Menira Logo Menira
Sign in

Privacy Policy

The controller within the meaning of the data protection laws, in particular the Swiss Data Protection Act (FADP), is:

Joël Noack
Alte Strasse 59
3778 Schönried
Switzerland

E-mail: ​

General note

Based on Article 13 of the Swiss Federal Constitution and the federal data protection provisions (Data Protection Act, DPA), everyone is entitled to protection of their privacy and to protection against misuse of their personal data. As the operator of Menira, we take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

Nature of the data processed

Within the scope of using our SaaS application Menira, the following data is processed:

  • Account data (e-mail address, name, encrypted password)
  • Tenant data (company name, address, logo)
  • Project data (Gantt charts, tasks, deadlines, dependencies)
  • Address data (companies, contact persons) entered by a customer in their address book – see section 9 regarding our role for this data
  • Server log files (IP address, browser, time of access)
  • Session data (authentication tokens, language setting)
  • Contact details from publicly accessible sources (telephone number, role, company address of your business, where publicly published)

Purpose of data processing

We process the data mentioned for the following purposes:

  • Provision and operation of the SaaS application Menira
  • User management and authentication
  • Tenant management and isolation
  • Creation and export of Gantt charts (PDF)
  • Technical maintenance and security of the service
  • Communication (e-mail notifications, invitations, password reset)
  • Personal enquiry about your user experience (one-off contact by e-mail, by telephone if you wish)

Legal basis (Art. 6 DPA)

The processing of your data is based on the following legal bases:

  • Contract performance: your data is processed in order to provide you with the agreed service (Art. 6 para. 1 DPA).
  • Legitimate interest: server log files are processed to ensure IT security and for error resolution.
  • Consent: insofar as you have separately given us your consent, we process your data to the extent specified in each case.
  • Legitimate interest (product improvement): if you have opened a user account, we contact you once by e-mail at the address given during registration to ask about your experience with Menira. A telephone call only takes place if you offer or agree to it beforehand; the telephone number required is then taken from publicly accessible sources (e.g. your company's website). You may object to this contact at any time and without formality; without a reply from you, no further enquiry is made.

Cloud hosting and data processing

Menira is operated on a dedicated server located in Switzerland (Zurich). Live data is stored there in a PostgreSQL database. For disaster recovery, client-side encrypted backups are stored with a processor in the European Union (Cloudflare R2, EU region); the provider has no access to the plaintext of your data at any time. The connection between your browser and our servers is encrypted end-to-end with TLS.

Passwords are stored exclusively as cryptographic hashes (bcrypt) and are not viewable by us in plain text.

We use the following processors:

  • Exoscale (Akenes SA), Switzerland: operation of the server located in Zurich (zone ch-dk-2). This covers all data stored in Menira.
  • Cloudflare, Inc. (Cloudflare R2), EU region: storage of backup copies. Backups are encrypted client-side and cannot be decrypted by the processor.
  • Infomaniak Network SA, Switzerland: delivery of system emails (invitations, password resets, notifications). This covers the recipient address and the content of the respective message.
  • SIA Monkey See Monkey Do (healthchecks.io), EU: Monitoring of operational readiness (the absence of scheduled technical signals triggers an alert). Only technical status values are transmitted (e.g. storage utilisation, number of restored records) – no customer data and no personal data.
  • Grafana Labs (Grafana Cloud), Switzerland: Off-host storage of technical operational logs (Zurich region). Only logs already stripped of access credentials and personal data are transmitted; IP addresses appear solely as a constant hash value.
  • Stripe (Stripe Payments Europe Ltd., Ireland; Stripe, Inc., USA): handling of subscription and payment. This covers the billing email address and the company name of the tenant, as well as the payment details you enter directly on the payment page operated by Stripe. Card details never reach our servers. Processing takes place in the EU and the USA; it is necessary for the performance of the contract and is safeguarded by the Swiss-U.S. Data Privacy Framework and standard contractual clauses.

The processors are bound to comply with data protection law and process the data solely on instruction. The basis for this are the respective providers' data processing agreements, which become part of the contract upon its conclusion; there are no individually negotiated contracts. No data is passed on for advertising or analytics purposes.

On request, we provide interested parties and customers with the complete documentation on commissioned processing: the list of processors, the technical and organisational measures, and a template of the data processing agreement. A message to the address above is sufficient.

Retention period (three-stage deletion model)

We retain personal data only for as long as is necessary for the purpose of processing or required by statutory retention obligations (in particular Art. 958f CO). After deletion of your account or an entry, data is processed in three stages:

  • Stage 1 – Recycle bin (0 to 30 days): deleted entries are marked as "soft-deleted", not visible to other users, but restorable by the system administrator. This phase prevents accidental data loss.
  • Stage 2 – Anonymisation (after 30 days): personal fields of users, tenants, companies and contacts (name, e-mail, phone, address, password hash, 2FA secret, notes) are irreversibly replaced with placeholders. Accounting-relevant references (audit log, invoices, subscription history) are retained in anonymised form in order to fulfil the statutory accountability and retention obligation.
  • Stage 3 – Final deletion (after 10 years): audit logs, invoices and already anonymised data sets are completely removed from the database (Art. 958f CO retention period expired).

Server log files are retained for a maximum of 90 days and then deleted automatically.

Rights of data subjects

Within the scope of the applicable statutory provisions, you have the following rights at any time:

  • Right of access: you can request information about the personal data we store about you.
  • Right to rectification: you can request the correction of inaccurate data.
  • Right to erasure: you can request the deletion of your data, provided that no statutory retention obligation exists.
  • Data portability: you can request the export of your data in a common format.
  • Right to object: you can object to the processing of your data.
  • Information about the origin: insofar as we did not obtain data about you directly from you, we will tell you on request what information is available about its origin (Art. 25(2)(e) FADP).

To exercise these rights, please contact: ​

Providing this information is free of charge for you and is generally done within 30 days (Art. 25(6) and (7) FADP). The same applies to handing over your data in a common electronic format (Art. 28 FADP).

You also have the right to lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC).

Cookies and session data

Menira uses exclusively technically necessary cookies:

  • Session cookie: for authentication and maintaining your session (HttpOnly, Secure).
  • Language cookie: for storing your preferred language.
  • Theme setting: stored in localStorage (light/dark mode).

No tracking cookies, analytics tools or third-party services are used. No tracking takes place.

Disclosure of data to third parties

Your data is not passed on to third parties for advertising or analytics purposes. The application is hosted on a dedicated server located in Switzerland. Beyond the processors named in section 5, data is transmitted only where strictly necessary to fulfil statutory obligations.

A special case applies to the address data our customers enter in their address book (for example contact persons at companies they work with). The respective customer alone decides about this data as the controller; we process it solely on their behalf and on their instructions. If you are such a contact person and wish to request information, rectification or deletion, please contact the company that entered your data. If you cannot reach them, we will forward your request to the relevant customer if you wish.

TLS encryption

This application uses TLS encryption to protect all transmitted data. You can recognise an encrypted connection by the padlock symbol in your browser bar and the "https://" protocol.

Changes

We amend this privacy policy when our data processing changes. The version currently published in the application, bearing the date given below, applies. If the purpose, data categories or recipients change substantially, we inform registered users in advance by e-mail or within the application; such a change does not take effect retroactively.

Last updated: 05.09.2026

GlossaryGuidesContactPrivacy PolicyLegal NoticeTerms
© 2026 Menira·Made in Switzerlandv4.5.7