AI Monks
HomePortalIndustriesUse casesPartnersHow it worksAboutContact
Get protected →
HomePortalIndustriesUse casesPartnersHow it worksAboutContactGet protected →
Legal

AI Monks — Privacy Policy

Version 1.0 · Effective 2 September 2026

Version 1.0 · Effective 2 September 2026

Controller: AI Monks Group B.V., registered with the Dutch Chamber of Commerce (KVK) under number 42132024, [registered office address], Amsterdam, the Netherlands ("AI Monks", "we", "us").
Privacy contact: privacy@ai-monks.io

This policy explains how we handle personal data when you visit ai-monks.io, use the AI Monks Portal, communicate with us, work with us as a partner, or appear in the data our Service processes. It is written for businesses and the people who work at them. We do not offer our services to consumers.

Contents

  1. 1. Who this policy covers
  2. 2. Our role: controller or processor
  3. 3. What we process, why, and on what basis
  4. 4. Data we obtain indirectly through the Service
  5. 5. AI in the Service
  6. 6. Partners and resellers
  7. 7. Who we share data with
  8. 8. International transfers
  9. 9. How long we keep data
  10. 10. Security and privacy by design
  11. 11. Your rights
  12. 12. Cookies
  13. 13. Marketing communications
  14. 14. Automated decision-making
  15. 15. Children
  16. 16. Changes to this policy
  17. 17. Contact and complaints
  18. Annex — Sub-processors

1. Who this policy covers

  • Website visitors — anyone visiting ai-monks.io.
  • Prospects and subscribers — people who contact us, request information, or subscribe to our updates.
  • Portal users — the person who opens a Customer account and any team members invited to it.
  • Partner contacts — people working at our partners and resellers, and at their customers.
  • People in Service Data — individuals whose data appears in the externally observable information our Service collects about a Customer's internet-facing infrastructure (see section 4).

2. Our role: controller or processor

For the website, Portal accounts, billing, support, marketing and partner relationships, AI Monks is the controller: we decide why and how the data is processed.

For personal data contained in a Customer's own Monitored Targets and account content, we act as processor on the Customer's behalf under the Data Processing Agreement that forms part of our Terms of Service. The Customer is the controller of that data; questions about it should go to the Customer first.

For Service Data we generate or collect ourselves when operating the Service — including data received from third-party data providers and telemetry from our own monitoring infrastructure — we are the controller, to the extent that data contains personal data.

3. What we process, why, and on what basis

PurposeDataLegal basis (art. 6 GDPR)
Providing the website and keeping it secureIP address, browser and device information, request logsLegitimate interest (operating and securing our website)
Responding to enquiriesName, work email, phone, company, message contentLegitimate interest (responding to a request you made); contract where the enquiry leads to one
Opening and managing a Portal accountName, work email, phone, job title, company name, company address, company website, login credentials, account settingsContract (Terms of Service)
Invited team membersName, work email, phone, job title, role in the accountContract with the Customer; legitimate interest in providing the account the Customer requested
BillingName, email, billing address, VAT number, payment status. Card details are entered directly with our payment provider; we do not store themContract; legal obligation (tax and accounting records)
Providing the ServiceAccount data, Monitored Targets designated by the Customer, alerts and reports, usage dataContract
Support and in-app messagingName, email, conversation content, account and technical contextContract; legitimate interest (resolving issues)
Product analytics and improvementUsage events tied to an account, error reportsLegitimate interest (understanding how the Portal is used and improving it)
Security, fraud and abuse preventionLog data, IP addresses, account activityLegitimate interest (protecting the Service, our Customers and ourselves)
Marketing communicationsName, work email, company, interaction with our messagesConsent, or legitimate interest for existing customers (section 13)
Partner and reseller relationshipsContact details of partner staff; customer and lead data exchanged with partners (section 6)Contract with the partner; legitimate interest (managing the partnership)
Legal claims and complianceAny of the above as relevantLegitimate interest (establishing, exercising or defending claims); legal obligation

Where we rely on legitimate interest we have assessed that our interest is not overridden by yours. You can ask us for a summary of that assessment and you can object (section 11).

Providing account and billing data is necessary to open and keep an account; without it we cannot provide the Service.

