LEGAL · GDPR & COMPLIANCE
GDPR & Compliance
Effective Date: 29 July 2026 · Last Updated: 29 July 2026
1Our Commitment
MEAIOW builds AI agents and workforce infrastructure for regulated enterprises, which means data protection has to be part of how we design and operate our products — not an afterthought. Every AXIOM and RESOURCE interaction is logged and auditable, every agent is tested before it goes live, and it is independently assured for as long as it runs through VERDICT, our testing and assurance discipline, and governed end-to-end through FIRST AI-D. This page explains how GDPR and UK GDPR apply to MEAIOW, the roles we play as controller and processor, and the compliance commitments behind those roles. It is written for both individual data subjects and the security/legal/procurement teams of prospective and current enterprise customers.
2Scope and Applicability
GDPR and UK GDPR can apply to us regardless of where MEAIOW or its customers are headquartered, whenever we offer services to, or monitor the behavior of, individuals located in the EU or UK. We also operate from Dubai, which may bring UAE, DIFC, or ADGM data-protection frameworks into scope for data handled there — see MEAIOW currently hosts and processes personal data in the UK and EEA; our Dubai office is being established and is not yet operational for data processing. This section will be updated with the relevant UAE/DIFC/ADGM transfer mechanism before any Dubai-based processing begins.. Given that our customers operate in regulated sectors themselves subject to frameworks such as GDPR, DORA, PSD2, HIPAA, and PCI-DSS — spanning the fifteen industries we serve, including Banking, Insurance, Healthcare Providers, Healthcare Payors, Legal, Public Sector, Life Sciences, and Defence — we design our data-handling practices to support, rather than complicate, our customers’ own compliance obligations.
3Our Roles: Controller and Processor
| Context | Our role | What it means |
|---|---|---|
| Website visitors, Discovery Call contacts, and job applicants | Data Controller | We decide why and how this data is processed, as described in our Privacy Policy. |
| Client Portal accounts | Data Controller | We administer Portal accounts directly; this is also described in our Privacy Policy. |
| AICADEMY applicants and learners | Data Controller (jointly with the accrediting body, for qualification records) | We administer applications, coursework, and certification; the awarding body may also independently control certain records. |
| End-user or business data processed through a customer’s AXIOM/RESOURCE deployment | Data Processor | The customer is the controller; we process data only on their documented instructions, under a signed Data Processing Agreement (DPA). |
4Legal Bases for Processing
Where we act as controller (Section 3), we rely on the legal bases summarized in our Privacy Policy: consent, contract, legitimate interests, and legal obligation. Where we act as processor, the customer determines the legal basis for its own processing; our role is to process data securely and only as instructed.
4aAutomated Decision-Making and Profiling
Where MEAIOW acts as data controller (Section 3), we do not subject individuals to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects, without meaningful human involvement and the ability to contest the decision and obtain human review.
Where MEAIOW acts as data processor and a customer configures AXIOM, RESOURCE, or another agent to inform or make decisions about that customer’s own employees, applicants, or end customers, the customer, as controller, is responsible for ensuring an appropriate legal basis and safeguards under Article 22 GDPR, and — where applicable — completing a Data Protection Impact Assessment before go-live. MEAIOW supports this through VERDICT’s independent testing and assurance discipline and the FIRST AI-D governance framework, which are designed to produce the evidence such an assessment typically requires.
5Security Measures
Our security program is built around our internal Information Security Policy and is aligned with recognized frameworks, including ISO/IEC 27001, the NIST Cybersecurity Framework, and SOC 2 principles. Consistent with the governance built into our products, key controls include:
- Access control based on least privilege, with logged and reviewable access to systems handling personal or client data.
- Encryption of data in transit and at rest, using industry-standard protocols.
- Continuous monitoring, logging, and regular vulnerability assessments and patch management across our infrastructure.
- Governed execution boundaries for every deployed agent, with every interaction logged and reconstructable — the same standard we apply to our own systems that we apply to what we build for customers.
- Pre-go-live testing and ongoing independent assurance for every agent, following the seven disciplines behind VERDICT: verified, evidenced, risk-calibrated, documented, independent, continuous, and trusted.
