Privacy Policy

Effective: February 20, 2026Updated: July 14, 2026

1. Data Controller

The data controller for the purposes of GDPR is Mobness Ltd, Athanasiou Diakou 21, 3032 Limassol, Cyprus. Contact: privacy@mttrly.com

2. Information We Collect

Account Information. When you create an account, we collect your email address, name (optional), organization name (optional), and messenger identifiers for enabled channels (Telegram today; Slack/Discord limited beta; WhatsApp when available).

Payment Information. Payment data is collected and processed directly by Stripe Inc. We receive only the last four digits of your card number, card type and expiration date, billing address (if provided), and Stripe customer ID. We do not store full credit card numbers, CVV codes, or other sensitive payment data on our servers.

Server Data (Customer Data). When you connect servers to the Service, the Agent may collect:

  • System metrics (CPU, RAM, disk usage, network traffic, process lists)
  • Log file contents (within the scope you configure)
  • Service/application status information
  • Command execution outputs and results
  • Configuration file contents (when accessed during diagnostics or remediation)
  • Agent connection metadata

The scope of data collection from your servers is determined by your configuration. You control which logs, services, and metrics the Agent can access.

Usage Data. We automatically collect IP address, browser type and version, pages visited, referral sources, feature usage patterns, commands and Playbooks executed, and error logs related to Service operation.

Cookies and Tracking. Please refer to our Cookie Policy for details.

3. Legal Bases for Processing (GDPR)

Contract performance (Art. 6(1)(b) GDPR): Processing necessary to provide the Service, manage your account, and process payments.

Legitimate interests (Art. 6(1)(f) GDPR): Processing for Service improvement, security, fraud prevention, and analytics, where our interests do not override your fundamental rights.

Consent (Art. 6(1)(a) GDPR): For marketing communications and non-essential cookies. You may withdraw consent at any time.

Legal obligation (Art. 6(1)(c) GDPR): Processing required to comply with tax, accounting, or other legal requirements.

4. How We Use Your Information

  • Provide the Service: Monitor your servers, execute diagnostics and remediation, deliver alerts through your configured messengers
  • Process payments: Manage subscriptions, billing, and invoicing through Stripe
  • Communicate: Send transactional emails and, with consent, marketing communications
  • Improve the Service: Analyze usage patterns, identify bugs, optimize performance
  • Ensure security: Detect and prevent unauthorized access, abuse, or fraud
  • Comply with law: Meet tax, accounting, and regulatory obligations

5. Data Storage and Location

Infrastructure. Our primary hosted Service infrastructure is in the European Union. Customer Data stored by that infrastructure remains in EU data centers; selected request content and operational data may also be processed by the third-party providers described below, including outside the EU under the safeguards described in Section 7.

Current retention model. The hosted runtime currently applies deployment-wide, configurable cleanup windows rather than different retention periods for Watchdog, Deployment Bro, Deployment Crew, and Enterprise. Do not rely on a plan-specific 7, 30, 90, or 365-day retention promise unless it is written into a separate contract.

Audit and operational records. Audit-log cleanup currently uses one runtime setting for the deployment; the current software default is 90 days and can be changed by the operator. Agent telemetry, pending actions, public scans, authentication records, and other operational data have separate technical lifecycles. These windows describe current software behavior, not a contractual retention guarantee.

Other records. Account, payment, support, and Customer Data are kept for as long as needed to provide the Service, secure it, resolve disputes, and meet legal or accounting obligations. Where the product does not enforce an automatic deletion window, we do not imply one on this page.

To ask what currently applies to your account, request deletion, or agree a contractual retention term, contact privacy@mttrly.com. We verify the request and explain any data that must be retained by law or in backups before confirming completion.

6. Data Sharing and Third Parties

We share your data only with the following categories of recipients, and only to the extent necessary:

Service Providers:

  • Stripe Inc. (payment processing) — US-based, EU-US Data Privacy Framework certified
  • PostHog (product analytics) — EU-hosted instance
  • Google Analytics (website analytics) — with IP anonymization enabled
  • Messenger platforms (Telegram today; Slack/Discord limited beta; WhatsApp when available) — only the data you choose to send/receive

AI Providers. AI-assisted features may send your request and relevant diagnostic output to the AI provider configured for your account. With BYOK, mttrly stores and uses your encrypted provider credential to make that request and still processes the request payload to provide the Service. Without BYOK, mttrly-managed provider credentials are used. Provider retention and training terms depend on the provider and account configuration.

Legal Requirements. We may disclose information if required by law, legal process, or governmental request.

Business Transfers. In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity. We will notify you of any such transfer.

We do not sell your personal data to third parties.

Data Processing Terms. Contact privacy@mttrly.com to ask which data-processing terms and transfer safeguards apply to the providers used for your account.

7. International Data Transfers

Our primary data processing occurs within the EU. When data is transferred outside the EU (e.g., to US-based service providers), we ensure appropriate safeguards:

  • EU-US Data Privacy Framework certification (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit for hosted service connections
  • Token-authenticated outbound Agent connections over TLS/WebSocket; no inbound mttrly control port is required
  • Principle of least privilege for Agent access (dedicated service users with restricted sudo permissions)
  • Audit logging for supported Agent playbook and command execution, approval decisions, and recorded results; delivery and retention coverage depend on connectivity and runtime configuration
  • Regular security assessments
  • Access controls and authentication for internal systems
  • Incident response procedures

Despite these measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

9. Your Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Request a copy of the personal data we hold about you
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data
  • Right to Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction (Art. 18): Request restriction of processing in certain circumstances
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, machine-readable format
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting prior processing

To exercise any of these rights, contact us at privacy@mttrly.com. We will respond within the period required by applicable data-protection law.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus or your local supervisory authority.

10. Children's Privacy

The Service is not directed to individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Marketing Communications

With your consent, we may send you marketing emails about new features, tips, and promotions. You can opt out at any time by clicking the "unsubscribe" link in any marketing email, contacting privacy@mttrly.com, or updating your preferences in Account settings.

Opting out of marketing does not affect transactional communications (billing, security alerts, service updates).

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated at least 30 days in advance via email or a prominent notice on the Service. Your continued use after the effective date constitutes acceptance.

Mobness Ltd

Athanasiou Diakou 21, 3032 Limassol, Cyprus