metisora — Privacy Policy
Version 2.0 — last updated 29 September 2026
This is a convenience translation. The German version of this policy is the authoritative one and is available at
https://app.metisora.com/legal/privacy.
This policy explains how Julian Miksch, trading as metisora ("metisora", "we"),
processes personal data when
you use the metisora application at app.metisora.com and when you contact us. It is provided under Articles 13 and 14 of the General Data Protection
Regulation (GDPR).
1. Two different roles — please read this first
metisora processes personal data in two distinct roles, and your rights are exercised in different places depending on which applies.
1.1 Data from your employer's Salesforce organisation — we are a processor
If your employer is a metisora customer, the application contains data extracted from your employer's Salesforce organisation: opportunities, accounts, contacts, activities, and the names of the sales representatives who own the deals. We process that data only on your employer's instructions. Your employer is the controller; we are its processor under Art. 28 GDPR.
If you are a sales representative, a contact or an account manager appearing in that data, please direct any request about it to your employer, not to us. Your employer's own privacy notice governs that processing. If you contact us anyway, we will pass your request to the relevant customer and inform you that we have done so.
Section 6 of this policy describes that processing anyway, for transparency, because we think you are entitled to know what we do with it.
1.2 Data we process for our own purposes — we are a controller
For everything described in sections 3, 4 and 5 — your metisora user account, our contract and billing relationship, and your correspondence with us — we are the controller and this policy applies in full.
2. Controller and contact
metisora — Julian Miksch
Schlott 24, 86558 Hohenwart, Germany
E-mail: info@metisora.com
Telephone: +49 151 70 19 19 90
Data protection officer: we are not required to appoint one. § 38(1) BDSG requires a data protection officer only where at least 20 people are constantly engaged in automated processing, and Art. 37(1) GDPR where processing on a large scale is a core activity; neither applies to us. For all data protection matters please contact us at the address above.
3. Your metisora user account
What we process
| Data | Where it comes from |
|---|---|
| Salesforce User ID | Your employer's Salesforce organisation, at sign-in |
| Name and e-mail address | Your employer's Salesforce organisation, at sign-in |
| Role in metisora (administrator or member) | Set by your employer's administrator or by us at provisioning |
| Time of last sign-in | Generated on sign-in |
| Session data (a random session identifier, your user and organisation reference) | Generated on sign-in, held in our session store |
| Your interface language | Your own setting |
We store no password. Authentication runs entirely through Salesforce single sign-on; we never see your Salesforce credentials.
Why, and on what legal basis
- To give you access to the application and keep your session working. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and your employer's, is that the service it has contracted for can actually be used, and that access is attributable to a specific person.
- To secure the application — to detect and investigate unauthorised access attempts and abuse. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in the security of our systems and of our customers' data.
How long
Your account exists for as long as your employer's contract runs and you remain a user. It is deleted when your employer's organisation is closed (see section 7). Session records expire automatically 14 days after they are created, or immediately when you sign out.
4. Contract, billing and correspondence
If you are a contact person at a customer or a prospective customer, we process your name, business contact details, your company and role, the content of our correspondence, and the contractual and billing data belonging to it.
- To conclude and perform the contract, and to answer pre-contractual enquiries. Legal basis: Art. 6(1)(b) GDPR, or Art. 6(1)(f) GDPR where you are a contact person for a corporate customer rather than the contracting party yourself.
- To comply with commercial and tax record-keeping duties. Legal basis: Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB.
- To send information about our own similar services to existing customers, where permitted. Legal basis: Art. 6(1)(f) GDPR and § 7(3) UWG. You may object at any time at no cost beyond basic transmission charges.
How long: correspondence for up to three years after the end of the calendar year in which the matter closed; contractual and accounting records for six or ten years as required by § 147 AO and § 257 HGB, after which they are deleted.
