Privacy Policy
Last Updated: August 4, 2026
This Privacy Policy ("Policy") describes how Metadiv Technology Limited ("Company", "we", "us", or "our") collects, uses, and handles information in connection with the B-Suite platform and related services accessible at bsuite.metadiv.io (collectively, the "Service"). By accessing or using the Service, you ("User", "you", or "your") acknowledge that you have read and understood this Policy.
The Service is an integrated business software platform that may include modules such as OperAgent, MCP Center, CRM, HR, Accounting, Inventory, Vendors, Omnichannel messaging, Team Chat, Meeting Center, Calendar, Cloud Drive, Office documents, EDM email marketing, TCG merchant tools, wallet/billing, and related features. Not all modules are available in every workspace.
THIS SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. WE MAKE NO REPRESENTATIONS OR WARRANTIES REGARDING THE SECURITY OR PRIVACY OF YOUR DATA BEYOND WHAT IS EXPRESSLY STATED IN THIS POLICY.
1. Information We Collect
1.1 Account Information
Account registration and authentication for the Service are provided through Metadiv Portal (portal.metadiv.io), a related Metadiv service. When you create or access an account, we (and Metadiv Portal on our behalf) may collect:
- Email address
- Authentication credentials (password hashes where applicable, email one-time verification codes, session tokens)
- Workspace membership and role information
Account registration fields are limited. We do not require your name, phone number, or physical address solely to create an account. However, you and other workspace users may voluntarily store names, phone numbers, addresses, and other personal data inside the Service as business or customer content (see Sections 1.3 and 1.4).
1.2 Usage and Technical Data
We automatically collect limited technical data when you use the Service:
- IP address (including for authentication and security)
- User agent string (browser/device type)
- Usage and billing metrics (for example AI token counts, MCP tool usage, storage usage, and associated wallet costs)
- Presence or online status indicators within collaboration features (where enabled)
- Web Push subscription endpoints and keys, if you enable browser push notifications
1.3 User-Generated and Workspace Content
The Service allows you and your workspace members to create, upload, and store content, including but not limited to:
- Team chat messages, attachments, and conversation history
- OperAgent chat messages, uploads, agent configurations, skills, memory, and schedules
- MCP Center configurations, tool usage inputs/outputs, and user-provided API keys
- Cloud Drive files and folders, including content shared via public or member links
- Office documents, spreadsheets, and presentations created or edited within the Service
- Calendar events, attendees, and reminders
- Meeting Center metadata, discussion content, guest access links, and related media
- Omnichannel messages, media, and conversation history across connected channels (see Section 1.6)
- EDM campaign content, templates, recipient lists, SMTP credentials you configure, and delivery/engagement events (see Section 1.7)
You are solely responsible for the content you submit to the Service and for ensuring you have a lawful basis to process any personal data of third parties (employees, customers, suppliers, or other end users) through the Service.
1.4 Business Application Data
Depending on the modules you enable, the Service may store business records you enter or import, including:
- CRM / Vendors: contact names, emails, phone numbers, addresses, pipeline/activity records, attachments, and messaging identity fields
- HR: employee names, personal contact details, addresses, leave records, onboarding information, and uploaded documents (for example ID proofs, CVs, or contracts)
- Accounting / Payroll: invoices, bills, journals, bank account and reconciliation data, company settings, and payroll-related information you choose to store (which may include government identifiers, bank details, and statutory contribution data such as Hong Kong MPF or Australia TFN/superannuation information, where those features are used)
- Inventory: products, warehouses, stock documents, and related reports
- TCG merchant features: catalog, buy/sell records, membership points, grading or mystery-pack configurations, and member-portal authentication data where enabled
If you choose to store sensitive personal data (including government identifiers, health information, financial account numbers, payroll tax identifiers, or information relating to minors), you do so at your own risk and remain solely responsible for compliance with applicable law. For employer customers, you are the data controller of employee and end-customer data; we process such data as a service provider to operate the modules you configure.
1.5 Payment and Wallet Information
If you make a purchase or top up a prepaid wallet, payment processing is handled by Stripe, Inc. (including via Metadiv Portal billing flows). We do not collect, store, or process your credit card numbers, bank account details, or other financial instrument information. We (and Metadiv Portal) may store:
- Transaction amounts and wallet balances
- Stripe session or payment identifiers
- Transaction timestamps and status
- Usage debits associated with AI, MCP, storage, or other metered features
For Stripe's privacy practices, please refer to Stripe's Privacy Policy.
1.6 Omnichannel and Messaging Integration Data
If you connect messaging channels (including Telegram, Meta WhatsApp Cloud API, Instagram, Facebook Messenger, and/or LINE), we collect and store data received through those provider APIs as needed to operate the integration, which may include:
- Customer profile fields: names, usernames, platform identifiers, and other profile data exposed by the channel
- Message content: text, captions, and media (photos, videos, voice messages, audio, documents, stickers, and similar attachments)
- Chat metadata: chat identifiers, timestamps, unread counts, delivery status, and conversation history
- Channel credentials: bot tokens, access tokens, webhook secrets, and related configuration you provide
Customer messages and knowledge-base content may be transmitted to AI model providers (as described in Section 3) when AI agent responses, embeddings, or retrieval features are enabled. Knowledge content you connect for Omnichannel AI may be embedded and indexed in a vector database for retrieval within your workspace.
