1. Overview
MeetIQ Ltd. ("MeetIQ", "we", "us") is a UK-based company operating the MeetIQ platform at getmeetiq.com and app.getmeetiq.com. Because we are UK-based, the UK GDPR is our baseline privacy law. We extend the same standards to every jurisdiction our customers operate in.
We will notify you of material changes to this policy by email (if we have your email) and by a prominent notice on getmeetiq.com. Older versions are archived and available on request.
We name our sub-processors publicly (see Section 7), disclose exactly what data goes to which AI provider (see Section 9), and default our ad-platform integrations to off until a workspace admin explicitly opts in.
2. About MeetIQ
MeetIQ is a marketing intelligence platform for B2B revenue teams. Our customers ("Customers"), meaning the companies that pay us to use MeetIQ, capture engagement signals about their own prospects and customers ("Client Data"), and use MeetIQ to score, prioritise, and act on those signals.
MeetIQ is currently in a private waitlist phase. Founding member access opens in a bounded cohort model. Public availability is planned but not yet dated.
3. What this policy covers
This policy applies to two distinct categories of information:
- Information about you as a website visitor, waitlist member, or Customer user. When you visit
getmeetiq.com, join the waitlist, or useapp.getmeetiq.comas a Customer's team member, MeetIQ acts as a data controller for information about you and processes it in accordance with this policy. - Client Data uploaded or captured by our Customers. When a Customer captures information about their own prospects (an anonymous website visitor to their site, a form submission, a call recording, a CRM record), MeetIQ acts as a data processor on the Customer's behalf. The Customer is the controller of that Client Data. Requests from prospects about Client Data should be directed to the Customer whose product they interacted with, not to MeetIQ.
4. Information we collect
4.1 Information you provide directly
- Waitlist / early access requests: your name, work email, company, role, and any free-text answers you provide.
- Account creation: once activated, your name, email, and account credentials (managed through a one-time passcode by default; no passwords stored).
- Support and feedback: anything you write to us in chat, on email, in support forms, or during a call with the founding team.
- Payment information: once billing is enabled, your card and billing address are handled by a PCI-compliant payment processor (see Section 7); we do not store card numbers on our infrastructure.
4.2 Information collected automatically
- Web analytics: IP address, browser, device, referrer, pages viewed, session duration on
getmeetiq.comandapp.getmeetiq.com. - MeetIQ tracking pixel: when installed by a Customer on their own website, the pixel records a first-party visitor identifier stored in
localStorage, pageviews, click IDs (gclid, fbclid, msclkid), and UTM parameters. This data belongs to the Customer as controller. MeetIQ processes it on their behalf. - Product usage: which pages of
app.getmeetiq.comyou use, features you interact with, and any errors reported by the app.
4.3 Information from third-party sources
We enrich contact records with data from public sources when a Customer requests it. For example, LinkedIn public profile fields or company registry data. We rely on third-party enrichment providers who represent that they collect this data lawfully.
4.4 Client Data
When our Customers use MeetIQ, they choose what information to capture about their prospects and customers. This is Client Data. Common categories include:
- Contact identifiers (name, email, LinkedIn URL, phone)
- Company data (company name, size, industry, domain)
- Engagement events (pageviews, form submissions, email opens, meeting attendance, sales-call transcripts, CRM stage changes)
- Warm-window scores and pattern-match scores calculated by MeetIQ
- Notes, tags, and lifecycle stages set by the Customer's team
MeetIQ processes Client Data only under instruction from the Customer. Individuals whose data is processed as Client Data should contact the Customer directly for access, deletion, or other rights. MeetIQ cannot honour those requests without the Customer's involvement.
5. How we use personal information
Under UK GDPR we must have a lawful basis for each processing purpose. Ours are:
| Purpose | Lawful basis |
|---|---|
| Providing the MeetIQ service to Customers and their teams | Contract performance |
| Managing the waitlist and communicating updates about MeetIQ | Legitimate interest (business development); consent for marketing emails |
| Securing our systems, detecting fraud and abuse | Legitimate interest (safety and security) |
| Providing customer support | Contract performance / legitimate interest |
| Complying with UK, EU, and other applicable law | Legal obligation |
| Improving MeetIQ (aggregated / de-identified usage patterns only) | Legitimate interest |
We do not use Customer or Client Data to train, fine-tune, or improve any AI or machine-learning model outside the specific Customer workspace it belongs to. See Section 9 for the specifics on how AI features work.
6. Who we share personal information with
We share personal information only with the categories of recipients below, and only where necessary.
- Sub-processors: vendors that operate infrastructure, AI, email sending, and analytics on our behalf. See Section 7 for the current list.
