Monaveo, operated by Monaveo Ltd., is fully committed to protecting personal data in compliance with the UK GDPR (as retained in UK law under the Data Protection Act 2018) and the General Data Protection Regulation (EU) 2016/679. As a UK company providing services in the United Kingdom, the European Union, and globally, GDPR compliance is at the core of how we build and operate our platform.
As a Monaveo customer (MSP), you are the Data Controller for the personal data collected through managed devices. You determine the purposes and means of processing.
We act as Data Processor on your behalf. We process data only according to your instructions and solely to provide the Monaveo service. Our obligations are detailed in our Data Processing Agreement.
All traffic between the dashboard, our servers, and agents is encrypted in transit using TLS, with mutual-TLS authentication for agents — each device has its own unique client certificate. Remote-desktop sessions are end-to-end encrypted by RustDesk, whose relay forwards traffic it cannot decrypt; other management traffic is decrypted by our servers under strict per-tenant access control.
Every MSP account is strictly isolated. One MSP's data can never be accessed by another. Customer, site, and device data are separated at the database level with enforced access controls.
Role-based access control (RBAC) ensures users only access data and features relevant to their role.
We collect only the data needed to monitor and manage enrolled devices — technical inventory and limited personal data such as the device's public IP address (obtained via a third-party IP-lookup service), hostnames, and the signed-in user where relevant. We do not collect unnecessary personal data from managed devices.
If your personal data is processed through Monaveo, contact the MSP managing your devices (the Data Controller) to exercise these rights:
Monaveo customers exercising rights on their own account data: contact hello@monaveo.com.
Monaveo offers regional data residency. When creating an account, customers choose their data region:
EU Region: Primary data processed and stored in Germany (Contabo GmbH and Hetzner Online GmbH), under EU jurisdiction. Certain functions rely on sub-processors that may process limited data outside the EU — chiefly mobile push notifications (Google Firebase Cloud Messaging and Apple APNs), under the safeguards below.
US Region: Primary data processed and stored in the United States (Contabo GmbH and Hetzner Online GmbH), completely independent from the EU environment.
Some services necessarily operate globally. Stripe (billing) involves payment data only. Mobile push notifications transit Google Firebase Cloud Messaging and Apple APNs (US) and may carry a device name and a short alert summary. Appropriate safeguards are in place for these transfers — the EU–U.S. Data Privacy Framework (Google) and Standard Contractual Clauses (Apple), plus the UK International Data Transfer Addendum where required.
Listed in our Data Processing Agreement. Customers are notified before new sub-processors are engaged.
You have the right to lodge a complaint with a supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ICO):
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom
Website: ico.org.uk
Users residing in the European Economic Area (EEA) may also lodge a complaint with their local Data Protection Authority (e.g., the Hellenic Data Protection Authority for users in Greece).
Company No.: 17173409 (Registered in England & Wales)
ICO Registration: ZC168240
Email: privacy@monaveo.com (person responsible for data protection)
Address: 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom