Metadiv TechnologyMetadiv Technology

Privacy Policy

Last Updated: August 4, 2026

This Privacy Policy ("Policy") describes how Metadiv Technology Limited ("Company", "we", "us", or "our") collects, uses, and handles information in connection with the B-Suite platform and related services accessible at bsuite.metadiv.io (collectively, the "Service"). By accessing or using the Service, you ("User", "you", or "your") acknowledge that you have read and understood this Policy.

The Service is an integrated business software platform that may include modules such as OperAgent, MCP Center, CRM, HR, Accounting, Inventory, Vendors, Omnichannel messaging, Team Chat, Meeting Center, Calendar, Cloud Drive, Office documents, EDM email marketing, TCG merchant tools, wallet/billing, and related features. Not all modules are available in every workspace.

THIS SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. WE MAKE NO REPRESENTATIONS OR WARRANTIES REGARDING THE SECURITY OR PRIVACY OF YOUR DATA BEYOND WHAT IS EXPRESSLY STATED IN THIS POLICY.


1. Information We Collect

1.1 Account Information

Account registration and authentication for the Service are provided through Metadiv Portal (portal.metadiv.io), a related Metadiv service. When you create or access an account, we (and Metadiv Portal on our behalf) may collect:

  • Email address
  • Authentication credentials (password hashes where applicable, email one-time verification codes, session tokens)
  • Workspace membership and role information

Account registration fields are limited. We do not require your name, phone number, or physical address solely to create an account. However, you and other workspace users may voluntarily store names, phone numbers, addresses, and other personal data inside the Service as business or customer content (see Sections 1.3 and 1.4).

1.2 Usage and Technical Data

We automatically collect limited technical data when you use the Service:

  • IP address (including for authentication and security)
  • User agent string (browser/device type)
  • Usage and billing metrics (for example AI token counts, MCP tool usage, storage usage, and associated wallet costs)
  • Presence or online status indicators within collaboration features (where enabled)
  • Web Push subscription endpoints and keys, if you enable browser push notifications

1.3 User-Generated and Workspace Content

The Service allows you and your workspace members to create, upload, and store content, including but not limited to:

  • Team chat messages, attachments, and conversation history
  • OperAgent chat messages, uploads, agent configurations, skills, memory, and schedules
  • MCP Center configurations, tool usage inputs/outputs, and user-provided API keys
  • Cloud Drive files and folders, including content shared via public or member links
  • Office documents, spreadsheets, and presentations created or edited within the Service
  • Calendar events, attendees, and reminders
  • Meeting Center metadata, discussion content, guest access links, and related media
  • Omnichannel messages, media, and conversation history across connected channels (see Section 1.6)
  • EDM campaign content, templates, recipient lists, SMTP credentials you configure, and delivery/engagement events (see Section 1.7)

You are solely responsible for the content you submit to the Service and for ensuring you have a lawful basis to process any personal data of third parties (employees, customers, suppliers, or other end users) through the Service.

1.4 Business Application Data

Depending on the modules you enable, the Service may store business records you enter or import, including:

  • CRM / Vendors: contact names, emails, phone numbers, addresses, pipeline/activity records, attachments, and messaging identity fields
  • HR: employee names, personal contact details, addresses, leave records, onboarding information, and uploaded documents (for example ID proofs, CVs, or contracts)
  • Accounting / Payroll: invoices, bills, journals, bank account and reconciliation data, company settings, and payroll-related information you choose to store (which may include government identifiers, bank details, and statutory contribution data such as Hong Kong MPF or Australia TFN/superannuation information, where those features are used)
  • Inventory: products, warehouses, stock documents, and related reports
  • TCG merchant features: catalog, buy/sell records, membership points, grading or mystery-pack configurations, and member-portal authentication data where enabled

If you choose to store sensitive personal data (including government identifiers, health information, financial account numbers, payroll tax identifiers, or information relating to minors), you do so at your own risk and remain solely responsible for compliance with applicable law. For employer customers, you are the data controller of employee and end-customer data; we process such data as a service provider to operate the modules you configure.

1.5 Payment and Wallet Information

If you make a purchase or top up a prepaid wallet, payment processing is handled by Stripe, Inc. (including via Metadiv Portal billing flows). We do not collect, store, or process your credit card numbers, bank account details, or other financial instrument information. We (and Metadiv Portal) may store:

  • Transaction amounts and wallet balances
  • Stripe session or payment identifiers
  • Transaction timestamps and status
  • Usage debits associated with AI, MCP, storage, or other metered features

For Stripe's privacy practices, please refer to Stripe's Privacy Policy.

1.6 Omnichannel and Messaging Integration Data

If you connect messaging channels (including Telegram, Meta WhatsApp Cloud API, Instagram, Facebook Messenger, and/or LINE), we collect and store data received through those provider APIs as needed to operate the integration, which may include:

  • Customer profile fields: names, usernames, platform identifiers, and other profile data exposed by the channel
  • Message content: text, captions, and media (photos, videos, voice messages, audio, documents, stickers, and similar attachments)
  • Chat metadata: chat identifiers, timestamps, unread counts, delivery status, and conversation history
  • Channel credentials: bot tokens, access tokens, webhook secrets, and related configuration you provide

Customer messages and knowledge-base content may be transmitted to AI model providers (as described in Section 3) when AI agent responses, embeddings, or retrieval features are enabled. Knowledge content you connect for Omnichannel AI may be embedded and indexed in a vector database for retrieval within your workspace.

You are responsible for informing your messaging end users that their messages are processed by the Service and may be transmitted to third-party AI providers, and for complying with each channel provider's terms and applicable privacy laws.

1.7 EDM and Email Marketing Data

If you use EDM (email marketing) features, we may process:

  • Recipient lists and audience segments (including contacts sourced from CRM)
  • Campaign content, templates, and send configurations
  • SMTP or domain credentials you configure (including DKIM-related settings)
  • Delivery, bounce, unsubscribe, and suppression records
  • Engagement events such as opens and clicks (which may include timestamps, links clicked, and technical metadata such as IP address or user agent)

You are solely responsible for obtaining any required consents and providing required notices before sending marketing or transactional emails through the Service.

1.8 Integration Credentials and Tokens

If you connect third-party services or bring your own API keys (for example AI providers or MCP tools), we store access tokens, refresh tokens, webhook secrets, and API keys solely to facilitate the integrations you have authorized. We do not access your third-party account data beyond what is necessary to perform the specific actions you request through the Service.

1.9 Document and Office Content

If you create or edit documents, spreadsheets, or presentations within the Service, the content may be processed by document collaboration infrastructure (including Collabora Online / WOPI where enabled) and stored on our or Metadiv Portal infrastructure. This content may also be indexed for search functionality within your workspace.


2. How We Use Information

We use the information collected strictly for the following purposes:

  • Providing the Service: Operating business modules, collaboration tools, AI agents, automations, messaging integrations, and document features you configure.
  • Authentication and access control: Verifying identity, maintaining sessions, and enforcing workspace permissions (including via Metadiv Portal).
  • Billing: Processing payments, maintaining wallet balances, and metering usage.
  • Notifications: Sending in-app, email, and (if enabled) Web Push notifications related to the Service.
  • Service operation: Maintaining, troubleshooting, securing, and improving the Service.
  • Legal compliance: Responding to lawful requests from governmental authorities where required by applicable law.

We do not use your information for:

  • Advertising or marketing to third parties
  • Selling or renting your personal data
  • Profiling for purposes unrelated to the Service
  • Training AI models on your content

3. Metadiv Portal and Third-Party Services

3.1 Metadiv Portal

The Service relies on Metadiv Portal for authentication, workspace membership, transactional email delivery, object/file storage, wallet and billing coordination, and certain AI or MCP proxy capabilities. Data processed by Metadiv Portal in connection with the Service is handled by Metadiv Technology Limited under this Policy and any applicable Portal terms.

3.2 Third-Party Services

The Service integrates with the following categories of third-party services, each of which operates under its own privacy policy. We are not responsible for the privacy practices, data handling, or security of any third-party service.

ServicePurposePrivacy Policy
OpenRouter / Google AI / Anthropic / OpenAI / other AI providers you selectAI model inference, embeddings, image generation, and related tooling (including models accessed via OpenRouter or bring-your-own-key configurations)openrouter.ai/privacy; Google; Anthropic; OpenAI
StripePayment processing and wallet top-upsstripe.com/privacy
MetaWhatsApp Cloud API, Instagram, and Facebook Messenger integrationsfacebook.com/privacy/policy
TelegramMessaging integration (Bot API)telegram.org/privacy
LINEMessaging integration (Messaging API)line.me/en/terms/policy
Collabora OnlineIn-browser document, spreadsheet, and presentation editingcollaboraonline.com/privacy-policy
Jitsi MeetVideo/voice meetings (Meeting Center / Talkspace)jitsi.org/security
Brave Search / other MCP upstreamsMCP Center tool queries and related third-party APIs you enablebrave.com/privacy
Google reCAPTCHABot protection for authentication or registration flows where enabledpolicies.google.com/privacy
Infrastructure providersHosting, databases, object storage, and related infrastructure (which may include providers such as DigitalOcean)digitalocean.com/legal/privacy-policy

When you use the Service, your data (including chat messages, uploaded files, images, video, audio, documents, business records, and messaging conversation history) may be transmitted to these third-party providers to fulfill your requests. By using the Service, you acknowledge and consent to such transmission. We have no control over how third-party providers process data once transmitted.


4. Data Storage and Security

4.1 Storage

Your data is stored on Metadiv-operated systems and third-party infrastructure providers (including storage coordinated through Metadiv Portal). We use commercially reasonable efforts to protect your data, but we do not guarantee the absolute security of any information transmitted to or stored by the Service.

