Skip to content

Exclusive 50% off for 36 months for the first 100 Professional accounts, until 31 December 2026. See the programme →

Privacy policy

This policy explains what data we process, why, and how to exercise your rights. Our servers are located within the European Union and we comply with GDPR. Last updated: September 2026.

1. Data controller

The data controller is VENTUS, a French simplified joint-stock company (société par actions simplifiée) with capital of €60,000, registered with the Rouen Trade and Companies Register (RCS Rouen) under number 917 982 969, with its registered office at 14 chemin des Tilleuls, 76130 Mont-Saint-Aignan, France, publisher of the Metaventus platform. For any question regarding your data: dpo@metaventus.com.

2. Our two roles

Data controller for site data, form submissions, account management, billing and platform security — this is the subject of this policy. Data processor for the data our customers import and manage in their CRM (their own contacts, prospects and customers): the customer remains the data controller, and this processing is governed by our Data Processing Agreement (DPA), accepted alongside the Terms of Service.

3. Data we collect

Identification data: first name, last name, email, phone, company (forms, account creation). Account and billing data: subscription, invoices, payment history — card data is processed by our payment provider and never passes through our servers. Usage data: pages viewed, interactions, technical logs (browser, device, IP addresses). Customer data (CRM): the data you enter into the application, processed on your behalf in our capacity as data processor.

4. Purposes and legal bases

Responding to your contact and demo requests — pre-contractual steps and legitimate interest. Providing, securing and improving the service — performance of the contract. Billing and accounting obligations — legal obligation. AI assistance features, triggered at your request — performance of the contract. Newsletter and marketing communications — consent, withdrawable at any time.

5. Retention periods

Account data is kept for the duration of the contract, then archived in accordance with legal obligations. Prospecting data is kept for a maximum of 3 years after the last contact. Technical logs are kept for short periods proportionate to the security of the service.

6. Recipients and subprocessors

Data is accessible to authorized VENTUS teams and to our technical subprocessors (hosting, email and SMS sending, payment, AI), selected for their guarantees and bound by compliance commitments. Our subprocessor register is kept up to date and available on request.

7. Your rights

You have the right to access, rectify, erase, restrict, object to and port your data. Exercise these rights by writing to dpo@metaventus.com; we respond within the statutory deadlines. You may also lodge a complaint with the CNIL (cnil.fr).

8. Connected third-party accounts: Google and Microsoft

Metaventus lets you connect a Google or Microsoft account in order to synchronise a calendar and, if you wish, a mailbox. This connection is optional, you initiate it yourself, and you can withdraw it at any time. Calendar — we read your availability and the events in the period being viewed, so that a slot which is already taken cannot be booked with you. We create, move and delete in your calendar only those appointments booked through Metaventus. We keep no calendar content: no title, no description, no attendee list. We store only the technical identifiers needed to find an appointment we ourselves wrote there, together with the address of the person who booked it. Mailbox — if you add your mailbox as a communication channel, we read incoming messages so that you can read and reply to them from Metaventus, and we send on your behalf the replies you write, or that you approve when they are suggested by the conversational agent. These messages are kept in your workspace for the duration of the contract, then purged according to the retention periods set in your administration centre (Compliance & retention), which your account administrator can adjust. Email signature — if you ask for it from Metaventus, we write your email signature into the sending settings of your Gmail mailbox. We neither read nor change any other setting of your mailbox. We also keep the access tokens issued by the provider, solely in order to maintain the connection you have authorised. Protection of this data — exchanges with Google and Microsoft, and between your browser and Metaventus, are encrypted in transit (TLS 1.2 or higher). Data and access tokens are kept in databases and storage encrypted at rest by our hosting providers, in data centres located in the European Union. Tokens are never sent to your browser or to any third party: only our servers use them, for the calls you have authorised. Access to this data is restricted to authorised VENTUS staff, limited to what is strictly necessary, and logged. Technical secrets are kept out of the code, in configuration isolated per environment. Data is deleted when the connection is revoked or the account is closed, and any data breach would be notified to you and to the supervisory authority within the time limits set by the GDPR. This data is neither sold, nor rented, nor used for advertising purposes, nor used to train artificial intelligence models. It is hosted on our infrastructure, located in the European Union, and is not shared with any third party other than the technical subprocessors strictly necessary for that hosting, mentioned in article 6. Metaventus's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You can revoke this access at any time from Metaventus, or from the provider's security settings: myaccount.google.com/permissions for Google, myapplications.microsoft.com for Microsoft. Revocation immediately stops synchronisation and the corresponding tokens are deleted.

9. Artificial intelligence

The platform's AI features are triggered on request and governed by our AI Charter: agent transparency, human control, and no use of your data to train models. These features rely on third-party providers accessed through professional programming interfaces: OpenAI, whose API does not train its models on the data submitted; Mistral AI, on a paid plan with the training option disabled; and Microsoft Azure AI Vision, for text recognition in documents, operated in France, whose data is deleted within 24 hours. Where several model providers are offered, your account administrator chooses which one is used. We use no multi-model gateway and run no self-hosted model. Data obtained from the Google APIs is never passed on to an artificial intelligence provider: the daily summary of your activity is compiled solely from appointments booked through Metaventus, never from the content of your connected calendar. Messages from a connected mailbox (article 8) are submitted to these providers only in order to suggest a reply to you, which you remain free to edit or discard. The list of these sub-processors, their location and the applicable safeguards appear in annex 3 of our data processing agreement.

The full contractual documents — terms of service, terms of use, data processing agreement and artificial intelligence usage policy — are published on the Contracts and GDPR page, together with their version, their effective date and their verification fingerprint.