MANTIS Privacy Policy
Effective date: 1 April 2026
Last updated: 13 August 2026
Version: 2026-08-13
1. Who We Are
MANTIS is operated by Navio Maritime OÜ, a company registered in Estonia.
- Registered name: Navio Maritime OÜ
- Registry number: 17461120
- Country: Estonia
- Registered address: Ahtri tn 12, 15551 Tallinn, Kesklinna linnaosa, Harju maakond, Estonia
- Contact: privacy@mantis-ihm.com
- Website: mantis-ihm.com
For customer-provided vessel and IHM records, Navio Maritime OÜ acts as a data processor and the subscribing organisation (the vessel owner, manager, or operator) is the data controller.
Navio Maritime OÜ acts as the data controller for website inquiries, requested sample downloads, optional marketing, account administration, billing, security, and its own service communications. Where a subscribing organisation also determines how account-related personal data is used, the parties may each have controller responsibilities for their respective processing activities.
2. What Data We Collect
2.1 Account Information
- Full name
- Email address
- Password (stored as a bcrypt hash; we never store or have access to plaintext passwords)
- Organisation membership and role
- MFA/TOTP enrolment status
2.2 Vessel Data
- Vessel name
- IMO number
- Flag state
- Gross tonnage (GT)
- Vessel type and classification
2.3 IHM Compliance Data
- Inventory of Hazardous Materials (IHM) Part I, II, and III records
- Material descriptions, locations, quantities, and hazard classifications
- Supplier declarations and supporting documentation
- Compliance status and check history
- Uploaded files (certificates, declarations, survey reports)
2.4 Usage Data
- Last login timestamp
- Pages viewed within the application
- Feature usage patterns (aggregated)
- Marketing conversion source, CTA location, and allowlisted campaign tags
- Browser type and screen resolution (for compatibility purposes only)
We do not send IP addresses as analytics properties or retain them in analytics profiles. PostHog GeoIP enrichment is disabled. Hosting and network providers may process an IP address transiently to deliver and secure an HTTP request. Where analytics services are used, they operate in cookieless mode with no personally identifiable information (see Section 6).
2.5 Website Inquiries and Sample Downloads
- Name and work email
- Company and role
- Optional fleet-size range
- The website page from which a form was submitted
- Optional marketing-consent choice
3. Why We Collect This Data
| Data category | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account information | To create and manage your user account, authenticate you, and communicate service updates | Contract performance — Art. 6(1)(b) |
| Vessel data | To provide the IHM compliance management service | Contract performance — Art. 6(1)(b) |
| IHM compliance data | Core service functionality: tracking hazardous materials, generating compliance reports, maintaining audit history | Contract performance — Art. 6(1)(b) |
| Usage data | To maintain service reliability, identify bugs, and improve the product | Legitimate interest — Art. 6(1)(f) |
| Website inquiries and requested downloads | To answer inquiries, deliver requested sample material, and understand commercial interest in MANTIS | Responding to your request and legitimate interest — Art. 6(1)(b) and Art. 6(1)(f) |
| Optional product updates | To send occasional MANTIS product information when you have separately opted in | Consent — Art. 6(1)(a) |
We do not process personal data for marketing purposes without separate, explicit consent.
4. Where Your Data Is Stored
MANTIS configures its primary application data stores in the European Union:
- Database, authentication, and file storage: Supabase, with the MANTIS project hosted on AWS eu-central-1 (Frankfurt, Germany)
- Encrypted database exports: Cloudflare R2, configured with an EU location preference
- Application delivery: Cloudflare’s global edge network
Primary IHM records and uploaded evidence are stored in the Frankfurt project. Some providers are headquartered outside the EU/EEA or operate global support, security, delivery, or control-plane systems. Those providers may process limited personal data outside the EU/EEA under the transfer safeguards described in Section 9. Current providers and their roles are maintained in the Service Provider Register.
5. Data Retention
- Active accounts: Your data is retained for the duration of your subscription
- Cancelled subscriptions: Access continues until the end of the current paid billing period. That date is the service termination date unless a separate customer agreement states otherwise
- After termination: Customer Personal Data is held only for export/return or reactivation during a maximum 30-day transition window, then deleted from production systems. You may request earlier deletion. Limited records may be retained where applicable law requires it (for example, invoices and tax records)
- Automated backups: Database backup copies age out under the 30-day operational backup rotation. Uploaded Storage files are not currently included in the independent R2 database-export backup; see the Trust Centre for the current recovery scope
- Deletion requests: You may request immediate deletion of your data at any time by contacting privacy@mantis-ihm.com. We will process deletion requests within 30 days
- Website inquiries and sample requests: Retained only as long as needed to respond, manage the commercial relationship, or meet applicable record-keeping requirements. Optional marketing contacts remain subscribed until they unsubscribe or withdraw consent.
