Privacy Notice
Last Updated: April 21, 2026
Who are we?
We ("we", "us", "our") are Metasteps P.C., with Headquarters located at Thessalonikis 43, 15234, Chalandri, Greece, a Greek registered company with company ID (VAT number) EL801995649. Metasteps P.C. is the data controller (contact details below). This means it decides how your personal data is processed and for what purposes.
Personal data - what is it?
Personal data relates to a living individual who can be identified from that data. Identification can be by the information alone or in conjunction with any other information in the data controller's possession or likely to come into such possession. The processing of personal data is governed by the General Data Protection Regulation 2016/679 (the "GDPR").
Personal Data we process
a) When you create a Metasteps account, we ask for some personal information that can identify you, including your email address, and a password, which is used to protect your account from unauthorized access. Once you register you can provide other information about yourself, such as your current residence, interests, website, Facebook page, etc. You will also be able to add an image of yourself. Any personal information or exhibitions or content that you voluntarily disclose online (e.g., exhibition caption, exhibition comments, your profile page) may be collected and used by others. We do not knowingly collect personal information from children under the age of 16. If we become aware that personal data of a child under 16 has been collected without appropriate consent or institutional authorization, we will take appropriate steps to delete such data without undue delay.
b) We also process your personal data when you contact us via email or by phone.
c) For orders placed through our platform, we process your billing information (such as name, email address, and billing address) to facilitate your purchase. We share limited data with Stripe, Inc. and Stripe Payments Europe, Ltd., who act as our Merchant of Record and independent data controllers. Stripe is responsible for processing payments, issuing invoices, managing fraud prevention, and handling all tax, VAT, and fiscal obligations associated with your transaction. Stripe processes this data in accordance with its own privacy notice and may transfer data outside the EU using approved safeguards such as Standard Contractual Clauses.
d) When we send you service-related or marketing emails (where you have consented to receive them), we use third-party email delivery services provided by Twilio Inc. (“SendGrid”) and Brevo SAS, formerly known as Sendinblue (“Brevo”). These services automatically collect certain data about your interactions with our emails, including whether an email was opened and which links within the email were clicked. This data is collected via tracking pixels and redirect links embedded in the emails and is associated with your email address.
e) If you are a teacher or administrator on the Academic Plan and connect your institution's Moodle instance to Metasteps, we access your Moodle content via the API token you provide. Through this connection we retrieve and synchronise course names, descriptions, and course resources into your Metasteps 3D spaces. The API token is stored securely and used solely for this purpose. Course content imported from Moodle may incidentally contain personal data where this has been included in course materials by the teacher.
How do we process your personal data?
Metasteps P.C. complies with its obligations under the GDPR by keeping personal data up to date; by storing and destroying it securely; by not collecting or retaining excessive amounts of data; by protecting personal data from loss, misuse, unauthorized access and disclosure and by ensuring that appropriate technical measures are in place to protect personal data.
a) If you submit personal information to Metasteps, we may use that information to operate, maintain, and improve the features and functionality of Metasteps and to facilitate the use of our website. We may also use that information to manage your account and your account activity and to process any flagging activity or other communication you send to us. We do not use your email address or other personal information to send commercial or marketing messages without your consent. We may use your email address without further consent for non-marketing or administrative purposes (such as notifying you of major Metasteps changes).
b) When you contact us via email or phone Metasteps uses information collected to contact you and provide you with the Services you request.
c) We may collect personal data about Users whenever they interact with our Web Site. This includes IP addresses, which are treated as personal data under applicable data protection laws. Non-personal identification information may include the browser name, the type of computer and technical information about Users’ means of connection to the Web Site. IP addresses are processed solely for security purposes and limited technical and statistical analytics necessary to ensure the stability, integrity, and security of our Services. We do not use IP addresses for profiling or marketing purposes.
d) We use email interaction data (opens and link clicks) collected via SendGrid and Brevo to monitor the deliverability and performance of our communications, to understand which content is relevant to our users, and to improve our email communications. We do not use this data for individual profiling or automated decision-making.
