Privacy policy

How Manda handles data.

Effective July 16, 2026 · Manda Technologies, Inc.

Manda provides legal work delivery software for in-house legal teams. This policy explains what we collect, how we use and retain it, and how to exercise your rights, including requesting deletion. Questions and requests reach us at hello@mandaplatform.com.

01

Who we are, and our role

Manda Technologies, Inc. operates the Manda platform. For the content your organization brings into its workspace (mandates, invoices, documents you choose to attach), we act as a service provider / processor on your organization's instructions. For account information (your name, work email, sign-in records) and for inquiries you send us, we act as a controller.

02

What we collect

Account and identity. Name, work email, and authentication events, managed through our sign-in provider (Clerk).

Workspace content. The mandate metadata your team creates: the nature of the mandate, pricing, quality reviews, mandates, invoices, and any documents your team chooses to attach. Manda is built on mandate metadata, not your mailbox or document stores: broader access to your systems happens only with explicit, granular permission.

Operational records. An audit trail of security-relevant events (sign-ins, permission changes, deletions) and service telemetry needed to run the product.

03

What we do not do

We do not sell personal information. We do not use your data to train AI models. AI inference runs with zero data retention and every call is logged with the model used. We do not read your mailbox. We do not serve advertising.

04

How we use data

To provide and secure the service; to support your team; to meet legal obligations; and, only where your organization has agreed in writing, to derive de-identified data for benchmarking features. De-identified contributions are designed so they cannot be tied back to you, your company, or any unique fact pattern, and can be withdrawn in full at any time.

05

Retention and deletion

Customer workspace data is retained for the life of the customer relationship and deleted within 30 days of termination under our documented offboarding procedure, which removes the workspace's database records and stored files. The audit trail is append-only and retained for at least one year, including the record that a deletion happened. Your organization can export its mandates and invoices from the product at any time.

06

Security

Every customer's data is isolated to their organization, enforced at the database layer. TLS 1.2 or higher in transit and encryption at rest. Least-privilege access with an audit trail of security-relevant events. Our SOC 2 and ISO/IEC 42001 programs are underway; our controls and roadmap are available in detail under NDA.

07

Subprocessors and international transfers

We use a short, deliberate list of infrastructure providers, each engaged under data-protection terms. Because they process data in the United States, information may be transferred outside your jurisdiction; we rely on contractual safeguards for those transfers.

ProviderPurposeRegion
SupabasePostgres database and document storageCanada (ca-central-1)
VercelApplication hosting and AI gatewayUnited States (application compute region: Montréal, Canada)
ClerkAuthentication and organization managementUnited States
AnthropicAI model inference, via Vercel AI Gateway, zero retentionUnited States
Moonshot AIAI model inference (Kimi), via Vercel AI Gateway, zero retentionUnited States
OpenAIText embeddings for search and matching, via Vercel AI Gateway, zero retentionUnited States
ResendTransactional and inbound emailUnited States
SentryServer error monitoringUnited States
UpstashRate limiting (request metadata only)United States
08

Your rights

Subject to applicable law (including PIPEDA in Canada and, where it applies, the GDPR), you may request access to, correction of, deletion of, or a portable copy of your personal information, and you may withdraw consent where processing rests on it. Workspace-level requests are honored through your organization, which controls its workspace. To exercise any right, use the form below or write to hello@mandaplatform.com. We respond within the timelines applicable law requires, and every request is logged and tracked to resolution.

09

Data deletion and other requests

Submit a request here. You will receive a reference id; we verify identity before acting on deletion requests, and the request's full lifecycle is recorded on our audit trail. Workspace administrators can also request deletion of their entire workspace from Settings inside the product.

Logged and tracked to resolution; you receive a reference id.

10

Changes and contact

We will post any changes to this policy here and update the effective date. Material changes affecting customer workspaces are communicated to workspace administrators. Contact: hello@mandaplatform.com.