Mesy

Mesy Privacy Policy

Last revised: 17 August 2026

Mesy is a CRM operated by Majulah SG Pte Ltd, a Singapore company. This policy explains what personal data we handle, why, and what your rights are. It is our notification under Singapore’s Personal Data Protection Act 2012 (PDPA) and it contains our disclosures under the Google API Services User Data Policy (section 8).

Four commitments up front:

  • We do not sell personal data.
  • We do not show advertisements or use advertising trackers.
  • We do not train our own AI models on your data.
  • We do not read your workspace content, except in the narrow cases this policy names.

1. Who we are

Legal entity Majulah SG Pte Ltd (Singapore)
UEN 202129171K
Registered address 6 Ubi Road 1, #06-10, Wintech Centre, Singapore 408726
Product Mesy, at https://app.mesy.ai
Data Protection Officer dpo@mesy.ai

“We”, “us” and “Majulah SG” mean Majulah SG Pte Ltd. “Mesy” means the service. We have designated a Data Protection Officer under section 11(3) of the PDPA. Contact the DPO at dpo@mesy.ai for any question, complaint, or access or correction request.

2. Our two roles

The PDPA separates an organisation that decides why data is processed from a data intermediary that processes data on another organisation’s behalf under a written contract (s.4(2)–(3)). Mesy involves both roles. Your rights depend on which one applies.

Your account: our responsibility. The data that runs your account (who you are, your workspace, your logins, how you use the product) is ours to protect under the full PDPA obligation set, and this policy is our notification for it.

Your workspace content: processed on your organisation’s instructions. Everything a customer puts into or connects to their workspace (CRM records, notes, tasks, files, and the email, calendar, and chat content they sync) is processed only on that customer’s instructions: the customer chooses what to load and why, and remains responsible for it under the PDPA. For this data our obligations are Protection (s.24), Retention Limitation (s.25), and breach notification to the customer (s.26C(3)(a)), plus our Data Processing Agreement (DPA) with them, which we provide to every customer. If your details sit inside a Mesy customer’s CRM, that organisation is your first point of contact for access, correction, and deletion requests. If you write to dpo@mesy.ai instead, we will pass your request to the right organisation where the law allows, and tell you what we did.

AI conversation transcripts sit in our own store but their content is mostly the customer’s, so we apply the customer-content retention rules to them (section 12).

Business Contact Information. Under PDPA s.4(5), the Data Protection Provisions do not apply to business contact information: a person’s name, title, business phone, business email, and similar. Much of the data in a B2B CRM is exactly that. We treat it no differently: the same security and retention rules apply to business contact information as to all other personal data.

3. Data we collect to run your account

Category Examples Why
Account identity Name, email, hashed password, role Create and authenticate your account
Social sign-in identity Google or Microsoft account email and name, if you sign in that way Password-free sign-in
Workspace details Workspace name, industry, settings Provision your tenant
Session records Hashed refresh tokens, session metadata Session security; detecting token reuse
Invitations The email address of a person you invite; signup codes Team invites; signup gating
Connection metadata Which accounts you connected, sync timestamps, encrypted access tokens Operate the integrations you enable
Messaging identity Telegram username and chat ID, if you link Telegram; your connected WhatsApp Business number Route your conversations
In-product messaging Team Feed posts, direct messages, notifications Collaboration features
AI conversation transcripts Your messages to Mesy AI and its replies; short redacted previews of each AI action Chat history; reviewing and undoing AI actions
Product and AI usage Feature usage; AI token counts, model, latency, cost Billing, capacity limits, abuse prevention
Support correspondence What you send us Answering you
Technical logs IP address, user agent, request paths, errors Security, debugging, availability

Our AI usage metering contains only counts, model, latency, and cost; no prompt or response text.

Cookies. We use strictly necessary cookies only. The main one is an HttpOnly cookie scoped to the session-refresh endpoint. We set no advertising or cross-site tracking cookies, in the product or on the marketing site at mesy.ai.

4. Data we process on our customers’ instructions

When your organisation uses Mesy, we process on its behalf:

  • CRM records: contacts, organisations, deals, products, and any custom fields, including names, emails, phone numbers, addresses, and free-text notes.
  • Notes, activities, tasks, and the change history of each record.
  • Files the customer uploads, and attachments from synced mail and messages.
  • Synced mailbox content from Gmail and Outlook: full message bodies, subjects, senders, recipients.
  • Synced calendar content from Google Calendar and Outlook Calendar: titles, descriptions, locations, times, attendees.
  • Synced chat from Microsoft Teams and Telegram, where connected.
  • WhatsApp conversations on the customer’s connected WhatsApp Business number: message text, sender phone numbers, and media (section 9).
  • Captured artefacts: for example a photographed business card and the contact details extracted from it.

