Privacy Policy
Privacy Policy
A plain-language summary of how METRA GET processes data, written so prospective customers know what to expect before a signed agreement is in place.
Status: Draft — pending qualified legal review. This page is not a final Privacy Policy and does not itself satisfy data-protection obligations in every jurisdiction our customers operate in.
What we process
- Account, organization, beneficiary, field-collection, communication and billing data — only what your organization enters to use the service.
- Newsletter subscriber email addresses, and the page a subscription came from (footer, contact form or trial signup).
- We do not sell any of this data to third parties.
How access is limited
- Access is scoped by organization, role, project and assigned permissions inside the platform.
- Contact and campaign data must be collected by your organization with a lawful basis and appropriate consent before it reaches us.
- Payment credentials are held by the payment provider directly; we store only transaction references and status.
Retention and your rights
- Data is retained only as required for the service, audit, contractual and legal obligations.
- Your organization may request access, correction, export or deletion of its data, subject to applicable law and retention duties.
- A newsletter subscriber can unsubscribe at any time by contacting us; we record the unsubscribe rather than deleting the history of the request.
Where responsibility sits
We are responsible for the technical security of data while it is on our systems and for processing it only as your organization instructs, through the platform. Your organization remains responsible for the lawfulness of the data it collects in the first place — including beneficiary consent — and for its own obligations as a data controller under the law that applies to it.
We do not currently hold ISO, SOC or equivalent third-party security certification, and nothing on this site constitutes GDPR or other regulatory compliance certification — an organization with certification or regulatory requirements of its own should confirm those separately before relying on the platform. A published register of subprocessors is not yet available; organizations that need one as part of a Data Processing Agreement should request it through Contact.