Legal
Data Processing Agreement
When you connect your store, Mano processes personal data belonging to your customers on your behalf. In data-protection terms, you are the controller and Mano is the processor. A Data Processing Agreement is the contract that sets out what we may do with that data, and what we owe you.
Where it stands today
A working-draft DPA exists and is available on request. It is not yet a published standard form, so we are not presenting it as one here. If you need a DPA before connecting a store (which is a reasonable thing to need), ask us and we will send you the current draft and talk you through where it is up to.
We would rather say that than publish a draft as though it were final. The finished standard form is being prepared with our solicitor and will be published on this page.
Request the current draft: security@mano.help
What is already documented
The substance a DPA governs (what we collect, why, where it is stored, how long we keep it, who we share it with, and how to have it erased) is written down and is accurate today:
- Privacy Policy : including retention periods and data-subject rights.
- Sub-processors : every third party that processes data on Mano’s behalf, what each touches, and where it runs. Published at 219sr; `LEGAL_COVERAGE_MAP` row 11 requires a DPA to identify them.
- Security : encryption and access control.