5. When you use the application — cookies, storage and logs
5.1 Cookies
We use only strictly necessary cookies. We do not use analytics, tracking, advertising, profiling or social-media cookies, and we embed no third-party content that sets them. For this reason no consent banner appears and none is required: the exemption in § 25(2) no. 2 TDDDG applies, and the legal basis for the processing that follows is Art. 6(1)(f) GDPR.
| Cookie | Purpose | Lifetime | Properties |
|---|---|---|---|
metisora_session | Keeps you signed in. Contains a random identifier only; no personal data is stored in the cookie itself | 14 days | HttpOnly, Secure, SameSite=Lax |
metisora_preauth | Protects the Salesforce sign-in against cross-site request forgery (OAuth 2.0 state and PKCE verifier) | 5 minutes | HttpOnly, Secure, SameSite=Lax |
metisora_lang | Remembers your interface language, so that pages are shown in it from the first request. Contains only the language code (de or en), taken from your own setting | 1 year | SameSite=Lax |
5.2 Local storage in your browser
The application stores the identifier of the Scope you last had open in your browser's
localStorage, so that it can reopen it. This never leaves your browser and is not
transmitted to us. You can clear it at any time through your browser settings.
5.3 Server and access logs
Our hosting provider and our application record technical log data: timestamps, request paths, HTTP status codes, response times, IP addresses, and internal identifiers for the organisation, the user and the affected Salesforce records. We use these logs solely to operate, troubleshoot and secure the service. Legal basis: Art. 6(1)(f) GDPR. They are retained for 30 days by our hosting provider and are not used to analyse your behaviour.
6. Data from your employer's Salesforce organisation
We act here as a processor. This section is for transparency; see section 1.1.
What is extracted
On your employer's instruction, and using an access authorisation your employer granted, we extract from its Salesforce organisation: opportunities (including name, stage, amount, close date, owner, account, loss reason), the stage-change history of those opportunities, stage definitions, opportunity line items (including the product's name, family and code), opportunity contact roles, accounts, contacts, activities (tasks and events) and the names of Salesforce users. Your employer chooses which of these objects are extracted and over what period. For opportunities, opportunity line items and accounts, every field the Salesforce user who authorised the connection can read is extracted, including your employer's own custom fields; your employer limits this through that user's field-level security in Salesforce.
Personal data appears in this set principally as: the names of your employer's own sales representatives (as deal owners and as members of the sales hierarchy), and the names, job titles and roles of contacts at your employer's customers and prospects.
What we do with it
We compute how deals actually moved through the sales process — conversion between stages, cycle length, deal size, loss reasons, forecast accuracy — and we compute the metisora SPI Score. Results can be displayed for the whole organisation or for a level or member of the sales hierarchy your employer has configured.
How deals developed over time
To show how deals developed, we keep a change history: each time a new extraction arrives, we record what differs from the previous one — for every opportunity, opportunity line item, opportunity contact role and account, which record was created or deleted, and which field changed from which value to which, within which week. This includes changes of the deal owner, so the history shows which sales representative owned a deal at which time. We also keep Salesforce's own field-change history for opportunities, which Salesforce itself deletes after 18 to 24 months. The change history is used for the same purposes as the rest of the extracted data (above) and is subject to the same limits, including that it is not used to evaluate individual employees.
Planning in the Sales Strategizer
Your employer's users can plan improvement work in the application's Sales Strategizer:
- Initiatives follow one key figure of the whole Scope — the win rate, for example — across the weekly snapshots. They relate to no individual. A user can add a short free-text description to an initiative, which is stored as entered.
- Weekly clean-up lists collect deals that need attention in a given calendar week — for example, open deals without a stage change for 60 days or more. Each list is assigned to a named member of the sales hierarchy. For every deal on it, the list records whether it was dealt with that week — ticked off by a user, or found resolved in a later extraction — and when. A list therefore shows, for a named sales representative and a given week, how much of it was completed, and a list from a past week that was not completed is shown as "not done". Open items can be carried over into the following week. We store the representative's Salesforce User ID, not their name; the name is read from the latest extraction whenever a list is shown. We do not record which user ticked a deal off.
- The weekly snapshots also record, for the whole Scope and for each member of the sales hierarchy, how many open deals had gone 60 days or more without a stage change.
These functions serve the same purposes as the rest of the extracted data and are subject to the same limits, including that they are not used to evaluate individual employees (section 9).
