Trust Center

Overview

Building Trust Through Security, Privacy, and Responsible Innovation

At M&E Plus, trust is fundamental to everything we do. Organizations rely on our platform to manage monitoring, evaluation, learning, case management, surveys, assessments, and organizational data that often involve sensitive information and vulnerable populations.
We understand that protecting this information is not only a technical responsibility but also an ethical commitment.

Our approach is built around five core pillars:

  • Data Ownership

    Your data remains your data.

    Organizations using M&E Plus retain full ownership and control of all information stored within the platform. M&E Plus does not claim ownership over customer data, survey responses, beneficiary records, case files, attachments, reports, or any other information managed through the platform.
    Customers can access, export, and manage their data at any time throughout their subscription period.

  • Privacy and Data Protection

    We are committed to protecting personal and organizational data through responsible data management practices and internationally recognized privacy principles.

    Our privacy framework is designed to support customer compliance with applicable data protection regulations, including the General Data Protection Regulation (GDPR) and other relevant privacy requirements.

    We strive to collect only the information necessary to deliver our services and to ensure that data is processed transparently, securely, and for legitimate purposes.

  • Security

    Protecting customer data is a core component of the M&E Plus platform.

    Our security approach combines secure cloud infrastructure, encryption technologies, role-based access controls, authentication mechanisms, audit logging, backup procedures, and operational safeguards designed to reduce risk and protect customer information.

    Security is continuously reviewed and strengthened as technologies, threats, and customer requirements evolve.

  • Responsible AI

    Protecting customer data is a core component of the M&E Plus platform.

    Our security approach combines secure cloud infrastructure, encryption technologies, role-based access controls, authentication mechanisms, audit logging, backup procedures, and operational safeguards designed to reduce risk and protect customer information.

    Security is continuously reviewed and strengthened as technologies, threats, and customer requirements evolve.

  • Responsible AI

    Artificial Intelligence is integrated into selected M&E Plus capabilities to improve efficiency, support analysis, and assist users in generating insights.

    We believe AI should support people, not replace them.

    Our Responsible AI approach emphasizes transparency, accountability, fairness, human oversight, privacy protection, and responsible innovation. AI-generated outputs should always be reviewed by qualified users and considered as decision-support tools rather than autonomous decision-making systems.

    Customer data is never used to train public artificial intelligence models without explicit authorization.

  • Transparency and Accountability

    We believe customers should clearly understand how their information is managed, protected, and processed.

    Through this Trust Center, we provide access to our privacy, security, compliance, and responsible AI commitments, as well as information regarding data ownership, subprocessors, retention practices, and customer rights.

    We continuously review and improve our policies and controls to align with evolving regulations, emerging technologies, and the needs of the organizations we serve.

  • Our Commitments

    Customer Data Ownership

    Customers retain full ownership of all information stored within M&E Plus.


    Secure Cloud Infrastructure

    M&E Plus is hosted on secure cloud infrastructure designed to provide reliability, availability, and protection of customer information.


    Controlled Access

    Access to information is governed through user roles, permissions, and authentication controls.


    Privacy by Design

    Privacy considerations are incorporated into the design, development, and operation of our platform.


    Responsible Innovation

    AI-enabled features are developed and deployed in accordance with ethical and responsible technology principles.


    Continuous Improvement

    We regularly review our policies, procedures, and security practices to strengthen protection and improve customer trust.
    Additional Information
    The Trust Center provides access to detailed information regarding:

    • Privacy Policy
    • Data Ownership & Processing
    • Security Overview
    • GDPR Compliance Statement
    • Data Retention & Deletion
    • Subprocessors
    • Incident Response
    • Responsible AI
    • Terms of Service

    Questions regarding privacy, security, compliance, or responsible AI practices may be directed to:
    privacy@mandeplus.com

Data Ownership & Processing

  • Your Data Remains Yours

    M&E Plus is designed around a simple principle: organizations should retain full ownership and control of their information.

    Whether you are managing monitoring and evaluation data, assessments, surveys, case management records, beneficiary information, project documentation, or organizational reports, ownership of that information always remains with your organization.

    M&E Plus does not claim ownership of customer data and does not use customer information for commercial purposes unrelated to the delivery of the platform and associated services.

  • Customer Ownership

    All information uploaded, collected, generated, stored, or managed within M&E Plus remains the sole property of the Customer.

    This includes, but is not limited to:

    • User-generated content
    • Survey and assessment responses
    • Beneficiary and participant records
    • Case management information
    • Project and program data
    • Monitoring and evaluation data
    • Attachments and supporting documents
    • Dashboards, reports, and analytics generated from customer data

    Customers maintain full control over how their information is collected, accessed, used, retained, shared, and deleted.

  • Data Controller and Data Processor Roles

    In most deployments, the Customer acts as the Data Controller.
    As Data Controller, the Customer determines:

    • What information is collected
    • Why information is collected
    • Who can access information
    • How long information is retained
    • Applicable consent requirements
    • Applicable legal and regulatory obligations

    ArabiaGIS K&A Plus acts as the Data Processor and processes information solely for the purpose of providing, securing, maintaining, and supporting the M&E Plus platform.

  • Access to Customer Data

    Access to customer information by ArabiaGIS K&A Plus personnel is restricted and controlled.

