Privacy Policy

Effective Date: 30 December 2025

Last Updated: 9 October 2026

This Privacy Policy explains how MeetDoris Ltd (trading as DorisLabs) ("MeetDoris", "we", "us") collects, uses, shares, and protects information when you visit our websites or use our products, browser extensions, and related services (collectively, the "Services").

If you do not agree with this Privacy Policy, please do not use the Services.

1) Who we are and how to contact us

We are MeetDoris Ltd (trading as DorisLabs).

  • Company number: 13110272 (England and Wales)
  • Registered office: 16 High Row Field, Felixstowe, Suffolk, England, IP11 7AE
  • Privacy & data requests: privacy [at] meetdoris [dot] com
  • General support: support [at] meetdoris [dot] com

2) Scope: website visitors, product users, meeting participants, and job applicants

Your relationship to MeetDoris affects how we process data:

  • Website visitors: we act as a controller for website analytics, marketing attribution, and inquiries.
  • Product users: we act as a controller for account management, billing, and operating the Services.
  • Meeting participants and customer content: where a business customer uses MeetDoris to process meeting content, that customer may be the controller for the meeting content, and MeetDoris typically acts as a processor/service provider.
  • Job applicants: we act as a controller for everything you send us when you apply for a role. Section 17 covers this in full.

Meeting recordings and participant consent

MeetDoris can record and transcribe meetings when a customer enables it. The customer that operates MeetDoris in a meeting is responsible for establishing a lawful basis for recording and for obtaining any consent required from participants under applicable laws — including "all-party" (two-party) consent laws in certain US states and notice/consent requirements under UK and EU law. Customers must not use MeetDoris to record where doing so would be unlawful.

Where required, participants are notified that a meeting is being recorded and may object or ask not to be recorded. If you are a meeting participant and have questions or want your data removed, contact the customer hosting the meeting, or email us at privacy [at] meetdoris [dot] com and we will route your request to the relevant controller.

3) Information we collect

Depending on how you use the Services and what you enable, we may collect:

A. Account and profile information

  • Email address, name, and account identifiers.
  • Workspace/team information, roles, and preferences (e.g., timezone).

B. Billing and transaction information

  • Subscription status, plan, and billing history.
  • Payment processing is handled by Stripe; we do not store full payment card numbers.

C. Customer content and connected data

  • Meeting recordings (where enabled/authorized), transcripts, speaker labels, and meeting metadata.
  • Calendar/email/CRM data you connect (e.g., Google/Microsoft/HubSpot), and files you upload.

D. AI-derived outputs

  • Summaries, key points, action items, tasks, Q&A, objections, decisions, and analytics outputs derived from your content.

E. Technical and usage information

  • IP address, browser type, device information, and logs.
  • Usage patterns (pages viewed, feature usage, clicks), and performance/error telemetry.

F. Cookies and similar technologies

We use cookies and similar technologies on our websites and within our Services for necessary functionality, analytics, and (where enabled) marketing attribution.

4) How we collect information

  • Directly from you (forms, account creation, product usage, uploads).
  • From integrations you connect (e.g., Google, Microsoft, HubSpot).
  • Automatically through cookies, SDKs, and logs.
  • From service providers (e.g., payment and authentication providers).

5) How we use information

  • Provide and operate the Services (authentication, core features, account management).
  • AI features (generate insights, summaries, analytics, and recommendations you request).
  • Support (respond to questions, troubleshoot issues).
  • Security (fraud prevention, abuse detection, incident investigation).
  • Billing (subscriptions, invoices, receipts).
  • Product improvement (usage analytics, debugging, performance monitoring).
  • Marketing and attribution (measure campaigns and conversions where enabled).
  • Legal compliance (comply with laws and enforce our terms).

6) Legal bases (UK GDPR / EU GDPR)

Where UK GDPR/EU GDPR applies, we process personal data based on one or more of the following:

  • Contract: to provide the Services you request.
  • Legitimate interests: to secure and improve the Services, prevent fraud, and measure performance.
  • Consent: where required for certain cookies/marketing technologies and optional features.
  • Legal obligation: to meet legal and regulatory requirements.

7) AI and automated processing

We use AI to deliver features like summaries, insights, analytics, and drafting assistance. This processing uses Azure OpenAI models hosted by Microsoft in its EU Data Zone, in France Central with failover to Germany West Central. Meeting transcription and the embeddings we use for search run there too.

The content we send to these models (inputs) and what they return (outputs) is not made available to other customers, and we do not allow the model providers to use it to train their models. Where each model runs is listed on our sub-processor page.

We do not use customer content — including meeting recordings, transcripts, or AI-derived outputs — to train our own models. Customer content is used only to provide the Services to you. We may use de-identified, aggregated usage data (which does not identify you or any individual) to operate and improve the Services.

8) Cookies, pixels, and similar technologies

We use cookies and similar technologies to support essential functionality, understand how our websites/Services are used, and measure marketing attribution where enabled.

  • Essential: security and core functionality. This includes Cloudflare Turnstile, which checks that a person, not an automated program, is sending our demo and waitlist forms. It runs only on pages with one of those forms, and Cloudflare receives your IP address and technical signals from your browser to make that check.
  • Marketing: understand which pages visitors read and connect a form you send to those visits. We use HubSpot for this.

On our website, non-essential analytics and marketing technologies load only after you consent through our cookie banner; you can change or withdraw your choices at any time using the Cookie settings link in the footer, and you can also control cookies through your browser settings.