Where it goes outside our systems
Parts of the analysis are turned into written findings by a large language model operated by Anthropic PBC (United States). What is sent depends on the function:
- Most functions send aggregated figures — counts, rates, averages. Where a view is narrowed to one member of the sales hierarchy, they also send that member's name and level, so that the findings say whose figures they are.
- The loss-reason themes send the loss reasons written in Salesforce, without any deal, account or owner field. These are free texts, and may themselves contain names.
- One function, the drill-down summary for a segment, additionally sends a sample of individual deals. That sample includes the deal name, the account name and the name of the deal owner.
- The business-profile function sends your employer's company name and website and uses a web-search tool to research publicly available company information.
Anthropic processes this as our sub-processor. Our contracting party is Anthropic Ireland, Limited, and under our agreement with it the content is not used to train models. Anthropic deletes inputs and outputs within 30 days. Where content is flagged by Anthropic's automated trust-and-safety systems, it may be retained for up to two years, and the resulting classification scores for up to seven years. Section 8 covers the onward transfer to the United States.
Prompt records
By default we store what was sent to the model and what it returned, for 30 days, so that we can diagnose incorrect or missing output. Your employer's administrator can switch this off in the application's settings, in which case the content is not written at all — only the model name, token counts, timing and outcome are recorded.
How long
Extracted Salesforce data is refreshed weekly: the two most recent extractions are kept, and older ones are deleted automatically. The change history and the weekly SPI snapshots are kept for as long as your employer is our customer, so that developments can be traced over time. Initiatives and weekly clean-up lists are kept until a user deletes them. Everything is deleted when your employer's organisation is closed (section 7).
7. Deletion when an organisation leaves
When a customer's organisation is closed — by its own administrator or by us at its written request — deletion is immediate and irreversible. It covers every extracted Salesforce record and the change history kept from them, every Scope with its configuration, snapshots, initiatives and weekly clean-up lists, every stored AI prompt and response, the business profile, the Salesforce connection (whose refresh token we revoke at Salesforce) and every user account of that organisation. Sessions stop working at once, and cached results are removed.
What survives, and why:
| What | Why | How long |
|---|---|---|
| A minimal record of the closed organisation: its name, its Salesforce organisation ID, the closure date, who requested the closure, and the e-mail address of the person who requested it | Evidence that the deletion happened and was instructed (Art. 5(2) GDPR accountability). Legal basis: Art. 6(1)(c) and Art. 6(1)(f) GDPR | Indefinitely, unless you object successfully under Art. 21 GDPR |
| A record of what our own operators did to the account | Our internal audit trail. Legal basis: Art. 6(1)(f) GDPR | Indefinitely |
| The record that your organisation's administrator accepted our Terms and the Data Processing Agreement: the accepting person's name and e-mail address, the time, and which version of each document was accepted | Evidence that a contract — in particular the Art. 28 GDPR data processing agreement — was concluded, and what it said. This question can arise years after a relationship ends, when everything else is gone. Legal basis: Art. 6(1)(c) with Art. 5(2) GDPR, and Art. 6(1)(f) GDPR | Indefinitely, unless you object successfully under Art. 21 GDPR |
| Copies in infrastructure backups | Disaster recovery only. Backups restore the whole database, never a single organisation, and are never used to bring a deleted account back | Daily backups 6 days; point-in-time recovery archive approximately four weeks |
| Accounting records | § 147 AO, § 257 HGB | 6 or 10 years |
Data already transmitted to Anthropic is subject to Anthropic's own retention; we cannot recall it.
8. Recipients and transfers outside the EU/EEA
We do not sell personal data and we disclose it only as set out below.
