→ Legal

Privacy Policy

Last updated · 4 June 2026 Entity · MeaningStack B.V. KvK · 42064215

This Privacy Policy explains how MeaningStack B.V. processes personal data in connection with meaningstack.com and kamiraflow.com. It covers our own activities as a data controller. Where we process customer data through the Services on a customer's behalf, we act as a processor under a separate Data Processing Agreement.

01 Controller and Contact

MeaningStack B.V. ("we," "us," "our") is the controller for personal data processed through meaningstack.com and kamiraflow.com.

  • Registered office: Papenweg 18, 6212 CG Maastricht, Netherlands · KvK 42064215
  • Privacy contact: Luciana Ledesma, admin@meaningstack.com

We have appointed a privacy contact to handle data-protection questions and requests. We are not currently required to appoint a statutory Data Protection Officer; should that change, we will publish the DPO's contact details here.

02 Roles: Controller vs. Processor

Websites & marketing — we are the controller. For the data described in this Policy (enquiries, demo and waitlist requests, analytics, and similar), we determine the purposes and means of processing.

The Services (KamiraFlow, Steward, and other MeaningStack products) — we are the processor. When a customer sends us AI reasoning traces and related data for governance evaluation, we process it on the customer's behalf and on their instructions. That processing is governed by our Data Processing Agreement (DPA), not this Policy. This Policy covers our own controller activities only.

03 What We Collect, Why, and on What Lawful Basis

DataPurposeLawful basis (Art. 6)
Name, email, company, message (contact / demo / waitlist forms) Respond to enquiries, arrange demos, manage the waitlist, sales 6(1)(b) pre-contract · 6(1)(f) legitimate interest
Email, marketing preferences Send requested materials and updates 6(1)(a) consent
Account / login data (if applicable) Provide access to the Services 6(1)(b) contract
Interface preferences, saved views, role / usage signals Personalize your experience (see §05) 6(1)(b) contract · 6(1)(a) consent · 6(1)(f) legitimate interest
Cookies & similar (analytics, embedded forms) Measure and improve the Websites 6(1)(a) consent (non-essential) · 6(1)(f) (strictly necessary)
Server logs, IP, device / browser data Security, fraud prevention, stability 6(1)(f) legitimate interest

We do not intentionally collect special-category data through the Websites. Please do not submit it.

04 AI Training — Our Commitment

We do not train AI models on personal data by default. Where we improve our models, we use only:

  • (a) Genuinely anonymized data — altered through a documented, tested process such that individuals can no longer be identified by any reasonable means. Anonymized data falls outside the GDPR.
  • (b) Explicit opt-in consent — data used with your specific, withdrawable consent (for example, the optional CTQ data export available in the Services).

We do not treat the mere removal of obvious identifiers ("pseudonymization") as anonymization. Pseudonymized data remains personal data and is not used for training without a lawful basis. Customer trace data processed through any of the Services (including KamiraFlow and Steward) under the DPA is never used to train our models except on documented customer instruction or genuine anonymization as above.

Data used to personalize your experience (see §05) is held on a separate data plane and is never used to train our models.

05 Personalization and Profiling

We may tailor aspects of the Services and Websites to you — for example, showing a dashboard scoped to your organization's own agents and alerts, remembering your interface preferences and saved views, or prioritizing the information most relevant to your role.

Lawful bases

  • Contract (Art. 6(1)(b)) where personalization is part of the Service you purchased — for example, presenting your organization's own governance data in your dashboard. This is core functionality, not optional tailoring.
  • Consent (Art. 6(1)(a)) for optional personalization beyond core functionality, which you can enable or withdraw at any time.
  • Legitimate interest (Art. 6(1)(f)) for low-risk conveniences you would reasonably expect, such as remembering UI preferences. You may object at any time.

Separation from training

Personalization data is identified data tied to your account. It lives on a separate data plane from any data used for model improvement, and the two do not mix. Personalization data is never used to train our models.

Automated decisions and human oversight (Art. 22)

Where the Services evaluate AI reasoning, flag concerns, or recommend interventions, these outputs are designed to support human decision-making, not to replace it. The Services provide human-in-the-loop oversight so that decisions producing legal or similarly significant effects are not taken solely by automated means without meaningful human involvement. Where our customer operates the Services in relation to their own end-users, the customer is the controller for that processing and is responsible for the Article 22 safeguards owed to those individuals; our DPA sets out the respective responsibilities.

Your controls

To review or change your personalization settings, withdraw optional-personalization consent, or object to legitimate-interest personalization, email us at admin@meaningstack.com and we will action your request.

06 Cookies and Consent

We use strictly necessary cookies (always on) and, only with your consent, analytics and functional cookies. Non-essential cookies and third-party scripts (including embedded forms) do not load before you consent. You can change or withdraw consent at any time via Cookie Settings . Full details are set out in our Cookie Policy .

07 Processors and Third Parties

We share personal data only with vetted processors under GDPR Article 28 contracts. Our current processors:

ProcessorPurposeLocation / safeguard
Cookiebot (Usercentrics)Cookie consent management — records and stores your consent choices (consent ID, timestamp, IP)EU (Germany)
HubSpotForms (functional) and marketing / traffic analytics (consent-based)EU hosting / SCCs
CloudflareContent delivery, bot management and security (processes visitor traffic, including IP addresses)EU config / SCCs
RailwayApplication hosting & infrastructureMay host outside EEA — SCCs
Google Workspace (Gmail)Business email & correspondenceSCCs / Google EU terms

We do not sell personal data.

08 International Transfers

We aim to keep personal data within the European Economic Area (EEA) where practical. Some of our infrastructure providers may process data outside the EEA. Where that happens, we rely on an adequacy decision, the EU–US Data Privacy Framework, or EU Standard Contractual Clauses (SCCs) with supplementary measures where required, so that your data continues to receive an equivalent level of protection. Details of any such transfer are available on request.

09 Retention

We keep personal data only for as long as necessary for the purposes described in this Policy, or as required by law. In practice this means:

  • Enquiry, demo, and waitlist data: for as long as needed to respond and follow up, and a reasonable period afterwards for our records.
  • Marketing data: until you withdraw consent or ask us to stop.
  • Account data: for the duration of your relationship with us, and a limited period afterwards.
  • Security and server logs: for a short period, for security and stability purposes.

When personal data is no longer needed, we delete it or anonymize it. You can ask us about retention of your data at any time.

10 Your Rights

You have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent at any time (without affecting prior lawful processing). To exercise any right, contact admin@meaningstack.com. We respond within one month.

You may also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with your local supervisory authority.

11 Security

We implement appropriate technical and organizational measures under GDPR Article 32 to protect personal data. These include encryption of data in transit (TLS), access controls on a least-privilege basis, and use of reputable infrastructure providers who maintain their own recognized security certifications. We keep our security measures under review and improve them as we grow.

12 Children

The Websites are not directed at children under 16, and we do not knowingly collect their personal data.

13 Changes

We post updates here with a revised "Last updated" date and notify you of material changes where required.

14 Contact

Questions about this Policy or your personal data can be directed to us by email or post.

Privacy contact
Post
MeaningStack B.V.
Papenweg 18, 6212 CG
Maastricht, the Netherlands