Skip to content
MonoDuty
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
🌐 EN
  • English
  • Türkçe
  • Deutsch
  • Eesti
  • Nederlands
Log inGet Started
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
Get StartedLog in
ENTRDEETNL

Legal

Data Processing Terms

A public description of the processing terms that must be confirmed in the applicable customer agreement.

Last updated: August 26, 2026

Contents

  1. 1. Status of This Page
  2. 2. Definitions
  3. 3. Processing Scope
  4. 4. Customer Responsibilities
  5. 5. MonoDuty Responsibilities
  6. 6. Service Providers
  7. 7. International Processing
  8. 8. Security Measures
  9. 9. Breach Cooperation
  10. 10. Individual Requests
  11. 11. Assurance Requests
  12. 12. End of Service
  13. 13. Contact

1. Status of This Page

This page describes intended data-processing terms for MonoDuty’s current Service. It is not evidence of an executed customer-specific document and does not state that these terms satisfy every customer’s Article 28 requirements.

Where MonoDuty processes personal data for a customer as processor, the binding terms are those accepted or executed by authorized parties in the applicable customer agreement. Customers should contact [email protected] before paid or regulated processing to confirm the current terms.

2. Definitions

“Controller”, “processor”, “personal data”, “processing”, “data subject”, and “supervisory authority” have the meanings given by applicable data-protection law. “Customer” means the organization that controls a MonoDuty workspace. “Provider” means a third party used to operate part of the Service.

3. Processing Scope

MonoDuty processes personal data to provide workspace access, incident management, HTTP Webhook ingestion, email/SMS/voice alert delivery, schedules, escalation policies, Heartbeats, Monitors, access control, support, and audit/security records.

Data subjects may include customer staff, responders, administrators, and people identified by customer-provided content. Data may include account and contact details, authentication identifiers, team membership, incident content and metadata, notification destinations and status, usage records, and security logs. Processing continues for the service term and the applicable retention or deletion period.

4. Customer Responsibilities

The customer is responsible for lawful instructions, required notices, the accuracy and necessity of submitted data, permissions for notification destinations, handling requests where it is controller, and compliance with laws that apply to its use.

The customer must not send special-category data, passwords, private keys, payment-card data, or other unnecessary sensitive information through alerts or Webhooks unless the parties have first documented a lawful and technically appropriate arrangement.

5. MonoDuty Responsibilities

To the extent required by applicable law and the binding customer agreement, MonoDuty processes customer personal data on documented instructions; limits access to authorized purposes; applies the measures described on the Security page; assists with individual requests and breach information reasonably available to it; and returns or deletes data at the end of service subject to lawful retention and backup expiry.

Any confidentiality, assistance, documentation, or regulator-cooperation commitment is governed by applicable law and the binding agreement, not by an unsupported operational claim.

6. Service Providers

Current provider categories include Hetzner for server infrastructure, Cloudflare for edge services, AWS SES for email, Stripe for hosted checkout and subscription billing, Twilio for SMS/voice and verification, and Google for optional sign-in, reCAPTCHA, Tag Manager, and consented analytics.

Authorization, notice, and objection terms for provider changes must be set in the binding customer agreement. Customers may request the current contractual provider schedule before entering a paid agreement.

7. International Processing

The production server is currently in the European Union, while some payment, communications, and Google services may process information elsewhere. Transfer requirements and safeguards depend on the destination, provider, data, and applicable agreement.

MonoDuty does not represent one mechanism as covering every transfer. Any required mechanism and supplementary measure must be confirmed in the binding customer agreement and provider schedule.

8. Security Measures

Current measures include TLS, one-way password and secret hashing where applicable, scoped access control, validation and rate limits, credential-field redaction, restricted production configuration, health monitoring, and access-restricted local backups with integrity checks and restore testing.

The current service is a single-host deployment and does not claim application-level encryption of all stored data or backups, geographic redundancy, enterprise federated sign-in, a formal certification, or a continuously staffed security center. Material customer-specific measures must be agreed in writing.

9. Breach Cooperation

MonoDuty investigates suspected personal-data breaches and provides affected customers with information reasonably available to support their legal obligations. Notice is given without undue delay where applicable law or the binding agreement requires it.

This page does not create an unconditional 24- or 48-hour deadline. The binding agreement should define contacts, required content, timing, and cooperation appropriate to the processing.

10. Individual Requests

MonoDuty assists customers with access, correction, erasure, restriction, portability, and objection requests to the extent required by applicable law and the binding agreement.

Requests are submitted to [email protected]. MonoDuty may verify identity, authority, account, and scope. No comprehensive self-service privacy-request control is promised.

11. Assurance Requests

MonoDuty provides information and reasonable cooperation needed to demonstrate processor obligations where applicable law or the binding agreement requires it, subject to protection of other customers, security-sensitive information, and confidentiality.

This page does not grant an unrestricted on-site inspection right, promise a third-party report, or state that MonoDuty holds a formal certification. Scope, notice, cost, frequency, and alternatives must be set in the binding agreement.

12. End of Service

After service ends, MonoDuty stops processing customer data except where retention is required by law, needed to protect the Service, present in backups awaiting expiry, or allowed by the binding agreement.

A customer may request a machine-readable copy or deletion through [email protected]. Available format, verification, timing, and scope depend on the current product capability, applicable law, and binding agreement; no comprehensive customer-operated privacy tool is promised.

13. Contact

Questions about processing terms can be sent to [email protected].

monoduty OÜ, registry code 17418117, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia.

Company details

Legal entity
monoduty OÜ
Legal structure
Limited company (OÜ)
Registry code
17418117 (Estonia)
Address
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Contact
[email protected]
MonoDuty

Focused incident alerting with on-call ownership and testable delivery routes.

Product

  • Features
  • Integrations
  • MonoDuty MCP
  • How it works
  • Pricing
  • Documentation
  • System status
  • Comparisons
  • vs PagerDuty
  • vs OpsGenie
  • Support

Company

  • Team
  • Careers
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • GDPR information
  • Data Processing Terms
  • Cookie Policy

Contact

  • [email protected]
  • Open a support ticket

monoduty OÜ
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Reg. 17418117

© 2026 monoduty OÜ. All rights reserved.🇪🇺 Made in EU

Your analytics choice

We use necessary browser storage for this choice. Optional analytics load only if you accept them. Cookie and storage details.