Meridian Terms & Conditions
These Terms and Conditions govern the use of Meridian, a proprietary client management platform developed and operated exclusively by Sydney Hudson Ltd (Company No. 11542823), registered in England and Wales. Meridian is an internal business tool and is not offered to the public. Access is restricted to authorised staff of Sydney Hudson Ltd and, where applicable, their clients via a dedicated portal.
Definitions
The Meridian client relationship management platform, including all modules (Sprint management, Schedule, Companies House integration, Knowledge Library, Client Portal, and Vault), operated by Sydney Hudson Ltd.
Sydney Hudson Ltd, Company No. 11542823, registered office: Bedford Heights, Brickhill Drive, Level 4, Unit 410, Bedford, MK41 7PH.
A member of staff employed or contracted by Sydney Hudson Ltd who has been granted access credentials by an administrator.
A client of Sydney Hudson Ltd who has been granted limited access to their own data via the Meridian client-facing workspace (/workspace).
Any financial, personal, corporate, or compliance data relating to clients of Sydney Hudson Ltd that is stored, processed, or displayed within the Software.
The HM Revenue & Customs Making Tax Digital API and associated application-restricted services used by the Software for VAT number verification and related functions.
Scope and Purpose
Meridian is developed and maintained solely for the internal operational use of Sydney Hudson Ltd in the delivery of its accountancy and tax advisory services. The Software is not a consumer product and is not licensed, sold, or distributed to third parties.
The principal functions of Meridian include:
- Client relationship and engagement management
- Annual accounts, corporation tax, VAT, and self-assessment sprint tracking
- Recurring bookkeeping schedule management and CRRF workflow
- Companies House data integration (read-only) and filing preparation
- Knowledge Library for staff training resources
- Encrypted shared credential storage (Vault)
- Client document sharing and acknowledgement via the Client Portal
- Integration with HMRC APIs for VAT number verification under Making Tax Digital
Meridian is an internal tool. These Terms govern use by Sydney Hudson Ltd staff and, to the extent applicable, Client Portal Users accessing their own records. No third-party software provider rights are implied.
Access and Authorisation
Staff Access
Access to Meridian is granted exclusively by the system administrator (Beverley Sydney, Founder of Sydney Hudson Ltd). Each Authorised User is assigned individual credentials. Credentials must not be shared, transferred, or disclosed to any person inside or outside the firm.
Authorised Users must:
- Complete any multi-factor authentication steps required at login
- Log out of active sessions when leaving a workstation unattended
- Notify the administrator immediately if credentials are lost, compromised, or if they suspect unauthorised access
- Use Meridian only in connection with their legitimate duties at Sydney Hudson Ltd
Client Portal Access
Client Portal Users access Meridian via a magic-link or password authentication. Portal access is scoped strictly to the Client Portal User's own client record. Portal Users may not access other clients' data, staff-facing modules, the Vault, or internal operational pages.
Revocation
Access may be revoked by the administrator at any time, including upon termination of employment or engagement. Upon revocation, the former user must immediately cease all access and must not retain, copy, or use any data obtained from the Software.
Data Handling and Privacy
Data Controller
Sydney Hudson Ltd is the data controller for all Client Data held within Meridian. The Software operates as an internal system and does not share data with third parties except as required for the lawful delivery of accountancy services (e.g. filing with HMRC or Companies House).
Data Stored
Meridian stores and processes the following categories of data:
| Category | Examples | Purpose |
|---|---|---|
| Client personal data | Name, email, UTR, NI number, date of birth | Client management and compliance |
| Corporate data | Company number, registered office, officer details | Companies House integration and filing |
| Financial data | MRR, turnover, VAT position | Service delivery and financial reporting |
| Compliance data | VAT returns, tax positions, filing status | Sprint and schedule management |
| Credential data | Government Gateway logins (encrypted) | Shared Vault — internal access only |
| Staff operational data | Task assignments, comments, audit logs | Internal workflow management |
Data Retention
Client Data is retained for the minimum period required by applicable law and professional regulatory obligations, including HMRC record-keeping requirements (currently six years for VAT and corporation tax records). Staff may not delete client records without authorisation from the system administrator.
Data Security
All data is stored on secured infrastructure. Credentials held in the Vault are encrypted using AES-256-GCM. Audit logs record all access to sensitive data including vault reveals, document views, and data exports. Role-based access controls restrict data visibility to the minimum necessary for each user's function.
Important: Financial data (MRR figures) is redacted for non-administrator users. Vault credentials are accessible only to authenticated staff members. The Client Portal cannot access internal staff modules or the Vault under any circumstances.
HMRC API Usage
Meridian integrates with HMRC's Making Tax Digital API and application-restricted services (including the \"Check a UK VAT number\" endpoint) under production credentials issued to Sydney Hudson Ltd by HMRC.
Permitted Use
HMRC API access within Meridian is used exclusively for:
- Verifying UK VAT registration numbers for clients of Sydney Hudson Ltd
- Supporting the delivery of VAT compliance services under the firm's AAT licence
- Functionality required for Making Tax Digital obligations on behalf of clients
Restrictions
HMRC API access must not be used for:
- Any purpose unrelated to the legitimate accountancy services of Sydney Hudson Ltd
- Bulk data harvesting or commercial data resale
- Accessing data relating to entities who are not clients of Sydney Hudson Ltd
- Any purpose that contravenes HMRC's API terms of use
Compliance
Sydney Hudson Ltd holds the necessary HMRC production credentials and is responsible for maintaining compliance with HMRC's developer terms. All API calls are authenticated using OAuth2 client credentials. Tokens are cached securely in-process and rotated before expiry. API call logs are retained for audit purposes.
The HMRC sandbox environment is used for development and testing. Production credentials are used exclusively for live client service delivery. Sydney Hudson Ltd does not share HMRC credentials with any third party.
User Obligations
All Authorised Users agree to:
- Use Meridian solely in connection with their duties at Sydney Hudson Ltd
- Maintain the confidentiality of all Client Data accessed via the Software
- Follow the firm's data protection policies and any instructions issued by the system administrator
- Report any suspected data breach, unauthorised access, or system vulnerability immediately to the administrator
- Not attempt to access, copy, extract, or transmit data beyond the scope of their role
- Not circumvent, disable, or tamper with any security feature, access control, or audit mechanism
- Not use the Software's infrastructure for personal projects, external clients, or any purpose outside Sydney Hudson Ltd's business
Breaches of these obligations may constitute a breach of employment or engagement contract and may result in disciplinary action, termination, and/or referral to the relevant regulatory or law enforcement authorities.
Liability and Disclaimers
Internal Tool
Meridian is an internal operational tool. It is provided to Authorised Users and Client Portal Users on an \"as is\" basis for the purposes described in these Terms. Sydney Hudson Ltd makes no warranties to users regarding uninterrupted availability, error-free operation, or fitness for any purpose beyond those described.
Data Accuracy
Companies House data displayed in Meridian is fetched in real time from the Companies House Public Data API and is provided for reference only. Sydney Hudson Ltd is not responsible for inaccuracies in data returned by third-party APIs (Companies House, HMRC, or Charity Commission).
System Availability
Sydney Hudson Ltd will use reasonable endeavours to maintain system availability but does not guarantee continuous uptime. Scheduled maintenance, infrastructure issues, or third-party service interruptions may affect availability.
Limitation
To the fullest extent permitted by law, Sydney Hudson Ltd's liability to any user arising out of or in connection with the use of Meridian is limited to direct losses only, and excludes indirect, consequential, or incidental losses.
Security Measures
Sydney Hudson Ltd implements the following security controls within Meridian:
- Authentication: Username and password with two-factor authentication (TOTP) for staff access. Magic-link and password authentication for Client Portal Users.
- Encryption: Vault credentials stored as AES-256-GCM ciphertext. All connections served over HTTPS/TLS.
- Role-based access control: Access scoped to each user's function. Administrators have additional privileges. Non-admins cannot access financial overviews, Vault entries, or override sprint assignments.
- Audit logging: All sensitive actions (vault access, document views, data exports, admin changes) are recorded with user, timestamp, and action type.
- Object storage: File attachments stored in encrypted private cloud storage (Cloudflare R2). Files served through authenticated API routes only — no public URLs.
- Isolation: Client Portal authentication is fully isolated from staff authentication. Portal JWTs cannot access staff routes and vice versa.
- Demo mode: A sandboxed demo environment is available for testing. All demo-mode actions and data are isolated and do not affect live client records.
Sydney Hudson Ltd reviews security controls regularly and updates them in response to emerging threats and regulatory guidance.
Governing Law and Contact
Governing Law
These Terms are governed by and construed in accordance with the laws of England and Wales. Any disputes arising from the use of Meridian shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Changes to These Terms
Sydney Hudson Ltd reserves the right to amend these Terms at any time. Authorised Users will be notified of material changes. Continued use of the Software following notification constitutes acceptance of the updated Terms.
Contact
For questions regarding these Terms, data access requests, or to report a security concern:
| Company | Sydney Hudson Ltd |
| Registered address | Bedford Heights, Brickhill Drive, Level 4, Unit 410, Bedford, MK41 7PH |
| Company number | 11542823 |
| AAT Licence | 10030823 |
| admin@sydneyhudson.co.uk | |
| Website | sydneyhudson.co.uk |
These Terms and Conditions were last updated in June 2026 and apply to Meridian version 1.0 and above.

