Mesy Privacy Policy
Last revised: 17 August 2026
Mesy is a CRM operated by Majulah SG Pte Ltd, a Singapore company. This policy explains what personal data we handle, why, and what your rights are. It is our notification under Singapore’s Personal Data Protection Act 2012 (PDPA) and it contains our disclosures under the Google API Services User Data Policy (section 8).
Four commitments up front:
- We do not sell personal data.
- We do not show advertisements or use advertising trackers.
- We do not train our own AI models on your data.
- We do not read your workspace content, except in the narrow cases this policy names.
1. Who we are
| Legal entity | Majulah SG Pte Ltd (Singapore) |
| UEN | 202129171K |
| Registered address | 6 Ubi Road 1, #06-10, Wintech Centre, Singapore 408726 |
| Product | Mesy, at https://app.mesy.ai |
| Data Protection Officer | dpo@mesy.ai |
“We”, “us” and “Majulah SG” mean Majulah SG Pte Ltd. “Mesy” means the service. We have designated a Data Protection Officer under section 11(3) of the PDPA. Contact the DPO at dpo@mesy.ai for any question, complaint, or access or correction request.
2. Our two roles
The PDPA separates an organisation that decides why data is processed from a data intermediary that processes data on another organisation’s behalf under a written contract (s.4(2)–(3)). Mesy involves both roles. Your rights depend on which one applies.
Your account: our responsibility. The data that runs your account (who you are, your workspace, your logins, how you use the product) is ours to protect under the full PDPA obligation set, and this policy is our notification for it.
Your workspace content: processed on your organisation’s instructions. Everything a customer puts into or connects to their workspace (CRM records, notes, tasks, files, and the email, calendar, and chat content they sync) is processed only on that customer’s instructions: the customer chooses what to load and why, and remains responsible for it under the PDPA. For this data our obligations are Protection (s.24), Retention Limitation (s.25), and breach notification to the customer (s.26C(3)(a)), plus our Data Processing Agreement (DPA) with them, which we provide to every customer. If your details sit inside a Mesy customer’s CRM, that organisation is your first point of contact for access, correction, and deletion requests. If you write to dpo@mesy.ai instead, we will pass your request to the right organisation where the law allows, and tell you what we did.
AI conversation transcripts sit in our own store but their content is mostly the customer’s, so we apply the customer-content retention rules to them (section 12).
Business Contact Information. Under PDPA s.4(5), the Data Protection Provisions do not apply to business contact information: a person’s name, title, business phone, business email, and similar. Much of the data in a B2B CRM is exactly that. We treat it no differently: the same security and retention rules apply to business contact information as to all other personal data.
3. Data we collect to run your account
| Category | Examples | Why |
|---|---|---|
| Account identity | Name, email, hashed password, role | Create and authenticate your account |
| Social sign-in identity | Google or Microsoft account email and name, if you sign in that way | Password-free sign-in |
| Workspace details | Workspace name, industry, settings | Provision your tenant |
| Session records | Hashed refresh tokens, session metadata | Session security; detecting token reuse |
| Invitations | The email address of a person you invite; signup codes | Team invites; signup gating |
| Connection metadata | Which accounts you connected, sync timestamps, encrypted access tokens | Operate the integrations you enable |
| Messaging identity | Telegram username and chat ID, if you link Telegram; your connected WhatsApp Business number | Route your conversations |
| In-product messaging | Team Feed posts, direct messages, notifications | Collaboration features |
| AI conversation transcripts | Your messages to Mesy AI and its replies; short redacted previews of each AI action | Chat history; reviewing and undoing AI actions |
| Product and AI usage | Feature usage; AI token counts, model, latency, cost | Billing, capacity limits, abuse prevention |
| Support correspondence | What you send us | Answering you |
| Technical logs | IP address, user agent, request paths, errors | Security, debugging, availability |
Our AI usage metering contains only counts, model, latency, and cost; no prompt or response text.
Cookies. We use strictly necessary cookies only. The main one is an HttpOnly cookie scoped to the session-refresh endpoint. We set no advertising or cross-site tracking cookies, in the product or on the marketing site at mesy.ai.
4. Data we process on our customers’ instructions
When your organisation uses Mesy, we process on its behalf:
- CRM records: contacts, organisations, deals, products, and any custom fields, including names, emails, phone numbers, addresses, and free-text notes.
- Notes, activities, tasks, and the change history of each record.
- Files the customer uploads, and attachments from synced mail and messages.
