Last updated: 18 August 2026
1.Introduction & Scope
LEGACY is an enterprise knowledge preservation and intelligence platform operated by Merison Tech & Consulting Limited ("Merison", "we", "us").
This Privacy Policy explains how personal data is collected, used, shared, stored, and protected in connection with the LEGACY platform and the LEGACY website. It applies to our public website and marketing pages, to account holders using the platform, and to visitors requesting a demo.
For website visitors, demo requests and account administration data, Merison acts as controller. For content that a customer organisation uploads into its own LEGACY workspace (documents, extracted text, chat history), Merison acts as processor on behalf of that organisation, which remains the controller of that content.
2.Controller & Contact Details
Merison Tech & Consulting Limited
Privacy contact: contact@merisontechconsulting.com
Requests concerning this policy, data subject rights, or our processing activities may be sent to the address above.
3.Categories of Data We Process
Account and identity data: name, business email address, company, department membership, assigned role, account status, and last activity/presence timestamps.
Authentication data: password hashes (never plaintext), multi-factor authentication enrolment state, sign-in attempt outcomes, and session metadata.
Customer content: documents uploaded by users, file metadata, text extracted from those documents, AI-generated summaries, vector embeddings, knowledge graph entities and relationships, review and approval decisions, and assistant chat history.
Operational and security telemetry: audit log entries, security events, rate limiting counters, IP-based blocking records, and anomaly detection findings.
Demo request data: name, company, business email, phone number (optional), and message content submitted through our demo form.
Technical data: browser and device information, and IP address as processed for security, abuse prevention, and audit purposes.
4.Purposes & Legal Bases (GDPR Art. 6)
- Providing the platform to account holders — performance of a contract (Art. 6(1)(b)), or the customer's instructions where we act as processor.
- Account administration, invitations and role management — performance of a contract (Art. 6(1)(b)).
- Security, abuse prevention, rate limiting, IP blocking, lockouts and anomaly detection — legitimate interests in protecting the platform and its users (Art. 6(1)(f)).
- Audit logging and accountability — legitimate interests and legal obligations (Art. 6(1)(f), Art. 6(1)(c)).
- Responding to demo requests and support enquiries — legitimate interests / steps prior to entering a contract (Art. 6(1)(f), Art. 6(1)(b)).
- Transactional email (invitations, verification codes, notifications) — performance of a contract (Art. 6(1)(b)).
- Service improvement and reliability using aggregated, non-identifying operational metrics — legitimate interests (Art. 6(1)(f)).
We do not use customer content for advertising, profiling, or automated decision-making that produces legal effects, and we do not sell personal data.
5.Artificial Intelligence Processing
LEGACY uses large language models to read uploaded documents (OCR and text extraction), generate summaries, create vector embeddings for search, extract knowledge graph entities and relationships, and answer questions in the AI assistant.
These operations are performed using the OpenAI API as a subprocessor. When AI features are used, the relevant document content, extracted text, retrieved excerpts and the user's question are transmitted to OpenAI for processing and the result is returned to LEGACY.
Zero data retention. Our OpenAI API usage is configured for zero data retention: prompts and outputs are processed to serve the request and are not retained by OpenAI, and customer content is never used to train public or third-party AI models.
AI retrieval is strictly tenant-scoped. The assistant can only retrieve content belonging to the requesting user's own organisation, and only documents the user is authorised to access and that have reached an approved review status. Cross-organisation retrieval is prevented at the database level.
AI output can contain errors. Answers are provided with source citations so that users can verify statements against the underlying documents; AI output should not be treated as a substitute for professional judgement.
6.Subprocessors
We use the following subprocessors to deliver LEGACY:
- Supabase — database, authentication, and document storage (hosting infrastructure in the EU).
- OpenAI — AI text extraction, summarisation, embeddings, and assistant responses (United States; zero data retention configured).
- Resend — delivery of transactional email such as invitations and verification codes.
- Cloudflare — application hosting, content delivery, and edge request handling.
Each subprocessor is bound by a data processing agreement and processes data only on our instructions. We will inform customers of material changes to this list.
7.International Transfers
Data is primarily processed within the European Union / European Economic Area. Where a subprocessor processes data outside the EEA — in particular AI processing by OpenAI in the United States — transfers are made on the basis of the European Commission's Standard Contractual Clauses together with supplementary technical measures including encryption in transit, minimised payloads, and zero data retention.
8.Customer Data Ownership
Documents and information uploaded to LEGACY remain the property of the customer organisation. Merison claims no ownership of customer content.
We process customer content only to operate the platform and follow the customer's instructions. We do not use it to train public AI models, and we do not disclose it to other customers.
9.Multi-Tenant Isolation & Access Controls
Every LEGACY workspace is isolated at the database level using row-level security policies enforced per organisation, per department, and per user role. Confidential documents additionally require an explicit, time-limited access grant.
Privileged administrative operations require server-side authorisation checks and, for platform-level super administrators, an active multi-factor authentication session.
10.Security Measures
Technical and organisational measures include:
- Encryption in transit (TLS) and encryption at rest for stored documents and database contents.
- Row-level security on all tenant tables; private storage buckets with short-lived signed URLs.
- Role-based access control with least-privilege server-side authorisation.
- Mandatory multi-factor authentication for platform super administrators.
- Rate limiting, progressive account lockout, temporary IP blocking, and bot protection on authentication and upload paths.
- Immutable audit logging of security-relevant actions and automated anomaly detection.
- Strict security headers, including a content security policy and HSTS, in production.
- Server-side validation of uploads, including file type and size restrictions.
11.Retention & Deletion
Documents. Deleting a document moves it to a recycle bin: it is removed from the repository and from AI answers immediately, but the stored file and its derived data (extracted text, summaries, embeddings and chunk records) are held for a configurable retention period — 90 days by default — during which an authorised administrator can restore it. When the retention period expires, or when a company administrator confirms permanent deletion early, the file and all derived data are irreversibly destroyed. Deletions, restorations and permanent purges are recorded in the audit log.
Accounts. When a user is off-boarded, their access is revoked immediately and their profile data is removed or anonymised, while audit records of their past actions are retained for accountability.
Organisations. Off-boarding a customer organisation is a verified, irreversible purge of that workspace: documents, storage objects, derived AI data, chat history, memberships and configuration are deleted.
Security telemetry. Rate limit counters, IP blocks, authentication attempt records and security events are retained only as long as needed for security purposes and are then automatically cleaned up.
Demo requests. Retained for as long as needed to respond and for a reasonable period thereafter for business record purposes.
12.Your Rights
Where GDPR applies you have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. You may also withdraw consent where processing is based on consent.
If you use LEGACY through your employer or another organisation, please direct requests concerning workspace content to that organisation as controller; we will assist them in responding. Requests may also be sent to our privacy contact above.
You have the right to lodge a complaint with your local data protection supervisory authority.
13.Cookies & Local Storage
LEGACY does not use advertising, tracking, or cross-site profiling cookies. We use strictly necessary storage only: an authentication session token, a workspace preference such as your selected theme, and a cookie that remembers whether the sidebar is expanded.
14.Data Breach Notification
In the event of a personal data breach, we will notify affected customer organisations without undue delay after becoming aware of it, and will notify the competent supervisory authority where required within 72 hours.
15.Children
LEGACY is a business platform intended for use by professional users. It is not directed at children and we do not knowingly collect personal data from children.
16.Changes to This Policy
This Privacy Policy may be updated from time to time. Material changes will be communicated to customer organisations, and the "last updated" date above will be revised.
17.Contact
Questions regarding this Privacy Policy may be directed to:
Merison Tech & Consulting Limited
