Privacy & Compliance
Privacy & Compliance
Privacy Policy
Last Updated: 15 - June 2026
M&E Plus is committed to protecting the privacy, confidentiality, and security of personal and organizational information processed through the M&E Plus platform.
This Privacy Policy describes how information is collected, used, stored, processed, protected, and disclosed when organizations and authorized users access or use M&E Plus and related services.
By using M&E Plus, you acknowledge and agree to the practices described in this Privacy Policy.
-
Scope
This Privacy Policy applies to:
- M&E Plus web applications
- Mobile applications
- APIs and integrations
- Customer support services
- Related websites and online services
-
Roles and Responsibilities
In most deployments:
- The Customer acts as the Data Controller.
- M&E Plus acts as the Data Processor.
The Customer determines:
- What information is collected
- Why information is collected
- How long is the information retained
- Who can access information
M&E Plus processes information solely to provide, maintain, secure, and support the platform.
-
Information We Process
Depending on how M&E Plus is configured and used, information processed may include:
Account Information
- Name
- Organization
- Email address
- User role
- Authentication details
Operational Information
- Project information
- Monitoring and evaluation data
- Survey responses
- Assessments
- Indicators
- Activity records
Beneficiary and Case Information
Where applicable:
- Demographic information
- Contact details
- Program and project participation records
- Case management information
- Uploaded documents
Technical Information
- Device information
- Browser information
- Login history
- IP addresses
- Audit logs
- Usage statistics
-
How Information is Used
Information may be processed for the following purposes:
- Delivering platform services
- Managing user access
- Generating reports and analytics
- Providing technical support
- Improving system performance
- Maintaining platform security
- Meeting legal obligations
Information is not sold, rented, or used for advertising purposes.
-
AI and Automated Processing
M&E Plus may provide AI-assisted features to support analysis, reporting, data management, and decision-support activities.
AI-generated outputs:
- Are intended to assist users
- Do not replace human judgment
- Should be reviewed before use
Customer information is not used to train public artificial intelligence models without explicit authorization from the Customer.
-
Security Measures
We implement technical and organizational measures designed to protect information from unauthorized access, disclosure, alteration, or destruction.
Measures may include:
- Encryption technologies
- Access controls
- User authentication
- Audit logging
- Backup procedures
- Security monitoring
No system can guarantee absolute security; however, we continuously improve our safeguards.
-
Data Retention
Information is retained according to:
- Customer instructions
- Contractual obligations
- Legal requirements
- Operational needs
Customers may define project-specific retention periods where applicable.
-
Data Sharing and Disclosure
Information may only be disclosed:
- To authorized users designated by the Customer
- To approved service providers supporting platform operations
- To comply with legal obligations
- To protect security, rights, or safety
We do not sell customer information.
-
International Data Transfers
Information may be processed using cloud infrastructure and authorized service providers located in different jurisdictions.
Appropriate safeguards are applied to support secure processing and transfer of information.
-
Data Subject Rights
Subject to applicable laws, individuals may have rights, including:
- Access to personal information
- Correction of inaccurate information
- Deletion of personal information
- Restriction of processing
- Data portability
- Withdrawal of consent where applicable
Requests should generally be directed to the Customer acting as Data Controller.
-
Cookies and Similar Technologies
M&E Plus may use cookies and similar technologies to:
- Maintain user sessions
- Improve functionality
- Support security
- Analyze service performance
Additional details may be provided through the Cookie Policy.
-
Changes to this Policy
We may update this Privacy Policy periodically.
Updated versions will be published through the M&E Plus website and Trust Center.
-
Contact
Questions regarding privacy or data protection may be directed to:
privacy@mandeplus.com
Data Processing Agreement (DPA)
Data Retention & Deletion Policy
Last Updated: 1 - January 2020
-
Purpose
M&E Plus recognizes that responsible information management includes not only secure storage but also appropriate retention and deletion practices.
This policy explains how information is retained, archived, exported, and deleted throughout the lifecycle of customer subscriptions and projects.
-
Customer Control
Customers retain primary responsibility for determining:
- Information retention periods
- Legal and regulatory requirements
- Program-specific obligations
- Archiving requirements
Where available, customers may configure retention periods according to their organizational policies and project requirements.
