1. Scope
This Mela AI Privacy Policy ("Policy") applies to Mela Meeting Assistant and related Mela administration, support, pilot, and product experiences provided by Armely, LLC ("Armely," "we," "us"). It supplements Armely's general website privacy policy.
This Policy does not govern Microsoft products, Customer-controlled Microsoft 365 environments, or third-party services, which are subject to their own terms and privacy notices.
2. Our Privacy Roles
For meeting content and other information submitted through a Customer's Microsoft 365 tenant, the Customer generally determines why and how information is processed. In that context, Customer acts as the data controller or business, and Armely acts as a processor or service provider on Customer's instructions.
Armely acts as an independent controller for account administration, billing, security monitoring, support communications, product analytics, and legal compliance. A data processing agreement may provide additional terms.
3. Information We Process
Customer and user information
- names, business email addresses, organization, job title, user and tenant identifiers;
- subscription, pilot, licensing, support, and administrative contact information;
- authentication events, permissions, configuration, and role information.
Meeting and workflow information
- meeting identifiers, title, date, time, organizer, attendees, and participation metadata;
- meeting chat, transcript, notes, or other content made available to Mela by authorized users and tenant configuration;
- generated summaries, decisions, action items, task assignments, due dates, and follow-up content;
- Planner plan and task identifiers, Outlook delivery information, and status of requested workflow actions.
Technical information
- IP address, device and browser information, timestamps, diagnostics, error logs, performance events, and security telemetry;
- support requests and communications with Armely.
The specific information Mela can access depends on the permissions approved by the Customer's Microsoft 365 administrator and on how authorized users invoke the Service.
4. Sources of Information
We receive information directly from Customers and users, from Customer-authorized Microsoft 365 APIs and services, from administrators configuring Mela, and automatically from use of the Service. We may also receive business contact information from implementation partners or a Customer's authorized representatives.
5. How We Use Information
We process information to:
- authenticate users and connect Mela to authorized Microsoft 365 services;
- capture authorized meeting context and generate summaries, action items, tasks, and follow-ups;
- create or update Planner tasks and deliver Outlook communications as requested;
- configure tenants, administer subscriptions, provide support, and respond to requests;
- maintain reliability, diagnose errors, prevent abuse, and protect accounts and systems;
- measure feature performance and improve the Service using aggregated, de-identified, or Customer-authorized data;
- comply with law, enforce agreements, and establish or defend legal claims.
Where required, our legal bases may include performance of a contract, legitimate interests, consent, and compliance with legal obligations.
6. AI Processing and Model Use
Mela uses automated and AI-enabled processing to identify discussion topics, decisions, action items, assignees, deadlines, and draft summaries. AI-generated output may be inaccurate and should be reviewed by authorized users.
Armely does not use Customer meeting content to train a general-purpose model for unrelated customers unless Customer has expressly agreed in writing. We may use de-identified and aggregated operational information to improve security, reliability, and product performance.
8. Microsoft 365 Integration
Mela accesses Microsoft 365 only through permissions approved by Customer administrators or authorized users. Depending on configuration, data may be read from or written to Teams, Microsoft Graph, Planner, Outlook, Entra ID, SharePoint, or related services.
Customer controls Microsoft identities, licenses, retention policies, access permissions, and tenant security. Data stored by Microsoft remains subject to Customer's Microsoft agreements and configuration. Revoking permissions or disabling Mela may stop future access but may not delete information already retained under an applicable agreement or legal obligation.
9. Data Retention and Deletion
We retain information only as long as reasonably necessary to provide the Service, satisfy Customer instructions and contractual commitments, maintain security and audit records, resolve disputes, and comply with law. Retention periods vary by data type, subscription, tenant configuration, and contractual requirements.
Upon termination, Customer may request return or deletion of Customer Data as provided in the applicable agreement. Some information may remain temporarily in encrypted backups or be retained where legally required. Customer administrators remain responsible for information stored in Customer's Microsoft 365 environment.
10. Security
Armely uses reasonable administrative, technical, and organizational safeguards designed to protect information. Measures may include access controls, least-privilege permissions, encryption in transit and where appropriate at rest, logging, monitoring, vulnerability management, and personnel confidentiality obligations.
No system is completely secure. Customers should configure appropriate Microsoft 365 controls, conditional access, retention, user training, endpoint protection, and incident procedures. Suspected security issues should be reported promptly to ask.me@armely.com.
11. International Data Transfers
Armely and its providers may process information in the United States and other countries where they operate. Where required, we use recognized transfer safeguards, contractual protections, and supplementary measures. Customer-selected Microsoft data residency and tenant settings may also affect processing locations.
12. Privacy Rights and Choices
Users should first direct requests concerning meeting content or Customer-controlled data to their organization's Microsoft 365 administrator or privacy contact. Where Armely acts as a processor, we assist the Customer as required by contract and law.
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to withdraw consent. Requests may be sent to ask.me@armely.com. We may verify identity and authority before responding. Authorized agents may submit requests where permitted by law.
Users may stop future Mela access by asking their administrator to disable the app or revoke permissions. Email recipients may use an available unsubscribe link for optional event or marketing communications; service and security messages may still be sent.
13. Children's Privacy
Mela is designed for organizational and workplace use and is not directed to children under 13. Customers must not knowingly use Mela to process children's personal information unless authorized by Armely in writing and configured with all legally required consents and safeguards.
14. Changes to This Policy
We may update this Policy to reflect changes to Mela, our practices, or legal requirements. We will post the revised Policy with a new "Last updated" date and provide additional notice where required. Material changes apply prospectively unless law permits otherwise.
15. Contact Armely
For privacy questions, rights requests, or concerns about Mela, contact:
Armely, LLC
Attn: Mela Privacy
17400 Dallas Pkwy, Suite 111
Dallas, TX 75287
United States
ask.me@armely.com
+1 972 460 0643