Version 1.0 · Effective 2 September 2026
Controller: AI Monks Group B.V., registered with the Dutch Chamber of Commerce (KVK) under number 42132024, [registered office address], Amsterdam, the Netherlands ("AI Monks", "we", "us").
Privacy contact: privacy@ai-monks.io
This policy explains how we handle personal data when you visit ai-monks.io, use the AI Monks Portal, communicate with us, work with us as a partner, or appear in the data our Service processes. It is written for businesses and the people who work at them. We do not offer our services to consumers.
Contents
- 1. Who this policy covers
- 2. Our role: controller or processor
- 3. What we process, why, and on what basis
- 4. Data we obtain indirectly through the Service
- 5. AI in the Service
- 6. Partners and resellers
- 7. Who we share data with
- 8. International transfers
- 9. How long we keep data
- 10. Security and privacy by design
- 11. Your rights
- 12. Cookies
- 13. Marketing communications
- 14. Automated decision-making
- 15. Children
- 16. Changes to this policy
- 17. Contact and complaints
- Annex — Sub-processors
1. Who this policy covers
- Website visitors — anyone visiting ai-monks.io.
- Prospects and subscribers — people who contact us, request information, or subscribe to our updates.
- Portal users — the person who opens a Customer account and any team members invited to it.
- Partner contacts — people working at our partners and resellers, and at their customers.
- People in Service Data — individuals whose data appears in the externally observable information our Service collects about a Customer's internet-facing infrastructure (see section 4).
2. Our role: controller or processor
For the website, Portal accounts, billing, support, marketing and partner relationships, AI Monks is the controller: we decide why and how the data is processed.
For personal data contained in a Customer's own Monitored Targets and account content, we act as processor on the Customer's behalf under the Data Processing Agreement that forms part of our Terms of Service. The Customer is the controller of that data; questions about it should go to the Customer first.
For Service Data we generate or collect ourselves when operating the Service — including data received from third-party data providers and telemetry from our own monitoring infrastructure — we are the controller, to the extent that data contains personal data.
3. What we process, why, and on what basis
| Purpose | Data | Legal basis (art. 6 GDPR) |
|---|---|---|
| Providing the website and keeping it secure | IP address, browser and device information, request logs | Legitimate interest (operating and securing our website) |
| Responding to enquiries | Name, work email, phone, company, message content | Legitimate interest (responding to a request you made); contract where the enquiry leads to one |
| Opening and managing a Portal account | Name, work email, phone, job title, company name, company address, company website, login credentials, account settings | Contract (Terms of Service) |
| Invited team members | Name, work email, phone, job title, role in the account | Contract with the Customer; legitimate interest in providing the account the Customer requested |
| Billing | Name, email, billing address, VAT number, payment status. Card details are entered directly with our payment provider; we do not store them | Contract; legal obligation (tax and accounting records) |
| Providing the Service | Account data, Monitored Targets designated by the Customer, alerts and reports, usage data | Contract |
| Support and in-app messaging | Name, email, conversation content, account and technical context | Contract; legitimate interest (resolving issues) |
| Product analytics and improvement | Usage events tied to an account, error reports | Legitimate interest (understanding how the Portal is used and improving it) |
| Security, fraud and abuse prevention | Log data, IP addresses, account activity | Legitimate interest (protecting the Service, our Customers and ourselves) |
| Marketing communications | Name, work email, company, interaction with our messages | Consent, or legitimate interest for existing customers (section 13) |
| Partner and reseller relationships | Contact details of partner staff; customer and lead data exchanged with partners (section 6) | Contract with the partner; legitimate interest (managing the partnership) |
| Legal claims and compliance | Any of the above as relevant | Legitimate interest (establishing, exercising or defending claims); legal obligation |
Where we rely on legitimate interest we have assessed that our interest is not overridden by yours. You can ask us for a summary of that assessment and you can object (section 11).
Providing account and billing data is necessary to open and keep an account; without it we cannot provide the Service.
4. Data we obtain indirectly through the Service
The Service observes a Customer's externally visible infrastructure: domains, hosts, certificates, DNS and mail configuration, and risk signals about them. Most of this is data about systems, not people. Some of it can relate to an identifiable person — for example a technical contact in public registration records or an administrator's address in a mail configuration.
