Privacy & Compliance

Privacy Policy

Last Updated: 15 - June 2026

M&E Plus is committed to protecting the privacy, confidentiality, and security of personal and organizational information processed through the M&E Plus platform.

This Privacy Policy describes how information is collected, used, stored, processed, protected, and disclosed when organizations and authorized users access or use M&E Plus and related services.

By using M&E Plus, you acknowledge and agree to the practices described in this Privacy Policy.

  • Scope

    This Privacy Policy applies to:

    • M&E Plus web applications
    • Mobile applications
    • APIs and integrations
    • Customer support services
    • Related websites and online services
  • Roles and Responsibilities

    In most deployments:

    • The Customer acts as the Data Controller.
    • M&E Plus acts as the Data Processor.

    The Customer determines:

    • What information is collected
    • Why information is collected
    • How long is the information retained
    • Who can access information

    M&E Plus processes information solely to provide, maintain, secure, and support the platform.

  • Information We Process

    Depending on how M&E Plus is configured and used, information processed may include:

    Account Information

    • Name
    • Organization
    • Email address
    • User role
    • Authentication details

    Operational Information

    • Project information
    • Monitoring and evaluation data
    • Survey responses
    • Assessments
    • Indicators
    • Activity records

    Beneficiary and Case Information

    Where applicable:

    • Demographic information
    • Contact details
    • Program and project participation records
    • Case management information
    • Uploaded documents

    Technical Information

    • Device information
    • Browser information
    • Login history
    • IP addresses
    • Audit logs
    • Usage statistics
  • How Information is Used

    Information may be processed for the following purposes:

    • Delivering platform services
    • Managing user access
    • Generating reports and analytics
    • Providing technical support
    • Improving system performance
    • Maintaining platform security
    • Meeting legal obligations

    Information is not sold, rented, or used for advertising purposes.

  • AI and Automated Processing

    M&E Plus may provide AI-assisted features to support analysis, reporting, data management, and decision-support activities.

    AI-generated outputs:

    • Are intended to assist users
    • Do not replace human judgment
    • Should be reviewed before use

    Customer information is not used to train public artificial intelligence models without explicit authorization from the Customer.

  • Security Measures

    We implement technical and organizational measures designed to protect information from unauthorized access, disclosure, alteration, or destruction.

    Measures may include:

    • Encryption technologies
    • Access controls
    • User authentication
    • Audit logging
    • Backup procedures
    • Security monitoring

    No system can guarantee absolute security; however, we continuously improve our safeguards.

  • Data Retention

    Information is retained according to:

    • Customer instructions
    • Contractual obligations
    • Legal requirements
    • Operational needs

    Customers may define project-specific retention periods where applicable.

  • Data Sharing and Disclosure

    Information may only be disclosed:

    • To authorized users designated by the Customer
    • To approved service providers supporting platform operations
    • To comply with legal obligations
    • To protect security, rights, or safety

    We do not sell customer information.

  • International Data Transfers

    Information may be processed using cloud infrastructure and authorized service providers located in different jurisdictions.

    Appropriate safeguards are applied to support secure processing and transfer of information.

  • Data Subject Rights

    Subject to applicable laws, individuals may have rights, including:

    • Access to personal information
    • Correction of inaccurate information
    • Deletion of personal information
    • Restriction of processing
    • Data portability
    • Withdrawal of consent where applicable

    Requests should generally be directed to the Customer acting as Data Controller.

  • Cookies and Similar Technologies

    M&E Plus may use cookies and similar technologies to:

    • Maintain user sessions
    • Improve functionality
    • Support security
    • Analyze service performance

    Additional details may be provided through the Cookie Policy.

  • Changes to this Policy

    We may update this Privacy Policy periodically.

    Updated versions will be published through the M&E Plus website and Trust Center.

  • Contact

    Questions regarding privacy or data protection may be directed to:
    privacy@mandeplus.com

Data Processing Agreement (DPA)

Data Retention & Deletion Policy

Last Updated: 1 - January 2020

  • Purpose

    M&E Plus recognizes that responsible information management includes not only secure storage but also appropriate retention and deletion practices.

    This policy explains how information is retained, archived, exported, and deleted throughout the lifecycle of customer subscriptions and projects.

  • Customer Control

    Customers retain primary responsibility for determining:

    • Information retention periods
    • Legal and regulatory requirements
    • Program-specific obligations
    • Archiving requirements

    Where available, customers may configure retention periods according to their organizational policies and project requirements.