    Access may occur only when:

    • Requested or authorized by the Customer
    • Required for technical support
    • Required for troubleshooting or maintenance
    • Required to investigate security incidents
    • Required by applicable law

    All such access is subject to internal authorization procedures and may be logged for audit and accountability purposes.

  • Customer Data is Not Sold or Monetized

    ArabiaGIS K&A Plus does not:

    • Sell customer data
    • Rent customer data
    • Share customer data for advertising purposes
    • Use customer data for marketing activities
    • Create commercial profiles based on customer data
    • Monetize customer information

    Customer information is processed solely for the delivery and operation of M&E Plus services.

  • Data Portability

    Customers may access and export their information throughout their subscription period.

    Where applicable, exports may be available in commonly used formats such as:

    • Excel
    • CSV
    • JSON
    • PNG
    • Files or Other supported formats

    This enables organizations to retain full control over their information and avoid vendor lock-in.

  • End of Subscription

    If a Customer decides to discontinue the use of M&E Plus, the Customer may request a complete export of its information.

    Following the completion of the export process and any applicable retention period, customer information will be removed from active production systems and subsequently deleted from backup systems in accordance with established retention and deletion procedures.

Security Overview

  • Protecting Your Information

    Security is a core component of the M&E Plus platform.

    We recognize that organizations use M&E Plus to manage operational, programmatic, and in some cases sensitive information. Our security approach combines technology, processes, and operational controls designed to help protect customer information from unauthorized access, disclosure, alteration, or loss.

  • Cloud Infrastructure

    M&E Plus is hosted on secure cloud infrastructure designed to provide reliability, scalability, and availability.
    The platform benefits from modern cloud security capabilities including physical security, network protection, infrastructure monitoring, and redundancy mechanisms.

  • Encryption

    M&E Plus uses encryption technologies to help protect information during transmission and storage.

    Security measures may include:

    • Encrypted communications using industry-standard TLS protocols
    • Encryption of stored information where applicable
    • Secure password storage mechanisms
    • Secure backup procedures
  • Access Control

    Access to information within M&E Plus is governed through role-based permissions and user authentication controls.

    Organizations can define user roles and access levels according to their operational requirements.

    Access control capabilities may include:

    • Role-based permissions
    • User management
    • Password policies
    • Multi-factor authentication capabilities
    • Session management controls
  • Audit and Accountability

    M&E Plus supports accountability through audit and monitoring capabilities.

    Depending on configuration, audit records may include:

    • User logins
    • Data creation activities
    • Data modifications
    • Data exports
    • Administrative actions
    • Security-related events
  • Backup and Recovery

    To help protect customer information against accidental loss or system failure, M&E Plus incorporates backup and recovery procedures.

    Backup processes are designed to support business continuity and service recovery requirements.

  • Security Monitoring

    Security controls and platform operations are regularly reviewed to identify risks, strengthen protections, and support platform reliability.

    Security measures continue to evolve as technology, regulations, and customer requirements change.

  • Shared Responsibility

    Security is a shared responsibility.

    While M&E Plus provides technical and operational safeguards, customers also play an important role through:

    • Appropriate user management
    • Access control reviews
    • Strong password practices
    • User awareness and training
    • Responsible for handling exported information

    Together, these measures help create a secure environment for managing organizational data.

GDPR Compliance Statement

  • Our Commitment to Privacy

    M&E Plus is committed to protecting personal information and supporting customers in meeting their privacy and data protection obligations.

    Our privacy practices are designed to align with internationally recognized data protection principles, including those reflected in the European Union General Data Protection Regulation (GDPR).

  • Data Controller and Data Processor

    For most implementations of M&E Plus:

    The Customer acts as the Data Controller.

    ArabiaGIS K&A Plus acts as the Data Processor.

    As Data Controller, the Customer determines:

    • The purpose of data collection
    • The lawful basis for processing
    • Data retention requirements
    • User permissions and access rights

    As Data Processor, ArabiaGIS K&A Plus processes information solely for the purpose of providing and supporting the M&E Plus platform.

  • Supporting Data Subject Rights

    M&E Plus is designed to support customer obligations related to data subject rights.

    Depending on configuration and customer policies, organizations may use platform capabilities to support:

    • Access requests
    • Data correction requests
    • Data export requests
    • Data deletion requests
    • Data portability requests

    Requests relating to personal data should generally be directed to the organization acting as the Data Controller.

  • Privacy by Design

    Privacy considerations are integrated into the design, development, and operation of the platform.

    This includes consideration of:

    • Access controls
    • Data minimization
    • User permissions
    • Auditability
    • Secure processing practices
  • Security Measures

    M&E Plus incorporates technical and organizational measures designed to help protect personal information, including:

    1. Access controls
    2. Authentication mechanisms
    3. Encryption technologies
    4. Audit logging capabilities
    5. Backup and recovery procedures
    6. Security monitoring practices
  • International Data Transfers

    Where information is processed using cloud infrastructure or authorized service providers, appropriate safeguards are applied to support the secure handling of information.

  • Contact

    Questions relating to privacy, data protection, or GDPR-related matters may be directed to:
    privacy@mandeplus.com

    We continuously review our privacy practices and policies to align with evolving regulations, customer expectations, and industry best practices.