The Client is the controller of all personal data within Client Data. The Processor acts solely as processor on the Client's behalf. The Client determines what personal data is collected, from whom, on what lawful basis, and for what purpose. The Processor does not determine the purposes or means of processing and has no independent relationship with the Client's beneficiaries.
Where the Processor handles the contact details of the Client's own staff for account administration, billing and support, it acts as a controller for that limited purpose, as described in the Privacy Policy.
The Client warrants that:
The Processor shall:
The Client grants general authorisation for the Processor to engage the sub-processors listed in Annex B. The Processor shall impose data-protection obligations on each sub-processor no less protective than those in this agreement, and remains fully liable to the Client for their performance.
The Processor will give the Client at least 30 days' notice before adding or replacing a sub-processor that handles personal data. If the Client reasonably objects on data-protection grounds within that period, the parties will discuss in good faith; failing resolution, the Client may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.
Client Data is stored at rest in Australia (AWS Asia Pacific, Sydney). The Processor is established in Papua New Guinea and accesses Client Data from there to operate and support the Services. The AI drafting sub-processor is established in the United States and receives only the limited categories described in Annex A.
Where the Client is established in the EU/EEA or the UK, or is otherwise subject to a law restricting international transfers, the parties shall enter into the applicable Standard Contractual Clauses or equivalent approved mechanism, which shall take precedence over this section to the extent of any conflict. The Processor will provide reasonable assistance with any transfer impact assessment.
The Processor shall maintain the measures described in Annex C and in the Security & Data Protection Pack, which is incorporated into this agreement by reference. The Client acknowledges it has read that document, including its stated limitations, and has satisfied itself that the measures are appropriate to the risk of the personal data it chooses to upload.
The Processor shall make available to the Client the information reasonably necessary to demonstrate compliance with this agreement, and shall allow for and contribute to audits, including inspections, conducted by the Client or a mandated auditor.
In practice, and to keep cost proportionate for both parties: the Processor will first provide its Security Pack, written responses to the Client's security questionnaire, and evidence of its sub-processors' certifications. Where these are insufficient, the Client may request an audit on 30 days' written notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach. Audits shall take place during business hours, shall not unreasonably disrupt the Processor's operations, and shall not grant access to other clients' data.
On termination or expiry, the Client may export all Client Data through the Services' export functions. For 30 days after termination the Client retains read-only access for this purpose. Thereafter, on the Client's written request, the Processor shall delete Client Data from production systems within 30 days and confirm deletion in writing. Residual copies within backups and system logs shall be deleted on their ordinary expiry cycle and shall not be restored into production except as part of a disaster-recovery event affecting the whole platform.
The liability provisions of the Terms of Service apply to this agreement. Nothing in this agreement limits either party's liability to a data subject or a supervisory authority under applicable data-protection law.
This agreement is governed by the laws of Papua New Guinea, without prejudice to any mandatory data-protection law applying to the Client, and to any Standard Contractual Clauses entered into under section 6, which are governed as those clauses provide. Both parties should confirm this clause with their own legal advisers; a Client subject to EU or UK law may reasonably require a different forum.
This agreement takes effect on the earlier of the Client's signature or the Client's first use of the Services, and continues for as long as the Processor processes Client Data.
| Subject matter | Provision of the MELscope monitoring, evaluation and learning platform. |
|---|---|
| Duration | The term of the Client's subscription, plus the wind-down period in section 9. |
| Nature and purpose | Storage, organisation, retrieval, aggregation, analysis and export of project monitoring data; generation of donor reports; provision of read-only access to evaluators and stakeholders nominated by the Client. |
| Categories of data subjects | The Client's staff and authorised users; project beneficiaries; evaluators and stakeholders given access by the Client; named responsible officers and implementing partner contacts. |
| Categories of personal data | Account users: name, work email address, organisation, job title, role. Beneficiaries: pseudonymous display identifier, full name where the Client chooses to record it, sex, youth status, organisation, benefit type, site or location, and consent status. Stakeholder contacts: where the Client chooses to record them, the name, role or job title, email address and telephone number of a contact person at a stakeholder organisation. These fields are optional, are visible only to the Client's own project team, and are excluded from every read-only share link. |
| Special category data | Yes — potentially. Disability status is recorded as a disaggregation category and constitutes data concerning health under GDPR Article 9. Where the Client records it, the Client must identify an Article 9 condition for doing so. MELscope holds disability primarily as aggregate counts rather than against named individuals. |
| Children's data | Possible where the Client's programme serves children (for example school WASH programmes). Guardian consent is the Client's responsibility. |
| Data sent to the AI sub-processor | Indicator values, targets and variances; results-framework statements; activity narratives; site records; document titles; aggregate and pseudonymised beneficiary counts; and the Client's uploaded report template text. Beneficiary names are not sent. |
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage, server-side functions | AWS Sydney, Australia |
| Amazon Web Services, Inc. | Underlying cloud infrastructure | Sydney, Australia |
| Anthropic PBC | AI drafting of donor reports | United States |
| Resend | Transactional email | United States |
| Cloudflare, Inc. | Static site hosting and delivery | Global edge network |
CARTO (map tiles) and the cdnjs and jsDelivr content networks deliver assets to the user's browser and receive IP addresses, but store no Client Data.
Signed for and on behalf of the parties:
To execute this agreement, or to request it as an editable document, contact info@melscope.com.