Skip to content

Legal

GDPR & data processing

Last updated: 8 October 2026

This document complements the Privacy policy and is written mainly for IT teams, data protection officers and legal departments evaluating Mets as a vendor. It fulfils our information duties under Articles 13 and 14 GDPR.

Draft — this document is pending legal review and may change before the commercial launch of the service.

1. Controller and contact

The controller is Mets sp. z o.o. (in organisation), ul. Prosta 1, 00-001 Warsaw, Poland. Until a data protection officer is appointed, data protection matters are handled by a designated person reachable at privacy@mets.ulewicz.space.

2. Roles: controller and processor

For account, billing and security data, Mets is the controller.

When an Organisation uses Mets (Business or Enterprise plan), the Organisation is the controller of meeting content — recordings, transcripts, summaries, chat and participant lists — and Mets processes that data on its behalf as a processor (Art. 28 GDPR).

3. Categories of data and data subjects

We process data of account holders, meeting guests, participants and registered webinar attendees, and people who contact us. Data categories:

  • identification and contact data (display name, email);
  • authentication data (password hash, identity provider ID);
  • meeting metadata (schedules, attendance, connection times);
  • communication content: real-time audio and video (not stored unless recording is on), chat, recordings, transcripts, translations, summaries, whiteboard content;
  • technical data (IP address, browser, connection quality statistics);
  • billing data (company details, payment history).

4. Legal bases (Art. 6 GDPR)

  • Art. 6(1)(b) — performance of a contract: Accounts, meetings, webinars, recordings, transcripts and summaries;
  • Art. 6(1)(c) — legal obligation: accounting and tax, responses to requests from competent authorities;
  • Art. 6(1)(f) — legitimate interests: service security, abuse prevention, legal claims, service communication;
  • Art. 6(1)(a) — consent: newsletter and optional surveys. Consent can be withdrawn at any time.

5. Retention periods

Meeting content is kept until deleted by the user or according to the Organisation's retention policy (on the Business plan, automatic deletion after 30, 90 or 365 days can be configured). Account data is deleted within 30 days of Account deletion, and from backups within 35 days. Security logs are kept for up to 90 days and accounting records for 5 years from the end of the tax year.

6. Processors

We rely on a small number of providers bound by data processing agreements. Meeting media never leaves our infrastructure in the EU.

ProviderPurposeLocationSafeguards
Supabase Inc.Database, authentication, file storage (recordings)EU — eu-west-1 (Ireland)DPA, SCCs, encryption at rest
LiveKit (open-source software)SFU media server — audio and video transportMets' own servers in the EUSelf-hosted, no data shared with the vendor
Cloudflare, Inc.DNS servicesGlobal network, headquartered in the USADPA, SCCs, EU-US Data Privacy Framework
Anthropic PBC (optional)Advanced summaries and translations — only when enabled by the OrganisationUSASCCs, no model training on customer data

7. Transfers outside the EEA

Core processing takes place in the EEA. Transfers to third countries happen only for the providers listed above, based on Standard Contractual Clauses (Art. 46(2)(c) GDPR) or a European Commission adequacy decision (Art. 45 GDPR), supplemented by a transfer impact assessment and additional technical measures.

8. AI features

Speech transcription runs on our servers in the EU using open speech recognition models. Default summaries are generated locally. Advanced summaries using an external language model are optional — an Organisation must deliberately turn them on. Customer data is never used to train models, neither by us nor by our providers.

We do not make decisions about users based solely on automated processing, including profiling, that produce legal effects (Art. 22 GDPR).

9. Data subject rights (Art. 15–22)

Every data subject has the right to:

  • access their data and obtain a copy (Art. 15);
  • rectification (Art. 16);
  • erasure — the "right to be forgotten" (Art. 17);
  • restriction of processing (Art. 18);
  • data portability in a structured format (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • not be subject to decisions based solely on automated processing (Art. 22).

10. Complaints to a supervisory authority

If you believe we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl), or with the supervisory authority in the member state of your habitual residence or place of work. We encourage you to contact us first — we resolve most issues quickly.

11. Data processing agreement for businesses (Art. 28)

We offer business customers a data processing agreement (DPA) compliant with Art. 28 GDPR, including the list of sub-processors, a description of technical and organisational measures and a breach notification procedure. On the Business plan the DPA is concluded electronically in the Organisation dashboard; Enterprise customers can negotiate individual terms. We announce planned sub-processor changes 30 days in advance, with a right to object.

12. Security measures (Art. 32)

  • TLS 1.2+ for all network traffic and DTLS-SRTP for media;
  • end-to-end encrypted (E2EE) rooms where the key never reaches the server;
  • encryption at rest (database and file storage);
  • Row Level Security — every database row is accessible only to authorised users;
  • short-lived room access tokens (up to 2 hours), hashed room and account passwords;
  • rate limiting, audit logs and least-privilege access for staff;
  • regular backups and restore tests.

13. Personal data breaches

In the event of a personal data breach we notify the President of UODO within 72 hours of becoming aware of it (Art. 33 GDPR) and, where it is likely to result in a high risk, inform the affected data subjects without undue delay (Art. 34). Organisations for which we act as a processor are notified without undue delay so they can meet their own obligations.

You can download or print this document using your browser's print function.

Back to top