Mega

0

Mega is an online file sharing service that allows users to sync files to the cloud, access them from any internet connected device, and share them with collaborators. Mega is based in Auckland, New Zealand and has been providing its cloud service since 2013. They use encryption to protect your data while in transit between your computer and their servers. “Data uploaded is encrypted on the uploading device before it is sent out to the Internet, and data downloaded is decrypted only after it has arrived on the downloading device. The client machines are responsible for generating, exchanging and managing the encryption keys. No usable encryption keys ever leave the client computers (with the exception of RSA public keys).” Mega does not disclose their data centre locations or security certifications. Data can easily be uploaded to/downloaded from Mega through their website or their mobile applications. Mega recognizes you as the owner of all data uploaded to your account and makes no claims to it. If you choose to terminate your Mega account, you must retrieve your data first, as they may wish to delete your data immediately.

This disclosure was provided and researched by Arrowrock. Sources are cited where possible.

Please report any inaccuracies in this report by leaving a reply below or sending us a private message. Thank you!

Company Identity

Trading Name Mega
Company Website https://mega.co.nz/
Company Phone Number Not available
Company Email Address support@mega.co.nz
legal@mega.co.nz
copyright@mega.co.nz
idea@mega.co.nz
bug@mega.co.nz
media@mega.co.nz
https://mega.co.nz/#contact
Physical Address Not available

What services does this disclosure apply to?
Mega
www.mega.co.nz

What country holds legal jurisdiction over the service(s)?
The relationship we have with you under these terms is governed by New Zealand law. You and we submit to the exclusive jurisdiction of the New Zealand arbitral tribunals and courts (for the purposes of that arbitation) and the parties agree to enforcement of the arbitral award and orders in New Zealand and any other country.
https://mega.co.nz/#terms

How long has your company been operating?
Since 2013
https://mega.co.nz/#about

How long has your company been providing the service(s) covered in this disclosure?
Not available

Is your company currently profitable?
Not available

return to the top

Customer Support and Service Level Agreement

What are your standard customer support hours?
Not available

What channels are available for communication with clients?
support@mega.co.nz
legal@mega.co.nz
copyright@mega.co.nz
idea@mega.co.nz
bug@mega.co.nz
media@mega.co.nz
https://mega.co.nz/#contact

Which is your preferred channel for client communications?
You can contact us by writing to support@mega.co.nz. If we need to contact you or provide you with Notice we will email you at the email address you gave us when you set up your access to the services and/or through any internal messaging system we provide
https://mega.co.nz/#terms

Do you collect any information from client communications?
We keep the following personal information:
– When a user signs up for particular services on our website they may need to give us the details required in our registration form and keep that information up to date;
– Communication logs, traffic data, site usage and other information related to us supplying the services (including for serving of advertising material on our site);
– Any personal information included in data uploaded to our system including but not limited to registration information.

We keep records of IP addresses used to access our services.
Access to your data is by way of username and password and it is your responsibility to keep these safe and secure.

We will collect and keep personal information about users and other visitors to our site to provide services and support to them related to the website and our services, to sell services to them and also for dealing with other user activities, market and product research and to be able to give users promotional material on our other services and special offers.

We keep all your data and personal information while you are subscribed to our services but subject to our suspension and termination rights set out in our Terms.
https://mega.co.nz/#privacy

What is your standard response time for customer support inquires?
Not available

Do you proactively communicate information about future planned outages and maintenance to clients?
We will try to give you access to our website all the time, but we do not make any promises or provide you with a warranty that our website or the services will be without any faults, bugs or interruptions.

Whilst we intend that the services should be available 24 hours a day, seven days a week, it is possible that on occasions the website or services may be unavailable to permit maintenance or other development activity to take place or be periodically interrupted for reasons outside our control.

Information on our website will change regularly. We will try to keep our website up to date and correct, but again, we do not make any promises or guarantees about the accuracy of the information on our website.
https://mega.co.nz/#terms

Do you proactively communicate information about current unscheduled outages and incidents to clients?
Not available

Do you make incident reports available to clients after major incidents?
Not available

What is the expected uptime of the service?
Whilst we intend that the services should be available 24 hours a day, seven days a week, it is possible that on occasions the website or services may be unavailable to permit maintenance or other development activity to take place or be periodically interrupted for reasons outside our control.
https://mega.co.nz/#terms

Has the service experienced any outages in the last 12 months?
Not available

Does the SLA guarantee service uptime?
Not available

return to the top

Security

Are logs kept of client logins and locations?
Not available

Does your service support password/account recovery?
Unfortunately, your MEGA password is not just a password – it is the master encryption key to all of your data. If you lose it, you lose access to all of your files that are not in a shared folder and that you have no previously exported file or folder key for.
https://mega.co.nz/#help_account

Does the service monitor for any suspicious account activity?
Not available

Does your service offer two-step or multi-factor authentication?
No

Does your service offer login via other services?
No

Does your service secure all client data in transit?
Mega secures all data in transit using TLS 1.1

Does your service secure client data at rest?
All encryption is end-to-end. Data uploaded is encrypted on the uploading device before it is sent out to the Internet, and data downloaded is decrypted only after it has arrived on the downloading device. The client machines are responsible for generating, exchanging and managing the encryption keys. No usable encryption keys ever leave the client computers (with the exception of RSA public keys).
https://mega.co.nz/#help_security

