Meridian

Privacy Policy

Sprout Technology Pty Ltd · Effective 29 June 2026

Sprout Technology Pty Ltd (ACN 658 119 450) (Meridian, we, us) operates the Meridian platform. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Most data in Meridian is business data (company financials, asset and exposure data, analyses). Some of it may be personal information where an individual can be identified. We treat all Customer Data as confidential under our Terms of Use; this policy focuses on personal information.

1. Information we collect

We collect:

  • Account and identity information - name, email address, organisation and role, handled through our authentication provider when you sign up, are invited, or log in.
  • Company and analysis data you provide - company financials, emissions, asset registers (which may include site addresses), exposures, and documents you upload such as annual and climate reports. These may contain personal information if individuals are identifiable.
  • Usage and technical data - server and request logs (which may include IP address), and basic device/browser information, generated when you use the Service.
  • Communications - information you provide when you contact us for support or enquiries.

We use essential cookies and similar technologies for authentication and security, and local browser storage for preferences (for example your description-detail setting). We do not use them to track you across other websites.

2. How we collect it

We collect personal information directly from you and your authorised users, from your organisation when it invites you, and as generated by your use of the Service. Where practicable we collect personal information directly from the individual concerned.

3. Why we use it

We use personal information to:

  • provide, operate, secure and support the Service;
  • run climate-risk quantification and generate draft disclosure narratives from the data you provide;
  • authenticate users, manage organisations and process billing;
  • communicate with you about the Service, including service and security notices;
  • maintain and improve the Service, and produce de-identified, aggregated insights; and
  • comply with our legal obligations and enforce our Terms.

4. Disclosure and sub-processors

We do not sell personal information. We disclose it to service providers (sub-processors) that help us run the Service - including hosting, database, file storage, authentication and AI processing - who are permitted to use it only to provide services to us. The current list, with each provider’s purpose and location, is on our Sub-processors page. We may also disclose information where required by law, to protect our rights or the Service, or in connection with a business transfer.

5. AI processing

Some features use a third-party AI provider. When you run document extraction, the text of the document you submit is sent to the provider to return structured results. When you generate a disclosure narrative, structured analysis data is sent to draft the prose. This processing occurs through the provider’s commercial API; under that provider’s commercial terms, data submitted via the API is used to return your result and is not used to train its models. We do not send your authentication identity to the AI provider.

6. De-identified benchmarking

Peer benchmarks are produced only as de-identified, sector-level aggregates. We enforce a k-anonymity floor: any aggregate built from fewer than five distinct companies is suppressed, and we expose only distribution statistics (such as the median and interquartile range), never an individual company’s figures. Properly de-identified information is not personal information.

7. Overseas disclosure

Some of our sub-processors store or process data outside Australia, including in the United States. Before disclosing personal information overseas we take reasonable steps to ensure it is handled consistently with the APPs, including through contractual protections. See the Sub-processors page for locations.

8. Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure - including encryption in transit, access controls, and strict per-organisation tenancy isolation so one customer cannot access another’s identifiable data. No system is completely secure, and we cannot guarantee absolute security.

9. Retention

We keep personal information for as long as needed for the purposes above and to meet legal, accounting and audit requirements. Cached company reference data is flagged stale after 12 months and refreshed on request rather than deleted automatically; documents and analyses are retained until you or your administrator delete them or your account is closed. On account closure we delete or de-identify personal information within a reasonable period, subject to legal retention and routine backup cycles.

10. Accessing and correcting your information

You may request access to, or correction of, the personal information we hold about you by contacting us. We will respond within a reasonable period and may need to verify your identity. Where we decline a request, we will explain why, as required by the APPs.

11. Children

The Service is a business tool intended for use by organisations and is not directed to individuals under 18. We do not knowingly collect personal information from children.

12. Changes to this policy

We may update this policy from time to time. We will post the updated version here and, where changes are material, take reasonable steps to notify you.

13. Contact and complaints

For privacy enquiries, requests or complaints, contact privacy@sprout.enterprises. We will acknowledge and investigate your complaint and respond within a reasonable period. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

← Back to home