Melan LLC (“Melan Group,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal information. This Privacy Notice explains how we collect, use, share, and safeguard your data when you interact with our websites, platforms, and services. It satisfies transparency requirements under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.
Data Collection and Usage
This section describes the categories of personal information we collect, how we obtain it, and the purposes for which it is processed.
Information Collected
We collect personal information that you voluntarily provide and information that is automatically generated through your interaction with our platforms.
- Identity and contact data: Full name, email address, phone number, postal address, and professional affiliation.
- Account credentials: Username, password, and authentication data used to access our platforms.
- Research and professional data: Institutional affiliation, publication history, research interests, grant information, and partnership preferences.
- Communication data: Records of correspondence, support inquiries, and feedback submitted through our channels.
- Technical data: Internet protocol (IP) address, browser type and version, operating system, device identifiers, and usage logs.
- Usage data: Pages visited, time spent on pages, clickstream data, referring URLs, and interaction patterns.
- Cookies and tracking data: Information collected through cookies, web beacons, and similar technologies as described below.
Collection Methods
We obtain personal information through the following means:
- Direct submissions: Information you provide through web forms, account registration, newsletter sign-ups, event registration, research partnership inquiries, and customer support requests.
- Automated technologies: Data collected automatically through cookies, server logs, analytics tools, and similar tracking technologies when you browse our websites or use our platforms.
- Third-party sources: Information obtained from publicly available research databases, institutional directories, professional networking platforms, and data brokers where permitted by law.
- Business partners: Data shared by research institutions, funding agencies, co-sponsors, and service providers in connection with partnership facilitation.
Purpose of Processing
We process personal information only for specified, explicit, and legitimate purposes:
- Service delivery: Facilitating research partnerships, managing accounts, processing requests, and providing customer support.
- Communication: Responding to inquiries, sending administrative notices, and delivering service-related updates.
- Marketing and outreach: Sending newsletters, event invitations, and information about our services, where we have consent or a legitimate interest.
- Platform improvement: Analyzing usage patterns to enhance user experience, develop new features, and optimize platform performance.
- Legal compliance: Meeting regulatory obligations, enforcing our terms of service, and protecting our legal rights.
- Security: Detecting and preventing fraudulent, unauthorized, or illegal activity.
Cookies and Tracking
Our websites and platforms use cookies, web beacons, and similar tracking technologies to enhance functionality, analyze performance, and deliver relevant content.
Categories of cookies we use:
- Essential cookies: Required for the basic operation of our platforms. These cannot be disabled.
- Functional cookies: Remember your preferences and settings to improve your experience.
- Analytics cookies: Help us understand how visitors interact with our platforms so we can measure and improve performance.
- Marketing cookies: Track your activity across websites to deliver relevant advertising and measure campaign effectiveness.
You may control cookie preferences through our cookie consent banner, which appears on your first visit and can be accessed at any time through your account settings or browser preferences. You may also configure your browser to reject cookies, though this may affect platform functionality.
Data Sharing and Governance
This section describes how we share personal information, how long we retain it, the safeguards we apply, and how we manage cross-border data transfers.
Third-Party Sharing
We do not sell personal information. We may share your data with the following categories of recipients:
- Service providers: Third-party vendors who perform services on our behalf, including cloud hosting, analytics, email delivery, payment processing, and customer relationship management. These providers are contractually bound to process data only on our instructions and to maintain appropriate security measures.
- Research partners and institutions: Entities involved in collaborative research partnerships facilitated through our platform, shared only to the extent necessary to establish and manage the partnership.
- Professional advisors: Legal counsel, auditors, insurers, and consultants who provide professional services to our organization.
- Legal and regulatory authorities: Law enforcement, courts, regulators, and government agencies where disclosure is required by applicable law or necessary to protect our legal rights.
- Corporate transactions: In connection with a merger, acquisition, restructuring, or sale of assets, personal information may be transferred to the successor entity, subject to continued protection under this Privacy Notice.
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law.
Retention criteria:
- Account data: Retained for the duration of your account relationship plus 12 months following closure, unless legal requirements mandate longer retention.
- Communication data: Retained for 24 months from the date of last correspondence.
- Technical and usage data: Retained for 36 months from collection.
- Marketing preferences: Retained until you withdraw consent or opt out.
- Legal hold data: Retained for the duration of any applicable legal or regulatory proceeding.
When retention periods expire, personal information is securely deleted or anonymized so that it can no longer be associated with an identifiable individual.
