monaveo ← Back to Home

Privacy Policy

Last updated: July 16, 2026

1. Introduction

This Privacy Policy explains how Monaveo Ltd. ("we", "us", "our"), operating the Monaveo platform, collects, uses, and protects personal data when you use our services. We are committed to protecting your privacy in accordance with the UK GDPR, the General Data Protection Regulation (EU) 2016/679, and applicable laws of England and Wales.

Data Controller: Monaveo Ltd.

Company No.: 17173409 (Registered in England & Wales)

ICO Registration: ZC168240

Address: 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom

Email: hello@monaveo.com

Person responsible for data protection: privacy@monaveo.com

Monaveo Ltd. is the data controller for the account, billing, website, and support-communication data described in this policy. For personal data processed from your managed devices and connected Microsoft 365 tenants, Monaveo acts as a data processor on behalf of the customer (the MSP), who is the controller — see our GDPR page and Data Processing Agreement.

2. Data We Collect

2.1 Account Data

When you create an account, we collect your name, email address, company name, billing address, and payment information (processed securely through Stripe).

2.2 Service Data

When you use Monaveo to manage devices, the platform processes device hostnames, IP addresses, operating system information, hardware metrics (CPU, memory, disk usage), and service/process status. This data is collected by agents installed on managed devices.

2.3 Microsoft 365 Data

If you connect your Microsoft 365 tenant, Monaveo accesses your environment via the Microsoft Graph API, only with your explicit administrator consent. By default this enables both reading information (user directory, license and subscription details, group memberships, sign-in activity, security posture / Secure Score, and Intune device inventory and compliance status) and — where you choose to use them — administrative actions such as enabling or disabling user accounts, resetting passwords, revoking sign-in sessions, managing license assignments, and deploying device-management scripts through Intune. A read-only connection mode is available if you prefer to grant Monaveo read access only. All administrative actions are role-controlled and recorded in our audit log. Data synced from your tenant is stored in our database for the duration of your M365 connection so we can display and manage your environment. When you disconnect your tenant or close your account, this data is removed in line with our retention schedule (Section 6).

2.4 Communication Data

We collect data from support tickets, emails, and other communications you send to us.

2.5 Usage Data

We collect basic analytics about how you interact with the dashboard, including pages visited, features used, and session duration. This usage analytics is first-party and derived from our server-side logs; it does not use analytics or tracking cookies.

3. How We Use Your Data

We use your data to:

  • Provide and maintain the Monaveo platform and its features
  • Process billing and payments
  • Send service notifications, alerts, and system updates
  • Provide technical support
  • Improve and develop new features
  • Comply with legal obligations

3.1 Lawful Basis (UK GDPR Article 6)

We rely on the following lawful bases for the processing above: performance of a contract (Art. 6(1)(b)) to provide the platform, manage your account, and process billing; legitimate interests (Art. 6(1)(f)) to send service and security notifications, prevent fraud and abuse, secure the service, and improve and develop features; legal obligation (Art. 6(1)(c)) to retain invoices and comply with law; and consent (Art. 6(1)(a)) for any optional marketing communications, which you may withdraw at any time.

4. Data Encryption & Security

All traffic between the Monaveo dashboard, our servers, and managed agents is encrypted in transit using TLS. Managed agents additionally authenticate with mutual TLS (mTLS) — each managed device is issued its own unique client certificate. Remote-desktop sessions are end-to-end encrypted by RustDesk, whose relay forwards traffic it cannot decrypt; other management commands are decrypted by our servers, which enforce strict per-tenant access control.

We implement industry-standard security measures including encrypted data transmission, secure authentication, role-based access control, and strict tenant isolation between MSP accounts.

Backup recovery key. By default the optional Endpoint Backup service is zero-knowledge: your backup passphrase/recovery key is generated and held on your endpoint and is never transmitted to or accessible by Monaveo. If you lose this key, your backups are permanently unrecoverable and Monaveo cannot recover them. An optional key-escrow facility is available; only if you expressly enable it, an encrypted copy of your recovery key is stored in Monaveo's credential vault (encrypted at rest) so you can recover it.

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Stripe — for payment processing
  • Cloudflare, Inc. — content delivery, security, and encrypted file/object storage (e.g. ticket attachments and file transfer)
  • Backblaze Inc. — immutable, encrypted object storage for the optional Endpoint Backup service; stores only client-side-encrypted backup objects (Backblaze cannot read or decrypt them), regionally isolated (EU backups in the EU, US backups in the US)
  • Contabo GmbH — EU region hosting (Germany)
  • Hetzner Online GmbH — EU region hosting (Germany)
  • Contabo GmbH — US region hosting (New Jersey, USA)
  • Hetzner Online GmbH — US region hosting (United States)
  • RustDesk (Purslane Ltd) — remote desktop software; sessions are relayed through Monaveo's own self-hosted relay servers in your region
  • SMTP2GO — for transactional email delivery (regionally routed)
  • Microsoft Corporation — only when you connect your M365 tenant (Graph API, admin consent required)
  • Law enforcement — only when legally required

In addition, to verify business identity and to prevent fraud and abuse when an account is created, we transmit limited technical data (such as your IP address, the email and website domain you provide, and your VAT number) to the following verification and security providers, on the basis of our legitimate interests:

  • Cloudflare Turnstile — bot and automated-signup detection
  • proxycheck.io — IP reputation (proxy / VPN / known-abuse) checks
  • Spamhaus & SpamCop — email and IP reputation (DNSBL) checks
  • EU VIES (European Commission service) — VAT-number validation for EU businesses
  • Domain-registration (RDAP) lookups — to confirm the age and validity of your business domain

6. Data Retention

We retain different categories of data for specific periods based on operational necessity and legal requirements:

  • Account Data (name, email, company) — retained for the duration of your active account. On deletion, the account enters a short, cancellable wind-down period (about 14 days) during which agents are removed, after which personal data is erased without undue delay, except records we must keep by law (see Billing Records)
  • Device Performance Metrics (CPU and memory usage) — retained for 7 days in high resolution, then automatically purged. Disk and volume usage is kept as the current inventory snapshot (latest value), not as a long-term time-series
  • Device Inventory Data (installed software, hardware specs, OS info) — retained for the duration of the account as part of asset management
  • Notifications (system notifications, in-app alerts) — retained for 30 days, then automatically purged
  • Alert History (device alerts, threshold violations) — active alerts are retained until resolved. Resolved and dismissed alerts are automatically purged after 1 year
  • Audit Logs (user actions, configuration changes, login events) — retained for 1 year, then automatically purged. In the event of active legal proceedings or regulatory investigation, relevant logs may be retained longer as required by law
  • Ticket Data (support tickets, comments, attachments) — retained for the duration of the account
  • Billing Records (invoices, payment history) — retained for 6 years as required by UK Tax Law (HMRC) and the Companies Act 2006.
  • Microsoft 365 Data (directory, licenses, security alerts, Intune inventory) — retained while your M365 tenant is connected; removed when you disconnect the tenant or close the account
  • Database Backups — encrypted and stored within your region, rotated on a regular rolling schedule and not retained long-term

When you close your account, we erase your personal data without undue delay following a short, cancellable wind-down period, except where retention is required by law (e.g., billing records kept for 6 years under UK tax law). Customers wishing to retain a copy of their data must submit a written request to privacy@monaveo.com before or within fourteen (14) days of termination. Monaveo will work with the Customer in good faith to provide a copy of their data on a case-by-case basis, with the format, scope, and delivery method agreed between the parties based on what is technically feasible at the time of the request. A reasonable service fee may apply to data export requests. Deletion of personal data remains free of charge. Full details are set out in our Terms of Service §14.4.

7. Your Rights

Under UK GDPR and EU GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten") — contact us and we will process your deletion request within 30 days, as required by UK GDPR
  • Restrict processing of your data
  • Data portability — receive your data in a structured format
  • Object to processing based on legitimate interests
  • Withdraw consent at any time

Where data is held in immutable Endpoint Backup storage that you or your MSP configured, physical deletion is technically deferred until the retention/immutability period expires. On a valid erasure request we cryptographically erase the affected backup (by destroying the encryption key so the data can no longer be read), suppress any further processing, and permanently delete the residual encrypted object when the lock expires.