What is the legal basis for processing your personal data?
We process your personal data on the basis of contractual necessity, legal obligations, legitimate interests, and, where required, your consent. We collect and process your IP address under special circumstances tο ensure cyber security (legal basis: legitimate interests).
Sharing your personal data
When you create a Metasteps Account, certain information about your Account and your account activity on the Services may be visible to other users of Metasteps. This may include the date you created your Metasteps Account, the number of your published exhibitions, the number of your assets included in your published exhibitions and the number of comments you have made. Your Metasteps Account name, but not your email address, is displayed to other users when you engage in certain activities on Metasteps, such as publishing an exhibition or interacting with other users within the platform. You may also choose to provide additional profile information such as your name, profile image, residence or other details which will be visible to other users in accordance with your account settings. We do not share your personal information with third parties except where necessary to comply with legal obligations, prevent fraud or abuse, protect the safety and security of users and the Services, or where you have been informed in advance and, where required, provided your consent. For payments and billing, limited personal data is shared with Stripe, Inc. and Stripe Payments Europe, Ltd., who act as our Merchant of Record and as independent data controllers. Stripe retains payment‑related data (including transaction records, invoices, tax/VAT information, and fraud‑prevention logs) in accordance with its own legal obligations and retention policies, which may require longer storage periods under financial, tax, and anti‑fraud regulations. Stripe may also transfer data outside the EU using Standard Contractual Clauses and other GDPR‑approved safeguards.
For email communications, limited personal data (email address and email interaction data such as open and click events) is shared with Twilio Inc. (SendGrid) and Brevo SAS (formerly Sendinblue), who act as our data processors. SendGrid and Brevo process this data in accordance with our Data Processing Agreements and their respective privacy practices. SendGrid (Twilio Inc.) is based in the United States; data transfers outside the EEA are protected by Standard Contractual Clauses. Brevo SAS is based in France and processes data within the EEA.
How long do we keep your personal data?
We retain your personal data for as long as your Metasteps account remains active. All user data is securely stored on servers located in Frankfurt, Germany, hosted by DigitalOcean. Metasteps implements appropriate technical and organizational measures designed to comply with EU data protection laws, including the GDPR. We may delete your account and associated personal data if your account remains inactive for an extended period. Before doing so, we will contact you by email and give you the opportunity to keep your account active. You may also delete your account and personal data at any time through your account settings. If you contact us through the website form or by email, we store the information you provide for up to six months to process your request and handle any follow‑up communication. We will not share this information without your consent. Your personal data (IP address) that we use in order to ensure cybersecurity safety will be kept for 1 month from the collection time.
Unless legal obligations require longer retention, the following Data Retention periods apply:
- Free accounts: Active + 6 months after deletion
- Subscription plan accounts: Subscription term + 6 months after deletion
- Support tickets: 9 months
- IP logs: 30 days from collection
- Backups: Encrypted, retained for up to 12 months
- Payment‑related data (via Stripe): Retained by Stripe according to financial, tax, and regulatory requirements
Use of Artificial Intelligence Technologies
Metasteps uses AI technologies to power certain features of the platform (“AI Features”).
The AI Features are provided by OpenAI, LLC, and currently power one feature: the Pythia Editor. When a user types a natural-language description of a 3D space they wish to build, OpenAI processes that text prompt to recommend matching templates and environmental assets. No other platform features use AI. Only the text prompt is transmitted to OpenAI — no user identifiers, account information, or session metadata are included.
The personal data that may be transmitted to an AI Provider may include:
- The text prompt a user types into the Pythia Editor (e.g. a description of the 3D space a user wishes to build), which may incidentally contain personal data entered by the user themselves.
- No user identifiers, account information, or session metadata are transmitted to OpenAI alongside the prompt.
Metasteps strongly advises users not to input special category personal data (as defined in Article 9 GDPR) or personal data relating to children into the AI Features. Users are responsible for ensuring that any personal data entered into the platform relates only to data subjects whose personal data are lawfully processed and who have been informed of this Privacy Notice.
