Privacy Policy
Effective Date: 30 December 2025
Last Updated: 2 July 2026
This Privacy Policy explains how MeetDoris Ltd (trading as DorisLabs) ("MeetDoris", "we", "us") collects, uses, shares, and protects information when you visit our websites or use our products, browser extensions, and related services (collectively, the "Services").
If you do not agree with this Privacy Policy, please do not use the Services.
1) Who we are and how to contact us
We are MeetDoris Ltd (trading as DorisLabs).
- Registered office: 16 High Row Field, Felixstowe, Suffolk, England, IP11 7AE
- Privacy & data requests: privacy [at] meetdoris [dot] com
- General support: help [at] meetdoris [dot] com
2) Scope: website visitors, product users, and meeting participants
Your relationship to MeetDoris affects how we process data:
- Website visitors: we act as a controller for website analytics, marketing attribution, and inquiries.
- Product users: we act as a controller for account management, billing, and operating the Services.
- Meeting participants and customer content: where a business customer uses MeetDoris to process meeting content, that customer may be the controller for the meeting content, and MeetDoris typically acts as a processor/service provider.
Meeting recordings and participant consent
MeetDoris can record and transcribe meetings when a customer enables it. The customer that operates MeetDoris in a meeting is responsible for establishing a lawful basis for recording and for obtaining any consent required from participants under applicable laws — including "all-party" (two-party) consent laws in certain US states and notice/consent requirements under UK and EU law. Customers must not use MeetDoris to record where doing so would be unlawful.
Where required, participants are notified that a meeting is being recorded and may object or ask not to be recorded. If you are a meeting participant and have questions or want your data removed, contact the customer hosting the meeting, or email us at privacy [at] meetdoris [dot] com and we will route your request to the relevant controller.
3) Information we collect
Depending on how you use the Services and what you enable, we may collect:
A. Account and profile information
- Email address, name, and account identifiers.
- Workspace/team information, roles, and preferences (e.g., timezone).
B. Billing and transaction information
- Subscription status, plan, and billing history.
- Payment processing is handled by Stripe; we do not store full payment card numbers.
C. Customer content and connected data
- Meeting recordings (where enabled/authorized), transcripts, speaker labels, and meeting metadata.
- Calendar/email/CRM data you connect (e.g., Google/Microsoft/HubSpot), and files you upload.
D. AI-derived outputs
- Summaries, key points, action items, tasks, Q&A, objections, decisions, and analytics outputs derived from your content.
E. Technical and usage information
- IP address, browser type, device information, and logs.
- Usage patterns (pages viewed, feature usage, clicks), and performance/error telemetry.
F. Cookies and similar technologies
We use cookies and similar technologies on our websites and within our Services for necessary functionality, analytics, and (where enabled) marketing attribution.
4) How we collect information
- Directly from you (forms, account creation, product usage, uploads).
- From integrations you connect (e.g., Google, Microsoft, HubSpot).
- Automatically through cookies, SDKs, and logs.
- From service providers (e.g., payment and authentication providers).
5) How we use information
- Provide and operate the Services (authentication, core features, account management).
- AI features (generate insights, summaries, analytics, and recommendations you request).
- Support (respond to questions, troubleshoot issues).
- Security (fraud prevention, abuse detection, incident investigation).
- Billing (subscriptions, invoices, receipts).
- Product improvement (usage analytics, debugging, performance monitoring).
- Marketing and attribution (measure campaigns and conversions where enabled).
- Legal compliance (comply with laws and enforce our terms).
6) Legal bases (UK GDPR / EU GDPR)
Where UK GDPR/EU GDPR applies, we process personal data based on one or more of the following:
- Contract: to provide the Services you request.
- Legitimate interests: to secure and improve the Services, prevent fraud, and measure performance.
- Consent: where required for certain cookies/marketing technologies and optional features.
- Legal obligation: to meet legal and regulatory requirements.
7) AI and automated processing (including Azure OpenAI Service)
We use AI to deliver features like summaries, insights, analytics, and drafting assistance. Certain processing may be performed through Azure OpenAI Service and related infrastructure.
When using Azure OpenAI Service, your prompts (inputs) and completions (outputs) are not available to other customers or to OpenAI, and are not used to train, retrain, or improve Azure OpenAI Service foundation models.
We do not use customer content — including meeting recordings, transcripts, or AI-derived outputs — to train our own models. Customer content is used only to provide the Services to you. We may use de-identified, aggregated usage data (which does not identify you or any individual) to operate and improve the Services.
