|
|
Thank you for Signing Up |
At M&E Plus, trust is fundamental to everything we do. Organizations rely on our platform to manage monitoring, evaluation, learning, case management, surveys, assessments, and organizational data that often involve sensitive information and vulnerable populations.
We understand that protecting this information is not only a technical responsibility but also an ethical commitment.
Our approach is built around five core pillars:
Your data remains your data.
Organizations using M&E Plus retain full ownership and control of all information stored within the platform. M&E Plus does not claim ownership over customer data, survey responses, beneficiary records, case files, attachments, reports, or any other information managed through the platform.
Customers can access, export, and manage their data at any time throughout their subscription period.
We are committed to protecting personal and organizational data through responsible data management practices and internationally recognized privacy principles.
Our privacy framework is designed to support customer compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR) and other relevant privacy requirements.
We strive to collect only the information necessary to deliver our services and to ensure that data is processed transparently, securely, and for legitimate purposes.
Protecting customer data is a core component of the M&E Plus platform.
Our security approach combines secure cloud infrastructure, encryption technologies, role-based access controls, authentication mechanisms, audit logging, backup procedures, and operational safeguards designed to reduce risk and protect customer information.
Security is continuously reviewed and strengthened as technologies, threats, and customer requirements evolve.
Protecting customer data is a core component of the M&E Plus platform.
Our security approach combines secure cloud infrastructure, encryption technologies, role-based access controls, authentication mechanisms, audit logging, backup procedures, and operational safeguards designed to reduce risk and protect customer information.
Security is continuously reviewed and strengthened as technologies, threats, and customer requirements evolve.
Artificial Intelligence is integrated into selected M&E Plus capabilities to improve efficiency, support analysis, and assist users in generating insights.
We believe AI should support people, not replace them.
Our Responsible AI approach emphasizes transparency, accountability, fairness, human oversight, privacy protection, and responsible innovation. AI-generated outputs should always be reviewed by qualified users and considered as decision-support tools rather than autonomous decision-making systems.
Customer data is never used to train public artificial intelligence models without explicit authorization.
We believe customers should clearly understand how their information is managed, protected, and processed.
Through this Trust Center, we provide access to our privacy, security, compliance, and responsible AI commitments, as well as information regarding data ownership, subprocessors, retention practices, and customer rights.
We continuously review and improve our policies and controls to align with evolving regulations, emerging technologies, and the needs of the organizations we serve.
Customers retain full ownership of all information stored within M&E Plus.
M&E Plus is hosted on secure cloud infrastructure designed to provide reliability, availability, and protection of customer information.
Access to information is governed through user roles, permissions, and authentication controls.
Privacy considerations are incorporated into the design, development, and operation of our platform.
AI-enabled features are developed and deployed in accordance with ethical and responsible technology principles.
We regularly review our policies, procedures, and security practices to strengthen protection and improve customer trust.
Additional Information
The Trust Center provides access to detailed information regarding:
Questions regarding privacy, security, compliance, or responsible AI practices may be directed to:
privacy@mandeplus.com
M&E Plus is designed around a simple principle: organizations should retain full ownership and control of their information.
Whether you are managing monitoring and evaluation data, assessments, surveys, case management records, beneficiary information, project documentation, or organizational reports, ownership of that information always remains with your organization.
M&E Plus does not claim ownership of customer data and does not use customer information for commercial purposes unrelated to the delivery of the platform and associated services.
All information uploaded, collected, generated, stored, or managed within M&E Plus remains the sole property of the Customer.
This includes, but is not limited to:
Customers maintain full control over how their information is collected, accessed, used, retained, shared, and deleted.
In most deployments, the Customer acts as the Data Controller.
As Data Controller, the Customer determines:
ArabiaGIS K&A Plus acts as the Data Processor and processes information solely for the purpose of providing, securing, maintaining, and supporting the M&E Plus platform.
Access to customer information by ArabiaGIS K&A Plus personnel is restricted and controlled.
Access may occur only when:
All such access is subject to internal authorization procedures and may be logged for audit and accountability purposes.
ArabiaGIS K&A Plus does not:
Customer information is processed solely for the delivery and operation of M&E Plus services.
