Privacy & GDPR

Privacy policy & GDPR information

This page explains what data we process, why we process it, and the rights available to you under applicable data protection laws, including GDPR.

Last updated: January 30, 2026Support: contact@monolith.xyzCookies: /legal/cookies
Quick summary
  • We collect data needed to operate the platform, manage eligibility checks, and support onboarding.
  • We apply security controls designed to protect data. See /security.
  • You can request access, correction, deletion, restriction, portability, or object to processing where applicable.
  • Cookies and preferences are described at /legal/cookies.

On this page

To submit a request, email contact@monolith.xyz.

Overview

Monolith Equity, Monolith, we, or us, processes personal data in connection with operating our website, onboarding users, responding to inquiries, and providing platform functionality for issuers and qualified investors.

This policy describes typical processing activities. Actual processing may vary based on enabled product features and the specific relationship you have with Monolith, such as visitor, prospect, investor, issuer, or service provider.

Data we collect

Account & contact
  • Name, email address, phone if provided
  • Account identifiers and role, issuer or investor
  • Support messages and communication metadata
Platform usage
  • Log and audit events for security, access control, and admin actions
  • Device and browser information for security and troubleshooting
  • Approximate location derived from IP for fraud prevention or geo controls
Verification / eligibility
  • Identity and entity information necessary for KYC or KYB where applicable
  • Proof of address or corporate documents where required
  • Risk and compliance checks required for onboarding
Website interactions
  • Pages visited and interactions if analytics is enabled by consent
  • Cookie preferences and consent choices
  • Security signals such as rate limiting and abuse detection

Do not send sensitive data by email unless requested and appropriate. For security disclosures, use Responsible Disclosure.

How we use data

Security & integrity
  • Protect accounts
  • Detect abuse and fraud
  • Maintain audit logs and access controls
Onboarding & operations
  • Account creation
  • Eligibility and verification workflows
  • Issuer and investor support
Communications
  • Service messages
  • Support responses
  • Operational notices and maintenance updates

We aim to minimize data collection and restrict access on a need to know basis. See /security for governance, logging, and control design.

Retention

We keep personal data only as long as necessary for the purposes described above, unless a longer retention period is required by law or for dispute resolution and security.

Support inquiries
Typically 12 to 24 months
Account data
While the account is active
Security logs
Based on security needs and policy

You may request deletion where applicable. Some records may be retained to comply with legal obligations or to protect the platform and users.

Processors & sharing

We may share personal data with vetted service providers, processors, that help operate the platform, such as infrastructure, support tooling, and identity verification where applicable. Processors are contractually required to protect data and process it only on our instructions.

Typical processor categories
  • Cloud hosting and storage
  • Email and support tooling
  • Security monitoring and logging
  • Identity verification services where required for onboarding
We may also share data
  • With you or your organization for account administration
  • When required by law or to protect rights and safety
  • During corporate events such as a merger, with safeguards

International transfers

Where personal data is transferred outside the EEA or UK, we use appropriate safeguards such as contractual protections and assessments where required by law. Transfer arrangements may depend on your geography and the service providers involved.

If you need more details on a particular transfer pathway, email contact@monolith.xyz.

Your rights

Depending on your location and applicable law, you may have rights including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. We may request verification before fulfilling a request.

Common requests
  • Access, receive a copy of your data
  • Correction, fix inaccurate information
  • Deletion, request erasure where applicable
  • Objection, object to certain processing
How we handle requests
  • We confirm identity to protect you
  • We respond within required timelines where GDPR applies
  • We explain any lawful reasons we cannot fully comply
  • We document fulfillment for audit and security

To submit a request, email contact@monolith.xyz with the request type and the account email, if applicable.

Cookies

Cookies may be used for strictly necessary site functionality, to remember preferences, and, if you allow, for analytics or marketing. You can manage your choices at any time.

Requests & contact

Email

Submit a privacy request

Use the template email below to help us respond quickly and securely.

Email contact@monolith.xyz
Tip: include your account email and the request type, such as access, correction, deletion, objection, portability, or restriction.

Security

Sensitive disclosures

If you found a security issue, please use the responsible disclosure route.

Responsible Disclosure
We may ask for details needed to reproduce the issue safely.