8) Cookies, pixels, and similar technologies
We use cookies and similar technologies to support essential functionality, understand how our websites/Services are used, and measure marketing attribution where enabled.
- Essential: security and core functionality.
- Analytics: understand usage and improve user experience. We use Google Analytics for this.
- Marketing: measure conversions and optimize campaigns. We use Google Ads, the Meta (Facebook) Pixel, HubSpot, and a visitor-identification provider (Leadsy) for this.
On our website, non-essential analytics and marketing technologies load only after you consent through our cookie banner; you can change or withdraw your choices at any time using the Cookie settings link in the footer, and you can also control cookies through your browser settings.
9) How we share information
We do not sell meeting recordings, transcripts, or other customer content. We may share information:
- With service providers that help us run the Services (e.g., hosting, analytics, support, payments, authentication) under confidentiality.
- With integration partners you choose to connect.
- For legal and safety reasons where required by law or to protect rights and safety.
- In business transfers (e.g., merger, acquisition) where allowed by law.
10) Third-party providers and sub-processors
Sub-processors. Where we process customer content on a customer's behalf (as a processor), we engage a small set of sub-processors to process that content for us: Microsoft Azure (cloud hosting, storage, and AI infrastructure, including Azure-hosted model endpoints such as Azure OpenAI Service), Attendee (meeting-bot infrastructure that joins meetings to capture audio and produce transcripts), Deepgram (speech-to-text transcription, engaged via Attendee), Auth0 (authentication), Help Scout (customer support), and Sentry (error and performance monitoring). Our current sub-processor list is published at dorislabs.com/subprocessors; where required by our customer agreements, we give advance notice of new sub-processors so customers can object.
Independent providers. Some providers process personal data for their own purposes as independent controllers rather than on our behalf — for example, Stripe (payments), which handles payment data under its own privacy policy and legal obligations.
Integrations you connect. Calendar, email, CRM, and meeting platforms you choose to connect — such as Google Workspace, Microsoft 365, HubSpot, Zoom, Microsoft Teams, and Google Meet — are governed by your own agreements with, and configuration of, those providers. They are not our sub-processors; we exchange data with them at your direction.
Website analytics and marketing. On our websites we also use analytics/measurement providers including Google (Analytics and Ads), Meta (Facebook Pixel), HubSpot, and Leadsy (website visitor identification), as described in Section 8.
11) International transfers
We host the Services on Microsoft Azure. Your data may be transferred to and processed in countries other than your own, including by service providers located in the United States. Where required, we use appropriate safeguards such as the UK International Data Transfer Agreement (or Addendum) and the EU Standard Contractual Clauses, together with other lawful transfer mechanisms.
12) Data retention
We retain information only as long as necessary for the purposes described in this policy. The period depends on the type of data and why we hold it:
- Customer content (recordings, transcripts, AI-derived outputs): retained for the life of the workspace, subject to workspace settings and deletion actions. When you delete content, or when a workspace is closed, we delete or de-identify the associated content within a commercially reasonable period unless we are required to retain it.
- Account and billing records: retained for the life of the account and, after closure, only as long as needed to meet legal, tax, and accounting obligations.
- Technical and usage logs: retained on a rolling short-term basis for security, debugging, and performance.
We may retain limited information longer where required to comply with law, resolve disputes, or enforce our agreements. You can request deletion as described in "Your rights and choices" below.
13) Security
We implement reasonable administrative, technical, and organizational measures designed to protect your information. No system is completely secure, and we cannot guarantee absolute security.
14) Your rights and choices
If you are located in the United Kingdom, the European Economic Area, California, or another jurisdiction that grants privacy rights, you may have rights such as access, correction, deletion, restriction, portability, and objection (including to direct marketing), subject to applicable law.
How to exercise your rights. You (or any meeting participant) can email privacy [at] meetdoris [dot] com. We will verify your identity and respond within 30 days (extendable by a further 60 days for complex requests, in which case we will notify you). We do not discriminate against anyone for exercising privacy rights.
You also have the right to lodge a complaint with the UK Information Commissioner's Office or your local supervisory authority.
15) Third-party links
Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties.
16) Children's privacy
The Services are not intended for individuals under the age of 16, and we do not knowingly collect personal information from children.
17) Changes to this policy
We may update this Privacy Policy from time to time. We will post changes on this page and update the "Last Updated" date.
18) Contact
If you have any questions about this Privacy Policy or our data practices, contact us at privacy [at] meetdoris [dot] com.