1. Data controller
The controller of your personal data is Mets sp. z o.o. (in organisation), ul. Prosta 1, 00-001 Warsaw, Poland ("Mets", "we").
For anything related to personal data, contact us at privacy@mets.ulewicz.space. For technical and account matters, write to support@mets.ulewicz.space.
2. Scope
This policy covers the Mets website, the web application for video meetings and webinars, and your communication with us (email, forms).
If you use Mets through a company account (organisation), the controller of meeting content is usually your employer or organisation, and Mets acts as a processor under a data processing agreement. See "GDPR & data processing" for details.
3. What data we process
We only process the data needed to provide the service:
- account data: name or display name, email address, hashed password, avatar, preferred language and time zone;
- guest data: the display name entered when joining a meeting (no account required);
- meeting data: title, schedule, room code, participant list, join and leave times, settings (waiting room, password, encryption);
- meeting content — only when the host enables the feature: chat messages, recordings, transcripts, translations, summaries, whiteboard content;
- technical data: IP address, browser and OS type, connection quality metrics, security event logs;
- billing data for paid plans: company name, VAT ID, address, payment history (no full card data — handled by the payment provider).
4. Purposes and legal bases
Every purpose has a legal basis under Art. 6(1) GDPR:
- providing the service, running your account and hosting meetings — performance of a contract (Art. 6(1)(b));
- recording, transcription and AI summaries — performance of a contract on the host's instruction; the host is responsible for informing participants and obtaining consent where required;
- security, abuse prevention and diagnostics — legitimate interests (Art. 6(1)(f));
- billing, invoicing and tax duties — legal obligation (Art. 6(1)(c));
- handling support requests and complaints — performance of a contract and legitimate interests;
- product newsletter — only with your consent (Art. 6(1)(a)), which you can withdraw at any time.
5. Meeting content, recordings and transcripts
Audio and video travel through our media server (SFU) located in the European Union. Transport is always encrypted (DTLS-SRTP). In rooms with end-to-end encryption (E2EE) the key is shared only among participants — our server forwards encrypted packets and is technically unable to read them.
Recordings, transcripts and summaries are created only when the host starts them, and every participant sees a clear recording indicator. Transcription runs on our servers in the EU; text is never used to train AI models.
In E2EE rooms, server-side recording and transcription are unavailable — a deliberate consequence of the encryption.
6. Recipients
We only entrust data to carefully selected processors bound by data processing agreements under Art. 28 GDPR. The full list is in "GDPR & data processing". The key providers are:
- Supabase — database, authentication and file storage in the eu-west-1 region (Ireland);
- LiveKit — media server running on our own infrastructure in the EU (open-source software, no data shared with the vendor);
- Cloudflare — DNS services;
- a large language model provider (Anthropic) — only if an organisation turns on advanced AI summaries.
7. Transfers outside the EEA
By default, all data is stored and processed in the European Economic Area. A transfer outside the EEA can only happen for optional AI features enabled by the customer or for the DNS provider's infrastructure — always under the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) or an adequacy decision.
8. Retention
- account data — for as long as you have an account, then up to 30 days after deletion (backups up to 35 days);
- recordings, transcripts and summaries — until deleted by the user or according to the organisation's retention policy;
- chat messages — together with the meeting, unless the host sets a shorter period;
- technical and security logs — up to 90 days;
- billing records — 5 years from the end of the tax year, as required by tax law.
9. Your rights
You have the right to access, rectify and erase your data, to restrict processing, to data portability and to object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing.
You can download or delete most data yourself in your account settings. For anything else, write to privacy@mets.ulewicz.space — we reply within 30 days. You also have the right to lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO, ul. Stawki 2, 00-193 Warsaw), or with the authority in your country.
11. Security
We use TLS for all traffic, DTLS-SRTP for media, optional end-to-end encrypted rooms, encryption at rest, database Row Level Security, short-lived room access tokens, password hashing and rate limiting. Staff access to production data is kept to the strict minimum and logged.
12. Changes to this policy
We may update this policy, for example because of new features or legal changes. We will notify signed-in users of material changes by email or in-app at least 14 days in advance. The date of the last update is shown at the top of this page.
You can download or print this document using your browser's print function.
Back to top