Privacy Policy

Last updated: 2 October 2026

Meet Me At Work (the “Service”) is a meeting room booking system operated by Puresoft Ltd, a company registered in Northern Ireland (company number NI051340) with its registered office at 27 Enterprise House Lisburn Enterprise Centre, Enterprise Crescent, Ballinderry Road, Lisburn, BT28 2BP, United Kingdom. Puresoft Ltd is the data controller for the personal data described in this policy for the purposes of the UK General Data Protection Regulation and the Data Protection Act 2018. This policy explains what personal data we collect, why we collect it, how we use it, and the choices you have. If you have questions, email support@meetmeat.work.

The short version

What we collect, and why

DataWhyRetention
Email address Emailed sign-in links, booking confirmations, attendee invitations, and administrator notifications. For the life of your account. When you delete your account, we remove it straight away from your account, your bookings (past ones are kept without your name or address), other people’s bookings you were invited to, your organisations’ lists of people and your calendar connections, we delete the sample organisation set up for you, if you have one, with its rooms and bookings, and we sign out the mobile app, the Outlook add-in and the Teams tab. It stays for up to 90 days in our security, email and error logs and in Booking Assistant messages, and for up to 30 days in sign-in records. Records an organisation keeps that name you, such as booking requests, room holds, meeting polls, saved attendee groups, invitations and site transfers, keep your address until the organisation deletes them or is deleted. If an organisation has blocked your address, it keeps that block.
Bookings (room, time, title, description, attendee emails, recurrence rule) Running the calendar, sending iCal attachments, conflict resolution. Kept while the room and its organisation exist, so the calendar and usage analytics work. When you delete your account, your future bookings are cancelled and your past ones are kept without your name or address. Bookings are deleted 90 days after their room or organisation is deleted (straight away when an administrator asks for the organisation’s immediate deletion), or when the organisation’s paid rooms are removed for non-payment.
Organisation details (name, address, billing address, billing email, currency) Generating invoices and processing payments. Kept while the organisation exists and deleted with it. Invoices, which show the organisation’s name and billing address, and our record of each payment and refund are kept for six years after the end of the financial year in which they were issued (our financial year ends on 30 September), for our bookkeeping, and are then deleted.
Device push-notification token (mobile app only) Sending booking confirmation, update, cancellation, and start-time reminder pushes. Until you sign out of the app or revoke the device, or 91 days after the app was last used on that device. A token the platform reports as no longer valid is not used again.
Camera (mobile app only) Used solely to scan QR codes on meeting room signs. We never read or upload images, and the camera is only active when the user opens the Scan screen. Not stored.
Microphone / voice input (Booking Assistant — optional) Only when you choose the assistant’s voice option instead of typing. The microphone turns on when you tap the voice control and off when you tap it again, or after 10 seconds. While you speak, short audio clips are turned into text by a speech-to-text service run by our hosting provider, and the text appears in the message box for you to check and send. If the 10 seconds run out, it is sent for you. The audio is not stored: each clip is transcribed and discarded. The text you send is kept as a Booking Assistant message (next row).
Booking Assistant messages (optional) What you type or dictate to the Booking Assistant, so it can work out the booking you are asking for. Each message is interpreted by an AI language model run by our hosting provider. We keep each message with your email address and what the assistant understood from it, to measure how well it understands requests. 90 days.
Google or Outlook calendar access (optional) Keeping your room bookings in your own calendar, and the other calendar features described in the Google and Microsoft sections below. Stored encrypted until you disconnect it or delete your account, or until no organisation you belong to uses it any more — for example, because your organisation turned the connection off or was permanently deleted (90 days after an administrator deletes it, or straight away if they ask for immediate deletion). The sections below give the details.
IP address Abuse prevention and rate-limiting. Recorded with security audit events (next row). Rate-limit counters that use it, such as the count of bookings made from one address on a public booking page, last up to one hour.
Security audit events (sign-ins, access changes, administrative actions), including the acting email address and IP address Security monitoring, detecting and investigating unauthorised access. 90 days.
Payment-provider customer and subscription identifiers (paid customers only) Recurring billing, refunds, payment-failure recovery. Kept while the organisation exists and deleted with it. The payment references in our record of each payment and refund are kept with the invoices, for the same period. The payment provider keeps its own records under its own terms.