| Recipient | What it receives | Where | Safeguard |
|---|---|---|---|
| Railway Corporation (hosting, database, cache, logs) | All application data | Company in the United States; data stored and processed in the EU (Netherlands, europe-west4) on Google Cloud | Data processing agreement incorporating EU Standard Contractual Clauses, Modules Two and Three |
| Google Cloud (Railway's infrastructure provider) | Storage and compute for the above | Netherlands | Contracted through Railway; storage encrypted at rest |
| Anthropic Ireland, Limited (AI model, see section 6) | The prompts described in section 6 | Ireland, with onward processing by Anthropic PBC in the United States | Anthropic's Data Processing Addendum with EU Standard Contractual Clauses, incorporated into its Commercial Terms. Contractually excluded from model training; inputs and outputs deleted within 30 days |
| Tailscale Inc. (private network access to our internal operator console) | Connection and device metadata; no customer sales data | United States / Canada; traffic end-to-end encrypted | Data processing agreement incorporating EU Standard Contractual Clauses |
| Google Ireland Limited (Google Workspace — business e-mail) | Correspondence and business contact details | European Union, with Google LLC (US) as onward processor | Google Cloud Data Processing Addendum with EU Standard Contractual Clauses |
| Qonto (Olinda SAS), France | Payment and account data for invoicing | European Union | A payment service provider acts as an independent controller under its own legal obligations |
| Tax advisers, auditors, lawyers, authorities | Only where required | EU | Legal obligation or Art. 6(1)(f) GDPR |
Transfers to the United States. Where a recipient is established in the United States, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and, where the recipient is certified, on the EU–US Data Privacy Framework adequacy decision. We have assessed the residual risk of access by US public authorities and apply supplementary measures — encryption in transit, storage in the EU, and minimisation of what is transmitted. A copy of the Standard Contractual Clauses is available from us on request at info@metisora.com.
The current list of our sub-processors is maintained in Annex 3 of our Data Processing Agreement at https://app.metisora.com/legal/dpa.
9. Automated decision-making and profiling
We do not carry out automated decision-making producing legal effects concerning you or similarly significantly affecting you, within the meaning of Art. 22(1) GDPR.
The service computes metrics about a sales process that can be viewed per sales representative, and generates written findings using an AI model. Our contract with our customers prohibits them from using the service, or its output, as a basis for decisions about individual employees, or for the systematic monitoring of individual performance. This applies equally to the weekly clean-up lists, which are assigned to individual sales representatives: they are a tool for planning work, and whether a representative's list was completed must not be used to assess that representative. Whether and how a customer complies with that prohibition is a matter between you and your employer; if you believe it has not, please raise it with your employer, its data protection officer or its works council.
10. Your rights
You have the right to:
- Access your personal data and receive a copy (Art. 15 GDPR);
- Rectification of inaccurate data (Art. 16 GDPR);
- Erasure (Art. 17 GDPR);
- Restriction of processing (Art. 18 GDPR);
- Data portability in a structured, machine-readable format (Art. 20 GDPR);
- Object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR — and at any time and without giving reasons to processing for direct marketing (Art. 21 GDPR);
- Withdraw consent at any time with effect for the future, where processing is based on consent (Art. 7(3) GDPR).
To exercise them, write to info@metisora.com. We respond within one month; we may extend that by two further months for complex requests and will tell you if we do. Please note section 1.1: for data from your employer's Salesforce organisation, your rights are exercised against your employer.
Right to lodge a complaint. You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR). The authority competent for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
https://www.lda.bayern.de
(The BayLDA supervises the private sector in Bavaria, where we have our seat.)
11. Is providing data required?
For the user account (section 3), providing your name, e-mail address and Salesforce User ID is necessary to use the application; without them we cannot give you access. There is no statutory obligation to provide it, and no disadvantage beyond not being able to use the service.
For the contract (section 4), providing the data is necessary to conclude and perform it.
12. Security
We protect personal data with technical and organisational measures appropriate to the risk, in accordance with Art. 32 GDPR. These include transport encryption (TLS), encryption of stored Salesforce access tokens, database-level separation of each customer organisation enforced by PostgreSQL row-level security under a non-privileged role, an application backend with no public internet endpoint, access to our internal operator console only over a private encrypted network, least-privilege database roles, and regular backups. The full description is in Annex 2 of our Data Processing Agreement at https://app.metisora.com/legal/dpa.
13. Changes to this policy
We update this policy when our processing changes or the legal position requires it. The current version is always available at https://app.metisora.com/legal/privacy. Where a change materially affects you, we will inform you in advance by e-mail or in the application.
metisora Privacy Policy, version 2.0, last updated 29 September 2026.