Privacy Policy

Last updated: 25 August 2026

Before publishing: this draft describes how the software actually behaves, but it has not been reviewed by a lawyer. Have a qualified adviser check it against the law that applies to your business and your clients — and replace the company details in section 12 — before you rely on it.

This policy explains what personal information Mandhouma collects, why we collect it, how long we keep it and what rights you have over it. It applies to the Mandhouma website at mandhouma.com and to the Admin, Employee and Client portals hosted on it.

1. Who is responsible for your data

Mandhouma is operated by the organisation named in section 12, which is the data controller for the information described here. Where we host client work on behalf of a customer, we act as a processor for that customer's data and handle it only on their instructions.

2. What we collect

Categories of personal data collected by Mandhouma
CategoryWhat it includesWhy we hold it
Account details Name, username, email address, role, department, account status. To create your account, sign you in and show your name to colleagues on tasks and messages.
Authentication data A cryptographically hashed password, session tokens, and — if you switch it on — a two-factor secret and recovery codes. To keep your account secure. We never store your password in a readable form and cannot recover it.
Work content Tasks, notes, comments, attachments, approval decisions, handoffs and the activity log of who changed what and when. This is the service itself — the record of your work.
Communications Messages, reactions, shared files, voice notes, and records of when calls started and how long they lasted. To deliver in-app messaging and to keep a history of the conversation.
Meetings Meeting titles, agendas, times, invitees and their responses. To run the scheduling feature.
Technical data Server logs recording requests made to the service, including timestamps and error details. To keep the service running, diagnose faults and detect abuse.
Error reports When something breaks: the error message, the technical stack trace, which page it happened on, and the role of whoever hit it. So faults surface and get fixed instead of going unnoticed. Email addresses, tokens and anything that looks like a credential are stripped before storage, and the contents of your tasks, messages and files are never included.
Website analytics Aggregated page views on the public marketing pages — only if you consent. To understand which pages are useful. Never collected inside the signed-in portals.

What we deliberately do not collect

3. How your data is collected

Almost all of it you or your administrator enter directly: an administrator creates your account, and you then create tasks, comments, messages and meetings as you use the service. Technical data is generated automatically by the server as it handles requests. Analytics data on the public site is collected only after you accept the cookie banner.

4. Legal bases for processing

Where data protection law such as the UK GDPR or EU GDPR applies, we rely on:

5. Cookies and local storage

The portals use your browser's local or session storage to keep you signed in and to remember your light or dark theme preference. These are strictly necessary for the service to function, are not used for tracking, and are not shared with anyone. Clearing your browser storage simply signs you out.

The public marketing pages set no cookies at all unless you accept the analytics banner. If you decline, or ignore it, nothing is set. If analytics has not been configured by the operator, the banner does not appear because there is nothing to consent to.

6. Who we share data with

We share personal data only where it is necessary to run the service:

If your administrator chooses to attach an external meeting link (such as Google Meet, Zoom or Teams) to a conversation, that third party's own privacy policy governs anything that happens on their platform once you follow the link.

7. Where your data is stored

Data is stored on servers operated by our hosting provider, in the region stated in section 12. Backups are taken nightly and retained for a limited period. Where data is transferred outside your own country, we rely on appropriate safeguards such as standard contractual clauses.

8. How long we keep it

9. How we protect it

No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify you and the relevant regulator as the law requires.

10. Your rights

Depending on where you live, you may have the right to access a copy of your data, correct it, have it deleted, restrict or object to how we use it, receive it in a portable format, and withdraw consent you previously gave. To exercise any of these, contact us using the details in section 12. If your data was entered by an organisation that uses Mandhouma to manage their work, we may need to refer your request to them as the controller of that data.

If you are unhappy with our response you may complain to your local data protection authority.

11. Children

Mandhouma is a workplace tool and is not intended for use by anyone under 16. We do not knowingly collect data about children.

12. Contact us

Questions about this policy, or a request about your data:

13. Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change significantly affects you, tell you inside the service.

← Back to home