Privacy and your rights
You decide what goes in. We process it on your instructions. How long we keep things, how you get them out, who answers a rights request, and what happens if something goes wrong.
Our role, and yours
For the data your organization puts into Mercleo (your contacts, your donors, your applicants, your staff), you decide what is collected and why, and we process it on your instructions. The distinction matters because it determines who answers when one of those people exercises a right: you decide, we support.
For the information we collect in our own right (our website visitors, account holders, billing contacts), we are the controller, and our privacy policy governs directly.
The data processing agreement
If your organization needs signed data-processing terms before it can proceed, ask us at legal@mercleo.com and tell us what your framework requires. We answer directly.
We do not yet publish a standard DPA as a download. When a counsel-reviewed version exists it will be linked here.
How long we keep things
While your account is active, your data is kept so the Services work. Some operational records expire on shorter clocks that are enforced in the systems themselves, such as analytics event cleanup.
When an account closes, an export remains available for 30 days. After that window we delete the account's data from live systems within a commercially reasonable period, keeping only what law requires us to retain. Copies in encrypted backups age out on the backup schedule rather than being individually purged.
If your diligence needs a line-item retention schedule, ask us. We will answer from what the systems actually do rather than publish a generic table here.
Getting your data out
You can request a complete export of your account's data at any time, not only when leaving. Today we prepare it for you on request rather than offering a self-serve button; the same route covers the 30-day window after termination.
For a young vendor this is also the honest answer to viability risk: your data is available to you, in a usable format, whenever you want it.
Deletion
When an account closes and the export window passes, the account's data is deleted from live systems as described above.
When one individual in your records asks to be removed, that request is yours to decide as controller. We act on your instruction, and deletion reaches live systems; backup copies age out on schedule rather than being rewritten. We do not yet offer a single control that erases one person across every product at once, and we will not claim one until it exists and has been verified end to end.
Individual rights requests
If someone in your records asks you for access, correction, or deletion, the statutory deadline is yours and we help you meet it. Requests that reach us directly at privacy@mercleo.com are passed to you rather than acted on unilaterally, because those decisions are yours to make as controller.
If there is a breach
If a breach affecting your data creates a real risk of significant harm, we notify you without unreasonable delay and tell you what we know. We keep a record of every incident as Canadian law requires, including those below the notification threshold, and we notify the Privacy Commissioner where the law requires it.
Incident response runs on written runbooks rather than improvisation; secret rotation and supply-chain compromise each have one.
The privacy policy itself
The policy governing our own collection of personal information lives at /legal/privacy. This page is about how we handle data on your behalf.
The rest of the trust centre. Everything else a reviewer asks for.
- Where your data livesWhere the infrastructure runs, who runs it, and whose law can reach the data.
- SubprocessorsEvery third party that touches customer data, and what each one sees.
- SecurityTenant isolation, staff access, and the supply chain.
- AI and your dataWhat uses a model, what gets sent, and whether it trains on anything.
- AccessibilityWhat has actually been checked, what has not been assessed, and how to report a barrier.
- ComplianceWhat we hold, what we are working towards, and what we do not have.
- Report a vulnerabilityHow to reach us, what is in scope, and what happens after you do.