Skip to content
MonoDuty
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
🌐 EN
  • English
  • Türkçe
  • Deutsch
  • Eesti
  • Nederlands
Log inGet Started
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
Get StartedLog in
ENTRDEETNL

Legal

GDPR Information

How MonoDuty currently handles personal data and supports requests under EU data-protection law.

Last updated: August 26, 2026

Contents

  1. 1. Scope
  2. 2. Roles
  3. 3. Purposes and Legal Bases
  4. 4. Individual Rights
  5. 5. Processing and Providers
  6. 6. International Processing
  7. 7. Retention
  8. 8. Security Measures
  9. 9. Personal Data Breaches
  10. 10. Analytics Choice
  11. 11. Children
  12. 12. Privacy Contact
  13. 13. Supervisory Authorities
  14. 14. Contact

1. Scope

This page summarizes how MonoDuty approaches the EU General Data Protection Regulation for the current Service. It supplements the Privacy Policy and does not constitute a certification or a legal conclusion that every customer use case is compliant.

2. Roles

monoduty OÜ generally acts as controller for account registration, website, security, support, and direct business communications. A customer generally determines the purpose of incident, monitoring, team, and notification data placed in its workspace; for that content, the customer may be the controller and MonoDuty may act as its processor.

Roles depend on the facts and the applicable agreement. A customer remains responsible for its own instructions, notices, lawful basis, and use of the Service.

3. Purposes and Legal Bases

Depending on the activity, MonoDuty may process personal data to perform or prepare a service agreement, pursue legitimate interests in operating and securing the Service, comply with legal obligations, or act on consent. Optional website analytics rely on the visitor’s stored analytics choice.

The applicable basis can vary by jurisdiction and context. Customers must determine the basis for data they instruct MonoDuty to process.

4. Individual Rights

Individuals may have rights of access, correction, erasure, restriction, portability, objection, withdrawal of consent, and complaint, subject to the conditions and exceptions in applicable law.

Requests can be sent to [email protected]. MonoDuty may verify identity, authority, account, and scope. If a customer controls the relevant workspace content, MonoDuty may refer the request to that customer or assist it as required. Responses follow the deadline provided by applicable law rather than an unconditional public deadline.

5. Processing and Providers

MonoDuty processes account, workspace, incident, monitoring, notification, support, browser, and security information for the purposes described in the Privacy Policy.

Current provider categories include Hetzner for server infrastructure, Cloudflare for edge services, AWS SES for email, Stripe for hosted checkout and subscription billing, Twilio for SMS/voice and verification, and Google for optional sign-in, reCAPTCHA, Tag Manager, and consented analytics. This list describes technical use; it does not claim that a separately signed processing agreement exists with every customer.

6. International Processing

The production server is currently in the European Union. Payment, communications, and Google services may process data outside the EEA. The necessary transfer analysis and safeguard depend on the provider, destination, data, and agreement.

MonoDuty does not state on this page that one adequacy decision or contractual clause covers every transfer. Customers with location or transfer requirements should request the current provider and contractual details before enabling the relevant feature.

7. Retention

Current plan-based operational retention is 7 days on Free, 30 days on Pro, and 90 days on Business for terminal incident history and specified monitor, Heartbeat, Webhook, audit, and completed outbox records. Active incidents are retained while active.

Workspace deletion has a 30-day cancellation period before active-system purge. Account, contact, authentication, delivery, and legal records do not share one universal period. Local production backup archives currently expire after 14 days. See the Privacy Policy for the operative detail.

8. Security Measures

Current measures include TLS, one-way hashing where applicable, scoped role and team authorization, input validation, rate limits, credential-field redaction, restricted production configuration, token-safe ingress logging, health monitoring, and access-restricted backups with integrity checks.

The Service does not claim application-level encryption for every stored field or backup archive. See the Security page for current limitations.

9. Personal Data Breaches

MonoDuty investigates suspected personal-data breaches, takes reasonable containment and recovery steps, preserves relevant information, and notifies affected customers, authorities, or individuals where applicable law or a binding agreement requires it.

Regulatory notification timing depends on MonoDuty’s role, the risk, when sufficient facts become known, and applicable law. This page does not add an unconditional 24- or 48-hour promise.

10. Analytics Choice

The marketing site does not load Google Tag Manager until a visitor accepts analytics. The choice is stored in the browser and can be reopened through “Cookie settings” in the footer. Choosing only necessary storage prevents analytics from loading on the next page load.

Google sign-in and reCAPTCHA are separate user-facing service or security features. Blocking them may require using email/password sign-in or contacting support through another channel. See the Cookie Policy.

11. Children

The Service is intended for organizations and authorized workplace users, not children. MonoDuty does not knowingly solicit children’s personal data. Concerns can be reported to [email protected].

12. Privacy Contact

Privacy inquiries and individual requests are currently handled through [email protected]. MonoDuty does not publish a separately appointed statutory privacy-officer contact.

If a separate appointment becomes legally required, this page and the relevant notices should be updated with that contact.

13. Supervisory Authorities

An individual may lodge a complaint with the data-protection supervisory authority available under applicable law, including the authority in the individual’s EU member state where relevant. The European Data Protection Board lists EU supervisory authorities.

Contacting MonoDuty first is welcome but does not limit the right to contact an authority.

14. Contact

Email [email protected] or use the contact form.

monoduty OÜ, registry code 17418117, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia.

Company details

Legal entity
monoduty OÜ
Legal structure
Limited company (OÜ)
Registry code
17418117 (Estonia)
Address
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Contact
[email protected]
MonoDuty

Focused incident alerting with on-call ownership and testable delivery routes.

Product

  • Features
  • Integrations
  • MonoDuty MCP
  • How it works
  • Pricing
  • Documentation
  • System status
  • Comparisons
  • vs PagerDuty
  • vs OpsGenie
  • Support

Company

  • Team
  • Careers
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • GDPR information
  • Data Processing Terms
  • Cookie Policy

Contact

  • [email protected]
  • Open a support ticket

monoduty OÜ
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Reg. 17418117

© 2026 monoduty OÜ. All rights reserved.🇪🇺 Made in EU

Your analytics choice

We use necessary browser storage for this choice. Optional analytics load only if you accept them. Cookie and storage details.