Privacy policy.
We respect your privacy. This page describes what data Maintoro collects, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR) and similar laws.
1 Β· Who we are
Maintoro OΓ ("Maintoro", "we", "us") is a private limited company registered in Estonia (registry code 16735423), with its registered office at Tallinn, Estonia. We build and operate the Maintoro CMMS platform β a SaaS application for maintenance teams, available at maintoro.com.
For the purposes of GDPR, Maintoro is the controller of personal data submitted via our public website and marketing communications, and a processor of the personal data that our customers upload into the application.
2 Β· Data we collect
We collect only what we need to operate the service. There are three categories:
Account & identity
- Name, email address, password (hashed with bcrypt), profile photo (optional)
- Organization name, role, and language preference
- Phone number if you choose to add one for SMS notifications
Operational data (entered by you)
- Work orders, preventive maintenance schedules, asset records, parts inventory
- Photos, comments, and documents you attach to work orders or assets
- QR code & NFC tag scan events (anonymized for unauthenticated scans)
Technical & usage data (collected automatically)
- IP address, browser type, device type, operating system, timezone
- Pages visited, features used, error logs (for debugging and abuse prevention)
- Cookies & local storage (see cookies section)
3 Β· How we use your data
We use your data to:
- Operate the service β authenticate you, deliver work orders, sync mobile data, generate reports
- Communicate with you β send work order notifications, security alerts, billing receipts, and occasional product updates (you can opt out anytime)
- Improve the product β aggregated usage analytics, feature performance, bug reports
- Protect the service β detect abuse, prevent fraud, enforce our Terms of Service
- Comply with law β respond to lawful requests from authorities
We never sell or rent your personal data. We never train AI models on your private operational data without explicit, opt-in consent.
4 Β· Legal basis for processing
Under GDPR Art. 6, we process personal data on one or more of these grounds:
- Contract β processing is necessary to provide the service you signed up for
- Legitimate interests β product improvement, security, fraud prevention
- Consent β marketing emails, optional analytics cookies (you can withdraw consent at any time)
- Legal obligation β tax records, regulatory compliance
6 Β· How long we keep data
- Active accounts β for as long as your subscription is active
- Cancelled accounts β 60 days grace period, then deleted (you can request immediate deletion)
- Backups β up to 30 days after deletion (then automatically purged)
- Billing records β 7 years (Estonian tax law)
- Anonymized usage analytics β up to 24 months
7 Β· Your rights under GDPR
If you are in the EU/EEA (and equivalent for the UK, Switzerland), you have the right to:
- Access the personal data we hold about you
- Rectify data that is incorrect or incomplete
- Erase your personal data ("right to be forgotten")
- Restrict how we process your data
- Object to processing based on legitimate interests
- Data portability β export your data in JSON or CSV at any time
- Withdraw consent at any time, where consent is the basis for processing
- Lodge a complaint with your local supervisory authority (in Estonia: aki.ee)
To exercise any right, email privacy@maintoro.com. We respond within 30 days.
8 Β· Security
We take security seriously and apply industry-standard controls:
- TLS 1.3 for all data in transit; AES-256 for data at rest
- Daily encrypted backups with off-site replication
- Two-factor authentication (TOTP, optional and recommended)
- Role-based access controls inside the application
- SOC 2 Type II audit in progress (target: Q4 2026)
- Annual third-party penetration tests
- Security incident response plan; we notify affected customers within 72 hours of a confirmed breach
10 Β· Childrenβs privacy
Maintoro is a B2B SaaS product not intended for children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11 Β· International data transfers
All Maintoro production data is hosted in the EU (AWS Frankfurt, eu-central-1). For sub-processors that may transfer data outside the EU (e.g. Stripe, Twilio), we rely on the European Commissionβs Standard Contractual Clauses (SCCs) and only work with vendors offering equivalent protection.
12 Β· Changes to this policy
We will update this policy if our practices change. The "Last updated" date at the top of this page reflects the most recent revision. For material changes affecting how we use your personal data, we will notify active customers by email at least 30 days before the changes take effect.
13 Β· Contact us
Privacy questions, data requests, or concerns:
Tallinn, Estonia
Reg. 16735423