Metaenga Privacy Policy
Version: 0.2
Last updated: 28 July 2026
Effective date: On publication
This Privacy Policy explains how Metaenga, Inc. (“Metaenga”, “we”, “us” or “our”) handles Personal Data in connection with our websites, business communications, platform, browser training, native VR applications and related services that link to this Policy (the “Services”).
Metaenga, Inc. is a Delaware corporation with a registered address at 1111B South Governors Avenue, Dover, Delaware 19904, United States.
“Personal Data” means information relating to an identified or identifiable person. It includes pseudonymised learner or device information where that information can be linked to a person.
1. Scope and our role
Metaenga may act in different roles depending on the context.
Metaenga as Controller
Metaenga generally acts as Controller when it decides why and how to process information about:
- visitors to our public website;
- people who contact us, request a demo or engage with sales;
- direct customers and account owners;
- billing, procurement and supplier contacts;
- support contacts;
- people who subscribe to Metaenga communications;
- job applicants, where no separate applicant notice is provided.
Metaenga as Processor
When an organisation selects learners, assigns training and decides how results will be used, that organisation normally acts as Controller and Metaenga acts as Processor.
In that case:
- the organisation’s privacy notice and instructions govern the purpose of the learner processing;
- Metaenga processes Customer Personal Data under the customer agreement and DPA;
- a learner should normally direct a privacy request concerning the organisation’s training records to the organisation;
- Metaenga will assist the organisation as required by the DPA and applicable law.
A self-contained course hosted entirely by a customer may operate without Metaenga receiving learner identity or result data. A Metaenga-hosted or hybrid deployment may process the fields described below. The Order, DPA and customer-specific notice identify the model that applies.
2. Information we collect
We collect only the information reasonably needed for the applicable purpose and service configuration.
Website, sales and business-contact data
- name, work email, telephone number and organisation;
- job title, business role and country;
- enquiry, requested solution, meeting details and correspondence;
- procurement, supplier, contract and due-diligence information;
- marketing preferences and communication history;
- public professional information provided by you or your organisation.
Account and identity data
- name, business email and internal user ID;
- organisation, tenant, group, role and account status;
- authentication method, password hash, MFA status, reset tokens and active-session identifiers;
- identity-provider attributes where a customer enables Google, Microsoft or another approved sign-in method;
- optional profile fields such as job title, worker identifier, telephone number or location, where configured by the customer or user.
Metaenga does not need or intend to store a readable account password.
Training, assessment and reporting data
Depending on the module and customer configuration:
- course, module, scenario and content version;
- learner, session and attempt identifiers;
- start, end and completion timestamps;
- duration and time between configured actions;
- completion and pass/fail status;
- score, rating or assessment outcome;
- selected decisions, ordered actions, errors, retries and stage-level events;
- facilitator or customer validation status;
- reports, exports and dashboard records.
These records are Personal Data where they are linked or linkable to a learner.
VR, browser, device and technical data
- headset, browser, application and operating-system type/version;
- device or installation identifier;
- local session record and synchronisation status;
- IP address, login events, audit events and security alerts;
- crash, performance, diagnostic and support information;
- controller, head or hand interaction events required to operate a training scenario.
Metaenga does not use interaction or motion events for biometric identification unless a separate expressly agreed service, notice and lawful assessment says otherwise.
Some VR deployments store a session first in a local headset database and synchronise it to the Metaenga backend when connectivity is available. Other deployments may remain local or customer-hosted. The applicable customer notice and DPA describe the actual mode.
Customer Content
- training materials, procedures, images, videos, 3D assets, voiceover, documents and other content submitted by or for a customer;
- metadata and permissions associated with that content.
Customers should not include Personal Data or confidential information in free-text fields or content unless it is necessary and authorised.
Billing and transaction data
- billing contact, company name, billing address and tax information;
- plan, order, invoice, payment status and transaction identifiers;
- limited payment-method metadata returned by a payment provider.
Payment-card details are normally collected directly by the displayed payment provider. Metaenga should not receive a complete card number or card-security code from that provider.
