MeeOpp Privacy and Data Protection Compliance Statement

Last updated: 26 January 2026

1. Introduction

Meego Technologies Limited ("MeeOpp") and its subsidiaries (collectively, "MeeOpp", "we", "us", or "our") respect your privacy and are committed to protecting personal data in accordance with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of the Hong Kong SAR.

This Privacy Policy explains how we collect, use, disclose, process, retain, secure, and manage personal data when you use our websites, services, platforms, and applications (collectively, the "Services"). By accessing or using our Services, you agree to the terms of this Privacy Policy.

We ensure that all personal data collected is handled in accordance with the six Data Protection Principles (DPPs) under the PDPO:

  • Purpose and Manner of Collection
  • Accuracy and Retention
  • Use of Data
  • Data Security
  • Transparency
  • Access and Correction

2. Personal Information Collection Statement (PICS)

We provide a clear and accessible Personal Information Collection Statement (PICS) at the time personal data is collected. The PICS includes:

  • Purpose of collecting the data
  • Whether provision of data is voluntary or obligatory
  • Consequences of failing to provide data
  • Classes of transferees
  • Data subject rights
  • DPO contact details

In compliance with Section 18 of the PDPO, our PICS is issued at or before the time of collection and is available through our website.

MeeOpp proactively conducts Privacy Impact Assessments (PIAs) for new or significantly altered systems involving personal data.

3. Personal Data We Collect

3.1 Types of personal data

We may collect, hold, process, transfer and use the following types of personal data:

  • full name*
  • email address*
  • school*
  • school grade*
  • phone number
  • audio / video recordings from sessions
  • date of birth
  • username
  • device and usage data (IP address, browser, device type, pages visited)
  • user-generated content (messages, uploads, feedback)
  • third-party data (integration services)
  • learning performance and behavioural data

* mandatory personal data

3.2 Failure to provide mandatory data

May result in us being unable to provide the Services.

4. How We Use Personal Data

We may collect, process, hold, transfer and use personal data for the following purposes:

  • Account creation and management
  • Delivery, analysis, and improvement of Services
  • Communication with users, parents, or guardians
  • Quality assurance, research, and product development
  • Security, fraud prevention, and monitoring
  • Compliance with applicable law
  • Establishment, exercise, or defence of legal rights

Personal data will not be used for any other purposes unless: (a) explicit consent is obtained, or (b) permitted by law.

5. Your Rights

Subject to the PDPO, you have the right to:

  • access personal data held about you
  • request correction of inaccurate data
  • request deletion (subject to lawful retention requirements)
  • manage communication and marketing preferences

A reasonable fee may be charged for data access or correction requests.

6. Data Retention

We retain personal data only as long as necessary for the purposes outlined in this policy, unless a longer retention period is required by law. Deleted data may remain in secure backups for a limited period.

7. Data Security

We take all practicable steps to safeguard personal data against unauthorised or accidental access, processing, erasure, loss or use. Security measures include:

  • Encryption of data at rest and in transit
  • Role-based access controls
  • Authentication and access logging
  • Regular audits and risk assessments
  • Incident response procedures
  • Staff training on data protection obligations

However, no system is fully secure, and transmissions over networks outside our control are at your own risk.

8. Internal Data Handling Guidelines

We maintain internal guidelines governing staff and contractor handling of personal data, including:

  • data minimisation and purpose limitation
  • secure data storage, transmission, and access controls
  • prohibition of unauthorised downloads, transfers, or local storage
  • mandatory reporting of suspected data incidents
  • confidentiality obligations

Staff and contractors must:

  • use authorised systems only
  • complete privacy compliance training
  • comply with security protocols and confidentiality requirements

9. Vendor and Third-Party Agreements

We may transfer personal data to third-party service providers ("Permitted Transferees") engaged to support our operations. Permitted transferees must:

  • process data only on our instructions
  • implement security safeguards
  • not disclose or use data for unrelated purposes
  • comply with contractual, legal, and confidentiality obligations

Vendor categories include:

  • administrative service providers
  • telecommunications and cloud services
  • analytics and processing providers
  • market research, advisory, legal, and accounting firms
  • payment processors

We do not sell personal data to third parties.

10. Data Transfers Outside Hong Kong

Personal data may be processed or stored in jurisdictions with different data protection laws.

By using our Services, you acknowledge this and consent where required.

11. Data Breach Response and Mitigation

A data breach includes any incident involving unauthorised or accidental:

  • access, disclosure, loss, or destruction of personal data
  • system compromise or security failure

If we become aware of a breach, we will:

  • activate internal incident response procedures
  • contain and mitigate the incident
  • investigate severity, cause, and impact
  • document findings and corrective actions

Where appropriate, we will consider notifying:

  • affected individuals
  • relevant authorities
  • other impacted stakeholders

Notifications, where made, will include:

  • nature of incident
  • affected data
  • potential risks
  • steps taken by us
  • steps individuals may take

Following a breach, we will review safeguards and policies to reduce recurrence.

