Privacy Policy
DynaMeet, Inc. (DynaMeet株式会社; the “Company,” “we”) provides the “DynaMeet Platform” (including Meeton ai; the “Service”). This Privacy Policy explains how we handle personal information for which we determine the purposes and means of processing — that is, where we act as a controller.
1. Our two roles: controller and processor
1.1 As a controller, we handle: information about our customers and their staff (account, billing and support data); information about people who contact us, subscribe to our newsletter, or visit our own website dynameet.ai; and information we use for our own marketing. This Policy governs that processing.
1.2 As a processor, we handle personal information collected from visitors to our customers’ websites through the Service (chat entries, form submissions, behavioural data, and the like) on behalf of and under the instructions of the customer. That processing is governed by our Data Processing Addendum (“DPA”) with the customer, not by this Policy. If you are a visitor to a website that uses the Service, the website operator’s privacy policy applies to that data; please direct requests to the website operator, and we will assist them in responding.
2. Language versions and precedence
This Policy is published in English and Japanese. The Japanese version is authoritative for customers who contract with us on our Japanese (order-form) channel; the English version is authoritative for customers who subscribe through our self-serve channel and for customers outside Japan.
3. Information we collect as a controller
- (1) Account and registration data — name, work email address, company name, country, language and similar details provided when registering for or administering the Service;
- (2) Billing data — plan, payment status, business tax identifiers, and billing contact details (card details are processed by our payment provider and are not stored by us);
- (3) Inquiries and support — information submitted through our contact forms, email, or support channels;
- (4) Newsletter and marketing data — email address and subscription preferences;
- (5) Our own website’s visitor data — dynameet.ai itself uses the Meeton widget and analytics tools, so we collect the same categories of data on our own site that the Service collects for customers: pages viewed, time on page, chat and form entries you choose to submit, IP address, device and browser information, cookie/session information, and company-level attributes (company name, industry, location, employee size) estimated from information such as IP addresses. See Section 12 for details.
4. Purposes of use
We use the information in Section 3 for the following purposes:
- (1) Providing, operating and billing the Service;
- (2) Responding to inquiries and providing support;
- (3) Sending service notices (renewal reminders, security and maintenance notices, changes to terms);
- (4) Sending marketing communications where permitted by law, with the ability to opt out at any time (Section 11);
- (5) Improving the Service and developing new features (including improving AI models using de-identified data only);
- (6) Maintaining security and preventing unauthorised use (including operating usage counters and abuse-detection telemetry);
- (7) Responding to conduct that violates our terms;
- (8) Complying with legal obligations;
- (9) Purposes incidental to the above.
5. Provision to third parties
We do not provide personal information to third parties without consent, except: where required or permitted by law; where necessary to protect a person’s life, body or property and consent is difficult to obtain; where especially necessary for public health or the sound development of children and consent is difficult to obtain; where necessary to cooperate with a government agency or its contractor performing statutory duties; or in connection with a merger or other business succession, within the scope of the original purposes of use. Disclosure to our sub-processors and service providers under Section 6 is entrustment, not third-party provision.
6. Sub-processors and service providers
6.1 We use the following categories of providers to operate the Service, under contracts that require appropriate safeguards:
- (1) Infrastructure — Amazon Web Services (hosting; Tokyo region) and Supabase (application infrastructure);
- (2) AI model provider — Google (Gemini API), used to generate AI responses. Chat and content passed to the provider is used to provide the Service, not for the provider’s own advertising;
- (3) Payment processing — our payment provider processes card details for self-serve billing;
- (4) IP-based company enrichment — for Japanese traffic, a Japanese geolocation provider estimates company-level attributes from IP addresses.
The current list of sub-processors that touch customer personal data, including their locations, is published at dynameet.ai/en/legal/sub-processors/ and is updated with advance notice as described there.
6.2 Customer-directed integrations (Google, Microsoft, Slack, Zoom, Salesforce, HubSpot and similar) exchange data with the Service only when a customer connects them and only at the customer’s direction; they are governed by Section 7 and by each provider’s own terms.
7. Data handling in OAuth integrations
7.1 General
To provide features, the Service may integrate (via OAuth and the like) with external services (such as Google, Microsoft, Slack, Zoom, Salesforce, and HubSpot). When integrating, we collect only the minimum information necessary to provide the relevant feature and handle it in accordance with each external service’s terms and this Section.
7.2 Limited Use of Google API user data
The use of information the Service receives from Google APIs, and any transfer of such information to other apps, will comply with the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google APIs (such as calendar information) is used solely to provide and improve the Service’s features, and is never used for ad delivery, marketing, or provision to any third party unrelated to the Service’s features.
7.3 Microsoft (Teams/Outlook)
Data obtained through the Microsoft Graph API is used solely for scheduling sales meetings, setting up meetings, and the notifications incidental thereto, and never for advertising or profiling purposes.
