Skip links

PRIVACY POLICY

1. Controller
The controller responsible for the processing of personal data on this website is:

heymeta GmbH Hofwiesenstraße 81 74081 Heilbronn Germany

Represented by its Managing Director: Korab Aliu

Email: info@heymeta.io

For privacy-related questions, requests, or the exercise of your data protection rights, please contact:
Email: legal@heymeta.io

2. Scope of This Privacy Policy
This Privacy Policy applies to the website heymeta.io, including its associated pages. It does not apply to websites, platforms, or services operated by third parties that may be accessed through external links on our website.

3. Hosting and Website Access
Our website is hosted by:

united-domains GmbH
Gautinger Straße 10
82319 Starnberg
Germany

The hosting servers used for our website are located in Germany. When you access our website, technical information is processed by the web server to deliver the website to your device and to maintain the security, stability, and functionality of the website.

The processed information may include:

• your IP address;
• the date and time of access;
• the requested domain, page, or file;
• the request method;
• the referring website, where transmitted by your browser;
• your browser type and version;
• your operating system;
• the amount of data transferred; and
• technical status and error information.

United Domains stores the server log data generated when the website is accessed for security purposes for 14 days. The legal basis for this processing is Article 6(1)(f) of the General Data Protection Regulation (“GDPR”).

Our legitimate interests are:

• providing a secure and functional website;
• delivering the website to visitors;
• identifying and resolving technical problems;
• preventing misuse and unauthorized access; and
• protecting our website and systems against attacks.

United Domains processes the relevant hosting data on our behalf as a service provider.

The server log data is deleted after the applicable retention period unless longer storage is required to investigate a specific security incident, comply with a legal obligation, or establish, exercise, or defend legal claims.

4. Cookies, Analytics, and Tracking
We do not use cookies on the publicly accessible pages of this website.

We also do not use:

• web analytics services;
• advertising or marketing trackers;
• tracking pixels;
• visitor profiling technologies;
• cross-site tracking technologies; or
• technologies intended to recognize visitors across different websites.

We do not analyze individual visitor behavior for advertising or marketing purposes.

If we introduce cookies, analytics tools, embedded third-party content, or other technologies that require consent in the future, we will obtain the required consent before activating those technologies and update this Privacy Policy accordingly.

5. Contacting Us by Email
You may contact us using the email addresses provided on this website.

When you contact us by email, we process the information you provide. Depending on the content of your message, this may include:

• your name;
• your email address;
• your company or organization;
• your professional position;
• your telephone number, if provided;
• the content of your message;
• documents and attachments; and
• any other information you voluntarily provide.

We process this information to:

• respond to your inquiry;
• communicate with you;
• understand and evaluate your request;
• provide requested information;
• prepare or conduct a business relationship; and
• take steps requested by you before entering into a contract.

Where your inquiry relates to a potential or existing contractual relationship, the legal basis is Article 6(1)(b) GDPR.

For other business-related or general inquiries, the legal basis is Article 6(1)(f) GDPR.

Our legitimate interests are responding to inquiries, maintaining business relationships, and operating and developing our business.

Where processing is necessary to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR.

Providing your information is generally voluntary. However, we may be unable to process or respond to your inquiry if you do not provide the information necessary to understand your request and contact you.

We retain general correspondence until the inquiry has been fully processed. Unless a business relationship results or a longer retention period is required, correspondence is generally deleted no later than 12 months after the last substantive communication.

Information may be retained for a longer period where:

• a contractual or business relationship exists;
• statutory retention obligations apply;
• continued storage has been agreed with you; or
• the information is required to establish, exercise, or defend legal claims.

Please note that standard email communication is generally not end-to-end encrypted. You should therefore avoid sending highly sensitive or confidential personal information by unencrypted email unless this is necessary and has been agreed with us.

6. Pitch Decks and Project Submissions
You may send us pitch decks, project descriptions, business plans, presentations, and other project-related materials by email.
Depending on the content of the submitted materials, we may process:

• names and contact details of founders, employees, team members, or other individuals;
• professional positions and responsibilities;
• professional experience and qualifications;
• information about a company, product, service, or project;
• information about customers, partners, advisers, or investors;
• financial or commercial project information; and
• other information included in the submitted documents.

We process this information to: • review and evaluate the submitted project;
• respond to the submission;
• communicate with the sender;
• assess a potential business relationship;
• evaluate potential advisory, development, partnership, or investment opportunities; and
• conduct any requested pre-contractual discussions.

Where the submission relates to a possible contract or requested service, the legal basis is Article 6(1)(b) GDPR.

In other cases, the legal basis is Article 6(1)(f) GDPR. Our legitimate interests are evaluating potential projects, partnerships, investments, and other business opportunities and developing our business.

Please provide only the personal information reasonably necessary for the evaluation of your project.

Please do not send special categories of personal data within the meaning of Article 9 GDPR unless this has been expressly agreed with us and there is a valid legal basis for the processing.

Special categories of personal data include information concerning:

• health;
• racial or ethnic origin;
• political opinions;
• religious or philosophical beliefs;
• trade-union membership;
• genetic or biometric characteristics; or
• a person’s sex life or sexual orientation.

If the submitted materials contain personal data relating to other individuals, you are responsible for ensuring that you are permitted to provide that information and that the affected individuals have been appropriately informed where required.

Submitted materials may be accessed by employees and other individuals within heymeta GmbH who require access to evaluate the submission.

Where necessary for the evaluation of a project, relevant information may also be disclosed to:

• legal, financial, or technical advisers;
• external specialists;
• potential development or technology partners;
• potential cooperation partners; or
• selected investment partners.

Information is shared only where the disclosure is necessary, legally permitted, and subject to appropriate confidentiality and data protection requirements.

