PDF

NetCrunch Privacy Policy

This policy explains how NetCrunch interacts with monitored systems and data within the end user’s environment, as well as optional internet-dependent features

Last Updated: April 11, 2025

1. Scope of This Policy

This privacy policy applies to NetCrunch, an on-premises or self-hosted network monitoring platform deployed and managed by end users (businesses or organizations) to monitor their infrastructure.

AdRem Software does not access, store, or process data monitored by NetCrunch.

2. Data Monitoring and Access

NetCrunch accesses data solely for operational monitoring purposes, as configured by the end user (Art. 6 Sec. 1 Letter b GDPR).

Monitored Data Includes:

  • Infrastructure Metrics: Server health, network latency, device performance, and application logs (Art. 6 Sec. 1 Letter b GDPR).
  • Email Services: Metadata (e.g., timestamps, headers) from test or real user mailboxes via IMAP4/SMTP (Art. 6 Sec. 1 Letter b GDPR). This metadata is processed locally within the end user’s NetCrunch deployment and is not transmitted to AdRem Software or used by AI features.
  • Cloud/On-Prem Resources: VM status, API metrics, and security group configurations (Art. 6 Sec. 1 Letter b GDPR).

No personal user data or sensitive content from the monitored environment is stored by NetCrunch or AdRem Software. The only exception is voluntarily transferred data files for technical support or program diagnostics, which constitute consent for processing such data (Art. 6 Sec. 1 Letters a and b GDPR).

3. Data Residency and Control

  • On-Prem/Self-Hosted Deployment: All monitored data resides within the end user’s infrastructure. NetCrunch can operate in air-gapped networks with no external connectivity.
  • Optional Internet Connectivity:
    • License Management: Periodic license validation communicates with adremsoft.com; air-gapped deployments use offline license activation.
    • Version Updates: Checks for software updates via adremsoft.com (optional). The update installation is initiated by the end user. It is not initiated automatically by NetCrunch.

4. Optional Services

The following services are disabled by default, except for bug reports and Ask AI:

a. NetCrunch Connection Cloud (NCC)

  • Purpose: Securely relay encrypted data streams between NetCrunch Server, consoles, probes, or shared dashboards.
  • Data Flow: Uses TLS 1.3 encryption via netcrunch.io.
  • No monitored data is stored or processed in the cloud. AI Explain operates on abstracted alert context only and does not receive raw monitoring telemetry or full performance datasets.

b. AI-Enhanced Alert Explanation and Diagnostics Recommendations

  • Purpose: Provides anonymized alert analysis via AI.
  • Data Flow: Sends anonymized alert context to netcrunch.io, including the metric deviation relevant to the triggered alert condition.
  • No node names, IP addresses, topology information, time-series history, credentials, or identifiers that could reveal the customer’s infrastructure are transmitted.
  • AI processing is governed by AdRem Software’s data processing agreements and does not permit model training on customer alert data.
  • The transmitted alert context is limited to technical metric deviation data and does not include identifiers of natural persons.
  • The AI functionality provides contextual explanation and recommendations only and does not perform automated decision-making that produces legal or similarly significant effects.

c. Bug Report Data Push

  • Purpose: Improve NetCrunch’s reliability and resilience by analyzing system performance.
  • Data Included:
    • Anonymized performance data related to NetCrunch program health (e.g., error codes, resource usage).
    • Name of the server where NetCrunch is installed (e.g., Server01).
    • No data from the monitored environment (e.g., customer applications, network traffic).
  • Default Setting: Enabled; users can opt out via NetCrunch settings.
  • Local Storage: If disabled, logs remain on the end user’s NetCrunch Server.

d. Ask AI (Documentation Assistant)

  • Purpose: Answers questions about how to use and configure NetCrunch, in the Help panel of the console.
  • Availability: Always available. Unlike the other services in this section, it is not disabled by default and is not separately licensed.
  • Data Flow: The question, exactly as typed, is sent to netcrunch.io and relayed to a third-party AI provider. Answers are generated from the official NetCrunch documentation and cite the source topics they were drawn from.
  • Data Included: The question text only. No atlas data, node names, IP addresses, topology, performance data, event data or credentials are transmitted, and the feature has no access to the monitored environment.
  • The AI provider does not use data submitted through its API to train or improve its models, and AdRem Software does not opt in to any such use.
  • Because the question is free text written by the operator, what it contains is under the operator's control. Ask about NetCrunch features and configuration rather than pasting host names, addresses, configuration extracts or log excerpts from the monitored environment.
  • Air-Gapped Deployments: Ask AI requires outbound connectivity. In an isolated deployment the tab remains visible and every question returns an error; no data leaves the network.

5. Data Protection

NetCrunch employs several measures to safeguard data:

  • Anonymization: Bug reports exclude identifiable details about monitored environments.
  • Encryption:
    • External connections (license checks, NCC, AI alerts, Ask AI, bug reports) use TLS 1.3.
    • Internal communication between NetCrunch components is encrypted.
  • Access Controls:
    • Integrates with Active Directory for authentication.
    • Configurable user permissions within NetCrunch.
  • Air-Gapped Deployments: Full operation without internet connectivity.

6. Secure Configuration

NetCrunch supports compliance with enterprise security standards through:

7. Data Retention

  • Monitored Data: Retained temporarily within the end user’s deployment; retention periods are user-configurable.

  • Bug Reports at AdRem Software: Retained temporarily for diagnostics and software improvement.

  • Local Bug Reports: Governed by the end user’s policies.
  • Technical Support/Diagnostics Data: Retained only for necessary diagnostic purposes.

8. Roles and Responsibilities

End User (Organization):

Acts as the data controller, determining what is monitored and managing retention/deletion policies.

AdRem Software:

Provides the NetCrunch software and optional services (NCC, AI alerts). Acts as a data processor only when optional services are enabled and uses bug reports solely to improve functionality.

9. Updates to This Policy

AdRem Software may update this policy to reflect changes in NetCrunch functionality. End users will be notified via release notes or direct communication.

10. Contact Information

For questions about NetCrunch’s data handling, contact AdRem Software at [email protected].