We use this data to provide the service to that customer and for nothing else.

Sensitive data. Mesy’s fields are free-form. Do not enter NRIC/FIN numbers, financial account numbers, or health data unless you have a lawful basis and a genuine need. Mesy has no special detection or masking for such data, and record history retains prior values.

5. Why we use your data, and on what basis

For data we are responsible for, in PDPA terms:

Purpose Basis
Creating your account and delivering the service Your express consent at signup, with this policy as the s.20 notification; deemed consent by voluntary provision (s.15(1)) where you provide data for that purpose.
Disclosures to providers needed to deliver what you signed up for Deemed consent by contractual necessity (s.15(3)–(6)), a disclosure limb only.
Running the integrations you connect Your express consent when you authorise each connection
Securing the service: abuse prevention, session integrity, logging Legitimate interests exception (First Schedule, Part 3), assessed and disclosed here
Service emails: outages, security notices, billing Consent at signup; these are not marketing
Improving the service and its reliability using aggregate, non-identifying data Legitimate interests; business improvement exception (First Schedule, Part 5) where it applies
Legal, regulatory, and tax obligations The PDPA’s legal-requirement exceptions
Marketing email Separate opt-in only. Every marketing email has an unsubscribe link and we honour it. We make no marketing calls or SMS; if we ever do, we check the Do Not Call Registry first.

6. AI features and AI providers

Mesy is an AI product. Its AI features send your content to third-party AI providers as it is, not anonymised.

Your workspace administrator selects one AI model in admin settings. Almost every AI feature runs on that model: co-pilot chat, email linking, the Telegram assistant, email drafting, capture enrichment, workflow AI steps, daily insights, and import auto-matching. The exceptions are in the table below.

Flow Provider What it receives
All AI features above The selected model’s provider: Anthropic (the default), Google, OpenAI, or OpenRouter Your messages to the assistant and the content the feature works on: record fields, full email bodies, calendar events, notes, chat text. Email drafting also sends the body of the email being replied to (up to ~2,000 characters).
Image and document capture The selected model, if it can process images; otherwise the workspace’s configured fallback model, which may be a different provider The image bytes and everything visible in them
Voice transcription OpenAI (Whisper), always, regardless of the selected model The raw audio of the voice note
Web research, where configured Tavily The search query, which can contain a contact’s or company’s name

Apart from the web-research row, this table is derived from the same server registry that drives the “Powered by this model” panel in Mesy’s admin settings. If a feature’s routing changes, this table changes with it.

In particular:

  1. Two flows ignore your model choice. Voice always goes to OpenAI, and web research, where configured, goes to Tavily. Image capture can reach your fallback provider. Everything else follows your selection.
  2. All of these providers process data outside Singapore, principally in the United States (section 11).
  3. We store your AI transcripts; our metering stores nothing. Transcripts are your chat history in the product, kept with short redacted previews of each AI action for 90 days. Metering holds only token counts, model, latency, and cost.
  4. We do not train our own models on your data. We do improve Mesy using aggregated, de-identified usage and performance data; it never includes the content of your workspace and never identifies anyone. What each provider may do with submitted data is governed by our contracts with them.
  5. AI output is a suggestion, not a decision. Mesy’s AI makes no decisions with legal or similarly significant effect on individuals. Whether an AI action needs your confirmation depends on the permission tier your workspace sets, and a fixed set of actions (role changes, invitations, calendar event creation, record merges) always requires confirmation. Mesy never sends email or WhatsApp messages from your accounts without a human confirming the send.

7. Where a human can see your data

We do not read workspace content in the ordinary course of operating Mesy. A person at Majulah SG can see it only:

  • in a support session you or your workspace admin can observe; support access is shown to the workspace by a visible banner and is audited;
  • when investigating abuse, fraud, or a security incident;
  • when the law requires it.

8. Google user data and Limited Use

Mesy requests access to Google account data through Google’s OAuth flow, using restricted Gmail scopes and sensitive Calendar scopes.

