Privacy and your rights

You decide what goes in. We process it on your instructions. How long we keep things, how you get them out, who answers a rights request, and what happens if something goes wrong.

Our role, and yours

For the data your organization puts into Mercleo (your contacts, your donors, your applicants, your staff), you decide what is collected and why, and we process it on your instructions. The distinction matters because it determines who answers when one of those people exercises a right: you decide, we support.

For the information we collect in our own right (our website visitors, account holders, billing contacts), we are the controller, and our privacy policy governs directly.

The data processing agreement

If your organization needs signed data-processing terms before it can proceed, ask us at legal@mercleo.com and tell us what your framework requires. We answer directly.

We do not yet publish a standard DPA as a download. When a counsel-reviewed version exists it will be linked here.

How long we keep things

While your account is active, your data is kept so the Services work. Some operational records expire on shorter clocks that are enforced in the systems themselves, such as analytics event cleanup.

When an account closes, an export remains available for 30 days. After that window we delete the account's data from live systems within a commercially reasonable period, keeping only what law requires us to retain. Copies in encrypted backups age out on the backup schedule rather than being individually purged.

If your diligence needs a line-item retention schedule, ask us. We will answer from what the systems actually do rather than publish a generic table here.

Getting your data out

You can request a complete export of your account's data at any time, not only when leaving. Today we prepare it for you on request rather than offering a self-serve button; the same route covers the 30-day window after termination.

For a young vendor this is also the honest answer to viability risk: your data is available to you, in a usable format, whenever you want it.

Deletion

When an account closes and the export window passes, the account's data is deleted from live systems as described above.

When one individual in your records asks to be removed, that request is yours to decide as controller. We act on your instruction, and deletion reaches live systems; backup copies age out on schedule rather than being rewritten. We do not yet offer a single control that erases one person across every product at once, and we will not claim one until it exists and has been verified end to end.

Individual rights requests

If someone in your records asks you for access, correction, or deletion, the statutory deadline is yours and we help you meet it. Requests that reach us directly at privacy@mercleo.com are passed to you rather than acted on unilaterally, because those decisions are yours to make as controller.

If there is a breach

If a breach affecting your data creates a real risk of significant harm, we notify you without unreasonable delay and tell you what we know. We keep a record of every incident as Canadian law requires, including those below the notification threshold, and we notify the Privacy Commissioner where the law requires it.

Incident response runs on written runbooks rather than improvisation; secret rotation and supply-chain compromise each have one.

The privacy policy itself

The policy governing our own collection of personal information lives at /legal/privacy. This page is about how we handle data on your behalf.

The rest of the trust centre. Everything else a reviewer asks for.

Need a DPA to move forward? Ask us and we will get it to you.