- Connected ad platforms: when a Customer explicitly connects Google Ads (and, in future releases, LinkedIn Ads, Meta Ads, or Microsoft Ads), we push conversion events and Customer Match audience lists on the Customer's behalf. Enhanced Conversions with hashed PII and Customer Match audience uploads are off by default and require explicit opt-in from a workspace admin. See Section 8.
- Legal recipients: if we receive a lawful demand from a court, regulator, or law enforcement authority, we may disclose personal information. Narrowly scoped to what is legally required.
- Business transfer: if MeetIQ is acquired or merges with another entity, personal information may transfer to the acquiring party. That party will be bound by terms at least as protective as this policy.
We do not sell personal information. We do not participate in ad-tech retargeting networks, and no personal data leaves MeetIQ for the purpose of third-party advertising beyond the ad-platform integrations you deliberately configure.
7. Sub-processors
We name every sub-processor that touches personal information. This list is updated when it changes; we will give Customers 30 days' notice before adding a new sub-processor.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, and application backend | US (EU region supported) |
| Lovable Cloud | Application hosting and edge compute | US |
| Anthropic | AI model provider (Claude) for outreach drafting and content analysis | US |
| OpenAI | AI model provider for call transcript analysis and enrichment tasks | US |
| Resend (via Lovable Emails) | Transactional email delivery from noreply@mail.getmeetiq.com | US |
| Tally | Waitlist form collection prior to app activation | EU (Belgium) |
| PostHog | Product analytics on app.getmeetiq.com | US / EU |
| Google (Google Analytics 4, Google Ads API, Google Tag) | Website analytics and conversion tracking on getmeetiq.com; ad-platform sync for Customers who explicitly connect Google Ads | US / EU |
Every sub-processor is bound by written terms requiring them to process personal information only under our instruction and to apply security measures at least as strong as our own. Where a sub-processor is US-based, we rely on the transfer mechanisms in Section 10.
8. Ad platform integrations
MeetIQ integrates with advertising platforms so Customers can push their downstream sales outcomes (Marketing Qualified Lead, Sales Qualified Lead, closed-won) back to platforms like Google Ads. This closes the loop between ad spend and real revenue.
Because these integrations involve sending contact data outside MeetIQ, we have built specific safeguards:
- Off by default. Enhanced Conversions (hashed PII) and Customer Match audience uploads are disabled on every new workspace. A workspace admin must explicitly enable them via an in-product consent modal that documents the data-sharing behaviour.
- Hashed identity only. Where PII is sent to an ad platform for identity matching, it is normalised (trimmed, lowercased, phone numbers to E.164) and SHA-256 hashed on our server before transmission. Raw PII never leaves MeetIQ to an ad platform.
- Contact-level opt-out. Any individual contact can be excluded from all ad-platform syncs via a per-contact toggle in the app. Excluded contacts are never uploaded to any connected ad platform, regardless of workspace defaults.
- Consent audit trail. Every time a workspace admin enables or disables an ad-platform sync feature, we log who did it, when, and against which platform. Customers can export this log at any time.
- Customer certification. Our Terms of Service require Customers to represent that they have obtained appropriate consent from their contacts to share contact data with connected ad platforms for measurement, targeting, and exclusion purposes.
MeetIQ never accesses a Customer's advertising account without an explicit OAuth grant from an authorised administrator of that account. OAuth refresh tokens are encrypted at rest and can be revoked at any time by disconnecting the integration in MeetIQ or by revoking the grant directly with the ad platform.
9. AI processing
MeetIQ uses AI models to draft outreach messages, analyse sales-call transcripts, extract signals from unstructured content, and score prospects against a Customer's closed-won pattern. These AI operations involve sending contact and engagement data to third-party AI providers (Anthropic and OpenAI. See Section 7).
Our commitments:
- No training on your data. We use commercial API endpoints where AI providers contractually commit not to train their models on the data we send. This applies to both Anthropic and OpenAI.
- Workspace isolation. Data from one Customer's workspace is never used to inform outputs for another Customer. Every AI request is scoped to a single workspace's own data.
- Minimal transmission. We send only the specific fields needed for each AI task. Fields that aren't relevant to a given operation are omitted from the request payload.
- Retention aligned with providers. AI provider retention windows are documented in their respective policies. Anthropic and OpenAI retain API request data for a bounded operational window and delete it thereafter.
- Customer opt-out. A workspace admin can disable specific AI features (call transcription, outreach drafting, or scoring) if they prefer not to send that category of data to an AI provider.
10. International data transfers
MeetIQ is UK-based. Some of our sub-processors are located in the United States (see Section 7). When we transfer personal information outside the UK or EEA, we rely on:
- Standard Contractual Clauses (2021 EU SCCs and the UK International Data Transfer Addendum), or
- Adequacy decisions where the recipient country has one, or
- The recipient's certification under the EU-U.S. Data Privacy Framework, UK Extension, or Swiss-U.S. DPF where applicable
MeetIQ itself is not currently certified under any Data Privacy Framework. We rely on Standard Contractual Clauses for transfers to US-based sub-processors and will pursue direct DPF certification when transfer volumes and customer requirements make it appropriate.
