Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Metomic is a data security and sensitive-data discovery platform (DLP for SaaS) that scans connected business tools such as Slack, Google Drive and Jira for personal and sensitive information. It acts as a data processor for its business customers. The web application sets cookies and Metomic is hosted in the UK and EU.
Metomic is a UK-based data security and sensitive-data discovery platform designed for organisations using cloud SaaS tools. It connects to business applications including Slack, Google Drive, Jira, GitHub, Salesforce, Confluence and Zendesk via OAuth and API integrations, then scans the content stored in those tools for personal identifiable information (PII) and other sensitive data such as financial data, health information and credentials. When sensitive data is detected, Metomic alerts administrators and provides remediation workflows to quarantine, redact or delete the data. The product is primarily a backend scanning service; it does not inject client-side scripts into customer websites.
Metomic processes the content of files, messages and records within connected SaaS tools in order to detect PII and sensitive data. This means it accesses and analyses actual personal data belonging to employees, customers and other individuals whose information is stored in those tools. Metomic''s web application and marketing site set first-party cookies including session authentication cookies, preference cookies and analytics cookies (where consent is obtained). These cookies are not deployed across third-party websites and are scoped to Metomic''s own domains including metomic.io, app.metomic.io and api.metomic.io.
Metomic operates as a data processor under Article 28 GDPR for the organisations that deploy it. The business customer is the data controller responsible for the personal data held in their SaaS environment; Metomic processes that data only under the customer''s instructions and subject to a Data Processing Agreement. Because Metomic scans data at scale, including data that may belong to employees (a category requiring particular care), the deployment should be subject to a thorough review of the processing activities that Metomic can access and appropriate technical access controls should be implemented to limit its scan scope to necessary data only. UK GDPR applies equally to Metomic''s UK operations and the UK adequacy decision should be monitored.
Special-category data (health data, biometric data, data revealing racial or ethnic origin and similar categories under Article 9 GDPR) may be present in unstructured SaaS content. If Metomic''s scanning is likely to surface such data, additional legal basis requirements under Article 9 apply to the controller''s processing, and the DPA with Metomic should address special-category data handling explicitly.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Metomic''s own website and web application set cookies that fall into different ePrivacy categories. Session authentication and security cookies are strictly necessary and do not require consent. Analytics and marketing cookies on the metomic.io marketing site require prior informed consent under ePrivacy Directive Article 5(3) and UK PECR Regulation 6. Organisations that link to or embed Metomic login flows within their own sites should audit whether any Metomic-origin cookies are set in their domain context and disclose them appropriately in their cookie notice.
Metomic is headquartered in London and processes production customer data in UK and EU cloud regions. The EU''s adequacy decision for the UK, adopted in June 2021, permits the free flow of personal data from the EU to the UK without additional safeguards. This decision has a four-year sunset clause; controllers should verify that any renewal has occurred. Metomic''s sub-processors are contractually restricted to EU and UK processing. No routine transfers to the United States or other third countries are involved in production data processing, distinguishing Metomic from many US-headquartered SaaS security vendors.
To deploy Metomic in a GDPR-compliant manner: execute a Data Processing Agreement with Metomic covering Article 28 requirements including sub-processor obligations, audit and limit the OAuth scopes granted to Metomic to the minimum necessary for its security function, document the legitimate interest or contractual basis for scanning employee data, notify employees and other data subjects that their SaaS tool content may be scanned for security compliance purposes as required by Articles 13 and 14 GDPR, conduct a DPIA if scanning will be large-scale or will likely surface special-category data, and review the UK adequacy decision status annually. For web cookie compliance, implement a consent management platform on metomic.io-linked pages and categorise Metomic cookies correctly in your cookie notice.
Websites using Metomic must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is recommended for organisations deploying Metomic to scan employee or customer personal data at scale within SaaS tools. Key considerations include the scope of personal data surfaced during scanning (which may include special-category data held in collaboration tools), the appropriateness of access controls limiting Metomic's scan access to only necessary data, the accuracy of automated PII detection and the risk of false positives exposing data to additional review, sub-processor arrangements and the contractual chain under Article 28 GDPR, and the implications of the UK adequacy decision expiry timeline for UK-based processing.