-
Retention Periods
Information may be retained for:
- Active project implementation
- Reporting and audit requirements
- Contractual obligations
- Legal compliance requirements
- Business continuity purposes
Retention periods may vary depending on:
- Project type
- Sector requirements
- Donor requirements
- National regulations
- Customer instructions
-
Inactive Projects
Customers may archive projects that are no longer active.
Archived information remains protected by the same security controls applied to active information. -
Customer Data Exports
Customers may request or perform exports of their information at any time during the subscription period.
Supported export formats may include:
- Excel
- CSV
- JSON
- Other supported formats
-
Subscription Termination
Upon termination or expiration of a subscription:
- Customers may export their information.
- Customers may request a final data package.
- Access to the platform may be restricted following termination.
-
Data Deletion
Following completion of the offboarding process and subject to applicable contractual or legal requirements:
- Customer information is removed from active systems.
- Associated files and attachments are removed from production environments.
- User access credentials are disabled.
-
Backup Systems
Information contained within encrypted backup systems may remain temporarily available until backup retention periods expire.
Upon expiration of backup retention periods, such information is automatically removed through standard backup lifecycle procedures.
-
Legal Holds
Where required by law, regulation, court order, investigation, or contractual obligation, deletion may be delayed until applicable requirements have been satisfied.
-
Policy Review
This policy may be reviewed and updated periodically to reflect operational improvements, regulatory requirements, and customer needs.
Incident Response & Breach Notification Policy
Last Updated: 1 - January 2020
-
Purpose
M&E Plus maintains procedures designed to identify, assess, respond to, and recover from security incidents that may affect platform operations or customer information.
The objective of this policy is to support timely response, minimize impact, and maintain transparency with customers.
-
Security Incident Management
Security incidents may include:
- Unauthorized access attempts
- Malware or malicious activity
- Credential compromise
- Service disruptions
- Data exposure events
- Infrastructure security events
All identified incidents are evaluated according to their nature, severity, scope, and potential impact.
-
Incident Response Process
Detection
Potential incidents may be identified through
- Security monitoring
- Audit logs
- Customer reports
- Automated alerts
- Internal reviews
AssessmentOnce identified, incidents are assessed to determine:
- Scope
- Severity
- Systems affected
- Potential impact on customers
ContainmentAppropriate measures are taken to limit the impact of the incident and prevent further exposure or disruption.
InvestigationThe incident is investigated to determine:
- Root cause
- Affected systems
- Corrective actions
- Preventive improvements
Recovery
Services and systems are restored using established recovery procedures.
-
Customer Notification
Where an incident is determined to have materially affected customer information or platform services:
- Affected customers will be notified without undue delay.
- Available information regarding the incident will be shared.
- Recommended mitigation actions will be communicated when applicable.
-
Continuous Improvement
Following significant incidents, lessons learned are incorporated into security practices, procedures, and controls to reduce the likelihood of recurrence.
-
Reporting Concerns
Security concerns may be reported to:
security@mandeplus.com or privacy@mandeplus.com
Subprocessors & Third-Party Service Providers
Last Updated: 1 - January 2020
-
Purpose
M&E Plus may engage carefully selected third-party service providers to support the delivery, security, maintenance, and operation of the platform.
These providers may process limited customer information solely for the purpose of delivering contracted services.
-
Selection Principles
Subprocessors are evaluated based on factors including:
- Security practices
- Reliability
- Service quality
- Privacy commitments
- Regulatory compliance
- Operational necessity
-
Current Service Providers
The following categories of providers may be used to support M&E Plus operations:
Cloud Infrastructure
Purpose
Application hosting, storage, networking, backup, and infrastructure services.
Examples
AWS or equivalent approved infrastructure providers.
Email and Communication Services
PurposeCustomer communications, notifications, and support operations.
ExamplesGoogle Workspace and related communication providers.
Artificial Intelligence Services
PurposeAI-assisted platform capabilities where enabled by customers.
ExamplesApproved AI service providers supporting analytics, reporting, translation, transcription, summarization, and other AI-enabled functionality.
Customer information is not used to train public AI models without customer authorization.
Monitoring and Security Services
PurposePlatform monitoring, performance management, security operations, and reliability improvement.
-
Data Processing Requirements
All subprocessors are required to:
- Process information only for authorized purposes.
- Maintain appropriate security measures.
- Protect confidentiality.
- Comply with applicable contractual obligations.
-
Updates
This list may be updated as service providers change or new services are introduced.
Material changes may be reflected within the M&E Plus Trust Center.