MenerFlow legal
Privacy Policy
This Policy explains how Menerai Inc. handles personal information in the supervised British Columbia business pilot, including customer-controlled data, AI and voice-derived text, providers, retention, and privacy requests.
- Version
- 2026-07-27
- Effective
- July 27, 2026
1. Scope and privacy roles
This Policy applies to MenerFlow websites, business workspaces, pilot onboarding, support, billing, security, and related services. The pilot is for British Columbia businesses and is not approved for personal, family, household, children's, regulated, emergency, or international self-service use.
Menerai controls account, contract, billing, tax, security, and service-administration information. For customer-submitted leads, contacts, messages, appointments, estimates, files, and workflow records, the customer generally determines the purpose and Menerai processes the information on documented instructions. Menerai remains responsible for its own processing and safeguards.
2. Information and sources
- Business account and contract information: name, business contact, role, workspace, location, signer authority, order, and legal acceptance evidence.
- Billing and tax information: billing contact, business address, plan, invoice, payment status, tax evidence, refund, and credit status. MenerFlow does not store complete payment-card numbers.
- Customer-controlled records: leads, contacts, messages, appointments, estimates, lifecycle details, tasks, files, and connected-provider data.
- Communication information: sender and recipient, channel, purpose, content, delivery, consent, unsubscribe, suppression, call status, duration, transcript, summary, and extracted details where enabled.
- AI information: prompts, context, drafts, summaries, classifications, output, review, and audit events.
- Technical and support information: IP address, browser/device, session, authentication, request, security/audit log, diagnostic, preference, support, privacy-request, and incident information.
Information comes from authorized users, customers, recipients who communicate with a customer, connected services, payment and identity providers, and the operation and security of MenerFlow. Customers must not submit information that is unnecessary or outside the approved pilot.
3. Purposes
- Provide, configure, secure, troubleshoot, and support the ordered pilot.
- Authenticate users and enforce organization, role, location, and entitlement access.
- Process orders, subscriptions, invoices, tax, payment status, and cancellation.
- Perform customer-instructed communications, integrations, AI assistance, and workflows.
- Record consent, suppression, delivery, human review, and contract evidence.
- Prevent abuse, investigate incidents, answer requests and complaints, and comply with law.
- Improve reliability and usability using minimized, aggregated, or de-identified information where appropriate.
We do not sell personal information for money. We do not use Customer Data for an unrelated advertising purpose.
4. Authority, notice, and consent
Menerai obtains consent or relies on another lawful authority where required for its own processing. Customers must have lawful authority to submit Customer Data, provide required privacy and AI/voice notices, and obtain and preserve channel- and purpose- specific consent before communication. A telephone number or email address alone does not prove consent.
Consent withdrawal or opt-out can limit a feature. We may retain a minimized suppression record so the withdrawal is honoured. We do not use generic Terms acceptance as consent for an unrelated marketing or automated-call purpose.
5. AI and human review
MenerFlow can draft, summarize, categorize, extract structured details, or suggest actions. Output can be wrong and is intended for human review. The pilot does not permit solely automated decisions that materially affect an individual, and AI cannot create consent, release suppression, or authorize an unsupported purpose.
Provider retention, request storage, and model-improvement behavior depend on the actual contract, account, API mode, request, and settings. We do not promise that provider data is never retained or used for improvement until those facts are verified and published for the active deployment. See the AI and Human Review Notice.
6. Calls, live audio, and recording
Call recording is disabled and cannot be enabled by a workspace setting in the current release. A connected voice provider may still process live audio and return call metadata, transcript, summary, or extracted text. Those records are personal information and require notice, minimization, access, retention, and provider controls. Outbound synthesized voice is blocked until its separate legal and technical gates pass.
7. Disclosure and providers
We disclose information only as reasonably necessary:
- to verified providers that host, authenticate, bill, communicate, secure, or support MenerFlow;
- to an integration the customer deliberately connects and instructs us to use;
- within the customer workspace according to authorized roles and locations;
- to approved advisers, auditors, insurers, or a successor in a transaction; or
- where required by law or necessary to protect people, rights, or service integrity.
Source code identifies provider candidates but does not prove the active production list. Production Customer Data remains blocked until the deployment is reconciled and the named register is published. See the Subprocessor Notice.
