Trust Center
Trust Center
Overview
Building Trust Through Security, Privacy, and Responsible Innovation
At M&E Plus, trust is fundamental to everything we do. Organizations rely on our platform to manage monitoring, evaluation, learning, case management, surveys, assessments, and organizational data that often involve sensitive information and vulnerable populations.
We understand that protecting this information is not only a technical responsibility but also an ethical commitment.
Our approach is built around five core pillars:
-
Data Ownership
Your data remains your data.
Organizations using M&E Plus retain full ownership and control of all information stored within the platform. M&E Plus does not claim ownership over customer data, survey responses, beneficiary records, case files, attachments, reports, or any other information managed through the platform.
Customers can access, export, and manage their data at any time throughout their subscription period. -
Privacy and Data Protection
We are committed to protecting personal and organizational data through responsible data management practices and internationally recognized privacy principles.
Our privacy framework is designed to support customer compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR) and other relevant privacy requirements.
We strive to collect only the information necessary to deliver our services and to ensure that data is processed transparently, securely, and for legitimate purposes.
-
Security
Protecting customer data is a core component of the M&E Plus platform.
Our security approach combines secure cloud infrastructure, encryption technologies, role-based access controls, authentication mechanisms, audit logging, backup procedures, and operational safeguards designed to reduce risk and protect customer information.
Security is continuously reviewed and strengthened as technologies, threats, and customer requirements evolve.
-
Responsible AI
Protecting customer data is a core component of the M&E Plus platform.
Our security approach combines secure cloud infrastructure, encryption technologies, role-based access controls, authentication mechanisms, audit logging, backup procedures, and operational safeguards designed to reduce risk and protect customer information.
Security is continuously reviewed and strengthened as technologies, threats, and customer requirements evolve.
-
Responsible AI
Artificial Intelligence is integrated into selected M&E Plus capabilities to improve efficiency, support analysis, and assist users in generating insights.
We believe AI should support people, not replace them.
Our Responsible AI approach emphasizes transparency, accountability, fairness, human oversight, privacy protection, and responsible innovation. AI-generated outputs should always be reviewed by qualified users and considered as decision-support tools rather than autonomous decision-making systems.
Customer data is never used to train public artificial intelligence models without explicit authorization.
-
Transparency and Accountability
We believe customers should clearly understand how their information is managed, protected, and processed.
Through this Trust Center, we provide access to our privacy, security, compliance, and responsible AI commitments, as well as information regarding data ownership, subprocessors, retention practices, and customer rights.
We continuously review and improve our policies and controls to align with evolving regulations, emerging technologies, and the needs of the organizations we serve.
-
Our Commitments
Customer Data Ownership
Customers retain full ownership of all information stored within M&E Plus.
Secure Cloud InfrastructureM&E Plus is hosted on secure cloud infrastructure designed to provide reliability, availability, and protection of customer information.
Controlled AccessAccess to information is governed through user roles, permissions, and authentication controls.
Privacy by DesignPrivacy considerations are incorporated into the design, development, and operation of our platform.
Responsible InnovationAI-enabled features are developed and deployed in accordance with ethical and responsible technology principles.
Continuous ImprovementWe regularly review our policies, procedures, and security practices to strengthen protection and improve customer trust.
Additional Information
The Trust Center provides access to detailed information regarding:- Privacy Policy
- Data Ownership & Processing
- Security Overview
- GDPR Compliance Statement
- Data Retention & Deletion
- Subprocessors
- Incident Response
- Responsible AI
- Terms of Service
Questions regarding privacy, security, compliance, or responsible AI practices may be directed to:
privacy@mandeplus.com
Data Ownership & Processing
-
Your Data Remains Yours
M&E Plus is designed around a simple principle: organizations should retain full ownership and control of their information.
Whether you are managing monitoring and evaluation data, assessments, surveys, case management records, beneficiary information, project documentation, or organizational reports, ownership of that information always remains with your organization.
M&E Plus does not claim ownership of customer data and does not use customer information for commercial purposes unrelated to the delivery of the platform and associated services.
-
Customer Ownership
All information uploaded, collected, generated, stored, or managed within M&E Plus remains the sole property of the Customer.
This includes, but is not limited to:
- User-generated content
- Survey and assessment responses
- Beneficiary and participant records
- Case management information
- Project and program data
- Monitoring and evaluation data
- Attachments and supporting documents
- Dashboards, reports, and analytics generated from customer data
Customers maintain full control over how their information is collected, accessed, used, retained, shared, and deleted.
-
Data Controller and Data Processor Roles
In most deployments, the Customer acts as the Data Controller.
As Data Controller, the Customer determines:- What information is collected
- Why information is collected
- Who can access information
- How long information is retained
- Applicable consent requirements
- Applicable legal and regulatory obligations
ArabiaGIS K&A Plus acts as the Data Processor and processes information solely for the purpose of providing, securing, maintaining, and supporting the M&E Plus platform.
-
Access to Customer Data
Access to customer information by ArabiaGIS K&A Plus personnel is restricted and controlled.
Access may occur only when:
- Requested or authorized by the Customer
- Required for technical support
- Required for troubleshooting or maintenance
- Required to investigate security incidents
- Required by applicable law
All such access is subject to internal authorization procedures and may be logged for audit and accountability purposes.
-
Customer Data is Not Sold or Monetized
ArabiaGIS K&A Plus does not:
- Sell customer data
- Rent customer data
- Share customer data for advertising purposes
- Use customer data for marketing activities
- Create commercial profiles based on customer data
- Monetize customer information
Customer information is processed solely for the delivery and operation of M&E Plus services.
-
Data Portability
Customers may access and export their information throughout their subscription period.
Where applicable, exports may be available in commonly used formats such as:
- Excel
- CSV
- JSON
- PNG
- Files or Other supported formats
This enables organizations to retain full control over their information and avoid vendor lock-in.
-
End of Subscription
If a Customer decides to discontinue the use of M&E Plus, the Customer may request a complete export of its information.
Following the completion of the export process and any applicable retention period, customer information will be removed from active production systems and subsequently deleted from backup systems in accordance with established retention and deletion procedures.
Security Overview
-
Protecting Your Information
Security is a core component of the M&E Plus platform.
We recognize that organizations use M&E Plus to manage operational, programmatic, and in some cases sensitive information. Our security approach combines technology, processes, and operational controls designed to help protect customer information from unauthorized access, disclosure, alteration, or loss.
-
Cloud Infrastructure
M&E Plus is hosted on secure cloud infrastructure designed to provide reliability, scalability, and availability.
The platform benefits from modern cloud security capabilities including physical security, network protection, infrastructure monitoring, and redundancy mechanisms. -
Encryption
M&E Plus uses encryption technologies to help protect information during transmission and storage.
Security measures may include:
- Encrypted communications using industry-standard TLS protocols
- Encryption of stored information where applicable
- Secure password storage mechanisms
- Secure backup procedures
-
Access Control
Access to information within M&E Plus is governed through role-based permissions and user authentication controls.
Organizations can define user roles and access levels according to their operational requirements.
Access control capabilities may include:
- Role-based permissions
- User management
- Password policies
- Multi-factor authentication capabilities
- Session management controls
-
Audit and Accountability
M&E Plus supports accountability through audit and monitoring capabilities.
Depending on configuration, audit records may include:
- User logins
- Data creation activities
- Data modifications
- Data exports
- Administrative actions
- Security-related events
-
Backup and Recovery
To help protect customer information against accidental loss or system failure, M&E Plus incorporates backup and recovery procedures.
Backup processes are designed to support business continuity and service recovery requirements.
-
Security Monitoring
Security controls and platform operations are regularly reviewed to identify risks, strengthen protections, and support platform reliability.
Security measures continue to evolve as technology, regulations, and customer requirements change.
-
Shared Responsibility
Security is a shared responsibility.
While M&E Plus provides technical and operational safeguards, customers also play an important role through:
- Appropriate user management
- Access control reviews
- Strong password practices
- User awareness and training
- Responsible for handling exported information
Together, these measures help create a secure environment for managing organizational data.
GDPR Compliance Statement
-
Our Commitment to Privacy
M&E Plus is committed to protecting personal information and supporting customers in meeting their privacy and data protection obligations.
Our privacy practices are designed to align with internationally recognized data protection principles, including those reflected in the European Union General Data Protection Regulation (GDPR).
-
Data Controller and Data Processor
For most implementations of M&E Plus:
The Customer acts as the Data Controller.
ArabiaGIS K&A Plus acts as the Data Processor.
As Data Controller, the Customer determines:
- The purpose of data collection
- The lawful basis for processing
- Data retention requirements
- User permissions and access rights
As Data Processor, ArabiaGIS K&A Plus processes information solely for the purpose of providing and supporting the M&E Plus platform.
-
Supporting Data Subject Rights
M&E Plus is designed to support customer obligations related to data subject rights.
Depending on configuration and customer policies, organizations may use platform capabilities to support:
- Access requests
- Data correction requests
- Data export requests
- Data deletion requests
- Data portability requests
Requests relating to personal data should generally be directed to the organization acting as the Data Controller.
-
Privacy by Design
Privacy considerations are integrated into the design, development, and operation of the platform.
This includes consideration of:
- Access controls
- Data minimization
- User permissions
- Auditability
- Secure processing practices
-
Security Measures
M&E Plus incorporates technical and organizational measures designed to help protect personal information, including:
- Access controls
- Authentication mechanisms
- Encryption technologies
- Audit logging capabilities
- Backup and recovery procedures
- Security monitoring practices
-
International Data Transfers
Where information is processed using cloud infrastructure or authorized service providers, appropriate safeguards are applied to support the secure handling of information.
-
Contact
Questions relating to privacy, data protection, or GDPR-related matters may be directed to:
privacy@mandeplus.comWe continuously review our privacy practices and policies to align with evolving regulations, customer expectations, and industry best practices.