Privacy notice
Last updated 12 August 2026
GodsEye RMM is a remote monitoring and management service used by IT administrators to keep Windows computers patched, secure and supported. This notice explains what personal data it processes, why, and what rights you have. It covers the service at app.godseyermm.io and the agent software installed on managed computers.
Who is responsible
[COMPANY NAME], [REGISTERED ADDRESS], company number [NUMBER], is the controller for data about people who hold a GodsEye account.
For data collected from managed computers, the organisation whose computers they are is the controller, and we act as a processor on their instructions. If your employer manages your work computer with GodsEye, direct questions about that data to them first.
What is processed
From people who use the console:
- Email address, and the organisation and role granted to you.
- An audit record of actions taken — who deployed, uninstalled, excluded, retired or deleted what, and when. This exists so administrative actions on other people's computers are attributable, and it is deliberately not deletable by the person it records.
From each managed computer:
- The username of the person signed in at the console (in DOMAIN\user form), with the time it was observed. This is personal data, and is collected so an administrator can tell whose machine a device is.
- Computer name, operating system and build, CPU, memory, and disk usage.
- Network adapter names, MAC addresses and IP addresses.
- Installed software, versions, and available updates.
- Security posture: antivirus and firewall state, missing patches, known vulnerabilities.
- BitLocker recovery keys, so an administrator can recover an encrypted disk. These are held for the managing organisation and are the most sensitive data in the system.
The agent does not record keystrokes, capture the screen, read file contents, monitor browsing, or provide remote viewing of a computer in use.
Why, and on what basis
Account and audit data are processed for our legitimate interests in operating a secure service and keeping administrative actions accountable. Device data is processed on the instructions of the managing organisation, which relies on its own basis — normally its legitimate interest in securing and supporting the equipment it owns. None of it is used for advertising or profiling, and it is never sold.
How long it is kept
Device inventory reflects the current state and is replaced as each computer reports in. Deleting a device from the console removes its inventory, history and BitLocker keys immediately and irreversibly. Audit records are retained for [RETENTION PERIOD]. Account data is kept while the account exists and deleted within [PERIOD] of closure.
Who else is involved
We use a small number of processors to run the service: Supabase (database and authentication, hosted in the EU), [HOSTING PROVIDER] (application hosting), and Resend (sending report and notification email). Each is bound to process data only on our instructions. We do not otherwise share personal data, except where the law requires it.
Cookies
This console sets only strictly necessary cookies, so it does not ask for consent — under PECR and equivalent rules, consent is not required for cookies without which a service the user has asked for cannot work. There is no analytics, advertising or tracking cookie of any kind, and no third-party cookie.
- sb-* — your signed-in session. Without it you cannot stay signed in.
- org_scope — which organisation you are currently viewing, so the choice survives a page load.
Clearing them signs you out; nothing else is affected.
Your rights
You may ask for a copy of your personal data, correction of it, deletion, restriction of its use, or object to processing based on legitimate interests. Where we act as a processor for your employer, we will pass your request to them. Contact [PRIVACY CONTACT EMAIL]. You can also complain to your data protection regulator — in the UK, the Information Commissioner's Office at ico.org.uk.
Security
Data is encrypted in transit. Access is limited by organisation and role, and enforced by the database itself rather than only by the application. Commands sent to agents are cryptographically signed so a computer will not act on an instruction that did not come from us.
Changes
If this notice changes materially we will tell account holders. The date at the top always shows the current version.