- Synced mailbox content from Gmail and Outlook: full message bodies, subjects, senders, recipients.
- Synced calendar content from Google Calendar and Outlook Calendar: titles, descriptions, locations, times, attendees.
- Synced chat from Microsoft Teams and Telegram, where connected.
- WhatsApp conversations on the customer’s connected WhatsApp Business number: message text, sender phone numbers, and media (section 9).
- Captured artefacts: for example a photographed business card and the contact details extracted from it.
We use this data to provide the service to that customer and for nothing else.
Sensitive data. Mesy’s fields are free-form. Do not enter NRIC/FIN numbers, financial account numbers, or health data unless you have a lawful basis and a genuine need. Mesy has no special detection or masking for such data, and record history retains prior values.
5. Why we use your data, and on what basis
For data we are responsible for, in PDPA terms:
| Purpose | Basis |
|---|---|
| Creating your account and delivering the service | Your express consent at signup, with this policy as the s.20 notification; deemed consent by voluntary provision (s.15(1)) where you provide data for that purpose. |
| Disclosures to providers needed to deliver what you signed up for | Deemed consent by contractual necessity (s.15(3)–(6)), a disclosure limb only. |
| Running the integrations you connect | Your express consent when you authorise each connection |
| Securing the service: abuse prevention, session integrity, logging | Legitimate interests exception (First Schedule, Part 3), assessed and disclosed here |
| Service emails: outages, security notices, billing | Consent at signup; these are not marketing |
| Improving the service and its reliability using aggregate, non-identifying data | Legitimate interests; business improvement exception (First Schedule, Part 5) where it applies |
| Legal, regulatory, and tax obligations | The PDPA’s legal-requirement exceptions |
| Marketing email | Separate opt-in only. Every marketing email has an unsubscribe link and we honour it. We make no marketing calls or SMS; if we ever do, we check the Do Not Call Registry first. |
6. AI features and AI providers
Mesy is an AI product. Its AI features send your content to third-party AI providers as it is, not anonymised.
Your workspace administrator selects one AI model in admin settings. Almost every AI feature runs on that model: co-pilot chat, email linking, the Telegram assistant, email drafting, capture enrichment, workflow AI steps, daily insights, and import auto-matching. The exceptions are in the table below.
| Flow | Provider | What it receives |
|---|---|---|
| All AI features above | The selected model’s provider: Anthropic (the default), Google, OpenAI, or OpenRouter | Your messages to the assistant and the content the feature works on: record fields, full email bodies, calendar events, notes, chat text. Email drafting also sends the body of the email being replied to (up to ~2,000 characters). |
| Image and document capture | The selected model, if it can process images; otherwise the workspace’s configured fallback model, which may be a different provider | The image bytes and everything visible in them |
| Voice transcription | OpenAI (Whisper), always, regardless of the selected model | The raw audio of the voice note |
| Web research, where configured | Tavily | The search query, which can contain a contact’s or company’s name |
Apart from the web-research row, this table is derived from the same server registry that drives the “Powered by this model” panel in Mesy’s admin settings. If a feature’s routing changes, this table changes with it.
In particular:
- Two flows ignore your model choice. Voice always goes to OpenAI, and web research, where configured, goes to Tavily. Image capture can reach your fallback provider. Everything else follows your selection.
- All of these providers process data outside Singapore, principally in the United States (section 11).
- We store your AI transcripts; our metering stores nothing. Transcripts are your chat history in the product, kept with short redacted previews of each AI action for 90 days. Metering holds only token counts, model, latency, and cost.
- We do not train our own models on your data. We do improve Mesy using aggregated, de-identified usage and performance data; it never includes the content of your workspace and never identifies anyone. What each provider may do with submitted data is governed by our contracts with them.
- AI output is a suggestion, not a decision. Mesy’s AI makes no decisions with legal or similarly significant effect on individuals. Whether an AI action needs your confirmation depends on the permission tier your workspace sets, and a fixed set of actions (role changes, invitations, calendar event creation, record merges) always requires confirmation. Mesy never sends email or WhatsApp messages from your accounts without a human confirming the send.
7. Where a human can see your data
We do not read workspace content in the ordinary course of operating Mesy. A person at Majulah SG can see it only:
- in a support session you or your workspace admin can observe; support access is shown to the workspace by a visible banner and is audited;
- when investigating abuse, fraud, or a security incident;
- when the law requires it.