Security Safeguards
We implement technical, organizational, and administrative measures to protect personal information against unauthorized access, alteration, disclosure, or destruction.
- Encryption: Data in transit is protected using TLS 1.2+ protocols. Data at rest is encrypted using industry-standard AES-256 encryption.
- Access controls: Access to personal information is restricted to authorized personnel on a need-to-know basis, enforced through role-based access controls and multi-factor authentication.
- Monitoring: Systems are monitored 24/7 for unauthorized access attempts, anomalies, and potential security incidents.
- Vendor assessments: Third-party service providers undergo security reviews and are contractually required to maintain equivalent safeguards.
- Incident response: We maintain a documented incident response plan to promptly detect, contain, and remediate security breaches, and to notify affected individuals and regulators as required by law.
International Transfers
As a global organization, we may transfer personal information to countries other than the country in which the data was originally collected. When we transfer data across borders, we ensure appropriate safeguards are in place.
Legal mechanisms for cross-border transfers:
- Standard Contractual Clauses (SCCs): EU- and UK-approved contractual provisions governing data transfers to third countries.
- Adequacy decisions: Transfers to jurisdictions recognized by the European Commission as providing adequate data protection.
- Data Protection Impact Assessments (DPIAs): Conducted where processing is likely to result in high risk to individuals’ rights and freedoms.
User Rights and Administration
This section outlines your legal rights regarding your personal information and provides the tools to exercise them, along with administrative provisions governing this Privacy Notice.
Consumer Rights
Depending on your jurisdiction, you may have the following rights under applicable privacy law, including the GDPR, CCPA, and similar regulations:
- Right to know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to access: Obtain a copy of the personal information we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete personal information.
- Right to deletion: Request deletion of your personal information, subject to certain legal exceptions.
- Right to portability: Receive your personal information in a structured, commonly used, machine-readable format and transmit it to another controller.
- Right to restrict processing: Request limitation of how we use your personal information in specific circumstances.
- Right to object: Object to processing based on legitimate interests, including direct marketing.
- Right to non-discrimination: Exercise your privacy rights without fear of discriminatory treatment.
Opt-Out Instructions
We respect your right to control how your data is used. You may exercise the following opt-out options:
- Email marketing: Click the “unsubscribe” link in any marketing email you receive from us.
- Cookie opt-out: Adjust your preferences at any time through our cookie consent banner.
- Data sharing opt-out: Submit a request using the contact information below to opt out of any data sharing for purposes other than those essential to service delivery.
- CCPA/CPRA opt-out: If you are a California resident, you may opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising by submitting a request to the contact information below.
We will process all verified opt-out requests within the timeframes required by applicable law, typically within 15-45 business days depending on jurisdiction.
Children’s Privacy
Our platforms and services are not directed to individuals under the age of 16. We do not knowingly collect personal information from minors without verifiable parental consent. If we become aware that a minor has provided us with personal information without parental consent, we will take steps to delete such information promptly.
Where required by applicable law, including the Children’s Online Privacy Protection Act (COPPA) in the United States, we implement age-verification mechanisms and obtain verifiable parental consent before collecting personal information from minors. If you believe a minor has submitted personal information to us, please contact us immediately.
Contact Information
If you have questions, concerns, or requests regarding this Privacy Notice or our data practices, please contact us:
Melan LLC (dba The Melan Group)
Email: support@themelan.com
Privacy inquiries: privacy@themelan.com
Response time: We acknowledge all privacy requests within 2 business days and respond substantively within 30 days.
If you are located in the European Economic Area (EEA) or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority.
Policy Updates
We may update this Privacy Notice from time to time to reflect changes in our practices, legal obligations, or operational requirements. When we make material changes, we will notify you through one or more of the following methods:
- A notice prominently displayed on our website or platform
- Email notification to the address associated with your account
- In-app notification upon your next login
We encourage you to review this Privacy Notice periodically. The “Last reviewed” date at the bottom of this document indicates when it was most recently updated. Continued use of our platforms after a change takes effect constitutes acceptance of the updated Privacy Notice.
Policy Governance
This Privacy Notice is reviewed annually by Melan’s Privacy Officer, Legal, and executive leadership. Updates are published with a new effective date and a summary of changes. Questions about this policy can be submitted at anytime by contacting our team.
Effective date: July 18, 2026
Last reviewed: July 18, 2026
Next review: July 18, 2027



