Skip to content
MonoDuty
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
🌐 EN
  • English
  • Türkçe
  • Deutsch
  • Eesti
  • Nederlands
Log inGet Started
  • Features
  • Integrations
  • Pricing
  • Documentation
  • Contact
Get StartedLog in
ENTRDEETNL

Legal

Privacy Policy

What personal information MonoDuty currently processes, why it is used, and how to make a request.

Last updated: August 26, 2026

Contents

  1. 1. Overview
  2. 2. Information We Process
  3. 3. Purposes
  4. 4. Service Providers and Disclosures
  5. 5. Security
  6. 6. Retention and Deletion
  7. 7. Cookies and Browser Storage
  8. 8. Third-Party Services
  9. 9. International Processing
  10. 10. Privacy Rights
  11. 11. Children
  12. 12. Policy Changes
  13. 13. Contact

1. Overview

This Privacy Policy describes how monoduty OÜ (“MonoDuty”, “we”, “us”) processes personal information when people visit the website, create an account, use a customer workspace, receive alerts, or contact support.

MonoDuty may act as a controller for account, website, security, and support information and as a processor for customer-controlled incident and monitoring content. The role depends on the processing activity and the applicable agreement.

2. Information We Process

2.1 Account, workspace, and contact information

We process information a person or customer provides, including name, email address, optional phone number and profile image, authentication identifiers, organization and team details, notification destinations and preferences, and support communications. Contact-form submissions include the submitted name, email, company, topic, message, locale, source IP address, and browser user-agent.

2.2 Incident and monitoring information

We process customer-configured services, teams, schedules, escalation policies, Heartbeats, Monitors, incident details, notification status, and related operational records. Heartbeat requests may record request time, source IP address, and user-agent. Monitor checks record configured targets, results, timing, and state.

2.3 Webhook information

Webhook JSON is validated before processing. MonoDuty stores cryptographic payload and idempotency hashes and converts selected fields into an incident title, description, source, and bounded metadata. Known credential fields in stored metadata are redacted. Application ingestion records do not retain raw HTTP headers, source IP addresses, user-agents, or a replayable raw payload. Customers should still avoid sending unnecessary sensitive data.

2.4 Website and security information

We process request and error records, timestamps, IP addresses, browser details, authentication events, and security/audit events as needed to operate and protect the Service. Optional website analytics are loaded only after the visitor accepts analytics storage. Google sign-in and the contact form involve information sent to Google when those features load.

2.5 Billing information

Stripe processes payment details entered in its hosted Checkout and billing portal. MonoDuty processes customer and subscription identifiers, selected plan, billing period, user quantity, and payment or subscription status to administer paid access. Payment-card details are entered directly with Stripe.

3. Purposes

MonoDuty uses information to provide and administer accounts and workspaces; route, deliver, and record alerts; operate Heartbeats and Monitors; authenticate users; prevent abuse; apply access and usage controls; administer subscriptions and payments; respond to support requests; diagnose failures; maintain audit and security records; meet legal obligations; and improve the Service.

Website analytics are used only after the visitor’s analytics choice permits them.

4. Service Providers and Disclosures

MonoDuty does not sell personal information. Information is disclosed only as needed to operate the current Service, follow customer instructions, protect the Service, complete a lawful corporate transaction, or comply with law.

4.1 Current provider categories

  • Hetzner — production server infrastructure and local storage
  • Cloudflare — DNS, edge proxying, transport protection, and abuse mitigation
  • AWS SES — transactional email delivery
  • Stripe — hosted checkout, subscription billing, payment processing, and the billing portal
  • Twilio — SMS, voice, and destination verification when those channels are enabled
  • Google — optional sign-in, contact-form abuse protection, Tag Manager, and consented website analytics

The exact provider, product, and location may change. A customer evaluating regulated or paid processing should request the current contractual provider schedule before relying on it.

5. Security

Current safeguards include TLS on public endpoints, one-way password and secret hashing where applicable, scoped workspace and team permissions, request validation, rate limits, credential-field redaction, restricted production configuration, health monitoring, and access-restricted backups with integrity checks.

