Manera Knowledge Base · Security & compliance

Loi 25 + GDPR + DPA: how Manera handles your data

Manera Technologies Inc. is a Québec-incorporated company. Our default privacy regime is Quebec's Loi 25 (the Act to modernize legislative provisions as regards the protection of personal information), which is the strictest provincial-level privacy regime in North America and which post-dates the GDPR. Customers from any jurisdiction get Loi 25-grade handling by default. EU customers get GDPR layered on top via our standard DPA.

This article covers what we collect, where it lives, who can access it, and how to exercise your data rights.

TL;DR for procurement diligence

What we collect (and don't)

What we collect

Data categoryPurposeStorageRetention
Email addressAccount auth, transactional emailCloudflare R2 (Canada)Lifetime + 90d post-cancel
Stripe customer IDBillingStripe (PCI DSS Level 1)Lifetime + 7yr (tax)
Workspace name + membersTenant isolationCloudflare R2 (Canada)Lifetime + 90d post-cancel
Petal configuration (e.g. FX pairs you watch)PersonalizationCloudflare R2 (Canada)Lifetime + 90d post-cancel
Synthesis fact-card outputsAudit chain (SHA-256)Cloudflare R2 (Canada)Lifetime + 90d post-cancel
Anonymized usage telemetryProduct improvementCloudflare Analytics90 days rolling

What we do not collect

Where data lives

Default residency: Canada

Optional residency: EU

EU customers can request EU-only residency. Storage flips to Cloudflare R2 eu-west-1 (Frankfurt), backups to eu-north-1 (Stockholm). FX-execution data continues through Wise's EU regulated entity (Wise Europe S.A., Belgium). The shift adds ~50ms of synthesis latency on the first call (subsequent calls cached at edge).

Optional residency: Sovereign

Sovereign Tier customers can request a dedicated tenant with custom residency (e.g. UK only, US only, AWS GovCloud, OVHcloud Sovereign). This is engineered per-customer; minimum quarterly commitment.

Sub-processors

Sub-processorRegionPurposeData shared
Stripe, Inc.GlobalBillingStripe customer ID, email, card last-4
Wise PlcGlobal (EU regulated)FX executionOAuth-scoped FX execution metadata
Anthropic, PBCUSSynthesis layer (Claude API)Fact-card text + synthesis instructions; NEVER customer-financial-data
Cloudflare, Inc.GlobalCDN + WAF + R2 storageAll TLS-terminated traffic; encrypted-at-rest data
MailtrapEUTransactional emailEmail address + transactional content
Anthropic prompt-cacheUS (Anthropic-managed)Performance optimizationCached fact-card snippets, 7-day TTL, customer-isolated

The full sub-processor list is at /trust. New sub-processors are notified 30 days in advance via email and a posted update at /trust/sub-processors.

Loi 25 specifics

Quebec's Loi 25 is the strictest privacy regime in Canada and arguably stricter than GDPR on a few axes. Manera is built for Loi 25 compliance from the ground up:

GDPR specifics

For EU customers, our standard DPA is a Schedule 2 to the Stripe-checkout terms. It covers:

Common procurement questions

Q: Where do I find your DPA? Auto-attached to your Stripe Checkout receipt. Long-form DPA for sovereign customers: email [email protected].

Q: Do you allow data residency in my jurisdiction? Canada (default) and EU available today on the Mesh Tier. UK, US, and custom sovereign residency on Sovereign Tier.

Q: How do you handle a customer subject access request? Self-serve from billing portal: export-all-data button. Returns JSON + CSV in minutes. No founder intervention required.

Q: What is your incident-response time? Within 72 hours of confirmed material breach for notification (Loi 25 Art. 17 + GDPR Art. 33). Internal incident-response runbook tested quarterly.

Q: SOC 2 Type II? In progress. Target Q4 2026. Pre-audit evidence packs available now: email [email protected] with subject "SOC 2 evidence pack".

Q: ISO 27001? On the roadmap for 2027 (after SOC 2 Type II). Not pursuing 27001 ahead of SOC 2 because the buyer overlap is high.

Q: HIPAA / PHI? Manera does not currently process PHI. We are not a HIPAA Business Associate and we do not sign BAAs. If your use case requires PHI handling, the Sovereign Tier with dedicated tenant is the path; engagement scoping required.

Exercising your rights

To exercise any of the rights below, email [email protected]. Most rights are also self-serve from your billing portal.

RightLoi 25 articleGDPR articlePath
Access2715Self-serve export
Rectification2816Workspace settings UI
Erasure28.117Cancel + 90-day window
Portability20Self-serve JSON+CSV export
Object to processing921Email DPO
Withdraw consent97Cancel from billing portal
Lodge complaint5177Commission d'accès à l'information du Québec / your local DPA

Related articles


← Back to knowledge base · Trust · Privacy · Contact DPO

Start 30-day Mesh Tier trialAll KB articles
Manera Technologies Inc. · Knowledge base · Blog · Pricing · Trust Doctrine · Contact