- A documented incident-response process. Where a security incident affects a customer’s data, we are committed to identifying and escalating it without undue delay, and — where required by contract — notifying the affected customer within 24 hours, including the nature and scope of the incident, affected data, mitigation steps, and timeline, followed by a full report once the incident is contained.
- Regular security awareness training for our team.
6AI-Specific Data Protection Safeguards
Because AXIOM, RESOURCE, and our other agentic products process customer data as part of delivering an AI workforce, we apply safeguards specific to AI processing, on top of the general security measures in Section 5:
- We do not use a customer’s data for any purpose beyond the scope agreed in the applicable Master Service Agreement and Data Processing Agreement, without the customer’s prior written authorization.
- We do not process a customer’s data using any AI system — including AXIOM, RESOURCE, or any third-party or foundation model — without the customer’s prior written authorization.
- Before any AI model or AI-enabled workflow is applied to a customer’s data, MEAIOW agrees the specific model, its intended use, and a usage plan with the customer, and completes a prior audit agreed with the customer — consistent with the “tested before it goes live, independently assured for as long as it runs” principle behind VERDICT.
- We do not use customer data to train shared or foundation models without the customer’s explicit written authorization.
- Agent configurations support data minimization, limiting each agent’s access to what is required for its assigned task, enforced through FIRST AI-D governance.
- Material AI-generated outputs affecting customer decisions are designed to support human review and oversight, consistent with the customer’s configuration and controls, and with the automated decision-making safeguards in Section 4a.
- Where a deployment involves special categories of data (for example, health data for Healthcare Provider or Healthcare Payor customers), the customer, as controller, determines the applicable Article 9 condition, and MEAIOW applies enhanced technical and organizational safeguards as agreed in the DPA.
- Customers retain control over retention and deletion of their data processed through our platform, as set out in the applicable DPA.
7Sub-Processors
We use a limited number of sub-processors (for example, cloud infrastructure and monitoring providers) to help deliver our services. We maintain an up-to-date list of sub-processors, available at the UK and EEA (our Dubai office is not yet operational for data processing), and we will notify customers of material changes in line with the notice period set out in their DPA, including the opportunity to object on reasonable data-protection grounds.
8International Data Transfers
We operate from London and Dubai. Where personal data is transferred outside the EEA or UK — including, potentially, to the UAE — we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, together with supplementary technical and organizational measures where appropriate. +44 (0)730 676 0007.
9Data Subject Rights
If GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your data, subject to legal exceptions.
- Restrict or object to certain processing.
- Receive your data in a portable format, where applicable.
- Withdraw consent at any time, where processing is based on consent.
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, without human involvement (see Section 4a).
- Lodge a complaint with your local data protection supervisory authority.
To exercise these rights, contact us at privacy@meaiow.com. We aim to respond within 30 days, as required under GDPR. Where you are the end user of a MEAIOW customer’s deployment, we may need to direct your request to that customer, since they are the data controller for that processing.
10Data Protection Impact Assessments
Agentic AI deployments in regulated sectors — including several of the fifteen industries we serve — often require a Data Protection Impact Assessment (DPIA) before go-live. VERDICT’s independent testing and assurance discipline and the FIRST AI-D governance framework are designed to produce the evidence (risk calibration, documentation, independent review) a customer’s DPIA typically requires, and we support customers’ DPIA processes with relevant documentation on request.
11Data Processing Agreement
Enterprise customers can request our standard Data Processing Agreement, incorporating Standard Contractual Clauses where relevant, by contacting privacy@meaiow.com.
12Supervisory Authority
Our lead supervisory authority is MEAIOW currently hosts and processes personal data in the UK and EEA; our Dubai office is being established and is not yet operational for data processing. This section will be updated with the relevant UAE/DIFC/ADGM transfer mechanism before any Dubai-based processing begins.. You may also contact the data protection authority in your own country of residence.
13Contact Our Data Protection Team
For any GDPR-related question, including exercising your rights or requesting a DPA, contact privacy@meaiow.com. or 6th Floor, 107 Cheapside, London, EC2V 6DN, United Kingdom.
NEED HELP?
We are reachable at all times. For any question or assistance, visit our Help Centre or write to helpme@meaiow.com.