Privacy Notice
How BridgeMeet collects, uses, and protects personal data, both for the businesses that use us and for the customers who book with them.
Last updated: August 14, 2026
1. Who We Are and the Legal Framework
This Privacy Notice is issued by Dario Auda González, operating commercially as AUDAWORKS and BridgeMeet, with registered address at L17 D10 Punta Yoquen, Supermanzana 24, Benito Juárez, Cancún, Quintana Roo, Mexico. It is governed by the Mexican Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), published in the Federal Official Gazette on March 20, 2025, and its applicable regulations. The competent authority for the private sector is the Ministry of Anti-Corruption and Good Governance.
We process personal data lawfully, fairly, and transparently, and we apply security measures to protect it throughout its lifecycle.
2. Personal Data We Process
The data we handle depends on who you are and how you use the service:
- Customers who book over WhatsApp
- Name, WhatsApp phone number, any optional contact details shared such as email, appointment details including a free-text notes field, and the content of the WhatsApp messages exchanged with the business. If the customer sends a voice note, we store its text transcript as one more message in the conversation. The original audio is not kept on our servers: it stays on the servers of Twilio, the provider that delivers the messages. How long those files are kept is explained in the data retention section.
- Business owners and staff
- Name, email, profile image, role, and organization membership, handled through our authentication provider.
- The business account
- Business name, description, timezone, contact details, and WhatsApp number.
- Billing
- Subscription and customer identifiers, plan, and status. We never receive or store card numbers.
- Security
- Technical records such as IP addresses in sign-in and rate-limit logs, used to protect the service.
3. How and Why We Use Data
3.1 Primary purposes
- Providing the service: scheduling, rescheduling, cancelling, and sending appointment notifications and reminders over WhatsApp.
- Managing accounts for owners and staff, including sign-in, access control, and permissions.
- Processing payments, billing, and subscription renewal through our payment provider.
- Maintaining and improving the service using aggregated or anonymized data.
- Keeping the platform secure, preventing unauthorized access, and complying with the law.
3.2 Secondary purposes
- Suggesting available times and tailoring the scheduling experience based on the appointment and preference data already held for the business.
You may object to the processing of your data for these secondary purposes through the process in the Privacy Rights section, without affecting the core service.
3.3 Legal basis
- Performance of the legal relationship with the data subject, including sending appointment reminders, under Article 9, section IV, of the LFPDPPP.
- Implied consent for identification and contact data, under Article 7 of the LFPDPPP.
- Express consent for sensitive personal data, under Article 8 of the LFPDPPP.
4. When We Are Processor and When We Are Controller
For the personal data of a business's own customers, the business is the Data Controller and BridgeMeet acts as its Data Processor, handling that data only to provide the service and on the business's instructions.
For the personal data of business owners and staff who register on the platform, BridgeMeet is the Data Controller, since we determine how and why that data is processed.
5. Automated Processing and AI Assistant
When a business enables our AI assistant, the content of the customer's WhatsApp messages, the business's list of services and staff, and the customer's name are sent to our AI provider, Anthropic, for the sole purpose of generating a scheduling reply.
When a customer sends a voice note over WhatsApp, the audio is sent to Fish Audio, our transcription provider, for the sole purpose of turning it into text so the assistant can understand the request. We do not send the customer's name or phone number alongside the audio: Fish Audio receives the recording on its own, transiently. The recording travels whole and unedited, so it may contain personal data if the customer says it out loud. That transfer leaves Mexico, so it involves an international data transfer, and it happens only when the business has the assistant switched on. The resulting text is stored in the conversation just like a typed message.
The assistant helps schedule appointments. It does not make legally significant decisions about a person without human oversight, and the business can review and correct how it behaves.
6. Service Providers and Subprocessors
We rely on a small set of trusted providers to run the service. Each one receives only the data it needs for its specific job, and none of them may use it for their own purposes.
- TwilioUnited States
Delivers WhatsApp messages to and from customers. Receives the customer phone number and message content.
- Meta (WhatsApp)United States
Platform that delivers WhatsApp messages and reminders to the customer's device. Receives the customer phone number and message content.
- AnthropicUnited States
Powers the optional AI scheduling assistant. Receives message content, the service and staff catalog, and the customer name when the assistant is on.