4.2 Security Measures

We implement the following measures:

  • Token-based authentication with expiration (including Portal/session controls)
  • HTTPS for data transmission
  • Webhook secret validation for messaging integrations where applicable
  • Encryption of certain sensitive credentials and identifiers at rest where the Service implements such controls

No method of electronic transmission or storage is 100% secure. We cannot and do not guarantee that your data will not be accessed, disclosed, altered, or destroyed by breach of any of our safeguards.

4.3 Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. We do not commit to any specific data retention schedule. If you wish to delete your account and associated data, you may contact us at the address provided below. We will make reasonable efforts to delete your data, subject to any legal obligations requiring retention.

4.4 Sharing Features You Enable

If you create Cloud Drive public share links, guest meeting links, public TCG pages, or similar access features, anyone with the link or page URL may be able to access the shared content. You are responsible for configuring sharing settings appropriately.


5. Data Sharing

We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:

  • Metadiv Portal and service providers: As described in Section 3, to operate the Service.
  • Legal requirements: If required by law, regulation, legal process, or governmental request.
  • Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
  • With your consent: Where you have explicitly authorized such sharing.
  • Workspace administrators and members: Content and records you store in a workspace may be visible to other authorized members of that workspace according to roles and permissions.

6. Your Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding your personal data, including:

  • Access: Request a copy of data we hold about you.
  • Deletion: Request deletion of your account and associated data.
  • Withdrawal of consent / disconnect integrations:Revoke connected channel authorizations, API keys, OAuth authorizations, Web Push subscriptions, or similar integrations at any time through the Service or the respective third-party provider's settings.

If you are an end customer, employee, or other individual whose data was uploaded by a B-Suite customer (workspace), please contact that customer first; we process such data on their instructions.

To exercise any of these rights with us, contact us at the address provided below. We will respond within a reasonable timeframe. We reserve the right to verify your identity before processing any request and to decline requests that are unreasonable, repetitive, or technically impractical.

We do not guarantee compliance with any specific data protection regulation (including but not limited to GDPR, CCPA, or PDPO) beyond what is expressly stated in this Policy. If you are located in a jurisdiction with data protection laws that provide rights beyond those described here, you should assess whether the Service meets your requirements before use.


7. Cookies and Tracking

The Service does not use third-party advertising cookies or advertising pixels. We may use:

  • Authentication cookies and/or local storage to maintain your session (including Metadiv Portal session controls)
  • First-party EDM open/click tracking tokens or pixels for campaigns you send through the Service (see Section 1.7)
  • Google reCAPTCHA or similar bot-protection technologies where enabled for authentication or registration

No third-party advertising networks are deployed by us on the Service for marketing to third parties.


8. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will take reasonable steps to delete such information.


9. International Data Transfers

The Service may process and store data in jurisdictions outside your country of residence. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction. We make no representations that the Service is appropriate or available for use in any particular jurisdiction.


10. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:

  • WE SHALL NOT BE LIABLE FOR ANY UNAUTHORIZED ACCESS TO, OR ALTERATION, THEFT, OR DESTRUCTION OF, YOUR DATA, WHETHER THROUGH BREACH, NEGLIGENCE, OR ANY OTHER CAUSE.
  • WE SHALL NOT BE LIABLE FOR ANY LOSS OR DAMAGE ARISING FROM YOUR USE OF THIRD-PARTY SERVICES ACCESSED THROUGH THE SERVICE.
  • WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM OR RELATED TO YOUR USE OF THE SERVICE OR THIS POLICY.
  • OUR TOTAL AGGREGATE LIABILITY TO YOU FOR ALL CLAIMS ARISING FROM OR RELATED TO THE SERVICE SHALL NOT EXCEED THE AMOUNT YOU HAVE PAID US IN THE THREE (3) MONTHS PRECEDING THE CLAIM, OR TEN US DOLLARS (USD $10), WHICHEVER IS GREATER.

11. Indemnification

You agree to indemnify, defend, and hold harmless the Company and its officers, directors, employees, and agents from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising from or relating to: (a) your use of the Service; (b) your violation of this Policy; (c) your User-Generated Content or business/customer data; (d) your messaging, EDM, or other communications to third parties; or (e) your violation of any rights of a third party.


12. Disclaimer

THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR DATA ACCURACY. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE.


13. Changes to This Policy

We may update this Policy at any time by posting the revised version on the Service. The "Last Updated" date at the top will be revised accordingly. Your continued use of the Service after any changes constitutes acceptance of the updated Policy. We are not obligated to notify you of changes.


14. Governing Law

This Policy shall be governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region, without regard to its conflict of law provisions. Any disputes arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of Hong Kong.


15. Severability

If any provision of this Policy is held to be unenforceable or invalid, such provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.


16. Contact Us

If you have questions about this Policy, please contact us at:

Metadiv Technology Limited
Email: nelson@metadiv.io


This Privacy Policy constitutes the entire agreement between you and the Company regarding the privacy practices described herein. This document does not create any contractual or other legal rights in or on behalf of any third party.

© 2026 Metadiv Technology Limited. All rights reserved.

Terms of ServicePrivacy Policy