Privacy policy
How Manda handles data.
Effective July 16, 2026 · Manda Technologies, Inc.
Manda provides legal work delivery software for in-house legal teams. This policy explains what we collect, how we use and retain it, and how to exercise your rights, including requesting deletion. Questions and requests reach us at hello@mandaplatform.com.
Who we are, and our role
Manda Technologies, Inc. operates the Manda platform. For the content your organization brings into its workspace (mandates, invoices, documents you choose to attach), we act as a service provider / processor on your organization's instructions. For account information (your name, work email, sign-in records) and for inquiries you send us, we act as a controller.
What we collect
Account and identity. Name, work email, and authentication events, managed through our sign-in provider (Clerk).
Workspace content. The mandate metadata your team creates: the nature of the mandate, pricing, quality reviews, mandates, invoices, and any documents your team chooses to attach. Manda is built on mandate metadata, not your mailbox or document stores: broader access to your systems happens only with explicit, granular permission.
Operational records. An audit trail of security-relevant events (sign-ins, permission changes, deletions) and service telemetry needed to run the product.
What we do not do
We do not sell personal information. We do not use your data to train AI models. AI inference runs with zero data retention and every call is logged with the model used. We do not read your mailbox. We do not serve advertising.
How we use data
To provide and secure the service; to support your team; to meet legal obligations; and, only where your organization has agreed in writing, to derive de-identified data for benchmarking features. De-identified contributions are designed so they cannot be tied back to you, your company, or any unique fact pattern, and can be withdrawn in full at any time.
Retention and deletion
Customer workspace data is retained for the life of the customer relationship and deleted within 30 days of termination under our documented offboarding procedure, which removes the workspace's database records and stored files. The audit trail is append-only and retained for at least one year, including the record that a deletion happened. Your organization can export its mandates and invoices from the product at any time.
Security
Every customer's data is isolated to their organization, enforced at the database layer. TLS 1.2 or higher in transit and encryption at rest. Least-privilege access with an audit trail of security-relevant events. Our SOC 2 and ISO/IEC 42001 programs are underway; our controls and roadmap are available in detail under NDA.
Subprocessors and international transfers
We use a short, deliberate list of infrastructure providers, each engaged under data-protection terms. Because they process data in the United States, information may be transferred outside your jurisdiction; we rely on contractual safeguards for those transfers.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Postgres database and document storage | Canada (ca-central-1) |
| Vercel | Application hosting and AI gateway | United States (application compute region: Montréal, Canada) |
| Clerk | Authentication and organization management | United States |
| Anthropic | AI model inference, via Vercel AI Gateway, zero retention | United States |
| Moonshot AI | AI model inference (Kimi), via Vercel AI Gateway, zero retention | United States |
| OpenAI | Text embeddings for search and matching, via Vercel AI Gateway, zero retention | United States |
| Resend | Transactional and inbound email | United States |
| Sentry | Server error monitoring | United States |
| Upstash | Rate limiting (request metadata only) | United States |
Your rights
Subject to applicable law (including PIPEDA in Canada and, where it applies, the GDPR), you may request access to, correction of, deletion of, or a portable copy of your personal information, and you may withdraw consent where processing rests on it. Workspace-level requests are honored through your organization, which controls its workspace. To exercise any right, use the form below or write to hello@mandaplatform.com. We respond within the timelines applicable law requires, and every request is logged and tracked to resolution.
Data deletion and other requests
Submit a request here. You will receive a reference id; we verify identity before acting on deletion requests, and the request's full lifecycle is recorded on our audit trail. Workspace administrators can also request deletion of their entire workspace from Settings inside the product.
Logged and tracked to resolution; you receive a reference id.
Changes and contact
We will post any changes to this policy here and update the effective date. Material changes affecting customer workspaces are communicated to workspace administrators. Contact: hello@mandaplatform.com.