Under the EU GDPR, we rely on the following legal basis/bases for processing personal data in connection with the AI Features:
- Contract Performance (Art. 6(1)(b)) GDPR: Where processing is necessary to provide you with the AI Features you have requested as part of our service to you.
- Legitimate Interests (Art. 6(1)(f)) GDPR: Where processing is necessary for our legitimate interest in improving our service, and detecting/preventing misuse of the AI Features, provided this is not overridden by your interests or rights.
OpenAI acts as our data processor when processing personal data contained in the inputs solely to provide the API services to us. We have entered into a Data Processing Agreement (“DPA”) with OpenAI. This DPA contractually requires OpenAI to:
- Process personal data only on our documented instructions and for the purposes described in this Privacy Notice.
- Implement appropriate technical and organizational security measures.
- Process Customer Data only to deliver the Services and not for any other purpose, including training or improving AI models, in accordance with Customer’s documented instructions under the DPA.
- Delete or return personal data upon termination of our agreement.
- Maintain a list of their own sub-processors and notify us of changes.
- OpenAI’s sub-processor list is available at: platform.openai.com/subprocessors
OpenAI is based in the United States. When your personal data is transmitted to them, it is transferred outside the European Economic Area (EEA). We ensure that appropriate safeguards are in place for such transfers as follows:
- Provider: OpenAI
- Transfer Mechanism: EU Standard Contractual Clauses (2021) — Module 2 (Controller to Processor); UK Addendum for UK data (per Section 4.2 of OpenAI’s DPA)
- Further Detail: The SCCs are incorporated into our DPA with OpenAI. A copy is available on request.
You can request a copy of the relevant transfer mechanism documentation by contacting our Data Protection Officer (DPO) at [email protected]
Personal data transmitted to the AI Provider via the API is retained by them only for a limited period for safety monitoring and abuse prevention purposes. Based on AI provider’s current API usage policy (separate from the DPA) :
- AI Provider: OpenAI
- Retention Period (API): Per OpenAI’s API usage policy (separate from the DPA), API inputs and outputs may be retained for a limited period for safety monitoring and abuse prevention purposes, after which they are deleted. API data is not used for model training. Retention periods are subject to change; refer to OpenAI’s current published policies at openai.com for the most up-to-date information.
Please note that retention periods are subject to change by the AI Provider. We will update this Privacy Notice if we become aware of material changes. For the most current information, please refer to the AI provider’s privacy policy.
The Pythia Editor uses AI to make recommendations about 3D templates and environmental assets based on a user’s text description. This does not constitute automated decision-making within the meaning of Article 22 GDPR - no decision is made that produces legal effects or similarly significantly affects you. Metasteps does not use the AI Features for profiling.
Your rights in relation to personal data processed via the AI Features are the same as those described in the ‘Your rights and your personal data’ section below. Please note one additional consideration specific to AI processing:
Right to erasure: Once data has been transmitted to OpenAI, our ability to retrieve it for deletion purposes is limited to the extent provided in our DPA with that provider. Where possible we will action erasure requests, but we cannot guarantee retrieval of data already processed by the API within OpenAI’s applicable retention period under their API usage policy.
In the future, Metasteps may use anonymised or aggregated data derived from platform usage - including text prompts submitted via the Pythia Editor - to train, test, or improve our own internal AI systems and features. We will only do so where we have a valid legal basis under applicable data protection law, which will either be the user's explicit consent or another basis notified to the user in advance. We will update this Privacy Notice and notify the user before any such processing begins. Users will always have the right to withdraw consent.
To exercise any of your rights, please contact our Data Protection Officer (DPO) at [email protected]
Moodle Integration
For Academic Plan users who connect their institution's Moodle instance to Metasteps, the following additional information applies:
What we access: We retrieve and synchronise course content - including course names, descriptions, and resources - using the API token you provide. This integration is available to administrators only. We do not access student data, enrolment records, grades, or any other student-related information through this integration.
