FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Consent Management
  4. Metomic
M

Metomic

Essential

Related services

2

2B Advice

2B Advice is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2B Advice integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2B Advice helps organizations maintain robust websites that meet user expectations and technical requirements.

Essential
A

Acconsento.click

Acconsento.click is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Acconsento.click integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Acconsento.click helps organizations maintain robust websites that meet user expectations and.

Essential
A

AdFixus

AdFixus is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AdFixus supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AdFixus ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

AdOpt

AdOpt is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AdOpt supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AdOpt ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

AdRoll CMP System

AdRoll CMP System is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AdRoll CMP System supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AdRoll CMP System ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

Aklamio

Aklamio is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Aklamio integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Aklamio helps organizations maintain robust websites that meet user expectations and technical requirements.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Metomic do?

Metomic is a data security and sensitive-data discovery platform (DLP for SaaS) that scans connected business tools such as Slack, Google Drive and Jira for personal and sensitive information. It acts as a data processor for its business customers. The web application sets cookies and Metomic is hosted in the UK and EU.

What Is Metomic and How Does It Work

Metomic is a UK-based data security and sensitive-data discovery platform designed for organisations using cloud SaaS tools. It connects to business applications including Slack, Google Drive, Jira, GitHub, Salesforce, Confluence and Zendesk via OAuth and API integrations, then scans the content stored in those tools for personal identifiable information (PII) and other sensitive data such as financial data, health information and credentials. When sensitive data is detected, Metomic alerts administrators and provides remediation workflows to quarantine, redact or delete the data. The product is primarily a backend scanning service; it does not inject client-side scripts into customer websites.

Data Processed and Cookies Set

Metomic processes the content of files, messages and records within connected SaaS tools in order to detect PII and sensitive data. This means it accesses and analyses actual personal data belonging to employees, customers and other individuals whose information is stored in those tools. Metomic''s web application and marketing site set first-party cookies including session authentication cookies, preference cookies and analytics cookies (where consent is obtained). These cookies are not deployed across third-party websites and are scoped to Metomic''s own domains including metomic.io, app.metomic.io and api.metomic.io.

GDPR and UK GDPR Implications

Metomic operates as a data processor under Article 28 GDPR for the organisations that deploy it. The business customer is the data controller responsible for the personal data held in their SaaS environment; Metomic processes that data only under the customer''s instructions and subject to a Data Processing Agreement. Because Metomic scans data at scale, including data that may belong to employees (a category requiring particular care), the deployment should be subject to a thorough review of the processing activities that Metomic can access and appropriate technical access controls should be implemented to limit its scan scope to necessary data only. UK GDPR applies equally to Metomic''s UK operations and the UK adequacy decision should be monitored.

Special-category data (health data, biometric data, data revealing racial or ethnic origin and similar categories under Article 9 GDPR) may be present in unstructured SaaS content. If Metomic''s scanning is likely to surface such data, additional legal basis requirements under Article 9 apply to the controller''s processing, and the DPA with Metomic should address special-category data handling explicitly.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent Requirements for Website Cookies

Metomic''s own website and web application set cookies that fall into different ePrivacy categories. Session authentication and security cookies are strictly necessary and do not require consent. Analytics and marketing cookies on the metomic.io marketing site require prior informed consent under ePrivacy Directive Article 5(3) and UK PECR Regulation 6. Organisations that link to or embed Metomic login flows within their own sites should audit whether any Metomic-origin cookies are set in their domain context and disclose them appropriately in their cookie notice.

International Data Transfers

Metomic is headquartered in London and processes production customer data in UK and EU cloud regions. The EU''s adequacy decision for the UK, adopted in June 2021, permits the free flow of personal data from the EU to the UK without additional safeguards. This decision has a four-year sunset clause; controllers should verify that any renewal has occurred. Metomic''s sub-processors are contractually restricted to EU and UK processing. No routine transfers to the United States or other third countries are involved in production data processing, distinguishing Metomic from many US-headquartered SaaS security vendors.

Practical Compliance Steps

To deploy Metomic in a GDPR-compliant manner: execute a Data Processing Agreement with Metomic covering Article 28 requirements including sub-processor obligations, audit and limit the OAuth scopes granted to Metomic to the minimum necessary for its security function, document the legitimate interest or contractual basis for scanning employee data, notify employees and other data subjects that their SaaS tool content may be scanned for security compliance purposes as required by Articles 13 and 14 GDPR, conduct a DPIA if scanning will be large-scale or will likely surface special-category data, and review the UK adequacy decision status annually. For web cookie compliance, implement a consent management platform on metomic.io-linked pages and categorise Metomic cookies correctly in your cookie notice.

GDPR consent category

Essential

Websites using Metomic must obtain user consent under GDPR regulations.

Legal basisFor the web application and marketing site: consent (Article 6(1)(a) GDPR) for analytics and marketing cookies; legitimate interest (Article 6(1)(f)) for security and session cookies. For the data scanning service itself (B2B context): contract performance (Article 6(1)(b)) and legitimate interest (Article 6(1)(f)) as between Metomic and its business customers; the business customer acts as data controller for the personal data in their SaaS tools and Metomic acts as data processor (Article 28 GDPR).
Risk levelmedium
Applicable regulationsGDPR (Art. 6, Art. 13/14, Art. 28, Art. 32), UK GDPR, ePrivacy Directive Art. 5(3), UK PECR, UK adequacy decision (monitor for renewal)

DPIA considerations

A Data Protection Impact Assessment is recommended for organisations deploying Metomic to scan employee or customer personal data at scale within SaaS tools. Key considerations include the scope of personal data surfaced during scanning (which may include special-category data held in collaboration tools), the appropriateness of access controls limiting Metomic's scan access to only necessary data, the accuracy of automated PII detection and the risk of false positives exposing data to additional review, sub-processor arrangements and the contractual chain under Article 28 GDPR, and the implications of the UK adequacy decision expiry timeline for UK-based processing.

Sample consent text

We use Metomic to scan our connected SaaS applications for personal and sensitive data in order to protect the privacy of our employees and customers and to maintain compliance with applicable data protection laws. Metomic accesses data within our business tools under our instructions and acts as a data processor under Article 28 GDPR. If you are a visitor to our website, Metomic's web application may set session and preference cookies that are necessary for the secure operation of the platform. For more information on how we use Metomic and how it processes personal data, please see our privacy notice at [privacy policy URL].

Technical details

Tracking methodSaaS application with backend data scanning pipeline. Metomic connects to customer SaaS environments (Slack, Google Drive, Jira, GitHub, Salesforce and others) via OAuth and API integrations to scan for personal and sensitive data. The web application and marketing site set first-party cookies. No client-side tracking pixels on third-party sites.
Server locationUnited Kingdom and European Union (Metomic is a UK company; production infrastructure hosted in UK and EU regions on cloud providers including AWS EU regions)

Third-party domains contacted

metomic.ioapp.metomic.ioapi.metomic.io

Cookies placed

NameTypeDurationPurpose
metomic_sessionStrictly NecessarySessionSession authentication cookie set by the Metomic web application to maintain the authenticated user session. Required for the secure operation of the platform.
__csrf_tokenStrictly NecessarySessionCSRF protection token used by the Metomic web application to prevent cross-site request forgery attacks on authenticated sessions.
metomic_prefsPreferences1 yearStores user interface preferences such as language, display settings and notification preferences for the Metomic dashboard.
_metomic_analyticsAnalytics2 yearsFirst-party analytics cookie used on the metomic.io marketing site to measure visitor behaviour and improve the website. Requires prior user consent.

Metomic is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Metomic set?

Metomic sets first-party cookies on its own domains (metomic.io, app.metomic.io, api.metomic.io) including session authentication cookies, user preference cookies and, where consent is given, analytics cookies. Metomic does not inject tracking cookies into third-party websites and its cookies are scoped to its own platform.

Is consent required to use Metomic?

Consent is required for non-essential cookies on the Metomic marketing site (metomic.io) under ePrivacy Article 5(3) and UK PECR. For the core data-scanning service used by business customers, consent is not the relevant legal basis; instead, the controller-processor relationship is governed by a Data Processing Agreement under Article 28 GDPR, with the business customer's processing activities relying on legitimate interest or contractual necessity.

What is the legal basis for processing data through Metomic?

For the web application and marketing site: consent for analytics cookies and legitimate interest for security cookies. For the SaaS data scanning service: Metomic acts as a data processor under Article 28 and the data controller (the business customer) must have its own legal basis for instructing the scan, typically legitimate interest in data security under Article 6(1)(f) or contractual necessity under Article 6(1)(b).

Does Metomic transfer personal data outside the EU?

No routine transfers to the US or other third countries occur for production data. Metomic processes customer data in the UK and EU. The UK benefits from an EU adequacy decision, though controllers should monitor renewal status as the decision contains a sunset clause. Sub-processors are contractually restricted to EU and UK processing regions.

Does deploying Metomic require a Data Protection Impact Assessment?

A DPIA is strongly recommended when Metomic is used to scan employee personal data at scale, or when special-category data (health, biometric, ethnicity data) may be present in the SaaS content being scanned. The large-scale, systematic nature of automated PII scanning in SaaS tools is likely to meet the DPIA threshold under Article 35 GDPR.

How do I implement Metomic in a GDPR-compliant way?

Execute a Data Processing Agreement with Metomic covering Article 28 requirements and sub-processor obligations. Limit OAuth integration scopes to the minimum necessary. Notify affected employees under Articles 13 and 14 GDPR that their SaaS content may be scanned. Document the legal basis for scanning. Conduct a DPIA for large-scale deployments. Review the UK adequacy decision status annually. Implement a consent management platform for the Metomic web interface cookies.

Are there alternatives to Metomic for SaaS data security?

Alternatives in the SaaS DLP space include Microsoft Purview (for Microsoft 365 environments), Google DLP for Workspace, Nightfall AI and Varonis. Some alternatives are US-hosted, which introduces different transfer considerations. Metomic's UK and EU hosting is a differentiator for organisations subject to strict data localisation requirements.

How do I keep my privacy notice up to date when using Metomic?

Update your privacy notice to list Metomic as a data processor and describe the categories of personal data it accesses, the purpose (data security scanning), the legal basis, and the security measures in place. Review the notice whenever Metomic updates its sub-processor list or when you extend the scope of SaaS integrations. Maintain a record of processing activities (ROPA) entry for the Metomic processing activity.