GDPR Readiness
Learn how Menyo implements GDPR: consent, data rights, retention, processors, and privacy controls.
This page explains how Menyo aligns with the General Data Protection Regulation (GDPR), including how we obtain and record consent, enable data subject rights, manage retention, and work with processors securely.
Controller & Contact
Menyo Technologies Inc. acts as the data controller for the Menyo web application.
Contact: hello@menyo.pro
Consent Management
- We provide a granular consent banner for analytics and marketing categories. Necessary cookies are always enabled to provide the service.
- Your consent choices are stored client-side and can be changed anytime using the “Manage Consent” button above.
- We record consent events in our audit log with pseudonymised IP (truncated+hashed) and trimmed user agent to comply with GDPR Art. 7 requirements.
- Analytics tags (e.g., Google Analytics) are only loaded after you opt in via the consent banner.
See also: Cookie Policy and Privacy Policy.
Your Data Rights
Access & Portability
Download a machine-readable export of your account data from your dashboard.
Download Data ExportErasure (Deletion)
Submit a deletion request from your dashboard. We apply a short verification and grace period before irreversible anonymisation.
Request Account DeletionYou can also contact us at hello@menyo.pro to exercise other rights (rectification, restriction, objection).
Legal Bases for Processing
- Contract: To provide and manage your Menyo account and features.
- Legitimate Interests: To improve product reliability and security (balanced against your rights).
- Consent: For non-essential analytics and marketing technologies.
- Legal Obligations: For records we must retain (e.g., invoices).
Subprocessors & International Transfers
We use a small number of trusted providers to deliver our service. We have agreements and appropriate safeguards in place (e.g., DPAs and, where applicable, SCCs).
- Stripe – payments and invoicing.
- Authentication – account access and sessions.
- Analytics (optional) – aggregated product insights; loaded only after consent.
Data may be processed in the EU and/or US depending on the service. Where data is transferred internationally, we implement appropriate safeguards.
Privacy Policy includes additional details.
Data Retention
We retain personal data only as long as necessary for the purposes outlined above or to satisfy legal obligations. In general:
- Account profile and content: for the life of the account (with a short grace period for recovery).
- Invoices and payment records: retained per applicable law.
- Raw product analytics: limited retention; aggregated metrics kept longer.
- Consent logs: retained for audit for a limited period.
Operational details are maintained internally, including purge scripts and aggregation policies.
Security
We employ modern security practices and limit access to personal data to authorized personnel. Application-level audit trails help us investigate and remediate issues quickly.
Related Policies
If you have questions or concerns about our GDPR approach, please contact us at hello@menyo.pro.