Meritan ← Back to home

Privacy Policy

Last updated: August 2026

Before you publish: replace [LEGAL ENTITY] and [REGISTERED ADDRESS] below with your registered business name and address, and confirm Sweden is the right governing law for your setup. A policy that names no legal entity is hard to enforce and looks unfinished to a business buyer. These documents are written in plain language and follow common practice, but they are not legal advice: have a lawyer read them before you rely on them, especially the DPA.

Two kinds of people, two different roles

Meritan is run by [LEGAL ENTITY], [REGISTERED ADDRESS], Sweden. This policy covers everyone whose data passes through the product, and the distinction below matters legally:

Hiring teams: our processor commitments are in the Data Processing Agreement, and every company we rely on is listed on the sub-processors page.

What we collect from hiring teams

Our legal bases are performing our contract with you (running the service and billing it), legitimate interests (keeping the service secure and understanding whether it works), and consent where you have given it. We do not sell personal data, ever, and we do not use it to train machine-learning models.

What we process about candidates, on the hiring team’s behalf

A candidate joins from a single link, without creating an account. Before anything is captured they are shown exactly what will be recorded and must agree. We then process:

We never capture the camera, the microphone, the screen outside the interview tab, files on the device, keystrokes as such, or anything before consent is given or after the session ends. Screen sharing, when a hiring team uses it, is peer-to-peer through LiveKit and is not recorded by us.

Where your data lives

Application data is stored on servers in the EU (Railway, EU West region). Some of the companies we rely on are based outside the EU; where that means a transfer, it is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision. The full list, with what each one receives, is on the sub-processors page.

How long we keep things

Your rights

Under the GDPR you can ask for access to your data, correction, deletion, a portable copy, restriction of processing, and you can object to processing based on legitimate interests. Hiring teams can act on most of this without asking us: every interview has a delete button that erases the recording and its events, and owners can export the whole workspace as JSON from Settings. To delete your entire account, use Settings, or email us and we will do it.

Candidates should contact the company that invited them, since that company decides what happens to interview data. If you cannot reach them, write to us and we will help.

You also have the right to complain to a supervisory authority. In Sweden that is Integritetsskyddsmyndigheten (IMY).

Cookies

We use one cookie: a signed, HttpOnly session cookie that keeps you logged in. It is not readable by page scripts, it is not shared with anyone, and it is not used for advertising or tracking. Because it is strictly necessary to provide a service you asked for, no consent banner is required. Our marketing pages set no cookies at all.

Security

Passwords are hashed with scrypt and never stored in plain text. Sessions are signed tokens in HttpOnly cookies. Sensitive integration credentials are encrypted at rest. Interview sessions are visible only to the hiring team that owns them. The details are on the security page. If something goes wrong that affects your data, we will tell you promptly and, where the law requires it, notify the relevant authority within 72 hours of becoming aware.

Changes

If we change this policy in a way that materially affects you, we will say so in the product or by email before it takes effect. The date at the top always reflects the current version.

Contact

Privacy questions, requests, or anything that looks wrong: founders@meritan.team. We answer people, not tickets.