Service Provider Register
Version: 1.0
Last updated: 13 August 2026
This register explains which third parties support MANTIS, why we use them, and how their role relates to Customer Personal Data. “Customer Personal Data” has the meaning given in the Data Processing Agreement.
Customer Personal Data sub-processors
These providers may process personal data on behalf of a MANTIS customer when Navio Maritime OÜ acts as that customer’s processor.
| Provider | Purpose | Personal data involved | Primary region | International-transfer position |
|---|---|---|---|---|
| Supabase Inc | Database, authentication, file storage, and edge functions | Account data, application records, uploaded evidence, and technical metadata | MANTIS project: AWS eu-central-1, Frankfurt | The selected project region is the primary storage and processing location. Limited access or processing may occur where Supabase or its sub-processors operate, under its DPA and applicable transfer safeguards. |
| Cloudflare Inc | Application delivery, CDN, DDoS protection, DNS, Turnstile abuse prevention, and encrypted database-export storage | Request metadata, security signals, static assets, and encrypted database-export files | Global edge network; R2 configured with an EU location preference | Cloudflare operates a global network. International processing is governed by its DPA and applicable transfer safeguards. |
| Sendinblue SAS (Brevo) | Transactional email | Recipient address and notification content, which may include a user or vessel name | EU-based provider | Processing is governed by Brevo’s DPA. Any international processing by its sub-processors is subject to the safeguards stated there. |
| Functional Software Inc (Sentry) | Error and crash monitoring | Stack traces, technical context, and identifiers that may appear in error context | MANTIS EU data region, Germany | The MANTIS project uses Sentry’s EU data region. Limited international access or processing may occur under Sentry’s DPA and applicable transfer safeguards. |
Other service providers
The following providers support processing for which Navio Maritime OÜ acts as controller, such as billing, scheduling, product analytics, or marketing-site analytics. They are not engaged to process Customer Personal Data on a customer’s behalf under the MANTIS DPA.
| Provider | Purpose | Data involved | Processing information |
|---|---|---|---|
| Stripe Payments Europe Ltd | Subscription billing and payments | Billing contact, subscription information, payment status, and payment details entered directly into Stripe | Stripe operates internationally. Its DPA and privacy terms describe the applicable transfer safeguards. MANTIS does not store card numbers or CVV. |
| PostHog Inc | Cookieless product and conversion analytics | In-memory anonymous UUID and allowlisted feature, source, CTA, campaign, and categorical event data | The MANTIS project uses PostHog’s EU host. Identified profiles, persistent analytics storage, autocapture, geolocation, and PostHog session recording are disabled. |
| Plausible Insights OÜ | Aggregate marketing-site analytics | Page views and referrers; IP addresses are processed transiently to produce aggregate metrics and are not stored | EU-hosted, cookieless aggregate analytics with no persistent visitor profiles. |
| Cal.com Inc | Scheduling calls requested by a visitor | Contact details and booking information entered by the visitor | Cal.com is a US provider. Its privacy terms describe its role and international-transfer safeguards. |
| Microsoft Ireland Operations Limited / Microsoft Corporation | Optional marketing-site heatmaps and session replay | Website interaction data and cookies | Loads only after visitor consent. Microsoft documents Clarity as a separate controller and describes its international-transfer safeguards in its privacy terms. |
Data residency and transfers
The primary MANTIS database and uploaded-file storage are configured in Frankfurt, Germany. Encrypted database exports use Cloudflare R2 with an EU location preference. An EU primary region does not mean that every provider operation is confined to the EU: global delivery, fraud prevention, security, support, or control-plane access may involve international processing.
For transfers outside the EU/EEA, MANTIS relies on an applicable adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework where available, or another lawful transfer mechanism, together with supplementary safeguards where appropriate.
Changes and objections
MANTIS will notify affected customers at least 30 days before authorising a new or replacement Customer Personal Data sub-processor. A customer may object on reasonable data-protection grounds during that notice period, as described in the DPA. Changes to providers used only for MANTIS-controlled billing, scheduling, security, or analytics will be reflected in this register and the Privacy Policy.
Questions, objections, and requests for current provider documentation can be sent to privacy@mantis-ihm.com.