Privacy & GDPR

Privacy policy & GDPR information

This page explains what data we process, why we process it, and the rights available to you under applicable data protection laws, including GDPR.

Last updated: January 30, 2026Support: contact@monolith.xyzCookies: /legal/cookies
Quick summary
  • We collect data needed to operate the platform, manage eligibility checks, and support onboarding.
  • We apply security controls designed to protect data (see /security).
  • You can request access, correction, deletion, restriction, portability, or object to processing where applicable.
  • Cookies and preferences are described at /legal/cookies.

On this page

To submit a request, email contact@monolith.xyz.

Overview

Monolith Equity (“Monolith”, “we”, “us”) processes personal data in connection with operating our website, onboarding users, responding to inquiries, and providing platform functionality for issuers and qualified investors.

This policy describes typical processing activities. Actual processing may vary based on enabled product features and the specific relationship you have with Monolith (visitor, prospect, investor, issuer, or service provider).

Data we collect

Account & contact
  • Name, email address, phone (if provided)
  • Account identifiers and role (issuer / investor)
  • Support messages and communication metadata
Platform usage
  • Log and audit events (security, access control, admin actions)
  • Device and browser information (for security and troubleshooting)
  • Approximate location derived from IP (for fraud prevention / geo controls)
Verification / eligibility
  • Identity and entity information necessary for KYC/KYB (if applicable)
  • Proof of address or corporate documents (where required)
  • Risk and compliance checks required for onboarding
Website interactions
  • Pages visited and interactions (if analytics is enabled by consent)
  • Cookie preferences and consent choices
  • Security signals (rate limiting, abuse detection)

Do not send sensitive data via email unless requested and appropriate. For security disclosures, use Responsible Disclosure.

How we use data

Security & integrity
  • Protect accounts
  • Detect abuse and fraud
  • Maintain audit logs and access controls
Onboarding & operations
  • Account creation
  • Eligibility/verification workflows
  • Issuer/investor support
Communications
  • Service messages
  • Support responses
  • Operational notices and maintenance updates

We aim to minimize data collection and restrict access on a need-to-know basis. See /security for governance, logging, and control design.

Retention

We keep personal data only as long as necessary for the purposes described above, unless a longer retention period is required by law or for dispute resolution and security.

Support inquiries
Typically 12–24 months
Account data
While the account is active
Security logs
Based on security needs and policy

You may request deletion where applicable; some records may be retained to comply with legal obligations or to protect the platform and users.

Processors & sharing

We may share personal data with vetted service providers (“processors”) that help operate the platform (e.g., infrastructure, support tooling, identity verification where applicable). Processors are contractually required to protect data and process it only on our instructions.

Typical processor categories
  • Cloud hosting and storage
  • Email and support tooling
  • Security monitoring and logging
  • Identity verification services (where required for onboarding)
We may also share data
  • With you or your organization (account administration)
  • When required by law or to protect rights and safety
  • During corporate events (e.g., merger) with safeguards

International transfers

Where personal data is transferred outside the EEA/UK, we use appropriate safeguards such as contractual protections and assessments where required by law. Transfer arrangements may depend on your geography and the service providers involved.

If you need more details on a particular transfer pathway, email contact@monolith.xyz.

Your rights

Depending on your location and applicable law, you may have rights including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. We may request verification before fulfilling a request.

Common requests
  • Access: receive a copy of your data
  • Correction: fix inaccurate information
  • Deletion: request erasure where applicable
  • Objection: object to certain processing
How we handle requests
  • We confirm identity to protect you
  • We respond within required timelines where GDPR applies
  • We explain any lawful reasons we cannot fully comply
  • We document fulfillment for audit and security

To submit a request, email contact@monolith.xyz with the request type and the account email (if applicable).

Cookies

Cookies may be used for strictly necessary site functionality, to remember preferences, and (if you allow) for analytics or marketing. You can manage your choices at any time.

Requests & contact

Email

Submit a privacy request

Use the template email below to help us respond quickly and securely.

Email contact@monolith.xyz
Tip: include your account email and the request type (access / correction / deletion / objection / portability / restriction).

Security

Sensitive disclosures

If you found a security issue, please use the responsible disclosure route.

Responsible Disclosure
We may ask for details needed to reproduce the issue safely.