Privacy Policy
Last Updated: 4 July 2026
This Privacy Policy explains how ICP Events Limited, trading as Metis RoomPlanner ("Company", "we", "us", or "our"), a company registered in England and Wales under company number 17284114 with its registered office at 167-169 Great Portland Street, London, England, W1W 5PF, collects, uses, and protects personal data in connection with the Metis Planner software platform and associated services (the "Service"), including the websites on which the Service is made available.
We are the data controller for the personal data described in this policy, except where section 4 (Guest and Client Data) applies. Questions and requests should be directed to [email protected].
1. Personal Data We Collect
- Account data — name, email address, company name, and phone number provided at registration; account role and status.
- Security data — password (stored only as a cryptographic hash, never in plain text), two-factor authentication settings and authenticator secrets, security codes, and recovery codes (stored hashed).
- Sign-in and audit records — IP address, browser/device information (user agent), timestamps, and outcomes of security-relevant actions (sign-ins, password resets, verification attempts). These records protect accounts against unauthorised access.
- Billing data — subscription package, seat count, billing country, VAT/tax identification number, tax status, and the IP address recorded at the time of purchase (kept as evidence of the place of supply for tax purposes). Card details are collected and stored by our payment processor, Stripe — full card numbers never touch or reside on our systems.
- Content you upload — floor plans, drawings, venue scans and point clouds, background images, logos and custom items, plan details (event names, dates, customer names), and guest lists.
- Review-link recipients — the email address of a client you issue a plan review link to, and any comments they leave.
- Support and correspondence — emails you send us and our replies.
2. How and Why We Use Personal Data
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating and administering your account; providing the Service, including storing and displaying your plans and content | Performance of a contract (Art. 6(1)(b)) |
| Processing subscription payments, renewals, upgrades and cancellations via Stripe | Performance of a contract (Art. 6(1)(b)) |
| Retaining tax and place-of-supply evidence (billing country, VAT number, purchase IP) | Legal obligation (Art. 6(1)(c)) |
| Account security: verification codes, two-factor authentication, sign-in audit logs, rate limiting, malware scanning of uploads | Legitimate interests (Art. 6(1)(f)) — keeping the Service and its users secure |
| Transactional email (verification codes, receipts, renewal and account notices) | Performance of a contract (Art. 6(1)(b)) |
| Keeping a record of email addresses used to register free trial accounts, so the one-trial-per-customer limit cannot be bypassed by re-registering | Legitimate interests (Art. 6(1)(f)) — preventing abuse of the free-trial offer |
| Responding to support requests | Legitimate interests (Art. 6(1)(f)) |
We do not sell personal data, and we do not use your content or your guests' data for advertising or to train artificial-intelligence models.
3. Cookies and Local Storage
The Service uses only cookies and browser storage that are strictly necessary to operate:
- Session cookie — keeps you signed in; deleted or invalidated when you sign out or the session expires.
- Security (CSRF) cookie — protects signed-in requests against cross-site forgery.
- 3D viewer cookie — a short-lived token that authorises the 3D view of your plan.
- Local storage — working copies of plans and interface preferences (for example, panel layout) kept in your own browser.
We do not use advertising or third-party analytics cookies, so no cookie consent banner is required.
4. Guest and Client Data — Our Role as Processor
Where you upload personal data about your own guests, clients, or contacts (for example a guest list for a seating plan, or the email address of a client you send a review link to), you are the data controller for that data and we act as your data processor. We process it only to provide the Service to you, on your instructions given through the Service, and we delete it when you delete the relevant plan or your account (subject to section 7). You are responsible for ensuring you are entitled to upload such data.
5. Who We Share Personal Data With, and How
We disclose personal data only to the recipients below, only to the extent needed for the stated purpose. Disclosures are made over encrypted (TLS) connections directly between our servers and the recipient's systems — for example, payment details are transmitted from your browser and our servers to Stripe's API, and email content is transmitted to SendGrid's API for delivery. We never sell personal data, publish it, or transfer it in bulk to third parties.
| Recipient | Purpose | Location / safeguards |
|---|---|---|
| Stripe, Inc. and affiliates | Payment processing, subscription billing, tax calculation | May process data in the United States; safeguarded by the UK International Data Transfer Agreement / Addendum and Stripe's certifications |
| Twilio SendGrid | Delivery of transactional email (security codes, receipts, notices) | May process data in the United States; safeguarded by the UK International Data Transfer Agreement / Addendum |
| Hosting infrastructure | Running the application and database on which the Service and your content are stored | United Kingdom |
| Professional advisers, authorities | Where required by law, to enforce our terms, or to protect rights and safety | As applicable |
People you share content with can also see it: colleagues in your company account can see shared plans, templates, logos, and custom items, and anyone holding an unexpired review link can view the plan it was issued for.
6. Security
All traffic to the Service is encrypted in transit (HTTPS/TLS). Passwords and recovery codes are stored hashed; two-factor authentication is available (and may be required) on accounts; uploads are scanned for malware; and security-relevant actions are recorded in an audit log. Access to production systems is restricted to authorised personnel.
7. Retention
- Account and content data — kept while your subscription or trial is active, and for up to ninety (90) days after termination or expiry, after which it may be permanently deleted (see the Terms of Use). Export anything you need before your account closes.
- Billing and tax records — kept for six (6) years as required by UK tax law.
- Sign-in and audit records — kept for as long as reasonably necessary for security purposes and then deleted or anonymised.
- Review links — expire automatically at the time set when they were created and can be revoked at any time.
- Trial registration records — the email address used to register a free trial is retained after the trial ends or the account is deleted, for as long as necessary to enforce the one-trial-per-customer limit. This record is kept even if you ask us to erase your other data, as permitted by UK GDPR Article 17(3), because it is necessary for the purpose it was retained for; it is used for nothing else.
8. Your Rights
Under the UK GDPR you have the right to request access to, rectification of, or erasure of your personal data; to restrict or object to processing; and to data portability. You can exercise these rights by emailing [email protected]. We will respond within one month.
If you are unhappy with how we handle your personal data, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk, although we would welcome the chance to resolve any concern first.
9. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 as an account holder.
10. Changes to this Policy
We may update this policy from time to time. The "Last Updated" date above shows the current version, and material changes will be notified within the Service or by email. Continued use of the Service after publication constitutes acceptance of the revised policy.
11. Contact
ICP Events Limited (trading as Metis RoomPlanner)
Registered in England and Wales, company number 17284114
Registered office: 167-169 Great Portland Street, London, England, W1W 5PF
Email: [email protected]
See also our Terms and Conditions of Use.