This Data Processing Agreement ("DPA") forms part of the agreement between Monaveo Ltd. ("Processor", "we") and the customer ("Controller", "you") for the use of the Monaveo platform. This DPA governs the processing of personal data on your behalf in accordance with Article 28 of the UK GDPR (as retained in UK law under the Data Protection Act 2018) and Article 28 of the General Data Protection Regulation (EU) 2016/679.
End users of managed devices, employees and contractors of the Controller's clients, and the Controller's own staff.
Device hostnames, IP addresses, operating system information, hardware identifiers, user account names displayed on devices, and network configuration data.
Processing is performed solely to provide the Monaveo RMM service: device monitoring, remote management, alerting, ticketing, and related features.
Where the Controller enables the optional Endpoint Backup service, Monaveo stores backups of files and system data selected by the Controller from its managed endpoints. All backup data is encrypted on the endpoint (client-side, AES-256) before it leaves the device. The encryption key is generated and held by the Controller's endpoint and is never transmitted to, stored by, or accessible to Monaveo (unless the Controller expressly enables the optional key-escrow facility, in which case an encrypted copy of the recovery key is held in Monaveo's credential vault at the Controller's request). Absent escrow, Monaveo therefore stores only ciphertext and cannot access, read, decrypt, inspect, or index the content of any backup. The Controller determines what data is backed up and remains solely responsible for the lawful basis for that data (including any special categories of personal data); Monaveo processes only opaque encrypted objects and does not process backup content.
We shall:
We implement the following measures:
We use the following sub-processors:
Contabo GmbH — EU region hosting and infrastructure (Nuremberg, Germany)
Hetzner Online GmbH — EU region hosting and infrastructure (Germany)
Contabo GmbH — US region hosting and infrastructure (New Jersey, USA)
Hetzner Online GmbH — US region hosting and infrastructure (United States)
Stripe, Inc. — Payment processing (USA, EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum (UK Addendum to the EU SCCs))
Cloudflare, Inc. — Content delivery, DDoS protection, and object storage for file transfer and ticket attachments (regionally isolated: EU Controller data stored in the EU, US Controller data stored in the US). Cloudflare, Inc. is US-based; any transfer is covered by the EU Standard Contractual Clauses as supplemented by the UK International Data Transfer Addendum.
Backblaze Inc. — Immutable (COMPLIANCE-mode Object Lock) object storage for the optional Endpoint Backup service. Stores only client-side-encrypted backup objects; Backblaze cannot access, read, decrypt, or index backup content. Regionally isolated: EU Controller backups stored in the EU (Amsterdam, Netherlands), US Controller backups stored in the US. Backblaze Inc. is US-based; transfers are covered by EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum (UK Addendum to the EU SCCs).
RustDesk (Purslane Ltd) — Remote desktop relay software. Sessions are relayed through Monaveo's own self-hosted relay servers within the selected region.
SMTP2GO — Transactional email delivery with regional routing (EU: Germany, US: United States)
Microsoft Corporation — Microsoft 365 and Intune integration via Graph API. Activated only when the Controller explicitly connects their M365 tenant with admin consent. Access covers reading directory, licensing, security-posture and Intune inventory data and, where the Controller enables it, Controller-initiated administrative actions (e.g. account enable/disable, password reset, session revocation, license assignment, Intune script deployment). A read-only connection mode is available.
Google LLC (Firebase Cloud Messaging) — Push-notification delivery to mobile and desktop devices. Receives the device push token and the notification payload, which for operational alerts may include a device name and a short event summary; never credentials or special-category data (USA, EU–U.S. Data Privacy Framework, incl. the UK Extension (UK–U.S. Data Bridge)).
Apple Inc. (Apple Push Notification service) — Push-notification delivery to Apple devices, reached via Firebase Cloud Messaging. Receives the device push token and the notification payload (as above); never credentials or special-category data (USA, EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum (UK Addendum to the EU SCCs)).
We will notify you before adding or replacing sub-processors, giving you the opportunity to object. If you object and we cannot accommodate, you may terminate the affected services.
We will notify you without undue delay (within 72 hours) after becoming aware of a personal data breach. The notification will include the nature of the breach, affected data subjects, and remediation measures.
At the time of account creation, the Controller selects a data region (EU or US). All Personal Data is processed and stored within the selected region, and is never replicated or mirrored between the EU and US regions. The only exception is mobile push-notification delivery, which necessarily transits the device operating-system push services (Google Firebase Cloud Messaging and Apple APNs, US) under the safeguards listed in Section 6.
EU Region: Hosted by Contabo GmbH and Hetzner Online GmbH in Germany; all Personal Data is stored and processed in the EU, except the mobile push-notification egress described in Section 6.
US Region: Hosted by Contabo GmbH and Hetzner Online GmbH in the United States. This environment is completely independent from the EU region.
