Skip to content
Article 14 notice

How we found your details, and how to make us forget them

If you received an email from us that you did not ask for, this page is the notice the GDPR requires us to give you. It is short, it is specific, and the fastest thing on it is the deletion instruction, which is one word in a reply.

The short version

We hold your work email address, your name, your role and your employer. We got them from public sources, listed below. We used them once to tell you something specific and technical about a system your organization operates. We keep them for thirty days from the day we obtained them and then delete them. Reply with the word “no” and the record is deleted the same day, with no reply-to-confirm and no further contact.

Who is responsible

MetaMinds, a trading name of NexManas Tech Pvt Ltd, is the controller for this processing. Contact for anything on this page, including a request to exercise any right below, is privacy@metaminds.store. A person answers it, usually within one business day.

What we hold, and where it came from

Article 14(2)(f) requires us to name the source rather than gesture at “publicly available information”, so here it is, in order of how often it applies.

  1. 01

    Your employer's public website

    Careers pages, product changelogs, release notes, engineering blogs and press releases. This is how we identify that an organization has an AI system in production and roughly when it was placed on the market, which is the question that decides whether an obligation applies to it at all.

  2. 02

    Your professional profile

    A public LinkedIn or company team page, used to establish that you are the person whose remit this falls in. We do not scrape connections, activity, or anything behind a login.

  3. 03

    The published output of a system

    Where the finding is technical, we downloaded a publicly available output from your product and inspected its metadata with open-source tooling. That analysis is about a file, not about a person.

  4. 04

    Public registers and official journals

    Company registers and regulatory publications, where establishing the legal entity matters.

We do not buy lists, we do not use email-guessing or verification services that confirm an address by probing your mail server, and we do not hold special category data about anyone. If you tell us an address is wrong, we delete it rather than correcting it, because a corrected address is a new one we were never given.

Why we think we are allowed to

Our lawful basis is legitimate interests, Article 6(1)(f): informing an organization of a specific, verifiable technical observation about a system it operates, where a regulatory deadline makes the timing material.

The constraints we accept as the price of that basis are set out below, and they are honored whether or not anyone asks. What is not yet in place is the formal written assessment that should record this reasoning as an accountability document, and it is listed here as missing rather than implied to exist. If you are a supervisory authority or a data protection officer asking to see it, the honest answer today is that the reasoning is this page and the document is outstanding.

  • The contact is to you in a work role, at a work address, about your professional remit. Nothing here is directed at you as a private individual.
  • The message has to carry a specific finding. A generic sales email cannot carry a legitimate-interests argument, because the interest that justifies the intrusion is you learning something you did not know. If we have nothing specific, we do not write.
  • At most four messages, over fourteen days, then we stop whether or not you reply. Silence is an answer and we treat it as one.
  • We do not email anyone in Germany, Austria, Italy. Those jurisdictions require prior express consent for commercial email with no business-to-business exception, so a legitimate-interests argument does not survive there and we do not make one. If you are reading this because we contacted you in one of those countries, that is our error: tell us and we will delete the record and find out how it happened.
  • No tracking of any kind. No open pixels, no wrapped links, no read receipts. We do not know whether you opened this, and that is deliberate.

How long we keep it

Thirty days from the day the details were obtained, not from the day we wrote to you. If you reply and we start a conversation, the record moves into our normal enquiry handling and the privacy notice governs it from that point. If you do not reply, it is deleted. If you ask us not to contact you again, we keep the minimum needed to honor that, which is your address and the instruction, because the only way to reliably never write to you again is to remember not to.

Your rights

You can ask for a copy of what we hold, ask us to correct or erase it, ask us to restrict what we do with it, ask for it in a portable form, and object to the processing. Because our basis is legitimate interests, an objection under Article 21 ends the processing unless we can show compelling grounds that override your interests, and we will not attempt that argument. In practice an objection and a deletion request get the same answer, which is that it is done.

You can also complain to a supervisory authority. If you are in the EU or EEA that is the authority for the country you live or work in, and you do not need to talk to us first.

Transfers outside the EEA

NexManas Tech Pvt Ltd is established in India, which does not hold a European Commission adequacy decision. Where personal data covered by this notice is transferred to us, the intended mechanism is Standard Contractual Clauses together with a transfer impact assessment. Stated precisely, because this is the question a data protection professional asks second and a vague answer is worse than a limited one: neither has been executed yet, and this notice will say so until they are. The same conditions in our data processing addendum apply. The subprocessors that could see it are named at /legal/subprocessors. We are telling you this here rather than making you find it, because it is the question a data protection professional asks second.

Questions about any of this

Data protection questions, and any request to see, correct or delete what we hold, go to privacy@metaminds.store. Anything else, including a markup of these documents from your own counsel, goes to hello@metaminds.store.

The answers your security team will ask for, including the attestations we do not hold, are on the security posture page.