1. Definitions and Interpretation
MonsterOps provides a way to manage your inbox and emails via the
MonsterOps website (the "Site"), the MonsterOps application
(the "App") and related Internet services (collectively, the
"Service(s)"). The Service is operated by HCG Partners GmbH
(the "Company", "we" or "us") for users
of the Service ("you"). This Privacy Policy sets forth our
policy with respect to information that is collected from visitors to
the Site and users of the App.
HCG Partners GmbH acts as both a data processor and a data controller
under the GDPR:
-
As a data processor – When we operate on your data on your behalf
(e.g. sending emails to prospects you want us to contact and follow
up on your behalf).
-
As a data controller – When we collect personal information such as
name and email address in exchange for you to use our Services.
2. Information We Collect
If you expressed consent to be contacted by us, we will store the
information you provided to our own MonsterOps account that we use as
an email marketing platform. That way, we can send you emails for
announcements, surveys, articles, and any other marketing information.
You can unsubscribe at any time (instructions are provided with each
email sent to you).
When you interact with us through the Services, we may collect
Personal Data and other information from you, as further described
below:
On the Site:
-
We use Google Analytics (https://www.google.com/analytics) as a
website analytics tool to track our site performance (number of
unique visitors, bounce rates, referrals, and other performance
indicators). The data retention is set to 26 months and we did not
allow Google to share our data.
-
We use our own pixel tracking to assess the performance of our
marketing efforts. We use cookies for that (see below). The data
retention is set to 26 months.
-
We use Crisp (https://crisp.chat/) to allow you to get in touch with
us to ask questions about the Service. We may capture some
information (like browser information and the page you were looking
at) in addition to the information you provide when reaching out
(such as your name and email address).
-
Our support tickets are then handled in Crisp, where we keep data
for 36 months to provide a greater level of service (to assist
returning visitors, train new support agents, prevent abuse of our
system and, in some cases, let you know that we have made progress
on issues that caused you to leave our Service).
-
Cookies: We employ cookies to have the above applications working
properly on the site.
- In the App:
-
We collect information from you when you voluntarily provide such
information, such as when you register for access to the Service.
Information we collect may include, but is not limited to, the first
name, last name, email address, company name, and website or other
content you add to your MonsterOps account. This information is used
to better serve you (e.g. assisting you via support or invoice
generation). We keep those data for 26 months after you cancel our
services to be able to provide invoices to past clients and prevent
abuse of our system. We may recontact you based on a legitimate
interest (e.g. the reason for cancellation was a missing feature we
developed after your cancellation).
-
Payment information is processed by Stripe (https://stripe.com,
https://stripe.com/guides/general-data-protection-regulation)
-
We use Google Analytics to track our App usage. The data retention
there is set to 26 months and we did not allow Google to share our
data.
-
Data We Collect Automatically: When you interact with us through the
Services, we receive and store certain information such as IP
address, and your activities within the Services. We may store such
information or such information may be included in databases owned
and maintained by service providers such as Amazon AWS and
Salesforce Heroku. We may use such information to help us improve
the App, assist with support, legal compliance or conflict
resolutions. The data retention is set to 3 months.
-
Aggregated Information: we may conduct research on our customers’
performance. Anonymized data may be shared with a broader audience
for marketing and educational purposes (e.g. blog articles or
speaking events). We may also disclose aggregated user statistics in
order to describe our services to current and prospective business
partners, and to other third parties for lawful purposes.
-
Information from Other Services: You may give us permission to
collect your information in other services. For example, you may
connect a social networking service (“SNS”) or Email Service
Provider such as Google, Microsoft, Facebook or LinkedIn to your
MonsterOps account. When you do this, we capture your first name,
last name and email address to prevent you from having to enter
them, as well as security tokens to allow us to provide you with the
Service (e.g. sending emails on your behalf).
-
You may decide to provide information to third parties by enabling
some add-ons. We have no control over data collection and retention
for the third-party applications you decide to enable in our App
(e.g. Zapier, BriteVerify, Close.io, Hunter.io, BuiltWith,
NeverBounce, Clearbit, Aircall…) and encourage you to check their
respective privacy policies before enabling the add-on. We may work
closely with them and exchange personal information such as name and
email to resolve issues raised by you as a support request.
-
Asking for support within the App is done using our AI. OpenAI and
Anthropic collects additional information to help us do our job
efficiently, such as the page you were looking at and your browser
information. We keep a duplication of the data for 36 months to
provide a greater level of service (to returning visitors, to train
new support agents and prevent abuse of our system).
-
Cookies: We employ cookies and similar technologies to keep track of
your local computer’s settings such as which account you have logged
into and notification settings. In addition, we use technologies
such as web beacons and single-pixel GIFs to record log data such as
open rates for emails sent by the system.
-
When you invite team members, the invitation information doesn’t
stay in our system for more than 5 days.
-
Definition: Cookies are pieces of data that sites and services can
set on your browser or device that can be read on future visits. We
may expand our use of cookies to save additional data as new
features are added to the Service.
-
All requests concerning access and modification of your data should
be sent to support@monsterops.io.
3. Where Information Is Processed
The Company is based in Switzerland. Our servers are located in the
U.S. to better serve the majority of our users. Our email support uses
Crisp and email services (G Suite), all located in the US. To use our
services or contact us, you have to consent to the processing and
transferring of your information in and to the U.S. and other
countries.
For our infrastructure, we rely primarily on Amazon AWS
(https://d1.awsstatic.com/legal/aws-gdpr/AWS_GDPR_DPA.pdf) and Heroku
(https://www.heroku.com/) with Salesforce as parent company
(https://www.salesforce.com/assets/pdf/misc/data-processing-addendum.pdf).
This allows us to transfer personal data from the EU to the US in a
compliant way.