Where the data is stored

Your data is stored in Western Europe — our databases, file storage, and backups are located in the European Economic Area or the United Kingdom — using established third-party service providers under appropriate data-protection terms. Requests are served through a global edge network, so a request may be processed at the location nearest to you; the stored data itself remains in Western Europe.

We keep encrypted backups of our database for disaster recovery. Daily backups are retained for 35 days and monthly backups for up to 13 months, after which they are deleted automatically. Data erased at your request therefore also disappears from backups on that rolling cycle.

Card payments are handled by a third-party payment provider; we don’t see or store card numbers. We share your email and organisation details with that provider only so it can process your payments and send you receipts and statements.

What we don’t do

Push notifications

The mobile app uses your device platform’s standard push-notification service to deliver booking notifications. The push payloads contain only the data needed to render the notification — typically a room name, start time, and a deep link. The platform handles delivery and does not see your booking detail beyond what we put in the payload.

You can turn notifications off in your device’s settings. Signing out of the app, or revoking a device on the app’s Devices screen, deletes that device’s push token from our database straight away.

Outlook, Teams & Microsoft 365 integration

Meet Me At Work offers an optional Microsoft integration: an Outlook add-in that lets you add a room to a meeting while you compose it, and a pinned Teams and Outlook tab that shows your rooms on one calendar so you can book in place. Both are published by Puresoft Ltd and are covered by this same policy.

How you sign in

Inside Teams and Outlook you can sign in with your existing Microsoft session (single sign-on). Everywhere else — and as a fallback inside Teams and Outlook — you sign in with a one-time link we email to your own mailbox, where possession of the mailbox is the proof of identity, or with Sign in with Google (described below). Either way there is no separate password to create, and we never receive your Microsoft or Google password.

What the add-in and tab access

What the calendar connection does

With the connection in place, Meet Me At Work acts as you in Microsoft 365, within what your own Microsoft account can already do:

Separately, while your calendar is connected and our Teams app is installed for you, booking notifications can reach you in the Teams activity feed instead of by email. Our app sends these with its own Teams permission, not as you.

Keeping this access secure

The access Microsoft grants is stored encrypted, with a key derived for your account alone, and the master key needed to decrypt it is not kept in our database. It is used only for the features above, never to read your email, and we never receive or store your Microsoft password.

Disconnecting

You can press Disconnect under Your Outlook calendar in the customer portal (Account & Billing, Organisation Settings), beside Outlook calendar under Connected accounts in the mobile app, or beside Outlook calendar in the menu that opens from your organisation’s name at the top of the Outlook add-in and the Teams tab. We then delete the access we store and ask Microsoft to stop telling us about changes to your calendar. The add-in and the tab stop connecting and reading your calendar until you press Connect Outlook calendar in the portal or Connect in the app, the add-in or the tab. Entries we already added stay in your calendar. Microsoft doesn’t let an app withdraw one person’s permission, so the permission your administrator granted stays in place for your organisation; without the stored access, we can’t use it for you.

We also delete the stored access when you delete your account (first asking Microsoft to remove the entries we added for the future bookings that deletion cancels). When an organisation turns the integration off or is permanently deleted, we stop using the stored access for that organisation, and we delete it once no organisation is left using it.

What we receive when you book

When you make a booking through the add-in or the tab, we receive your email address (verified by an emailed link or Microsoft sign-in) and the booking details — room, date and time, and any title or attendee emails you choose to include. This is the same booking data described in the table above, handled the same way.

Trust and visibility

The rooms you can see and book are limited to the organisations you administer and those that recognise your email address — through the lists of addresses and domains, and the invited users, that each organisation’s administrator manages in the customer portal.

