Overview
This Data Processing Agreement (the "DPA") governs how Monirum processes Personal Data on behalf of a customer organisation (the "Customer") when that Customer uses Monirum to manage their team, workspace, or operations.
This DPA forms part of the Terms of Service. By accepting the Terms of Service and using Monirum to process Personal Data on behalf of your organisation, you accept this DPA on behalf of that organisation and represent that you have authority to do so. Where this DPA conflicts with the Terms of Service for matters of data protection, this DPA controls.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Monirum on behalf of the Customer in connection with the Monirum service.
- "Data Subject" means the natural person to whom the Personal Data relates — typically a Customer employee, team member, contractor, or end customer.
- "Controller" means the Customer, who determines the purposes and means of processing Personal Data.
- "Processor" means Monirum, acting on behalf of the Customer.
- "Sub-processor"means any third party engaged by Monirum to process Personal Data on the Customer's behalf — listed in Annex B.
- "Data Protection Laws" means GDPR, UK GDPR, Saudi PDPL, UAE Federal Decree-Law 45/2021, and other applicable privacy laws.
- "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data.
2. Scope of processing
Monirum processes Personal Data only:
- To deliver the Monirum service to the Customer — provisioning workspaces, delivering invites, recording activity, running KPIs, time logs, inbox messages, and team operations.
- In accordance with the Customer's documented instructions (the Terms of Service, this DPA, and the way the Customer configures their workspace).
- To comply with applicable law (in which case Monirum will inform the Customer unless legally prohibited).
Monirum will not sell Personal Data, use it for advertising, or use it to train generative AI models. The categories of Personal Data and Data Subjects are listed in Annex A.
3. Monirum's obligations
As Processor, Monirum will:
- Process Personal Data only on the Customer's documented instructions.
- Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures to secure Personal Data — see Annex C.
- Engage Sub-processors only on the terms set out in Section 4 and Annex B.
- Reasonably assist the Customer in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection).
- Reasonably assist the Customer with data-protection impact assessments and consultations with supervisory authorities.
- Notify the Customer of Personal Data Breaches without undue delay (see Section 7).
- Delete or return Personal Data at the end of the service per Section 9.
- Make available the information needed to demonstrate compliance with this DPA (see Section 8).
4. Sub-processors
The Customer authorises Monirum to engage the Sub-processors listed in Annex B, each of which is contractually bound to data-protection terms no less protective than those in this DPA.
Monirum may add or replace Sub-processors. When that happens, Monirum will update Annex B and (for material changes) email the Customer's account owner with at least 30 days' notice. If the Customer reasonably objects on data-protection grounds, the Customer may terminate the service for the affected portion, in accordance with the Terms of Service.
Monirum remains liable to the Customer for any Sub-processor's acts and omissions that breach this DPA.
5. International transfers
Some Sub-processors store or process Personal Data outside the country of the Customer or the Data Subject. Where the law requires safeguards for such transfers, Monirum relies on:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into the Monirum–Sub-processor contracts.
- Equivalent transfer mechanisms recognised by the Customer's and the Data Subject's jurisdiction (for example, the UK International Data Transfer Addendum).
- Other safeguards required by applicable Data Protection Laws.
Where the Customer is established in a region that requires the SCCs to be signed directly between Customer and Monirum, the Customer is deemed to have entered into the relevant SCCs with Monirum by accepting this DPA, with Monirum acting as data exporter where applicable.
6. Security measures
Monirum implements and maintains the technical and organisational measures set out in Annex C, designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure or access.
Monirum regularly reviews and updates its security measures. The Customer acknowledges that no security system can guarantee absolute protection, but Monirum commits to security practices appropriate to the risk and the nature of the Personal Data processed.
7. Personal data breaches
Monirum will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 72 hours after becoming aware of it.
The notification will include, to the extent known:
- The nature of the Personal Data Breach, including categories and approximate number of Data Subjects and Personal Data records concerned.
- The likely consequences of the Personal Data Breach.
- Measures taken or proposed to be taken to address the breach and mitigate possible adverse effects.
- The name and contact details of a Monirum point of contact.
Monirum will reasonably cooperate with the Customer's investigation and response, including helping the Customer comply with notification obligations to supervisory authorities and Data Subjects where required.
8. Audit and cooperation
Monirum will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA. On reasonable request, Monirum will respond to written privacy questionnaires from the Customer or its data-protection officer within a reasonable time.
The Customer may audit Monirum's compliance with this DPA no more than once per twelve (12) months, during normal business hours, with at least 30 days' advance written notice, and subject to confidentiality and reasonable security restrictions. Where the Customer's right to audit is met by an independent third-party audit report or industry certification, the Customer agrees to rely on that instead.