We do not sell pitch decks, contact details, or project information. We do not disclose submitted information to third parties for their own advertising or direct marketing purposes.

If no business relationship results, we generally delete submitted pitch decks, project documents, and related correspondence no later than 12 months after the last substantive communication.

The information may be retained for a longer period where:

• discussions or evaluations remain ongoing;
• you have agreed to continued retention;
• a contractual relationship has resulted;
• statutory retention obligations apply; or
• continued storage is necessary to establish, exercise, or defend legal claims.

7. External Links and Social Media
Our website contains links to websites and profiles operated by third parties, including LinkedIn and Instagram.

These are ordinary external links. Content from these providers is not automatically loaded merely because you visit our website.

When you click an external link, you leave our website and access a website controlled by another provider.

The operator of the linked website may process information such as:

• your IP address;
• the date and time of access;
• browser and device information;
• the referring website; and
• information connected with an account you hold with that provider.

If you are logged into an account with the relevant provider, the provider may be able to associate your visit with that account.

The respective third-party provider is responsible for its own processing activities. Please review the privacy information provided by the operator of the external website.

We have no control over the purposes, scope, retention periods, or further use of personal data by third-party website operators.

8. Recipients of Personal Data
Within heymeta GmbH, personal data is accessible only to individuals who require the information to perform their work.

Where necessary and legally permitted, personal data may also be disclosed to or processed by:

• website hosting and IT service providers;
• email and communications service providers;
• technical maintenance and security providers;
• legal, tax, financial, and other professional advisers;
• technical specialists and selected project partners;
• public authorities, courts, or other government bodies where disclosure is legally required; and
• other recipients where the disclosure has been requested or authorized by you.

Service providers that process personal data on our behalf are contractually required to process the information only in accordance with our instructions and applicable data protection law.

We do not sell personal data.

9. International Data Transfers Our website hosting is provided on servers located in Germany. In connection with a specific business inquiry or project submission, personal data may be transferred to a recipient outside the European Economic Area if this is necessary for the requested evaluation, cooperation, or business relationship.

Where such a transfer takes place, we ensure that the requirements of Articles 44 through 49 GDPR are met. Depending on the recipient and destination country, the transfer may be based on:

• an adequacy decision issued by the European Commission;
• standard contractual clauses approved by the European Commission;
• additional contractual, technical, or organizational safeguards;
• your explicit consent, where legally permitted; or
• another transfer mechanism recognized under applicable data protection law.

You may contact us at legal@heymeta.io for additional information about the safeguards used for a specific transfer.

10. Retention of Personal Data
We retain personal data only for as long as necessary for the purposes for which it was collected.

The applicable retention period depends on the type of information and the purpose of the processing. In particular:

• server log data generated by United Domains is generally stored for 14 days;
• general inquiries are generally deleted no later than 12 months after the last substantive communication if no business relationship results;
• pitch decks and project submissions are generally deleted no later than 12 months after the last substantive communication if no business relationship results;
• data relating to an existing business or contractual relationship is retained for the duration of that relationship and any applicable statutory retention period; and
• information required to establish, exercise, or defend legal claims may be retained until the relevant claims are no longer enforceable.

After the applicable retention period has expired, the information is deleted or anonymized unless further processing is required or permitted by law.

11. Your Data Protection Rights
Subject to the applicable legal requirements, you have the following rights regarding your personal data:

Right of Access
Under Article 15 GDPR, you have the right to request confirmation as to whether we process personal data relating to you and to receive information about that processing.

Right to Rectification
Under Article 16 GDPR, you have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.

Right to Erasure
Under Article 17 GDPR, you have the right to request the deletion of your personal data where the applicable legal requirements are met.
Right to Restriction of Processing Under Article 18 GDPR, you have the right to request that the processing of your personal data be restricted where the applicable legal requirements are met.

Right to Data Portability
Under Article 20 GDPR, you have the right to receive personal data you have provided to us in a structured, commonly used, and machine-readable format where the applicable legal requirements are met. You may also have the right to request that the information be transmitted directly to another controller where technically feasible.

Right to Withdraw Consent
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Right to Object
Under Article 21 GDPR, you have the right to object, on grounds relating to your particular situation, to the processing of personal data based on Article 6(1)(f) GDPR.

If you object, we will no longer process the relevant personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms or unless the processing is necessary to establish, exercise, or defend legal claims.

Where personal data is processed for direct marketing purposes, you have the right to object to that processing at any time without providing a reason.

To exercise any of these rights, please contact: Email: legal@heymeta.io

We may request additional information where reasonably necessary to confirm your identity and protect personal data against unauthorized disclosure.

12. Right to Lodge a Complaint
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection law.

The supervisory authority responsible for our registered office is:

The State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35
70191 Stuttgart
Germany
Email: poststelle@lfdi.bwl.de

You may also contact the supervisory authority responsible for your habitual residence, your place of work, or the location of the alleged infringement.

The supervisory authority is an independent government authority. It is not a Data Protection Officer appointed by or employed by heymeta GmbH.

13. Automated Decision-Making
We do not use personal data collected through this website for decision-making based solely on automated processing, including profiling, that produces legal effects concerning an individual or similarly significantly affects an individual within the meaning of Article 22 GDPR.

14. Data Security
We use appropriate technical and organizational measures to protect personal data against accidental or unlawful loss, destruction, alteration, unauthorized disclosure, or unauthorized access.

Our website is transmitted using encrypted HTTPS connections. Please note that data transmission over the internet, including email communication, cannot be guaranteed to be completely secure.

15. Changes to This Privacy Policy
We may update this Privacy Policy if our website, processing activities, service providers, or applicable legal requirements change.


The version published on this website at the relevant time will apply.

Explore
Drag