4. Data we obtain indirectly through the Service

The Service observes a Customer's externally visible infrastructure: domains, hosts, certificates, DNS and mail configuration, and risk signals about them. Most of this is data about systems, not people. Some of it can relate to an identifiable person — for example a technical contact in public registration records or an administrator's address in a mail configuration.

We obtain this data from public sources, from our own non-intrusive monitoring, and from third-party data providers that specialise in external cyber risk data. We process it solely to provide cyber risk monitoring and reporting to the Customer that designated the target, and to operate and improve the Service. We do not use it to profile individuals, to market to them, or for any other purpose.

We do not contact individuals whose data appears in Service Data, because we generally cannot identify them without disproportionate effort and because the data relates to their role in an organisation's infrastructure rather than to them personally. This policy is how we inform them (art. 14(5)(b) GDPR). Anyone who believes their data appears in our Service Data can contact privacy@ai-monks.io and exercise the rights in section 11.

5. AI in the Service

We use AI models from third-party providers in two places:

  • Support and in-app messaging run on Intercom, including its AI assistant, which may answer questions using your conversation and account context.
  • Portal features such as explanations of findings and recommended fixes are generated using models from Anthropic (Claude) and Google (Gemini). The input consists of technical findings and, where needed, account context; we minimise personal data in these requests.

Our contracts with these providers prohibit them from using your data to train their models. AI output in the Portal is informational; the Terms of Service describe its status. No decision with legal or similarly significant effect on an individual is taken by AI (section 14).

6. Partners and resellers

We sell the Service directly and through partners and resellers. In that relationship:

  • A partner may pass a customer's or lead's contact and company details to us so that we can open an account, provide the Service, or follow up on an introduction.
  • We may share with the referring partner the account status, subscription details, and contact details of the customers it introduced, so that the partner can support them and manage its relationship with us.

Each party is an independent controller for its own use of this data. Our partners are bound by contract to handle it in line with data-protection law. We do not sell personal data, and we do not share a customer's data with a partner that did not introduce it unless the customer asks us to.

7. Who we share data with

  • Service providers (processors) that host our infrastructure, process payments, deliver email, provide support tooling, CRM, analytics and AI features. They act on our instructions under data-processing agreements. The current list is in the Annex.
  • Third-party data providers that supply external cyber risk data. We send them the domains and other technical identifiers of Monitored Targets — not the names or contact details of Customer staff.
  • Partners and resellers as described in section 6.
  • Professional advisers (legal, accounting, audit) under confidentiality.
  • Authorities where we are legally required to, or to protect our rights or the security of our Service.
  • A buyer or successor in a merger, acquisition or reorganisation, under confidentiality and this policy.

8. International transfers

We host the Portal and its data in the European Union. Some of our service providers are established in, or provide support from, the United States or other countries outside the European Economic Area. Where that is the case we transfer data only on a lawful basis: the EU-US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses together with an assessment of the transfer. The mechanism used for each provider is listed in the Annex. You can request a copy of the relevant safeguards via privacy@ai-monks.io.

9. How long we keep data

We keep personal data no longer than needed for the purpose it was collected for, and then delete or anonymise it.

DataRetention
Portal account and user dataFor the Subscription, plus a 30-day export window; then deleted from active systems within 90 days
Service Data (monitoring data, alerts, reports)For the Subscription; personal data within archived data is deleted or anonymised in line with our retention schedule and the Data Processing Agreement
Billing records and invoices7 years (Dutch tax law)
Support conversations24 months after the conversation is closed
Website and security logs12 months
Enquiries and prospect data (CRM)24 months after our last contact, unless a relationship follows
Marketing subscriptionsUntil you unsubscribe or 24 months of inactivity
Partner contact dataFor the partnership, plus 24 months

Where a legal claim, investigation or legal duty requires it, we keep data for as long as that requires.

10. Security and privacy by design

We build the Service with privacy as a design requirement rather than an afterthought. In practice this means:

  • we collect only what a purpose needs, and the Service is designed around data about systems rather than people;
  • personal data in the Portal is scoped to the account it belongs to, with access limited to the Customer's own users and to AI Monks staff who need it for support and operations;
  • data is encrypted in transit and at rest, and hosted in the European Union;
  • we minimise personal data in requests to AI providers and prohibit training on it;
  • retention periods are defined per data class and enforced, and data is deleted at the end of a Subscription after the export window;
  • new features that change how we handle personal data are assessed before launch, including a data protection impact assessment where the law requires one.

