PRIVACY POLICY Last Updated: June 27, 2026 INTRODUCTION Gammal Software, Inc. ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website metadock.app (the "Website") and use the MetaDock desktop application (the "Application" or "Software"). This Privacy Policy applies to: - The metadock.app website and all subdomains - The MetaDock desktop application for Windows - Any related services, communications, or interactions with our Company Please read this Privacy Policy carefully. By using our Website or Application, you acknowledge that you have read and understood this Privacy Policy and consent to our collection, use, and disclosure of your personal information as described herein. If you do not agree with the terms of this Privacy Policy, please do not access the Website or use the Application. TABLE OF CONTENTS 1. Information We Collect 2. How We Collect Information 3. How We Use Your Information 4. How We Share Your Information 5. Third-Party Service Providers 6. Cookies and Tracking Technologies 7. Data Retention 8. Data Security 9. Your Privacy Rights 10. Children's Privacy 11. International Data Transfers 12. Third-Party Websites and Services 13. Microsoft WebView2 Privacy Disclosure 14. Changes to This Privacy Policy 15. Contact Us 16. Privacy Rights for Specific Jurisdictions - Canada (PIPEDA) - Quebec (Law 25) - European Union (GDPR) - California (CCPA) 17. Person Accountable for Privacy 1. INFORMATION WE COLLECT We collect several types of information from and about users of our Website and Application. 1.1 Personal Information You Provide to Us a) Email Address - When you subscribe to our mailing list - When you contact us for support, sales inquiries, or other communications - When you create an account or subscribe to our services b) Contact Information - Name (optional, when provided in contact forms) - Any other information you choose to provide in communications with us c) Payment Information - Payment information is collected and processed by Stripe, our third-party payment processor - We do NOT store credit card numbers, CVV codes, or full payment details on our servers - We only store Stripe-generated identifiers on our servers including: * stripe_customer_id * stripe_subscription_id * stripe_payment_intent - These identifiers are linked to your license serial number - Note: Email addresses collected for mailing lists and accounts are stored separately from payment data 1.2 Information Automatically Collected a) Website Analytics Data (via Microsoft Clarity) - Pages viewed and time spent on pages - Referral source (how you found our website) - Device type and browser information - Operating system - General geographic location (country/region level, not precise location) - IP address (truncated for region-level aggregation; Microsoft Clarity does not anonymize the IP by default — we rely on Clarity's masking settings and on Microsoft's retention/access controls, and we do not join Clarity data to any directly identifying information we hold) - Date and time of access - Session replays, clicks, scroll depth, and heatmap data (Microsoft Clarity only) - Note: Microsoft Clarity is loaded only after you accept analytics cookies via the consent banner on our Website. If you decline, no Clarity data is collected. b) Application License Data - Hardware ID (hashed/anonymized; one-way SHA-derived fingerprint that cannot be reversed to original hardware identifiers) - License key/serial number - License activation status - Note: We do NOT collect your email address through the Application itself c) Anonymous Application Telemetry The MetaDock desktop application sends anonymous diagnostic and product-usage telemetry to our servers. The telemetry is designed to be non-identifying and covers ONLY the following: - Edition (Explorer / MetaDock / MetaDock Pro / Beta) and application version - Operating system version, CPU class, total system memory - Aggregate feature-usage counts (e.g., number of profiles opened, automation scripts run) — counts only, never the contents of profiles, browsing history, scripts, or user data - Application uptime and crash diagnostics (crash reports are processed by Sentry in the United States — see Section 5.5) - IP address (used to derive country/region for aggregation only; not stored against your license identifier in a way that re-identifies you) Anonymous telemetry is correlated to your hashed hardware ID for de-duplication only, not to your email address, name, or any other directly identifying information held in the Application. It does NOT include any user content. You can disable anonymous usage telemetry at any time from inside the MetaDock application: Settings > Privacy & Security > "Anonymous Usage Telemetry". The setting takes effect immediately. Disabling does not affect data we have already received (which expires on the schedule in Section 7), and it does not affect license verification or Microsoft WebView2 diagnostics (which are sent directly to Microsoft and are governed by Microsoft's own privacy settings). See the End User License Agreement ("Anonymous Usage Telemetry") for the complete enumeration of fields. 