Your responsibilities as teacher/administrator: You are the data controller of the content you import. You are responsible for ensuring that course materials imported into Metasteps do not contain personal data beyond what is necessary, that you have the appropriate rights to share that content via the integration, and the content complies with Metasteps’ Terms of Service.
API token: The token grants Metasteps access to your Moodle instance, scoped to the services and permissions you configure. We strongly recommend using a dedicated Moodle API user with minimum necessary permissions rather than an administrator account. You can revoke access at any time by disconnecting the integration in your settings or invalidating the token in Moodle.
Ongoing sync: The integration operates on a continuous basis and syncs changes automatically. Metasteps retains access to your Moodle content until you disconnect the integration.
Legal basis: We process this data on the basis of contract performance (Art. 6(1)(b) GDPR), as it is necessary to deliver the Moodle Integration feature you have requested.
Your rights and your personal data
You have the following rights with respect to your personal data:
Right of access: You may request a copy of the personal data that Metasteps holds about you.
Right to rectification: You may request that Metasteps correct any personal data that is inaccurate or incomplete. If you have a Metasteps Account, you may update or correct your profile information and account settings (including your email and password) at any time through your settings page.
Right to erasure: You may request the deletion of your personal data where it is no longer necessary for Metasteps to retain it. If you have a Metasteps Account, you may delete your account and all associated data at any time through your privacy settings.
Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time.
Right to restriction of processing: You may request that Metasteps restrict the processing of your personal data where there is a dispute regarding accuracy or where you object to the processing.
Right to object: You may object to the processing of your personal data where Metasteps relies on legitimate interests as the legal basis.
Right to data portability: Where applicable, you may request to receive your personal data in a structured, commonly used, and machine‑readable format and to have it transmitted to another controller.
Right to lodge a complaint: You may lodge a complaint with the Hellenic Data Protection Authority (HDPA) or with your local supervisory authority if you believe your rights have been violated.
Further processing
If we wish to use your personal data for a new purpose, not covered by this Privacy Notice, then we will provide you with a new notice explaining this new use prior to commencing the processing and setting out the relevant purposes and processing conditions. Where and whenever necessary, we will seek your prior consent to the new processing.
Links
This website contains links to other sites. Please be aware that we are not responsible for the content or privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of any other site that collects personally identifiable information.
Cookies
Cookies are small text files placed on your device by a website when you visit it. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. Cookies allow web applications to respond to you as an individual. The web application can improve functionality and user experience by gathering and remembering information about your preferences. We classify cookies in the following categories:
Strictly Necessary Cookies
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually set in response to actions you take, such as logging in, setting privacy preferences, or filling in forms. You may configure your browser to block these cookies, but some parts of the site may not function properly.
Performance Cookies
We may use Analytics cookies provided by Google Inc. (Google Analytics) to identify which pages are being used. This helps us analyze data about webpage traffic and improve our Products in order to tailor them to our users' needs. We only use this information for statistical analysis purposes. IP addresses are pseudonymized before storage. As a result, only a rough localization is possible. You can choose to accept or decline cookies. Google Analytics is used in accordance with Google’s privacy policy, and Google acts as a data processor under GDPR-compliant terms.
Targeting Cookies
Metasteps does not use targeting or advertising cookies by default. If such cookies are ever used, they will only be activated after you provide explicit consent. Targeting cookies are never used in private or restricted‑access areas of the platform.
Functionality Cookies
Functionality cookies enable enhanced features and personalization. They may be set by Metasteps or by third‑party providers whose services we integrate. If you disable these cookies, some features may not function correctly. When cookies are deployed, you can always manage or withdraw your consent. You may configure your cookie preferences at any time using the cookie settings icon located at the bottom left of the page.
Contact Details
To exercise any of your rights, or for any questions or concerns regarding this Privacy Notice or the processing of your personal data, you may contact our Data Protection Officer (DPO) at [email protected]
If you wish to learn more about how Stripe processes personal data, Stripe’s privacy notice is available at: https://stripe.com/privacy
If you wish to learn more about how OpenAI processes personal data, OpenAI's privacy policy is available at: https://openai.com/policies/privacy-policy