11. Your rights
Under UK GDPR and equivalent laws, you have the following rights over information we hold about you as a data controller:
- Access. Request a copy of the personal information we hold about you.
- Rectification. Ask us to correct inaccurate or incomplete information.
- Erasure. Ask us to delete your personal information (subject to certain legal exceptions).
- Restriction. Ask us to pause or limit our processing of your information.
- Portability. Receive your information in a structured, machine-readable format.
- Objection. Object to processing based on legitimate interests, including for direct marketing.
- Withdraw consent. Where processing is based on consent, withdraw it at any time.
- Complaint. Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
To exercise any of these rights, email privacy@getmeetiq.com. We will respond within one month, and may extend by up to two additional months for complex requests.
Californian residents
If you are a California resident, you have additional rights under the CCPA and CPRA. Including the right to know the categories of personal information collected, the right to delete, the right to correct, and the right to opt out of "sales" or "shares" of personal information. MeetIQ does not sell personal information as that term is defined under CCPA. To exercise your rights, contact privacy@getmeetiq.com.
Client Data requests
If your data appears in MeetIQ because one of our Customers captured it, the Customer is the data controller. We will forward your request to them and cooperate as required.
12. Data retention
We retain personal information only as long as necessary for the purposes described in this policy or as required by law.
- Waitlist records: retained until launch and up to 24 months after, after which unrevealed waitlist entries are deleted.
- Customer account data: retained for the life of the Customer's subscription plus 90 days after cancellation for data-export purposes. Deleted permanently after that unless a legal exception applies.
- Client Data: retained according to the Customer's own retention configuration and their agreement with MeetIQ. On termination we delete or return Client Data within 90 days.
- Billing records: retained for six years as required by UK tax law.
- Legal, audit, or dispute records: retained as long as needed for those purposes.
13. Security
We use industry-standard security measures. Because we are still an early-stage company, we describe what we actually do rather than list certifications we do not yet hold.
- Encryption in transit: all connections to
getmeetiq.comandapp.getmeetiq.comuse TLS 1.2 or above. - Encryption at rest: database and object storage encrypted at rest by our infrastructure providers. Sensitive tokens (OAuth refresh tokens for ad platforms) are encrypted at the application layer using an app-managed key.
- Access control: production data access is limited to the founding team on a need-to-know basis. All access is logged.
- Authentication: MeetIQ uses one-time passcode authentication by default. No passwords are stored on our systems.
- Sub-processor security: we only work with sub-processors that offer verified security controls appropriate to the data they process.
- Breach response: if a security incident affects personal information, we will notify affected Customers without undue delay and no later than 72 hours after we become aware, in line with GDPR obligations.
We are not currently SOC 2 or ISO 27001 certified. Both are on our roadmap for the year following commercial launch.
14. Cookies
MeetIQ uses cookies and equivalent storage on its own websites and inside app.getmeetiq.com. These fall into three groups:
- Strictly necessary: keep you signed in, remember your workspace, and secure session tokens. Cannot be disabled without breaking the product.
- Product analytics: PostHog cookies that help us understand how the app is used. Can be declined via the cookie banner.
- Website analytics: Google Analytics 4 (
gtag.js) ongetmeetiq.com, recording pages viewed, session duration, referrer, approximate location derived from IP, and clicks on our waitlist call to action. IP addresses are anonymised by Google before storage. Can be declined via the cookie banner. - Advertising measurement: Google Ads conversion tracking (
gtag.js) ongetmeetiq.comonly, for measuring the effectiveness of our own campaigns. Can be declined via the cookie banner.
The MeetIQ tracking pixel installed by our Customers on their own sites is a first-party cookie under the Customer's domain, not ours. The Customer's own privacy policy governs its use.
15. Children's data
MeetIQ is a B2B tool and is not intended for individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe we have collected such data, contact us and we will delete it.
16. Changes to this policy
We may update this policy from time to time. Material changes will be notified by email to registered users and by prominent notice on getmeetiq.com at least 30 days before taking effect. Non-material changes (grammar, formatting, updated sub-processor addresses) may be made without notice, but the "effective" date at the top of this page will always reflect the latest revision.
17. Contact us
For any question about this policy or your personal information:
- Email: privacy@getmeetiq.com (or mikes.njoku@gmail.com during the pre-launch period)
- Founder: Michael Njoku
- Registered address: available on request
If you are in the UK or EEA, you also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office at ico.org.uk.