1.3 Information We Do NOT Collect We want to be transparent about what we do NOT collect: a) Through the Website: - We do not collect precise geolocation data - We do not collect biometric data - We do not collect Sensitive Personal Information ("SPI") as that term is defined under the California Privacy Rights Act (CCPA/CPRA §1798.140(ae)) — specifically: government IDs, financial account or login credentials, precise geolocation, race or ethnic origin, religious or philosophical beliefs, union membership, communications contents, genetic data, biometric data used for unique identification, health data, or sexual orientation / sex-life data. We collect a hashed hardware fingerprint, an account email, and an IP address aggregated to country/region; none of these fields, individually or in combination, fall within the CCPA SPI definition. b) Through the Application: - We do not collect or access your browsing history - We do not collect or access websites you visit using MetaDock - We do not collect or access bookmarks, passwords, or form data - We do not collect or access wallet addresses, private keys, or cryptocurrency information - We do not collect or access your workspace configurations or browser profile data - We do not monitor or track the specific content, sites, or actions taken within the Application — only the aggregate feature-usage counts described in Section 1.2(c) - Your workspace data, browser profiles, and all user data remain LOCAL on your device 2. HOW WE COLLECT INFORMATION 2.1 Information You Provide Directly - When you fill out contact forms on our Website - When you subscribe to our mailing list - When you email us at support@metadock.app, sales@metadock.app, or other company emails - When you purchase a subscription 2.2 Automated Collection Technologies - Cookies and similar tracking technologies on our Website (see Section 6) - Microsoft Clarity (web analytics, session replays, heatmaps) integrated into our Website - License verification system in the Application 2.3 Third-Party Sources - Stripe provides us with payment confirmation and subscription status (no full payment details) - We do not purchase or obtain personal information from data brokers or other third parties 3. HOW WE USE YOUR INFORMATION We use the information we collect for the following purposes: 3.1 To Provide and Maintain Our Services - Process and fulfill your subscription orders - Verify your license and prevent unauthorized use - Provide customer support and respond to your inquiries - Send transactional emails (order confirmations, receipts, license keys, password resets, service announcements) 3.2 To Improve Our Services - Analyze website usage to improve user experience - Identify and fix bugs, errors, or performance issues - Develop new features and functionality - Understand how users interact with our Website and Application 3.3 To Communicate With You - Send you marketing emails about MetaDock products, updates, and promotions (only if you opt-in) - Send you newsletters (only if you subscribe to our mailing list) - Respond to your comments, questions, and support requests - Send important service updates or changes to our terms Note: Marketing emails are optional and separate from transactional emails. You can opt-out of marketing emails at any time (see Section 9). 3.4 For Legal and Security Purposes - Comply with legal obligations and respond to lawful requests from authorities - Enforce our Terms and Conditions and other agreements - Protect against fraud, abuse, and security threats - Protect our rights, property, and safety, and that of our users and others 3.5 For Business Operations - Maintain business records and accounting - Manage subscriptions and billing - Conduct internal research and analytics 4. HOW WE SHARE YOUR INFORMATION We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information in the following circumstances: 4.1 With Service Providers We share your information with trusted third-party service providers who assist us in operating our business: a) Stripe (Payment Processing) - Processes subscription payments securely - Subject to Stripe's Privacy Policy: https://stripe.com/privacy - Stripe is PCI-DSS compliant b) Mailjet (Email Service Provider) - Sends transactional emails (subscription receipts, license keys, password resets) and optional newsletters - Subject to Mailjet's Privacy Policy: https://www.mailjet.com/legal/privacy-policy/ - Mailjet is operated from France/European Union; EU data-protection rules apply - You can unsubscribe from our mailing list at any time c) Microsoft Clarity (Website Behavior Analytics) - Provides session replays, click maps, scroll maps, and heatmaps - Loaded only after the visitor accepts analytics cookies via our consent banner - Data is processed by Microsoft Corporation in the United States and may be subject to U.S. legal access requests; we rely on Standard Contractual Clauses for EU/UK transfers and on the EU-U.S. Data Privacy Framework where applicable - Subject to Microsoft Clarity Privacy Statement: https://privacy.microsoft.com d) Microsoft (WebView2 Runtime) - The MetaDock Application uses Microsoft Edge WebView2 as its browser engine - WebView2 may send diagnostic and usage data to Microsoft - See Section 13 for detailed disclosure e) Sentry (Application Crash Diagnostics) - Receives anonymized crash reports from the MetaDock Application (stack traces, faulting module, OS and application version, one-way hardware hash) - File paths are sanitized to remove your username before transmission; reports never include browsing history, URLs, page content, passwords, cookies, or personal files - Honors the in-app "Anonymous Usage Telemetry" setting - Data is processed by Functional Software, Inc. (d/b/a Sentry) in the United States - Subject to Sentry's Privacy Policy: https://sentry.io/privacy/ All service providers are contractually obligated to protect your information and use it only for the purposes we specify. 4.2 For Legal Reasons We may disclose your information if required to do so by law or in response to: - Court orders, subpoenas, or other legal processes - Requests from government authorities or law enforcement - Legal claims or disputes - Situations involving potential threats to safety or security 4.3 Business Transfers If Gammal Software, Inc. is involved in a merger, acquisition, asset sale, bankruptcy, or similar transaction, your information may be transferred to the acquiring entity. We will notify you of any such change via email and/or a prominent notice on our Website. 4.4 With Your Consent We may share your information for any other purpose with your explicit consent. 5. THIRD-PARTY SERVICE PROVIDERS We use the following third-party services: 5.1 Stripe (Payment Processing) - Purpose: Process subscription payments - Data Shared: Email, name, payment information - Privacy Policy: https://stripe.com/privacy - Location: United States (with global infrastructure) 5.2 Mailjet (Email Service) - Purpose: Send transactional emails (subscription receipts, license keys, password resets) and optional newsletters - Data Shared: Email address, name (if provided), subscription preferences, license / transaction context for transactional sends - Privacy Policy: https://www.mailjet.com/legal/privacy-policy/ - Location: France / European Union (EU data-protection rules apply) - Note: You can unsubscribe from marketing newsletters at any time via the link in any email; transactional emails are required to deliver the service you purchased 5.3 Microsoft Clarity (Web Behavior Analytics) - Purpose: Session replays, click maps, scroll maps, heatmaps; loads only after analytics-cookie consent - Data Shared: Anonymized session interactions, device fingerprint signals, IP-derived region - Privacy Policy: https://privacy.microsoft.com - Location: United States (Microsoft Corporation), with global Microsoft infrastructure - Cookie duration: up to 1 year; users can withdraw consent at any time via the "Cookie Preferences" link in the Website footer 5.4 Microsoft (WebView2 Runtime) - Purpose: Browser engine for MetaDock Application - Data Shared: Diagnostic and performance data (controlled by Microsoft) - Privacy Policy: https://privacy.microsoft.com - Location: Global Microsoft infrastructure - See Section 13 for detailed disclosure 5.5 Sentry (Application Crash Diagnostics) - Purpose: Receive and aggregate anonymized application crash reports for stability monitoring - Data Shared: Stack traces, faulting module, OS and application version, one-way hardware hash; path-sanitized and free of user content - Privacy Policy: https://sentry.io/privacy/ - Location: United States (Functional Software, Inc., d/b/a Sentry) - Note: Honors the in-app "Anonymous Usage Telemetry" setting; can be disabled there These third parties have their own privacy policies governing their use of your information. We encourage you to review their policies. 6. COOKIES AND TRACKING TECHNOLOGIES 6.1 What Are Cookies? Cookies are small text files placed on your device by websites you visit. They are widely used to make websites work more efficiently and provide information to website owners. 6.2 Cookies We Use Our Website uses the following types of cookies: a) Essential Cookies - Required for the Website to function properly - Enable core functionality like security and accessibility - Cannot be disabled without affecting Website functionality b) Analytics Cookies (Microsoft Clarity) - Set only after you accept the analytics-cookie consent banner - Collect information about how visitors use our Website (page views, clicks, scroll depth, and session replays) - Help us improve the Website and user experience - Do not collect names, email addresses, or payment information 6.3 Third-Party Cookies Third-party services (Microsoft Clarity) may set their own cookies on your device when you visit our Website AND you have provided analytics-cookie consent. We do not control how these third parties process the data they collect on their own infrastructure; review their privacy policy linked above for details. 6.4 Withdrawing Consent You can withdraw your analytics cookie consent at any time by clicking the "Cookie Preferences" link in our Website footer. Withdrawing consent will block any further analytics data collection and clear the Microsoft Clarity cookies on your device. 