News: Meetric raises SEK 21 million in a round led by Spintop Ventures. Read more!
This Data Processing Agreement, including the Appendices attached hereto ("the DPA") is hereby entered into by and between:
Each of the Data Controller and the Data Processor is referred to as a "Party" and together as the "Parties".
The following documents constitute the documented instruction together with Appendix 2.
Definitions used in this Appendix 1 shall have the same meaning as in the DPA unless the context clearly indicates otherwise.
This Appendix 1 sets out the details concerning the Included Personal Data and processing thereof pursuant to the DPA.
The purpose of this Appendix 1 is to clarify which processing and personal data that is covered by the DPA, and to fulfill the requirements of the Applicable Data Protection Legislation regarding the obligation to specify the categories of a processor's processing of personal data.
For communication and interaction with customers in digital salesrooms and meeting rooms in the tool Meetric. Personal data is saved for 12 months by default. This can be changed in settings.
Meetric will process Personal Data solely for the period during which the Services are provided under the Services Agreement, including any additional period agreed in writing or required by applicable law. Upon termination or expiration of the Services Agreement, personal data will be returned or, where technically feasible, securely deleted in accordance with Meetric's retention policies and legal obligations.
Meetric processes personal data as part of delivering its services. The specific categories of personal data include, but are not limited to:
The determination of which individuals' personal data is processed rests with The Customer and its authorized Users. Accordingly, Meetric processes personal data for the following categories of data subjects:
In alignment with the Services Agreement, Meetric undertakes the following detailed activities concerning the Included Personal Data, which may include, but is not limited to:
The following documents constitute the documented instruction together with Appendix 1.
Definitions used in this Appendix 1 shall have the same meaning as in the DPA unless the context clearly indicates otherwise.
At Meetric, safeguarding personal data is a top priority. Our security framework is designed to ensure compliance with the General Data Protection Regulation (GDPR) while maintaining the confidentiality, integrity, and availability of personal data processed in our EU-based cloud service. We achieve this through a layered approach that integrates robust technical controls with rigorous organizational policies.
Meetric has appointed a dedicated Data Protection Officer responsible for overseeing our data protection strategies, conducting regular compliance audits, and managing data subject requests. The DPO also serves as our primary liaison with regulatory authorities. For any data protection inquiries, please contact: dpo@meetric.com.
We maintain a robust security posture from the earliest stages of development by integrating a comprehensive suite of security tools directly into our CI/CD pipelines.
Our pipelines include:
By integrating these measures, we demonstrate a strong commitment to data protection and regulatory compliance. Our security practices are continuously reviewed and enhanced to stay ahead of emerging threats and ensure the ongoing safety of personal data entrusted to us.
Below is a list of the Sub-processors engaged for the processing of personal data under this DPA.
The list shall be amended and updated each time a new Sub-processor is engaged, or a Sub-processor is replaced throughout the term of this DPA.
The Customer (The Data Controller) has approved the use of the following Sub-processors:
# | Name of the Sub-processor | Registration number | Description of services and processing performed by the Sub-processor/Scope | Geographical location of the processing conducted by the Sub-processor |
---|---|---|---|---|
1. | Entire Nordic AB | 559261-2377 | Hosting services | Uppsala, Sweden |
2. | Scaleway | FR 35 433115904 | Hosting, Storage, Transactional Emails, Databases, Processing. European hosting and infrastructure provider. | Paris, France |
4. | Google Cloud EMEA Ltd. | Google Cloud EMEA Limited Company Number: 660412 Ireland | Cloud infrastructure, data storage, and AI processing services | Data is processed and stored exclusively within EU/EAA regions, in accordance with Google's DPA and data residency commitments. |