You are responsible for informing your messaging end users that their messages are processed by the Service and may be transmitted to third-party AI providers, and for complying with each channel provider's terms and applicable privacy laws.
1.7 EDM and Email Marketing Data
If you use EDM (email marketing) features, we may process:
- Recipient lists and audience segments (including contacts sourced from CRM)
- Campaign content, templates, and send configurations
- SMTP or domain credentials you configure (including DKIM-related settings)
- Delivery, bounce, unsubscribe, and suppression records
- Engagement events such as opens and clicks (which may include timestamps, links clicked, and technical metadata such as IP address or user agent)
You are solely responsible for obtaining any required consents and providing required notices before sending marketing or transactional emails through the Service.
1.8 Integration Credentials and Tokens
If you connect third-party services or bring your own API keys (for example AI providers or MCP tools), we store access tokens, refresh tokens, webhook secrets, and API keys solely to facilitate the integrations you have authorized. We do not access your third-party account data beyond what is necessary to perform the specific actions you request through the Service.
1.9 Document and Office Content
If you create or edit documents, spreadsheets, or presentations within the Service, the content may be processed by document collaboration infrastructure (including Collabora Online / WOPI where enabled) and stored on our or Metadiv Portal infrastructure. This content may also be indexed for search functionality within your workspace.
2. How We Use Information
We use the information collected strictly for the following purposes:
- Providing the Service: Operating business modules, collaboration tools, AI agents, automations, messaging integrations, and document features you configure.
- Authentication and access control: Verifying identity, maintaining sessions, and enforcing workspace permissions (including via Metadiv Portal).
- Billing: Processing payments, maintaining wallet balances, and metering usage.
- Notifications: Sending in-app, email, and (if enabled) Web Push notifications related to the Service.
- Service operation: Maintaining, troubleshooting, securing, and improving the Service.
- Legal compliance: Responding to lawful requests from governmental authorities where required by applicable law.
We do not use your information for:
- Advertising or marketing to third parties
- Selling or renting your personal data
- Profiling for purposes unrelated to the Service
- Training AI models on your content
3. Metadiv Portal and Third-Party Services
3.1 Metadiv Portal
The Service relies on Metadiv Portal for authentication, workspace membership, transactional email delivery, object/file storage, wallet and billing coordination, and certain AI or MCP proxy capabilities. Data processed by Metadiv Portal in connection with the Service is handled by Metadiv Technology Limited under this Policy and any applicable Portal terms.
3.2 Third-Party Services
The Service integrates with the following categories of third-party services, each of which operates under its own privacy policy. We are not responsible for the privacy practices, data handling, or security of any third-party service.
| Service | Purpose | Privacy Policy |
|---|---|---|
| OpenRouter / Google AI / Anthropic / OpenAI / other AI providers you select | AI model inference, embeddings, image generation, and related tooling (including models accessed via OpenRouter or bring-your-own-key configurations) | openrouter.ai/privacy; Google; Anthropic; OpenAI |
| Stripe | Payment processing and wallet top-ups | stripe.com/privacy |
| Meta | WhatsApp Cloud API, Instagram, and Facebook Messenger integrations | facebook.com/privacy/policy |
| Telegram | Messaging integration (Bot API) | telegram.org/privacy |
| LINE | Messaging integration (Messaging API) | line.me/en/terms/policy |
| Collabora Online | In-browser document, spreadsheet, and presentation editing | collaboraonline.com/privacy-policy |
| Jitsi Meet | Video/voice meetings (Meeting Center / Talkspace) | jitsi.org/security |
| Brave Search / other MCP upstreams | MCP Center tool queries and related third-party APIs you enable | brave.com/privacy |
| Google reCAPTCHA | Bot protection for authentication or registration flows where enabled | policies.google.com/privacy |
| Infrastructure providers | Hosting, databases, object storage, and related infrastructure (which may include providers such as DigitalOcean) | digitalocean.com/legal/privacy-policy |
When you use the Service, your data (including chat messages, uploaded files, images, video, audio, documents, business records, and messaging conversation history) may be transmitted to these third-party providers to fulfill your requests. By using the Service, you acknowledge and consent to such transmission. We have no control over how third-party providers process data once transmitted.
4. Data Storage and Security
4.1 Storage
Your data is stored on Metadiv-operated systems and third-party infrastructure providers (including storage coordinated through Metadiv Portal). We use commercially reasonable efforts to protect your data, but we do not guarantee the absolute security of any information transmitted to or stored by the Service.