Scope Why
gmail.readonly Show your mail inside Mesy and link it to CRM records
gmail.send Send the emails you write or approve in Mesy, from your own account
gmail.modify Keep read state and labels in step between Mesy and your mailbox. Gmail offers no narrower scope that permits message-label changes.
calendar.events Show your events and create the events you confirm. Event-scoped, not full calendar access
userinfo.email Identify the connected account

You grant these per account and can revoke them at any time, in Mesy’s integration settings or at https://myaccount.google.com/permissions.

Limited Use. Mesy’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We use Google user data only to provide and improve user-facing features that are prominent in Mesy’s interface.
  • We do not transfer Google user data to others, except as necessary to provide or improve those features, to comply with law, or as part of a merger or acquisition with your prior explicit consent.
  • We do not use Google user data for advertising of any kind.
  • We do not allow humans to read Google user data, except with your affirmative agreement for specific messages, for security purposes, to comply with law, or where the data is aggregated and de-identified.
  • We do not retain or use Google user data to develop, improve, or train generalised AI or ML models. Where an AI model in Mesy processes Google data, it does so only to execute the feature you invoked, for you.

On disconnect. When you disconnect Gmail or Google Calendar, Mesy stops syncing and deletes the synced messages, events, and metadata from our database. Attachment files already written to object storage are not yet removed by that action; deleting the workspace removes them.

9. WhatsApp

A workspace can connect a WhatsApp Business number so its team answers customer WhatsApp messages inside Mesy. This uses Meta’s WhatsApp Business Platform (Cloud API); Meta delivers the messages and is a sub-processor for this channel.

What we process when a workspace connects a number:

  • Inbound messages to the business number: message text, the sender’s phone number and profile name, and timestamps. Meta delivers these to Mesy the moment they arrive.
  • Media: images, documents, and audio the customer sends. We download each item from Meta on receipt and store it in our object storage, because Meta’s own copies expire within minutes.
  • Outbound replies the team sends from Mesy, recorded with the sending user.
  • Contact matching. We match the sender’s phone number against the phone fields the workspace has designated as identity fields on its contact records; the digits must match exactly. An unmatched sender is never silently added to the CRM; a person is created only when a team member confirms it.

WhatsApp’s platform rules apply to replies: a business can send free-form messages only within 24 hours of the customer’s last message. Mesy shows this window state and disables the composer outside it.

On disconnect. Disconnecting the number deletes its conversations and messages from our database. There is no way to re-download them from WhatsApp afterwards; deletion is permanent. Media files already stored are not yet removed by that action; deleting the workspace removes them.

10. Who receives data

We run Mesy on the providers below. Each receives only what its job needs, under contract. The full list, with what each one processes and where, is published at https://mesy.ai/subprocessors. In summary:

  • Hosting and storage: Supabase (database), DigitalOcean (compute), Cloudflare (object storage, transactional email).
  • AI: Anthropic, Google, OpenAI, OpenRouter (routing to DeepSeek and Tencent), Tavily, as section 6 describes.
  • Integrations: Google (Gmail, Calendar), Microsoft (Outlook, Teams), Telegram, and Meta (WhatsApp), for the accounts each workspace connects.
  • Operations: Sentry (error monitoring, configured to exclude personal data) and Better Stack (uptime and log monitoring; shipped logs include IP addresses).

We update the published list before adding or replacing a sub-processor that handles personal data, and customers receive notice as the DPA provides.

Beyond sub-processors, we disclose personal data only: to you or at your direction; where law, a court, or a regulator requires it; to professional advisers under confidentiality; or in a merger, acquisition, or asset sale, in which case this policy continues to apply until replaced by one with comparable protection.

11. Where data lives

Our primary database and application servers are in Singapore, and our object storage (uploaded files and attachments) is configured for Cloudflare’s Asia-Pacific region. Full database backups are retained on the application host’s disk (newest ten dumps, at least 14 days) with an off-site copy in object storage.

Several providers process data outside Singapore, principally in the United States: every AI provider, the integration providers, and the monitoring providers. Under the Transfer Limitation Obligation (PDPA s.26) we transfer personal data abroad only where the recipient is bound to a standard of protection comparable to the PDPA, which we establish through data processing agreements and standard contractual clauses with each provider.

12. How long we keep data

We keep personal data only as long as it serves its purpose or a legal need requires (PDPA s.25).

