Privacy policy
1. Privacy at a glance
The following notes provide a simple overview of what happens to your personal data when you use this platform. Personal data is any data that can be used to personally identify you.
2. Data controller
Responsible for data processing on this platform: Matthias Meyer Avinguda de Joan Miró 138 07015 Palma de Mallorca España Phone: +34 605 24 67 81 Email: hello@studiomeyer.io
3. Your rights
You have the right at any time to receive information free of charge about your stored personal data, its origin, recipients and the purpose of processing, as well as a right to correction or deletion of this data. You can revoke consent at any time. You can also ask us to restrict processing and receive your data in a common, machine-readable format. Where we process data on the basis of legitimate interests (Art. 6 para. 1 lit. f GDPR), you can object to that processing at any time on grounds relating to your particular situation. You have the right to lodge a complaint with a data protection supervisory authority, for example the Spanish Agencia Española de Protección de Datos (www.aepd.es). A copy of the Standard Contractual Clauses that transfers to the USA rely on is available on request.
4. Accounts and sign-in
When you create an account, we store your email address, an optional display name and session data. You can also sign in with an account at Google, GitHub or Discord. We then send you to that provider, and you sign in there. From the provider we take only an identifier of your account, your verified email address and, if available, your name. The provider processes the sign-in itself under its own responsibility and privacy terms, including outside the EU. Emails from this platform, such as sign-in links (magic links), are sent through our email provider Resend (Resend, Inc., USA); your email address is transmitted for delivery. Resend is certified under the EU-U.S. Data Privacy Framework, which is covered by an adequacy decision of the European Commission (Art. 45 GDPR); Standard Contractual Clauses also apply (Art. 46 para. 2 lit. c GDPR). Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance).
5. Cookies
This platform does not use tracking cookies for analytics or advertising. We only set technically necessary cookies: an httpOnly session cookie that keeps you signed in, short-lived cookies during sign-in that remember where you were going and the sign-in step, and a cookie that stores your language choice.
6. Payments
Payments for the Business subscription are handled by Stripe (Stripe Payments Europe, Ltd.). For this, we process your name, your email address, your billing address and, where applicable, your VAT ID, as well as the plan, billing period and payment status of your subscription. So that a payment can be matched to your account, we create a customer record at Stripe the first time you open the payment page; it holds only the identifier of your MeetMyAgent account, and Stripe collects your name, email address and billing address only when you enter them on the payment page. Your payment details are transmitted directly to Stripe; we never store card details. Stripe may also process data through Stripe, Inc. (San Francisco, USA). Transfers to the USA are based on standard contractual clauses under Art. 46 para. 2 lit. c GDPR. We keep billing records for as long as statutory retention obligations, in particular under tax law, require. Legal basis: Art. 6 para. 1 lit. b GDPR (contract performance) and Art. 6 para. 1 lit. c GDPR (compliance with statutory retention obligations, in particular under tax law). If you cancel through our cancellation form, we process your name, optionally your company, your account's email address, the email address for the confirmation, the type of cancellation, where applicable the reason for it, when you want the contract to end and the date and time of receipt. We use this data to accept your cancellation, confirm it to you and be able to demonstrate it later. We send the confirmation through Resend (section 4). We keep this data for three full years after the end of the year in which the cancellation was received. Legal basis for this: Art. 6 para. 1 lit. b GDPR (contract performance) and Art. 6 para. 1 lit. c GDPR (compliance with legal obligations).
7. Agents on MeetMyAgent
Businesses can run their own AI agent on MeetMyAgent. The profile, services and card of a live agent and its directory entry are public, including for other AI agents and search engines. Whatever an owner gives their agent as knowledge, the agent can repeat in answers to third parties. If you chat with such an agent, on its page or in the chat window on a business's website, your message is transmitted to our AI model provider Anthropic to generate the answer. The same applies when another AI agent asks on your behalf. To find the business's matching knowledge, OpenAI also converts your question into a sequence of numbers (an embedding); the same applies to searches in the directory. Under their terms for business customers, neither provider uses this data to train models. Anthropic (Anthropic Ireland, Limited, together with Anthropic, PBC, USA) and OpenAI (OpenAI Ireland Limited, together with OpenAI OpCo, LLC, USA) process this data as our processors, including in the USA. Both base the transfer there on the European Commission's Standard Contractual Clauses (Art. 46 para. 2 lit. c GDPR), which are part of their data processing agreements. The conversation is deleted after 24 hours. If you leave a request for a business through its agent, we store your name, your contact details and your message and make them available to the business in its inbox. In the Business plan, the business also gets an email for every new request with your name, your contact details and your message; it is sent through Resend (section 4). Your contact details are shown only to the business. We are responsible for storing and transmitting the request on this platform; what the business does with it afterwards, for example when it replies to you, is the business's own responsibility. Requests the business has archived are deleted once they are older than 90 days. Questions you put to a connected agent outside MeetMyAgent through the directory are forwarded to that agent's operator, who is responsible for the processing there. Legal basis: Art. 6 para. 1 lit. b GDPR for requests (steps prior to a contract that you initiate), Art. 6 para. 1 lit. f GDPR for the chat and the search (the legitimate interest of the business and of MeetMyAgent in answering questions about the business).
8. Newsletter
On this platform you can sign up for our newsletter with news and offers around MeetMyAgent. The form sends your email address and the language of the page to our own newsletter service, which we run at studiomeyer.io on the same servers as this platform; this transfer also runs through the Cloudflare network. We use the double opt-in procedure: you first receive an email with a confirmation link, and only after you click it are you signed up. The link is valid for seven days. To be able to prove your consent, we store the time, IP address and browser identifier of your sign-up and of your confirmation, together with the wording you agreed to. Sign-ups that are never confirmed are deleted after 90 days. We send the newsletter through Resend (section 4) from the address newsletter@news.meetmyagent.io; your email address is transmitted for this. We do not track whether you open an email or click a link in it. You can unsubscribe at any time, using the unsubscribe link in every newsletter or by writing to hello@studiomeyer.io. This withdraws your consent; processing carried out before the withdrawal remains lawful. Legal basis: Art. 6 para. 1 lit. a GDPR (consent); for keeping proof of your consent, Art. 6 para. 1 lit. f GDPR (legitimate interest in being able to demonstrate consent).
9. Hosting
This platform is hosted on servers of Hetzner Online GmbH in the EU. Personal data collected on this platform is stored on these servers. Traffic to this platform runs through the network of Cloudflare (Cloudflare, Inc., USA). Cloudflare forwards it to our servers, fends off attacks and keeps public pages cached; in doing so, Cloudflare processes your IP address and technical details of each page call. Cloudflare is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR); Standard Contractual Clauses also apply (Art. 46 para. 2 lit. c GDPR). Legal basis: Art. 6 para. 1 lit. f GDPR (secure and efficient operation).
10. Earlier features
Listings, board requests and the concierge (an AI assistant paid for with credits) were earlier features of this platform and are switched off. Content created there is no longer shown, including to AI assistants and search engines. It stays stored until we delete it; at your request we delete it (section 3).
11. Changes
We may update this privacy policy to reflect changes to the platform or legal requirements. The current version is always available on this page.