These statements are intentionally limited to controls and responsibilities described by Mandate's Privacy Policy, Terms of Use and EULA.
CUSTOMER DATA
The customer organisation retains ownership of Customer Data and decides what information it is legally entitled to collect and store.
ORGANISATION SEPARATION
Controls may include organisation separation, permission-based access, authentication controls and secure document access.
DATA PROTECTION
Mandate takes reasonable technical and organisational steps designed to protect information from misuse, interference, loss and unauthorised access.
SERVICE PROVIDER ACCESS
External provider access must be authorised by the customer and remains subject to the scope and permissions configured for that relationship.
AUDIT + SECURITY EVENTS
Technical, usage and security information may include timestamps, authentication events, diagnostic logs and security events.
RETENTION + BACKUPS
Deletion from active systems may not immediately remove information from encrypted backups or immutable security records; those copies may remain for a limited period.