Melan LLC (“Melan Group,” “we,” “us,” or “our”) — GDPR Privacy Policy
This policy informs individuals in the European Economic Area (EEA), Switzerland, and the United Kingdom about how we collect, use, and protect their personal data, and about their rights under the General Data Protection Regulation (GDPR) and the UK GDPR.
1. Data Controller and Data Protection Officer
Data Controller
Melan LLC (dba The Melan Group) is the data controller responsible for your personal data.
Melan LLC
Address: 1330 Avenue of the Americas, Suite 23A, New York, NY 10019, United States
Email: [email protected]
Website: www.themelan.com
Data Protection Officer (DPO)
We have appointed a Data Protection Officer to oversee our data protection strategy and ensure compliance with GDPR requirements. Our DPO serves as the point of contact for all data protection matters, including supervisory authority inquiries and data subject requests.
Data Protection Officer
Email: [email protected]
Postal address: Melan LLC, Attn: DPO, 1330 Avenue of the Americas, Suite 23A, New York, NY 10019, United States
Response time: All DPO inquiries are acknowledged within 2 business days.
2. Categories of Personal Data Collected
We collect and process the following categories of personal data:
- Identity data: Full name, job title, company name, professional affiliation, and institutional role.
- Contact data: Email address, phone number, postal address, and professional mailing address.
- Account data: Username, password hash, account preferences, and authentication logs.
- Research and professional data: Publication history, research interests, grant information, academic credentials, and partnership preferences.
- Communication data: Records of correspondence with us, including support tickets, inquiries, and feedback submissions, along with any personal data you choose to include in those communications.
- Technical data: IP address, browser type and version, time zone setting, operating system and platform, device type, and other technology on the devices you use to access our platforms.
- Usage data: Information about how you use our websites, platforms, and services, including pages visited, time spent, clickstream data, referring URLs, and navigation patterns.
- Marketing and communications data: Your preferences in receiving marketing from us, communication preferences, newsletter subscription status, and event registration history.
- Cookie and tracking data: Data collected through cookies, web beacons, pixel tags, and similar tracking technologies as set out in our Cookie Policy.
We do not collect special categories of personal data (race, ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification, health data, or sexual orientation) unless you voluntarily provide them in communications with us.
3. Lawful Basis for Processing
Under the GDPR, we process your personal data only when we have a valid lawful basis. The specific basis we rely on for each processing activity is set out below:
| Processing Activity | Lawful Basis | Explanation |
|---|---|---|
| Account creation and management | Contractual necessity (Art. 6(1)(b)) | Processing is necessary to perform our contract with you and provide the requested services. |
| Service delivery and support | Contractual necessity (Art. 6(1)(b)) | Processing is necessary to respond to your requests and deliver our services. |
| Newsletter and marketing communications | Consent (Art. 6(1)(a)) | We send marketing communications only after you have given your explicit, freely given consent via opt-in. |
| Platform analytics and improvement | Legitimate interests (Art. 6(1)(f)) | We have a legitimate interest in analyzing usage to improve our platforms and user experience. We balance this against your privacy rights through data minimization and anonymization. |
| Security, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) | We have a legitimate interest in protecting our systems, users, and data against unauthorized access and fraudulent activity. |
| Legal compliance and regulatory obligations | Legal obligation (Art. 6(1)(c)) | Processing is necessary for compliance with applicable legal and regulatory requirements. |
| Cookies (non-essential) | Consent (Art. 6(1)(a)) | Non-essential cookies are placed only after you have given your consent through our cookie banner. You may withdraw consent at any time. |
| Event registration and facilitation | Contractual necessity (Art. 6(1)(b)) | Processing is necessary to register you for and facilitate your participation in events. |
4. Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. The retention periods for each category of data are:
| Data Category | Retention Period | Criteria / Rationale |
|---|---|---|
| Identity and contact data | Duration of account + 12 months | Needed to maintain the account relationship and manage post-closure obligations. |
| Account data (credentials, preferences) | Duration of account + 12 months | Required for account functionality and security. |
| Research and professional data | Duration of account + 36 months | Retained to facilitate ongoing and future research partnership opportunities. |
| Communication data | 24 months from last correspondence | Sufficient to maintain service continuity and address follow-up inquiries. |
| Technical and usage data | 36 months from collection | Standard analytics retention for trend analysis and platform improvement. |
| Marketing preferences and consent records | Until consent is withdrawn or opt-out exercised | We must honor your marketing preferences indefinitely until you change them. |
| Cookie consent records | 12 months from collection | Standard period for retaining evidence of consent under GDPR. |
| Legal hold data | Duration of applicable legal or regulatory proceeding + 6 months | Required to comply with legal holds and litigation preservation obligations. |
When retention periods expire, personal data is securely deleted or anonymized so that it can no longer be associated with an identifiable individual.
5. Categories of Recipients
We may share your personal data with the following categories of recipients:
- Cloud infrastructure providers: Hosting and data storage services (e.g., AWS, Google Cloud, Azure) that store and process data on our behalf under strict data processing agreements.
- Analytics service providers: Tools that help us understand platform usage and improve user experience (e.g., analytics platforms that act as data processors under our instructions).
- Email and communication platforms: Services that facilitate email delivery, newsletters, and customer communications.
- Customer relationship management (CRM) platforms: Tools used to manage interactions with users, partners, and prospects.
- Payment processors: Entities that process payments on our behalf, where applicable (e.g., Stripe, PayPal). These processors are PCI DSS compliant and handle payment data under strict contractual terms.
