FaceMeet policies

Data Processing Addendum

Last updated: October 2026

This Data Processing Addendum ("DPA") forms part of the Role Agent Terms between FaceMeet and the company using the Role Agent ("Customer"). It applies to personal data FaceMeet processes for the Customer through the Role Agent.

1. Roles

The Customer decides why and how its personal data is processed and is the controller. FaceMeet processes that data on the Customer's behalf and is the processor.

2. What FaceMeet processes

  • Who: the Customer's administrators, managers and employees who use a Role Agent, and people named in role documents or conversations.
  • What: names, work email addresses, role assignments, conversations with the Role Agent, documents shared with it, approved role knowledge, and records of actions taken in connected apps.
  • Why: only to provide, secure and support the Role Agent for the Customer.
  • How long: as set out on the Data Retention page.

3. FaceMeet's commitments

  • Process Customer personal data only on the Customer's documented instructions, which are the Role Agent Terms, this DPA and the Customer's use of the Role Agent's settings.
  • Not sell Customer personal data and not use it to train AI models.
  • Make sure everyone at FaceMeet who can access it is bound by confidentiality.
  • Keep each Customer's data separate from every other Customer's.
  • Help the Customer answer requests from people exercising their privacy rights, and with any required impact assessment.
  • Delete or return Customer personal data when the Customer's account closes, as described in the Role Agent Terms.

4. Security

  • Data is encrypted in transit and at rest.
  • Role Agent data is reachable only through FaceMeet's servers, which check the person's company membership and open role assignment on every request.
  • Access by FaceMeet staff is limited to support and security needs and is logged.
  • Every change to who can see what, and every action taken in a connected app, is recorded in an audit log.
  • Credentials for connected apps are held by the connection provider, not in FaceMeet's database.

5. Subprocessors

The Customer authorizes FaceMeet to use the subprocessors listed on the Subprocessors page. FaceMeet binds each to data protection terms at least as protective as this DPA and remains responsible for them. FaceMeet will give company owners at least 30 days' notice before adding or replacing a subprocessor; a Customer that objects on reasonable data protection grounds may end the affected service and receive a refund of prepaid fees for it.

6. Security incidents

FaceMeet will notify the Customer without undue delay, and in any case within 72 hours of becoming aware, of a breach affecting the Customer's personal data, with the information the Customer needs to meet its own obligations.

7. Where data is processed

FaceMeet processes data in the United States. Where the law of the Customer's country requires a transfer mechanism, such as the European Commission's Standard Contractual Clauses or the UK addendum to them, those clauses apply and are incorporated by reference.

8. Audits

Once a year, or after a security incident, the Customer may ask for written information showing FaceMeet's compliance with this DPA. FaceMeet will answer reasonable questions in writing.

9. Contact

Privacy and data protection questions: hello@facemeet.app.

Related: Role Agent Terms, Data Processing Addendum, Subprocessors, Employee Notice, Data Retention and the full list of policies.