Privacy Policy
Effective Date: 2026-07-08
Introduction
Metavoli ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website or use our platform and tell you about your privacy rights.
Data We Collect
As a public visitor, we collect minimal data from you. We may collect, use, store, and transfer the following kinds of personal data:
- Identity & Contact Data: Includes first name, last name, email address, and phone number only if you voluntarily provide them when contacting us.
- Technical Data: Includes internet protocol (IP) address, browser type and version, time zone setting, and operating system used to access this website.
Note: We do not collect professional profile data (employment history, skills, etc.) from public visitors.
Cookies
We do not use cookies for general public visitors. Strictly necessary cookies are only used for authorized administrators to maintain their secure session.
Traffic Analytics
We measure aggregate site traffic in a privacy-preserving way, recording page views to understand which content is useful.
- No cookies and no cross-site tracking are used.
- No IP addresses are stored in our analytics.
- Timestamps are rounded to the hour, so a visit cannot be tied to a precise moment.
- The data is aggregate — we build no profiles of individual visitors.
How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- To respond to your inquiries sent through our contact forms.
- To send you contact form confirmation emails.
- To administer and protect our business and this website (including troubleshooting, data analysis, system maintenance, and security).
- To maintain security logs that help us detect and prevent unauthorized access or abuse of our services.
Email Processing
We use Postmark, a third-party email service provider, to send transactional emails such as contact form confirmations. When we send you an email, your email address and the email content are processed by Postmark.
Postmark processes this data in accordance with their privacy policy, available at postmarkapp.com/privacy-policy. We do not use email services for marketing purposes.
Hosting and Data Processors
Our platform is hosted in the European Union (Hetzner, Helsinki, Finland). We rely on the following data processors:
- Hetzner Online: server and database infrastructure, hosted in the EU.
- Hetzner Object Storage (Helsinki): storage for files uploaded by members (such as profile images and documents), kept in the EU.
- Postmark: sending contact form confirmation emails (as described above).
- Keycloak: our self-hosted identity provider, running on our EU infrastructure (see Data Security).
Transactional Emails
We may send you the following types of transactional emails:
- Contact form confirmations: Sent to confirm receipt of your inquiry through our contact form.
These emails are purely functional and are not marketing communications. You cannot unsubscribe from transactional emails as they are necessary for the services you have requested.
Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know.
Specific security measures include:
- Encryption of data in transit (TLS 1.3).
- Authentication and passwords are managed by our self-hosted identity provider, Keycloak, which stores passwords hashed with Argon2id (a memory-hard algorithm) and never in plaintext. A strong password policy is enforced (minimum 12 characters with mixed case, a digit and a special character, and no reuse of recent passwords).
- Session tokens are cryptographically signed and bound to your device (DPoP); server-to-identity-provider calls use mutual TLS.
- Strict access controls and regular security assessments.
Security Logging
We maintain security logs to protect our platform and users. These logs record security-relevant events such as login attempts and password changes. To protect your privacy, we use anonymization techniques:
- Email addresses and other identifiers are hashed (one-way encrypted) before being stored in logs.
- Logs cannot be used to identify specific individuals without additional information that we keep separately.
- Logs are automatically deleted after 90 days.
Threat Intelligence
To protect our platform from automated attacks and known malicious actors, we use CrowdSec, a collaborative security system. This involves:
- Attack detection: Our systems analyze access patterns to detect suspicious activity such as brute-force attacks, vulnerability scanning, and other malicious behavior.
- Community threat sharing: When an attack is detected, only the attacker's IP address and the type of attack (e.g., "brute-force login attempt") are shared with the CrowdSec community. No request content, user data, or personal information is ever shared.
- Blocklist protection: We receive community-contributed blocklists of known malicious IP addresses, allowing us to proactively block threats before they reach our application.
This threat intelligence sharing is essential for protecting our platform and users. For more information about CrowdSec's privacy practices, visit crowdsec.net/privacy.
Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Contact form submissions: Retained for up to 2 years to allow for follow-up communication and service improvement analysis.
- Member uploads: Files uploaded by members (profile images, documents) are retained while the associated account is active.
- Security logs: Retained for up to 90 days for security monitoring and incident response.
Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data, including the right to request access, correction, erasure, restriction, transfer, to object to processing, to portability of data, and (where the lawful ground of processing is consent) to withdraw consent.
Contact Us
If you have any questions about this privacy policy or our privacy practices, please contact us at admin@metavoli.no.