6. Third-Party Providers
We use the following services to operate, secure, bill for, and understand MANTIS. The provider’s role depends on the processing: some act as sub-processors for Customer Personal Data, while others process personal data for MANTIS’s own account administration, billing, or website analytics. Microsoft documents Clarity as acting as a separate controller for its optional marketing-site analytics.
| Provider | Service | Data processed | Location |
|---|---|---|---|
| Supabase Inc | Database, authentication, file storage, edge functions | Application and account data | Primary storage: EU (Frankfurt); limited international processing may occur under its DPA |
| Cloudflare Inc | Application hosting, CDN, DNS, abuse protection, Turnstile, encrypted database-export storage | HTTP request data, security signals, static assets, encrypted export files | Global edge network; R2 configured with EU location preference; international processing under its DPA |
| Sendinblue SAS (Brevo) | Transactional email | Email addresses and notification content | EU-based provider; see provider register for current processing details |
| Stripe Payments Europe Ltd | Subscription billing and payment processing | Billing contact, subscription and payment data (card details are processed by Stripe directly and are never stored by MANTIS) | Stripe’s global infrastructure; protected under its DPA and applicable transfer safeguards |
| Functional Software Inc (Sentry) | Application error monitoring | Error events, stack traces, technical context, and identifiers that may appear in error context | MANTIS EU data region (Germany); limited international processing may occur under its DPA |
| PostHog Inc | Product and conversion analytics | In-memory anonymous UUID, feature events, source page, CTA location, allowlisted campaign tags, and non-identifying sample-download categories — no email, name, company, cookies, session recording, or IP-derived geolocation | MANTIS EU project; limited international processing may occur under its DPA |
| Plausible Insights OÜ | Aggregate web analytics (marketing site only) | Page views and referrers; no cookies or persistent visitor profiles. IP addresses are processed transiently to produce aggregate metrics and are not stored | EU |
| Cal.com Inc | Call scheduling | Details you choose to provide when booking a call | Provider-hosted service; international transfers are governed by Cal.com’s privacy terms |
| Microsoft Clarity | Heatmaps and session replay (marketing site only; Microsoft acts as a separate controller) | Website interaction data; sets cookies and loads only with your consent | Microsoft Ireland Operations Limited for EU visitors, with international transfers under Microsoft’s stated safeguards |
We do not sell or rent your data or use advertising networks. Data is shared only for the stated operational, billing, scheduling, security, and analytics purposes. The current role and transfer information for each provider is maintained in the Service Provider Register. Customers are notified at least 30 days in advance of a new or replacement Customer Personal Data sub-processor, with a right to object under the DPA. Stripe, PostHog, Plausible, Cal.com, and Clarity support processing for which MANTIS acts as controller, rather than processing Customer Personal Data on a customer’s behalf under the DPA.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15) — Request a copy of all personal data we hold about you
- Right to rectification (Art. 16) — Request correction of inaccurate data
- Right to erasure (Art. 17) — Request deletion of your personal data
- Right to data portability (Art. 20) — Receive your data in a structured, machine-readable format. MANTIS provides in-app exports for inventory records and full archive exports designed to include uploaded evidence documents.
- Right to restrict processing (Art. 18) — Request that we limit how we use your data
- Right to object (Art. 21) — Object to processing based on legitimate interest
- Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time
- Right to lodge a complaint — You may file a complaint with your national Data Protection Authority. For Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
To exercise any of these rights, contact privacy@mantis-ihm.com. We will respond within 30 days.
8. Cookies and local storage
The MANTIS application stores your authentication session in your browser’s localStorage, not in cookies, and its analytics (PostHog, in-memory) and traffic measurement (Plausible) are cookieless. We do not use advertising cookies or cross-site tracking. Cloudflare may set strictly-necessary performance cookies for DDoS protection.
On our marketing site only, Microsoft Clarity (heatmaps and anonymised session replay) sets cookies. It is not loaded unless you opt in via the cookie banner shown on your first visit. You can accept or reject it, and change your choice at any time using the “Cookie settings” link in the site footer. Rejecting means Clarity never loads and no Clarity cookies are set; the cookieless analytics above continue regardless.
9. International Data Transfers
MANTIS keeps its primary application database and uploaded-file storage in the EU. Because several service providers operate internationally, limited personal data may be accessed or processed outside the EU/EEA for service delivery, security, support, billing, or control-plane operations.
Where personal data is transferred outside the EU/EEA, MANTIS relies on an applicable adequacy decision, the EU Standard Contractual Clauses, the EU–US Data Privacy Framework where available, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. Provider-specific information is available in the Service Provider Register. Microsoft Clarity remains optional and consent-gated on the marketing site.
10. Security Measures
We implement the following technical and organisational measures to protect your data:
- AES-256 encryption at rest
- TLS 1.2+ encryption in transit
- PostgreSQL Row Level Security ensuring data isolation between organisations, vessels, and shared-access grants
- Multi-factor authentication (MFA/TOTP)
- Bcrypt password hashing with per-user salts
- Rate-limited authentication endpoints
- Session timeout after inactivity
- Audit trail for data modifications, archive actions, exports, and billing lifecycle events
- Automated daily encrypted database exports with 30-day retention
11. Children’s Data
MANTIS is a business-to-business service for maritime compliance management. We do not knowingly collect data from anyone under the age of 16. If we become aware that we have collected personal data from a child, we will delete it promptly.
12. Changes to This Policy
We may update this privacy policy from time to time. When we make material changes:
- We will notify all registered users by email at least 30 days before the changes take effect
- The updated policy will be published within the application with the new effective date
- Continued use of MANTIS after the effective date constitutes acceptance of the updated policy
13. Contact
For any questions about this privacy policy or our data practices:
Email: privacy@mantis-ihm.com
Company: Navio Maritime OÜ, registry number 17461120
Registered address: Ahtri tn 12, 15551 Tallinn, Kesklinna linnaosa, Harju maakond, Estonia
Web: mantis-ihm.com
For security concerns, contact security@mantis-ihm.com.