We obtain this data from public sources, from our own non-intrusive monitoring, and from third-party data providers that specialise in external cyber risk data. We process it solely to provide cyber risk monitoring and reporting to the Customer that designated the target, and to operate and improve the Service. We do not use it to profile individuals, to market to them, or for any other purpose.
We do not contact individuals whose data appears in Service Data, because we generally cannot identify them without disproportionate effort and because the data relates to their role in an organisation's infrastructure rather than to them personally. This policy is how we inform them (art. 14(5)(b) GDPR). Anyone who believes their data appears in our Service Data can contact privacy@ai-monks.io and exercise the rights in section 11.
5. AI in the Service
We use AI models from third-party providers in two places:
- Support and in-app messaging run on Intercom, including its AI assistant, which may answer questions using your conversation and account context.
- Portal features such as explanations of findings and recommended fixes are generated using models from Anthropic (Claude) and Google (Gemini). The input consists of technical findings and, where needed, account context; we minimise personal data in these requests.
Our contracts with these providers prohibit them from using your data to train their models. AI output in the Portal is informational; the Terms of Service describe its status. No decision with legal or similarly significant effect on an individual is taken by AI (section 14).
6. Partners and resellers
We sell the Service directly and through partners and resellers. In that relationship:
- A partner may pass a customer's or lead's contact and company details to us so that we can open an account, provide the Service, or follow up on an introduction.
- We may share with the referring partner the account status, subscription details, and contact details of the customers it introduced, so that the partner can support them and manage its relationship with us.
Each party is an independent controller for its own use of this data. Our partners are bound by contract to handle it in line with data-protection law. We do not sell personal data, and we do not share a customer's data with a partner that did not introduce it unless the customer asks us to.
7. Who we share data with
- Service providers (processors) that host our infrastructure, process payments, deliver email, provide support tooling, CRM, analytics and AI features. They act on our instructions under data-processing agreements. The current list is in the Annex.
- Third-party data providers that supply external cyber risk data. We send them the domains and other technical identifiers of Monitored Targets — not the names or contact details of Customer staff.
- Partners and resellers as described in section 6.
- Professional advisers (legal, accounting, audit) under confidentiality.
- Authorities where we are legally required to, or to protect our rights or the security of our Service.
- A buyer or successor in a merger, acquisition or reorganisation, under confidentiality and this policy.
8. International transfers
We host the Portal and its data in the European Union. Some of our service providers are established in, or provide support from, the United States or other countries outside the European Economic Area. Where that is the case we transfer data only on a lawful basis: the EU-US Data Privacy Framework where the provider is certified, or the European Commission's Standard Contractual Clauses together with an assessment of the transfer. The mechanism used for each provider is listed in the Annex. You can request a copy of the relevant safeguards via privacy@ai-monks.io.
9. How long we keep data
We keep personal data no longer than needed for the purpose it was collected for, and then delete or anonymise it.
| Data | Retention |
|---|---|
| Portal account and user data | For the Subscription, plus a 30-day export window; then deleted from active systems within 90 days |
| Service Data (monitoring data, alerts, reports) | For the Subscription; personal data within archived data is deleted or anonymised in line with our retention schedule and the Data Processing Agreement |
| Billing records and invoices | 7 years (Dutch tax law) |
| Support conversations | 24 months after the conversation is closed |
| Website and security logs | 12 months |
| Enquiries and prospect data (CRM) | 24 months after our last contact, unless a relationship follows |
| Marketing subscriptions | Until you unsubscribe or 24 months of inactivity |
| Partner contact data | For the partnership, plus 24 months |
Where a legal claim, investigation or legal duty requires it, we keep data for as long as that requires.
10. Security and privacy by design
We build the Service with privacy as a design requirement rather than an afterthought. In practice this means:
- we collect only what a purpose needs, and the Service is designed around data about systems rather than people;
- personal data in the Portal is scoped to the account it belongs to, with access limited to the Customer's own users and to AI Monks staff who need it for support and operations;
- data is encrypted in transit and at rest, and hosted in the European Union;
- we minimise personal data in requests to AI providers and prohibit training on it;
- retention periods are defined per data class and enforced, and data is deleted at the end of a Subscription after the export window;
- new features that change how we handle personal data are assessed before launch, including a data protection impact assessment where the law requires one.
