Skip to content
MétisMesh
HomeHow We ThinkOur WorkBlogsAboutContact
PortalStart a conversation
  • Home01
  • How We Think02
  • Our Work03
  • Blogs04
  • About05
  • Contact06
PortalStart a conversation
MétisMesh
PrivacyTermsSecurity

Legal

Privacy Policy

Last updated June 15, 2026

MétisMesh (“MétisMesh”, “we”, “us”, or “our”) provides software and generative-AI (GenAI) consulting, advisory, and development services. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit our website, contact us, subscribe to communications, use our client portal, or engage us for services.

This Policy covers personal information about website visitors, prospective clients, client personnel, newsletter subscribers, and other individuals who interact with us. It does not govern our processing of client data within a paid engagement, which is governed by the applicable Master Services Agreement (“MSA”), Statement of Work (“SOW”), and/or Data Processing Agreement (“DPA”).

1. Information We Collect

Information you provide to us

  • Contact and inquiry details (name, email, phone, company, message) submitted through forms, email, or scheduling tools.
  • Newsletter and marketing subscription details.
  • Account and authentication data for our client portal (email and authentication identifiers managed via our identity provider).
  • Information exchanged during sales discussions, engagements, and support.

Information collected automatically

  • Usage and device data (IP address, browser type, pages viewed, referring URLs, timestamps) collected via server logs and analytics.
  • Cookies and similar technologies (see Cookies and Tracking below).

Information processed on behalf of clients

  • During an engagement we may process data, documents, prompts, and other content provided by or on behalf of a client (“Client Data”). We act as a processor/service provider for Client Data and process it only per the client’s instructions and the governing MSA/SOW/DPA.

2. How We Use Information

We use personal information to:

  • Respond to inquiries and provide requested information.
  • Deliver, maintain, and improve our services and website.
  • Administer client-portal access and authenticate users.
  • Send newsletters and service communications (with opt-out where required).
  • Maintain security, prevent fraud and abuse, and debug issues.
  • Comply with legal obligations and enforce our agreements.

3. Generative AI, Models, and Your Data

Because our work involves GenAI systems, we want to be explicit:

  • No training on confidential data without authorization. We do not use client confidential data or personal information to train, fine-tune, or improve foundation models, and we do not permit third-party model providers to use it for their own model training, unless explicitly authorized in writing.
  • Model providers and sub-processors. Delivering GenAI solutions may require routing inputs and outputs through third-party model and infrastructure providers (for example, cloud platforms and LLM providers such as AWS / Amazon Bedrock, Anthropic, and self-hosted runtimes such as Ollama). Where such providers process data, we seek configurations that disable provider training on submitted data and that meet the data-handling commitments in the governing agreement.
  • Prompts and outputs. Inputs (prompts) and generated outputs may be logged for debugging, quality, safety, and audit purposes consistent with the engagement and this Policy. We apply access controls and retention limits to such logs.
  • Probabilistic outputs. GenAI outputs are probabilistic and may be inaccurate; see our Terms of Service for the related disclaimers.

4. Cookies and Tracking

We use strictly necessary cookies to operate the website and may use analytics or preference cookies. Where required by law, we request consent before setting non-essential cookies. You can control cookies through your browser settings; disabling some cookies may affect site functionality.

5. Legal Bases for Processing (EEA/UK)

Where the EU/UK GDPR applies, we rely on one or more of: your consent; performance of a contract; our legitimate interests (e.g., operating and securing our business and website); and compliance with legal obligations. You may withdraw consent at any time without affecting prior processing.

6. How We Share Information

We do not sell personal information. We share it only:

  • With service providers / sub-processors (e.g., hosting, email delivery, analytics, CRM, identity, and model/infrastructure providers) bound by contractual confidentiality and data-protection obligations.
  • For legal reasons (to comply with law, regulation, legal process, or governmental request, or to protect rights, safety, and security).
  • In a business transfer (merger, acquisition, or asset sale), subject to this Policy.
  • With your consent or at your direction.

7. International Data Transfers

We may process and store information in countries other than your own. Where we transfer personal data internationally, we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognized under applicable law.

8. Data Retention

We retain personal information only as long as necessary for the purposes described here, to comply with legal, accounting, or reporting obligations, and to resolve disputes. Client Data is retained and deleted in accordance with the governing MSA/SOW/DPA. Typical retention periods are documented internally [CONFIRM RETENTION SCHEDULE WITH COUNSEL].

9. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information. See our Security Policy for details. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your Rights and Choices

Depending on your location, you may have rights to:

  • Access, correct, update, or delete your personal information.
  • Port your data or restrict / object to certain processing.
  • Withdraw consent and opt out of marketing communications.
  • For California residents (CCPA/CPRA): rights to know, delete, correct, and opt out of “sale”/“sharing” of personal information, and the right to non-discrimination for exercising these rights. We do not sell or share personal information as those terms are defined under California law.

To exercise rights, contact us using the details below. We will verify your request and respond within the timeframe required by applicable law. You may also have the right to lodge a complaint with a supervisory authority.

11. Children’s Privacy

Our website and services are not directed to children, and we do not knowingly collect personal information from individuals under [16]. If you believe a child has provided us personal information, please contact us so we can delete it.

12. Third-Party Links and Services

Our website and content may link to third-party sites and services that we do not control. Their privacy practices are governed by their own policies.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date and, where required, provide additional notice.

14. Contact Us

Questions or requests regarding this Policy or your personal information:

  • Email: privacy@metismesh.com
  • Mail: MétisMesh, [LEGAL ENTITY NAME], [ADDRESS], Reston, VA, [USA]
  • For EEA/UK matters: [DESIGNATE CONTACT / REPRESENTATIVE / DPO IF REQUIRED].
MétisMesh

Noise into data. Data into knowledge you can trust.

A commitment to excellence, applied to the systems your business depends on.

Navigate

  • Home
  • How We Think
  • Our Work
  • Blogs
  • About
  • Contact

Reach us

  • contact@metismesh.com
  • +1 703 656 6394
  • Vienna, Virginia
  • Team sign-in

© 2025–2026 MétisMesh. All rights reserved.

PrivacyTermsSecurityRSSbuild 0d4b305