This Privacy Policy explains how MeaningStack B.V. processes personal data in connection with meaningstack.com and kamiraflow.com. It covers our own activities as a data controller. Where we process customer data through the Services on a customer's behalf, we act as a processor under a separate Data Processing Agreement.
01 Controller and Contact
MeaningStack B.V. ("we," "us," "our") is the controller for personal data processed through meaningstack.com and kamiraflow.com.
- Registered office: Papenweg 18, 6212 CG Maastricht, Netherlands · KvK 42064215
- Privacy contact: Luciana Ledesma, admin@meaningstack.com
We have appointed a privacy contact to handle data-protection questions and requests. We are not currently required to appoint a statutory Data Protection Officer; should that change, we will publish the DPO's contact details here.
02 Roles: Controller vs. Processor
Websites & marketing — we are the controller. For the data described in this Policy (enquiries, demo and waitlist requests, analytics, and similar), we determine the purposes and means of processing.
The Services (KamiraFlow, Steward, and other MeaningStack products) — we are the processor. When a customer sends us AI reasoning traces and related data for governance evaluation, we process it on the customer's behalf and on their instructions. That processing is governed by our Data Processing Agreement (DPA), not this Policy. This Policy covers our own controller activities only.
03 What We Collect, Why, and on What Lawful Basis
| Data | Purpose | Lawful basis (Art. 6) |
|---|---|---|
| Name, email, company, message (contact / demo / waitlist forms) | Respond to enquiries, arrange demos, manage the waitlist, sales | 6(1)(b) pre-contract · 6(1)(f) legitimate interest |
| Email, marketing preferences | Send requested materials and updates | 6(1)(a) consent |
| Account / login data (if applicable) | Provide access to the Services | 6(1)(b) contract |
| Interface preferences, saved views, role / usage signals | Personalize your experience (see §05) | 6(1)(b) contract · 6(1)(a) consent · 6(1)(f) legitimate interest |
| Cookies & similar (analytics, embedded forms) | Measure and improve the Websites | 6(1)(a) consent (non-essential) · 6(1)(f) (strictly necessary) |
| Server logs, IP, device / browser data | Security, fraud prevention, stability | 6(1)(f) legitimate interest |
We do not intentionally collect special-category data through the Websites. Please do not submit it.
04 AI Training — Our Commitment
We do not train AI models on personal data by default. Where we improve our models, we use only:
- (a) Genuinely anonymized data — altered through a documented, tested process such that individuals can no longer be identified by any reasonable means. Anonymized data falls outside the GDPR.
- (b) Explicit opt-in consent — data used with your specific, withdrawable consent (for example, the optional CTQ data export available in the Services).
We do not treat the mere removal of obvious identifiers ("pseudonymization") as anonymization. Pseudonymized data remains personal data and is not used for training without a lawful basis. Customer trace data processed through any of the Services (including KamiraFlow and Steward) under the DPA is never used to train our models except on documented customer instruction or genuine anonymization as above.
Data used to personalize your experience (see §05) is held on a separate data plane and is never used to train our models.
05 Personalization and Profiling
We may tailor aspects of the Services and Websites to you — for example, showing a dashboard scoped to your organization's own agents and alerts, remembering your interface preferences and saved views, or prioritizing the information most relevant to your role.
Lawful bases
- Contract (Art. 6(1)(b)) where personalization is part of the Service you purchased — for example, presenting your organization's own governance data in your dashboard. This is core functionality, not optional tailoring.
- Consent (Art. 6(1)(a)) for optional personalization beyond core functionality, which you can enable or withdraw at any time.
- Legitimate interest (Art. 6(1)(f)) for low-risk conveniences you would reasonably expect, such as remembering UI preferences. You may object at any time.
Separation from training
Personalization data is identified data tied to your account. It lives on a separate data plane from any data used for model improvement, and the two do not mix. Personalization data is never used to train our models.
Automated decisions and human oversight (Art. 22)
Where the Services evaluate AI reasoning, flag concerns, or recommend interventions, these outputs are designed to support human decision-making, not to replace it. The Services provide human-in-the-loop oversight so that decisions producing legal or similarly significant effects are not taken solely by automated means without meaningful human involvement. Where our customer operates the Services in relation to their own end-users, the customer is the controller for that processing and is responsible for the Article 22 safeguards owed to those individuals; our DPA sets out the respective responsibilities.
Your controls
To review or change your personalization settings, withdraw optional-personalization consent, or object to legitimate-interest personalization, email us at admin@meaningstack.com and we will action your request.
06 Cookies and Consent
We use strictly necessary cookies (always on) and, only with your consent, analytics and functional cookies. Non-essential cookies and third-party scripts (including embedded forms) do not load before you consent. You can change or withdraw consent at any time via Cookie Settings . Full details are set out in our Cookie Policy .
07 Processors and Third Parties
We share personal data only with vetted processors under GDPR Article 28 contracts. Our current processors:
| Processor | Purpose | Location / safeguard |
|---|---|---|
| Cookiebot (Usercentrics) | Cookie consent management — records and stores your consent choices (consent ID, timestamp, IP) | EU (Germany) |
| HubSpot | Forms (functional) and marketing / traffic analytics (consent-based) | EU hosting / SCCs |
| Cloudflare | Content delivery, bot management and security (processes visitor traffic, including IP addresses) | EU config / SCCs |
| Railway | Application hosting & infrastructure | May host outside EEA — SCCs |
| Google Workspace (Gmail) | Business email & correspondence | SCCs / Google EU terms |
We do not sell personal data.
08 International Transfers
We aim to keep personal data within the European Economic Area (EEA) where practical. Some of our infrastructure providers may process data outside the EEA. Where that happens, we rely on an adequacy decision, the EU–US Data Privacy Framework, or EU Standard Contractual Clauses (SCCs) with supplementary measures where required, so that your data continues to receive an equivalent level of protection. Details of any such transfer are available on request.
09 Retention
We keep personal data only for as long as necessary for the purposes described in this Policy, or as required by law. In practice this means:
- Enquiry, demo, and waitlist data: for as long as needed to respond and follow up, and a reasonable period afterwards for our records.
- Marketing data: until you withdraw consent or ask us to stop.
- Account data: for the duration of your relationship with us, and a limited period afterwards.
- Security and server logs: for a short period, for security and stability purposes.
When personal data is no longer needed, we delete it or anonymize it. You can ask us about retention of your data at any time.
10 Your Rights
You have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent at any time (without affecting prior lawful processing). To exercise any right, contact admin@meaningstack.com. We respond within one month.
You may also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with your local supervisory authority.
11 Security
We implement appropriate technical and organizational measures under GDPR Article 32 to protect personal data. These include encryption of data in transit (TLS), access controls on a least-privilege basis, and use of reputable infrastructure providers who maintain their own recognized security certifications. We keep our security measures under review and improve them as we grow.
12 Children
The Websites are not directed at children under 16, and we do not knowingly collect their personal data.
13 Changes
We post updates here with a revised "Last updated" date and notify you of material changes where required.
14 Contact
Questions about this Policy or your personal data can be directed to us by email or post.
Papenweg 18, 6212 CG
Maastricht, the Netherlands