TermsPrivacyData & permissionsProcessingContact
Legal

Data processing agreement

The Article 28 terms that apply when ManteIQ reads data on your behalf, and the full list of companies involved.

Last updated11 September 2026
01

Which of us is the controller

Two roles, and which one applies decides whose obligations these are. For the business data ManteIQ reads out of the sources you connect, your shop, Search Console, Analytics and Ads, you are the controller and MB Mante strategy is your processor. We read it on your instruction and for no other purpose.

For your own account data, meaning name, email, billing details, the Telegram chat and sign-in records, MB Mante strategy is the controller. That side is covered by the privacy policy, not by this agreement.

02

How this agreement is entered into

It is incorporated into the terms of service by reference, so it is in force from the moment you use ManteIQ for a business. No signature is needed. If your procurement process requires a countersigned copy, write to info@manteiq.com with your entity name and registered address and you will have one back, usually the same day.

03

Subject matter, duration and purpose

Subject matter: reading the accounts you connect and turning what they report into briefings, dashboards, alerts, exports and answers inside ManteIQ. The nature of the processing is collection, storage, aggregation and presentation. It is read-only at every source.

Duration: for as long as your account is open. Delete a connection and its credentials are destroyed at once. Delete a site or the account and the stored metrics go with it, immediately rather than on a thirty-day timer.

Purpose: your business data produces your reporting and nothing else. It is not sold, not pooled with another customer's data, not used to train models, and never used to contact your customers.

04

Personal data and data subjects

ManteIQ is built to hold as little personal data as the metrics allow, and most of what it reads is not personal data at all.

—Shop customers, pseudonymised: a site-scoped keyed digest of the shop email, never the address itself. It groups orders by person so new against returning, cohorts and lifetime value work. We hold the key, so this is pseudonymisation under recital 26 and stays in scope. It is not anonymous data.
—Order facts: value, currency, state, timestamps, discount code, line items, and the delivery country as a two-letter code. No name, street, city, postcode, phone or email is read into storage.
—Search terms from Search Console: queries, clicks, impressions and positions. Google aggregates these and withholds rare queries, but a query can in principle carry personal data.
—Analytics and Ads figures: sessions, channels, conversions and spend, as aggregates.
—Your own people: the team members you invite, by name, email and role.
—Never processed: card numbers, customer names, customer contact details, customer addresses.
05

Sub-processors

All of them, with what each one can see. Google is deliberately not on this list: the data moves from your Google account to ManteIQ, which makes Google your source rather than our sub-processor.

Sub-processorWhat it doesWhat it can seeWhere
Hostinger InternationalApplication hosting, the database, outbound mailAll service data at rest, and the recipients and content of transactional mailEU
Stripe Payments EuropeSubscriptions, credit packs, invoicesYour name, email, billing address and card details, which Stripe holds and we never seeEU, Ireland
AnthropicThe model that writes briefings and answers in AskThe metrics and question text needed for one answer. Not retained for trainingUS, standard contractual clauses
SentryError monitoringDiagnostics from a failure: account id, request path, stack traceUS, standard contractual clauses
Umami CloudVisitor counts on the public pagesCookieless page views. No identifiers, and nothing from inside the appEU
DataForSEOMeasured rank and search volume checksThe keywords and domains you track. No personal dataUS, standard contractual clauses
TelegramDelivering briefings, only if you link a chatThe briefing text you asked us to send to that chatOutside the EU, and only for accounts that use it
06

Transfers outside the EU

Hosting, storage, payments, mail and visitor analytics all stay in the European Union. Three services sit outside it: the language model, error monitoring, and Telegram for accounts that choose Telegram delivery. Each is covered by the European Commission's standard contractual clauses in that company's own processing terms.

Telegram is the one you control directly. Link no chat and nothing is ever sent there.

07

Security measures

Data is encrypted in transit and at rest. Access tokens for your sources live in a separate encrypted store, never in the tables that hold metrics, and customer identity is pseudonymised on the way in rather than cleaned up afterwards.

Access to production is limited to named staff, logged, and used for support and security investigation only. The API is rate limited, and every write checks the signed-in person's role on that specific site before it runs.

08

What we do for you as controller

The obligations Article 28 puts on a processor, in the order you are most likely to need them.

—Breach: we tell you without undue delay and within 48 hours of becoming aware, with what we know and what we are doing about it.
—Requests from your customers: if one reaches us, we point them to you and help you answer.
—Deletion and return: delete the site or the account and it happens then. Ask in writing and we confirm when it is done.
—Audit: we answer security questionnaires and provide what Article 28(3)(h) requires. An on-site audit is available where the law requires one.
—Confidentiality: everyone with production access is bound by it.
09

Changes to this list

Adding or replacing a sub-processor means an email to account owners thirty days before it carries any data, so there is time to object. Object on reasonable data protection grounds and we will either offer an alternative or let you cancel for the unused part of the term. To be on that notice list, write to info@manteiq.com.

Questions about any of this?Write to info@manteiq.com and a person answers, usually the same day.
Email us
ManteIQ - Sees the change. Helps you act.