Customers may access and export their information throughout their subscription period.
Where applicable, exports may be available in commonly used formats such as:
This enables organizations to retain full control over their information and avoid vendor lock-in.
If a Customer decides to discontinue the use of M&E Plus, the Customer may request a complete export of its information.
Following the completion of the export process and any applicable retention period, customer information will be removed from active production systems and subsequently deleted from backup systems in accordance with established retention and deletion procedures.
Security is a core component of the M&E Plus platform.
We recognize that organizations use M&E Plus to manage operational, programmatic, and in some cases sensitive information. Our security approach combines technology, processes, and operational controls designed to help protect customer information from unauthorized access, disclosure, alteration, or loss.
M&E Plus is hosted on secure cloud infrastructure designed to provide reliability, scalability, and availability.
The platform benefits from modern cloud security capabilities including physical security, network protection, infrastructure monitoring, and redundancy mechanisms.
M&E Plus uses encryption technologies to help protect information during transmission and storage.
Security measures may include:
Access to information within M&E Plus is governed through role-based permissions and user authentication controls.
Organizations can define user roles and access levels according to their operational requirements.
Access control capabilities may include:
M&E Plus supports accountability through audit and monitoring capabilities.
Depending on configuration, audit records may include:
To help protect customer information against accidental loss or system failure, M&E Plus incorporates backup and recovery procedures.
Backup processes are designed to support business continuity and service recovery requirements.
Security controls and platform operations are regularly reviewed to identify risks, strengthen protections, and support platform reliability.
Security measures continue to evolve as technology, regulations, and customer requirements change.
Security is a shared responsibility.
While M&E Plus provides technical and operational safeguards, customers also play an important role through:
Together, these measures help create a secure environment for managing organizational data.
M&E Plus is committed to protecting personal information and supporting customers in meeting their privacy and data protection obligations.
Our privacy practices are designed to align with internationally recognized data protection principles, including those reflected in the European Union General Data Protection Regulation (GDPR).
For most implementations of M&E Plus:
The Customer acts as the Data Controller.
ArabiaGIS K&A Plus acts as the Data Processor.
As Data Controller, the Customer determines:
As Data Processor, ArabiaGIS K&A Plus processes information solely for the purpose of providing and supporting the M&E Plus platform.
M&E Plus is designed to support customer obligations related to data subject rights.
Depending on configuration and customer policies, organizations may use platform capabilities to support:
Requests relating to personal data should generally be directed to the organization acting as the Data Controller.
Privacy considerations are integrated into the design, development, and operation of the platform.
This includes consideration of:
M&E Plus incorporates technical and organizational measures designed to help protect personal information, including:
Where information is processed using cloud infrastructure or authorized service providers, appropriate safeguards are applied to support the secure handling of information.
Questions relating to privacy, data protection, or GDPR-related matters may be directed to:
privacy@mandeplus.com
We continuously review our privacy practices and policies to align with evolving regulations, customer expectations, and industry best practices.
M&E Plus is committed to protecting the privacy, confidentiality, and security of personal and organizational information processed through the M&E Plus platform.
This Privacy Policy describes how information is collected, used, stored, processed, protected, and disclosed when organizations and authorized users access or use M&E Plus and related services.
By using M&E Plus, you acknowledge and agree to the practices described in this Privacy Policy.
This Privacy Policy applies to:
In most deployments:
The Customer determines:
M&E Plus processes information solely to provide, maintain, secure, and support the platform.
Depending on how M&E Plus is configured and used, information processed may include:
Where applicable:
Information may be processed for the following purposes:
Information is not sold, rented, or used for advertising purposes.
M&E Plus may provide AI-assisted features to support analysis, reporting, data management, and decision-support activities.
AI-generated outputs:
Customer information is not used to train public artificial intelligence models without explicit authorization from the Customer.
We implement technical and organizational measures designed to protect information from unauthorized access, disclosure, alteration, or destruction.
Measures may include:
No system can guarantee absolute security; however, we continuously improve our safeguards.
Information is retained according to:
Customers may define project-specific retention periods where applicable.
Information may only be disclosed:
We do not sell customer information.
Information may be processed using cloud infrastructure and authorized service providers located in different jurisdictions.