8. Google user data and Limited Use
Mesy requests access to Google account data through Google’s OAuth flow, using restricted Gmail scopes and sensitive Calendar scopes.
| Scope | Why |
|---|---|
gmail.readonly |
Show your mail inside Mesy and link it to CRM records |
gmail.send |
Send the emails you write or approve in Mesy, from your own account |
gmail.modify |
Keep read state and labels in step between Mesy and your mailbox. Gmail offers no narrower scope that permits message-label changes. |
calendar.events |
Show your events and create the events you confirm. Event-scoped, not full calendar access |
userinfo.email |
Identify the connected account |
You grant these per account and can revoke them at any time, in Mesy’s integration settings or at https://myaccount.google.com/permissions.
Limited Use. Mesy’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve user-facing features that are prominent in Mesy’s interface.
- We do not transfer Google user data to others, except as necessary to provide or improve those features, to comply with law, or as part of a merger or acquisition with your prior explicit consent.
- We do not use Google user data for advertising of any kind.
- We do not allow humans to read Google user data, except with your affirmative agreement for specific messages, for security purposes, to comply with law, or where the data is aggregated and de-identified.
- We do not retain or use Google user data to develop, improve, or train generalised AI or ML models. Where an AI model in Mesy processes Google data, it does so only to execute the feature you invoked, for you.
On disconnect. When you disconnect Gmail or Google Calendar, Mesy stops syncing and deletes the synced messages, events, and metadata from our database. Attachment files already written to object storage are not yet removed by that action; deleting the workspace removes them.
9. WhatsApp
A workspace can connect a WhatsApp Business number so its team answers customer WhatsApp messages inside Mesy. This uses Meta’s WhatsApp Business Platform (Cloud API); Meta delivers the messages and is a sub-processor for this channel.
What we process when a workspace connects a number:
- Inbound messages to the business number: message text, the sender’s phone number and profile name, and timestamps. Meta delivers these to Mesy the moment they arrive.
- Media: images, documents, and audio the customer sends. We download each item from Meta on receipt and store it in our object storage, because Meta’s own copies expire within minutes.
- Outbound replies the team sends from Mesy, recorded with the sending user.
- Contact matching. We match the sender’s phone number against the phone fields the workspace has designated as identity fields on its contact records; the digits must match exactly. An unmatched sender is never silently added to the CRM; a person is created only when a team member confirms it.
WhatsApp’s platform rules apply to replies: a business can send free-form messages only within 24 hours of the customer’s last message. Mesy shows this window state and disables the composer outside it.
On disconnect. Disconnecting the number deletes its conversations and messages from our database. There is no way to re-download them from WhatsApp afterwards; deletion is permanent. Media files already stored are not yet removed by that action; deleting the workspace removes them.
10. Who receives data
We run Mesy on the providers below. Each receives only what its job needs, under contract. The full list, with what each one processes and where, is published at https://mesy.ai/subprocessors. In summary:
- Hosting and storage: Supabase (database), DigitalOcean (compute), Cloudflare (object storage, transactional email).
- AI: Anthropic, Google, OpenAI, OpenRouter (routing to DeepSeek and Tencent), Tavily, as section 6 describes.
- Integrations: Google (Gmail, Calendar), Microsoft (Outlook, Teams), Telegram, and Meta (WhatsApp), for the accounts each workspace connects.
- Operations: Sentry (error monitoring, configured to exclude personal data) and Better Stack (uptime and log monitoring; shipped logs include IP addresses).
We update the published list before adding or replacing a sub-processor that handles personal data, and customers receive notice as the DPA provides.
Beyond sub-processors, we disclose personal data only: to you or at your direction; where law, a court, or a regulator requires it; to professional advisers under confidentiality; or in a merger, acquisition, or asset sale, in which case this policy continues to apply until replaced by one with comparable protection.
11. Where data lives
Our primary database and application servers are in Singapore, and our object storage (uploaded files and attachments) is configured for Cloudflare’s Asia-Pacific region. Full database backups are retained on the application host’s disk (newest ten dumps, at least 14 days) with an off-site copy in object storage.
Several providers process data outside Singapore, principally in the United States: every AI provider, the integration providers, and the monitoring providers. Under the Transfer Limitation Obligation (PDPA s.26) we transfer personal data abroad only where the recipient is bound to a standard of protection comparable to the PDPA, which we establish through data processing agreements and standard contractual clauses with each provider.
