Legal
Privacy Policy
1. Who we are
MetaCoach is a product of Immersion sp. z o.o., ul. Jana Ciszewskiego 15, 2nd floor, 02-777 Warsaw, Poland, KRS 0000518914, NIP 9512382050, REGON 147357722. MetaCoach and Immersion Labs are trading names of the same company.
For the data described in this policy, we are the data controller under Regulation (EU) 2016/679 (GDPR) and, for our UK users, the UK GDPR and the Data Protection Act 2018, except as stated in section 3. For our US users, we are a “business” under applicable US state privacy laws. You can reach us about anything in this policy at office@immersionlabs.us.
This policy covers metacoach.ai. Our other website, immersionlabs.us, has its own.
2. What this policy covers
It covers personal data we handle when you visit metacoach.ai, submit a form on it, subscribe to our newsletter, or meet us at an event and give us your details.
3. What it does not cover
If you use the MetaCoach platform because an organisation gave you access to it, that organisation is the data controller (or, for our US business customers, the “business”) for your training data, which includes simulation transcripts, performance results, and, transiently, your voice audio while it is being transcribed in real time. We do not retain, record or store that audio, and it is deleted automatically once transcription is complete.
We process that data as a processor under the GDPR/UK GDPR, or as a “service provider” or “processor” under applicable US state law, on that organisation’s instructions, under a data processing agreement, whether the platform was supplied by us directly or through a partner. Please send requests about that data to the organisation you use the platform through. Details are in our Trust Statement and the applicable data processing agreement. Our Trust Statement is available on request.
4. What we collect, why, and for how long
In this section, you will find a description of data categories that we collect and further process, divided into sections that reflect the method of collecting that data (as per headings) by us and the purposes that we process such data for.
4.1 Forms
Data: name, business email, phone number if you give it, company, and your message.
Purpose: to answer you, arrange a demo, or assess a partnership.
Legal basis: steps taken at your request before a contract (Art. 6(1)(b) GDPR/UK GDPR) and our legitimate interest in handling business enquiries (Art. 6(1)(f) GDPR/UK GDPR).
Filling in a form is voluntary. Name and business email are needed for us to reply; without them we cannot.
Retention: 24 months from our last contact. If you become a customer, for the duration of the relationship and then for the statutory limitation and accounting periods, which for accounting records is five years from the end of the financial year
4.2 Newsletter and marketing email
Data: email address, first name, and your company, role or interests if you give them. We record whether our emails were delivered, opened, and clicked.
Purpose: to send you news about MetaCoach and to follow up on interest you have shown.
Legal basis: your consent, given by ticking a separate optional box (Art. 6(1)(a) GDPR/UK GDPR), or, where we are following up on your inquiry or a conversation at an event, our legitimate interest in business development (Art. 6(1)(f) GDPR/UK GDPR). You can withdraw consent or object at any time using the unsubscribe link in every email or by writing to us. Please note that a completed contact form is not consent to marketing.
Tracking whether an email was opened or clicked uses similar technology to a cookie (e.g. a tracking pixel) and is covered by the same consent requirement as section 4.3; we do not use it for emails sent solely on a legitimate-interest basis unless you have separately consented to tracking.
Retention: until you unsubscribe or object. We then keep your address on a suppression list, so that you are not added again by mistake, for as long as we run the list.
4.3 Cookies and analytics
Purpose: to measure traffic and improve the site.
Legal basis: your consent, given through our cookie banner, for everything other than strictly necessary cookies (Art. 6(1)(a) GDPR). Strictly necessary cookies rely on our legitimate interest in a secure, working website (Art. 6(1)(f) GDPR).
We use Google Analytics 4 with Consent Mode v2, so nothing is set before you consent, and Consent Pro to collect and record your choice. You can change or withdraw it at any time at cookie settings. We use two categories of cookies, strictly necessary and analytics. We do not use advertising or personalisation cookies, and video on this site is served from the site itself, so no third party sets a cookie when it plays. The individual cookies are listed in section 13.
Retention: 14 months in Google Analytics, which is the maximum for our property type. Records of your cookie choice are kept for 12 months after that choice expires or is withdrawn.
4.4 Server logs
Data: IP address, timestamps, request details, user agent.
Purpose: Keeping the site available and secure. Specifically: diagnosing errors and outages; detecting and blocking automated traffic such as bots, scrapers and credential-stuffing attempts; filtering spam and fraudulent contact form submissions; mitigating denial-of-service attacks; and investigating security incidents. These logs are generated and processed by our hosting and CDN providers acting on our behalf. We do not use them to build profiles of individual visitors or for marketing.
Legal basis: our legitimate interest in the security of our systems (Art. 6(1)(f) GDPR/UK GDPR).
Retention: These logs are retained by our hosting and CDN providers in accordance with their own retention schedules; we do not control the retention period and do not have access to the raw logs. We do not retain copies of them ourselves.
4.5 Events
Data: the details on a badge you let us scan or a card you give us, and notes from our conversation. Purpose: to follow up.
Legal basis: our legitimate interest in business development (Art. 6(1)(f) GDPR/UK GDPR), and your consent where the event operator requires it for badge scanning.
Retention: 24 months, or under section 4.1 if the conversation becomes an active opportunity for business.
Retention: 24 months, or under section 4.1 if the conversation becomes an active opportunity.
4.6 Our social media profiles
We maintain profiles on LinkedIn, Instagram and X. When you interact with them, the platform operator processes your data under its own privacy policy and sets its own cookies, over which we have no control. Should you have any concerns or questions in this regard, please see the relevant platform’s privacy policy / statement.
For the aggregated audience statistics we receive about our LinkedIn and Instagram profiles, we are joint controllers with the platform operator (Art. 26 GDPR/UK GDPR). The essence of that arrangement, and the operator's own information about the processing, is set out here:
- Page Insights Joint Controller Addendum: https://legal.linkedin.com/pages-joint-controller-addendum
- Privacy Policy: https://www.linkedin.com/legal/privacy-policy
Meta (Instagram)
- Page Insights Controller Addendum: https://www.facebook.com/legal/terms/page_controller_addendum
- Information about Page Insights Data: https://www.facebook.com/legal/terms/information_about_page_insights_data
- Meta Privacy Policy: https://www.facebook.com/privacy/policy/
You can exercise your rights against the operator directly or against us. Our legal basis is our legitimate interest in maintaining a presence on these platforms (Art. 6(1)(f) GDPR).
5. Who we share it with
We do not sell you personal data to anyone. We share it with a limited number of entities, essentially: with service providers acting on our instructions, each under a data processing agreement and only for the purposes we set. These service providers are
- Webflow, Inc., 398 11th Street, Floor 2, San Francisco, CA 94103, United States — website and video hosting
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland — analytics
- Finsweet Inc., United States — cookie banner and consent records (Consent Pro)
We also share data with our accountants and lawyers where necessary and under a duty of confidentiality, and with public authorities where we are legally required to.
For our US users: in the preceding 12 months we have disclosed the categories of personal information listed in section 4 to the service providers listed above for the business purposes described in this policy. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy law.
6. Transfers outside the EEA
Our own infrastructure sits in the European Union. Some of the providers that we use are established in the United States. In order for them to be able to provide services to us that include the processing of personal data, we need to transfer such data For those transfers we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on Standard Contractual Clauses adopted by the European Commission. For transfers from the UK, we rely on the UK Extension to the EU-US Data Privacy Framework (the “UK-US Data Bridge”) where the provider is certified, and otherwise on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards that apply.
7. Security
We apply a very high standard of protection to your personal data. Immersion sp. z o.o. holds ISO/IEC 27001 and ISO/IEC 27701 certification at company level, therefore the security measures we take adhere to standards verified by external experts. Our security measures include encryption in transit and at rest, role-based access control, logging, staff training, and review of our sub-processors. However, please know that no system is completely secure, therefore if any security incidents happen, we report them in line with our legal duties under relevant privacy laws.
8. Your rights (EEA and UK users)
You have the following rights with regard to your personal data that we process: to access your data and get a copy, to have it corrected, to have it erased where Art. 17 GDPR/UK GDPR applies, to restrict processing, to receive it in a portable format where processing is based on consent or contract and is automated, to object to processing based on legitimate interest, to withdraw consent at any time (where the processing is based on your consent), and not to be subject to a decision based solely on automated processing that has legal effects for you.
Should you wish to use any of those rights or have any questions about your personal data, please contact us at to office@immersionlabs.us. We are bound to reply within one month, and may extend that by up to two further months for complex or multiple requests, telling you within the first month if we do. Please note that withdrawing consent does not affect the legality of processing carried out before such withdrawal.
You can also complain to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, or to the supervisory authority where you live. UK users can instead complain to the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, or at ico.org.uk. Complaining to a regulator does not stop you from bringing a claim in court.
9. If you are in the United States
Depending on your state of residence, you may have some or all of the following rights over the personal information we hold about you:
- to know or access the categories and specific pieces of personal information we have collected about you, and the sources, purposes and categories of third parties involved;
- to correct inaccurate personal information;
- to delete personal information we hold about you, subject to certain exceptions;
- to opt out of the sale or sharing of personal information, and of profiling that produces legal or similarly significant effects — we do not currently engage in either;
- to limit the use of sensitive personal information — we do not currently collect sensitive personal information as defined by these laws;
- to receive a copy of your personal information in a portable format; and
- to appeal if we decline to act on your request, using the contact details below.
We will not discriminate against you for exercising these rights. You, or an authorised agent acting on your behalf, can exercise these rights by writing to [privacy@yourdomain.com]. We may need to verify your identity before responding. We recognise the Global Privacy Control as a valid opt-out request where applicable (see section 4.3).
10. Automated decision-making
We do not make decisions about you on this website based solely on automated processing, including profiling, that produces legal effects for you or otherwise significantly affects you. The MetaCoach platform produces performance feedback and scores, which may involve processing; where you use the platform through an organisation, that organisation decides how those results are used and is the controller for them. See section 3.
11. Changes
We may update this policy in order to adjust to any changes of circumstances or laws. The version and date at the top of the policy tell you which version applies. If a change is significant, we will flag it on the website or, where we have your address, by email.
12. Contact
Immersion sp. z o.o., ul. Jana Ciszewskiego 15, 2nd floor, 02-777 Warsaw, Poland. office@immersionlabs.us
13. Cookies we use