Cookies and online usage data
- cookie and consent choices;
- browser, device, IP address, page and referring URL;
- page views, clicks, form interactions and public-site performance;
- analytics or campaign identifiers where you have provided the required choice.
Details are provided in the Cookie Policy.
Support and incident data
- support requests, correspondence and troubleshooting details;
- screenshots or files you choose to provide;
- security reports, investigation information and remediation records.
Please avoid sending learner records or secrets in support tickets unless necessary and approved.
3. How we collect information
We collect information:
- directly from you;
- from the customer or administrator that provisions your account;
- from your use of the Services and connected device;
- from an identity, payment, email, analytics or integration provider;
- from a customer-authorised LMS, xAPI endpoint or other business system;
- from public business sources where permitted by law.
4. Why we use Personal Data
Where EU, EEA or UK data-protection law applies, the table identifies the usual legal basis for Metaenga’s Controller processing. A customer determines the legal basis for Customer Personal Data that Metaenga processes as Processor.
| Purpose | Typical data | Usual Controller legal basis |
|---|
| Respond to an enquiry, demo or sales request | Contact, organisation, correspondence | Legitimate interests in responding to business enquiries; steps requested before a contract |
| Create and administer a direct account | Identity, account, role, authentication | Contract; legitimate interests in account administration and security |
| Deliver direct-account training and platform functionality | Account, training, device and Customer Content | Contract where Metaenga is Controller |
| Process enterprise learner training and results | Learner, session, completion, assessment and report data | Customer determines its Article 6 basis; Metaenga Processes under the DPA and documented instructions as Processor |
| Support local-first VR synchronisation | Session, device, synchronisation and technical data | Contract where Metaenga is Controller; otherwise Customer’s DPA instructions |
| Secure the Services and prevent abuse | Authentication, IP, logs, security events, reCAPTCHA signals | Legitimate interests in protecting users, systems and rights; legal obligation where applicable |
| Provide support and investigate incidents | Account, support, technical and incident data | Contract; legitimate interests; legal obligation where applicable |
| Process payments, invoices and tax | Billing, transaction and tax data | Contract; legal obligation |
| Improve reliability and usability | Technical, diagnostic and appropriately minimised usage data | Legitimate interests; consent where a non-essential device technology requires consent |
| Send requested or permitted marketing | Business contact and communication preferences | Consent where required; otherwise legitimate interests for proportionate B2B communications |
| Establish, exercise or defend legal claims | Relevant account, contract, communication and incident data | Legitimate interests; legal obligation |
| Corporate administration, diligence and compliance | Business, supplier, ownership and transaction data | Legal obligation; legitimate interests |
We do not rely on a general statement that use of the Services means consent to all processing. Where consent is the appropriate basis, we request a specific choice and allow withdrawal.
Account identifiers, authentication details and required billing information must be provided where they are necessary to create a direct account or complete a purchase. Without required information, Metaenga may be unable to create the account, authenticate the user, enter or perform the contract, or process payment. Optional profile fields are identified as optional in the interface or customer configuration.
5. Enterprise learner data
For Customer Personal Data processed on behalf of an organisation, Metaenga will:
- use the data only to deliver, secure, support and report on the agreed service;
- follow documented customer instructions;
- limit access to authorised personnel and approved providers;
- not sell the data;
- not create advertising profiles from learner records;
- not add enterprise learner email addresses to marketing campaigns merely because the person has a training account;
- not use the data to train or retrain a shared, general-purpose or third-party AI model without a separate written customer instruction, transparency assessment and lawful basis.
Metaenga may use information that has been irreversibly anonymised so that no person or customer can reasonably be identified. Pseudonymised data is not treated as anonymous where re-identification remains possible.
6. AI and automated decisions
The standard Metaenga training modules use pre-built content and configured assessment logic unless an Order expressly includes a different capability.
Metaenga does not make solely automated decisions about a person that produce legal or similarly significant effects through the standard Services.
If a customer orders an AI-enabled feature that processes Personal Data, the Order, DPA and applicable notice will identify:
- the purpose and data;
- the role of each party;
- whether a third-party model is used;
- safeguards, retention and human oversight;
- any applicable rights concerning automated decisions.
