MenerFlow legal
Data Processing Addendum
Customer and Menerai responsibilities when Menerai processes Customer Data for the supervised MenerFlow pilot.
- Version
- 2026-07-27
- Effective
- July 27, 2026
1. Scope, definitions, and roles
This Addendum forms part of the agreement between the British Columbia business identified in an accepted MenerFlow order (“Customer”) and Menerai Inc. It applies when Menerai processes personal information in Customer Data to provide the ordered pilot. “Process” and related terms have the meaning given by applicable privacy law.
Customer generally determines the business purpose for its leads, contacts, messages, appointments, estimates, files, and workflows. Menerai acts on Customer's documented instructions for that data. Menerai independently determines purposes for account, contract, billing, tax, security, fraud-prevention, and service-administration information.
2. Subject matter and duration
Processing covers hosting, access, organization, communication, integration, AI assistance, scheduling, recovery, analytics, support, security, export, and deletion for the features written in the order. It lasts for the agreement term plus the approved export, deletion, backup, evidence, and legal-hold periods.
3. People and data
Data subjects can include Customer owners, staff, users, leads, customers, prospects, communication recipients, callers, service contacts, signers, and support requesters. Data can include business contact and account details, messages, call metadata and post-call text, appointments, estimates, lifecycle records, files, consent and suppression evidence, AI prompt/output and review records, device/session information, audit/security logs, support information, and billing status.
The pilot excludes healthcare, financial-account, government-identifier, employment- screening, criminal-justice, children's, biometric, emergency, and similarly regulated data unless a separate written review expressly approves it.
4. Documented instructions
The Terms, completed order, Customer configuration, and authenticated authorized support requests are Customer's instructions. Menerai processes Customer Data only to provide, secure, maintain, and support the service, prevent abuse, comply with law, and carry out those instructions. Menerai will notify Customer if an instruction appears unlawful or outside the approved scope and may pause it.
5. Customer responsibilities
- Establish lawful collection authority and compatible processing purposes.
- Provide required privacy, communications, AI, and voice notices.
- Obtain and preserve required consent and honour withdrawal and suppression.
- Submit only necessary, accurate, approved data.
- Configure users, roles, locations, providers, channels, and retention lawfully.
- Answer data-subject requests for Customer-controlled data, with Menerai assistance.
6. Confidentiality and access
Menerai limits Customer Data access to personnel and approved providers who need it for their duties and are subject to appropriate confidentiality obligations. Access follows least privilege, role and tenant scope, and audit controls appropriate to the service. Customer controls its authorized users and must promptly remove unnecessary access.
7. Security measures
Measures designed for the pilot include encrypted transport, organization and location scoping, role enforcement, protected credentials, signed provider callbacks, replay and idempotency controls, audit records, private file quarantine and scan gates, and fail-closed provider and communication decisions where implemented. Exact production access, encryption, backup, restore, deletion, and provider settings must be verified before activation. Menerai does not claim an unverified certification.
Additional detail appears in the Security and Technical Measures Addendum incorporated into the completed pilot order.
8. Subprocessors
Customer gives general authorization for the Menerai-selected subprocessors in the verified active register. The current public register is conditional and production processing is blocked until the exact deployment, contracting entity, service, region, data, retention, deletion, security, and onward-provider state is approved.
Menerai will update the versioned register and provide notice of a material new subprocessor before it begins affected processing where practical. Customer may raise a reasonable written data-protection objection. The parties will consider an available alternative; if none is reasonably available, the affected feature may be discontinued.
9. Customer-selected services
A provider Customer deliberately connects under its own account is a separate recipient of data needed for the instructed workflow. Customer is responsible for that provider relationship and configuration. Menerai remains responsible for transmitting only the authorized data through the implemented connection and for accurately describing the boundary.
10. Cross-border processing
Verified providers may process data in Canada, the United States, or another published region. Information may be subject to local law and lawful access. Menerai will use provider terms and safeguards appropriate to the verified service. A data-residency, localization, regulated-industry, or special transfer requirement must be reviewed and written in an order before affected data is submitted.
11. Individual requests
Taking account of the nature of processing, Menerai will reasonably assist Customer with access, correction, export, deletion, consent withdrawal, complaint, and related requests. Menerai may route a direct request about Customer-controlled data to Customer while keeping a restricted case record and meeting its own legal duties. Customer must respond promptly to verification and instruction requests.
12. Incidents
Menerai will notify the affected Customer without unreasonable delay after confirming a security incident involving Customer Data and will provide available information reasonably needed for Customer's assessment and response, subject to security, privilege, law-enforcement restriction, and other customers' rights. Notice is not an admission of fault. Menerai will preserve the incident record required by applicable law.
13. Return and deletion
On termination or an authorized request, Menerai will provide the approved export and deletion process in the Retention and Deletion Policy. Financial, suppression, decision-record, incident, dispute, and legal-hold information may be separated and restricted for its necessary period. Backup copies expire on the approved rotation and are not restored to ordinary use without replaying deletion records.
14. Information and review rights
On reasonable written request, Menerai will provide information reasonably necessary to assess its processing and safeguards. A negotiated audit must protect security, privilege, provider confidentiality, and other customers, avoid unreasonable production disruption, and use existing independent or technical evidence first where appropriate. No certification or audit report is promised unless it exists and is approved for disclosure.
15. Legal requests and precedence
If Menerai receives a legally binding request for Customer Data, it will notify Customer where law permits, review scope, disclose only what is required, and record the response. This Addendum controls over conflicting general Terms for Customer Data processing. The completed order controls approved commercial and implementation scope. A signed amendment controls only where it expressly identifies the change.