Effective 28 July 2026

Privacy Policy

We verify whether traffic is genuine, which means we handle data about the devices and behaviour behind a request. This policy explains what we collect, why, who it goes to, and what you can ask us to do about it — in both of the roles we occupy.

01

Scope and our two roles

This policy covers Attayn Group LLC, a New York limited liability company, doing business as Metaphasic(“Metaphasic”, “we”, “us”). We handle personal data in two distinct roles, and the difference matters for who you should contact about it.

As a controller

For visitors to metaphasic.io, and for the account data of our customers, we decide why and how data is processed. This policy governs that processing, and you can exercise your rights directly with us.

As a processor

When a customer integrates our Service, we evaluate requests reaching their properties. That data is processed on their instructions, for their purposes. In that context our customer is the controller and we are the processor (or, under US state law, the service provider).

If your data was processed because you visited a website or clicked an ad belonging to one of our customers, that customer’s privacy policy governs, and requests to access or delete are best directed to them. You may still contact us at privacy@metaphasic.io, and we will assist that customer in responding.

02

Data we collect on our website

  • Contact data — name, email, company, and anything you choose to write, when you email us or request access.
  • Account data — registration details, billing contact, and authentication data for customers.
  • Technical data — IP address, browser and device characteristics, pages viewed, and referring source, collected when you visit the site.

We do not sell this data, and we do not use it to build advertising profiles about you.

03

Data processed through the service

When a customer sends us a request, we evaluate signals that indicate whether it reflects a real person operating a real device. Depending on the integration, these may include:

  • Network data — IP address, connection and routing characteristics, and whether the origin appears to be a proxy, data centre, or anonymising service.
  • Device and browser data — user agent, operating system, rendering and configuration characteristics, and whether the environment is internally consistent.
  • Interaction data — timing, rhythm, and input characteristics that distinguish human interaction from automation.
  • Context supplied by our customer — such as a campaign, partner, or sub-identifier, used to attribute a verdict.

IP addresses and device characteristics are personal data under laws including the GDPR, and we treat them accordingly. We do not seek to identify individuals by name, and we do not use this data to contact anyone or to build marketing profiles.

We do not knowingly collect special category data, and our customers must not send it to us.

04

How we use data

  • To evaluate requests and return verdicts and supporting evidence.
  • To detect, investigate, and prevent fraudulent, invalid, and abusive activity — including maintaining records that let a customer substantiate a verdict.
  • To provide, secure, monitor, troubleshoot, and support the Service.
  • To bill for usage and administer accounts.
  • To improve detection quality, including by analysing patterns of abuse in aggregated or de-identified form.
  • To comply with legal obligations and enforce our terms.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

05

Legal bases

Where the GDPR or UK GDPR applies and we act as controller, we rely on:

  • Legitimate interests — operating and securing the Service, preventing fraud, and understanding how our site is used. Fraud prevention is expressly recognised as a legitimate interest.
  • Contract — providing the Service to a customer and administering their account.
  • Consent — where required, for example certain cookies. You may withdraw consent at any time.
  • Legal obligation — where we must retain or disclose data by law.

Where we act as processor, our customer is responsible for establishing a lawful basis and for providing notice to the individuals concerned.

06

Who we share data with

We share personal data only as described here. We do not sell it, and we do not disclose it for anyone else’s marketing.

  • Service providers and subprocessors — organisations that process data on our behalf and under contract, including providers of cloud hosting and infrastructure, traffic analysis and fraud detection technology, payment processing, error monitoring, and customer communication. They may use the data only to perform services for us.
  • Our customers — where we act as processor, we return verdicts and evidence to the customer whose integration generated the request.
  • Professional advisers — lawyers, auditors, and insurers, bound by confidentiality.
  • Authorities — where required by law, or to establish, exercise, or defend legal claims. We assess each request and disclose no more than necessary.
  • Corporate transactions — a buyer or successor in a merger, acquisition, or asset sale, subject to this policy.

Customers who require a current list of subprocessors for their own compliance obligations may request one under our data processing addendum by contacting privacy@metaphasic.io.

07

International transfers

We operate internationally, and data may be processed in countries other than your own, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — ordinarily the European Commission’s Standard Contractual Clauses together with transfer risk assessments and supplementary measures where needed.

You may request a copy of the relevant safeguards by contacting us.

08

Retention

We keep personal data only as long as needed for the purpose it was collected for.

  • Verdicts and evidence — retained for the period agreed with the customer, so that a verdict can be substantiated in a later dispute or audit. Where no period is agreed, we apply a default retention period and delete or de-identify thereafter.
  • Account and billing records — retained for the life of the account and then as required by tax and accounting law.
  • Website and contact data — retained no longer than necessary for the enquiry or analysis concerned.

Aggregated and de-identified data, which cannot reasonably be linked to an individual, may be retained indefinitely.

09

Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit, access controls on a least-privilege basis, logging, and segregation of production systems. Access to verdict data is limited to personnel who need it.

No system is perfectly secure. If a breach affects your personal data and the law requires it, we will notify you and the relevant supervisory authority within the applicable deadlines.

10

Your rights

Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent. Where we make decisions by automated means, you may have the right to request human review.

To exercise a right, contact privacy@metaphasic.io. We will respond within the period the applicable law allows, ordinarily one month under the GDPR. We may need to verify your identity, and we will not charge a fee unless a request is manifestly unfounded or excessive.

If your data was processed through a customer’s integration, we will refer the request to that customer, who is the controller, and support them in responding.

If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority. We would welcome the chance to address your concern first.

11

US state privacy rights

Residents of California and other US states with comprehensive privacy laws may have the right to know what personal information we collect, to request deletion or correction, to obtain a portable copy, and to be free from discrimination for exercising those rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under the CCPA as amended. We have not done so in the preceding twelve months.

Where we process personal information on behalf of a customer, we act as a service provider and process it only for the business purposes set out in our contract.

You may use an authorised agent to submit a request. We will require proof of authorisation.

12

Cookies

Our website uses only what is necessary to operate and to understand aggregate usage. We do not run advertising trackers on metaphasic.io. Where consent is required for non-essential cookies, we ask for it before setting them, and you can change your choice at any time.

Separately, our Service may set or read identifiers on our customers’ properties as part of verification. That processing is carried out on the customer’s instructions and is disclosed in their own privacy notice.

13

Children

The Service is intended for business use and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

14

Changes and contact

We may update this policy. If a change is material, we will give notice before it takes effect and update the effective date above.

The controller for the purposes of this policy is Attayn Group LLC, doing business as Metaphasic.

Privacy enquiries, and requests to exercise any of the rights described above, should be sent to privacy@metaphasic.io. General enquiries can go to hello@metaphasic.io.

Privacy questions — privacy@metaphasic.io