AI-assisted tools used internally to create static content do not receive Customer Personal Data unless separately approved.
7. When we disclose information
We may disclose Personal Data to:
- the customer or organisation that administers an enterprise account;
- authorised Metaenga personnel and contractors under confidentiality duties;
- hosting, infrastructure, backup and security providers;
- identity and authentication providers selected by Metaenga or the customer;
- transactional email, business communication and customer-support providers;
- payment and fraud-prevention providers, including the provider displayed at checkout;
- consent, analytics and website-technology providers, subject to applicable cookie choices;
- customer-authorised LMS, xAPI, reporting and integration endpoints;
- professional advisers, auditors, insurers and financial institutions;
- authorities or other parties where required by law or necessary to protect rights, safety or the Services;
- a buyer, investor or successor in a corporate transaction, subject to appropriate confidentiality and legal safeguards.
Depending on the feature and deployment actually enabled, provider categories may include OVHcloud for hosting, Google for reCAPTCHA and optional identity or analytics, Microsoft for customer-enabled identity, Hotjar for consented public-site analytics, Stripe or Fondy for configured payment flows, and an approved provider for transactional or business email. Not every provider is used for every service or customer.
A provider processes enterprise Customer Personal Data only where it is enabled for that customer and authorised under the applicable DPA. A current customer-specific subprocessor list is included in the DPA schedule or made available on request.
Metaenga does not disclose learner results to data brokers.
8. International transfers and data location
Metaenga, Inc. is established in the United States and operates internationally. Our providers and authorised personnel may be located in more than one country.
Where required, Metaenga uses an appropriate transfer mechanism, which may include:
- an adequacy decision;
- the European Commission’s 2021 Standard Contractual Clauses;
- the UK International Data Transfer Addendum or another valid UK mechanism;
- contractual and supplementary technical or organisational safeguards.
A customer may order a geographically restricted deployment. For example, an approved enterprise deployment may use OVHcloud infrastructure in Ireland for application data and agreed EEA locations for logs and backups, with production administrative access restricted to authorised personnel in EEA countries.
Data residency and international transfer are related but different. Hosting data in the EEA does not by itself determine whether a restricted transfer occurs. The applicable Order, DPA and transfer assessment control.
To request information about or, where available, a copy of the transfer safeguard applicable to Metaenga’s Controller Processing, contact privacy@metaenga.com. Commercially sensitive information may be redacted where the law permits.
9. Retention
We retain Personal Data only for the applicable purpose, customer instruction, legal requirement or documented legal hold.
| Category | Standard position |
|---|
| Direct account and tenant data | During the service relationship; disable on termination and delete according to the applicable account/customer schedule |
| Enterprise learner results and session events | The period agreed with the customer; if no schedule applies, service term plus the documented deletion period |
| Local VR session records | Until verified synchronisation and reconciliation, then cleared within the configured local period; unsynchronised records follow the customer closure procedure |
| Dashboard reports and exports | While required for the service or customer delivery; temporary export copies are removed after delivery or under the customer schedule |
| Authentication and application security logs | Normally up to 90 days, unless a shorter customer schedule or a documented security/legal need applies |
| Website enquiries and sales contacts | Normally 24 months after the last substantive interaction unless a relationship continues or earlier deletion is required |
| Marketing profile | Until opt-out or normally 24 months of inactivity; a minimal suppression record may be retained to respect the opt-out |
| Support records | Normally 24 months after closure; embedded learner data follows the shorter learner-data schedule |
| Contracts, invoices, tax and accounting records | Normally seven years after the relevant financial period, or another period required by applicable law |
| Applicant data | Normally 12 months after the hiring decision unless a different legal rule or valid consent applies |
| Privacy requests, deletion evidence and incident records | Normally three years after closure, minimised to what is needed for accountability or legal claims |
| Copyright notices, counter-notices and repeat-infringer records | For the period reasonably needed to administer the request, maintain accountability and establish, exercise or defend legal claims |
| Recovery backups | Isolated from ordinary use and expired through the documented backup cycle; the customer-specific schedule controls where Metaenga acts as Processor |
At termination, Customer Personal Data is returned or deleted as stated in the DPA and customer schedule. A backup copy that cannot be selectively edited remains isolated, is not used for ordinary processing and expires through the approved cycle. After a restore, applicable deletion records must be reapplied before production use.