8. Cross-border processing
Verified service providers may process information in Canada, the United States, or another published region. Information may be subject to the laws and lawful access processes there. Before production activation, Menerai must verify the provider, contracting terms, primary region, onward providers, retention, deletion, security, and AI data-use settings. A customer needing localization or a regulated transfer term must obtain a written review before submitting data.
9. Retention, export, and deletion
The proposed pilot schedule uses different periods by record. Examples include 24 months after last activity for lead/customer and email/SMS content, 12 months for call transcript/summary and AI conversation content, 12 months for routine security logs, 24 months for ordinary support records, relationship plus six years for consent and suppression evidence, six years after closure for privacy/incident evidence, and seven fiscal years for billing/tax/accounting records. Personal information used to make a direct decision about an individual is kept at least one year where BC law requires.
The proposed termination schedule is a 30-day export window, active-system deletion within 30 additional days, and encrypted backup expiry within 35 days after active deletion. Legal holds, disputes, incidents, financial records, suppression, and minimum decision records are separated, restricted, and retained only for their necessary purpose. These periods become a service commitment only after the related controls and providers are verified; paid activation remains blocked until then.
10. Safeguards
Measures designed for the pilot include organization and location scoping, role enforcement, encrypted transport, protected credentials, signed provider callbacks, replay and idempotency controls, audit records, private file quarantine and scan gates, and fail-closed provider and communication decisions where implemented. Exact production encryption, access, backup, retention, and provider settings must be verified. No system guarantees absolute security and Menerai does not claim an unverified certification.
11. Privacy requests and complaints
Subject to applicable law, an individual may request access or correction, withdraw consent, challenge compliance, or ask about deletion. An authorized workspace owner may request customer-data export or deletion. If a customer controls the requested record, we may route the request to that customer while assisting and retaining our case record.
Email admin@meneraihq.com. An authenticated organization owner or manager records the request in MenerFlow's restricted privacy-operations register. The workflow tracks an organization-wide case owner, a 30-day response deadline, one evidenced extension of up to 30 days, identity and authority verification, legal holds, source-system fulfillment evidence, terminal closure, and immutable hashed event history. For a BC PIPA access/correction request, an operator must confirm that any extension is lawful. Do not send identity documents unless requested through an approved secure method.
Recording fulfillment confirms an authorized operator's evidence that the required work was checked and completed in applicable source systems. The case record does not itself automatically export, correct, or erase every MenerFlow store, backup, or provider copy. Those actions must be completed and verified before fulfillment is recorded.
12. Security and privacy incidents
Menerai maintains an incident procedure for containment, evidence, scope, customer assistance, legal assessment, notification decisions, recovery, and corrective action. Where PIPEDA applies, Menerai records every breach of security safeguards for at least 24 months and assesses whether a real risk of significant harm requires reporting and notice. Notification duties depend on the facts and governing law; this Policy does not state that every incident has the same requirement.
13. Necessary cookies and browser storage
The current application uses identity/session, security, routing, and preference storage needed for the requested service, including sidebar and AI workspace preferences. No advertising or non-essential marketing tracker is approved. If an optional tracker is introduced, Menerai must update the data map and provide required notice, choice, and withdrawal before it loads. See the Necessary Cookie and Storage Notice.
14. Excluded users and data
MenerFlow is a business service and is not directed to children or consumer purchases. The pilot is not approved for healthcare, financial-account, government-identifier, employment-screening, criminal-justice, biometric, emergency, or similarly regulated data or use. Contact us before submitting data if scope is uncertain.
15. Versions and changes
This Policy has its own version and effective date. Menerai archives historical versions and will give additional notice of a material change. Where a change requires renewed agreement, affected use remains blocked until unselected acceptance is recorded; a historical acceptance record is not overwritten.
16. Accountability and contact
The accountable Privacy Officer must be named in Menerai's internal founder approval record before launch. The public contact is Privacy Officer, Menerai Inc., admin@meneraihq.com, 1395 Palmerston Avenue, West Vancouver, British Columbia V7T 2H8, Canada. We investigate complaints and respond under applicable law. An individual may also contact the privacy regulator with jurisdiction.