Skip to content
Meridia
SolutionsSectorsMethodRevenue LabBlogPricing
ITRequest screening
Menu
SolutionsSectorsMethodRevenue LabBlogPricingItaliano

Documents

Privacy Policy

Which data we process, why, for how long, with which providers and which rights you can exercise.

Last updated: 13 July 2026

ContentsController and contactsData we processPurposesWhat we do not doProvidersTransfers outside the EURetentionRoles with clientsYour rightsUpdates
01

Controller and contacts

Meridia operates meridiagency.it and the connected services for independent hotels, B&Bs, agriturismi and restaurants.

For any privacy question or to exercise your rights, write to info@meridiagency.it. Fiscal details and the operating legal name are stated in the commercial proposal, order or applicable invoice.

02

Data we process

We only process the data each situation requires. We do not request special categories of data under Art. 9 GDPR: please do not send sensitive data through forms or conversations.

SituationDataLegal basis
Website visitTechnical logs, IP address, user agent, locally stored cookie preference.Technical operation and security; consent for non-essential tools.
Screening or contact requestBusiness type, work email, category, current website status, request content.Pre-contractual measures requested by the data subject.
Conversations with SofiaMessages sent, conversation context, technical identifier.Response to the request or service delivery.
Purchase and billingEmail, billing details, chosen service, payment status, Stripe identifiers.Contract performance and accounting or tax obligations.
Client areaCredentials, session tokens, operational service data.Contract performance, security and account management.
B2B outreachPublicly available professional data: business name, city, business email, website, sector.Legitimate B2B interest, with an immediate right to object.
03

Purposes

We use data only for declared and proportionate purposes.

  • Answering requests, screenings, quotes and service questions.
  • Delivering contracted modules: websites, Sofia, Stay, Table, Guest Commerce, Growth and connected tools.
  • Managing payments, renewals, onboarding and support.
  • Keeping technical logs for security, abuse prevention and service continuity.
  • Sending transactional and operational messages: confirmations, credentials, service notices.
  • Contacting professional businesses proportionately with relevant B2B proposals, always with the option to object.
04

What we do not do

We do not sell data, we do not run advertising profiling and we do not use client data to train Meridia-owned models. The language-model providers behind Sofia are configured not to retain data for training, within the contractual limits each provider offers.

05

Providers

We use selected technical providers that process data only as needed for the service. The current sub-processor list is published on its dedicated page.

ProviderRole
StripePayments, checkout and fraud prevention.
BrevoTransactional email and commercial communications.
Language-model providersGenerating Sofia's replies from approved knowledge.
European hostingServer infrastructure and backups.
Print-on-demand suppliers (e.g. Printify)Guest Commerce only; the account belongs to the client.
06

Transfers outside the EU

Where a provider processes data outside the European Union, the transfer relies on standard contractual clauses or adequacy decisions. We prefer providers with European processing options where available.

07

Retention

Technical logs: up to 12 months unless security requires longer. Commercial requests without follow-up: up to 24 months. Contractual and fiscal data: for the legally required period. Demo conversations with Sofia: the technical minimum.

08

Roles with clients

For services delivered to clients (for example Sofia on the client's channels or Guest Commerce), the client remains the controller towards their own guests and consumers; Meridia acts as a processor under Art. 28 GDPR based on a data processing agreement. In Guest Commerce the client is the seller of record towards the consumer.

09

Your rights

You can exercise access, rectification, erasure, restriction, portability and objection rights by writing to info@meridiagency.it. We reply within 30 days. You may also lodge a complaint with the Italian data protection authority.

10

Updates

This notice may be updated. The last update date is shown above; substantial changes are announced on the website.

Questions about this document?

info@meridiagency.it
Meridia

Revenue operating system for independent hospitality.

info@meridiagency.it
BlogRevenue LabSecurityRules and oversightAccessibilitySubprocessorsPrivacyCookieTerms
© 2026 MeridiaDomain and data remain client-owned.