Privacy Policy
Effective date: 25 July 2026 · MELscope, operated by ImpactSpring Smart Farm, a business registered in Papua New Guinea ("MELscope", "we", "us").
MELscope is a monitoring, evaluation and learning (MEL) platform for donor-funded development projects. This policy explains what data we collect, how we protect it, and the rights of the people it concerns. We take this seriously because our clients' data often includes information about project beneficiaries — some of the most vulnerable people our clients serve.
1. The two kinds of data we handle
- Account and website data (we are the data controller). Names, email addresses and organisation details you give us when you create an account, request access, or contact us; and basic technical logs needed to run the service securely. The access request form specifically collects your name, work email address and organisation, and optionally your job title; together with details of the project you want to manage — its name, donor, location, start and end dates, an optional approximate budget range, and anything you choose to tell us in the free-text field. Only name, email and project name are required. We record the time you accepted this policy and the Terms of Service.
- Project data (we are a data processor). Indicators, results, sites, documents and beneficiary records that client organisations enter into their own project workspace. The client organisation controls this data and decides what is collected; we store and process it only to provide the service, on the client's instructions.
2. Beneficiary data and consent
Client responsibility: organisations that record identifiable beneficiary information (such as names) in MELscope are responsible for having a lawful basis to do so — normally the informed consent of the person concerned or their guardian, or a donor/administrative requirement. MELscope provides a consent field on every register entry so this can be recorded and evidenced.
MELscope applies privacy-by-design protections to beneficiary records:
- Beneficiary names are never included in share links. External stakeholders and evaluators using a share link see pseudonymised IDs (e.g. BEN-0042) and aggregate statistics only.
- Access to named records is restricted to the project's own team members under role-based, row-level access control.
- Beneficiary data is never used for marketing, profiling, or any purpose other than the client's own monitoring and reporting.
3. What we use account data for
- Creating and securing your account, and linking you to the projects you are invited to.
- Responding to access requests and support messages.
- Service notices (for example payment confirmation or security alerts). We do not send marketing emails without your consent.
Each field on the access request form has a specific purpose, and we ask for nothing beyond it:
- Name and work email — to reply to you, and because approving a request creates a project whose ownership is claimed by whoever signs up with that exact address. We ask for an organisational address so that ownership of the workspace stays with the organisation rather than an individual, but we do not refuse personal addresses.
- Job title (optional) — so that onboarding matches your role, and so we know whether we are speaking to the person who decides.
- Project name, donor, location — to set up the workspace and check the platform fits your reporting obligations.
- Project start and end dates (optional) — to configure time-phased targets, and to check that a three-month free trial fits within the life of your project.
- Approximate budget range (optional) — to suggest an appropriate plan. We ask for a range, never an exact figure, "Prefer not to say" is an accepted answer, and the choice does not affect whether a request is approved. We recognise that budget detail is commercially or operationally sensitive for some programmes.
We use this information to assess and respond to your request and to set up your workspace. We do not use it for profiling, we do not sell it, and we do not share it with other clients. If we decline a request, or you ask us to, we delete the record.
4. Where data is stored and how it is protected
- Data is hosted with Supabase on Amazon Web Services infrastructure, encrypted in transit (TLS) and at rest.
- Every table is protected by row-level security: users can only read or change data for projects they are a member of, according to their role (owner, editor, evaluator).
- Share links are read-only, expire automatically, and can be revoked at any time by the project owner.
- Uploaded documents are stored in private storage and served through short-lived signed URLs.
- The website is served through Cloudflare, which may process technical connection data (such as IP addresses) to deliver and protect the site.
- Third-party assets loaded by your browser. To keep the application small we load some open-source libraries from public code distribution networks (cdnjs, operated by Cloudflare, and jsDelivr). Where a project site map is displayed, the background map tiles are loaded from CARTO. Requests of this kind reveal your IP address to those providers, and in the case of map tiles, the approximate area being viewed. We set no cookies through them. Typefaces are served from our own domain, not from Google Fonts, so displaying a page sends nothing to Google. If your programme operates in a context where even the approximate location of project sites is sensitive, tell us — the site map can be disabled for your workspace.
- AI-drafted reports (optional, administrator-triggered). When a project administrator chooses to generate an AI report, MELscope sends that project's aggregated results data — indicators, targets, activity summaries and anonymised beneficiary counts (never individual names) — to Anthropic, the provider of the Claude AI model, which drafts the report narrative and returns it. This happens only when an administrator triggers it. Anthropic processes the data solely to produce the report and does not use data submitted through its API to train its models. If you prefer not to use this feature, do not generate AI reports — the rest of MELscope works without it.
5. Sharing and disclosure
We never sell or rent data. We disclose data only: (a) to the sub-processors named above (Supabase/AWS for hosting; Cloudflare for delivery and protection; cdnjs, jsDelivr and CARTO for browser-loaded assets as described in section 4; and — only when an administrator generates an AI report — Anthropic) strictly to operate the service; (b) within a client's project, according to the roles and share links the client itself creates; or (c) where required by law.
Project and beneficiary data is never sent to the asset providers in section 4. They receive only the technical request needed to deliver a script, stylesheet or map tile.
6. Retention and project close-out
- Project data is retained for as long as the client's project workspace is active.
- When a project closes, the workspace becomes read-only and the client can export all data (Excel and documents) at any time.
- Clients may request permanent deletion of their project workspace, including beneficiary records, by writing to us; we complete deletion within 30 days and confirm in writing.
- Account data is deleted on request, subject to records we must keep for legal or accounting reasons.
7. Your rights
You may ask us to access, correct, export or delete the personal data we hold about you. Beneficiaries whose data was entered by a client organisation should contact that organisation first (as data controller); we will support the client in honouring the request. Contact us at info@melscope.com — we respond within 30 days.
8. Legal framework
MELscope is operated from Papua New Guinea, where the right to privacy is protected under Section 49 of the Constitution of the Independent State of Papua New Guinea. Because many of our clients implement projects funded by international donors (including the GEF, the European Union, DFAT and MFAT), we align our practices with internationally recognised data-protection principles, including those of the EU General Data Protection Regulation (GDPR): lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
9. Children's data
Client projects may record data about children as beneficiaries (for example school WASH programmes). Clients are responsible for obtaining guardian consent where required. MELscope applies the same technical protections described in section 2, and never exposes identifiable children's data through share links.
10. Changes to this policy
If we make material changes we will post the new version here and notify account holders by email. Continued use of the service after changes take effect constitutes acceptance.
11. Contact
ImpactSpring Smart Farm
Port Moresby, Papua New Guinea
info@melscope.com