本文件为法律文件,只以英文维护。英文版本为准。
MeeOpp Privacy and Data Protection Compliance Statement
Contents
- Introduction and School Data Roles
- Personal Information Collection Statement (PICS)
- Personal Data We Collect and Google SSO
- How We Use Personal Data and AI Training Prohibition
- Your Rights, Response Times and Fees
- Data Retention and Erasure Schedule
- Data Security and Third-Party Assurance
- Internal Data Handling Guidelines
- Vendor and Third-Party Agreements
- Data Transfers Outside Hong Kong
- Data Breach Response and Mitigation
- Children's Privacy
- Cookies & Tracking Technologies
- Direct Marketing
- Third-Party Links
- User Content
- Updates to This Policy
- Contact Us
MeeOpp Personal Information Collection Statement (PICS)
Additional Sections
1. Introduction
Meego Technologies Limited ("MeeOpp") and its subsidiaries (collectively, "MeeOpp", "we", "us", or "our") respect your privacy and are committed to protecting personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of the Hong Kong SAR.
This Privacy Policy explains how we collect, use, disclose, process, retain, secure, and manage personal data when you use our websites, services, platforms, and applications (collectively, the "Services"). By accessing or using our Services, you agree to the terms of this Privacy Policy.
We ensure that all personal data collected is handled in accordance with the six Data Protection Principles (DPPs) under the PDPO:
- Purpose and Manner of Collection
- Accuracy and Retention
- Use of Data
- Data Security
- Transparency
- Access and Correction
1.1 School Data and controller / processor roles
For Services provided to a school, the school is the data controller (the data user under the PDPO) and Meego Technologies Limited acts as its data processor for School Data. "School Data" means personal data and user content supplied by the school or collected or generated on its behalf in delivering the Services, including student and staff account details, assignments, learning records, feedback, recordings, transcripts, AI prompts and outputs, and associated usage records.
The school determines the purposes of processing School Data. MeeOpp processes School Data only on the school's documented instructions to deliver, secure and support the contracted Services, and requires its subprocessors to follow the same restrictions. We do not use School Data for our own independent research, product development or marketing. The school's responsibility for notices and any required consent does not remove MeeOpp's obligations as a processor.
MeeOpp acts as a separate data user for personal data it processes for its own direct customer relationships, website enquiries and legally required business records. This does not permit us to repurpose School Data or retain student content as a business record without a specific legal requirement.
1.2 School agreements and priority
A signed data processing agreement (DPA) with a school governs processing on that school's behalf and takes precedence over conflicting general provisions of this Privacy Policy, the PICS and the Terms of Service. In the absence of such a conflict with a signed DPA, the School Data protections in this policy take precedence over general permissions to use, improve or retain data. Individual account acceptance, marketing consent or continued use cannot override the school's instructions or these School Data protections.
2. Personal Information Collection Statement (PICS)
We provide a clear and accessible Personal Information Collection Statement (PICS) at the time personal data is collected. The PICS includes:
- Purpose of collecting the data
- Whether provision of data is voluntary or obligatory
- Consequences of failing to provide data
- Classes of transferees
- Data subject rights
- DPO contact details
In accordance with Data Protection Principle 1 of the PDPO, our PICS is issued at or before the time of collection and is available through our website.
MeeOpp proactively conducts Privacy Impact Assessments (PIAs) for new or significantly altered systems involving personal data.
3. Personal Data We Collect
3.1 Types of personal data
We may collect, hold, process, transfer and use the following types of personal data:
- full name*
- email address*
- school*
- school grade*
- phone number
- audio / video recordings from sessions
- date of birth
- username
- device and usage data (IP address, browser, device type, pages visited)
- user-generated content (messages, uploads, feedback)
- third-party data (integration services)
- learning performance and behavioural data
* mandatory personal data
3.2 Failure to provide mandatory data
May result in us being unable to provide the Services.
