Enterprise Privacy Policy

Manna Analytics is built upon mathematical determinism and uncompromising data sovereignty. This document outlines our data handling policies, encryption protocols, and regulatory protections for enterprise customers.

Effective Date: September 20, 2026•Version: 3.4 (Enterprise Standard)
Contents

1. Scope & Sovereign Architecture

This Enterprise Privacy Policy governs the collection, processing, transmission, and retention of data across Manna Analytics software applications, including the Manna Autonomous ERP suite, Manuscript Management (manuscript.mannaanalytics.com), Manna Plagiarism (mannaplag.mannaanalytics.com), and associated gRPC and REST integration endpoints.

For the purposes of applicable data privacy legislation (including the EU General Data Protection Regulation 2016/679 and California Consumer Privacy Act / CPRA), our enterprise customer serves as the Data Controller, and Manna Analytics acts exclusively as the Data Processor / Service Provider.

2. Categories of Data Collected

We process only data strictly necessary to execute customer-mandated business operations:

  • Customer Business Payloads: Invoices, general ledger entries, purchase orders, bill of materials (BOM), academic manuscripts, XML markup files, and clinical trial records processed through configured workflows.
  • Operational Telemetry: Machine metrics, job run-latencies, deterministic transaction receipts, and execution timestamps essential for maintaining our 99.99% operational SLA.
  • Authorized Identity Credentials: Names, corporate email addresses, IP addresses, and cryptographic SAML/OIDC session tokens for enterprise personnel accessing administrative consoles.

3. Multi-Tenant Isolation & Zero Model Training

Explicit Guarantee: Under no circumstances is customer data, intellectual property, financial records, or unpublished scholarly manuscripts used to train, fine-tune, or benchmark public foundation AI models. Customer data never crosses tenant boundaries.

Manna employs logical and cryptographic tenant isolation. Every customer tenant maintains separate cryptographic keys, dedicated database schemas, and isolated memory spaces preventing cross-tenant leakage.

4. Cryptographic Safeguards & Key Custody

All data ingested by Manna Analytics is protected by defense-in-depth cryptographic standards:

  • In-Transit: Enforced TLS 1.3 encryption with strict HSTS, forward secrecy, and mutual TLS (mTLS) for all gRPC microservice communication.
  • At-Rest: Industry-standard AES-256-GCM encryption across all databases, transaction logs, and cold storage snapshots.
  • Customer-Managed Encryption Keys (CMEK): Enterprise accounts may manage their own root keys via AWS KMS, Azure Key Vault, or Google Cloud KMS, retaining instant cryptographic kill-switch capabilities.

5. Regulatory Frameworks (SOC2, HIPAA, GDPR)

Manna maintains continuous adherence to global compliance and audit standards:

  • SOC 2 Type II: Annual independent audit covering Security, Availability, Confidentiality, and Processing Integrity without qualification.
  • FedRAMP High Alignment: Hardened configurations supporting sovereign cloud infrastructure and government workloads.
  • HIPAA Business Associate: Available Business Associate Agreements (BAAs) for healthcare systems handling protected health information (PHI).
  • GDPR & Standard Contractual Clauses (SCCs): Legally binding data transfer mechanisms for European Union cross-border transmissions.

6. Retention, Portability & Deletion

You retain complete sovereignty over your data. Upon termination of an enterprise subscription:

  • Customers may trigger automated exports of all transactional records and manuscript archives in canonical JSON, Parquet, or JATS XML formats.
  • Manna executes DoD 5220.22-M compliant cryptographic sanitization of all hot, warm, and snapshot replicas within 30 calendar days, accompanied by a formal Certificate of Destruction.

7. Subprocessors & Cloud Infrastructure

Manna leverages audited tier-1 hyperscale cloud infrastructure providers (Amazon Web Services, Microsoft Azure, Google Cloud Platform) operating in designated customer regions (US East, US West, Frankfurt/EU, Singapore/APAC). All subprocessors are bound by equivalent confidentiality and data handling obligations.

8. Data Protection Officer (DPO) Inquiries

For questions concerning this Privacy Policy, to exercise statutory data rights under GDPR or CCPA, or to obtain our SOC 2 Type II compliance pack, contact our Chief Security Office and Data Protection Officer:

Manna Analytics — Office of the Data Protection Officer
8 The Green, Suite A, Dover, DE 19901, USA
Phone: +1 (302) 208-8120