4. Our Use of Your Information
We use the information you provide in a manner that is consistent with
this Privacy Policy. If you provide information for a certain reason,
we may use the information in connection with the reason for which it
was provided. For instance, if you contact us by email, we will use
the information you provide to answer your question or resolve your
problem. Also, if you provide information in order to obtain access to
the Services, we will use your information to provide you with access
to such services and to monitor your use of such services.
When enrolled in our lead-sharing program, you agree to have your data
used in exchange for credits that can be used to query our global
database of contacts.
5. Our Legal Bases for Handling of Your Personal Data
The laws in some jurisdictions require companies to tell you about the
legal ground they rely on to use or disclose your personal data. To
the extent those laws apply, our legal grounds are as follows:
-
To honor our contractual commitments to you: Much of our processing
of personal data is to meet our contractual obligations to our
users, or to take steps at users’ request in anticipation of
entering into a contract with them. For example, we handle personal
data on this basis to create your account and provide our Services.
-
Legitimate interests: In many cases, we handle personal data on the
ground that it furthers our legitimate interests in ways that are
not overridden by the interests or fundamental rights and freedoms
of the affected individuals. This includes: providing a safe user
experience; customer service; informing users of new feature;
protecting our users, personnel, and property; analyzing and
improving our business, e.g. collecting information about how you
use our Services to optimize the design and placement of certain
features; processing job applications; managing legal issues.
-
Legal compliance: We may need to use and disclose personal data in
certain ways to comply with our legal obligations.
-
Consent: Where required by law, and in some other cases, we handle
personal data on the basis of your implied or express consent.
6. Our Disclosure of Your Information
We are not in the business of selling your information. These are the
circumstances in which we may share some information with certain
third parties as set forth below:
- Consent: We may transfer your information with your consent.
-
Agents, Consultants and Related Third Parties: Like many businesses,
we sometimes hire other companies or individuals to perform certain
business-related functions. Examples of such functions include the
development of the application, maintaining databases and processing
payments.
-
Legal Requirements: We may disclose your information if required to
do so by law or in the good faith belief that such action is
necessary to (i) comply with a legal obligation, (ii) protect and
defend the rights or property of the Company or Related Companies,
(iii) protect the personal safety of users of the Services or the
public, or (iv) protect against legal liability.
7. Unsolicited Information
You may provide us with ideas for new products or modifications to
existing products, and other unsolicited submissions (collectively,
"Unsolicited Information"). All Unsolicited Information
shall be deemed to be non-confidential and we shall be free to
reproduce, use, disclose, and distribute such Unsolicited Information
to others without limitation or attribution.
8. Children
Our Services are targeted at users who are at least 16 years old and
owning a credit card. We do not knowingly collect personal information
from children under the age of 13. If we learn that we are engaged in
data processing with children under the age of 13, we will halt such
processing, close the account and take reasonable measures to promptly
remove applicable information from our records.
9. Links to Other Websites
This Privacy Policy applies only to the Services. The Services may
contain links to other websites not operated or controlled by us (the
"Third Party Sites"). The policies and procedures we
described here do not apply to the Third Party Sites. The links from
the Services do not imply that we endorse or have reviewed the Third
Party Sites. We suggest contacting those sites directly for
information on their privacy policies.
10. Data Retention
We will retain your information for as long as your account is active
or as needed to provide you services. When an account is closed, we
will retain and use your information up to 26 months.
Data may persist in encrypted copies made for backup and business
continuity purposes for an additional time.
11. Customer Testimonials
We post customer testimonials on our website, which may contain
Personal Data. Before posting a customer's name and testimonial,
we obtain their consent by email. To request removal of your Personal
Data from testimonials, please contact us at support@monsterops.io.
12. Security
We take reasonable steps to protect the information provided via the
Services from loss, misuse, and unauthorized access, disclosure,
alteration, or destruction. However, no Internet or email transmission
is ever fully secure or error-free. In particular, email sent to or
from the Services may not be secure. Therefore, you should take
special care in deciding what information you send to us via email.
Please keep this in mind when disclosing any information via the
Internet.
13. Your Data Rights and Choices
We believe that users should be treated equally no matter where they
are in the world, and so we are making the following options to
control your data available to all users, regardless of their
location. You can update certain information by accessing your profile
via "Settings." You can also unsubscribe from certain emails
by clicking the "unsubscribe" link they contain. You may
change your browser settings to opt out from certain cookie-related
processing. Further information about the procedure to follow in order
to disable cookies can be found on your Internet browser provider’s
website via your help screen.
You can correct, update, amendment or delete your data.
How can you access the personal data we have about you?
If you would like to submit a data access request, send
support@monsterops.io a request. We will then start the process and
provide you a link to access the personal data that we have on you
within 30 days. For your protection, we will take steps to verify
identity before responding to your request.
How can you correct, update, amend, or delete the personal data we
have about you?
In addition to the functionality available through the
"Settings" of the Services, in which you can correct,
update, amend, or delete certain personal data, you can also request
other modifications from us directly. Please write to us at
support@monsterops.io with the words "Personal Data Request"
in the subject or body of your message, along with an explanation of
what data subject right you are seeking to exercise. For your
protection, we will take steps to verify identity before responding to
your request.
14. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any
time and from time to time without prior notice. Please review this
policy periodically, and especially before you provide any
information. This Privacy Policy was last updated on the date
indicated above. Your continued use of the Services after any changes
or revisions to this Privacy Policy shall indicate your agreement with
the terms of such revised Privacy Policy.
15. Contacting Us
To report any vulnerability issue, please use
vulnerability@monsterops.io.
If you have any questions about this Privacy Policy or the information
practices of the Services. You may contact us as follows:
privacy@monsterops.io.