monaveo ← Back to Home

Data Processing Agreement

Last updated: July 16, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between Monaveo Ltd. ("Processor", "we") and the customer ("Controller", "you") for the use of the Monaveo platform. This DPA governs the processing of personal data on your behalf in accordance with Article 28 of the UK GDPR (as retained in UK law under the Data Protection Act 2018) and Article 28 of the General Data Protection Regulation (EU) 2016/679.

2. Definitions

  • "Personal Data" — any information relating to an identified or identifiable natural person processed through the Monaveo platform.
  • "Processing" — any operation performed on Personal Data, including collection, storage, use, transmission, and deletion.
  • "Sub-processor" — any third party engaged by us to process Personal Data on your behalf.

3. Scope of Processing

3.1 Categories of Data Subjects

End users of managed devices, employees and contractors of the Controller's clients, and the Controller's own staff.

3.2 Types of Personal Data

Device hostnames, IP addresses, operating system information, hardware identifiers, user account names displayed on devices, and network configuration data.

3.3 Purpose of Processing

Processing is performed solely to provide the Monaveo RMM service: device monitoring, remote management, alerting, ticketing, and related features.

3.4 Endpoint Backup Service (Optional)

Where the Controller enables the optional Endpoint Backup service, Monaveo stores backups of files and system data selected by the Controller from its managed endpoints. All backup data is encrypted on the endpoint (client-side, AES-256) before it leaves the device. The encryption key is generated and held by the Controller's endpoint and is never transmitted to, stored by, or accessible to Monaveo (unless the Controller expressly enables the optional key-escrow facility, in which case an encrypted copy of the recovery key is held in Monaveo's credential vault at the Controller's request). Absent escrow, Monaveo therefore stores only ciphertext and cannot access, read, decrypt, inspect, or index the content of any backup. The Controller determines what data is backed up and remains solely responsible for the lawful basis for that data (including any special categories of personal data); Monaveo processes only opaque encrypted objects and does not process backup content.

4. Obligations of the Processor

We shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure that authorized persons are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to data subject requests
  • Assist with compliance obligations (security, breach notification, impact assessments)
  • Delete or return all Personal Data upon termination, at the Controller's choice
  • Make available all information necessary to demonstrate compliance

5. Security Measures

We implement the following measures:

  • Encrypted transport (TLS 1.2+/WSS) for all dashboard and agent communications, with mutual-TLS authentication for agents; remote-desktop sessions end-to-end encrypted by RustDesk
  • Unique cryptographic identity per managed device
  • Strict tenant isolation between MSP accounts
  • Role-based access control
  • Encrypted data transmission for all communications
  • Regular security assessments and updates
  • Access logging and audit trails
  • Backup data (where the optional Endpoint Backup service is enabled) is encrypted client-side (AES-256) before transmission; encryption keys remain under the Controller's exclusive control and are not held by Monaveo (zero-knowledge storage by default), unless the Controller expressly enables the optional key-escrow facility, in which case an encrypted copy of the recovery key is held in Monaveo's credential vault at the Controller's request

6. Sub-processors

We use the following sub-processors:

Contabo GmbH — EU region hosting and infrastructure (Nuremberg, Germany)

Hetzner Online GmbH — EU region hosting and infrastructure (Germany)

Contabo GmbH — US region hosting and infrastructure (New Jersey, USA)

Hetzner Online GmbH — US region hosting and infrastructure (United States)

Stripe, Inc. — Payment processing (USA, EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum (UK Addendum to the EU SCCs))

Cloudflare, Inc. — Content delivery, DDoS protection, and object storage for file transfer and ticket attachments (regionally isolated: EU Controller data stored in the EU, US Controller data stored in the US). Cloudflare, Inc. is US-based; any transfer is covered by the EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum.

Backblaze Inc. — Immutable (COMPLIANCE-mode Object Lock) object storage for the optional Endpoint Backup service. Stores only client-side-encrypted backup objects; Backblaze cannot access, read, decrypt, or index backup content. Regionally isolated: EU Controller backups stored in the EU (Amsterdam, Netherlands), US Controller backups stored in the US. Backblaze Inc. is US-based; transfers are covered by EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum (UK Addendum to the EU SCCs).

RustDesk (Purslane Ltd) — Remote desktop relay software. Sessions are relayed through Monaveo's own self-hosted relay servers within the selected region.