Sample consent text
We use Metomic to scan our connected SaaS applications for personal and sensitive data in order to protect the privacy of our employees and customers and to maintain compliance with applicable data protection laws. Metomic accesses data within our business tools under our instructions and acts as a data processor under Article 28 GDPR. If you are a visitor to our website, Metomic's web application may set session and preference cookies that are necessary for the secure operation of the platform. For more information on how we use Metomic and how it processes personal data, please see our privacy notice at [privacy policy URL].
Third-party domains contacted
metomic.ioapp.metomic.ioapi.metomic.ioCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| metomic_session | Strictly Necessary | Session | Session authentication cookie set by the Metomic web application to maintain the authenticated user session. Required for the secure operation of the platform. |
| __csrf_token | Strictly Necessary | Session | CSRF protection token used by the Metomic web application to prevent cross-site request forgery attacks on authenticated sessions. |
| metomic_prefs | Preferences | 1 year | Stores user interface preferences such as language, display settings and notification preferences for the Metomic dashboard. |
| _metomic_analytics | Analytics | 2 years | First-party analytics cookie used on the metomic.io marketing site to measure visitor behaviour and improve the website. Requires prior user consent. |
Metomic is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Metomic sets first-party cookies on its own domains (metomic.io, app.metomic.io, api.metomic.io) including session authentication cookies, user preference cookies and, where consent is given, analytics cookies. Metomic does not inject tracking cookies into third-party websites and its cookies are scoped to its own platform.
Consent is required for non-essential cookies on the Metomic marketing site (metomic.io) under ePrivacy Article 5(3) and UK PECR. For the core data-scanning service used by business customers, consent is not the relevant legal basis; instead, the controller-processor relationship is governed by a Data Processing Agreement under Article 28 GDPR, with the business customer's processing activities relying on legitimate interest or contractual necessity.
For the web application and marketing site: consent for analytics cookies and legitimate interest for security cookies. For the SaaS data scanning service: Metomic acts as a data processor under Article 28 and the data controller (the business customer) must have its own legal basis for instructing the scan, typically legitimate interest in data security under Article 6(1)(f) or contractual necessity under Article 6(1)(b).
No routine transfers to the US or other third countries occur for production data. Metomic processes customer data in the UK and EU. The UK benefits from an EU adequacy decision, though controllers should monitor renewal status as the decision contains a sunset clause. Sub-processors are contractually restricted to EU and UK processing regions.
A DPIA is strongly recommended when Metomic is used to scan employee personal data at scale, or when special-category data (health, biometric, ethnicity data) may be present in the SaaS content being scanned. The large-scale, systematic nature of automated PII scanning in SaaS tools is likely to meet the DPIA threshold under Article 35 GDPR.
Execute a Data Processing Agreement with Metomic covering Article 28 requirements and sub-processor obligations. Limit OAuth integration scopes to the minimum necessary. Notify affected employees under Articles 13 and 14 GDPR that their SaaS content may be scanned. Document the legal basis for scanning. Conduct a DPIA for large-scale deployments. Review the UK adequacy decision status annually. Implement a consent management platform for the Metomic web interface cookies.
Alternatives in the SaaS DLP space include Microsoft Purview (for Microsoft 365 environments), Google DLP for Workspace, Nightfall AI and Varonis. Some alternatives are US-hosted, which introduces different transfer considerations. Metomic's UK and EU hosting is a differentiator for organisations subject to strict data localisation requirements.
Update your privacy notice to list Metomic as a data processor and describe the categories of personal data it accesses, the purpose (data security scanning), the legal basis, and the security measures in place. Review the notice whenever Metomic updates its sub-processor list or when you extend the scope of SaaS integrations. Maintain a record of processing activities (ROPA) entry for the Metomic processing activity.