting tool, and the customer who unlocks a profile becomes data controller for the use they then make of it.
If you appear in this base without being a customer, you can ask to be removed by writing to contact@meidly.com with the address of your public profile. We erase you from the base, from the search results that named you and from the workspaces that had unlocked you, and we keep the sole identifier of your profile in an opposition register, so that a later import by any customer cannot bring you back. That register holds nothing but what is needed to keep honouring your request. You can also ask us at any time what data concerning you we hold, and you may lodge a complaint with the CNIL.
We only process your data for specific, documented purposes. For each processing activity, the legal basis under the GDPR is indicated below:
Meidly does not use your data for marketing purposes without your explicit prior consent.
To deliver its services, Meidly relies on a carefully selected set of sub-processors, each chosen for their security standards and their ability to comply with applicable regulations. The list below reflects the current sub-processors and may be updated as the platform evolves.
Vercel is our main infrastructure provider, hosting both the application and the database (PostgreSQL) as well as uploaded files via Vercel Blob. The company is SOC 2 certified and headquartered in the United States, with data transfers governed by Standard Contractual Clauses (SCCs).
Stripe handles all payment processing on the platform. As a PCI-DSS certified provider, it ensures that bank card data never transits through Meidly's systems.
Resend is used to send transactional emails such as registration confirmations and platform alerts. Only the recipient's email address and the message content are transmitted.
Sentry collects error logs and crash reports to help us maintain platform stability. Data is anonymized as much as possible, and no sensitive business content is ever included in these reports.
Crisp powers our in-app support messaging. When you reach out to our team, your email address, name and the content of your messages are shared with this service.
Inngest orchestrates the background jobs that power file processing and analysis workflows, including the ingestion of uploaded audio and video files before they are submitted for AI analysis.
To deliver its AI-powered features, Meidly transmits certain content to third-party AI providers selected according to the task concerned. The providers currently used are:
None of these providers use submitted content to train their models, under the terms of their business offering. Content is processed confidentially, retained only for the time strictly necessary to perform the task and any abuse monitoring imposed on the provider, then deleted. These providers act as sub-processors of Meidly within the meaning of article 28 of the GDPR, and transfers outside the European Union are governed by the Standard Contractual Clauses described in section 5. The list of active AI providers may evolve as the platform's tools expand, and it is kept up to date in this section: any addition of a provider is published here, and you may object to it under the conditions of section 14.
Some of our sub-processors are headquartered outside the European Union, primarily in the United States. These international transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Article 46 of the GDPR, which provides an appropriate level of protection for your data.
Meidly applies a set of technical and organizational measures designed to protect your data against unauthorized access, disclosure or misuse:
No system is entirely infallible, and we make no claim otherwise. Should a data breach occur, we will notify the affected individuals and the CNIL within the timeframes required by the GDPR.
As a resident of the European Union, you have the following rights:
To exercise any of these rights, simply write to us at contact@meidly.com and we will respond within 30 days.
If you feel your rights have not been respected, you may also lodge a complaint with the CNIL at www.cnil.fr.
Meidly uses only cookies that are strictly necessary for the service to function, primarily to manage your authentication session. No advertising or third-party tracking cookies are placed without your prior consent.
You can disable cookies in your browser settings at any time, though doing so may affect certain features of the service.
As a professional user, you bear full responsibility for the content you submit to Meidly through any of its tools, in particular with regard to the following points:
The analyses produced by Meidly are automatically generated by artificial intelligence models and are provided for informational purposes only. While we strive for quality, they may contain inaccuracies or omissions, and Meidly makes no guarantee as to their accuracy, completeness or relevance in any given situation. They should not be treated as legal, commercial or professional advice of any kind. In accordance with Article 22 of the GDPR, no decision producing significant legal effects is taken solely on the basis of automated processing: Meidly's AI outputs are decision-support recommendations, and the final decision always rests with you.
Within the meaning of Regulation (EU) 2024/1689 on artificial intelligence, Meidly acts as the provider of the AI systems built into the platform, and you act as their deployer when you use them in the course of your professional activity. Every content generated by the platform is presented as such in the interface, and it is a draft that you review before using or sending it. These tools are intended neither to assess the professional performance of a person, nor to be used for human resources purposes, nor to infer the emotions of a person: those uses are prohibited by article 6 of the Terms of Service, which sets out in full the respective obligations of each party under that Regulation.
We reserve the right to modify this policy at any time. The update date will be shown at the top of this page. In the event of a substantial change, we will inform you by email or via a notification on the platform.
For any questions regarding this policy: contact@meidly.com
Where you use Meidly as a professional and process personal data of third parties (prospects, customers, partners) through the platform, you act as the data controller within the meaning of the GDPR, and Meidly acts as your data processor. In this capacity, Meidly undertakes to:
These provisions constitute the data processing agreement (DPA) within the meaning of Article 28(3) of the GDPR and apply to all personal data processing carried out in connection with your use of the platform.
By using our platform, you acknowledge having read, understood and accepted this Privacy Policy.