LEGAL

Privacy Policy

How DataMonks collects, uses, processes, protects and retains personal information across our website, software and authorised integrations.

Effective: 7 September 2026Last updated: 7 September 2026

01

Introduction and who we are

This Privacy Policy explains how DataMonks Axiom Limited ("DataMonks", "we", "our" or "us") handles personal information when people visit datamonks.io, contact us, use a DataMonks product or service, or connect a supported third-party service.

DataMonks is a Kenya-based software company. Depending on the activity, DataMonks may act as a data controller for information we determine how and why to use, or as a data processor/service provider when we process information for a business customer under that customer's instructions.

02

Scope of this policy

This policy applies to the DataMonks corporate website, business enquiries, support and security communications, and personal information handled through DataMonks software and integrations unless a product-specific notice or customer agreement states otherwise.

A business using a DataMonks product may have its own privacy notice. Where that business controls the relevant personal information, its notice and instructions also matter.

03

Information we collect

Information you provide may include your name, work email address, organisation, role, contact details, enquiry content, support information, account details and information you choose to submit through a DataMonks service.

Technical information may include IP address, device and browser information, timestamps, authentication and security events, application logs, diagnostic information and service usage events required to operate, secure and troubleshoot a service.

04

Customer-controlled and processor data

Business customers may use DataMonks software to process information about their own customers, staff, contacts or operations. In those cases the customer may determine the purpose and means of processing, and DataMonks processes the information on the customer's behalf according to the service, contract and lawful instructions.

Requests about customer-controlled information may need to be handled by the relevant customer. DataMonks may assist the customer with access, correction, deletion or other rights where required.

05

Information from connected third-party services

When an authorised user connects a third-party platform, DataMonks may receive only the information made available by the permissions granted for the requested functionality. Depending on the integration this can include account identifiers, profile information, message content and metadata, calendar or email data, files, business-page information, conversation events or other operational data.

Connecting a service does not give DataMonks unrestricted access to that service. Access is limited by the provider's APIs, the permissions approved by the user or administrator, product configuration and applicable platform policies.

06

How we use personal information

We may use personal information to provide and operate services; authenticate users; carry out authorised workflows; communicate with users and customers; provide support; maintain integrations; secure and monitor systems; troubleshoot incidents; improve reliability and usability; prevent fraud and abuse; maintain business records; and comply with legal obligations.

We do not use third-party platform access for purposes incompatible with the permissions granted or the applicable provider requirements.

07

Lawful processing

Where applicable law requires a lawful basis, processing may rely on performance of a contract, steps requested before entering a contract, legitimate interests such as operating and securing our services, consent where appropriate, or compliance with legal obligations.

The appropriate basis depends on the relationship, service, data and purpose. Customers remain responsible for establishing an appropriate basis for information they control and instruct DataMonks to process.

08

Artificial intelligence and automated processing

Some DataMonks products may use artificial intelligence to assist with tasks such as classification, drafting, information retrieval, routing, summarisation or workflow execution. The exact use depends on the product and customer configuration.

AI output can be incomplete or incorrect. Product design may include human review, confidence checks, permissions or escalation controls according to the risk of the action. DataMonks does not present general-purpose AI output as regulated professional advice.

09

Google user data

Where a user or administrator connects a supported Google service, DataMonks will request only the Google OAuth scopes needed for the enabled functionality. Depending on the product, this could include access to permitted email, calendar, file or profile information.

Google user data is used only to provide or improve user-facing features that the user or business has enabled, to maintain security and reliability, and to comply with applicable law. DataMonks does not sell Google user data, does not use it for advertising, and does not transfer it to third parties except service providers acting on our behalf, as necessary to provide the enabled feature, for security purposes, or where legally required.

Where Google API Services User Data Policy or other Google requirements apply, DataMonks intends to handle Google user data in accordance with those requirements, including Limited Use obligations where applicable.

10

Meta platform data

Where a business connects supported Meta services such as Facebook, Instagram or WhatsApp, DataMonks may process authorised page, account, conversation, messaging and webhook information needed for the enabled business functionality.

Meta platform data is used for the connected service, related customer workflows, security, troubleshooting and service operation. Access is limited to permissions and assets authorised by the relevant business or account administrator and remains subject to Meta platform terms and policies.