6.5 Cookie Management You can control cookies through your browser settings: - Most browsers allow you to refuse cookies or delete cookies - Browser help sections provide instructions on managing cookies - Note: Disabling cookies may affect Website functionality For more information about cookies, visit: https://www.allaboutcookies.org 6.6 Do Not Track Signals Some browsers include a "Do Not Track" (DNT) feature. Our Website does not currently respond to DNT signals because there is no industry standard for how to respond to them. 7. DATA RETENTION 7.1 How Long We Keep Your Information We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. a) Active Accounts - We retain your information while your account or subscription is active b) Inactive Accounts and Historical Records - After account closure or subscription termination, we retain your information for seven (7) years to comply with tax, accounting, and legal obligations - This includes license keys, subscription history, and transaction records required for financial audits and tax compliance - After the 7-year retention period, personal information is deleted unless we have a legal obligation to retain it longer c) Mailing List - We retain your email address until you unsubscribe from our mailing list - Upon unsubscribe from marketing emails, your email is removed from the marketing list within ten (10) business days, as required by Canada's Anti-Spam Legislation (CASL) and aligned with similar EU/UK/CCPA expectations. (Transactional emails — receipts, license keys, and account-security notifications — continue as long as you have an active subscription, because they are necessary to deliver the service you paid for.) d) Support Communications - We retain support emails and communications for three (3) years for customer service improvement and dispute resolution purposes - After 3 years, support communications are deleted unless needed for ongoing legal matters e) Application Crash Diagnostics (Sentry) - Anonymized crash reports are retained by Sentry for up to ninety (90) days, after which they are deleted 7.2 Legal and Regulatory Retention We may be required to retain certain information for legal, tax, accounting, or regulatory purposes, including: - Financial transaction records (typically 7+ years) - License and subscription records - Records necessary to comply with tax laws and audits 7.3 Data Deletion Even after you request deletion of your personal information (see Section 9), we may retain certain information as permitted or required by law, including: - Information necessary to resolve disputes or enforce our agreements - Information required for legal, tax, or regulatory compliance - Anonymized or aggregated data that does not identify you 8. DATA SECURITY 8.1 Security Measures We implement reasonable administrative, technical, and physical security measures to protect your personal information from unauthorized access, use, disclosure, alteration, or destruction. Security measures include: - Encryption of data in transit (HTTPS/TLS) - Secure storage of data with access controls - API key protection for accessing sensitive data - Regular security assessments and updates - Use of reputable third-party service providers with strong security practices 8.2 Third-Party Security Payment information is handled exclusively by Stripe, a PCI-DSS Level 1 certified payment processor. We never have access to your full credit card details. 8.3 No Absolute Security While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information. 8.4 Your Responsibility You are responsible for: - Maintaining the confidentiality of your account credentials - Notifying us immediately of any unauthorized access to your account - Using strong, unique passwords 8.5 Breach Notification In the event of a data breach that creates a real risk of significant harm, we will: - Notify the Office of the Privacy Commissioner of Canada and the Commission d'accès à l'information du Québec without delay, as required by PIPEDA s. 10.1 and Quebec Law 25 s. 3.5. - For EU and UK residents, notify the lead supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33 and UK GDPR Art. 33. - Notify affected individuals directly where the breach poses a real risk of significant harm, in language they can understand, with practical guidance on protective steps. We maintain an internal breach-response process and a register of breaches as required by PIPEDA s. 10.3 and GDPR Art. 33(5), regardless of whether external notification is triggered. 9. YOUR PRIVACY RIGHTS You have certain rights regarding your personal information, depending on your location. 9.1 Rights Available to All Users a) Access - You can request a copy of the personal information we hold about you b) Correction - You can request that we correct inaccurate or incomplete information c) Deletion - You can request deletion of your personal information, subject to legal and regulatory exceptions (see Section 7.2) d) Opt-Out of Marketing - You can unsubscribe from marketing emails at any time by clicking the "unsubscribe" link in any email or contacting privacy@metadock.app - Note: You will still receive transactional emails (receipts, license information, critical service updates) e) Object to Processing - You can object to certain uses of your personal information f) Data Portability - You can request a copy of your information in a structured, commonly used format 9.2 How to Exercise Your Rights To exercise any of these rights, please contact us at: Email: privacy@metadock.app Subject: Privacy Rights Request Please include: - Your full name and email address - A description of your request - Any relevant account or license information We will respond to your request within 30 days (or as required by applicable law). 