Data Retention
Account and workspace data Life of the account, plus a limited period after closure for legal and dispute purposes
Customer CRM content, synced mail, calendar, chat, WhatsApp, files While the subscription is active; on termination, deleted or returned as the DPA provides after an export window of 30 days
Google data on disconnect Deleted from the database at disconnect; stored attachments currently persist until workspace deletion (section 8)
WhatsApp data on disconnect Deleted from the database at disconnect, permanently; stored media currently persists until workspace deletion (section 9)
In-product messaging Notifications deleted after 90 days; message bodies live with the workspace
AI transcripts Deleted on the customer-content schedule; per-action previews deleted after 90 days
Session and authentication records Until expiry or revocation, plus a short security window
AI metering (no content) Cost and latency metering deleted after 90 days; aggregate token counts while the workspace is live
Technical and error logs A short rolling window
Record change history Retained with the record. It preserves prior field values, so an edited or deleted value can persist in it

Backups. Deleted data remains in backups until they age out on rotation, at most 30 days. We never selectively edit backups.

Automated deletion exists today for some categories (notifications, AI action previews, and internal event feeds prune at 90 days; backups rotate). It does not yet exist for CRM records, files, synced content, or change history.

13. How we protect data

  • Tenant isolation in the database. Workspace content is segregated by PostgreSQL row-level security, bound to the authenticated workspace on every request. A small enumerated set of connection and routing tables is reached before workspace context exists (sign-in, webhooks) and is scoped by explicit filtering instead; those tables hold credentials and routing metadata, not CRM content.
  • TLS in transit for all access and all provider traffic.
  • Credentials encrypted at rest: integration tokens and secrets encrypted with a separately held key; passwords stored only as bcrypt hashes; refresh tokens only as hashes, in HttpOnly cookies scripts cannot read.
  • Multi-factor authentication (TOTP and passkeys), role-based access control, per-record sharing rules.
  • Signed webhooks, verified with constant-time comparison, for every inbound integration including WhatsApp.
  • An append-only change log; AI actions recorded against the user who initiated them; rate limiting; secret scanning, dependency audits, and static and test gates in the build pipeline.
  • Nightly backups, and a backup before each release.
  • Restricted administrative access; support access to customer content is banner-visible and audited (section 7).

If a breach occurs, section 14 applies.

14. Data breaches

We assess every suspected breach promptly. A breach is notifiable when it is likely to result in significant harm to affected individuals, or when it affects 500 or more individuals. For a notifiable breach we notify the PDPC no later than 3 calendar days after determining it is notifiable, and affected individuals as the PDPA requires. We work to complete assessment and notification within 30 days of becoming aware. Where we hold data as an intermediary, we notify the customer organisation without undue delay so it can meet its own duties.

15. Your rights

Under PDPA sections 21 and 22 you may ask us for access to the personal data we hold about you and how it was used or disclosed in the past year, and for correction of errors or omissions.

Email dpo@mesy.ai with enough detail to identify you and locate the data. We may verify your identity first. We acknowledge your request and respond as soon as reasonably possible; if we cannot respond within 30 days, we tell you when we will. An access request may carry a reasonable fee, stated before we proceed. PDPA exceptions may apply, for example where a request would reveal another person’s data.

If your data sits in a customer’s CRM, that organisation is your first point of contact for access, correction, and deletion; send your request there (section 2).

Withdrawing consent. You may withdraw consent for any purpose that rests on it: disconnect an integration, or close your account. Withdrawal is not retrospective, and some withdrawals end our ability to provide part or all of the service.

Complaints. Write to dpo@mesy.ai first. If unsatisfied, you may complain to the Personal Data Protection Commission (https://www.pdpc.gov.sg).

16. Children

Mesy is a business tool, not directed at children. We do not knowingly collect personal data from anyone under 18, and an account requires the capacity to enter our Terms of Service. Contact dpo@mesy.ai if you believe a child’s data has reached us.

17. Changes to this policy

When we update this policy we change the date at the top. For changes that materially affect how we handle your data, we notify account holders by email or in-product before they take effect.

18. Contact

Data Protection Officer, Majulah SG Pte Ltd Email: dpo@mesy.ai · Postal: 6 Ubi Road 1, #06-10, Wintech Centre, Singapore 408726 · UEN: 202129171K

MesyMake Every Sale Yours
Email salesBook a demoDocsSign inPrivacyTerms

© 2026 Mesy · Singapore · A product of Majulah SG