Does your service allow clients to collaborate with 3rd parties?
Not available

Does your primary system reside in a data center with a security certification?
All files stored on MEGA are encrypted. All data transfers from and to MEGA are encrypted. And while most cloud storage providers can and do claim the same, MEGA is different – unlike the industry norm where the cloud storage provider holds the decryption key, with MEGA, you control the encryption, you hold the keys, and you decide who you grant or deny access to your files, without requiring any risky software installs. It’s all happening in your web browser!
https://mega.co.nz/#privacycompany

Does your backup/disaster recovery system reside in a data center with a security certification?
Not available

return to the top

Data Ownership

Do you claim ownership of any client data or information uploaded to your service?
You own, or warrant that you are authorised to use, any intellectual property in any data you store on, use, download, upload or otherwise transmit to or from, our service. You grant us a worldwide, royalty free licence to use, store, back-up, copy, transmit, distribute, communicate and otherwise make available, your data, for the purposes of enabling you and those you give access to, to use the website and the services and for any other purpose related to provision of the services to you.
https://mega.co.nz/#terms

Does the client retain full ownership of any data of information transmitted or stored via upstream providers?
You own, or warrant that you are authorised to use, any intellectual property in any data you store on, use, download, upload or otherwise transmit to or from, our service. You grant us a worldwide, royalty free licence to use, store, back-up, copy, transmit, distribute, communicate and otherwise make available, your data, for the purposes of enabling you and those you give access to, to use the website and the services and for any other purpose related to provision of the services to you.
https://mega.co.nz/#terms

Does client use of your service generate any metadata or other statistical information?
We may also collect information about visits to our website to measure the number of visitors to different parts of the website, to assess user access patterns and otherwise to operate the website. We may use cookies or other similar technology for these purposes. By using our website or our services, you specifically agree to our use of cookies and such other technology to collect personal information. You can usually remove or block cookies (such as by using the settings in your browser), but it may affect your ability to use the website.

We may keep non-personal information about visits to the website or which is obtained via cookies or other similar technology:
– and might join that information with other users’ information and give it to advertisers in a way which doesn’t personally identify you;
– might analyse and use this information for marketing or statistical purposes as well as to improve the way we do business with our users.
https://mega.co.nz/#privacy

return to the top

Data Location

Where are the primary systems that host client data located?
Not available

Where are the backup/disaster recovery systems that host client data located?
Not available

Are there any other systems that host client data on behalf of your service?
Not available

return to the top

Data Access and Use

Does the client have full access to their data during the service contract period?
Yes, via the Mega website and mobile applications.

Can the client freely download their data from the service during the contract period?
Yes, all data a client stores in Mega an be easily downloaded via the Mega website and mobile apps. The files will be in the same format as they were added by the client.

Can the client easily import/upload their data from a competing service provider into your service?
Yes, any files/formats can be uploaded to Mega. All formats are supported.

Does your services include an API to access client data?
Yes. Please use our software development kit to add MEGA support to your application.
https://mega.co.nz/#help

Following termination of the service, will the client be able to access their data?
We will store your data on our service subject to these terms and any plan you subscribe to. If you choose to stop using our services, you need to make sure you retrieve your data first because, after that, we may, if we wish, delete it. If we suspend our services to you because you or someone you have given access to has breached these terms, during the term of that suspension, we may if we wish deny you access to your data. If we terminate our services to you because you or someone you have given access to has breached these terms, we may if we wish delete your data immediately. In circumstances where we cease providing all our services for other reasons, we will, if reasonably practicable and we are not prevented by law from doing so, give you 30 days access to retrieve your data.
https://mega.co.nz/#terms

Following termination of the service, is all client data deleted?
We will store your data on our service subject to these terms and any plan you subscribe to. If you choose to stop using our services, you need to make sure you retrieve your data first because, after that, we may, if we wish, delete it. If we suspend our services to you because you or someone you have given access to has breached these terms, during the term of that suspension, we may if we wish deny you access to your data. If we terminate our services to you because you or someone you have given access to has breached these terms, we may if we wish delete your data immediately. In circumstances where we cease providing all our services for other reasons, we will, if reasonably practicable and we are not prevented by law from doing so, give you 30 days access to retrieve your data.
https://mega.co.nz/#terms

Does anyone in your organization (including contractors and upstream providers) have the ability to directly access client data?
Your data is encrypted by you before upload to our system and therefore we do not and cannot access that content unless we are provided with the decryption key. You may give access to others by providing them with a link and decryption key and you shall be responsible for their compliance with this Policy.
https://mega.co.nz/#privacy

Does your company use client data or information for any business function (other than the provision of the service)?
We will collect and keep personal information about users and other visitors to our site to provide services and support to them related to the website and our services, to sell services to them and also for dealing with other user activities, market and product research and to be able to give users promotional material on our other services and special offers.
https://mega.co.nz/#privacy

Does your company use client data or information to generate revenue (other than the provision of the service)?
Not available

Do you access client data in any additional circumstance not yet specified in this disclosure?
Not available

return to the top

Data Breach Notification

Do you have a policy in place for dealing with data loss or breach?
You must maintain copies of all data stored by you on our service. We do not make any guarantees that there will be no loss of data or the services will be bug free. You are completely responsible to remove all data prior to termination of services.
https://mega.co.nz/#terms

Do you notify clients if their data has been lost or compromised?
Not available

return to the top

Backup and Maintenance

Does your service support data versioning?
Not available

How often are service/client data backups performed?
Not available

What method is used to perform service/client data backups?
Not available

How long is backup data retained for?
Not available

return to the top

Disclaimer

The information in this report is provided “AS IS” without warranty of any kind, express or implied. Please use good judgement and verify the information you consider important before basing any decisions on it.