Appropriate safeguards are applied to support secure processing and transfer of information.
Subject to applicable laws, individuals may have rights, including:
Requests should generally be directed to the Customer acting as Data Controller.
M&E Plus may use cookies and similar technologies to:
Additional details may be provided through the Cookie Policy.
We may update this Privacy Policy periodically.
Updated versions will be published through the M&E Plus website and Trust Center.
Questions regarding privacy or data protection may be directed to:
privacy@mandeplus.com
This Cookie Policy explains how M&E Plus uses cookies and similar technologies when users access our websites, applications, and related services.
Cookies help us improve security, functionality, performance, and user experience.
Cookies are small text files stored on a user's device when visiting a website or using an online service.
Cookies may be used to:
These cookies are necessary for the operation of the platform.
Examples include:
Without these cookies, certain services may not function properly.
Functional Cookies
These cookies help remember user preferences and settings.
Examples include:
These cookies help us understand how visitors interact with our websites and services.
Examples may include:
Information collected is generally aggregated and used to improve service quality.
These cookies help detect suspicious activity and protect user accounts and platform resources.
Examples include:
Certain third-party services integrated with M&E Plus websites may place cookies on user devices.
Examples may include:
Such services operate according to their own privacy and cookie practices.
Users can control cookies through browser settings
Most browsers allow users to:
Please note that disabling certain cookies may affect platform functionality.
Where required by applicable regulations, users will be provided with options to accept, reject, or customize cookie preferences.
Continued use of the platform following acceptance of cookies may constitute consent where permitted by applicable law.
This Cookie Policy may be updated periodically to reflect operational, legal, or technical changes.
Updated versions will be published through the M&E Plus Trust Center.
Questions regarding cookies or online privacy may be directed to:
privacy@mandeplus.com
M&E Plus recognizes that responsible information management includes not only secure storage but also appropriate retention and deletion practices.
This policy explains how information is retained, archived, exported, and deleted throughout the lifecycle of customer subscriptions and projects.
Customers retain primary responsibility for determining:
Where available, customers may configure retention periods according to their organizational policies and project requirements.
Information may be retained for:
Retention periods may vary depending on:
Customers may archive projects that are no longer active.
Archived information remains protected by the same security controls applied to active information.
Customers may request or perform exports of their information at any time during the subscription period.
Supported export formats may include:
Upon termination or expiration of a subscription:
Following completion of the offboarding process and subject to applicable contractual or legal requirements:
Information contained within encrypted backup systems may remain temporarily available until backup retention periods expire.
Upon expiration of backup retention periods, such information is automatically removed through standard backup lifecycle procedures.
Where required by law, regulation, court order, investigation, or contractual obligation, deletion may be delayed until applicable requirements have been satisfied.
This policy may be reviewed and updated periodically to reflect operational improvements, regulatory requirements, and customer needs.
M&E Plus maintains procedures designed to identify, assess, respond to, and recover from security incidents that may affect platform operations or customer information.
The objective of this policy is to support timely response, minimize impact, and maintain transparency with customers.
Security incidents may include:
All identified incidents are evaluated according to their nature, severity, scope, and potential impact.
Potential incidents may be identified through
Once identified, incidents are assessed to determine:
Appropriate measures are taken to limit the impact of the incident and prevent further exposure or disruption.
The incident is investigated to determine:
Services and systems are restored using established recovery procedures.
Where an incident is determined to have materially affected customer information or platform services:
Following significant incidents, lessons learned are incorporated into security practices, procedures, and controls to reduce the likelihood of recurrence.
Security concerns may be reported to:
security@mandeplus.com or privacy@mandeplus.com
M&E Plus may engage carefully selected third-party service providers to support the delivery, security, maintenance, and operation of the platform.
These providers may process limited customer information solely for the purpose of delivering contracted services.
Subprocessors are evaluated based on factors including:
The following categories of providers may be used to support M&E Plus operations:
Purpose
Application hosting, storage, networking, backup, and infrastructure services.
Examples
AWS or equivalent approved infrastructure providers.
Purpose
Customer communications, notifications, and support operations.
Examples
Google Workspace and related communication providers.
Purpose
AI-assisted platform capabilities where enabled by customers.
