Data & Privacy
How customer traffic, prompts, and telemetry are handled.
Data handling guidance should explain what Meridias stores, how long it is retained, and which operational users can access it.
Data categories
Meridias may process request payloads, routing metadata, benchmark fixtures, and operational telemetry. Each category should have different retention and access expectations.
Minimisation
Only the data needed to evaluate, route, and debug requests should be retained. Minimisation reduces privacy risk and lowers the operational burden of data governance.
Retention and deletion
Retention periods should be explicit and tied to operational need, customer commitments, and legal requirements. Teams should also have a clear deletion process when data no longer needs to be stored.
Access controls
Access to request-derived data should be limited to roles with a legitimate operational need. Sensitive data access should be logged and reviewed.
Next step
Return to Telemetry Overview if you need to understand how operational visibility fits within those privacy boundaries.