3.3 School Google single sign-on (SSO)
MeeOpp supports authentication using a school's Google Workspace accounts. Students and staff can use their school-issued Google account to sign in to the Services. Google handles authentication; MeeOpp does not receive or store the user's Google password. We process the identity information needed to authenticate and match the account, such as the user's name, school email address and Google account identifier, for account access and security.
The school manages its Google Workspace accounts and any administrator approvals required to allow sign-in. Any requirement to restrict access to particular school domains or accounts must be agreed and configured with the school. School SSO data is subject to the School Data protections, deletion schedule and marketing and AI training restrictions in this policy.
4. How We Use Personal Data
We may collect, process, hold, transfer and use personal data for the following purposes:
- Account creation and management
- Delivery, analysis, and improvement of Services
- Communication with users, parents, or guardians
- Quality assurance, research, and product development
- Security, fraud prevention, and monitoring
- Compliance with applicable law
- Establishment, exercise, or defence of legal rights
These purposes are subject to the School Data restrictions in Section 1.1, the AI training prohibition below and the marketing controls in Section 14. School Data is used only on the school's documented instructions. For other personal data, any new purpose requires the consent or other authority required by applicable law.
4.1 Prohibition on AI model training
MeeOpp will not use, or permit its service providers or subprocessors to use, personal data or user content to train, fine-tune or improve general-purpose or shared AI models, or models for use by other customers. This prohibition covers recordings, transcripts, assignments, prompts, responses, feedback and learning records, including pseudonymised, de-identified, anonymised or aggregated versions derived from them. School Data will not be used for AI model training or fine-tuning of any kind.
AI processing of user data is limited to applying existing models to deliver the requested Services, such as generating learning activities and feedback or assessing responses. For School Data, this processing must follow the school's documented instructions. MeeOpp will require binding no-training terms from AI providers and use service settings that prevent provider model training and optional data sharing for model improvement. General references to research, service improvement or internal training do not create an exception to this prohibition.
5. Your Rights
Subject to the PDPO, you have the right to:
- access personal data held about you
- request correction of inaccurate data
- request deletion (subject to lawful retention requirements)
- manage communication and marketing preferences
5.1 Requests and response times
Send access, correction or deletion requests to our Data Protection Officer at csteam@meeopp.com. We may ask for information reasonably necessary to verify your identity and authority. We handle PDPO data access and correction requests without undue delay and, subject to the Ordinance's permitted exceptions, complete them within 40 calendar days after receipt. Where the PDPO permits refusal or delayed compliance, we provide the required written reasons within that period and comply as soon as practicable where required. Identity checks do not create an automatic extension of a statutory deadline.
For School Data, we promptly refer requests to the school and assist it in responding, including supplying the relevant data and implementing its instructions within the applicable deadline. You may contact the school or MeeOpp; referral does not remove any duty imposed on us by law. Where GDPR applies, the one-month response period and permitted extensions in Section 19.3 apply. If more than one deadline applies, we meet the earlier deadline.
5.2 Fees
Data correction requests are free of charge. MeeOpp does not charge schools for routine access, correction or erasure assistance relating to School Data. For other PDPO data access requests, any fee is limited to the directly related and necessary cost of compliance and must not be excessive. We explain the amount and its basis before charging, as soon as possible and no later than 40 calendar days after receipt. We do not include general overheads, legal advice costs or a profit margin. The GDPR fee rules in Section 19.3 apply to requests under GDPR.
6. Data Retention
We retain personal data only for its specified purpose. The following schedule applies to School Data, including account details, assignments, learning records, recordings, transcripts, AI prompts and outputs, associated usage records and copies or derivatives held by MeeOpp or its subprocessors.
6.1 School Data retention and erasure schedule
- During the Services: School Data is retained only for the period needed to deliver the school's contracted Services on its documented instructions. A school may require earlier deletion of any or all School Data at any time.
- Active systems and subprocessors: We erase the affected School Data from active systems, including subprocessor systems, within 30 calendar days after receipt of an authorised school erasure request or the end of the school's Services, whichever occurs first. We stop using that data for ordinary service purposes once the request or termination takes effect. If the school requests a return of its data, we arrange that return within the same period before erasing our copies.
