Privacy Policy
orgameet is a meeting-first CRM. This policy explains what personal data we handle, why, where it is stored and what your rights are. We keep it short and specific to how the product actually works.
Last updated: 2026-09-24
1. Who is responsible
The service is provided by Pablo Cortés ([NIF pendiente]), [Dirección pendiente], Alicante, Spain, trading as orgameet. For anything related to personal data write to privacy@orgameet.com.
Two roles apply. For your account (email, workspace, billing, usage) we are the controller. For the content you put in your workspace (your contacts, meetings, notes, tasks, files) you are the controller and we act as your processor, under the Data Processing terms in our Terms of Service.
2. What we collect
- Account data: your email address (used to sign in with a magic link), the name you give your workspace and, optionally, your display name.
- Workspace content: everything you enter or import: contacts and their details, organizations, meetings, notes, tasks, projects, milestones, attachments (files and links) and inbox items.
- Connected accounts (optional): if you connect Google or Microsoft, we store encrypted access tokens and import what you choose: calendar events, contacts, and email headers only (sender, subject, date). We never read email bodies.
- Billing: when you subscribe, Stripe handles your payment details. We store only your Stripe customer and subscription identifiers, plan and status.
- Usage: a log of AI actions (which feature, when, token counts) to enforce plan limits, plus standard server logs (IP address, request path, time) kept for security and rate limiting.
- Public project pages: if you share a project publicly, the page shows its name, health, milestones, upcoming meetings and notes summaries to anyone with the link.
3. Why we use it and on what legal basis
- To provide the service (contract, art. 6.1.b GDPR): signing you in, storing your workspace, syncing connected accounts, sending the daily agenda and reminders you enable, billing.
- AI features (contract): when you click an AI action (Prep brief, Debrief, Summary, Ask AI, contact enrichment, inbox triage, reports) the relevant content is sent to our AI provider to generate the result. Nothing is sent unless you trigger an action.
- Security and abuse prevention (legitimate interest, art. 6.1.f): rate limiting, logs, fraud checks by Stripe.
- Legal obligations (art. 6.1.c): invoices and tax records.
- Product emails about your account or changes to these documents (contract). We do not send marketing emails without asking first.
We do not sell personal data, we do not run advertising, and we do not use your content to train AI models.
4. Where your data lives
Your database and authentication run on Supabase in the European Union. The application server and file attachments run on Hetzner in Germany. Some providers we rely on are outside the EU; each one and the safeguard used is listed on our Sub-processors page.
AI features use Anthropic (United States). Only the content required for the action you trigger is sent, under Anthropic's commercial API terms, which do not permit training on customer content. Transfers rely on the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses.
5. Google and Microsoft account data
Connecting an account is optional. We request the minimum scopes needed: calendar events (read and create), contacts (read) and email metadata (read). Tokens are encrypted at rest. You can disconnect at any time from Connections, which deletes the tokens; you can also revoke access from your Google or Microsoft account settings.
orgameet's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features you see in the app, is not used for advertising, and is not transferred to third parties except as needed to provide those features (see Sub-processors).
7. How long we keep it
- Your workspace stays as long as your account exists, including after a trial ends or a subscription is cancelled, so you can come back.
- When you ask us to delete your account, or delete it yourself once that option is available in Settings, we remove the workspace and its files within 30 days. Backup copies expire on a rolling basis after that.
- Invoices and billing records are kept for the period required by Spanish tax law.
- Server logs are kept for a short period (weeks) for security purposes.
8. Your rights
You can access, correct, export, restrict, object to or delete your personal data. Most of your data can be edited directly in the app. For an export of your workspace, account deletion or any other request, email privacy@orgameet.com from the address you sign in with; we answer within one month. You may also complain to your data protection authority (in Spain, the Agencia Española de Protección de Datos, aepd.es).
If a contact of yours asks us about data you stored about them, we will refer them to you as the controller and help you respond.
9. Security
Every workspace is isolated at the database level with row-level security, so one customer's queries can never reach another's rows. Connections are encrypted in transit (TLS); connected-account tokens are encrypted at rest; sign-in uses single-use email links rather than passwords. Access to production systems is limited to the operator.
10. Business use and minors
The service is intended for professional use by adults. We do not knowingly collect data from anyone under 16.
11. Changes
If we change this policy in a way that matters, we will tell you by email or in the app before it takes effect. The version date at the top always tells you which text applies.