If a personal data breach occurs we handle it under our incident procedure and notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and affected parties where required.
11. Your rights
Under the GDPR you can ask us to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase data, where there is no overriding reason to keep it;
- restrict processing in certain circumstances;
- port data you provided to us, in a machine-readable format;
- object to processing based on legitimate interest, including direct marketing (which we then stop).
Where we rely on consent, you can withdraw it at any time; this does not affect processing before withdrawal.
Send requests to privacy@ai-monks.io. We respond within one month; for complex requests we may extend this by two months and will tell you. We may ask you to verify your identity. If the data concerns a Customer's Monitored Targets or account content for which we are processor, we will refer your request to that Customer.
You can complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to resolve your concern first.
12. Cookies
ai-monks.io and the Portal currently use only strictly necessary cookies and similar technologies: those needed for login sessions, security, load balancing and remembering your settings. These do not require consent under Dutch law (art. 11.7a Telecommunicatiewet).
We do not currently use analytics, advertising or other non-essential cookies. If we introduce them, we will ask for your consent through a banner before they are set, make refusing as easy as accepting, and list each cookie, its purpose and duration in a cookie table on this page. Until then, there is nothing to accept or reject.
13. Marketing communications
We send newsletters, product and feature updates, and run campaigns on LinkedIn.
- We send email marketing only with your opt-in consent, or to existing customers about our own similar products and services, in line with art. 11.7 Telecommunicatiewet. Every message contains an unsubscribe link; unsubscribing is immediate and free.
- We may use aggregated interaction data (opens, clicks) to improve our communications; we do not build individual profiles for advertising.
- LinkedIn campaigns run under LinkedIn's own terms and privacy settings; where we use LinkedIn's audience tools, we use them with hashed, non-identifiable inputs and do not share your data with LinkedIn for its own purposes.
14. Automated decision-making
The Service produces risk scores and findings about organisations and their infrastructure, not about individuals. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
15. Children
Our website and Service are directed at businesses. We do not knowingly process personal data of anyone under 16.
16. Changes to this policy
We may update this policy. The version and effective date are shown at the top. For material changes affecting Portal users we give notice through the Portal or by email before the change takes effect.
17. Contact and complaints
AI Monks Group B.V.
[registered office address], Amsterdam, the Netherlands
privacy@ai-monks.io
We have not appointed a data protection officer; our processing does not meet the thresholds that require one. The privacy contact above handles all data-protection matters.
Annex — Sub-processors
Current as of 2 September 2026. We update this list when providers change; Customers are notified under the Data Processing Agreement.
| Provider | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Vercel Inc. | Web hosting and application delivery | EU / US | EU-US Data Privacy Framework |
| Supabase Inc. | Database and authentication | EU (region) | Standard Contractual Clauses |
| Amazon Web Services EMEA SARL | Cloud infrastructure | EU (Europe regions) | EU-based entity; SCCs for any US support access |
| Stripe Payments Europe Ltd. | Payment processing and invoicing | EU / US | Standard Contractual Clauses |
| Intercom R&D Unlimited Company | Support, in-app messaging, AI assistant | EU / US | Standard Contractual Clauses |
| HubSpot Inc. | CRM and marketing | EU (data centre) / US | Standard Contractual Clauses |
| Notion Labs Inc. | Internal documentation and operations | US | Standard Contractual Clauses |
| Google Ireland Ltd. (Google Workspace) | Email, documents, internal collaboration | EU / US | EU-based entity; Standard Contractual Clauses for US processing |
| Google (Gemini API) | AI features in the Portal | EU / US | Standard Contractual Clauses |
| Anthropic PBC (Claude API) | AI features in the Portal | US | Standard Contractual Clauses |
| Resend Inc. | Transactional email | US | EU-US Data Privacy Framework |
| Third-party cyber risk data provider(s) | External risk data for Monitored Targets (technical identifiers only) | US / EU | Standard Contractual Clauses |