1. Introduction
This Privacy Policy explains how Metanoia AS ("Metanoia", "we", "us", or "our") collects, uses, stores, and protects personal data in connection with the NET Backup Vault platform and related services.
NET Backup Vault is a cloud-based platform for backup, restore, monitoring, export, and configuration management of Cisco Meraki environments.
This Privacy Policy applies to:
- Website visitors
- Trial users
- Customers
- Customer administrators
- Authorised users of NET Backup Vault
2. Company Information
Metanoia AS
3. Roles Under Data Protection Law
Depending on the situation, Metanoia may act as:
- Data controller for account, billing, support, platform, and website data
- Data processor when processing customer data on behalf of customers through NET Backup Vault
Where required, processing activities are governed by a separate Data Processing Agreement (DPA).
4. Information We Collect
4.1 Account and Organisation Data
- Name
- Email address
- Organisation name
- Account role and permissions
- Authentication-related information
- Subscription and billing information
4.2 Platform Usage Data
- Login activity
- IP addresses
- Device and browser information
- Audit logs
- User actions
- Backup activity
- Restore activity
- Configuration change history
- System usage metrics
4.3 Cisco Meraki-Related Data
NET Backup Vault may process:
- Configuration backups
- Network names
- Device names
- Network configuration settings
- Firewall configuration
- VLAN configuration
- Wireless configuration
- Routing and switching settings
- Metadata related to managed environments
The scope of processed data depends on customer configuration, enabled features, available Cisco Meraki APIs, and customer permissions.
4.4 Website and Communication Data
- Contact form submissions
- Support requests
- Email communication
- Website usage information
- Cookies and analytics data
5. How We Use Information
We use information to:
- Provide and operate NET Backup Vault
- Authenticate users
- Perform backups and restore operations
- Maintain audit logs
- Provide support
- Improve reliability and security
- Monitor system health and abuse
- Process subscriptions and billing
- Communicate with customers
- Comply with legal obligations
We do not sell customer data.
6. Legal Basis for Processing
Depending on the situation, we process personal data based on performance of a contract, legitimate interests, legal obligations, and consent where required.
Legitimate interests may include service security, fraud prevention, abuse prevention, platform improvement, operational monitoring, and customer support.
7. Data Retention
7.1 Active Accounts
Backup retention depends on the selected customer plan. Unless otherwise stated, the default backup retention period is 12 months. Audit logs and operational logs may be retained as required for operational, legal, or security purposes.
7.2 After Cancellation or Termination
Customer account data, configuration backups, logs, and related service data may be retained for up to 30 days unless a longer retention period is required by law, dispute handling, security obligations, or written agreement.
After the retention period, data may be permanently deleted. Customers are responsible for exporting required data before termination takes effect.
8. Subprocessors and Third-Party Services
Metanoia uses third-party providers to operate NET Backup Vault. Current subprocessors may include Microsoft Azure, Render.com, and Anthropic. These providers may process limited data necessary to provide hosting, infrastructure, support, monitoring, or related platform functionality.
Full details are available on the Subprocessors page.
Metanoia remains responsible for managing subprocessors in accordance with applicable data protection obligations.
9. International Transfers
NET Backup Vault is primarily hosted within the EU/EEA. Certain subprocessors or services may involve processing outside the EU/EEA where permitted under applicable law and appropriate safeguards.
10. Security Measures
Metanoia implements reasonable technical and organisational measures designed to protect customer data. Security measures may include:
- Encryption in transit
- Encryption at rest
- Access controls
- Role-based permissions
- Audit logging
- Monitoring and alerting
- Secrets management
- Restricted internal access
No system can be guaranteed to be completely secure or uninterrupted.
11. AI-Related Processing
NET Backup Vault does not use customer configuration backups to train public AI models.
If AI-assisted functionality is introduced in NET Backup Vault, additional disclosures or settings may be provided where required.
12. Cookies and Analytics
The Metanoia website or NET Backup Vault platform may use essential cookies, authentication cookies, security-related cookies, and analytics technologies.
Cookies may be used to maintain sessions, improve platform functionality, monitor reliability and usage, and improve user experience.
Additional cookie information may be provided separately where required.
13. Your Rights
Subject to applicable law, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Request deletion of data
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent where processing is based on consent
Requests may be sent to [email protected].
14. Customer Responsibilities
Customers are responsible for:
- Ensuring they have authority to connect Cisco Meraki environments
- Managing internal user access
- Reviewing restore operations
- Configuring retention policies appropriate for their organisation
- Complying with applicable laws and internal policies
15. Changes to This Privacy Policy
Metanoia may update this Privacy Policy from time to time. Material updates may be communicated through NET Backup Vault, by email, or through the Metanoia website.
Continued use of NET Backup Vault after updates become effective constitutes acceptance of the updated Privacy Policy.
16. Contact Information
Metanoia AS