SMTP2GO — Transactional email delivery with regional routing (EU: Germany, US: United States)

Microsoft Corporation — Microsoft 365 and Intune integration via Graph API. Activated only when the Controller explicitly connects their M365 tenant with admin consent. Access covers reading directory, licensing, security-posture and Intune inventory data and, where the Controller enables it, Controller-initiated administrative actions (e.g. account enable/disable, password reset, session revocation, license assignment, Intune script deployment). A read-only connection mode is available.

Google LLC (Firebase Cloud Messaging) — Push-notification delivery to mobile and desktop devices. Receives the device push token and the notification payload, which for operational alerts may include a device name and a short event summary; never credentials or special-category data (USA, EU–U.S. Data Privacy Framework, incl. the UK Extension (UK–U.S. Data Bridge)).

Apple Inc. (Apple Push Notification service) — Push-notification delivery to Apple devices, reached via Firebase Cloud Messaging. Receives the device push token and the notification payload (as above); never credentials or special-category data (USA, EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum (UK Addendum to the EU SCCs)).

We will notify you before adding or replacing sub-processors, giving you the opportunity to object. If you object and we cannot accommodate, you may terminate the affected services.

7. Data Breach Notification

We will notify you without undue delay (within 72 hours) after becoming aware of a personal data breach. The notification will include the nature of the breach, affected data subjects, and remediation measures.

8. Data Transfers & Regional Isolation

At the time of account creation, the Controller selects a data region (EU or US). All Personal Data is processed and stored within the selected region, and is never replicated or mirrored between the EU and US regions. The only exception is mobile push-notification delivery, which necessarily transits the device operating-system push services (Google Firebase Cloud Messaging and Apple APNs, US) under the safeguards listed in Section 6.

EU Region: Hosted by Contabo GmbH and Hetzner Online GmbH in Germany; all Personal Data is stored and processed in the EU, except the mobile push-notification egress described in Section 6.

US Region: Hosted by Contabo GmbH and Hetzner Online GmbH in the United States. This environment is completely independent from the EU region.

Some sub-processors necessarily operate across regions. Stripe (payment processing) receives billing data only. Mobile push providers (Google FCM and Apple APNs) receive push tokens and notification payloads, which for operational alerts may include a device name and a short event summary. All such transfers are covered by appropriate safeguards (Section 6).

9. Data Retention & Deletion

Upon termination, we will delete all Personal Data within thirty (30) days at no cost to the Controller, except (a) records we must retain by law (e.g., billing records under UK tax law), and (b) immutable Endpoint Backup data, which is retained and billed until its lock period expires (see Backups, below). On termination or account/device deletion, the Monaveo Agent software (and the bundled remote-access component) is remotely deactivated and uninstalled from the affected managed devices.

Controllers wishing to retain a copy of their data must submit a written request to privacy@monaveo.com before or within fourteen (14) days of termination. Monaveo will work with the Controller in good faith to provide a copy of the data on a case-by-case basis, with the format, scope, and delivery method agreed between the parties based on what is technically feasible at the time of the request. A reasonable service fee may apply to data export requests. Deletion of Personal Data remains free of charge. Full details are set out in our Terms of Service §14.4.

Backups. Backup objects are stored client-side-encrypted in the Controller's region on immutable, COMPLIANCE-mode Object-Lock storage. For the retention period the Controller configures, backup objects cannot be modified or deleted by the Controller, by Monaveo, or by any sub-processor — a security control against ransomware and malicious or accidental deletion, consistent with standard WORM/Object-Lock backup practice.

Effect on erasure (Art. 17, Art. 28(3)(g)). Because of this immutability, a Controller deletion instruction or a data-subject erasure request cannot be given immediate physical effect against a locked backup object. Consistent with GDPR guidance that personal data in backups need not be erased immediately where retention concerns take precedence, Monaveo gives effect to a valid erasure request by, in combination: (a) cryptographic erasure — destroying the relevant per-device encryption key material and any escrowed copy, rendering the affected backup permanently unreadable and irretrievable even while the encrypted object remains under lock (a data-destruction method recognised by NIST SP 800-88 "Cryptographic Erase"); (b) suppressing and ceasing all further processing of the affected data; and (c) permanently deleting the residual ciphertext object promptly on lock expiry. The Controller acknowledges, and is responsible for informing affected data subjects, that physical deletion of a locked backup copy is deferred to the expiry of the retention window the Controller selected, and that during that window the data is cryptographically erased and processing is suppressed.

On account offboarding, Monaveo schedules the repository for deletion; objects under an active lock are deleted on lock expiry and remaining unlocked data within thirty (30) days. Legally-required retention (e.g. billing records; content under legal hold) is unaffected. Because backups are client-side encrypted, deletion of the repository, or destruction/loss of the key material, renders the data permanently unrecoverable.