12. How long we keep data
We keep personal data only as long as it serves its purpose or a legal need requires (PDPA s.25).
| Data | Retention |
|---|---|
| Account and workspace data | Life of the account, plus a limited period after closure for legal and dispute purposes |
| Customer CRM content, synced mail, calendar, chat, WhatsApp, files | While the subscription is active; on termination, deleted or returned as the DPA provides after an export window of 30 days |
| Google data on disconnect | Deleted from the database at disconnect; stored attachments currently persist until workspace deletion (section 8) |
| WhatsApp data on disconnect | Deleted from the database at disconnect, permanently; stored media currently persists until workspace deletion (section 9) |
| In-product messaging | Notifications deleted after 90 days; message bodies live with the workspace |
| AI transcripts | Deleted on the customer-content schedule; per-action previews deleted after 90 days |
| Session and authentication records | Until expiry or revocation, plus a short security window |
| AI metering (no content) | Cost and latency metering deleted after 90 days; aggregate token counts while the workspace is live |
| Technical and error logs | A short rolling window |
| Record change history | Retained with the record. It preserves prior field values, so an edited or deleted value can persist in it |
Backups. Deleted data remains in backups until they age out on rotation, at most 30 days. We never selectively edit backups.
Automated deletion exists today for some categories (notifications, AI action previews, and internal event feeds prune at 90 days; backups rotate). It does not yet exist for CRM records, files, synced content, or change history.
13. How we protect data
- Tenant isolation in the database. Workspace content is segregated by PostgreSQL row-level security, bound to the authenticated workspace on every request. A small enumerated set of connection and routing tables is reached before workspace context exists (sign-in, webhooks) and is scoped by explicit filtering instead; those tables hold credentials and routing metadata, not CRM content.
- TLS in transit for all access and all provider traffic.
- Credentials encrypted at rest: integration tokens and secrets encrypted with a separately held key; passwords stored only as bcrypt hashes; refresh tokens only as hashes, in
HttpOnlycookies scripts cannot read. - Multi-factor authentication (TOTP and passkeys), role-based access control, per-record sharing rules.
- Signed webhooks, verified with constant-time comparison, for every inbound integration including WhatsApp.
- An append-only change log; AI actions recorded against the user who initiated them; rate limiting; secret scanning, dependency audits, and static and test gates in the build pipeline.
- Nightly backups, and a backup before each release.
- Restricted administrative access; support access to customer content is banner-visible and audited (section 7).
If a breach occurs, section 14 applies.
14. Data breaches
We assess every suspected breach promptly. A breach is notifiable when it is likely to result in significant harm to affected individuals, or when it affects 500 or more individuals. For a notifiable breach we notify the PDPC no later than 3 calendar days after determining it is notifiable, and affected individuals as the PDPA requires. We work to complete assessment and notification within 30 days of becoming aware. Where we hold data as an intermediary, we notify the customer organisation without undue delay so it can meet its own duties.
15. Your rights
Under PDPA sections 21 and 22 you may ask us for access to the personal data we hold about you and how it was used or disclosed in the past year, and for correction of errors or omissions.
Email dpo@mesy.ai with enough detail to identify you and locate the data. We may verify your identity first. We acknowledge your request and respond as soon as reasonably possible; if we cannot respond within 30 days, we tell you when we will. An access request may carry a reasonable fee, stated before we proceed. PDPA exceptions may apply, for example where a request would reveal another person’s data.
If your data sits in a customer’s CRM, that organisation is your first point of contact for access, correction, and deletion; send your request there (section 2).
Withdrawing consent. You may withdraw consent for any purpose that rests on it: disconnect an integration, or close your account. Withdrawal is not retrospective, and some withdrawals end our ability to provide part or all of the service.
Complaints. Write to dpo@mesy.ai first. If unsatisfied, you may complain to the Personal Data Protection Commission (https://www.pdpc.gov.sg).
16. Children
Mesy is a business tool, not directed at children. We do not knowingly collect personal data from anyone under 18, and an account requires the capacity to enter our Terms of Service. Contact dpo@mesy.ai if you believe a child’s data has reached us.
17. Changes to this policy
When we update this policy we change the date at the top. For changes that materially affect how we handle your data, we notify account holders by email or in-product before they take effect.
18. Contact
Data Protection Officer, Majulah SG Pte Ltd Email: dpo@mesy.ai · Postal: 6 Ubi Road 1, #06-10, Wintech Centre, Singapore 408726 · UEN: 202129171K