Legal

Privacy Policy

Effective date: 28 May 2026

Last updated: 28 May 2026

1. Who we are

This website, mettafi.com (“the Site”), is operated by [MettaFi legal entity name — to be confirmed], [entity type — e.g. company / sole proprietorship — to be confirmed], registered in [jurisdiction of registration — to be confirmed] [registration number — to be confirmed] (“MettaFi”, “we”, “us”, “our”).

MettaFi is an agency and platform serving Buddhist teachers, monastics, and Buddhist organisations. For the purposes of data protection law, we act as the data controller for personal information collected through this Site.

If you have any questions about this policy or how we handle your personal information, contact us at connect@mettafi.com.

2. Scope of this policy

This policy explains what personal information we collect through mettafi.com, why, how we use and protect it, who we share it with, and your rights.

It is written to comply with the personal-data laws that most commonly apply to our visitors, including:

  • The EU General Data Protection Regulation (GDPR) and the UK GDPR
  • The California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA)
  • The Australian Privacy Act 1988 and the Australian Privacy Principles
  • The Hong Kong Personal Data (Privacy) Ordinance (PDPO)
  • Canada's PIPEDA
  • Brazil's LGPD

Where these laws grant you specific rights, we honour them — see Section 8.

3. What personal information we collect

We collect only what we need:

Information you give us directly:

  • Newsletter / waitlist signup — your email address, and your name if you provide it, when you join our mailing list or waitlist.
  • Contact form / email — your name, email address, and the content of your message when you contact us.
  • Discovery-call booking (Calendly) — when you book a call with us through our Calendly scheduling tool, Calendly collects your name, email address, the time you book, and any information you provide in the booking form, and shares it with us so we can hold the call. This data is processed by Calendly on our behalf and is also subject to Calendly's own privacy policy.

Information collected automatically:

  • Basic technical information — our hosting providers log standard technical data (IP address, browser type, device type, referring page, pages viewed) for security, troubleshooting, and site operation. We do not use analytics or tracking tools on this Site.
  • Cookies — see our separate Cookie Policy. We do not set advertising or analytics cookies of our own; some third-party functional cookies are involved with the Calendly booking tool.

We do not intentionally collect sensitive personal information through this Site. Please do not send sensitive information through the contact form.

4. Why we collect it and our legal basis

What we collectWhyLegal basis (GDPR)
Newsletter/waitlist emailTo send updates you asked forConsent
Contact form detailsTo respond to your enquiryLegitimate interest / steps prior to a contract
Calendly booking detailsTo schedule and hold a call you requestedSteps prior to a contract / consent
Technical/server logsSecurity, troubleshooting, site operationLegitimate interest

You can withdraw consent at any time — unsubscribe from emails using the link in any message, or email connect@mettafi.com.

5. Who we share it with

We do not sell your personal information. We never have and we never will.

We share personal information only with the third-party providers who help us operate the Site, to the extent they need it:

  • Vercel (United States) — website hosting and content delivery.
  • GitHub (United States) — source-code hosting (does not process visitor personal data in normal operation).
  • Brevo (European Union) — email newsletter/waitlist management and delivery.
  • Calendly (United States) — discovery-call scheduling. When you book a call, your booking details are processed by Calendly.

Each provider processes data under its own privacy and security commitments. Where they are located outside your home jurisdiction, your data may be transferred internationally — see Section 6.

We may also disclose personal information where required by law, regulation, court order, or governmental authority with valid jurisdiction; or where necessary to protect our legal rights.

6. International data transfers

Our service providers are located in the United States (Vercel, GitHub, Calendly) and the European Union (Brevo), and we may operate from [jurisdiction — to be confirmed], Hong Kong, and Australia. This means your personal information may be processed in, and transferred between, these and other jurisdictions where our providers operate.

Where personal information is transferred out of a jurisdiction whose laws require specific safeguards (such as the EU/UK under GDPR), we rely on appropriate legal mechanisms for such transfers (such as standard contractual clauses or adequacy arrangements maintained by our providers). By using the Site, you understand your information may be processed in these locations.

7. How long we keep it

  • Newsletter/waitlist subscribers — until you unsubscribe, then removed from the active list within a reasonable period.
  • Contact enquiries — as long as needed to handle your enquiry, plus a reasonable record-keeping period, then deleted.
  • Calendly bookings — retained for as long as needed to hold and follow up on the call, then handled per our records-retention practice and Calendly's own retention.
  • Server logs — retained for a limited period by our hosting providers.

We do not keep personal information longer than necessary.

8. Your rights

Depending on where you live, you have some or all of the following rights:

  • Access — a copy of the personal information we hold about you.
  • Correction — correct inaccurate or incomplete information.
  • Deletion / erasure — ask us to delete your personal information.
  • Withdraw consent — unsubscribe or otherwise withdraw consent at any time.
  • Object / restrict — object to or restrict certain processing (GDPR/UK GDPR).
  • Portability — your data in a portable, machine-readable format.
  • Non-discrimination — we will not treat you differently for exercising your rights (CCPA/CPRA).
  • Do Not Sell / Share — we do not sell or share personal information for cross-context behavioural advertising; you retain the right to direct us not to (CCPA/CPRA).

To exercise any right, email connect@mettafi.com. We will respond within the timeframe required by the law applicable to you (for example, one month under GDPR; 45 days under CPRA). We may need to verify your identity first.

You also have the right to complain to your local data protection authority — for example, the EU/UK supervisory authorities, the OAIC in Australia, or the PCPD in Hong Kong.

9. How we protect your information

We take reasonable technical and organisational measures to protect personal information against loss, misuse, and unauthorised access. Our providers (Vercel, Brevo, Calendly, GitHub) maintain their own industry-standard security. However, no internet transmission is completely secure, and we cannot guarantee absolute security.

10. Children

This Site is not directed at children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us with personal information, contact connect@mettafi.com and we will delete it.

11. Links to other sites

The Site links to other websites, including zadalau.com and external pages. We are not responsible for the privacy practices of other sites. We encourage you to read their privacy policies.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date shows when. Significant changes will be communicated where appropriate. Continued use of the Site after a change means you accept the updated policy.

13. Contact

Email: connect@mettafi.com

Operated by: [MettaFi legal entity name — to be confirmed], [jurisdiction — to be confirmed]

Postal address: [to be confirmed]