Privacy Notice
How BridgeMeet collects, uses, and protects personal data, both for the businesses that use us and for the customers who book with them.
Last updated: July 30, 2026
1. Who We Are and the Legal Framework
This Privacy Notice is issued by AUDAWORKS, operating commercially as BridgeMeet, with registered address in Mexico City. It is governed by the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Federal Official Gazette on March 20, 2025, and its applicable regulations. The competent authority for the private sector is the Ministry of Anti-Corruption and Good Governance.
We process personal data lawfully, fairly, and transparently, and we apply security measures to protect it throughout its lifecycle.
2. Personal Data We Process
The data we handle depends on who you are and how you use the service:
- Customers who book over WhatsApp
- Name, WhatsApp phone number, any optional contact details shared such as email, appointment details including a free-text notes field, and the content of the WhatsApp messages exchanged with the business.
- Business owners and staff
- Name, email, profile image, role, and organization membership, handled through our authentication provider.
- The business account
- Business name, description, timezone, contact details, and WhatsApp number.
- Billing
- Subscription and customer identifiers, plan, and status. We never receive or store card numbers.
- Security
- Technical records such as IP addresses in sign-in and rate-limit logs, used to protect the service.
3. How and Why We Use Data
3.1 Primary purposes
- Providing the service: scheduling, rescheduling, cancelling, and sending appointment notifications and reminders over WhatsApp.
- Managing accounts for owners and staff, including sign-in, access control, and permissions.
- Processing payments, billing, and subscription renewal through our payment provider.
- Maintaining and improving the service using aggregated or anonymized data.
- Keeping the platform secure, preventing unauthorized access, and complying with the law.
3.2 Secondary purposes
- Suggesting available times and tailoring the scheduling experience based on the appointment and preference data already held for the business.
You may object to the processing of your data for these secondary purposes through the process in the Privacy Rights section, without affecting the core service.
3.3 Legal basis
- Performance of the legal relationship with the data subject, including sending appointment reminders, under Article 9, section IV, of the LFPDPPP.
- Implied consent for identification and contact data, under Article 7 of the LFPDPPP.
- Express consent for sensitive personal data, under Article 8 of the LFPDPPP.
4. When We Are Processor and When We Are Controller
For the personal data of a business's own customers, the business is the Data Controller and BridgeMeet acts as its Data Processor, handling that data only to provide the service and on the business's instructions.
For the personal data of business owners and staff who register on the platform, BridgeMeet is the Data Controller, since we determine how and why that data is processed.
5. Automated Processing and AI Assistant
When a business enables our AI assistant, the content of the customer's WhatsApp messages, the business's list of services and staff, and the customer's name are sent to our AI provider, Anthropic, for the sole purpose of generating a scheduling reply.
The assistant helps schedule appointments. It does not make legally significant decisions about a person without human oversight, and the business can review and correct how it behaves.
6. Service Providers and Subprocessors
We rely on a small set of trusted providers to run the service. Each one receives only the data it needs for its specific job, and none of them may use it for their own purposes.
- TwilioUnited States
Delivers WhatsApp messages to and from customers. Receives the customer phone number and message content.
- Meta (WhatsApp)United States
Platform that delivers WhatsApp messages and reminders to the customer's device. Receives the customer phone number and message content.
- AnthropicUnited States
Powers the optional AI scheduling assistant. Receives message content, the service and staff catalog, and the customer name when the assistant is on.
- GoogleUnited States
Two-way calendar sync. We read staff availability and create the events for the appointments you book.
- ClerkUnited States
Sign-in and account authentication.
- StripeUnited States
Subscription billing. Card details are entered on Stripe and never reach our servers.
- NeonUnited States
Database hosting for the platform data.
- VercelUnited States
Application hosting and basic page-view analytics.
- ipwho.isThird-party service
Best-effort timezone detection from IP address on first visit.
7. Google API Services and Limited Use
BridgeMeet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We request access to your Google Calendar only to provide the scheduling features you enable. Specifically, we read your calendars and their events, including busy and free times, to find open slots, and we create, update, and delete calendar events for the appointments booked through BridgeMeet. Those events include the customer's name, the selected service, and the appointment notes.
The Google Calendar authorization (access and refresh tokens) is held securely in BridgeMeet's own encrypted credential store, isolated per business account, and is used only while you keep the calendar connected. You can disconnect it at any time. We do not use Google Calendar data for advertising, we do not sell it, and we do not use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. We do not transfer this data to others except as needed to provide the feature at your request, to comply with applicable law, or as part of a merger or acquisition, consistent with the Limited Use requirements.
8. Sensitive and Health Data
Because clinics, dental offices, and veterinary practices use BridgeMeet, appointment notes and messages may include health-related information. We treat this as sensitive data, apply enhanced safeguards, and use it only to manage the appointment.
When a business processes health data, it does so as Data Controller and is responsible for obtaining the customer's express consent, in accordance with Article 8 of the LFPDPPP and other applicable provisions on sensitive personal data.
9. Information Security
We keep each business's data logically separated so one business cannot access another's, encrypt sensitive credentials so that not even our own team can read them, and restrict internal access to what each role needs.
If a security incident affecting personal data occurs, we will act to contain it and notify affected parties as required by applicable law.
10. How Long We Keep Data
We keep personal data for as long as your account and our relationship are active, and for any additional period the law requires us to retain it, for example tax records.
You can ask us to access, correct, or delete your data at any time through the process in the Privacy Rights section, and we respond as the law provides. When a team member is removed, their record may be kept in a deactivated state for continuity and audit.
11. Your Privacy Rights (ARCO)
You may exercise your rights of Access, Rectification, Cancellation, and Objection (ARCO), and withdraw consent you previously gave.
Owners and staff can update their profile details from the dashboard. Customers of a business exercise their rights directly with that business, which acts as the Data Controller.
To make a formal request, write to privacidad@bridgemeet.com and include valid official identification so we can verify who you are. If you have questions about the process you can ask us on WhatsApp at +52 998 695 8160, though the request itself must arrive by email so we can verify your identity.
12. International Data Transfers
Some of our providers operate in the United States, so using BridgeMeet involves transferring personal data there. We limit these transfers to what the service requires and bind each provider by contract to protect the data.
13. Our Commitments
- We do not sell or rent your customers' phone numbers, and we do not use them for our own marketing.
- Card details are handled by Stripe and never touch our servers.
- Each business's data is logically isolated from every other business.
- Sensitive credentials are encrypted so they cannot be read, even internally.
15. Changes to This Notice
We may update this Privacy Notice from time to time. The current version is always published here with its last updated date.