Last updated 19 August 2026
Agent MEL is a workspace for organisations doing monitoring, evaluation, and learning. You connect your own data, ask questions about it, and produce reports and indicators. This policy explains what we hold, why we hold it, and who else touches it.
This policy covers the Agent MEL service. It does not cover anything you do on the third-party services you choose to connect.
We are the data user for the account and usage data described below. For the content you upload into your organisation's workspace, we act on your organisation's behalf: your organisation decides what goes in and what comes out, and we only handle it to run the service.
Any usage data we collect is used strictly to improve the product experience — understanding which features are used, where they fail, and what needs fixing. We do not use it for advertising, we do not sell it, and we do not run third-party ad or tracking scripts on the service.
Answering your questions requires sending part of your workspace content to a large language model. Before we do, we strip personally identifiable information from the material we send. The exception is what you type yourself: if you include personal details in a message, or ask a question that requires the model to see them, they are sent as you wrote them. Please avoid putting personal data about staff, partners, or beneficiaries into your messages unless the analysis genuinely needs it.
Content sent to a model is used to produce your answer and nothing else. We do not use your content to train models.
Agent MEL's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to third parties except as required to provide and improve the service, nor do we use it for serving advertisements or training AI models.
We do not sell your data and we do not share it for advertising. We disclose it only on a need-to-know basis, under contracts that limit what recipients may do with it, to the following categories of recipient:
We will tell you the identity of any current provider on request, at the address below.
Your data resides in the jurisdiction in which we operate. We currently operate only in the Hong Kong SAR, and your data is held there. If we begin operating elsewhere, and that would mean holding your data in another jurisdiction, we will update this policy and notify you before the change takes effect.
Workspace content is kept while your organisation is using the service. You or an organisation admin can delete content in the app at any time; deleting a source or a conversation also removes the material derived from it — extracted text, embeddings, and attachments.
You may also request deletion of your data by writing to us. We will complete the deletion within 30 days of the request, across our live systems and our backups. We will confirm once it is done. Where the law requires us to retain something (for example, records we must keep for a fixed period), we will tell you what we kept and why.
Access to your organisation's data is scoped to its members and enforced in the database itself, so a signed-in user cannot read another organisation's records. Data is encrypted in transit and at rest. Uploaded files are stored in a private bucket and served only through short-lived, signed links. No system is perfectly secure, and we cannot guarantee absolute security.
We handle personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) and its six Data Protection Principles: we collect personal data lawfully and only what is necessary; we keep it accurate and no longer than needed; we use it only for the purposes set out in this policy, or a directly related purpose, unless you consent otherwise; we take practicable steps to keep it secure; we are open about our practices; and we honour your rights of access and correction.
Under Data Protection Principle 6 and sections 18, 22, and 38 of the Ordinance, you have the right to ask whether we hold personal data about you, to be given a copy of it, and to have inaccurate data corrected. Send a data access or correction request to the address below. We will respond within 40 days, as the Ordinance requires. We may charge a fee for complying with a data access request, but it will not be excessive; we will tell you the amount before we proceed.
We do not use your personal data in direct marketing, and we do not provide it to anyone else for their direct marketing, without your consent.
If you are not satisfied with how we have handled your data, you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong (pcpd.org.hk).
If you are outside Hong Kong, you may have additional rights under your local law — such as portability, erasure, or objection to processing. Write to us and we will honour them where they apply.
The service is not intended for children under 16, and we do not knowingly collect their personal data. Note that data about beneficiaries, including children, may appear in the content an organisation uploads; that content is the organisation's responsibility.
We will update this policy as the service changes. If a change matters to you, we will say so in the app before it takes effect. The date at the top always reflects the current version.
Questions, data access or correction requests, deletion requests, or complaints: legal@nous.life.