12. Children's Privacy

We provide enhanced protections for users under 18. We may:

  • limit the collection of data to what is necessary
  • require teacher or parent authorisation
  • restrict access to personal data to authorised staff
  • provide rights of access, correction, or deletion

Children are encouraged to consult a parent or teacher before submitting personal data.

13. Cookies & Tracking Technologies

We use cookies for:

  • login and authentication
  • analytics (Google Analytics, Amplitude)
  • device optimisation and security

Users may disable cookies, but some functionality may be limited.

14. Direct Marketing

We may use personal data for direct marketing only with prior consent. Users may withdraw consent at any time by emailing csteam@meeopp.com.

Our Services may contain links to external sites. We are not responsible for their content or privacy practices.

16. User Content

You grant MeeOpp a limited licence to process content you upload for the purposes of delivering and improving the Services. We claim no ownership over your content. You are responsible for ensuring that your content does not violate intellectual property, privacy, or legal rights of others.

17. Updates to This Policy

We may modify this Privacy Policy from time to time. Updated versions will be posted on our website. Continued use of the Services constitutes acceptance.

18. Contact Us

To request access, correction, or deletion of personal data, or to ask privacy-related questions, please contact our Data Protection Officer:

Data Protection Officer
Email: csteam@meeopp.com
Alternate Contact: jeffrey.l@meeopp.com

MeeOpp Personal Information Collection Statement (PICS)

Last updated: 11 August 2025

1. Introduction

This PICS informs you of:

  • purposes of collecting personal data
  • data transferees
  • rights of access and correction
  • how to contact us

By submitting data through our Services, you agree to this PICS.

2. Data User

Meego Technologies Limited is the data user under this PICS.

3. Personal Data Collected

As described in Section 3 above.

4. Purposes of Use

As described in Section 4 above.

5. Permitted Transferees

As described in Section 9 above.

6. Rights of Access and Correction

As described in Section 5 above.

7. Direct Marketing

As described in Section 14 above.

8. Contact

Users may request access or correction by contacting:

Data Protection Officer
Email: jeffrey.l@meeopp.com

GDPR Applicability and Compliance

19.1 Scope of Application

The General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to the collection, processing, and transfer of personal data relating to individuals located in the European Union ("EU Data Subjects"), regardless of nationality. For the avoidance of doubt, unless otherwise provided under this GDPR Applicability and Compliance section, the other provisions of this Privacy and Data Protection Compliance Statement shall continue to apply to EU Data Subjects (including but not limited to Section 3 (Personal Data We Collect) and Section 4 (How We Use Personal Data)).

While MeeOpp primarily serves clients in Hong Kong, Singapore, and other parts of Asia, EU Data Subjects may access or use our Services, for example, students participating in international programs, families residing in the EU, or institutional clients with EU-based participants. Where we collect or process personal data of an EU Data Subject, we will comply with the applicable GDPR requirements.

Where the GDPR applies, we process personal data on one or more of the following legal bases:

(a) Consent – Where you have given clear, affirmative consent for us to process your personal data for a specific purpose. For example, opting in to receive marketing communications, consenting to session recordings for quality assurance, or allowing your child to participate in personalized AI-based learning activities.

(b) Performance of a contract – Where processing is necessary to deliver the Services you have requested, to perform a contract that you are a party to, or to take steps at your request before entering into a contract. For example, creating and managing your account, scheduling and delivering lessons, or processing payments.

(c) Legitimate interests – Where processing is necessary for purposes that are in our legitimate interests (or those of a third party), provided those interests are not overridden by your interests or fundamental rights and freedoms which require the protection of your personal data. For example, improving our platform and developing new features, analyzing learning outcomes in aggregated or de-identified form, preventing fraud and ensuring platform security, or conducting internal training using anonymized session data.

(d) Legal obligation – Where processing is necessary to comply with a legal requirement that we are subject to, such as maintaining records for tax purposes or responding to lawful requests from authorities.

(e) Vital interests – In rare circumstances, where processing is necessary to protect a person's vital interests.

(f) Public interest – Where processing is necessary for a task carried out in the public interest (which is unlikely to apply to most of our Services).

19.3 EU Data Subject Rights

Under GDPR, EU Data Subjects have the following rights, subject to applicable limitations and exceptions:

Right of access – You can request a copy of the personal data we hold about you and that are being processed. We may charge a reasonable fee based on administrative costs for any further copies requested by you.

Right to rectification – You can ask us to correct inaccurate or incomplete data concerning you.