Some sub-processors necessarily operate across regions. Stripe (payment processing) receives billing data only. Mobile push providers (Google FCM and Apple APNs) receive push tokens and notification payloads, which for operational alerts may include a device name and a short event summary. All such transfers are covered by appropriate safeguards (Section 6).
Upon termination, we will delete all Personal Data within thirty (30) days at no cost to the Controller, except (a) records we must retain by law (e.g., billing records under UK tax law), and (b) immutable Endpoint Backup data, which is retained and billed until its lock period expires (see Backups, below). On termination or account/device deletion, the Monaveo Agent software (and the bundled remote-access component) is remotely deactivated and uninstalled from the affected managed devices.
Controllers wishing to retain a copy of their data must submit a written request to privacy@monaveo.com before or within fourteen (14) days of termination. Monaveo will work with the Controller in good faith to provide a copy of the data on a case-by-case basis, with the format, scope, and delivery method agreed between the parties based on what is technically feasible at the time of the request. A reasonable service fee may apply to data export requests. Deletion of Personal Data remains free of charge. Full details are set out in our Terms of Service §14.4.
Backups. Backup objects are stored client-side-encrypted in the Controller's region on immutable, COMPLIANCE-mode Object-Lock storage. For the retention period the Controller configures, backup objects cannot be modified or deleted by the Controller, by Monaveo, or by any sub-processor — a security control against ransomware and malicious or accidental deletion, consistent with standard WORM/Object-Lock backup practice.
Effect on erasure (Art. 17, Art. 28(3)(g)). Because of this immutability, a Controller deletion instruction or a data-subject erasure request cannot be given immediate physical effect against a locked backup object. Consistent with GDPR guidance that personal data in backups need not be erased immediately where retention concerns take precedence, Monaveo gives effect to a valid erasure request by, in combination: (a) cryptographic erasure — destroying the relevant per-device encryption key material and any escrowed copy, rendering the affected backup permanently unreadable and irretrievable even while the encrypted object remains under lock (a data-destruction method recognised by NIST SP 800-88 "Cryptographic Erase"); (b) suppressing and ceasing all further processing of the affected data; and (c) permanently deleting the residual ciphertext object promptly on lock expiry. The Controller acknowledges, and is responsible for informing affected data subjects, that physical deletion of a locked backup copy is deferred to the expiry of the retention window the Controller selected, and that during that window the data is cryptographically erased and processing is suppressed.
On account offboarding, Monaveo schedules the repository for deletion; objects under an active lock are deleted on lock expiry and remaining unlocked data within thirty (30) days. Legally-required retention (e.g. billing records; content under legal hold) is unaffected. Because backups are client-side encrypted, deletion of the repository, or destruction/loss of the key material, renders the data permanently unrecoverable.
Post-termination charges. Where immutable backup objects remain after termination, they are retained until lock expiry and the associated storage is chargeable to the Controller for the remaining period per Terms Schedule 1 §S1.7 — an exception to the 30-day no-cost deletion commitment for Endpoint Backup only.
You have the right to audit our compliance with this DPA with reasonable notice during business hours. We may satisfy requests by providing certifications, reports, or documentation.
This DPA and these Terms are governed by the laws of England and Wales, and any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
Account & Identity Data: Full name, email address, phone number, company name, billing address, job title, user role
Authentication Data: Password hashes (bcrypt), MFA secrets (TOTP), session tokens (JWT), login timestamps, IP addresses at login
Device Identification Data: Hostname, device UUID, operating system type and version, public and private IP addresses, MAC addresses, hardware serial numbers
Device Operational Data: CPU usage, memory usage, disk usage and capacity, uptime, installed software list, running services and processes, Windows update status, antivirus status, firewall status, BitLocker/FileVault encryption status
Network Data: IP addresses, subnet information, DNS configuration, network adapter details, SNMP data from network devices
User Account Data from Devices: Last logged-in username, user profile names visible on the operating system
Hardware Data: CPU model, GPU model, motherboard model, RAM module details, monitor information (EDID), USB devices, connected printers
Microsoft 365 Data (when connected): User directory (names, emails, UPNs), assigned licenses, group memberships, device compliance status, Intune device inventory, security alerts, Secure Score
Communication Data: Support ticket content, email correspondence, inbound email metadata (sender, subject, timestamps)
Billing Data: Stripe customer ID, subscription details, invoice history, payment method type (card last 4 digits only — full card data is stored by Stripe, never by Monaveo)
The platform is not designed to process special categories of personal data as defined in Article 9 of the UK GDPR and EU GDPR (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, etc.). Controllers should configure their environments to avoid transmitting such data through the platform.
Privacy & Data Processing: privacy@monaveo.com
Monaveo Ltd. — Company No. 17173409 (Registered in England & Wales) — 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom