1. Controller and contact
The controller is Mets sp. z o.o. (in organisation), ul. Prosta 1, 00-001 Warsaw, Poland. Until a data protection officer is appointed, data protection matters are handled by a designated person reachable at privacy@mets.ulewicz.space.
2. Roles: controller and processor
For account, billing and security data, Mets is the controller.
When an Organisation uses Mets (Business or Enterprise plan), the Organisation is the controller of meeting content — recordings, transcripts, summaries, chat and participant lists — and Mets processes that data on its behalf as a processor (Art. 28 GDPR).
3. Categories of data and data subjects
We process data of account holders, meeting guests, participants and registered webinar attendees, and people who contact us. Data categories:
- identification and contact data (display name, email);
- authentication data (password hash, identity provider ID);
- meeting metadata (schedules, attendance, connection times);
- communication content: real-time audio and video (not stored unless recording is on), chat, recordings, transcripts, translations, summaries, whiteboard content;
- technical data (IP address, browser, connection quality statistics);
- billing data (company details, payment history).
4. Legal bases (Art. 6 GDPR)
- Art. 6(1)(b) — performance of a contract: Accounts, meetings, webinars, recordings, transcripts and summaries;
- Art. 6(1)(c) — legal obligation: accounting and tax, responses to requests from competent authorities;
- Art. 6(1)(f) — legitimate interests: service security, abuse prevention, legal claims, service communication;
- Art. 6(1)(a) — consent: newsletter and optional surveys. Consent can be withdrawn at any time.
5. Retention periods
Meeting content is kept until deleted by the user or according to the Organisation's retention policy (on the Business plan, automatic deletion after 30, 90 or 365 days can be configured). Account data is deleted within 30 days of Account deletion, and from backups within 35 days. Security logs are kept for up to 90 days and accounting records for 5 years from the end of the tax year.
6. Processors
We rely on a small number of providers bound by data processing agreements. Meeting media never leaves our infrastructure in the EU.
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase Inc. | Database, authentication, file storage (recordings) | EU — eu-west-1 (Ireland) | DPA, SCCs, encryption at rest |
| LiveKit (open-source software) | SFU media server — audio and video transport | Mets' own servers in the EU | Self-hosted, no data shared with the vendor |
| Cloudflare, Inc. | DNS services | Global network, headquartered in the USA | DPA, SCCs, EU-US Data Privacy Framework |
| Anthropic PBC (optional) | Advanced summaries and translations — only when enabled by the Organisation | USA | SCCs, no model training on customer data |
7. Transfers outside the EEA
Core processing takes place in the EEA. Transfers to third countries happen only for the providers listed above, based on Standard Contractual Clauses (Art. 46(2)(c) GDPR) or a European Commission adequacy decision (Art. 45 GDPR), supplemented by a transfer impact assessment and additional technical measures.
8. AI features
Speech transcription runs on our servers in the EU using open speech recognition models. Default summaries are generated locally. Advanced summaries using an external language model are optional — an Organisation must deliberately turn them on. Customer data is never used to train models, neither by us nor by our providers.
We do not make decisions about users based solely on automated processing, including profiling, that produce legal effects (Art. 22 GDPR).
9. Data subject rights (Art. 15–22)
Every data subject has the right to:
- access their data and obtain a copy (Art. 15);
- rectification (Art. 16);
- erasure — the "right to be forgotten" (Art. 17);
- restriction of processing (Art. 18);
- data portability in a structured format (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- not be subject to decisions based solely on automated processing (Art. 22).
10. Complaints to a supervisory authority
If you believe we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl), or with the supervisory authority in the member state of your habitual residence or place of work. We encourage you to contact us first — we resolve most issues quickly.
11. Data processing agreement for businesses (Art. 28)
We offer business customers a data processing agreement (DPA) compliant with Art. 28 GDPR, including the list of sub-processors, a description of technical and organisational measures and a breach notification procedure. On the Business plan the DPA is concluded electronically in the Organisation dashboard; Enterprise customers can negotiate individual terms. We announce planned sub-processor changes 30 days in advance, with a right to object.
12. Security measures (Art. 32)
- TLS 1.2+ for all network traffic and DTLS-SRTP for media;
- end-to-end encrypted (E2EE) rooms where the key never reaches the server;
- encryption at rest (database and file storage);
- Row Level Security — every database row is accessible only to authorised users;
- short-lived room access tokens (up to 2 hours), hashed room and account passwords;
- rate limiting, audit logs and least-privilege access for staff;
- regular backups and restore tests.
13. Personal data breaches
In the event of a personal data breach we notify the President of UODO within 72 hours of becoming aware of it (Art. 33 GDPR) and, where it is likely to result in a high risk, inform the affected data subjects without undue delay (Art. 34). Organisations for which we act as a processor are notified without undue delay so they can meet their own obligations.
You can download or print this document using your browser's print function.
Back to top