- Backups: Remaining copies in backups, including subprocessor backups, are erased or expire within 90 calendar days of the same request or end of Services. During that period, they are isolated from ordinary use and accessed only for necessary disaster recovery. If a backup is restored, the erasure instructions are reapplied before the restored data is returned to operational use.
- Confirmation: We provide written confirmation of active-system erasure within the 30-day period and backup erasure within the 90-day period, including the status of subprocessor copies and any strictly required legal retention described below.
The school does not need to provide a reason for erasure. We do not make erasure conditional on payment, contract renewal or MeeOpp's consent. Research, service improvement, possible future use and general business interests are not grounds to retain School Data. These requirements also apply to pseudonymised, de-identified, anonymised or aggregated copies derived from School Data that we hold. Shorter periods agreed in a signed DPA apply.
6.2 Strictly required legal retention
The only exception to school-requested erasure is where a specific applicable law or binding legal order requires us to retain particular records. We retain only those records for the required period, restrict access and processing to that legal purpose, and erase them when the obligation ends. Unless legally prohibited, we tell the school which records are retained, the specific legal basis and required duration or release condition. An exception for one record does not delay erasure of the remaining School Data.
6.3 Other personal data
For personal data outside School Data, retention is limited to the period necessary for the purposes explained at collection and any specific applicable legal requirement. Requests are handled under Section 5 and, where applicable, Section 19.3. This provision does not extend the School Data deadlines above.
7. Data Security
We take all practicable steps to safeguard personal data against unauthorised or accidental access, processing, erasure, loss or use. Security measures include:
- Encryption of data at rest and in transit
- Role-based access controls
- Authentication and access logging
- Regular audits and risk assessments
- Incident response procedures
- Staff training on data protection obligations
However, no system is fully secure, and transmissions over networks outside our control are at your own risk.
7.1 Third-party security certifications and reports
MeeOpp will use cloud hosting and storage services for School Data that are covered by current ISO/IEC 27001 certification and/or SOC 2 Type II reports. We will review the relevant service scope and assurance evidence when selecting those services and on renewal, and require appropriate contractual and security safeguards from all subprocessors.
AWS and Google Cloud publish independent assurance information for their covered services:
- Amazon Web Services: ISO/IEC 27001 certification and SOC reports; detailed reports are available through AWS Artifact subject to its access and confidentiality conditions.
- Google Cloud: ISO/IEC 27001 certification and SOC 2 Type II reports; detailed reports are available through Google's Compliance Reports Manager subject to its access conditions.
On a school's request, MeeOpp will identify the providers and services used for that school's data and provide the relevant publicly available certificates and information on obtaining restricted audit reports, subject to provider confidentiality terms. Certifications and reports cover the provider services and periods specified in the evidence. They do not certify MeeOpp itself or remove our responsibility for our application, configuration and data handling. GDPR is a legal framework, not a substitute for this independent security assurance.
8. Internal Data Handling Guidelines
We maintain internal guidelines governing staff and contractor handling of personal data, including:
- data minimisation and purpose limitation
- secure data storage, transmission, and access controls
- prohibition of unauthorised downloads, transfers, or local storage
- mandatory reporting of suspected data incidents
- confidentiality obligations
Staff and contractors must:
- use authorised systems only
- complete privacy compliance training
- comply with security protocols and confidentiality requirements
9. Vendor and Third-Party Agreements
We may transfer personal data to third-party service providers ("Permitted Transferees") engaged to support our operations. Permitted transferees must:
- process data only on our instructions
- implement security safeguards
- not disclose or use data for unrelated purposes
- comply with contractual, legal, and confidentiality obligations
Vendor categories include:
- administrative service providers
- telecommunications and cloud services
- analytics and processing providers
- market research, advisory, legal, and accounting firms
- payment processors
We do not sell personal data to third parties.
