Legal

Menasa AI Terms of Service

Data Processing Annex · Privacy Policy

Last updated: 27 September 2026

These terms are an agreement between the business that uses Menasa AI and Menasa, with its registered address at AstroLabs, Jumeirah Lakes Towers (JLT), Cluster R, Unit R6, Unit Code RET-R6-100, PO Box 336851, Dubai, United Arab Emirates ("Menasa", "we", "us"). They cover the Menasa dashboard, the Menasa mobile app, the partner portal, the online stores, point of sale, CRM, inbox, campaigns, AI features and developer API we provide (together, "the service"). Our Privacy Policy explains how we handle personal data, and the Data Processing Annex at the end of these terms applies to personal data you put into the service.

Please read them. By creating an account, accepting an invitation to set up a store, or using the service, you accept these terms on behalf of your business.

1. Words we use

  • "You" and "the merchant" mean the business that holds a Menasa account, and the person who accepts these terms for it.
  • "Store" means a merchant's space in the service: its storefront, dashboard, data and settings. One business may have several stores.
  • "Team member" means anyone you invite into a store.
  • "Shopper" or "customer" means your own customers and contacts.
  • "Your content" means everything you or your team put into the service: products, photos, texts, prices, customer and order data, messages, documents and settings.
  • "Plan" means the subscription you choose, as described on our pricing page and in the dashboard.
  • "Third-party service" means any service not operated by Menasa, including payment gateways, couriers, Meta (WhatsApp, Instagram, Messenger), Telegram, Slack, Shopify, WooCommerce, delivery and marketplace apps, Qlub and domain registrars.

2. Who may use Menasa AI

  • The service is for businesses and for people acting for a business. It is not for personal or household use.
  • You must be at least 18 years old and able to enter into a binding contract under the law that applies to you.
  • The person who creates an account or accepts ownership of a store confirms that they are authorised to bind the business, and that business is bound by these terms.
  • You must give us accurate account, business and billing details and keep them up to date.
  • We may refuse or close an account where the law, sanctions rules or a third-party service we rely on does not allow us to serve that business or country.

3. Your account, your team and security

  • You are responsible for everything done through your account and your stores, including by your team members, their roles and anything your AI employees do with your approval.
  • You decide who joins your store and with which role, branches and access end date. The owner and admins of a store always have full access to it; other roles can be narrowed. Remove people who should no longer have access.
  • Keep sign-in details and developer API keys secret. We recommend two-step sign-in for everyone on your team. Tell us at hello@menasa.net without delay if you believe an account or key has been misused.
  • Only the owner of a store can make someone else its owner. If an owner deletes their account, ownership passes as described in section 18.
  • Menasa staff may enter a store to support you, to keep the service secure or to meet a legal obligation. Staff access is limited to what that task needs and is recorded.

4. The service

  • The features available to you depend on your plan, the add-ons you take and what you switch on. What each plan includes is set out on our pricing page and in the dashboard.
  • We improve the service continuously. We may add, change or remove features. If we remove a feature that is a material part of a paid plan you are on, we will tell you in advance and, where you prepaid for it and it is not replaced, give you a fair adjustment in account credit.
  • Plan limits apply. Each plan has limits, for example on team members, products, branches, inbox channels, AI employees and contacts. When a limit is reached, adding more is refused until you change plan or remove something. Some usage is instead charged when it goes over the plan (section 7.5).
  • Beta. Some features and integrations are marked Beta in the dashboard. They are built and tested but have not yet completed a full run with a real merchant account. We will test your first live connection together with you, but Beta features are provided "as is", may change, and may not work as expected. Do not rely on a Beta integration for critical operations until that first run has succeeded.
  • Storefront attribution. Storefronts may show a small "Powered by Menasa" mark unless you have the add-on that removes it.
  • Sample data. A new store may be filled with fictitious sample products, customers and orders so you can see how things work. Sample records are marked as such, are left out of your books and of usage billing, and can be removed from the dashboard. Do not treat sample data as real.
  • Test mode. Menasa's team may switch a store into test mode, for example while setting up a payment gateway. In test mode, checkout uses the gateway's test environment, orders are marked as test orders, no real payment is taken, and test orders are left out of your books and usage billing.