10. Security
Metaenga uses technical and organisational measures intended to protect Personal Data against accidental or unlawful loss, alteration, disclosure or access.
Depending on the Service and risk, measures include:
- encrypted transport;
- protected credential storage;
- MFA for privileged access;
- role-based access and least privilege;
- environment and tenant controls;
- logging and incident handling;
- backup and recovery controls;
- change, patch and vulnerability management;
- personnel confidentiality and provider diligence;
- retention and deletion procedures.
No online system is completely secure. Provider certifications, including certificates published by OVHcloud, apply to the provider and certified service scope. Metaenga does not claim that those certificates certify Metaenga itself.
11. Your privacy rights
Depending on your location and the context, you may have the right to:
- access or confirm processing of your Personal Data;
- correct inaccurate Personal Data;
- request deletion;
- restrict or object to processing;
- receive portable data where applicable;
- withdraw consent without affecting earlier lawful processing;
- opt out of direct marketing;
- opt out of sale, sharing for cross-context behavioural advertising, targeted advertising or qualifying profiling where applicable;
- appeal a refusal of a request where applicable;
- not receive discriminatory treatment for exercising a privacy right;
- complain to a competent data-protection or consumer-privacy authority.
If your employer or another organisation controls your learner record, contact that organisation first. Metaenga will assist it under the DPA.
For Personal Data Metaenga controls, email privacy@metaenga.com. We may verify your identity and authority before acting. You may use an authorised agent where applicable. We will respond within the period required by the law that applies.
EEA and UK complaints
You may complain to the data-protection authority in the country where you live or work, or where you believe an infringement occurred.
United States state privacy disclosures
Where a U.S. state privacy law applies:
- the categories collected, purposes, sources and recipient categories are described in Sections 2–7;
- retention criteria are described in Section 9;
- Metaenga does not sell Personal Data for money;
- enterprise learner data is not used for targeted advertising;
- optional public-site analytics or advertising disclosures may constitute “sale”, “sharing” or targeted advertising under a particular law, depending on the provider and configuration;
- you can use Cookie Settings and any legally recognised opt-out preference signal to exercise the applicable choice;
- Metaenga does not knowingly sell or share Personal Data of people under 16 for cross-context behavioural advertising.
We do not offer a financial incentive for Personal Data unless a separate notice explains the material terms.
12. Do Not Track and opt-out preference signals
Because there is no single universal Do Not Track standard, Metaenga does not interpret every Do Not Track signal in the same way.
Where applicable law requires recognition of a browser-based opt-out preference signal, such as Global Privacy Control, Metaenga will treat the signal as the relevant opt-out request for that browser or device.
Cookie consent in the EEA and UK remains opt-in where required.
13. Children
The Services are designed for businesses, industrial organisations and authorised adult learners. Direct Metaenga accounts are intended only for adults.
An organisation must not provision a minor unless:
- the deployment is appropriate for that age group;
- the organisation and Metaenga have agreed the required safeguards;
- legally required notices and parental or guardian permissions are in place.
If we learn that Personal Data was collected from a child in a way that does not comply with applicable law, we will take appropriate steps to delete or otherwise address it.
14. Third-party services
The Services may link to or integrate with customer systems, headset stores, identity providers, payment services or other third parties. Those parties may act as independent Controllers under their own notices.
Metaenga is not responsible for a third party’s independent privacy practices. The customer agreement determines responsibility for customer-selected integrations.
15. Changes to this Policy
We may update this Policy when our Services, providers or legal obligations change.
We will post the new version and effective date. Where a material change affects an existing customer agreement or requires a new choice, we will provide additional notice or obtain agreement as required. A Privacy Policy is a transparency notice and not a substitute for contractual acceptance.
16. Contact
Metaenga, Inc.
Attention: Privacy
1111B South Governors Avenue
Dover, Delaware 19904
United States
Email: privacy@metaenga.com