GDPR at Meeting Room 365.
We're committed to protecting the privacy and security of our users, and to meeting the requirements of the General Data Protection Regulation.
Make a data request.
You can request access to, correction of, or deletion of your personal data at any time. We respond to all data-subject requests within 30 days.
Data subject access requests
To exercise your right to know how your data is used, export it, or have it deleted, email our privacy lead and we'll take it from there, with no account portal hoops.
Who touches your data, and where.
We rely on a small set of trusted third parties to operate the service. Each is carefully evaluated for security and privacy practices.
| Partner | Region | Purpose |
|---|---|---|
| OVHcloud | EUUS | Primary cloud infrastructure |
| DigitalOcean | EU | Managed databases (AMS region) |
| Cloudflare | US | CDN, DDoS protection and Web Application Firewall |
| Stripe | US | Payment processing (PCI Level 1 Service Provider) |
| PostHog | EU | Product analytics (EU-hosted) |
| Crisp | EU | Customer support chat |
| Postmark | US | Transactional email delivery |
| Sentry | US | Error tracking and monitoring |
| Google Cloud | US | Authentication (Cloud Identity) and database (Firestore) |
| Bunny.net | EU | CDN and EU-based object storage |
| Backblaze B2 | US | Object storage (supplemental) |
What we've put in place.
GDPR compliance is ongoing work. Here's a summary of the measures already implemented.
Application security
- TLS/SSL deployed across all endpoints
- Personal data collection restricted to the minimum necessary
- Logs redacted to avoid writing unnecessary personal data
- Web Application Firewall enabled and blocking common attacks
- Access to backups restricted to authorized personnel
Privacy procedures
- Data Protection Lead nominated
- Process established for subject data requests
- Procedure for correcting inaccuracies in personal data
- Internal personal-data handling documented for staff & contractors
- Security reporting process published publicly
GDPR, answered.
If you have a concern that isn't covered here, reach out and we'll be happy to help.
The General Data Protection Regulation is privacy legislation enacted by the European Union. It governs how personal data (such as IP addresses, email addresses and names) and sensitive data is handled by organizations.
Our databases are hosted on DigitalOcean in the AMS (Amsterdam) region. Primary application infrastructure runs on OVHcloud across US and European datacenters. We do not process or store EU customer data outside the EU for database operations.
We're happy to discuss your specific data-processing requirements. Contact [email protected] to request a Data Processing Agreement or discuss your organization's needs.
Email [email protected] with details of any potential data breaches, vulnerabilities or concerns. We commit to acknowledging all reports within 48 hours.
Request access to, correction of, or deletion of your personal data at any time by emailing [email protected]. We respond to all data-subject requests within 30 days.