For School Data, providers act as subprocessors under written obligations covering confidentiality, security, assistance with requests, retention and deletion, and the prohibition on AI model training in Section 4.1. Their access is limited to what is necessary to provide the contracted Services on the school's instructions. MeeOpp remains responsible for their processing on its behalf; a provider's separate terms do not override our commitments to the school.
10. Data Transfers Outside Hong Kong
Personal data may be processed or stored in jurisdictions with different data protection laws.
By using our Services, you acknowledge this and consent where required.
11. Data Breach Response and Mitigation
A data breach includes any incident involving unauthorised or accidental:
- access, disclosure, loss, or destruction of personal data
- system compromise or security failure
If we become aware of a breach, we will:
- activate internal incident response procedures
- contain and mitigate the incident
- investigate severity, cause, and impact
- document findings and corrective actions
Where appropriate, we will consider notifying:
- affected individuals
- relevant authorities
- other impacted stakeholders
Notifications, where made, will include:
- nature of incident
- affected data
- potential risks
- steps taken by us
- steps individuals may take
Following a breach, we will review safeguards and policies to reduce recurrence.
12. Children's Privacy
We provide enhanced protections for users under 18. We may:
- limit the collection of data to what is necessary
- require teacher or parent authorisation
- restrict access to personal data to authorised staff
- provide rights of access, correction, or deletion
Children are encouraged to consult a parent or teacher before submitting personal data.
13. Cookies & Tracking Technologies
We use cookies for:
- login and authentication
- analytics (Google Analytics, Amplitude)
- device optimisation and security
Users may disable cookies, but some functionality may be limited.
14. Direct Marketing
We do not send direct marketing communications to students or use student personal data for direct marketing. We do not disclose School Data to third parties for their own marketing.
Direct marketing is set to NO by default for school staff and other adult users. We send marketing about MeeOpp's Services only after a separate, specific and affirmative opt-in that identifies the data to be used and the classes of services to be marketed. Account creation, acceptance of these terms, participation through a school and consent to service-related messages do not constitute marketing consent. Pre-ticked boxes and silence are not consent.
Users can withdraw marketing consent at any time, free of charge, using the unsubscribe option in a marketing message or by emailing csteam@meeopp.com. We will stop the affected marketing communications. Necessary account, lesson, security and support messages may still be sent, but will not be used to include promotional content. An individual opt-in does not override a school's DPA restrictions or the prohibition on student marketing.
15. Third-Party Links
Our Services may contain links to external sites. We are not responsible for their content or privacy practices.
16. User Content
You grant MeeOpp a limited licence to process content you upload as necessary to deliver, secure and support the Services. School Data is processed only on the school's documented instructions. This licence is subject to the AI training prohibition in Section 4.1 and the retention and deletion requirements in Section 6. We claim no ownership over your content. You are responsible for ensuring that your content does not violate intellectual property, privacy, or legal rights of others.
17. Updates to This Policy
We may modify this Privacy Policy from time to time. Updated versions and their revision dates will be posted on our website, and we will notify affected schools of material changes. Website updates and continued use do not amend a signed DPA or authorise additional processing of School Data. Where new consent is required by law, we obtain it separately.
18. Contact Us
To request access, correction, or deletion of personal data, or to ask privacy-related questions, please contact our Data Protection Officer:
Data Protection Officer
Email: csteam@meeopp.com
Alternate Contact: jeffrey.l@meeopp.com
MeeOpp Personal Information Collection Statement (PICS)
1. Introduction
This PICS informs you of:
- purposes of collecting personal data
- data transferees
- rights of access and correction
- how to contact us
This PICS provides information about our handling of personal data. Submitting data does not constitute consent to direct marketing or AI model training and does not override the school's instructions for School Data.
2. Data User
For School Data, the school is the data controller (data user) and Meego Technologies Limited is its data processor. MeeOpp is a separate data user for the limited purposes described in Section 1.1. The school's own collection statement also applies to processing it controls.
3. Personal Data Collected
As described in Section 3 above.
4. Purposes of Use
As described in Section 4 above.
5. Permitted Transferees
As described in Section 9 above.
6. Rights of Access and Correction
As described in Section 5 above.