Right to erasure (right to be forgotten) – You can ask us to delete your personal data in certain circumstances set out under Article 17 of the GDPR, such as when such personal data is no longer needed for the purposes for which it was originally collected or processed, or where there is no other legal ground for processing. Deletion requests will be honored subject to our legal obligations and any legitimate retention needs (for example, where we are required to retain records for tax, legal, or regulatory purposes).

Right to restriction – You can ask us to limit how we process your personal data in certain circumstances set out under Article 18 of the GDPR, such as during the period of time required by us to verify the accuracy of your personal data when you have contested the accuracy of the same.

Right to data portability – You can request your personal data in a structured, commonly used and machine-readable format and have it transferred to another provider where (i) technically feasible; (ii) our processing was based on your consent or was necessary for the performance of a contract to which you were a party; and (iii) our processing was carried out by automated means.

Right to object – You can object to processing based on legitimate interests or for direct marketing purposes at any time, in which case we will stop such processing unless we demonstrate compelling legitimate grounds or are otherwise permitted or required by law.

Right to withdraw consent – Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing that occurred before withdrawal.

Rights related to automated decision-making – You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal or similarly significant effects, unless certain exceptions apply under Article 22 of the GDPR (for example, where the decision based solely on automated processing is necessary for the performance of a contract between us and you, or is authorised by Union or Member State law with appropriate safeguards, or is otherwise based on your explicit consent).

To exercise any of these rights, contact our Data Protection Officer using the details in Section 19.7 below. We will respond without undue delay, and in any event, within one month of receipt of your request, though this may be extended by up to two additional months taking into account the complexity and number of the requests. We will inform you of any extension within one month of the receipt of your relevant request together with the reasons for it. We will communicate any rectification, erasure or restriction of data processing carried out pursuant to your requests to any recipients to whom your personal data has been disclosed, unless doing so would prove impossible or involves disproportionate efforts.

Where we rely on consent as a legal basis, we will obtain it in a manner that is freely given (i.e., you have a genuine choice and can refuse without penalty), specific (i.e., consent covers clearly defined purposes), informed (i.e., you know what you are consenting to before agreeing), and unambiguous (i.e., consent requires a clear affirmative action, not pre-ticked boxes or silence).

For children under 16 (or the applicable age threshold in your EU member state), we require the relevant child's parental or guardian consent before processing personal data.

You may withdraw consent at any time by contacting us at the details below or, where applicable, through your account settings. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

19.5 Automated Decision-Making and Profiling

MeeOpp uses AI-powered tools to provide personalized learning recommendations, generate feedback on student work, and assess language proficiency. These tools may involve automated processing of personal data.

Where automated decision-making produces legal effects or similarly significant effects on an EU Data Subject, we will:

  • inform you that automated decision-making is being used
  • provide meaningful information about the logic involved
  • allow you to request human review of the decision
  • enable you to express your point of view and contest the outcome

For most of our Services, AI outputs are intended as educational support rather than definitive assessments, and human oversight remains available.

19.6 International Data Transfers

MeeOpp is based in Hong Kong, and personal data of EU Data Subjects may be transferred to and processed in jurisdictions outside the European Economic Area (EEA) that may not offer the same level of data protection as the GDPR.

Where we transfer personal data outside the EEA, we ensure an adequate level of protection as provided by the GDPR through one or more of the following mechanisms:

  • Adequacy decisions – transfers to countries that the European Commission has determined to provide adequate protection
  • Standard Contractual Clauses – EU-approved contractual terms that bind the recipient to protect your personal data
  • Binding Corporate Rules – internal policies approved by EU supervisory authorities for intra-group transfers
  • Other lawful safeguards – such as approved codes of conduct or certification mechanisms

You may request a copy of the relevant transfer safeguards by contacting our Data Protection Officer.

19.7 Data Protection Officer and Complaints

For questions about GDPR compliance or to exercise your rights, contact:

Data Protection Officer
Email: csteam@meeopp.com
Alternate Contact: jeffrey.l@meeopp.com

EU Data Subjects also have the right to lodge a complaint with a supervisory authority in the EU member state where they reside, work, or where the alleged infringement occurred. A list of EU supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

19.8 Data Retention for EU Data Subjects

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy and Data Protection Compliance Statement and to comply with our legal, accounting or reporting obligations and subject to your right to erasure under the GDPR. Account data, session recordings, and learning performance data are kept for the duration of your relationship with us and for a reasonable period thereafter until you request earlier erasure where applicable. Learning performance data may also be retained in aggregated or anonymized form for research and improvement purposes after your account is closed.

Commitment to Privacy and Safeguards

MeeOpp is committed to:

  • establishing a culture of privacy protection
  • conducting ongoing risk monitoring
  • applying privacy-by-design principles
  • adopting industry best practices in data governance