4.2 Security Measures
We implement the following measures:
- Token-based authentication with expiration (including Portal/session controls)
- HTTPS for data transmission
- Webhook secret validation for messaging integrations where applicable
- Encryption of certain sensitive credentials and identifiers at rest where the Service implements such controls
No method of electronic transmission or storage is 100% secure. We cannot and do not guarantee that your data will not be accessed, disclosed, altered, or destroyed by breach of any of our safeguards.
4.3 Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. We do not commit to any specific data retention schedule. If you wish to delete your account and associated data, you may contact us at the address provided below. We will make reasonable efforts to delete your data, subject to any legal obligations requiring retention.
4.4 Sharing Features You Enable
If you create Cloud Drive public share links, guest meeting links, public TCG pages, or similar access features, anyone with the link or page URL may be able to access the shared content. You are responsible for configuring sharing settings appropriately.
5. Data Sharing
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- Metadiv Portal and service providers: As described in Section 3, to operate the Service.
- Legal requirements: If required by law, regulation, legal process, or governmental request.
- Business transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
- With your consent: Where you have explicitly authorized such sharing.
- Workspace administrators and members: Content and records you store in a workspace may be visible to other authorized members of that workspace according to roles and permissions.
6. Your Rights and Choices
Depending on your jurisdiction, you may have certain rights regarding your personal data, including:
- Access: Request a copy of data we hold about you.
- Deletion: Request deletion of your account and associated data.
- Withdrawal of consent / disconnect integrations:Revoke connected channel authorizations, API keys, OAuth authorizations, Web Push subscriptions, or similar integrations at any time through the Service or the respective third-party provider's settings.
If you are an end customer, employee, or other individual whose data was uploaded by a B-Suite customer (workspace), please contact that customer first; we process such data on their instructions.
To exercise any of these rights with us, contact us at the address provided below. We will respond within a reasonable timeframe. We reserve the right to verify your identity before processing any request and to decline requests that are unreasonable, repetitive, or technically impractical.
We do not guarantee compliance with any specific data protection regulation (including but not limited to GDPR, CCPA, or PDPO) beyond what is expressly stated in this Policy. If you are located in a jurisdiction with data protection laws that provide rights beyond those described here, you should assess whether the Service meets your requirements before use.
7. Cookies and Tracking
The Service does not use third-party advertising cookies or advertising pixels. We may use:
- Authentication cookies and/or local storage to maintain your session (including Metadiv Portal session controls)
- First-party EDM open/click tracking tokens or pixels for campaigns you send through the Service (see Section 1.7)
- Google reCAPTCHA or similar bot-protection technologies where enabled for authentication or registration
No third-party advertising networks are deployed by us on the Service for marketing to third parties.
8. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will take reasonable steps to delete such information.
9. International Data Transfers
The Service may process and store data in jurisdictions outside your country of residence. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your jurisdiction. We make no representations that the Service is appropriate or available for use in any particular jurisdiction.
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW:
- WE SHALL NOT BE LIABLE FOR ANY UNAUTHORIZED ACCESS TO, OR ALTERATION, THEFT, OR DESTRUCTION OF, YOUR DATA, WHETHER THROUGH BREACH, NEGLIGENCE, OR ANY OTHER CAUSE.
- WE SHALL NOT BE LIABLE FOR ANY LOSS OR DAMAGE ARISING FROM YOUR USE OF THIRD-PARTY SERVICES ACCESSED THROUGH THE SERVICE.
- WE SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING FROM OR RELATED TO YOUR USE OF THE SERVICE OR THIS POLICY.
- OUR TOTAL AGGREGATE LIABILITY TO YOU FOR ALL CLAIMS ARISING FROM OR RELATED TO THE SERVICE SHALL NOT EXCEED THE AMOUNT YOU HAVE PAID US IN THE THREE (3) MONTHS PRECEDING THE CLAIM, OR TEN US DOLLARS (USD $10), WHICHEVER IS GREATER.
11. Indemnification
You agree to indemnify, defend, and hold harmless the Company and its officers, directors, employees, and agents from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees) arising from or relating to: (a) your use of the Service; (b) your violation of this Policy; (c) your User-Generated Content or business/customer data; (d) your messaging, EDM, or other communications to third parties; or (e) your violation of any rights of a third party.
12. Disclaimer
THE SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR DATA ACCURACY. WE DO NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE.
13. Changes to This Policy
We may update this Policy at any time by posting the revised version on the Service. The "Last Updated" date at the top will be revised accordingly. Your continued use of the Service after any changes constitutes acceptance of the updated Policy. We are not obligated to notify you of changes.
14. Governing Law
This Policy shall be governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region, without regard to its conflict of law provisions. Any disputes arising under or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of Hong Kong.
15. Severability
If any provision of this Policy is held to be unenforceable or invalid, such provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
16. Contact Us
If you have questions about this Policy, please contact us at:
Metadiv Technology Limited
Email: nelson@metadiv.io
This Privacy Policy constitutes the entire agreement between you and the Company regarding the privacy practices described herein. This document does not create any contractual or other legal rights in or on behalf of any third party.