7. Direct Marketing
As described in Section 14 above.
8. Contact
Users may request access or correction by contacting:
Data Protection Officer
Email: jeffrey.l@meeopp.com
GDPR Applicability and Compliance
19.1 Scope of Application
The General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to the collection, processing, and transfer of personal data relating to individuals located in the European Union ("EU Data Subjects"), regardless of nationality. For the avoidance of doubt, unless otherwise provided under this GDPR Applicability and Compliance section, the other provisions of this Privacy and Data Protection Compliance Statement shall continue to apply to EU Data Subjects (including but not limited to Section 3 (Personal Data We Collect) and Section 4 (How We Use Personal Data)).
While MeeOpp primarily serves clients in Hong Kong, Singapore, and other parts of Asia, EU Data Subjects may access or use our Services, for example, students participating in international programs, families residing in the EU, or institutional clients with EU-based participants. Where we collect or process personal data of an EU Data Subject, we will comply with the applicable GDPR requirements.
19.2 Legal Bases for Processing
Where the GDPR applies and MeeOpp acts as controller, we process personal data on one or more of the following legal bases. For School Data, the school determines the applicable lawful basis and MeeOpp processes the data on its documented instructions. These legal bases do not override the AI training prohibition or marketing controls in this policy.
(a) Consent – Where you have given clear, affirmative consent for us to process your personal data for a specific purpose. Examples include a separate adult opt-in to receive marketing about MeeOpp's Services, or consent to session recordings where required. We do not market to students, and staff marketing remains off unless separately opted in, as set out in Section 14.
(b) Performance of a contract – Where processing is necessary to deliver the Services you have requested, to perform a contract that you are a party to, or to take steps at your request before entering into a contract. For example, creating and managing your account, scheduling and delivering lessons, or processing payments.
(c) Legitimate interests – Where processing is necessary for our legitimate interests, provided those interests are not overridden by your interests or fundamental rights and freedoms. Examples include preventing fraud and securing our platform. We do not rely on our own legitimate interests to repurpose School Data. Internal staff training uses synthetic examples or materials that do not contain user data; it does not authorise AI model training or reuse of session recordings.
(d) Legal obligation – Where processing is necessary to comply with a legal requirement that we are subject to, such as maintaining records for tax purposes or responding to lawful requests from authorities.
(e) Vital interests – In rare circumstances, where processing is necessary to protect a person's vital interests.
(f) Public interest – Where processing is necessary for a task carried out in the public interest (which is unlikely to apply to most of our Services).
19.3 EU Data Subject Rights
Under GDPR, EU Data Subjects have the following rights, subject to applicable limitations and exceptions:
Right of access – You can request a copy of the personal data we hold about you and that are being processed. The first copy is free. For further copies, we may charge a reasonable fee based on administrative costs where GDPR permits; the no-charge commitment for routine School Data assistance in Section 5.2 continues to apply.
Right to rectification – You can ask us to correct inaccurate or incomplete data concerning you.
Right to erasure (right to be forgotten) – You can ask us to delete your personal data in the circumstances set out in Article 17 of the GDPR, subject to the exceptions specified there. For School Data, the school's erasure instructions and the fixed deadlines in Section 6 apply, with only the specific legal-retention exception in Section 6.2. General research, improvement or business interests do not override those instructions.
Right to restriction – You can ask us to limit how we process your personal data in certain circumstances set out under Article 18 of the GDPR, such as during the period of time required by us to verify the accuracy of your personal data when you have contested the accuracy of the same.
Right to data portability – You can request your personal data in a structured, commonly used and machine-readable format and have it transferred to another provider where (i) technically feasible; (ii) our processing was based on your consent or was necessary for the performance of a contract to which you were a party; and (iii) our processing was carried out by automated means.
Right to object – You can object to processing based on legitimate interests. We will stop unless we establish grounds permitted by GDPR to continue. If you object to direct marketing, we stop that processing, including related profiling, without applying a legitimate-interests exception.