9.3 Verification For security purposes, we may need to verify your identity before processing your request. This may involve asking for additional information or documentation. 9.4 No Discrimination We will not discriminate against you for exercising your privacy rights. 9.5 Additional Rights by Jurisdiction Depending on your location, you may have additional rights. See Section 16 for jurisdiction-specific rights under PIPEDA (Canada), GDPR (EU), and CCPA (California). 10. AGE RESTRICTION & CHILDREN'S PRIVACY 10.1 Age Requirement MetaDock is a paid commercial Windows desktop product intended for adult business and professional use. To purchase, register an account, or enter into a binding subscription agreement with us, you must be: - In Canada and the United States: at least 18 years of age (or the age of majority in your province/state, whichever is higher). - In the European Union, United Kingdom, and EEA: at least 16 years of age, subject to applicable national-law thresholds for digital-service consent under GDPR Art. 8 (some member states have set a higher floor, such as 14, 15, or 16; we require 16+ regardless). - In all other jurisdictions: the local age of digital consent (and at least 16). By creating an account, subscribing, or otherwise contracting with us, you represent that you meet the age threshold for your jurisdiction. If you do not, please ask a parent or legal guardian to contract on your behalf, or do not use the paid service. 10.2 Children's Privacy We do not knowingly collect personal information from anyone below the applicable age threshold above. Our services are designed for adults and business use and contain no content directed at children. We do not knowingly process personal data of any child under 13 (COPPA) and we do not target children with marketing. If you are below your jurisdiction's age threshold, please do not provide any personal information through our Website or Application. 10.3 Parental Rights If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at privacy@metadock.app. Parents and guardians have the right to: - Review any personal information we have collected from their child - Request deletion of their child's personal information - Refuse to permit further collection or use of their child's information To exercise these rights, contact privacy@metadock.app with: - Your relationship to the child - The child's name and email address (if known) - Your preferred method of contact for verification purposes We will verify your identity as the parent or legal guardian before processing any requests. We will respond within 30 days and delete the child's information promptly upon verification. 11. INTERNATIONAL DATA TRANSFERS 11.1 Data Storage Location Your personal information is primarily stored on servers located in Canada. However, our service providers may store or process data in other countries, including the United States. 11.2 Cross-Border Transfers When we transfer personal information outside of Canada, we ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable laws, including: - PIPEDA (Canada) - GDPR (European Union) - CCPA (California) 11.3 Service Provider Locations Our third-party service providers may process your information in the following locations: - Stripe: United States and globally - Mailjet: France / European Union - Microsoft Clarity: United States, with global Microsoft infrastructure - Microsoft (WebView2): Global infrastructure - Sentry (Functional Software, Inc.): United States 11.4 Legal Protections Data transferred outside Canada is protected by: - Contractual agreements with service providers - Compliance with applicable data protection laws - Industry-standard security measures 11.5 Risks Associated with US-Routed Transfers Personal information processed in the United States (Stripe, Microsoft Clarity, Microsoft for WebView2 diagnostics, Sentry for crash diagnostics) may be subject to access by US government authorities under US law, including the Clarifying Lawful Overseas Use of Data Act (CLOUD Act) and Section 702 of the Foreign Intelligence Surveillance Act (FISA 702). These laws can compel a US-based service provider to disclose data without notice to the data subject, regardless of where the data is physically stored. Mailjet (France/European Union) is not subject to those US laws but may receive requests under EU member-state laws or mutual legal assistance treaties. We disclose this so you can make an informed decision before providing personal information to us. If these risks are unacceptable for your use case, please do not provide personal information to us. Contact our Privacy Officer (Section 12) if you have questions. 12. THIRD-PARTY WEBSITES AND SERVICES 12.1 Third-Party Links Our Website may contain links to third-party websites, services, or resources. We are not responsible for the privacy practices or content of these third-party sites. 