Examples
Approved AI service providers supporting analytics, reporting, translation, transcription, summarization, and other AI-enabled functionality.
Customer information is not used to train public AI models without customer authorization.
Platform monitoring, performance management, security operations, and reliability improvement.
All subprocessors are required to:
This list may be updated as service providers change or new services are introduced.
Material changes may be reflected within the M&E Plus Trust Center.
M&E Plus incorporates artificial intelligence (AI) technologies to assist users in managing information, generating insights, improving efficiency, and supporting decision-making processes.
This policy explains how AI features are used within M&E Plus and outlines our commitment to transparency, accountability, and human oversight.
We believe that AI should support people, not replace them.
AI capabilities within M&E Plus are designed to assist organizations in performing tasks more efficiently while ensuring that final decisions remain under human control.
AI-generated outputs should be considered recommendations, suggestions, summaries, or decision-support tools rather than authoritative or final decisions.
Depending on enabled modules and customer configurations, AI features may assist with:
Capabilities may evolve as new features are introduced.
Human review remains essential.
Organizations and users remain responsible for:
M&E Plus does not make autonomous decisions on behalf of customers.
Where AI-generated outputs are provided, M&E Plus seeks to clearly distinguish AI-generated content from user-generated content whenever practical.
Users should understand:
Customer information remains protected under the same privacy and security controls applicable to the rest of the platform.
M&E Plus does not use customer information to train public artificial intelligence models without explicit customer authorization.
We strive to promote fairness and reduce the risk of unintended bias in AI-assisted features.
Organizations should independently evaluate AI-generated outputs before applying them to sensitive operational, programmatic, or policy decisions.
AI-generated outputs should not be used as the sole basis for decisions involving:
Appropriate human review should always be maintained.
We continuously review AI-enabled capabilities to improve quality, transparency, safety, and reliability.
Feedback from customers plays an important role in this process.
Questions regarding AI governance or responsible AI practices may be directed to:
privacy@mandeplus.com
By accessing or using M&E Plus, you agree to be bound by these Terms of Service.
If you are using M&E Plus on behalf of an organization, you represent that you are authorized to accept these Terms on behalf of that organization.
M&E Plus is a cloud-based platform designed to support impact management, monitoring, evaluation, learning, surveys, assessments, case management, reporting, data collection, analytics, and related operational functions.
Services may evolve over time as new features, integrations, and capabilities are introduced.
Customers are responsible for:
M&E Plus reserves the right to suspend access in cases of abuse or security risks.
All customer data remains the property of the Customer.
M&E Plus does not claim ownership over information stored within the M&E Plus platform.
Additional details are available in the Data Ownership & Processing Policy.
All rights, title, and interest in M&E Plus, including:
remain the exclusive property of M&E Plus and its licensors.
These Terms do not grant ownership of the platform itself.
We strive to provide reliable and uninterrupted service.
However, M&E Plus is provided on a commercially reasonable basis, and availability may be affected by:
Support services may be provided according to the Customer's subscription plan, support agreement, or contractual arrangements.
Response times and service levels may vary by subscription type.
M&E Plus may integrate with third-party products or services.
M&E Plus is not responsible for the availability, content, or practices of third-party services.
Each party agrees to protect confidential information received from the other party and to use such information solely for authorized purposes.
Confidential information shall not be disclosed except as required by law or authorized by the disclosing party.
To the maximum extent permitted by law, M&E Plus shall not be liable for indirect, incidental, special, consequential, or punitive damages arising from the use or inability to use M&E Plus platform.
Total liability shall not exceed amounts paid by the Customer for the applicable subscription period unless otherwise agreed in writing.
Customers may discontinue use of M&E Plus in accordance with their subscription terms.
ArabiaGIS K&A Plus may suspend or terminate access where necessary to protect platform security, comply with legal obligations, or address material violations of these Terms.
These Terms shall be governed by the laws applicable to the contractual agreement between the parties unless otherwise specified in a separate written agreement.
We may update these Terms periodically.
Material updates will be communicated through appropriate channels and published through the M&E Plus Trust Center.
Questions regarding these Terms may be directed at:
privacy@mandeplus.com or info@mandeplus.com