Privacy Notice
Last updated: June 2026
1. Who we are
This Privacy Notice explains how MeTime Corporation Limited ("MeTime", "we", "us", "our"), registered in Ireland under company number 669120 with registered office at 5 Fitzwilliam Square East, Dublin 2, Ireland, processes your personal data when you visit our website at metime.com, sign up as a customer (patient) or provider, complete the multimedia journey, transact through the platform, or otherwise interact with MeTime services.
MeTime is the controller of your personal data for the activities described in this Notice, except where this Notice states that a healthcare provider you have engaged through MeTime is a separate controller (see §6 'Special category personal data' and §8 'How we share your data').
1.1 Data Protection Officer
MeTime's Data Protection Officer is and can be contacted in writing at [email protected] or by post to the registered office above, marked 'For the attention of the Data Protection Officer'.
2. Scope of this Notice
This Notice applies to personal data MeTime collects and processes about (a) customers / patients who register on metime.com or in the customer mobile applications and submit a multimedia journey or contact a provider; (b) providers (medical, aesthetic and wellness professionals and their organisations) who register on provider-auth.metime.com or in the provider mobile applications; (c) candidates applying for roles at MeTime (covered by a separate Candidate Privacy Notice); and (d) visitors to metime.com before they create an account.
Where you engage a provider through MeTime and submit information directly to them through the platform, the provider becomes a separate controller of that information for the purposes of delivering the treatment, recording clinical notes and meeting their own professional obligations. We act as a processor for the provider in respect of that processing. The provider's own privacy notice governs how they then handle your data.
3. Territorial coverage and applicable laws
MeTime targets data subjects in the European Economic Area, the United Kingdom and the United States. Depending on where you are located when you provide your data, the following laws apply to our processing:
- EEA visitors: the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), supervised by the Irish Data Protection Commission as our lead supervisory authority.
- United Kingdom visitors: the UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"), supervised by the UK Information Commissioner's Office.
- United States visitors: applicable US federal and state privacy laws including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"). See §13 for the US state-specific addendum.
MeTime also handles personal data of providers and patients located in Canada (currently Ontario) through the Provider mobile application. Canadian-specific disclosures (PIPEDA / PHIPA) will be added to this Notice in a future version once the Canadian provider rollout is generally available.
4. Personal data we collect
The categories of personal data we collect depend on the role you have on the platform (customer or provider) and how you interact with us. The lists below summarise the data we collect from each category of data subject. Detailed field-by-field disclosures are maintained in our Records of Processing Activities and are available on request.
4.1 Customers (patients)
- Account data: first name, last name, email address, password (hashed), and your federated identifier where you sign in via Google or Apple.
- Multimedia journey data: a short video selfie, treatment intent (selected from prompts or free text), date of birth, Fitzpatrick skin type, height, weight, phone number, geolocation (city or address), marketing-consent flags, optional photographs of body areas you select (Face and other areas), and a free-text description of your concern. A subset of this data constitutes special category personal data — see §6.
- In-app profile data: gender, full medical history, display name (for the MeTime Community feature), language, and any further information you choose to add.
- Interaction data: messages and attachments you exchange with providers in our in-app chat, content shared in any live video consultation, appointment records, treatment selections and treatment outcomes.
- Payment data: card details tokenised by our payment processor (we do not retain raw card numbers), transaction amount, currency and reference.
- Technical data: IP address, device identifiers (advertising ID and app instance ID), browser user agent, and cookie / similar technology identifiers as described in our Cookie Policy.
4.2 Providers
- Account data: work email address, password (hashed), first name, last name, business name and (optional) business website. Federated identifier where you sign in via Google.
- Onboarding data: country, city, postal code, business address, clinic phone number and default currency; your professional photograph (mandatory and used as your public profile image); years of experience; a free-text description of your practice; selected specialties; selected treatments and brands you offer.
- Profile data: clinic / professional name, phone number, default currency, expertise narrative, education and degree, awards and certifications, training and membership, hospital privileges, insurance, publications, social media handles, cover photo, photo gallery, video gallery, list of practitioners associated with your account, and the shareable referral link we generate for you.
- Verification data: where required to enable certain features, regulatory licence and qualification information that we ask you to provide and that we check before enabling the feature. Account verification status is recorded against your account.
