MANTIS Privacy Policy

Effective date: 1 April 2026
Last updated: 13 April 2026


1. Who We Are

MANTIS is operated by Navio Maritime OÜ, a company registered in Estonia.

For the purposes of the General Data Protection Regulation (GDPR), Navio Maritime OÜ is the data processor. Your organisation (the vessel owner, manager, or operator subscribing to MANTIS) is the data controller.

Where users create individual accounts directly, Navio Maritime OÜ acts as a joint controller for account-related data.


2. What Data We Collect

2.1 Account Information

2.2 Vessel Data

2.3 IHM Compliance Data

2.4 Usage Data

We do not collect IP addresses for analytics. We do not use third-party analytics services.


3. Why We Collect This Data

Data categoryPurposeLegal basis (GDPR)
Account informationTo create and manage your user account, authenticate you, and communicate service updatesContract performance — Art. 6(1)(b)
Vessel dataTo provide the IHM compliance management serviceContract performance — Art. 6(1)(b)
IHM compliance dataCore service functionality: tracking hazardous materials, generating compliance reports, maintaining audit historyContract performance — Art. 6(1)(b)
Usage dataTo maintain service reliability, identify bugs, and improve the productLegitimate interest — Art. 6(1)(f)

We do not process personal data for marketing purposes without separate, explicit consent.


4. Where Your Data Is Stored

All data is stored within the European Union.

No data is transferred outside the EU/EEA during normal operation.


5. Data Retention


6. Third-Party Sub-Processors

We use the following third-party services to operate MANTIS. Each processes data only as necessary to provide their service.

Sub-processorServiceData processedLocation
Supabase IncDatabase, authentication, file storageAll application dataEU (Frankfurt)
Cloudflare IncApplication hosting and CDNHTTP requests, static assetsEU edge network
Sendinblue SAS (Brevo)Transactional emailEmail addresses, notification contentEU

We do not sell, rent, or share your data with any other third parties. We do not use advertising networks or third-party tracking services.


7. Your Rights Under GDPR

You have the following rights regarding your personal data:

To exercise any of these rights, contact privacy@mantis-ihm.com. We will respond within 30 days.


8. Cookies

MANTIS uses only essential cookies required for the application to function:

We do not use:

No cookie consent banner is required because we only use strictly necessary cookies as defined by the ePrivacy Directive.


9. International Data Transfers

All data processing occurs within the EU/EEA. We do not transfer personal data to countries outside the EU/EEA.

If this changes in the future, we will ensure appropriate safeguards are in place (such as Standard Contractual Clauses) and update this policy accordingly.


10. Security Measures

We implement the following technical and organisational measures to protect your data:


11. Children’s Data

MANTIS is a business-to-business service for maritime compliance management. We do not knowingly collect data from anyone under the age of 16. If we become aware that we have collected personal data from a child, we will delete it promptly.


12. Changes to This Policy

We may update this privacy policy from time to time. When we make material changes:


13. Contact

For any questions about this privacy policy or our data practices:

Email: privacy@mantis-ihm.com
Company: Navio Maritime OÜ, Estonia
Web: mantis-ihm.com

For security concerns, contact security@mantis-ihm.com.