To exercise any of these rights, contact us at hello@monaveo.com.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority, at ico.org.uk or 0303 123 1113, if you believe we have not handled your personal data lawfully. We would, however, appreciate the chance to address your concerns first — please contact privacy@monaveo.com.

If you are located in the European Union, you also have the right to lodge a complaint with the data protection supervisory authority in your Member State of residence, place of work, or the place of the alleged infringement. You may also contact our EU representative (see “Contact Us” below) on any matter relating to the processing of your personal data.

8. Cookies

The Monaveo website and dashboard use only strictly necessary cookies required for authentication, session management, and security. These cookies are exempt from consent requirements under Regulation 6(4) of the UK Privacy and Electronic Communications Regulations (PECR) 2003, as they are essential for the service you have requested. During checkout and billing, our payment processor (Stripe) may set cookies strictly necessary for secure payment and fraud prevention. We do not use advertising, analytics, or cross-site tracking cookies, and no cookies are used to track you across other websites.

9. Data Residency & International Transfers

When you create your Monaveo account, you select your data region (EU or US). All your data — including device information, tickets, alerts, and reports — is processed and stored exclusively within your chosen region.

Each region operates as a completely independent environment with separate databases and application instances. No personal data is replicated, mirrored, or transferred between regions.

EU Region: Hosted in Germany (Contabo GmbH and Hetzner Online GmbH) — subject to German and EU data protection law only

US Region: Hosted in the United States (Contabo GmbH and Hetzner Online GmbH) — completely separate from the EU environment

Endpoint Backups (optional service): EU backups are stored in the EU (Backblaze B2, Amsterdam, Netherlands); US backups are stored in the US. Backups never leave your selected region.

Payment processing is handled by Stripe, Inc. and content delivery by Cloudflare, Inc. — both operate under their own data processing agreements and applicable transfer safeguards.

Push notifications. To deliver real-time notifications to your devices (for example sign-in approval requests, and alert or ticket notifications), we use the operating-system push services operated by Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service, reached via Firebase Cloud Messaging for Apple devices). When you enable push notifications, a device-specific push token is transmitted to these providers along with the notification itself, which may be processed on servers in the United States. We minimise what each notification contains: sign-in approval notifications carry only a generic message and opaque, single-use technical tokens — no personal data. Operational notifications (such as device alerts) may include the managed device's name and a short summary of the event (for example, “SERVER-01: High CPU”), but never credentials, full ticket contents, or special-category data. These transfers are covered by appropriate safeguards under Articles 44–46 GDPR: Google LLC is certified under the EU–U.S. Data Privacy Framework, and onward delivery to Apple Inc. for Apple devices is made under the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable). You can disable push notifications at any time in your device or application settings, without affecting your use of the rest of the platform.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised policy here with a new "Last updated" date. For any material change, we will notify you by email and through the Monaveo dashboard at least thirty (30) days before it takes effect, stating the effective date. Non-material changes take effect when posted.

11. Contact Us

Monaveo Ltd.

Company No.: 17173409 (Registered in England & Wales)

Email: privacy@monaveo.com

Address: 71-75 Shelton Street, London, WC2H 9JQ, United Kingdom

EU Representative (Article 27 GDPR)

For individuals in the European Union, our representative under Article 27 of the EU GDPR, appointed to be addressed in addition to or instead of us on questions relating to the processing of personal data, is:

247.SYSTEMS – ΛΥΣΕΙΣ ΠΛΗΡΟΦΟΡΙΚΗΣ Ε.Ε. (247.Systems LP — a Greek limited partnership)
Leof. Syngrou 196, 17671 Kallithea, Athens, Greece
Email: monaveo@247systems.gr

© 2026 Monaveo by Monaveo Ltd. All rights reserved.

Monaveo Ltd. · Company No. 17173409 · Registered in England & Wales

Privacy Terms DPA GDPR Contact