Menira Logo Menira
Sign in

Privacy Policy

The controller within the meaning of the data protection laws, in particular the Swiss Data Protection Act (FADP), is:

Joël Noack
Alte Strasse 59
3778 Schönried
Switzerland

E-mail: ​

General note

Based on Article 13 of the Swiss Federal Constitution and the federal data protection provisions (Data Protection Act, DPA), everyone is entitled to protection of their privacy and to protection against misuse of their personal data. As the operator of Menira, we take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

Nature of the data processed

Within the scope of using our SaaS application Menira, the following data is processed:

  • Account data (e-mail address, name, encrypted password)
  • Tenant data (company name, address, logo)
  • Project data (Gantt charts, tasks, deadlines, dependencies)
  • Address data (companies, contact persons, recorded on behalf of the tenant)
  • Server log files (IP address, browser, time of access)
  • Session data (authentication tokens, language setting)

Purpose of data processing

We process the data mentioned for the following purposes:

  • Provision and operation of the SaaS application Menira
  • User management and authentication
  • Tenant management and isolation
  • Creation and export of Gantt charts (PDF)
  • Technical maintenance and security of the service
  • Communication (e-mail notifications, invitations, password reset)

Legal basis (Art. 6 DPA)

The processing of your data is based on the following legal bases:

  • Contract performance: your data is processed in order to provide you with the agreed service (Art. 6 para. 1 DPA).
  • Legitimate interest: server log files are processed to ensure IT security and for error resolution.
  • Consent: insofar as you have separately given us your consent, we process your data to the extent specified in each case.

Cloud hosting and data processing

Menira is operated on a dedicated server located in Switzerland (Zurich). Live data is stored there in a PostgreSQL database. For disaster recovery, client-side encrypted backups are stored with a processor in the European Union (Cloudflare R2, EU region); the provider has no access to the plaintext of your data at any time. The connection between your browser and our servers is encrypted end-to-end with TLS.

Passwords are stored exclusively as cryptographic hashes (bcrypt) and are not viewable by us in plain text.

We use the following processors:

  • Exoscale (Akenes SA), Switzerland: operation of the server located in Zurich (zone ch-dk-2). This covers all data stored in Menira.
  • Cloudflare, Inc. (Cloudflare R2), EU region: storage of backup copies. Backups are encrypted client-side and cannot be decrypted by the processor.
  • Infomaniak Network SA, Switzerland: delivery of system emails (invitations, password resets, notifications). This covers the recipient address and the content of the respective message.
  • SIA Monkey See Monkey Do (healthchecks.io), EU: Monitoring of operational readiness (the absence of scheduled technical signals triggers an alert). Only technical status values are transmitted (e.g. storage utilisation, number of restored records) – no customer data and no personal data.
  • Grafana Labs (Grafana Cloud), Switzerland: Off-host storage of technical operational logs (Zurich region). Only logs already stripped of access credentials and personal data are transmitted; IP addresses appear solely as a constant hash value.

All processors are contractually bound to comply with data protection law and process the data solely on our instructions. No data is passed on for advertising or analytics purposes.

Retention period (three-stage deletion model)

We retain personal data only for as long as is necessary for the purpose of processing or required by statutory retention obligations (in particular Art. 958f CO). After deletion of your account or an entry, data is processed in three stages:

  • Stage 1 – Recycle bin (0 to 30 days): deleted entries are marked as "soft-deleted", not visible to other users, but restorable by the system administrator. This phase prevents accidental data loss.
  • Stage 2 – Anonymisation (after 30 days): personal fields of users, tenants, companies and contacts (name, e-mail, phone, address, password hash, 2FA secret, notes) are irreversibly replaced with placeholders. Accounting-relevant references (audit log, invoices, subscription history) are retained in anonymised form in order to fulfil the statutory accountability and retention obligation.
  • Stage 3 – Final deletion (after 10 years): audit logs, invoices and already anonymised data sets are completely removed from the database (Art. 958f CO retention period expired).

Server log files are retained for a maximum of 90 days and then deleted automatically.

Rights of data subjects

Within the scope of the applicable statutory provisions, you have the following rights at any time:

  • Right of access: you can request information about the personal data we store about you.
  • Right to rectification: you can request the correction of inaccurate data.
  • Right to erasure: you can request the deletion of your data, provided that no statutory retention obligation exists.
  • Data portability: you can request the export of your data in a common format.
  • Right to object: you can object to the processing of your data.

To exercise these rights, please contact: ​

You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

Cookies and session data

Menira uses exclusively technically necessary cookies:

  • Session cookie: for authentication and maintaining your session (HttpOnly, Secure).
  • Language cookie: for storing your preferred language.
  • Theme setting: stored in localStorage (light/dark mode).

No tracking cookies, analytics tools or third-party services are used. No tracking takes place.

Disclosure of data to third parties

Your data is not passed on to third parties for advertising or analytics purposes. The application is hosted on a dedicated server located in Switzerland. Beyond the processors named in section 5, data is transmitted only where strictly necessary to fulfil statutory obligations.

TLS encryption

This application uses TLS encryption to protect all transmitted data. You can recognise an encrypted connection by the padlock symbol in your browser bar and the "https://" protocol.

Changes

We may adjust this privacy policy at any time without prior notice. The current version published on our application applies.

Last updated: April 2026

ContactPrivacy PolicyLegal NoticeTerms
© 2026 Menira·Made in Switzerlandv4.3.8