Mesodian
Last updated: 15 September 2026

Privacy Policy

This Privacy Policy explains how Mesodian ("Mesodian", "we", "us" or "our") collects, uses, stores and protects personal data when you use the Mesodian website, application and related services.

This Privacy Policy applies to:

  • mesodian.com
  • app.mesodian.com
  • Mesodian accounts
  • Mesodian portfolios and strategies
  • brokerage connectivity features
  • automated portfolio functionality
  • communications from Mesodian
  • other services operated by Mesodian that link to this Privacy Policy

We are committed to handling personal data responsibly and in accordance with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Irish data protection legislation.

1. Who We Are

Mesodian is the data controller for the personal data we process in connection with the Mesodian Service, except where a different role applies under applicable law.

As a data controller, Mesodian determines the purposes and means of processing personal data for the purposes described in this Privacy Policy.

The Irish Data Protection Commission describes a data controller as the person or organisation that determines the purposes and means of processing personal data.

2. Personal Data We Collect

The information we collect depends on how you use Mesodian.

We may collect the following categories of personal data.

2.1 Account Information

When you create a Mesodian Account, we may collect:

  • name
  • email address
  • username
  • password or authentication credentials
  • account preferences
  • account creation date
  • account status
  • information you provide during onboarding

2.2 Profile and Preference Information

We do not need to collect every category listed above from every user.

You may provide information about your preferences when using Mesodian.

This may include:

  • investment interests
  • preferred markets
  • investment preferences
  • experience level
  • preferred features
  • learning preferences
  • product preferences
  • onboarding responses
  • notification preferences

This information may be used to personalise the Mesodian experience.

3. Portfolio and Investment Information

If you use Mesodian's portfolio functionality, we may process information relating to your portfolio.

This may include:

  • investments
  • securities
  • holdings
  • quantities
  • portfolio allocations
  • transaction information
  • account balances
  • portfolio performance
  • portfolio history
  • investment strategies
  • selected Portfolios
  • selected Strategies
  • rebalancing information
  • investment-related preferences

This information may be obtained directly from you or from a connected third-party Brokerage Provider.

4. Brokerage Account Information

If you choose to connect a Brokerage Account to Mesodian, we may receive information made available through the relevant brokerage connectivity provider.

Depending on the Brokerage Provider, connection and permissions granted, this may include:

  • brokerage account identifiers
  • account balances
  • holdings
  • positions
  • transactions
  • orders
  • securities
  • portfolio information
  • account status
  • currency information
  • other information made available through the connection

The exact information available to Mesodian depends on the Brokerage Provider and the permissions you grant. Mesodian does not request access to information that is not necessary for the functionality you have enabled, where technically and operationally practicable.

5. Automated Portfolio Information

If you enable an Automated Portfolio, we may process information necessary to operate that functionality.

This may include:

  • selected Portfolio
  • selected Strategy
  • target allocations
  • current holdings
  • rebalancing information
  • transaction instructions
  • transaction status
  • connected Brokerage Account information
  • information concerning the permissions you have granted

This information is processed to provide the automated portfolio functionality you have requested.

6. Payment Information

If you purchase a paid Mesodian subscription, payment information may be processed by our payment service providers.

Depending on the payment method, this may include:

  • payment status
  • transaction reference
  • subscription information
  • billing information
  • limited payment-card information

Mesodian does not generally need to store complete payment-card details where these are handled directly by our payment provider. Payment providers process payment information under their own terms and privacy policies.

7. Technical and Usage Information

When you use Mesodian, we may automatically collect technical and usage information.

This may include:

  • IP address
  • browser type
  • device type
  • operating system
  • device identifiers
  • application version
  • pages or screens accessed
  • features used
  • session information
  • timestamps
  • referring website
  • error information
  • performance information
  • interactions with the Service

We use this information to operate, secure, maintain and improve Mesodian.

8. Cookies and Similar Technologies

Mesodian may use cookies and similar technologies.

Cookies may be used for purposes including:

  • authentication
  • maintaining sessions
  • security
  • remembering preferences
  • analytics
  • understanding how users interact with the Service
  • improving performance
  • measuring website activity

Some cookies may be necessary for the Service to operate. Other cookies or similar technologies may require your consent depending on their purpose and applicable law. Where required, we will provide appropriate controls allowing you to manage non-essential cookies.