The Customer pays its own audit costs. Monirum's reasonable internal costs of supporting the audit are billable at agreed rates if the audit extends beyond two business days of Monirum staff time.
9. Term and deletion
This DPA takes effect when the Customer accepts the Terms of Service and remains in effect for as long as Monirum processes Personal Data on behalf of the Customer.
On termination of the service or on the Customer's written request, Monirum will, at the Customer's choice:
- Return all Personal Data to the Customer in a structured, commonly-used, machine-readable format; or
- Delete all Personal Data from Monirum's production systems.
Personal Data in routine system backups will be deleted in accordance with the hosting provider's backup retention window. Monirum may retain Personal Data to the extent required by law, and will continue to protect it under this DPA until deletion.
Provisions that should naturally outlive this DPA — including confidentiality, breach notification for incidents that occurred during the term, audit support for the prior 12 months, liability, and governing law — survive termination.
10. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA excludes or limits liability that cannot be excluded or limited under applicable law, including liability arising from gross negligence, wilful misconduct, or breach of statutory data-protection obligations to a Data Subject.
Annex A — Description of processing
A.1 Subject matter
The provision of the Monirum service to the Customer — a workspace for team operations, including tasks, KPIs, time tracking, inbox messaging, members and team directories, and Amazon product research.
A.2 Nature and purpose of processing
- Hosting, storing and serving the Customer's workspace content.
- Authenticating users and enforcing role-based access.
- Sending service notifications (sign-in emails, security alerts, downtime notices).
- Surfacing AI-assisted summaries and recommendations when the user invokes them.
- Maintaining audit and activity records of administrative events.
- Providing technical support to the Customer.
A.3 Duration
For the duration of the Customer's use of the service plus the deletion window described in Section 9.
A.4 Categories of Data Subjects
- Employees, contractors, and team members of the Customer organisation.
- Administrators and account owners of the Customer organisation.
- Other people the Customer chooses to record in workspace content (for example, suppliers, third-party contacts, or end-customer references inside tasks or inbox messages).
A.5 Categories of Personal Data
- Identity data: name, email address, public user ID, optional profile photo.
- Authentication data: hashed password, Google or Microsoft OAuth identifiers, session tokens.
- Profile and role data: workspace role (Owner, Co-Admin, Member), team memberships, role labels, joined and last-active timestamps.
- Activity data: IP address, browser and operating system, pages visited, timestamps, and entries in the workspace activity log (joins, role changes, removals).
- User-generated content: tasks, KPIs, time logs, inbox messages, comments, files and attachments uploaded by the Data Subject or the Customer.
A.6 Special category data
Monirum is not designed to process special categories of personal data (health, racial or ethnic origin, religion, biometric data, etc.). The Customer agrees not to submit special category data into the service except where strictly necessary and lawful.
Annex B — Sub-processors
Monirum engages the following Sub-processors. Each is bound by data-protection terms no less protective than this DPA.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | EU region |
| Vercel, Inc. | Application hosting, CDN, edge runtime | Global edge |
| Anthropic, PBC | AI features (Claude API) | United States |
| EasyParser | Public Amazon product data (no Customer Personal Data is sent) | Primarily United States |
EasyParser receives only public Amazon product identifiers (ASINs, URLs) and does not receive Customer Personal Data. It is listed here for transparency.
Annex C — Technical and organisational security measures
C.1 Access control
- Authentication via Supabase Auth, including email/password and OAuth (Google, Microsoft).
- Passwords stored hashed with bcrypt — never in plaintext.
- Row-level security (RLS) enforced at the database layer for every read and write, scoped to the workspace and user.
- Workspace-role based authorisation (Owner, Co-Admin, Member) for administrative actions.
- Production system access is restricted to a small number of authorised engineers and audited.
C.2 Encryption
- Encryption in transit using TLS 1.2 or higher.
- Encryption at rest provided by the underlying hosting and database providers.
C.3 Logging and monitoring
- Application and infrastructure logs from Vercel and Supabase.
- Workspace activity log capturing joins, role changes, removals, and similar administrative events.
C.4 Backups and resilience
- Database backups managed by the hosting provider per their published retention window.
- Stateless application tier deployed on a managed platform with built-in failover.
C.5 Incident response
- Defined process to investigate, contain, and remediate Personal Data Breaches.
- Customer notification within 72 hours of confirmation, as set out in Section 7.
C.6 Personnel
- Personnel with access to Customer Personal Data are bound by written confidentiality obligations.
- Access is granted on a need-to-know basis and revoked when no longer required.
Contact us
Data-protection questions, DPA execution requests, or sub-processor inquiries — send us a message via the Help Center and choose Security or privacy issue as the topic.