- Research partners and institutions: Entities involved in collaborative research partnerships, shared only to the extent necessary to establish and manage the partnership.
- Professional advisors: Legal counsel, auditors, insurers, and consultants bound by confidentiality obligations.
- Public authorities: Law enforcement, courts, regulators, and government agencies where disclosure is required by applicable law or necessary to protect our legal rights.
- Corporate transaction parties: In connection with a merger, acquisition, restructuring, or sale of assets, personal data may be transferred to the successor entity, subject to continued protection under this policy.
All recipients are contractually obligated to process personal data only on our documented instructions, to maintain appropriate technical and organizational security measures, and to comply with GDPR obligations applicable to data processors.
We do not sell your personal data to third parties.
6. International Data Transfers
As a global organization based in the United States, we may transfer your personal data to countries outside the EEA, Switzerland, and the UK. When we transfer personal data to countries that have not been deemed adequate by the European Commission or the UK Government, we implement appropriate safeguards to ensure your data receives an equivalent level of protection.
Safeguards for international transfers:
- Standard Contractual Clauses (SCCs): We use the European Commission’s Standard Contractual Clauses (2021) and the UK International Data Transfer Agreement (IDTA) for transfers to data processors and data controllers in third countries. A copy of the relevant SCCs can be provided upon request.
- Adequacy decisions: Where the European Commission or UK Secretary of State has determined that a third country ensures an adequate level of protection, we rely on that adequacy decision for transfers.
- Transfer Impact Assessments (TIAs): We conduct TIAs for each transfer to assess the legal framework and enforcement in the recipient country, and to ensure supplementary measures are applied where necessary.
- Data Processing Agreements (DPAs): We enter into GDPR-compliant data processing agreements with all third-party data processors, incorporating the applicable SCCs.
Our primary data centers are located in the United States. Data may also be processed in the European Union, the United Kingdom, and other jurisdictions where our service providers operate. If you would like details about the specific safeguards applied to transfers of your data, please contact our DPO at [email protected].
7. Your Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right to be informed: You have the right to be provided with clear, transparent, and easily understandable information about how we use your personal data. This policy fulfills that obligation.
- Right of access (Art. 15): You have the right to obtain confirmation from us as to whether we are processing your personal data, and if so, to request a copy of that data along with supplementary information about the processing.
- Right to rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data that we hold about you.
- Right to erasure (“right to be forgotten”) (Art. 17): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing, including when you withdraw consent, object to processing, or the data is no longer necessary for the purpose collected.
- Right to restrict processing (Art. 18): You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest its accuracy or object to our legitimate interest basis.
- Right to data portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON) and to transmit that data to another data controller without hindrance, where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21): You have the right to object to processing based on legitimate interests (including profiling) or for direct marketing purposes. We will comply with your objection unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
All rights requests are processed free of charge within one month of receipt, unless the request is manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable fee or refuse to act. We may request specific information from you to confirm your identity before processing your request.
Right to Withdraw Consent
Where we process your personal data based on consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
How to withdraw consent:
- Marketing emails: Click the “unsubscribe” link in any marketing email you receive from us.
- Cookie consent: Adjust your preferences at any time through our cookie consent banner, which is accessible on every page of our website.
- General withdrawal: Email our DPO at [email protected] with the specific processing activity for which you wish to withdraw consent.
We will process your withdrawal request within 5 business days. After withdrawal, we will stop processing your data for the purpose for which consent was given, unless we have another lawful basis for continued processing.
8. Automated Decision-Making and Profiling
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you under Article 22 of the GDPR.
We may use basic automated processes for operational purposes, such as:
- Content personalization: Recommending relevant content or research opportunities based on your stated preferences and usage history.
- Security monitoring: Automatically detecting and blocking suspicious login attempts or abnormal account activity.
These processes do not produce legal effects concerning you and are subject to human review upon request. If our practices change in the future, we will update this section and provide prior notice to affected individuals.
9. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EEA member state of your habitual residence, place of work, or place of the alleged infringement.
Lead Supervisory Authority (for cross-border processing):
Irish Data Protection Commission (DPC)
Address: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: www.dataprotection.ie
Phone: +353 1800 437 737
UK Supervisory Authority:
Information Commissioner’s Office (ICO)
Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
Website: www.ico.org.uk
Phone: +44 303 123 1113
We encourage you to contact us first at [email protected] so that we may attempt to resolve your concern directly before you approach a supervisory authority.
10. Policy Updates
We may update this GDPR Privacy Policy from time to time to reflect changes in our data processing activities, legal obligations, or regulatory guidance. When we make material revisions, we will notify you through one or more of the following mechanisms:
- A prominent notice displayed on our website or platform at least 14 days before material changes take effect.
- An email notification sent to the address associated with your account, where we hold your contact details.
- An in-app notification upon your next login.
Each update will include a summary of the changes made and a revised “Last reviewed” date. We encourage you to review this policy periodically. Continued use of our platforms or services after a revision takes effect constitutes acceptance of the updated policy.
11. Contact Information
If you have any questions, concerns, requests, or complaints regarding this GDPR Privacy Policy or our data processing practices, please contact us using the details below:
Melan LLC (dba The Melan Group)
1330 Avenue of the Americas, Suite 23A
New York, NY 10019, United States
Email: [email protected]
DPO contact: [email protected]
Response time: We acknowledge all data subject requests within 2 business days and respond substantively within 30 calendar days.
Effective date: July 18, 2026
Last reviewed: July 18, 2026
Next review: July 18, 2027



