Compliance
Privacy Policy
Last updated: July 2026
Metadot Corporation develops and operates hardware and software products, including Das Keyboard, Mojo Helpdesk, Metadot Apps Workspace, Bamzooka, Montastic, and TyprX. This Privacy Policy describes how Metadot collects, uses, discloses, and protects Personal Data when you use our websites, products, and services.
This Privacy Policy explains what information we collect, how we use it, how we share it, and the safeguards we put in place to protect it.
SOC 2 Type II
Our SaaS products operate under a SOC 2 Type II program. An independent third-party audit verifies that our security controls are appropriately designed and consistently operating to help protect customer data.
A current SOC 2 Type II attestation letter is available upon reasonable request, subject to appropriate confidentiality obligations.
AI Features and Customer Data
When our products use AI to assist users, customer data remains within the account from which it originated. We do not use customer content to train third-party foundation models, and we contractually require the model providers we work with to do the same.
Information We Collect
We collect Personal Data that you choose to provide when using our websites, products, and services, including account and contact information, billing information needed to process a purchase, support requests, ticket content, attachments, and other information you submit. We use this information only as necessary to provide, support, secure, and improve our products and services, or as otherwise described in this Privacy Policy. Additional information about our data processing practices is available upon request.
How We Protect Your Data
We implement administrative, technical, and organizational safeguards designed to protect Personal Data from unauthorized access, disclosure, alteration, and destruction. Access to Personal Data is limited to authorized personnel with a legitimate business need, and those individuals are subject to confidentiality obligations and appropriate security training.
- Passwords are stored using one-way cryptographic hashing.
- Payment information is tokenized by our payment processor; full payment card numbers are never stored on our servers.
- Personal Data is encrypted in transit and, where appropriate, at rest.
- Customer data is backed up regularly using encrypted backups.
- Our systems are continuously monitored, and we regularly evaluate the effectiveness of our security controls.
Hosting
Our SaaS products are hosted on Amazon Web Services (AWS) in ISO 27001-certified data centers. We implement administrative, technical, and organizational safeguards designed to protect the security, availability, and integrity of our services.
HIPAA and Business Associate Agreements
For customers who require a Business Associate Agreement (BAA), Metadot will provide one upon request for eligible products and services. See our HIPAA page for additional information.
Cookies and Tracking
We use cookies and similar technologies to operate our websites and services, maintain user sessions, enhance security, remember your preferences, and understand how our websites and products are used. You can manage or disable cookies through your browser settings; however, some features may not function properly without essential cookies.
Analytics
We use analytics tools, including Google Analytics, to better understand how visitors use our websites and to improve their performance and user experience. Analytics information is collected in aggregate or using pseudonymous identifiers and is not used to identify individual users. You can manage your analytics preferences by adjusting your browser settings or by using Google's available opt-out tools.
Third-Party Services
We engage a limited number of trusted third-party service providers to support the delivery, operation, maintenance, and security of our websites, products, and services, such as payment processing, email delivery, hosting, and business operations. We require these providers to implement appropriate safeguards to protect Personal Data and to process it only in accordance with our instructions and applicable contractual and legal obligations.
Google User Data
Data Accessed
When you connect your Google account, our products may access your Google account email address, calendars, calendar availability, events created by our application, and Google Meet conference information (when enabled).
Data Usage
This information is used solely to provide calendar and scheduling features, including connecting your account, displaying calendar availability, creating and managing booking events, inviting attendees, and generating Google Meet links when requested.
Metadot does not use Google user data for advertising, marketing, profiling, or training AI models.
Limited Use Disclosure
Metadot's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Data Sharing
Metadot does not sell Google user data. Google user data is shared only as necessary to provide the requested functionality, including with Google services to perform calendar operations, meeting attendees through calendar invitations initiated by the user, and trusted service providers that support the operation of our products and services.
Data Storage & Protection
Google user data is protected using administrative, technical, and organizational safeguards. Data is encrypted in transit and, where appropriate, at rest, and access is limited to authorized personnel and systems.
Data Retention & Deletion
Google account credentials are retained only while the integration remains active. You may disconnect your Google account at any time, after which the associated credentials will be securely deleted. You may also request deletion of related data by contacting support@metadot.com.
Payment Processing
Payments are securely processed by Stripe, a PCI DSS-compliant payment processor. Payment information is handled by Stripe in accordance with its security and privacy standards.
When We Share Information
We do not sell or share your information for advertising or marketing purposes. We share information only to:
- provide the services you request
- support the operation of our products and services
- comply with legal obligations or protect the security of our products, services, customers, or others
Your Privacy Rights
Depending on your location and Applicable Data Protection Laws, you may have rights regarding the information we process about you, including the right to access, correct, delete, restrict, or receive a copy of your information.
If you use our products through an organization, such as your employer or school, you may need to submit your request through that organization. We will respond to requests in accordance with Applicable Data Protection Laws. Please contact us with any questions at support@metadot.com.
Data Processing Agreement
Our Data Processing Agreement (DPA) is available on request. To obtain a signed copy, please contact support@metadot.com.