12.2 No Control We do not control third-party websites and are not responsible for their privacy policies, terms, or practices. We encourage you to review the privacy policies of any third-party websites you visit. 12.3 MetaDock Application The MetaDock Application allows you to browse the internet and access third-party websites. Your interactions with those websites are governed by their respective privacy policies, not this Privacy Policy. We do not collect, monitor, or have access to your browsing activity within the Application. 13. MICROSOFT WEBVIEW2 PRIVACY DISCLOSURE 13.1 What is WebView2? MetaDock uses Microsoft Edge WebView2 as its browser engine. WebView2 is a component provided by Microsoft that enables web browsing functionality within desktop applications. 13.2 Data Collected by Microsoft WebView2 may send diagnostic and performance data to Microsoft, including: - Crash reports and error diagnostics - Performance metrics - Feature usage statistics - Browser compatibility data This data collection is controlled by Microsoft, not Gammal Software, Inc. 13.3 Microsoft's Privacy Policy Microsoft's collection and use of data through WebView2 is governed by Microsoft's Privacy Policy, available at: https://privacy.microsoft.com We recommend reviewing Microsoft's Privacy Policy to understand what data Microsoft collects and how it is used. 13.4 Our Relationship with Microsoft Gammal Software, Inc. does NOT receive, access, or control the diagnostic data that WebView2 sends to Microsoft. This data is sent directly from your device to Microsoft's servers. 13.5 User Control You may have some control over Microsoft's data collection through: - Windows privacy settings - Microsoft account settings - WebView2 configuration options (if available) Please refer to Microsoft's documentation for information on managing privacy settings. 13.6 No Liability Gammal Software, Inc. is not responsible for Microsoft's data collection practices, privacy policies, or use of data collected through WebView2. 14. CHANGES TO THIS PRIVACY POLICY 14.1 Right to Modify We reserve the right to update, modify, or change this Privacy Policy at any time to reflect changes in our practices, legal requirements, or for other operational, legal, or regulatory reasons. 14.2 Notice of Changes When we make material changes to this Privacy Policy, we will: - Update the "Last Updated" date at the top of this page - Provide notice through our Website (such as a banner notification) - Send an email notification to our mailing list subscribers (for significant changes) 14.3 Effective Date Changes become effective when posted on our Website, or on the date specified in the notice, whichever is later. 14.4 Acceptance of Changes For non-material changes (such as clarifications or minor updates), your continued use of our Website or Application after changes are posted constitutes your acceptance of the revised Privacy Policy. For material changes that affect how we collect, use, or share your personal information, or that affect your rights under GDPR: - We will request your explicit consent before the changes take effect for users in the European Economic Area, United Kingdom, or Switzerland - Other users may continue using our services, and continued use constitutes acceptance - If you do not agree to material changes, you must stop using our services and may request deletion of your personal information 14.5 Review Regularly We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. 15. CONTACT US If you have questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us: Privacy Inquiries: Email: privacy@metadock.app Subject: Privacy Policy Inquiry General Support: Email: support@metadock.app Legal Matters: Email: legal@metadock.app Mailing Address: Gammal Software, Inc. 303D-2967 Dundas Street West Toronto, Ontario M6P 1Z2 Canada Telephone: +1 (647) 547-6803 We will respond to privacy inquiries within 30 days or as required by applicable law. 16. PRIVACY RIGHTS FOR SPECIFIC JURISDICTIONS 16.1 CANADA (PIPEDA - Personal Information Protection and Electronic Documents Act) If you are a resident of Canada, you have specific rights under PIPEDA: a) Right to Access - You have the right to request access to your personal information in our possession b) Right to Correction - You have the right to request correction of inaccurate or incomplete personal information c) Right to Withdraw Consent - You may withdraw your consent to our use of your personal information at any time, subject to legal or contractual restrictions d) Right to File a Complaint - You have the right to file a complaint with the Office of the Privacy Commissioner of Canada if you believe we have violated PIPEDA - Website: https://www.priv.gc.ca - Phone: 1-800-282-1376 e) Accountability - We are accountable for personal information under our control, including information transferred to third-party service providers f) Limiting Collection - We only collect personal information that is necessary for the purposes identified in this Privacy Policy g) Consent - We obtain your express or implied consent before collecting, using, or disclosing your personal information - Express consent is obtained for sensitive matters (e.g., mailing list subscription, account creation) - Implied consent is relied upon for transactional and service-delivery purposes