The Article 28 terms that apply when ManteIQ reads data on your behalf, and the full list of companies involved.
Two roles, and which one applies decides whose obligations these are. For the business data ManteIQ reads out of the sources you connect, your shop, Search Console, Analytics and Ads, you are the controller and MB Mante strategy is your processor. We read it on your instruction and for no other purpose.
For your own account data, meaning name, email, billing details, the Telegram chat and sign-in records, MB Mante strategy is the controller. That side is covered by the privacy policy, not by this agreement.
It is incorporated into the terms of service by reference, so it is in force from the moment you use ManteIQ for a business. No signature is needed. If your procurement process requires a countersigned copy, write to info@manteiq.com with your entity name and registered address and you will have one back, usually the same day.
Subject matter: reading the accounts you connect and turning what they report into briefings, dashboards, alerts, exports and answers inside ManteIQ. The nature of the processing is collection, storage, aggregation and presentation. It is read-only at every source.
Duration: for as long as your account is open. Delete a connection and its credentials are destroyed at once. Delete a site or the account and the stored metrics go with it, immediately rather than on a thirty-day timer.
Purpose: your business data produces your reporting and nothing else. It is not sold, not pooled with another customer's data, not used to train models, and never used to contact your customers.
ManteIQ is built to hold as little personal data as the metrics allow, and most of what it reads is not personal data at all.
All of them, with what each one can see. Google is deliberately not on this list: the data moves from your Google account to ManteIQ, which makes Google your source rather than our sub-processor.
| Sub-processor | What it does | What it can see | Where |
|---|---|---|---|
| Hostinger International | Application hosting, the database, outbound mail | All service data at rest, and the recipients and content of transactional mail | EU |
| Stripe Payments Europe | Subscriptions, credit packs, invoices | Your name, email, billing address and card details, which Stripe holds and we never see | EU, Ireland |
| Anthropic | The model that writes briefings and answers in Ask | The metrics and question text needed for one answer. Not retained for training | US, standard contractual clauses |
| Sentry | Error monitoring | Diagnostics from a failure: account id, request path, stack trace | US, standard contractual clauses |
| Umami Cloud | Visitor counts on the public pages | Cookieless page views. No identifiers, and nothing from inside the app | EU |
| DataForSEO | Measured rank and search volume checks | The keywords and domains you track. No personal data | US, standard contractual clauses |
| Telegram | Delivering briefings, only if you link a chat | The briefing text you asked us to send to that chat | Outside the EU, and only for accounts that use it |
Hosting, storage, payments, mail and visitor analytics all stay in the European Union. Three services sit outside it: the language model, error monitoring, and Telegram for accounts that choose Telegram delivery. Each is covered by the European Commission's standard contractual clauses in that company's own processing terms.
Telegram is the one you control directly. Link no chat and nothing is ever sent there.
Data is encrypted in transit and at rest. Access tokens for your sources live in a separate encrypted store, never in the tables that hold metrics, and customer identity is pseudonymised on the way in rather than cleaned up afterwards.
Access to production is limited to named staff, logged, and used for support and security investigation only. The API is rate limited, and every write checks the signed-in person's role on that specific site before it runs.
The obligations Article 28 puts on a processor, in the order you are most likely to need them.
Adding or replacing a sub-processor means an email to account owners thirty days before it carries any data, so there is time to object. Object on reasonable data protection grounds and we will either offer an alternative or let you cancel for the unused part of the term. To be on that notice list, write to info@manteiq.com.