  • Retention Periods

    Information may be retained for:

    • Active project implementation
    • Reporting and audit requirements
    • Contractual obligations
    • Legal compliance requirements
    • Business continuity purposes

    Retention periods may vary depending on:

    • Project type
    • Sector requirements
    • Donor requirements
    • National regulations
    • Customer instructions
  • Inactive Projects

    Customers may archive projects that are no longer active.
    Archived information remains protected by the same security controls applied to active information.

  • Customer Data Exports

    Customers may request or perform exports of their information at any time during the subscription period.

    Supported export formats may include:

    • Excel
    • CSV
    • JSON
    • Other supported formats
  • Subscription Termination

    Upon termination or expiration of a subscription:

    • Customers may export their information.
    • Customers may request a final data package.
    • Access to the platform may be restricted following termination.
  • Data Deletion

    Following completion of the offboarding process and subject to applicable contractual or legal requirements:

    • Customer information is removed from active systems.
    • Associated files and attachments are removed from production environments.
    • User access credentials are disabled.
  • Backup Systems

    Information contained within encrypted backup systems may remain temporarily available until backup retention periods expire.

    Upon expiration of backup retention periods, such information is automatically removed through standard backup lifecycle procedures.

  • Legal Holds

    Where required by law, regulation, court order, investigation, or contractual obligation, deletion may be delayed until applicable requirements have been satisfied.

  • Policy Review

    This policy may be reviewed and updated periodically to reflect operational improvements, regulatory requirements, and customer needs.

Incident Response & Breach Notification Policy

Last Updated: 1 - January 2020

  • Purpose

    M&E Plus maintains procedures designed to identify, assess, respond to, and recover from security incidents that may affect platform operations or customer information.

    The objective of this policy is to support timely response, minimize impact, and maintain transparency with customers.

  • Security Incident Management

    Security incidents may include:

    • Unauthorized access attempts
    • Malware or malicious activity
    • Credential compromise
    • Service disruptions
    • Data exposure events
    • Infrastructure security events

    All identified incidents are evaluated according to their nature, severity, scope, and potential impact.

  • Incident Response Process

    Detection

    Potential incidents may be identified through

    • Security monitoring
    • Audit logs
    • Customer reports
    • Automated alerts
    • Internal reviews


    Assessment

    Once identified, incidents are assessed to determine:

    • Scope
    • Severity
    • Systems affected
    • Potential impact on customers


    Containment

    Appropriate measures are taken to limit the impact of the incident and prevent further exposure or disruption.


    Investigation

    The incident is investigated to determine:

    • Root cause
    • Affected systems
    • Corrective actions
    • Preventive improvements

    Recovery

    Services and systems are restored using established recovery procedures.

  • Customer Notification

    Where an incident is determined to have materially affected customer information or platform services:

    • Affected customers will be notified without undue delay.
    • Available information regarding the incident will be shared.
    • Recommended mitigation actions will be communicated when applicable.
  • Continuous Improvement

    Following significant incidents, lessons learned are incorporated into security practices, procedures, and controls to reduce the likelihood of recurrence.

  • Reporting Concerns

    Security concerns may be reported to:
    security@mandeplus.com  or privacy@mandeplus.com

Subprocessors & Third-Party Service Providers

Last Updated: 1 - January 2020

  • Purpose

    M&E Plus may engage carefully selected third-party service providers to support the delivery, security, maintenance, and operation of the platform.

    These providers may process limited customer information solely for the purpose of delivering contracted services.

  • Selection Principles

    Subprocessors are evaluated based on factors including:

    • Security practices
    • Reliability
    • Service quality
    • Privacy commitments
    • Regulatory compliance
    • Operational necessity
  • Current Service Providers

    The following categories of providers may be used to support M&E Plus operations:

    Cloud Infrastructure


    Purpose
    Application hosting, storage, networking, backup, and infrastructure services.


    Examples
    AWS or equivalent approved infrastructure providers.


    Email and Communication Services


    Purpose

    Customer communications, notifications, and support operations.


    Examples

    Google Workspace and related communication providers.


    Artificial Intelligence Services


    Purpose

    AI-assisted platform capabilities where enabled by customers.


    Examples

    Approved AI service providers supporting analytics, reporting, translation, transcription, summarization, and other AI-enabled functionality.

    Customer information is not used to train public AI models without customer authorization.


    Monitoring and Security Services


    Purpose

    Platform monitoring, performance management, security operations, and reliability improvement.

  • Data Processing Requirements

    All subprocessors are required to:

    • Process information only for authorized purposes.
    • Maintain appropriate security measures.
    • Protect confidentiality.
    • Comply with applicable contractual obligations.
  • Updates

    This list may be updated as service providers change or new services are introduced.

    Material changes may be reflected within the M&E Plus Trust Center.