MantisOps
MANTISOPS Managed IT Operations
Home

Privacy Policy

Effective: June 3, 2026 · Last updated: June 3, 2026
Contents
  1. Overview
  2. Data we collect
  3. How we use your data
  4. Storage and infrastructure
  5. Retention
  6. Sub-processors
  7. Your rights
  8. GDPR (EU/UK customers)
  9. Children's privacy
  10. Security
  11. Changes to this policy
  12. Contact

1. Overview

MantisOps, LLC ("MantisOps," "we," "us") operates MantisRMM, Mantis360, and MantisNMS. This Privacy Policy explains what data we collect, why we collect it, and how we protect it.

2. Data we collect

2.1 Account data

When you register, we collect:

  • Name, email address, and company name
  • Billing address and payment information (processed by Stripe — we do not store raw card data)
  • Product key and activation details
  • Timestamp and IP of your acceptance of these terms

2.2 Product usage data

Our products collect data from your infrastructure to provide the Services:

The MantisRMM agent collects:

  • System metrics (CPU, memory, disk, processes, services)
  • Installed software and patch status
  • Agent version, hostname, OS version, and connectivity status
  • Remote desktop session frames (while an active session is in progress)
  • Terminal command output (commands you execute via the console)
  • File listings and transfers (files you access via the file browser)

The Mantis360 probe collects:

  • Network scan results (IP addresses, open ports, device types, OS fingerprints)
  • Vulnerability findings against CVE / NVD data
  • DNS, WHOIS, and TLS certificate metadata for targets you scan
  • Probe status, version, and connectivity data

The MantisNMS collector collects:

  • SNMP metrics from the devices you monitor — interface bandwidth/utilisation and up/down status, plus device host resources (CPU, memory, disk, uptime)
  • Availability and latency results from ICMP/ping, HTTP(S), TCP, and SSH sensors
  • Syslog messages and SNMP traps that your devices send to the collector
  • Network flow summaries (NetFlow / IPFIX / sFlow) — ranked top talkers, conversations, and applications per exporter (aggregate summaries, not raw packet capture)
  • Collector status, version, and connectivity data

2.3 Log data

We automatically collect:

  • API request logs (endpoint, timestamp, response code — no request bodies)
  • Error logs for debugging
  • Authentication events (login attempts, MFA, session activity)

2.4 Cookies and browser data

Our web applications use:

  • Session cookies (HttpOnly, Secure, SameSite=Strict on admin / Lax on customer-facing) for authentication
  • No advertising or third-party tracking cookies
  • Our live chat widget uses your existing sign-in session and local browser storage for UI preferences (no separate tracking cookie)

3. How we use your data

Data typePurpose
Account dataAccount management, billing, support
Network scan dataDisplaying results in your Mantis360 dashboard
Agent metricsDisplaying in your MantisRMM dashboard, alerting
Network monitoring dataDisplaying sensor status, graphs, and alerts in your MantisNMS dashboard
Remote session dataProviding remote access; not recorded or stored server-side
Log dataDebugging, security monitoring, abuse prevention

We do not sell your data. We do not use your data to train AI models, and the third-party AI provider we use to assist support (see Sub-processors below) does not train on it either.

4. Storage and infrastructure

  • All data is stored on Cloudflare's infrastructure (Workers D1 databases, R2 object storage)
  • Cloudflare operates globally; data may be stored and processed in the United States and European Union
  • Each customer's data is stored in an isolated per-tenant database — your data is not commingled with other customers'
  • Data is encrypted in transit (TLS 1.2+) and at rest

5. Retention

Data typeRetention period
Account dataDuration of subscription + 30 days after termination
Scan results and agent metrics90 days rolling history (configurable)
API and login audit logs90 days
Remote session framesNot retained — streamed in real-time only
Payment records7 years (US tax / legal requirement)

6. Sub-processors

We use the following third parties who may process your data. The current authoritative list lives at /legal/sub-processors.html.

ServicePurpose
CloudflareInfrastructure, CDN, DDoS protection
StripePayment processing
ResendTransactional email delivery
Microsoft Graph APIEmail sending for administrative correspondence
Anthropic, PBCAI-assisted support — triaging support requests and drafting replies (processes the content of support tickets you send us)

We will notify you by email at least 30 days before adding a new sub-processor.

AI-assisted support. When you contact support, we may use a third-party AI provider (Anthropic) to help categorize and prioritize your request and to draft a suggested response. A MantisOps team member reviews every AI-drafted reply before it is sent — replies are never sent to you automatically by AI. Support content is processed only to assist our team and, under our commercial agreement with the provider, is not used to train the provider’s models.

7. Your rights

Depending on your location, you may have rights to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data (subject to legal retention requirements)
  • Export your data in a portable format
  • Object to certain processing

To exercise these rights, contact us at support@mantisops.net. We will respond within 30 days.

8. GDPR (EU/UK customers)

If you are located in the European Union or United Kingdom:

  • Our lawful basis for processing is contract performance (providing Services you subscribed to) and legitimate interests (security, fraud prevention)
  • For data transfers outside the EU/UK, we rely on Cloudflare's Standard Contractual Clauses
  • Our Data Protection contact is security@mantisops.net
  • You have the right to lodge a complaint with your local supervisory authority

Enterprise customers requiring a formal Data Processing Agreement should contact us.

9. Children's privacy

Our Services are not directed at individuals under 18. We do not knowingly collect data from minors.

10. Security

We implement reasonable technical and organizational measures to protect your data, including:

  • Encryption in transit (TLS 1.2+) and at rest
  • Per-tenant data isolation (separate D1 database per customer)
  • Multi-factor authentication on administrative accounts
  • Login audit logging and anomalous-activity alerting
  • Rate limiting and account lockout on authentication endpoints
  • Regular dependency security reviews

To report a vulnerability, please email security@mantisops.net.

11. Changes to this policy

We will notify you by email at least 30 days before material changes take effect. Continued use of the Services after the effective date constitutes acceptance.

12. Contact

MantisOps, LLC
6650 Rivers Ave., Suite 100
Charleston, SC 29406
Email: support@mantisops.net
Security: security@mantisops.net

← Back to MantisOps