- Operational data: the matches you receive, custom labels you assign, chat content with patients, price and appointment offers you send, the chat-offer expiry defaults you configure, and your performance metrics (Leads, Engagement, Responsiveness, Conversions, ROI and the associated 'Revenue opportunity' value — see §7 on automated decision-making).
- Financial data: your payout bank details (processed by our payments partner Stripe Connect under Stripe's own legal basis for AML/KYC), the payment method you add for paying our per-lead charges, and the resulting transaction records.
- Technical data: IP address, device identifiers, browser user agent, app instance identifiers, and (if you grant the permission) device location and camera / microphone access for in-app video consultations.
4.3 Visitors (no account)
- Browsing data: IP address, user agent, referring URL, language, cookies and similar tracking technology identifiers as described in our Cookie Policy.
5. Purposes of processing and lawful bases
We process personal data for the purposes listed in the table below. For each purpose we identify the lawful basis under Article 6 GDPR (and Article 6 UK GDPR) on which we rely, and — where the purpose involves special category personal data — the additional Article 9 ground. US-state-law equivalents (business purposes under CCPA/CPRA) are addressed in §13.
| Purpose | Lawful basis (Art. 6) | Special category (Art. 9), where applicable |
| Provide and operate the platform — account creation, customer-provider matching, in-app messaging, appointment booking, payment processing. | Art. 6(1)(b) — contract | Art. 9(2)(a) explicit consent (customer journey content); Art. 9(2)(h) provision of healthcare (provider-side). |
| Operate the customer multimedia journey — capture and transmit treatment-intent video, photographs, body measurements and health context to the provider you choose. | Art. 6(1)(a) — consent; Art. 6(1)(b) — contract. | Art. 9(2)(a) — explicit consent. |
| Verify provider credentials and identity, and meet anti-money-laundering and other regulatory requirements (handled by our payment partner Stripe Connect for payout onboarding). | Art. 6(1)(c) — legal obligation; Art. 6(1)(b) — contract. | Not applicable. |
| Process payments from customers to providers and per-lead charges from providers to MeTime, including refund handling, tax reporting and accounting. | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation (tax/accounting retention). | Not applicable. |
| Generate the algorithmic metrics shown to providers (Leads, Engagement, Conversions, Responsiveness, ROI, predicted values, 'Revenue opportunity' value and the AI Smart Filter on Matches). | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest (platform improvement). See §7 on Art. 22. | Where the input data is special category, Art. 9(2)(a) consent applies to the underlying record. |
| Send service emails (account, security, transactional updates). | Art. 6(1)(b) — contract. | Not applicable. |
| Send marketing communications about MeTime services and partner offers, where you have opted in. | Art. 6(1)(a) — consent. | Not applicable. |
| Keep our records, defend legal claims, respond to data-subject rights requests, and demonstrate compliance with applicable laws. | Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interest in protecting our position. | Where the request relates to special category data, Art. 9(2)(f) — legal claims. |
| Ensure the security, integrity and availability of the platform; detect and prevent fraud and abuse; protect users. | Art. 6(1)(f) — legitimate interest; Art. 6(1)(c) — legal obligation. | Not applicable. |
| Comply with disclosure requests from competent regulators, law enforcement and courts. | Art. 6(1)(c) — legal obligation. | Art. 9(2)(f) — legal claims; Art. 9(2)(g) — public interest where applicable. |
6. Special category personal data
Several pieces of information we collect during the customer journey are special categories of personal data within the meaning of GDPR Article 9. These include health data (your treatment intent, free-text issue description, body measurements, photographs of body areas and your full medical history), biometric data (your video selfie used to convey treatment context and your profile photograph), and information that may reveal racial or ethnic origin (the Fitzpatrick skin-type categories presented during the multimedia journey). We are reviewing the wording of the Fitzpatrick step to remove direct racial-origin descriptors; in the meantime we treat any answer you give as Article 9 data.
We process this special category data on the basis of your explicit consent (Article 9(2)(a)) when you submit the multimedia journey. If you submit your information to a provider for treatment, the provider then processes the same data as a separate controller on the basis of Article 9(2)(h) (provision of healthcare). MeTime acts as the provider's processor for that downstream processing. The boundaries between MeTime as controller, the provider as controller and MeTime as processor are documented in our Article 30 Records of Processing.
You can withdraw your explicit consent at any time. Withdrawing consent does not affect the lawfulness of any processing carried out before the withdrawal. Where you have already submitted information to a provider, the provider's separate retention obligations may continue to apply.
6.1 HIPAA — MeTime as Business Associate
Where the provider you have selected is a Covered Entity for the purposes of the U.S. Health Insurance Portability and Accountability Act of 1996, as amended ("HIPAA"), and the personal data the provider processes through MeTime constitutes Protected Health Information ("PHI") within the meaning of HIPAA, MeTime acts as that provider's HIPAA Business Associate. A Business Associate Agreement is in place between MeTime and the relevant provider that governs MeTime's permitted uses and disclosures of PHI and imposes the administrative, physical, and technical safeguards required by 45 CFR §§ 164.308, 164.310 and 164.312, together with the use, disclosure, subcontracting and breach-notification obligations in 45 CFR §§ 164.502(e), 164.504(e) and 164.410.
Under the Business Associate Agreement, MeTime does not use or disclose PHI for any purpose other than performing services for the provider, except as required by law. Each subprocessor that processes PHI on MeTime's behalf in the United States (including our hosting, payment, video consultation, in-app messaging, and error-monitoring providers) is engaged under back-to-back Business Associate Agreements as required by 45 CFR § 164.504(e)(2)(ii) and § 164.308(b)(1).
If you have any questions about how the provider you have selected handles PHI under HIPAA, please raise them with the provider directly (the provider is the Covered Entity and the principal accountable party). For HIPAA-specific questions concerning MeTime's role as a Business Associate, write to [email protected], marking your message 'HIPAA Business Associate inquiry'.
7. Profiling and automated decision-making
We use algorithmic processing in three places that you should know about:
- Instant personalised suggestions: after you complete the multimedia journey we may show you suggested treatments or provider matches. These suggestions are generated automatically from the information you provided. They are presented for your information; a person — you, and the provider you choose to contact — makes the final decision on whether to proceed.
- Provider-facing metrics: the 'Revenue opportunity' value shown to providers next to each lead is calculated automatically from the treatments you have indicated interest in. The figures shown to providers in the ROI and Conversions tiles include 'Predicted' values generated by a model alongside 'Actual' figures.
- AI Smart Filter on the Matches list: providers may use an 'AI Smart Filter' to organise their match list. The filter operates on the same multimedia journey data you submitted.
None of these algorithmic outputs produces a decision with legal or similarly significant effect on you without human review. You have the right to obtain human intervention, to express your point of view, and to contest any algorithmic processing of your personal data under Article 22(3) GDPR. To exercise these rights please contact us at [email protected].
8. How we share your data
We share your personal data only as set out below. We do not sell your personal data within the meaning of CCPA/CPRA — see §13 for the related US-state rights and the controls available to you.
| Recipient | Purpose of sharing | Role |
| Providers you choose to contact | When you submit your multimedia journey to a provider in Step 13 of the journey, we transmit your submitted information to the provider you selected. | Independent controllers (the providers) |
| Stripe, Inc. (and affiliates) | Payment processing for customer payments; payout onboarding and disbursement to providers (Stripe Connect). | Processor (payments); independent controller (Stripe Connect AML/KYC) |
| Stripe Connect (provider KYC) | Processes provider identity data for anti-money-laundering and tax-reporting purposes. | Independent controller |
| Amazon Web Services | Hosting our application and storing application data and assets in the European Economic Area (eu-central-1, Frankfurt). | Processor |
| WhereBy AS | In-app video consultations between customers and providers. | Processor |
| Intercom, Inc. | In-app chat and customer support. | Processor |
| Sentry | Error monitoring (EU ingest endpoint). | Processor |
| Cloudflare, Inc. (including Cloudflare Insights) | Content delivery, security and first-party-style web analytics. | Processor |
| Google LLC | Google Analytics; Google Tag Manager; Google identity-provider sign-in (Continue with Google); Google advertising-related tags on certain pages. | Processor (Analytics, Tag Manager); independent controller (advertising; identity-provider sign-in) |
| Apple Inc. | Identity-provider sign-in (Continue with Apple). | Independent controller |
| Meta Platforms Ireland Limited | WhatsApp Business communications where you choose this channel. | Independent controller |
| Professional advisors and auditors | Lawyers, accountants and auditors where reasonably required. | Independent controllers |
| Regulators, courts and law enforcement | Where we are required to disclose by law or to defend legal claims. | Independent controllers |
9. International data transfers
Some of the recipients listed in §8 are based outside the European Economic Area or the United Kingdom. Where we transfer personal data to those recipients, we rely on the safeguards summarised below. You can request a copy of the relevant safeguard for any specific transfer by writing to [email protected].
| Transfer route | Recipients | Transfer mechanism |
| EEA → United States | Stripe (where US-based processing applies); Google LLC; Apple Inc.; Intercom; Cloudflare; certain Meta operations. | Standard Contractual Clauses (Module 2 controller-to-processor or Module 1 controller-to-controller, as applicable) supplemented by Transfer Impact Assessments under EDPB Recommendations 01/2020. EU-US Data Privacy Framework certification relied upon for DPF-certified recipients where applicable. |
| UK → United States | Same recipients as above. | UK International Data Transfer Addendum to the EU SCCs or UK International Data Transfer Agreement, supplemented by Transfer Impact Assessments. |
| EEA → United Kingdom | Where applicable. | Adequacy decision by the European Commission — no additional safeguard required. |
| EEA / UK → Germany (Sentry) | Sentry ingest endpoint hosted in Germany. | No transfer outside the EEA — no additional safeguard required. |
10. How long we keep your data
| Category of data | Retention period |
| Customer account data (name, email, password hash, federated ID) | For as long as your account is active. Deleted 180 days after the account becomes inactive, unless a longer period is required by law. |
| Multimedia journey data — special category | Stored against your account for as long as the account is active, to allow you to re-share with another provider and to allow the provider you contacted to deliver care. Deleted with the account subject to the provider's separate clinical-record retention obligations. |
| Provider clinical records of your treatment | Retained by the provider for the period required by their own professional and regulatory obligations. MeTime retains its processor copy for the same period in line with the Data Processing Agreement. |
| Provider account data (sign-up, onboarding, profile, payments) | For as long as the provider account is active, plus any statutory retention period for financial records (typically 6-10 years depending on jurisdiction). |
| Transaction and payment records | Retained for the statutory accounting and tax retention period applicable to MeTime and to the provider (typically 6-10 years). |
| Marketing-consent records | Retained for as long as the consent is in force and for two years thereafter to evidence that the consent was given. |
| Server logs, security logs | Retained for the period defined in our information-security policy (typically up to 12 months) and longer for records that form part of an incident response or legal-claim record. |
| Cookies and similar technologies | As listed in our Cookie Policy. |
| DSAR and complaint records | Retained for the period required to demonstrate compliance and to defend any related legal claim. |
Where we identify that a retention period is shorter than the period for which the provider is required to keep clinical records under their own professional obligations, the provider's obligation prevails for the provider's copy of the record.
11. Your rights
11.1 EEA / UK rights
If you are in the EEA or the UK, you have the following rights under GDPR or UK GDPR. We will respond to a request within one month of receipt; we may extend this period by two further months where the request is complex, and we will let you know within the first month if we need to extend.
- Access: the right to obtain confirmation that we process your personal data and a copy of that data.
- Rectification: the right to have inaccurate data corrected or incomplete data completed.
- Erasure: the right to have your personal data erased where one of the grounds in Article 17 GDPR applies; this right is not absolute and we will explain when we cannot delete.
- Restriction: the right to restrict our processing in certain situations.
- Portability: the right to receive personal data you provided to us in a structured, commonly used and machine-readable format, where we process it on the basis of consent or contract by automated means.
- Object: the right to object to processing based on legitimate interest and to direct marketing.
- Withdraw consent: where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
- Lodge a complaint: the right to complain to a supervisory authority — primarily the Irish Data Protection Commission (www.dataprotection.ie) and, for UK data subjects, the UK Information Commissioner's Office (www.ico.org.uk).
- Decisions and profiling: the rights under Article 22 GDPR described in §7.
11.2 US state rights
See §13 for the rights available to residents of California and other US states with comprehensive consumer privacy laws.
11.3 How to exercise your rights
To exercise any of these rights, please email [email protected] from the email address associated with your account or post a written request to our registered office. We may ask you to verify your identity before we act on a request. There is no charge for the first request; we may charge a reasonable fee or refuse the request where it is manifestly unfounded or excessive, and we will tell you why if that is the case.
12. Security
We use appropriate technical and organisational measures to protect personal data. Measures include encryption of personal data in transit, role-based access control, secure software development practices, regular vendor due diligence, and incident response procedures. We treat any unauthorised access, loss or disclosure of personal data as a personal data breach and we notify the Irish Data Protection Commission and any affected individuals where the law requires us to.
MeTime does not currently hold a third-party information-security certification such as ISO/IEC 27001 or SOC 2. We will update this Notice when that position changes.
13. US-state addendum (CCPA/CPRA and equivalent laws)
This §13 applies to personal information of residents of California and supplies the additional disclosures required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). Residents of other US states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana) have similar rights and may rely on the same disclosures except where state law specifically differs.
13.1 Categories of personal information collected and disclosed
| Category of personal information | Collected? | Categories of recipients |
| Identifiers (name, email, federated ID, IP address, device IDs) | Yes | Service providers; identity providers (Google, Apple); analytics; hosting; payment processor; CDN. |
| Customer records (account profile, journey data) | Yes | Same as above; also providers selected by the customer. |
| Characteristics protected under California or US federal law (e.g. age, sex, gender) | Yes | Providers selected by the customer; MeTime internal teams. |
| Commercial information (treatments selected, transactions) | Yes | Providers; payment processor; analytics. |
| Internet or other network activity information | Yes | Analytics; tag manager; advertising tags; CDN. |
| Geolocation data (city / address; precise where device-API granted) | Yes | Providers; matching service. |
| Sensory data (video selfie, photographs) | Yes | Providers; processor for storage. |
| Professional or employment-related information (provider only) | Yes | Marketplace listing; verification. |
| Inferences (e.g. likely treatment, predicted revenue value, AI Smart Filter outputs) | Yes | Providers; MeTime. |
| Sensitive personal information (health, biometric, racial-origin descriptors via Fitzpatrick) | Yes | Providers; processor for storage. |
13.2 Sale or sharing for cross-context behavioural advertising
MeTime does not sell personal information in exchange for money. We may share certain identifiers and online activity information with advertising and analytics partners for cross-context behavioural advertising as that term is defined under CCPA/CPRA, where you have opted in via our cookie banner. You may opt out at any time by adjusting your preferences in the cookie banner, by using the 'Your Privacy Choices' link in the footer of metime.com (when present), or by transmitting a Global Privacy Control signal — which we recognise.
13.3 Sensitive personal information limitation
California residents may direct us to limit our use of sensitive personal information to purposes permitted under CCPA/CPRA section 1798.121. To exercise this right, please email [email protected].
13.4 Other US-state rights
- Right to know: you can request the categories of personal information we have collected, the categories of sources, the purposes for which we collected it, the categories of recipients, and the specific pieces of personal information we have collected about you.
- Right to delete: you can request that we delete your personal information, subject to the legal exceptions in CCPA/CPRA section 1798.105.
- Right to correct: you can request that we correct inaccurate personal information.
- Right to opt out of sale or sharing: as described in §13.2.
- Right to non-discrimination: we will not discriminate against you for exercising any of these rights.
We do not offer financial incentives in exchange for the retention or sale of personal information.
13.5 Authorised agents
An authorised agent may submit a CCPA/CPRA request on your behalf with written authorisation that we can verify. We may ask you to confirm directly that you have authorised the agent.
14. Changes to this Notice
We may update this Notice from time to time. When we make a material change, we will update the 'Last updated' date at the top of this Notice and, where appropriate, notify you by email or via an in-app message. We encourage you to review this Notice periodically.
15. Contact details
If you have any questions about this Notice or about how we handle your personal data, please write to:
Data Protection Officer
MeTime Corporation Limited
5 Fitzwilliam Square East
Dublin 2, Ireland