MonoDuty does not represent the current database or backup archives as application-encrypted at rest. No technical measure removes all risk; customers must protect issued tokens and avoid placing unnecessary sensitive data in alert payloads.

6. Retention and Deletion

The current automated retention task applies a workspace plan period of 7 days on Free, 30 days on Pro, and 90 days on Business to resolved, closed, or deleted incident history and to specified operational records. Open, acknowledged, and investigating incidents remain available while active. Raw monitor results, Heartbeat request/event records, Webhook ingestion hashes, workspace audit records, and completed operational-outbox records are also pruned under the plan period.

A workspace owner may schedule workspace deletion with a 30-day cancellation period. After that period, the workspace and its active-system records are eligible for permanent purge. Deleting a workspace does not necessarily delete a person’s account if it is used elsewhere.

Account, contact, authentication, delivery, and legally required records do not currently have one universal published period. Production backup archives are currently retained locally for 14 days; deletion from active systems may therefore take additional time to age out of protected copies. Verified privacy requests and mandatory legal holds may change the applicable timing.

7. Cookies and Browser Storage

The marketing site stores an analytics choice in browser local storage. It does not load Google Tag Manager until analytics are accepted. The application uses a Secure, HttpOnly API-origin cookie for its browser session; the active workspace selection, display theme, and a short-lived navigation return path remain in local storage.

Google sign-in and reCAPTCHA can use Google-controlled cookies or browser storage when those features load. See the Cookie Policy for the current keys, purposes, and controls.

8. Third-Party Services

Third-party providers process information under their own terms and privacy notices in addition to MonoDuty’s instructions. Links to an external website do not make that website part of the Service.

Customers should review provider terms relevant to their use, particularly before placing regulated or sensitive information in notification destinations or payloads.

9. International Processing

The production server is currently in the European Union. Some providers, including payment, communications, and Google services, may process information in other countries.

Transfer safeguards depend on the provider, destination, processing activity, and applicable agreement. This page does not claim that one transfer mechanism covers every transfer. Customers that require a particular location or safeguard should request the current contractual details before using the relevant feature.

10. Privacy Rights

Depending on the applicable law and MonoDuty’s role, a person may have rights to access, correct, erase, restrict, or receive certain personal information, object to processing, withdraw consent, or complain to a supervisory authority.

Requests can be sent to [email protected]. MonoDuty may ask for information reasonably needed to verify identity, authority, account, and scope. Customer-controlled content requests may be referred to the customer that controls the workspace. Requests are handled within the period required by applicable law; no comprehensive self-service privacy-request tool is promised.

11. Children

The Service is intended for organizations and people authorized to act for them, not for children. MonoDuty does not knowingly solicit children’s personal information. If you believe a child has provided personal information, contact [email protected] so the circumstances can be reviewed.

12. Policy Changes

MonoDuty may update this Policy when the Service, providers, or legal requirements change. The current version and date are published on this page. Additional notice is provided when required by law or a written customer agreement.

13. Contact

Privacy questions and requests can be sent to [email protected] or through the contact form.

monoduty OÜ, registry code 17418117, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia.

Company details

Legal entity
monoduty OÜ
Legal structure
Limited company (OÜ)
Registry code
17418117 (Estonia)
Address
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Contact
[email protected]
MonoDuty

Focused incident alerting with on-call ownership and testable delivery routes.

Product

  • Features
  • Integrations
  • MonoDuty MCP
  • How it works
  • Pricing
  • Documentation
  • System status
  • Comparisons
  • vs PagerDuty
  • vs OpsGenie
  • Support

Company

  • Team
  • Careers
  • Contact

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • GDPR information
  • Data Processing Terms
  • Cookie Policy

Contact

  • [email protected]
  • Open a support ticket

monoduty OÜ
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Reg. 17418117

© 2026 monoduty OÜ. All rights reserved.🇪🇺 Made in EU

Your analytics choice

We use necessary browser storage for this choice. Optional analytics load only if you accept them. Cookie and storage details.