MenerFlow legal
Conditional Subprocessor Notice
Named deployment candidates and the verification required before MenerFlow accepts production Customer Data.
- Version
- 2026-07-27
- Effective
- July 27, 2026
1. Verification status
The application source references the named candidates below. Source does not prove that an account is active, which legal entity contracts with Menerai, where data is processed, which onward providers are used, or what retention and AI data-use settings apply. Production Customer Data remains blocked until an authorized reviewer reconciles the exact deployment, removes inactive candidates, adds every recipient, and approves the dated register.
2. Named deployment candidates
- Railway — candidate application hosting, database/cache, and object storage. Expected data can include Customer Data, metadata, logs, and encrypted secrets. Account, contracting entity, services, regions, backups, access, and deletion are unverified.
- Clerk — candidate identity, session, and organization provider. Expected data can include user profile, business email, organization/role, device, and security information. Account, DPA, region, retention, and identity settings are unverified.
- Stripe — candidate checkout, subscription, invoice, payment, and tax provider. Expected data can include signer/contact, business address, transaction, invoice, tax, and provider-hosted card data. Canadian entity, DPA, tax, retention, and portal configuration are unverified.
- OpenAI — candidate server-side AI provider for drafting, summarization, and classification. Prompt/context and output can contain Customer Data. Account, DPA, request storage, retention, model-improvement setting, access, and region are unverified.
- Twilio — candidate SMS/telephony provider. Expected data can include phone numbers, message/call content and metadata, and consent/suppression events. Account, DPA, region, content retention, number, and messaging configuration are unverified.
- Resend — candidate email provider. Expected data can include email address, sender, content, and delivery metadata. Account, DPA, region, retention, and unsubscribe configuration are unverified.
- ElevenLabs — candidate conversational-voice provider. Expected data can include phone number, live audio, transcript, summary, and call metadata. Account, entity, DPA, region, audio saving, retention/zero-retention, model-improvement, and agent settings are unverified; outbound synthesized voice is blocked.
- Object storage and malware scanner — actual legal entities, if separate from Railway, have not been established from source alone.
3. Official provider information
Provider privacy, DPA, and subprocessor links are maintained in Menerai's official-source register and are checked against the actual account before approval. Provider public documentation describes defaults and options; it does not prove Menerai's configuration.
4. Customer-selected integrations
ServiceTitan, Jobber, and Housecall Pro connectors appear in source. A provider the Customer independently selects and contracts with may be a customer-directed recipient rather than a Menerai-selected subprocessor. The order must identify approved connectors, data direction/fields, account owner, region, credentials, retention, and deletion. A directory listing does not establish production availability.
5. Changes and objections
Once the active register is approved, Menerai will publish its verification date and give versioned notice of a material new Menerai-selected subprocessor before affected processing where practical. A Customer may raise a reasonable data-protection objection. The parties will consider an available alternative; if none is reasonably available, the affected feature may be discontinued.