Effective Date: 11 August 2026, Last Updated: 11 August 2026
1. Introduction
Ministry of Economy and Finance ("we," "our," or "us") operates MEF E-Meeting (the "App"), distributed as com.itd.dio.e_meeting on Android and com.itd.mef.emeeting on iOS.
The App is an internal workspace tool for our organization's staff and administrators. It is not a public consumer product: accounts are created by administrators, there is no public sign-up, and access requires credentials issued by the organization.
This Privacy Policy explains what information the App collects, how we use it, who can see it, and how you can ask for it to be deleted. It applies to the mobile application and the backend service it connects to.
2. Information We Collect
To provide internal booking, scheduling, and record-keeping services, the App collects and processes the following data.
2.1 Account and Profile Information Created and maintained by administrators, not by self-registration:
Full name
Email address (also used as the sign-in username)
Assigned role (see Section 3.4)
Assigned office and organization
Password (transmitted for authentication; the App never stores your password on the device)
2.2 Scheduling and Request Data Content you create or that is created about you in the course of your work:
Meeting bookings: subject, location, start and end date/time, chosen room, building and floor, assigned meeting leader, a private/public flag, and approval status.
Meeting participants: the names and email addresses of the people you add to a meeting.
Leave requests: the requester, the stated reason for leave, and start and end dates.
Document records: subject, location, assigned responder, and status.
Mission and training records: name, email, and role of the listed person.
Announcements: title, description, and display period.
Facilities directory: buildings, floors, rooms, offices, and meeting leaders maintained by administrators.
2.3 Files and Attachments :
You may attach files to meeting bookings and leave requests.
The App accepts these file types only: PDF, DOC, DOCX, XLS, XLSX, PNG, JPG, and JPEG.
Files are selected through your device's standard document picker.
The App does not request access to your camera or to your photo library, and it cannot browse your device's files on its own — it receives only the specific files you choose in that picker.
The contents of any file you attach are uploaded to our servers and become part of the associated meeting or leave record.
2.4 Technical and Device Data:
Session credentials: stores tokens and profile records using secure storage (iOS Keychain / Android encrypted storage).
Language preference: chosen interface language (Khmer or English) is saved locally.
Temporary attachment cache: files in the temporary folder are deleted on sign-out and App start.
What we do not collect: the App does not collect your location, contacts, calendar stored on your device, photos, microphone or camera input, advertising identifiers, or behavioural analytics.
3. How We Use Your Information
We use the collected information strictly for internal organizational purposes:
Authentication and session management: to verify your sign-in and keep you signed in until you log out or your session expires.
Booking and approvals: to reserve meeting rooms, route booking requests to the appropriate approver, and record whether a request was approved or rejected.
Request and record management: to process leave requests, document records, and mission or training records.
Role-based access: to determine which screens and actions are available to you. Roles recognized by the system are Administrator, System Administrator, Office Administrator, and standard users. Administrators can view and manage records belonging to other users in their organization.
Meeting visibility: meetings marked private are limited in visibility compared with ordinary meetings.
Calendar synchronization: where the organization has enabled it, to publish meeting schedules to the organization's Google Calendar (see Section 4.2).
We do not use your data for advertising, marketing, profiling, or any automated decision-making that produces legal or similarly significant effects.
4.1 Within the Organization
Your data is stored on our own backend infrastructure at e-meeting.mef.one. Within the App, other members of your organization can see information relevant to shared work:
Your name as a meeting organizer or participant.
Meetings booked in shared rooms.
Administrators have broader visibility, including user account details and submitted requests.
We do not sell your data, and we do not share it with advertisers, data brokers, or analytics providers. The App contains no advertising SDK, no analytics SDK, no crash-reporting SDK, and no third-party tracking library of any kind.
The App supports an optional Google Calendar integration. Please note how this works, as it differs from a typical personal calendar connection:
The connection is organization-wide and administrator-controlled. An administrator connects a single Google account on behalf of the whole organization. Individual staff members do not connect their own personal Google accounts, and the App does not read your personal Google Calendar.
When an administrator connects the account, the sign-in and consent screen is opened in your device's system browser, not inside the App. The App never sees your Google password, and the confidential OAuth credentials are held on our server, not in the App.
Once connected, meeting schedule information from the App is written to that organizational calendar so schedules stay up to date. This is transmitted directly to Google over a secure connection.
An administrator can disconnect the organization's Google account at any time from the App's settings.
Google's handling of data it receives is governed by Google's own privacy policy.
4.3 Opening Attachments
When you open an attachment, your device may hand the file to another application installed on your device (for example, a PDF or Office document viewer) so it can be displayed. That application's handling of the file is governed by its own terms.
4.4 Legal Disclosure
We may disclose information where required to do so by applicable law, regulation, legal process, or an enforceable governmental or institutional request.
5. Data Security
We apply the following measures to protect your information:
Encryption in transit: all communication between the App and our servers uses HTTPS/TLS. Release builds do not permit unencrypted connections.
Secure credential storage: session tokens and your profile record are stored using the iOS Keychain and Android's encrypted storage, never in plain application preferences.
No device backup of app data: on Android, application data is excluded from device and cloud backups, so session data cannot be extracted through a backup.
Code hardening: Android release builds are minified and obfuscated.
Session expiry: if your session is rejected by the server, the App immediately clears all stored session data and returns you to the sign-in screen.
Attachment cleanup: attachments opened for preview are removed from the device's temporary storage on sign-out and at App start.
No method of transmission or storage is completely secure. While we work to protect your information using the measures above, we cannot guarantee absolute security.
6. Data Retention and Account Deletion
We retain your account and the records associated with it for as long as you hold an active account with the organization, and thereafter for as long as required for administrative and institutional record-keeping obligations.
Note that certain records — such as a meeting you organized or a leave request you submitted — form part of the organization's operational record and may be retained even after your individual account is removed.
Requesting Deletion
The App does not provide self-service account deletion. To request deletion of your account and its associated data, please follow these steps:
Email gavinmy21@gmail.com with the subject line "Account Deletion Request", sent from your registered work email address.
An administrator will verify the request and manually remove your account records from the system. Administrators are also able to delete user accounts directly through the App as part of normal staff administration.
We will respond to deletion requests within a reasonable period, subject to any record-keeping obligations described above.
The App requests a deliberately minimal set of device permissions:
• Android: INTERNET - To communicate with the E-Meeting server. This is the only permission the App declares.
• iOS: Local Network access - Only used when connecting to an E-Meeting server on the same local network.
The App does not request camera, photo library, microphone, location, contacts, device calendar, or background location permissions.
8. Children's Privacy
The App is an internal tool provided to employees and authorized staff. It is not directed at children, and we do not knowingly collect information from children. Accounts are issued only by organizational administrators.
We may update this Privacy Policy periodically to reflect changes in our internal processes or in the App's features. When we make a significant change, we will update the "Last Updated" date above and notify staff through the organization's usual channels.
10. Contact Us
If you have questions or concerns about this Privacy Policy, about how your data is handled, or if you wish to exercise any rights available to you under applicable law, contact us at:
Email: gavinmy21@gmail.com , Organization: Ministry of Economy and Finance of Cambodia
Address:Street 92, Phnom Penh 120211