Right to withdraw consent – Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing that occurred before withdrawal.
Rights related to automated decision-making – You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects, unless certain exceptions apply under Article 22 of the GDPR (for example, where the decision based solely on automated processing is necessary for the performance of a contract between us and you, or is authorised by Union or Member State law with appropriate safeguards, or is otherwise based on your explicit consent).
To exercise any of these rights, contact our Data Protection Officer using the details in Section 19.7 below. We will respond without undue delay, and in any event, within one month of receipt of your request, though this may be extended by up to two additional months taking into account the complexity and number of the requests. We will inform you of any extension within one month of the receipt of your relevant request together with the reasons for it. We will communicate any rectification, erasure or restriction of data processing carried out pursuant to your requests to any recipients to whom your personal data has been disclosed, unless doing so would prove impossible or involves disproportionate efforts.
19.4 Consent Standards
Where we rely on consent as a legal basis, we will obtain it in a manner that is freely given (i.e., you have a genuine choice and can refuse without penalty), specific (i.e., consent covers clearly defined purposes), informed (i.e., you know what you are consenting to before agreeing), and unambiguous (i.e., consent requires a clear affirmative action, not pre-ticked boxes or silence).
For children under 16 (or the applicable age threshold in your EU member state), we require the relevant child's parental or guardian consent before processing personal data.
You may withdraw consent at any time by contacting us at the details below or, where applicable, through your account settings. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
19.5 Automated Decision-Making and Profiling
MeeOpp uses AI-powered tools to provide personalized learning recommendations, generate feedback on student work, and assess language proficiency. These tools may involve automated processing of personal data.
Where automated decision-making produces legal effects or similarly significant effects on an EU Data Subject, we will:
- inform you that automated decision-making is being used
- provide meaningful information about the logic involved
- allow you to request human review of the decision
- enable you to express your point of view and contest the outcome
For most of our Services, AI outputs are intended as educational support rather than definitive assessments, and human oversight remains available.
19.6 International Data Transfers
MeeOpp is based in Hong Kong, and personal data of EU Data Subjects may be transferred to and processed in jurisdictions outside the European Economic Area (EEA) that may not offer the same level of data protection as the GDPR.
Where we transfer personal data outside the EEA, we ensure an adequate level of protection as provided by the GDPR through one or more of the following mechanisms:
- Adequacy decisions – transfers to countries that the European Commission has determined to provide adequate protection
- Standard Contractual Clauses – EU-approved contractual terms that bind the recipient to protect your personal data
- Binding Corporate Rules – internal policies approved by EU supervisory authorities for intra-group transfers
- Other lawful safeguards – such as approved codes of conduct or certification mechanisms
You may request a copy of the relevant transfer safeguards by contacting our Data Protection Officer.
19.7 Data Protection Officer and Complaints
For questions about GDPR compliance or to exercise your rights, contact:
Data Protection Officer
Email: csteam@meeopp.com
Alternate Contact: jeffrey.l@meeopp.com
EU Data Subjects also have the right to lodge a complaint with a supervisory authority in the EU member state where they reside, work, or where the alleged infringement occurred. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
19.8 Data Retention for EU Data Subjects
The School Data retention and erasure schedule in Section 6 also applies to EU School Data: active-system and subprocessor erasure within 30 calendar days, and backup erasure within 90 calendar days, after the school's request or the end of Services, whichever occurs first. Shorter applicable legal or agreed DPA deadlines take precedence. We do not retain School Data, including aggregated or anonymised derivatives, after these deadlines for research or improvement. Any required legal retention is restricted to Section 6.2 and must also comply with applicable GDPR transfer and processing requirements.
For other EU personal data, we retain it only while necessary for the specified purposes and applicable legal obligations, subject to the rights and exceptions under GDPR. This does not extend School Data retention or create an exception to the AI training prohibition.
Commitment to Privacy and Safeguards
MeeOpp is committed to:
- establishing a culture of privacy protection
- conducting ongoing risk monitoring
- applying privacy-by-design principles
- adopting industry best practices in data governance