Post-termination charges. Where immutable backup objects remain after termination, they are retained until lock expiry and the associated storage is chargeable to the Controller for the remaining period per Terms Schedule 1 §S1.7 — an exception to the 30-day no-cost deletion commitment for Endpoint Backup only.

10. Audits

You have the right to audit our compliance with this DPA with reasonable notice during business hours. We may satisfy requests by providing certifications, reports, or documentation.

11. Governing Law

This DPA and these Terms are governed by the laws of England and Wales, and any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

12. Annex I — Description of Processing

A. Categories of Data Subjects

  • MSP Administrators and Staff — employees of the Controller who use the Monaveo dashboard to manage devices, tickets, and reports
  • End Users of Managed Devices — employees, contractors, and other individuals whose devices are monitored and managed through the platform
  • Customer Contacts — individuals listed as contacts for the Controller's clients (names, emails, phone numbers for ticketing and communication purposes)

B. Categories of Personal Data Processed

Account & Identity Data: Full name, email address, phone number, company name, billing address, job title, user role

Authentication Data: Password hashes (bcrypt), MFA secrets (TOTP), session tokens (JWT), login timestamps, IP addresses at login

Device Identification Data: Hostname, device UUID, operating system type and version, public and private IP addresses, MAC addresses, hardware serial numbers

Device Operational Data: CPU usage, memory usage, disk usage and capacity, uptime, installed software list, running services and processes, Windows update status, antivirus status, firewall status, BitLocker/FileVault encryption status

Network Data: IP addresses, subnet information, DNS configuration, network adapter details, SNMP data from network devices

User Account Data from Devices: Last logged-in username, user profile names visible on the operating system

Hardware Data: CPU model, GPU model, motherboard model, RAM module details, monitor information (EDID), USB devices, connected printers

Microsoft 365 Data (when connected): User directory (names, emails, UPNs), assigned licenses, group memberships, device compliance status, Intune device inventory, security alerts, Secure Score

Communication Data: Support ticket content, email correspondence, inbound email metadata (sender, subject, timestamps)

Billing Data: Stripe customer ID, subscription details, invoice history, payment method type (card last 4 digits only — full card data is stored by Stripe, never by Monaveo)

C. Sensitive Data

The platform is not designed to process special categories of personal data as defined in Article 9 of the UK GDPR and EU GDPR (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, etc.). Controllers should configure their environments to avoid transmitting such data through the platform.

D. Processing Operations

  • Collection — via agent software installed on managed devices, dashboard user input, Microsoft Graph API (when connected), inbound email parsing
  • Storage — in PostgreSQL databases within the selected data region (EU: Germany, US: United States), with file attachments and backups in encrypted object storage in the same region
  • Use — real-time monitoring dashboards, alerting engine, report generation, ticket management, security assessments
  • Transmission — encrypted agent-to-server communication over mutual TLS (mTLS), SMTP email delivery via SMTP2GO, and remote-desktop sessions end-to-end encrypted via the RustDesk relay
  • Deletion — automated purging per retention schedule, manual deletion via GDPR delete functionality, and account erasure following a short cancellable wind-down period (within 30 days of request)

E. Retention Periods

  • Device performance metrics (CPU, RAM): 7 days. Disk/volume usage: current inventory snapshot (latest value)
  • Device inventory data (software, hardware, OS): duration of account
  • Notifications: 30 days (automatically purged)
  • Alert history: active and dismissed alerts retained until resolved; resolved alerts auto-purged 1 year after resolution
  • Audit logs: 1 year (legal-hold extension applied manually where required)
  • Ticket data: duration of account
  • Account data: duration of account + up to 30 days (cancellable wind-down, typically ~14 days)
  • Billing records: 6 years as required by UK Tax Law (HMRC) and the Companies Act 2006.
  • Microsoft 365 data (directory, licenses, security alerts, Intune inventory): retained while the tenant is connected; removed on disconnect or account closure
  • Database backups: encrypted, in-region, rolling rotation (not retained long-term)

13. Contact

Privacy & Data Processing: privacy@monaveo.com

Monaveo Ltd. — Company No. 17173409 (Registered in England & Wales) — 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom

© 2026 Monaveo by Monaveo Ltd. All rights reserved.

Monaveo Ltd. · Company No. 17173409 · Registered in England & Wales

Privacy Terms DPA GDPR Contact