9) How we share information

We do not sell meeting recordings, transcripts, or other customer content. We may share information:

  • With service providers that help us run the Services (e.g., hosting, analytics, support, payments, authentication) under confidentiality.
  • With integration partners you choose to connect.
  • For legal and safety reasons where required by law or to protect rights and safety.
  • In business transfers (e.g., merger, acquisition) where allowed by law.

10) Third-party providers and sub-processors

Sub-processors. Where we process customer content on a customer's behalf (as a processor), we engage sub-processors to process that content for us, such as Microsoft Azure for hosting, our meeting bots and AI processing. The full current list, with what each one processes and where, is published at dorislabs.com/subprocessors. We give customers at least 30 days' notice of a new sub-processor so they can object.

Independent providers. Some providers process personal data for their own purposes as independent controllers rather than on our behalf — for example, Stripe (payments), which handles payment data under its own privacy policy and legal obligations.

Integrations you connect. Calendar, email, CRM, and meeting platforms you choose to connect — such as Google Workspace, Microsoft 365, HubSpot, Zoom, Microsoft Teams, and Google Meet — are governed by your own agreements with, and configuration of, those providers. They are not our sub-processors; we exchange data with them at your direction.

Our own service providers. For data we hold as controller, such as account details and product usage, we also use Resend (email delivery) and Kickbox (checking whether a sign-up email address uses a disposable domain; Kickbox receives the domain only, never the full address).

Website forms and marketing. On our website we use Cloudflare (Turnstile, to keep automated submissions out of our forms) and HubSpot (marketing analytics, after you consent, and the record of a form you send us), as described in Section 8.

11) International transfers

We host the Services on Microsoft Azure in the United Kingdom, and the AI inference, embeddings and transcription we run on Microsoft Azure take place in Microsoft’s EU Data Zone. Some providers process data outside the UK and the EU, including in the United States, as shown on our sub-processor page. Where a transfer needs a safeguard under UK or EU law, we rely on adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified) or on standard contractual clauses with the UK Addendum, as provided in each provider's data processing terms.

12) Data retention

We retain information only as long as necessary for the purposes described in this policy. The period depends on the type of data and why we hold it:

  • Customer content (recordings, transcripts, AI-derived outputs): retained for the life of the workspace, subject to workspace settings and deletion actions. When a workspace is closed or a trial ends, the customer has 30 days to export its content; we then delete it from our active systems by an automated process, unless we are required to retain it. Copies in backups are deleted when the backups expire, within 35 days.
  • Account and billing records: retained for the life of the account and, after closure, only as long as needed to meet legal, tax, and accounting obligations.
  • Technical and usage logs: retained on a rolling short-term basis for security, debugging, and performance.

We may retain limited information longer where required to comply with law, resolve disputes, or enforce our agreements. You can request deletion as described in "Your rights and choices" below.

13) Security

We implement reasonable administrative, technical, and organizational measures designed to protect your information. No system is completely secure, and we cannot guarantee absolute security.

14) Your rights and choices

If you are located in the United Kingdom, the European Economic Area, California, or another jurisdiction that grants privacy rights, you may have rights such as access, correction, deletion, restriction, portability, and objection (including to direct marketing), subject to applicable law.

How to exercise your rights. You (or any meeting participant) can email privacy [at] meetdoris [dot] com. We will verify your identity and respond within one month (extendable by up to two further months for complex or numerous requests, in which case we will tell you within the first month). We do not discriminate against anyone for exercising privacy rights.

You also have the right to lodge a complaint with the UK Information Commissioner's Office or your local supervisory authority.

15) Third-party links

Our Services may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties.

16) Children's privacy

The Services are not intended for individuals under the age of 16, and we do not knowingly collect personal information from children.

17) Job applicants and candidates

This section applies if you apply for a role at MeetDoris, or send us your details speculatively. We are the controller for everything in it.

What we collect

  • Your name, email address, phone number, and anything else you choose to put in your application.
  • Your CV, covering note, portfolio, code samples, and links you send us.
  • Your work history, education, and right-to-work information.
  • Interview notes and the assessment of any exercise we ask you to do.
  • References, which we request only after we have made you an offer and you have agreed we can.

Diversity monitoring information, if we ever ask for it, is optional, anonymised, kept apart from your application, and never seen by the people deciding.

Why we process it, and on what basis

  • To assess you for the role and run the hiring process. Our legitimate interest in deciding who to hire, and taking steps at your request before entering a contract.
  • To check your right to work in the UK. A legal obligation, and we run the same check for everyone we hire.
  • To keep your details on file for future roles. Only with your consent, which you can withdraw at any time.

Who sees it

The people at MeetDoris involved in that hire, and our email provider (Microsoft 365), which hosts the mailbox your application arrives in. We do not sell candidate data, and we do not use it to train models.

How long we keep it

  • If we do not offer you the role: 6 months from the decision, then deleted. We keep it that long so we can answer a question or a complaint about the process.
  • If you ask us to keep you in mind: 12 months, then we delete it or ask you whether to keep going.
  • If you join us: your application becomes part of your employment record and is kept under our staff privacy notice, which we give you when you start.

Your rights

The rights in section 14 apply here too. You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it before the periods above run out. Email privacy [at] meetdoris [dot] com and we will do it. You can also complain to the Information Commissioner's Office at ico.org.uk.

Automated decisions

We do not use automated decision-making or profiling to sift or screen candidates. A person reads every application.

18) Changes to this policy

We may update this Privacy Policy from time to time. We will post changes on this page and update the "Last Updated" date. Where a change is material, for example a new purpose or a new type of recipient, we will also email account administrators before it takes effect.

19) Contact

If you have any questions about this Privacy Policy or our data practices, contact us at privacy [at] meetdoris [dot] com.