SUPPORTRMM TECHNOLOGIES S.R.L. is the controller for the Provider-side processing described in this policy. We are registered in Romania, with registered office at Str. Walter Mărăcineanu, Bl. 14, Sc. A, Et. 2, Ap. 9, 825300 Măcin, Jud. Tulcea, Trade Register no. J2026038323003, CUI 54883393, VAT ID RO54883393. Contact: contact@supportrmm.com.
SupportRMM is designed so that normal fleet-management content is stored on the customer's own Server and managed endpoints. This includes, for example, endpoint names, health metrics, process information, Windows/security events, scripts and script output, USB activity, network information, configuration and other operational records generated by normal RMM use.
This operational content is not uploaded as general telemetry to the Provider licensing backend. Limited technical metadata needed for licensing, anti-abuse, update and recovery functions is processed separately as described in Section 3.
Provider services process the minimum technical information reasonably required to authorise licences, protect evaluation access against repeated abuse, coordinate supported recovery, deliver release information, and maintain an audit trail of security-sensitive state changes.
| Data category | Typical form | Purpose |
|---|---|---|
| Installation and deployment identifiers | Opaque generated identifiers | Associate a licence with an authorised SupportSDK/Server installation and maintain continuity |
| Server hardware-backed identity | Stable cryptographic/hashed identity; no private key material | Licence authorisation, replacement protection and recovery continuity |
| Managed-endpoint identity observations | Approved stable hashes or equivalent non-secret identity evidence | Demo anti-abuse correlation and fleet continuity |
| Fleet, licence and commercial state | Opaque IDs, state values, authorisation sequence, timestamps | Demo/paid lifecycle, revocation, replacement, audit and support |
| Public network / request context | IP address or limited connection metadata where required | Security, abuse prevention, recovery continuity, request audit and normal network operation |
| Software/release information | Version and compatibility metadata | Update and compatibility decisions |
| Recovery coordination metadata | Generation/status identifiers, cryptographic public identifiers and audit state | Coordinate supported Server recovery without storing ordinary fleet-monitoring content in Provider cloud services |
We do not store TPM private keys, TPM authorisation values, private signing keys, reusable authentication secrets, or raw payment-card data in the SupportRMM licensing backend.
Anti-abuse controls may retain historical identity observations, state transitions and related audit evidence after a Demo expires or is suspended where reasonably necessary to detect repeated evaluation abuse and defend the licensing system. The precise detection rules and thresholds are security-sensitive and are not published.
Where the distributed recovery feature is enabled for a paid Server, encrypted backup material is distributed within the customer's managed fleet according to the product's recovery design. Provider services may process limited recovery coordination, licence, hardware-identity and network-continuity metadata needed to validate a legitimate replacement Server. Provider cloud services are not intended to store the customer's ordinary plaintext fleet backup or monitoring history.
When commercial checkout is provided through Lemon Squeezy, Lemon Squeezy acts as Merchant of Record and processes checkout, billing, payment, tax, refund and chargeback information under its own terms and privacy notice. SupportRMM may receive order and fulfilment metadata needed to provision and support the purchased licence, such as order/customer identifiers, customer name and email, company/VAT information where supplied, product/variant, currency, amounts, payment/refund status and purchase timestamps.
SupportRMM does not receive or store the customer's full payment-card number from Lemon Squeezy checkout.
Depending on the processing activity, our lawful bases may include:
Retention depends on purpose. Active licence/installation records are retained while needed to provide and protect the entitlement. Security, anti-abuse and audit records may be retained after Demo expiry or suspension for a reasonable period where necessary to detect repeated abuse, investigate disputes and protect the service. Commercial/accounting data is retained as required by applicable law and Merchant-of-Record processes. Data that is no longer required is deleted, anonymised, or allowed to expire according to the applicable retention policy.
Provider-side licensing, anti-abuse and recovery services use Cloudflare infrastructure. Commercial purchases may use Lemon Squeezy as Merchant of Record and its payment providers. Support correspondence may pass through our configured email providers.
These providers may process data in jurisdictions outside Romania or the EEA subject to their applicable data-protection terms and transfer safeguards.
Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, objection and portability, subject to the conditions and exceptions in applicable law. In particular, an erasure request may be limited where retention is necessary for legal obligations, establishment/defence of claims, or legitimate anti-fraud/security purposes.
To exercise your rights, contact contact@supportrmm.com. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP) or another competent supervisory authority.
The public supportrmm.com site does not currently use analytics cookies or third-party advertising trackers. If you choose to open a third-party checkout or contact us by email, the relevant provider will process the data necessary for that interaction under its own privacy terms.
We use technical and organisational controls intended to limit the data processed by Provider services and to protect security-sensitive material. No system can guarantee absolute security. Customers remain responsible for securing their own SupportRMM Server, administrator accounts, endpoints and network environment.
We may update this policy as the product and its service providers evolve. The current version is published at supportrmm.com/privacy with the effective date shown above.
Privacy and data-protection queries: contact@supportrmm.com