7.4 Slack
Workspace information, channel information, message data, and the like obtained through the integration are used solely for notifications and log creation within the Service, and are managed in accordance with Slack’s terms.
7.5 Zoom
Data obtained through the Zoom API (such as meeting information, user names, and email addresses) is used solely for scheduling sales meetings, issuing meeting URLs, and the notifications incidental thereto. We never access, obtain, or store users’ audio, video, chat content, or other communication content obtained through the Zoom API, nor use such data to train or improve our own AI models or those of third parties. The obtained data is handled in accordance with the Zoom Privacy Statement and is never used for ad delivery or user profiling. If a customer removes (uninstalls) the Service’s integration from the Zoom Marketplace, we will, notwithstanding Section 10, promptly delete or anonymize the OAuth access tokens already obtained and any Zoom-related data within 24 hours.
7.6 CRMs (Salesforce/HubSpot)
Data is sent to and received from external CRMs to synchronize data designated by the customer and make sales-opportunity management more efficient.
7.7 Restrictions on human access
We restrict employees from viewing user data obtained through external integrations, except for security reasons (such as investigating unauthorised use), legal obligations, or support responses with the customer’s consent.
8. Where data is stored; international transfers
8.1 Personal information and customer data obtained through the Service are stored in the Amazon Web Services Tokyo region (ap-northeast-1) in Japan. Details of our hosting and security posture are published on our Security page.
8.2 If you access the Service from outside Japan, your personal information is transferred to and stored in Japan. Japan’s data-protection framework has been recognised as providing adequate protection by the European Commission, and Japan participates in the Global CBPR system. For customers, the contractual commitments that govern the overseas processing of their visitor data — including sub-processor locations and transfer safeguards — are set out in the DPA and on the sub-processor page.
9. Security and breach response
9.1 We maintain an information security management system certified to ISO/IEC 27001 and ISO/IEC 27017 and take appropriate technical and organisational measures against loss, destruction, alteration and leakage of personal information. See Security for details.
9.2 If a data breach occurs or is likely to have occurred, we will: notify affected customers without undue delay in accordance with the notification commitment in the DPA; report to the Personal Information Protection Commission of Japan (preliminary report within 3–5 days of becoming aware, final report in principle within 30 days) where required by the APPI; and make any further notifications to regulators or individuals that applicable law requires. For large-scale cyberattacks we coordinate with JPCERT/CC and, where criminal conduct is suspected, with the police.
10. Retention and deletion
10.1 We retain personal information for as long as needed for the purposes in Section 4 and to meet legal obligations.
10.2 When a customer’s agreement ends, we delete or de-identify the identifiable personal data registered by the customer (such as names and email addresses) in principle within 90 days, subject to the data-export window described in the applicable terms.
10.3 Behavioural history, statistical information and metadata that have been processed so that no individual can be identified or re-identified may be retained after termination for service improvement and analytics.
11. Your rights and marketing opt-out
11.1 You may request access to, correction, addition, deletion, restriction of use, or (where applicable law provides) portability of your personal information held by us. After verifying your identity, we will respond without undue delay. If we refuse a request, we will give reasons.
11.2 Marketing opt-out. Every marketing email we send contains an unsubscribe link. You may also opt out of marketing at any time by contacting us (Section 15). Opting out does not affect service notices necessary for operating your account.
12. Cookies, analytics and our own use of the Meeton widget
12.1 Our website uses cookies and similar technologies for functionality and access analysis. You can disable cookies in your browser, though some features may stop working.
12.2 We use Google Analytics to analyse site traffic. Google Analytics uses cookies to collect traffic data.
12.3 dynameet.ai itself runs the Meeton widget — the same product we sell. Through it, information about your visit (pages viewed, time on page, chat and form entries you submit, IP address, device and browser information) is transmitted to and processed on our infrastructure, and company-level attributes (company name, industry, location, employee size) may be estimated from your IP address. We use this to respond to you, to operate our own sales and marketing, and to improve the Service.
13. AI model improvement
We may use data to improve AI models only after it has been de-identified and aggregated so that it cannot identify, and cannot reasonably be re-linked to, any individual or customer. Customers can opt out of the use of their data for AI model improvement via the settings screen within the Service.
14. Additional rights under your local law
Depending on where you are located, the law that applies to you may grant you additional rights in relation to your personal information or additional routes of complaint. Nothing in this Policy limits any right you have under a law that applies to you. To exercise such a right, contact us using the details in Section 15.
15. Contact
For privacy inquiries, requests under Section 11, or complaints, contact:
DynaMeet, Inc. — Privacy Office
Daikanyama Art Village 2C, 17-10 Sarugakucho, Shibuya-ku, Tokyo 150-0033, Japan
Email: info@dynameet.ai
16. Changes to this Policy
We may update this Policy from time to time. For material changes, we will give customers advance notice by email or within the Service before the change takes effect. The updated Policy applies from the stated effective date (or, for non-material changes, from posting on our website).
Established: October 3, 2024
Last updated: [set at publish]