If a personal data breach occurs we handle it under our incident procedure and notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and affected parties where required.

11. Your rights

Under the GDPR you can ask us to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase data, where there is no overriding reason to keep it;
  • restrict processing in certain circumstances;
  • port data you provided to us, in a machine-readable format;
  • object to processing based on legitimate interest, including direct marketing (which we then stop).

Where we rely on consent, you can withdraw it at any time; this does not affect processing before withdrawal.

Send requests to privacy@ai-monks.io. We respond within one month; for complex requests we may extend this by two months and will tell you. We may ask you to verify your identity. If the data concerns a Customer's Monitored Targets or account content for which we are processor, we will refer your request to that Customer.

You can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to resolve your concern first.

12. Cookies

ai-monks.io and the Portal currently use only strictly necessary cookies and similar technologies: those needed for login sessions, security, load balancing and remembering your settings. These do not require consent under Dutch law (art. 11.7a Telecommunicatiewet).

We do not currently use analytics, advertising or other non-essential cookies. If we introduce them, we will ask for your consent through a banner before they are set, make refusing as easy as accepting, and list each cookie, its purpose and duration in a cookie table on this page. Until then, there is nothing to accept or reject.

13. Marketing communications

We send newsletters, product and feature updates, and run campaigns on LinkedIn.

  • We send email marketing only with your opt-in consent, or to existing customers about our own similar products and services, in line with art. 11.7 Telecommunicatiewet. Every message contains an unsubscribe link; unsubscribing is immediate and free.
  • We may use aggregated interaction data (opens, clicks) to improve our communications; we do not build individual profiles for advertising.
  • LinkedIn campaigns run under LinkedIn's own terms and privacy settings; where we use LinkedIn's audience tools, we use them with hashed, non-identifiable inputs and do not share your data with LinkedIn for its own purposes.

14. Automated decision-making

The Service produces risk scores and findings about organisations and their infrastructure, not about individuals. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

15. Children

Our website and Service are directed at businesses. We do not knowingly process personal data of anyone under 16.

16. Changes to this policy

We may update this policy. The version and effective date are shown at the top. For material changes affecting Portal users we give notice through the Portal or by email before the change takes effect.

17. Contact and complaints

AI Monks Group B.V.
[registered office address], Amsterdam, the Netherlands

privacy@ai-monks.io

We have not appointed a data protection officer; our processing does not meet the thresholds that require one. The privacy contact above handles all data-protection matters.


Annex — Sub-processors

Current as of 2 September 2026. We update this list when providers change; Customers are notified under the Data Processing Agreement.

ProviderPurposeLocation of processingTransfer mechanism
Vercel Inc.Web hosting and application deliveryEU / USEU-US Data Privacy Framework
Supabase Inc.Database and authenticationEU (region)Standard Contractual Clauses
Amazon Web Services EMEA SARLCloud infrastructureEU (Europe regions)EU-based entity; SCCs for any US support access
Stripe Payments Europe Ltd.Payment processing and invoicingEU / USStandard Contractual Clauses
Intercom R&D Unlimited CompanySupport, in-app messaging, AI assistantEU / USStandard Contractual Clauses
HubSpot Inc.CRM and marketingEU (data centre) / USStandard Contractual Clauses
Notion Labs Inc.Internal documentation and operationsUSStandard Contractual Clauses
Google Ireland Ltd. (Google Workspace)Email, documents, internal collaborationEU / USEU-based entity; Standard Contractual Clauses for US processing
Google (Gemini API)AI features in the PortalEU / USStandard Contractual Clauses
Anthropic PBC (Claude API)AI features in the PortalUSStandard Contractual Clauses
Resend Inc.Transactional emailUSEU-US Data Privacy Framework
Third-party cyber risk data provider(s)External risk data for Monitored Targets (technical identifiers only)US / EUStandard Contractual Clauses

Version 1.0
Effective date: 2 September 2026

AI Monks

Resilient, always-on cyber protection for every business online.

Product
  • AI Monks Portal
  • Pricing
  • Industries
  • Use cases
  • How it works
Company
  • About
  • Partners
  • Press
  • Contact
Resources
  • Privacy
  • Terms of Service
© 2026 AI Monks
AMSTERDAM