5. Free trial

  • A new store may start with a free trial. Its length and its small allowance of AI replies and campaign emails are shown in the dashboard and may change for new trials. A store set up for you by a partner starts its trial when you accept ownership.
  • During the trial you can use the service without plan limits, but the allowance limits the features that cost money per use.
  • We will remind you before the trial ends. When it ends, the store is suspended until you pay for a plan. Choosing and paying for a plan lifts the suspension.
  • A Store plan includes, once per store, a CRM trial of limited length. When it ends, CRM features that the Store plan does not include are removed after a reminder, unless you move to a plan that includes them.

6. Menasa's plans

We offer three products (Store, CRM and AI, which includes both) in three sizes. Prices, allowances and extras are published on our pricing page and shown in the dashboard before you pay. The prices shown there at the time you pay are the prices that apply; these terms do not state prices because they change.

7. Fees and billing

7.1 Currency. You are billed in your store's currency where we publish a price in it; otherwise in US dollars. Plan and pack prices are whole amounts of their currency, and a discount is rounded to a whole amount as well, so the price you are shown is the price you are charged.

7.2 Monthly and yearly. Plans are billed monthly or yearly, in advance. A yearly plan costs the price shown for the year, which is set at ten months of the monthly price.

7.3 Automatic renewal. Your plan renews automatically at the end of each period at the price that applies then. We raise an invoice at renewal and charge the card you have saved. You authorise us, and our payment provider, to charge that card for invoices you owe.

7.4 Account credit. Any credit on your account is used first on a new invoice; the saved card is charged only for what remains. Credit is not cash and cannot be withdrawn, except where the law requires otherwise.

7.5 Usage beyond your plan. Orders above your plan's monthly allowance, and branches above its limit, are not refused. They are charged on one usage invoice in the following month, at the prices shown in the dashboard. Cancelled, refunded, declined, test, sample and imported orders are not counted.

7.6 Packs and usage limits. You can buy packs of AI replies and campaign emails. Pack credits do not expire and carry over from month to month; AI replies your plan includes each month are added to the same balance and carry over too. To protect you and us from runaway costs, some features that cost money per use (for example voice, document and receipt reading) have monthly limits per store, which Menasa sets and may adjust. When such a limit is reached, that feature stops until the next month or until the limit is raised. We tell your billing team as you approach a limit.

7.7 Founding offer. The first 200 stores to pay for a plan receive 25% off the plan price for as long as they keep a plan (the "founding offer"). A place is counted when a store's first plan invoice is paid. The discount is a percentage of the list price at the time, so if list prices change, a founding store pays 75% of the new price. It continues when you change plan or billing period; it is lost if the subscription stays cancelled for more than 30 days; it does not combine with other offers; and it does not apply to packs, add-ons, domains, usage charges or other extras.

7.8 Add-ons, services and domains. Add-ons, one-off services and domains are charged as shown when you order them.

7.9 Taxes. Fees are stated without taxes unless shown otherwise. Where the law requires us to charge VAT or a similar tax on our fees, we add it to the invoice. You are responsible for any taxes, duties or withholdings that apply to you, and if you must withhold tax you will pay us the extra needed so we receive the full fee.

7.10 Late payment and suspension. If a plan invoice is not paid when due, you have a five-day grace period. During it we will try your saved card again and show a notice in the dashboard. If the invoice is still unpaid after five days, your store is suspended until it is paid; paying lifts the suspension. Invoices for add-ons, usage, packs and one-off services do not suspend your store, but they remain owed and we may stop the related feature or refuse new orders for it until they are paid.

7.11 Refunds. Fees are non-refundable, except where these terms say otherwise or the law requires a refund. If we void an invoice or refund it in full, any account credit used on it is restored.