Google sign-in & Google Calendar

Meet Me At Work offers two optional ways to use your Google account: Sign in with Google, and a Google Calendar connection that adds the room bookings you make to your own Google Calendar. Neither is required: you can always sign in with an emailed link, and bookings work the same without a connected calendar.

Sign in with Google

When you choose Sign in with Google, we ask Google only for your basic identity: your email address and basic profile. Google tells us your email address, confirms that it has verified that address, and gives us an identifier for your Google account; it may also include your name and profile picture. We use the verified email address to sign you in, exactly as if you had clicked an emailed sign-in link. We don’t use or keep your name or profile picture, and signing in this way gives us no access to your calendar, mailbox, contacts or files.

We record the Google account identifier in our security audit log with the sign-in, where it is kept for 90 days. Nothing else from Google is stored: the tokens Google issues for the sign-in are discarded once your identity has been checked.

What the Google Calendar connection does

If you choose Connect Google Calendar in the customer portal (Account & Billing, Organisation Settings), or Connect beside Google Calendar under Connected accounts in the mobile app, Google asks you to let Meet Me At Work see, create, change and delete events on the Google calendars you own. We accept the connection only if the Google account’s verified email address is the same address you use for Meet Me At Work. It connects your own calendar only, never anyone else’s.

We use that permission for one purpose: keeping a copy of your room bookings in your Google Calendar.

What we store, and how it’s protected

So that your calendar stays up to date when you aren’t using Meet Me At Work, we store the access Google grants us. It is encrypted before it is stored, with a key derived for your account alone, and the master key needed to decrypt it is not kept in our database. Alongside it we keep your Google account identifier, the permissions you granted, and when the access was granted and last used. On each booking we keep the identifier of the calendar entry we created, so that later changes reach the right entry. If a calendar update fails, we log the error Google returns for 90 days to diagnose the fault. Nothing else from your Google account is stored.

Disconnecting

You can press Disconnect in the same places. We then ask Google to cancel our access, and delete the stored access from our database straight away, whether or not Google answers. Calendar entries we already added stay in your Google Calendar until you delete them, and while you are disconnected, changes to those bookings are no longer copied there.

You can also remove Meet Me At Work’s access from your Google Account’s own settings. The stored access then stops working, and the portal and the app show the connection as expired or needing reconnecting, with Disconnect beside the reconnect button, so you can delete the stored copy too.

We also cancel and delete the stored access when you delete your account (first asking Google to remove the entries we added for the future bookings that deletion cancels), and when an organisation you belong to turns the Google Calendar connection off or is permanently deleted, unless another organisation you belong to still uses the connection. Otherwise we keep it until you disconnect.

How we use information from Google

We use information from your Google account only to sign you in and to keep your room bookings in your own Google Calendar. We don’t sell it, use it for advertising, or use it to develop or train AI or machine-learning models, and we don’t share it with anyone apart from the service providers that host Meet Me At Work.

Meet Me At Work’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Cookies

The web Service uses three cookies, all needed for it to work. We don’t use tracking, advertising, or analytics cookies.

The mobile app, the Outlook add-in and the Teams tab don’t use cookies: each keeps a sign-in token on your device, which lasts 90 days from when you last used it. The web pages also remember a few display choices in your browser’s storage, such as which organisation and panels you last had open.

Your rights

If you live in the United Kingdom, the European Union, or any jurisdiction with comparable data-protection law, you have the right to:

Children

The Service is intended for use by adults in a workplace context. We do not knowingly collect data from children under 13.

Data breaches

If we discover a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it, as required by UK GDPR Article 33.

Changes to this policy

If we change this policy in a way that affects your rights, we’ll notify users by email at least 30 days before the change takes effect. Minor wording or clarifications are made silently — check this page’s “Last updated” date to see when it was last revised.

Contact
Questions, requests, or complaints about your data:
support@meetmeat.work
Puresoft Ltd
27 Enterprise House Lisburn Enterprise Centre
Enterprise Crescent, Ballinderry Road
Lisburn, BT28 2BP
United Kingdom
Company number NI051340