11

Microsoft user data

Where a user or organisation connects a supported Microsoft service, DataMonks may process information available through the authorised Microsoft identity, Graph or related API permissions required for the enabled functionality.

Such information is used to provide the requested feature, maintain the integration, protect the service and comply with applicable law. Permissions are expected to be scoped to the functionality provided rather than unrestricted access.

12

Other connected services

DataMonks products may connect to additional communication, payment, productivity, cloud or business systems. The data handled depends on the provider, the permissions granted and the functionality enabled.

Third-party services are also governed by their own terms and privacy notices. Changes or outages at a provider can affect an integration independently of DataMonks.

13

How information may be shared

We may share information with infrastructure and service providers that help us operate the relevant service; with connected platforms as needed to perform an authorised action; with professional advisers under appropriate duties; in a lawful corporate transaction; to protect users, customers or DataMonks from security threats, fraud or abuse; or where disclosure is required by law.

We do not sell personal information to advertisers. Service-provider access should be limited to the role required to deliver the relevant service.

14

Service providers and subprocessors

Our current corporate-site and communications providers are listed on the public Subprocessors page. Product-specific providers may differ as products enter production and will be disclosed where applicable.

We assess provider use in light of the service, the data involved and appropriate contractual, technical and organisational safeguards.

15

Data security

DataMonks uses technical and organisational measures intended to protect information against unauthorised access, disclosure, alteration, loss or misuse. Measures vary by product and may include access controls, authentication, tenant isolation, encryption, secrets management, logging, monitoring, backup and secure-development practices.

No transmission or storage method can guarantee absolute security. Security concerns can be reported to security@datamonks.io without sending passwords, access tokens, private keys or other secrets in the initial report.

16

Retention

We retain personal information only as long as reasonably necessary for the purpose for which it was collected, to provide and secure a service, maintain legitimate business records, resolve disputes and meet contractual or legal obligations.

Retention periods can differ by data type, product, customer configuration and legal requirement. Information may be deleted, anonymised or aggregated when no longer required.

17

Data deletion

Individuals and authorised organisations may request deletion of eligible personal information by following the instructions at https://datamonks.io/data-deletion/ or contacting privacy@datamonks.io.

Deletion can be limited where information must be retained for legal obligations, security, fraud prevention, financial records, dispute resolution, enforcement of agreements or other lawful reasons. Deleting DataMonks-held information does not automatically delete information independently retained by a connected third-party provider.

18

International data processing

DataMonks may use infrastructure or service providers that process information in countries other than the user's own. Where cross-border transfer rules apply, we intend to use appropriate safeguards required by applicable data-protection law and the circumstances of the transfer.

Infrastructure regions and provider locations can vary by product and deployment and should be documented accurately for the applicable service.

19

Your rights and choices

Depending on applicable law and DataMonks' role in the processing, individuals may have rights to be informed about processing, request access, request correction, object to or restrict certain processing, request deletion, withdraw consent where consent is the basis, and request portability where applicable.

We may need to verify identity or authority before fulfilling a request. Where another business is the controller, we may direct the request to that business or assist it in responding.

20

Cookies and website technologies

This launch version of datamonks.io does not intentionally use non-essential advertising or behavioural analytics cookies. Basic hosting, security or browser functionality may still involve technical information required to deliver the site.

If the website later introduces analytics, advertising or other non-essential tracking, this policy and any required consent controls will be updated before or with that change.

21

Children's information

DataMonks corporate services are not directed to children for the purpose of knowingly collecting their personal information. A customer-specific service involving minors would require appropriate legal authority, notices, product controls and safeguards for that use case.

22

Changes to this policy

We may update this policy as our products, providers, legal requirements or data practices change. The current version will be published on this page with an updated revision date. Material changes may also be communicated through appropriate customer or product channels.

23

Privacy enquiries

Privacy and data-protection enquiries can be sent to privacy@datamonks.io. Data-deletion requests can also use the dedicated public instructions. Do not send passwords, API keys, private keys or access tokens in a privacy request.

Contact

Questions about this document may be sent to privacy@datamonks.io.

DataMonks Axiom Limited
Park Suites, Parklands Road, Westlands District, Nairobi, Kenya
P.O. Box 39107-00623

Security & Trust · Data Deletion