- GoogleUnited States
Two-way calendar sync. We read staff availability and create the events for the appointments you book.
- ClerkUnited States
Sign-in and account authentication.
- StripeUnited States
Subscription billing. Card details are entered on Stripe and never reach our servers.
- NeonUnited States
Database hosting for the platform data.
- VercelUnited States
Application hosting and basic page-view analytics.
- ipwho.isThird-party service
Best-effort timezone detection from IP address on first visit.
- Fish AudioThird-party service
Transcribes the voice notes customers send so the assistant can understand them. Receives the recording on its own, transiently, with no name or phone number attached, though the audio itself may contain personal data if the customer says it.
Resend (United States) delivers the email notices your team gets when the assistant books, confirms, changes or cancels an appointment. It receives the business email address the notice is addressed to and the text of the notice, which includes the client's name and the appointment time. It never receives the client's phone number or the content of the WhatsApp conversation. This is an international transfer of data, under the same contractual guarantees as every other provider on this list.
7. Google API Services and Limited Use
BridgeMeet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We request access to your Google Calendar only to provide the scheduling features you enable. Specifically, we read your calendars and their events, including busy and free times, to find open slots, and we create, update, and delete calendar events for the appointments booked through BridgeMeet. Those events include the customer's name, the selected service, and the appointment notes.
The Google Calendar authorization (access and refresh tokens) is held securely in BridgeMeet's own encrypted credential store, isolated per business account, and is used only while you keep the calendar connected. You can disconnect it at any time. We do not use Google Calendar data for advertising, we do not sell it, and we do not use it to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models. We do not transfer this data to others except as needed to provide the feature at your request, to comply with applicable law, or as part of a merger or acquisition, consistent with the Limited Use requirements.
8. Sensitive and Health Data
Because clinics, dental offices, and veterinary practices use BridgeMeet, appointment notes and messages may include health-related information. We treat this as sensitive data, apply enhanced safeguards, and use it only to manage the appointment.
When a business processes health data, it does so as Data Controller and is responsible for obtaining the customer's express consent, in accordance with Article 8 of the LFPDPPP and other applicable provisions on sensitive personal data.
9. Information Security
We keep each business's data logically separated so one business cannot access another's, encrypt sensitive credentials so that not even our own team can read them, and restrict internal access to what each role needs.
If a security incident affecting personal data occurs, we will act to contain it and notify affected parties as required by applicable law.
10. How Long We Keep Data
We keep personal data for as long as your account and our relationship are active, and for any additional period the law requires us to retain it, for example tax records.
The files a customer sends over WhatsApp, such as voice notes and images, are not kept on our servers. They stay on the servers of Twilio, the provider that delivers them, and we delete them 7 days after they arrive. The transcript of a voice note is kept, under the same retention policy as any other message in the conversation.
You can ask us to access, correct, or delete your data at any time through the process in the Privacy Rights section, and we respond as the law provides. When a team member is removed, their record may be kept in a deactivated state for continuity and audit.
11. Your Privacy Rights (ARCO)
You may exercise your rights of Access, Rectification, Cancellation, and Objection (ARCO), and withdraw consent you previously gave.
Owners and staff can update their profile details from the dashboard. Customers of a business exercise their rights directly with that business, which acts as the Data Controller.
Owners and staff who want their BridgeMeet account or personal data deleted must submit a privacy and data deletion ticket from the authenticated support panel. We verify the requester through the signed-in account and may request additional information before acting. For other ARCO requests, or if you cannot access your account, write to privacy@bridgemeet.com. Customers of a business exercise their rights directly with that business. Questions may be sent by WhatsApp to +52 998 695 8160.
12. International Data Transfers
Our providers operate outside Mexico, most of them in the United States, so using BridgeMeet involves transferring personal data abroad. The Service Providers and Subprocessors section states the location of each one. We limit these transfers to what the service requires and bind each provider by contract to protect the data.
13. Our Commitments
- We do not sell or rent your customers' phone numbers, and we do not use them for our own marketing.
- Card details are handled by Stripe and never touch our servers.
- Each business's data is logically isolated from every other business.
- Sensitive credentials are encrypted so they cannot be read, even internally.
15. Changes to This Notice
We may update this Privacy Notice from time to time. The current version is always published here with its last updated date.