7.12 Price changes. We may change our prices. For a plan you already have, a new price applies from your next renewal after we have given you at least 30 days' notice, by an announcement in the dashboard and by email. A price decrease applies at once. If you do not accept it, you can stop renewal before it applies (section 7.13). Founding-offer holders keep their discount as defined in section 7.7.

7.13 Changing or stopping your plan. You can change plan from the dashboard. Before you move to a smaller plan, we show you what it would remove (for example AI employees, inbox channels, team invitations, or products beyond the new limit, which are switched off rather than deleted) and ask you to choose what to keep; nothing is removed until the new plan is paid. You can stop renewal at any time: your plan then runs to the end of the period you have paid for and does not renew. There is no pro-rated refund for the unused part of a period, and invoices already raised remain owed.

7.14 Disputes about an invoice. If you believe an invoice is wrong, tell us at hello@menasa.net within 30 days of its date. We will review it in good faith and correct any error with a refund or account credit.

8. Store addresses and domains

  • Every store has an address on a Menasa domain. We may refuse an address that is reserved, misleading or infringes someone's rights, and may change it if it does.
  • Your own domain. You can connect a domain you own. Your plan includes one connected domain; each additional domain has a monthly charge shown before you add it, invoiced with your plan and stopping at the next renewal after you remove it. An additional domain whose first charge stays unpaid may be disconnected. You remain responsible for your domain, its registration and its DNS.
  • Domains bought through Menasa. You can buy a domain in the dashboard. It is registered through Cloudflare Registrar, with Menasa as the registrant, and registration happens only after the invoice is paid. Renewal is never automatic: we send a renewal invoice before the domain expires, and if it is not paid by expiry the domain lapses and may be lost. An unpaid domain invoice does not suspend your store. Domain registration is also subject to the registrar's and the domain registry's rules. If you ask, and all fees you owe Menasa are paid, we will transfer a domain we registered for you to you or to the registrar you choose, under the registrar's and the registry's transfer rules. Any fee the registrar charges for the transfer is yours.
  • We are not responsible for losing a domain because a renewal was not paid, or for decisions of a registrar, registry or DNS provider.

9. You are the seller

Menasa provides software. You are the seller of record for everything sold through your store, point of sale, inbox, payment links and connected apps. We are not a party to your sales. You are solely responsible for:

  • your products and services, their descriptions, photos, quality, safety and legality, and any licence or permit you need to sell them;
  • your prices, currency, discounts, gift cards, loyalty points and promotions;
  • taxes on your sales, including VAT, invoicing and e-invoicing requirements (for example ZATCA in Saudi Arabia, which the service does not currently provide) and your tax filings; our reports are aids, not tax advice;
  • consumer protection law, including the information you must show, your terms of sale, cancellation rights, delivery, returns and refunds to shoppers;
  • your own terms and privacy notice on your storefront and wherever you collect data, and consent for marketing, tracking pixels and call recording;
  • employment and payroll law if you use payroll: the service records pay and applies rules you can review and change, but it does not pay salaries or file anything with any authority, and you must check its results;
  • dealing with shoppers' complaints, chargebacks and disputes.

10. Payments to your store, and third-party services

  • Your own accounts. Payments from your shoppers are taken through payment gateways under your own account with each gateway, and deliveries are booked with couriers under your own account. Menasa does not receive or hold your shoppers' money. Your agreement with each gateway or courier, including its fees, payout times, reserves and refunds, is between you and that provider.
  • Start taking payments with MyFatoorah. If you do not have your own gateway account, you can apply from the dashboard to start taking payments with MyFatoorah. MyFatoorah reviews your application and documents, and takes and settles payments under its own terms and checks. We pass the details you provide to MyFatoorah, and we do not guarantee that it will accept you.
  • Other third-party services. Meta (WhatsApp, Instagram, Messenger), Telegram, Slack, Shopify, WooCommerce, delivery and marketplace apps (such as Deliveroo, Talabat and Trendyol, directly or through Grubtech), Qlub, Google Maps and domain registrars are governed by their own terms and policies, which you must accept and follow. Orders from delivery and marketplace apps are priced and paid on those apps. Qlub calls the service with a key you give it.
  • We are not responsible for third-party services: their availability, changes to their APIs or policies, their fees, their decisions to suspend or close your account, or loss caused by them. A third party may change or withdraw access in a way that stops an integration working; we will try to adapt, but cannot promise to.
  • Credentials. You give us the credentials a connection needs and confirm you are allowed to. We keep them in a secure secrets store, use them only to provide what you asked for, and delete them when you disconnect a payment gateway, courier or Shopify or WooCommerce connection, and in every case when your store is purged.
  • Imports. When you import from Shopify or WooCommerce, we copy the data and images you choose. Check the result; the source platform's data may not map one-to-one.

11. Artificial intelligence

  • Mena and your AI employees act for your store. They can look things up and create internal records such as notes and tasks on their own. Anything that publishes, edits or deletes something, or involves money, is shown to you for approval first. You are responsible for what you approve.
  • Customer-facing assistants that you switch on reply to your shoppers in the inbox without a person approving each reply. You choose whether to switch them on and what they may do, and you are responsible for what they say for you.
  • AI output may be inaccurate, incomplete or out of date. Review it before you rely on it, especially for prices, stock, tax, legal, financial or medical matters. We do not guarantee any particular result from AI features, including sales, replies or savings.
  • AI features consume AI credits from your plan, trial or packs, and stop when the balance is used up.
  • Do not use AI features to mislead people, to impersonate anyone, to produce unlawful content, or to try to make them ignore their instructions or reveal other stores' data.
  • We do not train AI models on your data or your customers' data (see our Privacy Policy).

12. Messaging, campaigns and the inbox

  • You must have your customers' consent, or another lawful basis, before sending them marketing messages by WhatsApp, email or any other channel, and you must honour opt-outs. The service records consents per channel; keeping it accurate is your responsibility.
  • You must follow WhatsApp's Business and Commerce Policies, Meta's terms and the rules of every channel you connect. Meta may restrict or close your WhatsApp or Instagram access; we are not responsible for that.
  • Campaign sending is limited by your plan's allowance and your packs. We may pause a campaign that shows signs of spam or abuse, such as high complaint or bounce rates.
  • WhatsApp calling and call recording are off by default. If you switch recording on, you must tell callers and obtain any consent the law requires.

13. Acceptable use

You and your team must not use the service to:

  • sell, advertise or deliver anything illegal, or anything prohibited or restricted in your country or your shoppers' country without the required licence, including weapons, drugs, counterfeit goods, stolen goods and items that infringe intellectual property;
  • commit fraud, launder money, deceive shoppers or process payments for another business;
  • send spam or unsolicited messages, or buy, scrape or rent contact lists;
  • publish unlawful, defamatory, hateful, obscene or harmful content, or content that exploits children;
  • infringe anyone's intellectual property, privacy or other rights;
  • upload malware, probe, scan or attack the service or other stores, or bypass security, plan limits, usage limits or billing;
  • scrape, copy, reverse engineer, decompile or resell the service, or use it to build a competing product, except where the law expressly allows it;
  • use the developer API beyond its documented limits or with another store's data;
  • abuse AI features as described in section 11.

We may remove content that breaks these rules and act under section 17.

14. Your content and your data

  • You own your content. You give Menasa a worldwide, non-exclusive, royalty-free licence to host, store, copy, display, adapt (for example resize photos or translate text you ask us to) and otherwise process your content only as needed to provide, secure and support the service for you, and to show your storefront to the public. The licence ends when your content is deleted from the service, except for copies kept in backups for the time stated in our Privacy Policy.
  • You confirm you have the rights and consents needed for your content and for us to process it as described.
  • Personal data. For your shoppers', contacts' and employees' personal data, you are the controller and Menasa is your processor, under the Data Processing Annex below. For data about you and your team, Menasa is the controller, as our Privacy Policy explains.
  • Product photos and similar storefront images are publicly accessible by design.
  • We may use aggregated information that does not identify you, your store or any person to run and improve the service.

15. Menasa's rights

  • The service, its software, designs, themes, templates, texts, AI instructions and the Menasa and Mena names and marks belong to Menasa or its licensors. We give you a limited, non-exclusive, non-transferable right to use the service during your subscription under these terms. No other right is granted.
  • Developer API. Your plan includes access to the developer API at the level it states. API keys belong to your store and must be kept secret; we may limit or revoke a key that is misused or endangers the service.
  • If you send us suggestions or feedback, we may use them without obligation to you.

16. Partners

Some stores are set up or managed by Menasa partners (resellers). A partner is an independent business, not Menasa's agent, and cannot change these terms or bind Menasa. Any arrangement between you and a partner, including their fees and services, is between you and them. A partner has access to a store only as you allow. These terms still apply to your store, and Menasa is not responsible for a partner's acts or omissions.

17. Suspension by Menasa

We may suspend all or part of your access, a store, a storefront, a feature or an integration:

  • for non-payment, as described in section 7.10 and at the end of a trial;
  • if you breach these terms, in particular sections 9, 12 or 13;
  • if needed to prevent fraud, harm to shoppers or others, a security risk, or damage to the service or other merchants;
  • if a law, court, authority or third-party service we rely on requires it.

Where it is reasonable, we will tell you first and give you a chance to fix the problem. We will lift the suspension once the reason is resolved. Fees for the period of a suspension caused by you remain payable.

18. Ending the agreement, and your data

  • You can stop renewal at any time (section 7.13), and can delete your account from Settings › Sign-in security.
  • Account deletion. If you are not the owner, you leave the store. If you own a store with a team, ownership passes to the next most senior member. If you are the only person in a store, the store is cancelled, its subscription ends, and it is permanently purged after 30 days; until then it can be restored by contacting us.
  • We may end this agreement or close a store: for a serious or repeated breach of these terms; if a store stays suspended for non-payment for more than 90 days; or with at least 30 days' notice for any other reason, in which case we will refund any prepaid fees for the unused period.
  • Getting your data out. While your store is active, you can export your data using the tools in the dashboard (for example customer and contact exports). After your store is cancelled or closed, you can ask us within the 30-day window to restore access so you can export it, unless we closed the store for fraud or unlawful use, or the law forbids it. After purge, we cannot recover your data, except that copies may remain in backups for up to about 14 weeks until they are overwritten, and Menasa keeps its own invoices as the law requires.
  • Sections that by their nature should survive the end of this agreement survive it, including those on fees owed, your content, liability, indemnity and governing law.

19. No warranty

The service is provided "as is" and "as available". To the fullest extent the law allows, Menasa makes no warranties, express or implied, including of merchantability, fitness for a particular purpose, non-infringement, accuracy of AI output or results, or that the service will be uninterrupted, error-free or secure against every threat. We do not offer an uptime or service-level commitment unless we agree one with you separately in writing. Nothing in these terms excludes a warranty that the law does not allow to be excluded.

20. Limitation of liability

To the fullest extent the law allows:

  • Menasa is not liable for any indirect, incidental, special, consequential or punitive loss, or for loss of profits, revenue, sales, goodwill, business opportunity or data, however caused, even if we were told it was possible.
  • Menasa's total liability for all claims arising out of or relating to these terms or the service is limited to the fees you paid Menasa for the service in the three (3) months before the event giving rise to the claim.
  • These limits do not apply to liability that cannot be limited by law, such as liability for fraud or wilful misconduct, or to your obligation to pay fees and your indemnity under section 21.

21. Your indemnity

You will defend and indemnify Menasa, its staff and partners against claims, fines, losses and reasonable costs (including legal fees) arising from: your products and services and your sales to shoppers; your content; your breach of these terms or of the law (including consumer protection, tax, marketing and data protection law); your use of third-party services; and anything your team members or AI employees do in your store with your approval or under settings you chose. We will tell you promptly of a claim, let you control its defence, and cooperate reasonably at your cost; you may not settle a claim that admits fault on our part without our consent.

22. Changes to these terms

We may update these terms at any time. The updated version is posted here with its date and applies from that date. Continuing to use the service after an update means you accept the updated terms. If you do not agree, stop renewal or close your account.

23. Events beyond our control

Neither party is liable for a delay or failure caused by events beyond its reasonable control, such as natural disasters, war, unrest, government action, power or internet failures, outages of cloud or third-party providers, or attacks on the service. This does not excuse paying fees that are due.

24. General

  • Assignment. You may not transfer this agreement without our written consent. We may transfer it to a company in our group or to a successor to our business, and will tell you if we do.
  • Entire agreement. These terms, the Data Processing Annex, the Privacy Policy and the prices and plan details shown when you pay are the whole agreement between you and Menasa about the service. If there is a conflict, these terms prevail, except that the Annex prevails on the processing of personal data. A written agreement signed by both parties prevails over these terms where it says so.
  • Severability. If any part of these terms is found unenforceable, the rest remains in force, and that part is applied as far as the law allows.
  • No waiver. Not enforcing a right is not a waiver of it.
  • Independent parties. Nothing here creates a partnership, agency or employment relationship.
  • Notices. We send notices to your account email or in the dashboard. You send notices to legal@menasa.net.

25. Governing law and disputes

These terms are governed by the laws of the United Arab Emirates. Before going to court, both parties will try in good faith to resolve a dispute by discussion for 30 days after one party notifies the other. Disputes that are not resolved are subject to the exclusive jurisdiction of the courts of the United Arab Emirates, without prejudice to mandatory rights the law of your country gives you.

26. Language and contact

These terms are published in English and Arabic. If the English and Arabic versions differ, the English version prevails.

Questions about these terms: legal@menasa.net.

Annex

Data Processing Annex

Annex to the Menasa AI Terms of Service. Last updated: 27 September 2026

This annex applies when Menasa processes personal data on a merchant's behalf in providing Menasa AI. It forms part of the Terms of Service and is read together with our Privacy Policy. Where it conflicts with the Terms on the processing of personal data, this annex prevails.

1. Roles

  • The merchant is the controller of the personal data it puts into the service or collects through it: its shoppers, customers, contacts, conversation participants, and employees (the "merchant data").
  • Menasa is the processor of the merchant data. Menasa is the provider named in the Terms: Menasa, AstroLabs, Jumeirah Lakes Towers (JLT), Cluster R, Unit R6, Unit Code RET-R6-100, PO Box 336851, Dubai, United Arab Emirates.
  • Data about the merchant, its team and partners is outside this annex: Menasa is its controller, as the Privacy Policy explains.

2. What is processed

  • Subjects: the merchant's shoppers and customers, CRM contacts, people who message the merchant on its connected channels, and, if payroll is used, the merchant's employees.
  • Data: as listed in section 4 of the Privacy Policy, for example names, phone numbers, emails, addresses and map locations, orders, returns, loyalty and gift card records, bookings, conversations and attachments, marketing consents, call records and (only if the merchant turns recording on) recordings and transcripts, and payroll records.
  • Purpose and duration: only to provide, secure and support the service for the merchant, for as long as the merchant uses the service and then as described in section 11.
  • The merchant should not put special categories of data (for example health data) into the service unless it needs to and has a lawful basis to do so.

3. Menasa's instructions

Menasa processes merchant data only on the merchant's documented instructions. The Terms, this annex, and the merchant's use and configuration of the service (the features and integrations it switches on, the settings it chooses, and the actions it or its AI employees take with its approval) are those instructions. Menasa may also process merchant data where the law requires it; if so, it will tell the merchant first unless the law forbids that. If Menasa believes an instruction breaks the law, it will tell the merchant and may decline to follow it.

Menasa does not sell merchant data, does not use one merchant's data for another merchant or for its own marketing, and does not train AI models on it.

4. The merchant's responsibilities

The merchant is responsible for having a lawful basis for the merchant data, for its own privacy notice to its customers, for obtaining any consent the law requires (including for marketing, tracking pixels and call recording), and for the lawfulness of its instructions.

5. Confidentiality

Menasa ensures that its staff and contractors who can access merchant data are bound by confidentiality, and that they access it only when needed to provide, secure or support the service, or when the merchant asks for help. Menasa staff access to stores requires two-step sign-in and is recorded.

6. Security

Menasa applies technical and organisational measures appropriate to the risk, as described in section 12 of the Privacy Policy, including encrypted connections, encryption at rest by its cloud provider, separation between stores that is tested regularly, role- and branch-based access for store teams, credentials held in a secrets store rather than in the database, private storage for sensitive files, and audit logs. The merchant is responsible for the security of its own accounts, devices and team access. No system is perfectly secure, and Menasa does not claim any security certification.

7. Sub-processors

The merchant authorises Menasa to use the sub-processors listed in section 7 of the Privacy Policy. Menasa binds each of them to data protection obligations appropriate to the service it provides, and remains responsible to the merchant for their performance of those obligations. Menasa will update that list before adding or replacing a sub-processor and tell merchants of material changes by email or in the dashboard. A merchant that objects on reasonable data-protection grounds may tell us at privacy@menasa.net; if we cannot address the objection, the merchant may stop using the affected feature or end the Terms.

Services the merchant chooses to connect (payment gateways, couriers, Meta, Telegram, Slack, Shopify, WooCommerce, delivery and marketplace apps, Qlub and others) are not Menasa's sub-processors. The merchant instructs Menasa to send them the data they need, and they process it under their own terms with the merchant.

8. International transfers

Merchant data is stored mainly in Google Cloud's Doha region, and some processing takes place in other countries, as section 8 of the Privacy Policy describes (including the European Union and, for AI requests, countries such as the United States). The merchant authorises these transfers. Where the applicable law requires it, Menasa relies on the transfer mechanisms that law allows, such as contractual safeguards with its providers, and transfers only what the service needs.

9. Helping the merchant

  • Rights requests. The service lets the merchant find, export (as a file) and erase a contact's data. Where a request cannot be handled with those tools, Menasa will give reasonable help when the merchant asks. If a person contacts Menasa directly about merchant data, Menasa will pass the request to the merchant and will not answer it itself unless the merchant asks or the law requires.
  • Assessments and authorities. Menasa will give reasonable information the merchant needs for a data protection impact assessment or to answer a data protection authority about the service.

10. Personal data breaches

If Menasa becomes aware of a breach of security that leads to accidental or unlawful destruction, loss, alteration, disclosure of, or access to merchant data, it will notify the merchant without undue delay, and give the information it reasonably has about the nature of the breach, the data and people affected, the likely consequences and the measures taken or proposed. Menasa will take reasonable steps to contain the breach and will cooperate with the merchant on notifications the merchant must make. Telling the merchant about a breach is not an admission of fault.

11. Deletion at the end

When a store is deleted or closed, its merchant data is permanently purged 30 days later, including its files, stored credentials and search records. Before that, the merchant can export its data with the tools in the dashboard, or ask Menasa to restore access to do so within that window. Copies in backups are overwritten within about 14 weeks. Menasa keeps merchant data beyond that only where the law requires it.

12. Information and review

Menasa will answer a merchant's reasonable written questions about its compliance with this annex, and provide the relevant written information it holds, no more than once a year unless a breach or an authority requires more. This does not include on-site audits, access to other merchants' data, or information whose disclosure would compromise security or confidentiality.

13. Liability

The limits of liability in the Terms of Service apply to this annex.