where the purpose is obvious; opt-in consent is obtained for analytics cookies (Microsoft Clarity) and marketing emails - You may withdraw consent at any time, subject to legal or contractual restrictions To exercise your PIPEDA rights, contact privacy@metadock.app. 16.2 QUEBEC, CANADA (Law 25 - An Act to modernize legislative provisions as regards the protection of personal information) If you reside in Quebec, you have specific rights under Law 25, in addition to PIPEDA rights described above: a) Right to Information at Collection - You have the right to be informed, at the time of collection, of the purposes, means of collection, recipients, retention period, and your rights of access and rectification regarding your personal information. b) Right to Data Portability (Effective September 2024) - You have the right to receive the personal information you provided to us in a structured, commonly used technological format, and to transmit it to another organization. c) Right to De-Indexation - You have the right to request that we cease disseminating personal information about you or that we de-index any hyperlink attached to your name that provides access to such information by a technological means, where the dissemination causes you serious injury and is not justified by law or for legitimate journalistic, historical, or research purposes. d) Right to Be Informed of Automated Decision-Making - We do not currently use automated decision-making or profiling to make decisions about you. If this changes, we will inform you and provide the factors and parameters used. e) Right to Lodge a Complaint - You have the right to file a complaint with the Commission d'accès à l'information du Québec (CAI): - Website: https://www.cai.gouv.qc.ca - Phone: 1-888-528-7741 f) Person Accountable for the Protection of Personal Information - Under s. 3.1 of Law 25, we designate a person accountable for the protection of personal information. See Section 17 of this Privacy Policy for contact details. g) Confidentiality Incidents - In the event of a confidentiality incident presenting a risk of serious injury, we will notify affected individuals and the Commission d'accès à l'information du Québec without delay, as required by Law 25. h) Cross-Border Transfers from Quebec - Where we transfer personal information about Quebec residents outside Quebec in connection with a new processing activity or a materially expanded use of an existing service provider, we conduct a privacy impact assessment as required by Law 25 ss. 3.3 and 17. For our current core service providers (Stripe, Mailjet, Microsoft Clarity, Microsoft WebView2) we rely on contractual safeguards (Standard Contractual Clauses with the U.S.-based providers), the EU-U.S. Data Privacy Framework where applicable, and verification of the data-protection regime of the receiving jurisdiction. We will produce the relevant PIA documentation on request from the Commission d'accès à l'information du Québec. To exercise your Law 25 rights, contact privacy@metadock.app or the Person Accountable identified in Section 17. 16.3 EUROPEAN UNION (GDPR - General Data Protection Regulation) If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have specific rights under GDPR: a) Legal Basis for Processing We process your personal data based on the following legal grounds: - Consent: You have given clear consent for us to process your personal data for specific purposes (e.g., mailing list subscription) - Contract: Processing is necessary to fulfill our contract with you (e.g., providing the Application, processing subscriptions) - Legal Obligation: Processing is necessary to comply with legal obligations - Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., improving our services, preventing fraud) b) Your GDPR Rights - Right of Access: Obtain confirmation of whether we process your data and request a copy - Right to Rectification: Request correction of inaccurate or incomplete data - Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal exceptions - Right to Restriction of Processing: Request that we limit how we use your data - Right to Data Portability: Receive your data in a structured, commonly used format and transmit it to another controller - Right to Object: Object to our processing of your data based on legitimate interests or for direct marketing - Right to Withdraw Consent: Withdraw your consent at any time (does not affect the lawfulness of processing before withdrawal) - Right Not to Be Subject to Automated Decision-Making: We do not use automated decision-making or profiling c) Data Protection Officer For GDPR-related inquiries, contact our privacy team at: Email: privacy@metadock.app Subject: GDPR Inquiry d) Supervisory Authority You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe we have violated GDPR. e) International Transfers When we transfer your personal data outside the EEA, we ensure appropriate safeguards are in place: - We use service providers (Stripe, Mailjet, Microsoft) that comply with applicable data protection laws; Mailjet is EU-based and processes EU data under GDPR directly - Where required, we implement Standard Contractual Clauses (SCCs) approved by the European Commission with our service providers - We rely