SupportRMM
← Back to site

Privacy Policy

Effective date: 9 September 2026  ·  Controller: SUPPORTRMM TECHNOLOGIES S.R.L.  ·  Contact: contact@supportrmm.com
ℹ SupportRMM is designed around a self-hosted operational-data model. Endpoint monitoring content stays in the customer-controlled SupportRMM environment. Provider cloud services process only the limited licensing, security, anti-abuse, update, recovery and commerce metadata described below.

1. Who we are

SUPPORTRMM TECHNOLOGIES S.R.L. is the controller for the Provider-side processing described in this policy. We are registered in Romania, with registered office at Str. Walter Mărăcineanu, Bl. 14, Sc. A, Et. 2, Ap. 9, 825300 Măcin, Jud. Tulcea, Trade Register no. J2026038323003, CUI 54883393, VAT ID RO54883393. Contact: contact@supportrmm.com.

2. Self-hosted operational data

SupportRMM is designed so that normal fleet-management content is stored on the customer's own Server and managed endpoints. This includes, for example, endpoint names, health metrics, process information, Windows/security events, scripts and script output, USB activity, network information, configuration and other operational records generated by normal RMM use.

This operational content is not uploaded as general telemetry to the Provider licensing backend. Limited technical metadata needed for licensing, anti-abuse, update and recovery functions is processed separately as described in Section 3.

3. Technical data processed by Provider services

Provider services process the minimum technical information reasonably required to authorise licences, protect evaluation access against repeated abuse, coordinate supported recovery, deliver release information, and maintain an audit trail of security-sensitive state changes.

Data categoryTypical formPurpose
Installation and deployment identifiersOpaque generated identifiersAssociate a licence with an authorised SupportSDK/Server installation and maintain continuity
Server hardware-backed identityStable cryptographic/hashed identity; no private key materialLicence authorisation, replacement protection and recovery continuity
Managed-endpoint identity observationsApproved stable hashes or equivalent non-secret identity evidenceDemo anti-abuse correlation and fleet continuity
Fleet, licence and commercial stateOpaque IDs, state values, authorisation sequence, timestampsDemo/paid lifecycle, revocation, replacement, audit and support
Public network / request contextIP address or limited connection metadata where requiredSecurity, abuse prevention, recovery continuity, request audit and normal network operation
Software/release informationVersion and compatibility metadataUpdate and compatibility decisions
Recovery coordination metadataGeneration/status identifiers, cryptographic public identifiers and audit stateCoordinate supported Server recovery without storing ordinary fleet-monitoring content in Provider cloud services

We do not store TPM private keys, TPM authorisation values, private signing keys, reusable authentication secrets, or raw payment-card data in the SupportRMM licensing backend.

Anti-abuse controls may retain historical identity observations, state transitions and related audit evidence after a Demo expires or is suspended where reasonably necessary to detect repeated evaluation abuse and defend the licensing system. The precise detection rules and thresholds are security-sensitive and are not published.

4. Server recovery and distributed backup

Where the distributed recovery feature is enabled for a paid Server, encrypted backup material is distributed within the customer's managed fleet according to the product's recovery design. Provider services may process limited recovery coordination, licence, hardware-identity and network-continuity metadata needed to validate a legitimate replacement Server. Provider cloud services are not intended to store the customer's ordinary plaintext fleet backup or monitoring history.

5. Purchases and Lemon Squeezy

When commercial checkout is provided through Lemon Squeezy, Lemon Squeezy acts as Merchant of Record and processes checkout, billing, payment, tax, refund and chargeback information under its own terms and privacy notice. SupportRMM may receive order and fulfilment metadata needed to provision and support the purchased licence, such as order/customer identifiers, customer name and email, company/VAT information where supplied, product/variant, currency, amounts, payment/refund status and purchase timestamps.

SupportRMM does not receive or store the customer's full payment-card number from Lemon Squeezy checkout.

6. Lawful bases

Depending on the processing activity, our lawful bases may include:

7. Data retention

Retention depends on purpose. Active licence/installation records are retained while needed to provide and protect the entitlement. Security, anti-abuse and audit records may be retained after Demo expiry or suspension for a reasonable period where necessary to detect repeated abuse, investigate disputes and protect the service. Commercial/accounting data is retained as required by applicable law and Merchant-of-Record processes. Data that is no longer required is deleted, anonymised, or allowed to expire according to the applicable retention policy.

8. Service providers and international transfers

Provider-side licensing, anti-abuse and recovery services use Cloudflare infrastructure. Commercial purchases may use Lemon Squeezy as Merchant of Record and its payment providers. Support correspondence may pass through our configured email providers.

These providers may process data in jurisdictions outside Romania or the EEA subject to their applicable data-protection terms and transfer safeguards.

9. Your GDPR rights

Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, objection and portability, subject to the conditions and exceptions in applicable law. In particular, an erasure request may be limited where retention is necessary for legal obligations, establishment/defence of claims, or legitimate anti-fraud/security purposes.

To exercise your rights, contact contact@supportrmm.com. You may also lodge a complaint with the Romanian supervisory authority (ANSPDCP) or another competent supervisory authority.

10. Website, cookies and communications

The public supportrmm.com site does not currently use analytics cookies or third-party advertising trackers. If you choose to open a third-party checkout or contact us by email, the relevant provider will process the data necessary for that interaction under its own privacy terms.

11. Security

We use technical and organisational controls intended to limit the data processed by Provider services and to protect security-sensitive material. No system can guarantee absolute security. Customers remain responsible for securing their own SupportRMM Server, administrator accounts, endpoints and network environment.

12. Changes to this policy

We may update this policy as the product and its service providers evolve. The current version is published at supportrmm.com/privacy with the effective date shown above.

13. Contact

Privacy and data-protection queries: contact@supportrmm.com