9. Communications

If you communicate with Mesodian, we may collect information contained in those communications.

This may include:

  • emails
  • support requests
  • feedback
  • survey responses
  • product feedback
  • bug reports
  • other communications you send to us

We use this information to respond to you, provide support and improve the Service.

10. How We Collect Personal Data

We may collect personal data:

  • directly from you
  • when you create an Account
  • when you use the Service
  • when you connect a Brokerage Account
  • through third-party brokerage connectivity providers
  • through payment providers
  • through authentication providers
  • through cookies and similar technologies
  • through support communications
  • through surveys and feedback
  • from other service providers used to operate Mesodian

Where personal data is obtained from a third party rather than directly from you, we will provide the information required by applicable data protection law. The GDPR requires appropriate transparency where personal data is obtained from sources other than the individual.

11. How We Use Personal Data

We may process personal data for the following purposes.

11.1 Providing Mesodian

We use personal data to:

  • create and manage Accounts
  • authenticate users
  • provide the Service
  • provide portfolios and strategies
  • provide portfolio analysis
  • display portfolio information
  • provide automated portfolio functionality
  • connect Brokerage Accounts
  • provide customer support
  • maintain user preferences
  • provide requested features

11.2 Operating and Maintaining the Service

We use information to:

  • maintain our systems
  • monitor system performance
  • troubleshoot errors
  • detect technical problems
  • improve reliability
  • maintain security
  • prevent misuse
  • investigate incidents

11.3 Improving Mesodian

We may use information to understand how users interact with the Service and improve:

  • functionality
  • user experience
  • product design
  • portfolio features
  • research features
  • educational content
  • performance
  • reliability

11.4 Communications

Where possible, we may use aggregated or anonymised information for product analysis.

We may use your contact information to:

  • respond to support requests
  • send important service communications
  • notify you about changes to the Service
  • provide security notifications
  • provide account-related information
  • communicate about subscriptions
  • send other communications where permitted by law

11.5 Payments and Subscriptions

Where marketing communications require consent, we will seek consent where required.

We process information necessary to:

  • manage subscriptions
  • process payments
  • verify payment status
  • manage billing
  • prevent payment fraud
  • provide paid features

11.6 Security and Fraud Prevention

We may process information to:

  • detect suspicious activity
  • protect Accounts
  • protect the Service
  • investigate security incidents
  • prevent fraud
  • enforce our Terms
  • protect users and third parties

11.7 Legal and Regulatory Compliance

We may process personal data where necessary to:

  • comply with legal obligations
  • respond to lawful requests
  • establish or defend legal claims
  • comply with court orders
  • enforce contractual rights
  • maintain appropriate business records

12. Legal Bases for Processing

Under GDPR, personal data must be processed on a lawful basis.

Depending on the processing activity, Mesodian may rely on one or more of the following legal bases.

12.1 Performance of a Contract

We may process personal data where necessary to provide the Service you have requested or perform our agreement with you.

This may include:

  • creating your Account
  • authenticating your Account
  • providing portfolios
  • providing strategies
  • providing portfolio analysis
  • providing automated portfolio functionality
  • managing subscriptions
  • providing customer support

12.2 Legitimate Interests

We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms.

Our legitimate interests may include:

  • operating Mesodian
  • improving the Service
  • maintaining security
  • preventing fraud
  • understanding Service usage
  • developing products
  • maintaining business records
  • enforcing our Terms
  • protecting our legal rights

12.3 Legal Obligations

Where we rely on legitimate interests, we consider the impact of the processing on individuals and apply appropriate safeguards. The Irish Data Protection Commission identifies legitimate interests as one of the lawful bases available under Article 6 GDPR.

We may process personal data where necessary to comply with an applicable legal obligation.

12.4 Consent

We may rely on consent where applicable.

Where we rely on consent, you may withdraw your consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

13. How We Use Brokerage Information

Where you connect a Brokerage Account, information obtained through that connection is used to provide the functionality you have requested.

This may include:

  • displaying your portfolio
  • analysing your holdings
  • calculating portfolio metrics
  • displaying transactions
  • calculating portfolio performance
  • implementing an Automated Portfolio
  • determining whether rebalancing may be required
  • transmitting authorised transaction instructions
  • maintaining portfolio history

We do not use Brokerage Account information to take ownership of your investments.

14. Brokerage Connectivity Providers

Mesodian may use third-party brokerage connectivity providers, including SnapTrade, to connect users with supported Brokerage Providers.

These providers may process information necessary to establish and maintain the connection between Mesodian and your Brokerage Account.

The relevant provider may process information under its own privacy policy and terms.

You should review the applicable third-party privacy policy before connecting a Brokerage Account.

15. Who We Share Personal Data With

We may share personal data with service providers where necessary to operate Mesodian.

These may include:

  • cloud hosting providers
  • database providers
  • authentication providers
  • payment processors
  • brokerage connectivity providers
  • Brokerage Providers
  • market data providers
  • analytics providers
  • customer support providers
  • email and communications providers
  • security providers
  • infrastructure providers
  • professional advisers
  • legal advisers
  • accountants
  • auditors

We only share information where there is an appropriate legal basis and where the disclosure is necessary for the relevant purpose.

16. Brokerage Providers

If you choose to connect a Brokerage Account, information may be shared with or received from the relevant Brokerage Provider or brokerage connectivity provider as necessary to provide the requested functionality.

The information shared depends on:

  • the Brokerage Provider
  • the connectivity provider
  • the permissions you grant
  • the features you enable

Your Brokerage Provider may process your information independently under its own privacy policy.

17. Service Providers and Data Processors

Some companies provide services to Mesodian on our behalf.

Where a service provider acts as a processor of personal data for Mesodian, we will use appropriate contractual arrangements and require the processor to process personal data in accordance with applicable data protection requirements.

The Irish Data Protection Commission states that controllers engaging processors must have an appropriate legally binding data processing arrangement governing the processing.

18. Business Transfers

If Mesodian is involved in:

  • a merger
  • acquisition
  • restructuring
  • financing
  • sale of assets
  • sale of the business
  • insolvency or similar transaction

personal data may be transferred as part of that transaction where legally permitted. Any transfer will remain subject to applicable data protection requirements.

19. Legal Disclosures

We may disclose personal data where necessary to:

  • comply with applicable law
  • comply with a court order
  • respond to lawful requests from authorities
  • protect our legal rights
  • investigate fraud
  • investigate security incidents
  • protect users or third parties
  • enforce our agreements

20. International Data Transfers

Some of our service providers may process personal data outside the European Economic Area ("EEA").

Where personal data is transferred outside the EEA, we will use an appropriate legal mechanism where required by GDPR.

Depending on the circumstances, this may include:

  • an adequacy decision
  • Standard Contractual Clauses
  • another lawful transfer mechanism
  • applicable safeguards recognised under GDPR

Where required, additional information concerning relevant transfer safeguards may be provided upon request.

21. Data Security

We use appropriate technical and organisational measures designed to protect personal data against:

  • unauthorised access
  • unauthorised disclosure
  • accidental loss
  • destruction
  • alteration
  • misuse

Security measures may include:

  • access controls
  • authentication
  • encryption where appropriate
  • system monitoring
  • logging
  • infrastructure security
  • least-privilege access
  • security testing
  • backup procedures

No internet-based service can be guaranteed to be completely secure. The GDPR requires controllers to apply appropriate security measures and protect personal data against unauthorised or unlawful processing and accidental loss, destruction or damage.

22. Data Breaches

If Mesodian becomes aware of a personal data breach, we will assess the breach and take appropriate action in accordance with applicable data protection law.

Where legally required, we will notify the Irish Data Protection Commission and affected individuals.

23. How Long We Keep Personal Data

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, unless a longer period is required or permitted by law.

Different categories of information may be retained for different periods. For example:

Account information

Generally retained while your Account remains active and for a reasonable period after account closure where necessary for legitimate business, legal or security purposes.

Portfolio and brokerage information

Generally retained while necessary to provide portfolio functionality and maintain relevant records, subject to applicable legal requirements.

Payment and transaction records

May be retained for the period necessary to comply with accounting, tax, financial or legal obligations.

Support communications

May be retained for as long as reasonably necessary to manage support matters, disputes and service improvements.

Security and technical logs

Generally retained for a limited period appropriate to security, troubleshooting and operational purposes.

We periodically review retained information and delete or anonymise information when it is no longer required, subject to applicable legal obligations. The GDPR includes a storage limitation principle requiring personal data not to be kept longer than necessary for its purpose.

24. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have the following rights.

Right of access

You may request access to personal data we hold about you.

Right to rectification

You may ask us to correct inaccurate or incomplete personal data.

Right to erasure

You may ask us to delete personal data in certain circumstances. This right is sometimes referred to as the "right to be forgotten".

Right to restriction

You may request that we restrict processing of your personal data in certain circumstances.

Right to data portability

Where applicable, you may request certain personal data in a structured, commonly used and machine-readable format and ask us to transmit it to another organisation.

Right to object

You may object to certain processing based on legitimate interests. You may also have an unconditional right to object to direct marketing.

Right to withdraw consent

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out lawfully before withdrawal.

Rights concerning automated decision-making

Where applicable, you may have rights relating to automated decision-making and profiling.

Mesodian does not intend to make decisions about your legal rights or similarly significant matters solely through automated processing.

Mesodian may use automated systems to analyse investments, portfolios and financial information. These analytical processes are not intended to make legally or similarly significant decisions about you.

25. How to Exercise Your Rights

You can exercise your data protection rights by contacting us using the contact details provided at the end of this Privacy Policy.

When making a request, we may need to verify your identity to ensure that personal data is not disclosed to the wrong person.

The Irish Data Protection Commission states that organisations may request additional information where they have reasonable doubts about an individual's identity.

We will generally respond to valid data protection requests within the timeframe required by applicable law.

26. Complaints

If you believe that Mesodian has processed your personal data unlawfully or has not properly addressed your data protection rights, please contact us first so that we can investigate the matter.

You also have the right to lodge a complaint with the relevant supervisory authority.

For Mesodian's Irish operations, the relevant supervisory authority is:

Data Protection Commission — Website: dataprotection.ie. The Irish Data Protection Commission is responsible for supervising and enforcing data protection law in Ireland.

27. Children

Mesodian is not intended for children who are below the minimum age required to use the Service under applicable law.

We do not knowingly collect personal data from children where such collection is prohibited.

If you believe that a child has provided personal data to Mesodian without appropriate permission, please contact us so that we can investigate and take appropriate action.

28. Third-Party Websites

Mesodian may contain links to third-party websites.

This Privacy Policy does not apply to third-party websites.

You should review the privacy policy of any third-party website or service before providing personal information.

29. Third-Party Brokerage Accounts

When you connect a Brokerage Account, the relevant Brokerage Provider remains responsible for its own processing of your personal data.

Your Brokerage Provider may have different privacy practices and may collect information directly from you.

You should review the Brokerage Provider's privacy policy and terms before connecting your account.

30. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

Changes may be made to reflect:

  • changes to the Service
  • new features
  • new data processing activities
  • changes to service providers
  • changes in applicable law
  • changes to our data protection practices

When we make material changes, we may notify you through the Service, by email or through another appropriate method. The "Last updated" date at the beginning of this Privacy Policy indicates when it was most recently updated. The Irish Data Protection Commission recommends that privacy policies remain dynamic documents and are regularly reviewed to reflect an organisation's actual processing activities.

31. Contact and Legal Information

Legal entity: Mesodian

Registered address: 15 Rockbarton Road, Ireland

Email: contact@mesodian.com

For privacy and data protection enquiries, you can contact us using the email address above.

32. Governing Framework

This Privacy Policy is intended to explain Mesodian's processing of personal data in accordance with applicable data protection law, including the GDPR and applicable Irish data protection legislation.

Nothing in this Privacy Policy limits any rights you have under applicable data protection law.

Last updated: 15 September 2026 · Questions? Contact contact@mesodian.com