on adequacy decisions by the European Commission where applicable (e.g., Canada has received an adequacy decision for PIPEDA-compliant organizations) - Our service providers maintain their own GDPR compliance programs and safeguards f) Data Retention We retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy or as required by law. To exercise your GDPR rights, contact privacy@metadock.app. We will respond within 30 days. 16.4 CALIFORNIA (CCPA - California Consumer Privacy Act) If you are a California resident, you have specific rights under the CCPA (as amended by the CPRA): a) Right to Know You have the right to request that we disclose: - Categories of personal information we collected about you - Categories of sources from which we collected personal information - Our business or commercial purpose for collecting or selling personal information - Categories of third parties with whom we share personal information - Specific pieces of personal information we collected about you b) Right to Delete You have the right to request deletion of your personal information, subject to certain exceptions (e.g., legal compliance, completing transactions, security purposes). c) Right to Correct You have the right to request correction of inaccurate personal information. d) Right to Opt-Out of Sale or Sharing We do NOT sell your personal information to third parties. We do NOT share your personal information for cross-context behavioral advertising. e) Right to Limit Use of Sensitive Personal Information We do not collect or use sensitive personal information in ways that would trigger this right. f) Right to Non-Discrimination We will not discriminate against you for exercising your CCPA rights, including by: - Denying goods or services - Charging different prices or rates - Providing a different level or quality of goods or services g) Authorized Agents You may designate an authorized agent to make a CCPA request on your behalf. We may require verification of the agent's authority. h) Categories of Personal Information We Collect In the past 12 months, we have collected the following categories of personal information: - Identifiers (email address, hashed hardware ID, license key) - Commercial information (subscription history, purchase records) - Internet or network activity (website analytics, pages viewed) - Geolocation data (general region from IP address) i) Categories of Personal Information We Disclose We disclose the following categories for business purposes: - Identifiers: to Stripe (payment processing), Mailjet (email services) - Commercial information: to Stripe (payment processing) - Internet activity: to Microsoft Clarity (analytics) j) How to Exercise Your CCPA Rights To exercise your rights under CCPA, contact us at: Email: privacy@metadock.app Subject: CCPA Privacy Rights Request Include your name, email address, and a description of your request. We will verify your identity before processing your request and respond within 45 days (extendable by an additional 45 days if necessary). k) Shine the Light Law California's "Shine the Light" law permits California residents to request information about our disclosure of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes. 17. PERSON ACCOUNTABLE FOR PRIVACY Under Quebec Law 25 s. 3.1 and as a matter of accountability for all jurisdictions in which we operate, Gammal Software, Inc. designates the following as the Person Accountable for the protection of personal information: Name: Daniel Gammal, Privacy Officer, Gammal Software, Inc. Email: privacy@metadock.app Subject: "Privacy Officer — [Your Request Type]" Address: Gammal Software, Inc. 303D-2967 Dundas Street West Toronto, Ontario M6P 1Z2 Canada The Privacy Officer is responsible for: - Receiving and processing privacy requests, complaints, and inquiries - Routing inbound mail at privacy@metadock.app to the Privacy Officer queue, with an acknowledgement of receipt within five (5) business days and a substantive response within thirty (30) days (or sooner where required by law — e.g., 30 days under PIPEDA, 30 days under Law 25, 45 days under CCPA/CPRA with one 45-day extension, one month under GDPR Art. 12(3)) - Conducting privacy impact assessments for new processing activities or for materially expanded uses of existing third-party processors - Coordinating responses to confidentiality incidents and notifying the Commission d'accès à l'information du Québec without delay where a Law 25 incident risks serious injury - Ensuring our personal-information practices comply with PIPEDA, Quebec Law 25, GDPR, UK GDPR, CCPA/CPRA, and other applicable laws We will acknowledge receipt of privacy requests within 5 business days and substantively respond within 30 days (or as otherwise required by applicable law). --- ACKNOWLEDGMENT BY USING OUR WEBSITE OR APPLICATION, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY. WHERE THE LAW REQUIRES CONSENT — FOR EXAMPLE, ANALYTICS COOKIES OR MARKETING EMAILS — WE OBTAIN IT SEPARATELY THROUGH A CLEAR OPT-IN, NOT THROUGH YOUR USE OF THE SITE ALONE. If you have any questions or concerns about this Privacy Policy, please contact us at privacy@metadock.app. --- END OF PRIVACY POLICY Copyright © 2026 Gammal Software, Inc. All rights reserved.