Skip to content
MonsterOps logoMonsterOps®
About
Platform
Leadership meetingsRocks & objectivesBusiness metricsMonsterAI™Integrations
Resources
BlogLeadership assessmentFind your framework
PricingSign inGet started free ↗

MonsterOps Data Processing Agreement

Version: 25 September 2026

1 Parties, incorporation, and scope

1.1 Parties

This Data Processing Agreement ("DPA") forms part of the agreement governing the Customer's use of the MonsterOps Services (the "Agreement") between:

  • MonsterOps: HCG Partners GmbH, trading as MonsterOps, Blegistrasse 11B, 6340 Baar, Switzerland ("MonsterOps"); and
  • Customer: the person or legal entity identified as the Customer in the Agreement.

MonsterOps' privacy contact is [email protected].

1.2 Effective date

This DPA takes effect when the Customer first accepts or enters into an Agreement that incorporates it, unless the parties agree another effective date in writing.

1.3 Scope

This DPA applies only to Personal Data that MonsterOps processes on the Customer's behalf in providing the Services ("Customer Personal Data"). It does not apply when MonsterOps processes Personal Data as an independent controller, including for billing and accounting, direct marketing, fraud and abuse prevention, product research under Section 6.1(e) of the Terms, or Aggregated Statistics under Section 4.3 of the Terms. Those activities are described in the MonsterOps Privacy Policy.

1.4 Roles

The Customer is a controller of Customer Personal Data or a processor authorized by the relevant controller. MonsterOps is respectively a processor or subprocessor. Each party will comply with the obligations applicable to its role under Applicable Data Protection Law.

2 Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

Applicable Data Protection Law means privacy and data-protection laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the EU GDPR as incorporated into United Kingdom law ("UK GDPR"), the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection ("Swiss FADP").

Customer Personal Data means Personal Data contained in Customer Data that MonsterOps processes on the Customer's behalf in providing the Services.

Data Subject, Personal Data, process, processing, controller, processor, and supervisory authority have the meanings given by Applicable Data Protection Law.

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise processed.

Restricted Transfer means a transfer of Customer Personal Data that requires an adequacy decision, appropriate safeguard, or other transfer mechanism under Applicable Data Protection Law.

Subprocessor means a third party engaged by MonsterOps to process Customer Personal Data on the Customer's behalf.

3 Instructions and permitted processing

3.1 Documented instructions

The Agreement, this DPA, the Customer's and Authorized Users' use and configuration of the Services, and the Customer's documented requests constitute the Customer's instructions to MonsterOps. MonsterOps will process Customer Personal Data only on those instructions and as necessary to provide the Services, including hosting, collaboration, integrations, notifications, support, and enabled or automated AI Features described in Appendix A, except for independent-controller processing permitted by the Agreement and described in Section 1.3.

3.2 Processing required by law

If applicable law requires MonsterOps to process Customer Personal Data other than on the Customer's instructions, MonsterOps will inform the Customer before that processing unless the law prohibits notice.

3.3 Unlawful instructions

MonsterOps will promptly inform the Customer if, in MonsterOps' reasonable opinion, an instruction infringes Applicable Data Protection Law. MonsterOps may suspend the affected processing until the parties resolve the issue.

3.4 Customer responsibilities

The Customer is responsible for:

  • having authority to provide Customer Personal Data to MonsterOps and instruct its processing;
  • providing legally required notices and obtaining any legally required permissions or consents;
  • ensuring its instructions and use of the Services comply with Applicable Data Protection Law;
  • configuring access, integrations, retention, and AI Features appropriately for its use; and
  • not submitting data subject to specialized regulatory requirements unless MonsterOps has expressly agreed in writing to support that processing.

MonsterOps remains responsible for its own obligations under this DPA.

3.5 US state privacy laws

To the extent MonsterOps processes Customer Personal Data as a processor, service provider, or contractor under an applicable US state privacy law, MonsterOps will:

  • process it only for the limited and specified purposes described in the Agreement, this DPA, and the Customer's documented instructions;
  • not sell or share it as those terms are defined under applicable US state privacy law;
  • not retain, use, or disclose it outside the direct business relationship with the Customer or for a purpose other than the permitted purposes, except as allowed or required by law;
  • not combine it with Personal Data received from another person or collected from MonsterOps' own interaction with an individual, except as permitted by applicable law; and
  • notify the Customer if MonsterOps determines that it can no longer meet these obligations.

The Customer may take reasonable and appropriate steps to verify compliance through Section 6.4 and to stop and remediate unauthorized processing. MonsterOps certifies that it understands and will comply with the restrictions in this Section.

4 Confidentiality and security

4.1 Confidentiality

MonsterOps will ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations and access it only when necessary for authorized duties.

4.2 Security measures

MonsterOps will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Appendix C. MonsterOps may update those measures as the Services evolve, provided the overall level of security is not materially reduced.

4.3 Administrative access

Administrative access to Customer Personal Data is limited to the purposes and safeguards described in Section 6 of the Terms, including requested support, technical troubleshooting, security and abuse investigations, legal compliance, and the Customer's written instructions.

4.4 AI model training

MonsterOps will not use Customer Personal Data to train a shared or general-purpose artificial intelligence model, or permit an AI Subprocessor to do so, unless the Customer has expressly instructed that use in a separate written arrangement that complies with Applicable Data Protection Law.

5 Subprocessors

5.1 General authorization

The Customer gives MonsterOps general written authorization to engage the Subprocessors listed in Appendix B. A Subprocessor supporting an optional feature will receive Customer Personal Data only when that feature is used or enabled.

5.2 Subprocessor obligations

Before a Subprocessor processes Customer Personal Data, MonsterOps will:

  • assess the Subprocessor's data-protection and security practices as appropriate to the risk;
  • ensure the Subprocessor is bound by written terms, including electronic or incorporated terms, that impose data-protection obligations that are no less protective, in substance, than the obligations applicable to the delegated processing under this DPA; and
  • ensure an appropriate transfer mechanism is in place for any Restricted Transfer.

MonsterOps remains responsible to the Customer for a Subprocessor's performance of its data-protection obligations to the extent required by Applicable Data Protection Law.

5.3 Changes and objections

MonsterOps will give the Customer at least 14 days' advance notice by email or through the Services before an intended addition or replacement of a Subprocessor begins processing Customer Personal Data. The notice will identify the Subprocessor's function and relevant processing locations.

The Customer may object during the notice period on reasonable grounds relating to the protection of Customer Personal Data. The parties will work in good faith to find a practical resolution. If MonsterOps cannot reasonably resolve the objection, the Customer may terminate the affected Services before the new Subprocessor begins processing Customer Personal Data. Any refund is governed by the Agreement.

5.4 Subprocessor chains

A Subprocessor may use its own downstream processors under its agreement with MonsterOps. MonsterOps will maintain information sufficient to assess the relevant processing chain, security, and international transfers. A downstream processor is not required to be listed separately in Appendix B when it is already disclosed and governed through the listed Subprocessor's terms.

6 Assistance, incidents, and audits

6.1 Data Subject requests

Taking account of the nature of the processing and information available to it, MonsterOps will reasonably assist the Customer in responding to requests to exercise Data Subject rights, including access, correction, erasure, restriction, objection, and portability. MonsterOps will promptly forward a request relating to Customer Personal Data to the Customer and will not respond on the Customer's behalf unless instructed or legally required.

6.2 Personal Data Breaches

MonsterOps will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent available, MonsterOps will provide:

  • a description of the nature of the Personal Data Breach;
  • the categories and approximate number of affected Data Subjects and records;
  • the likely consequences;
  • measures taken or proposed to contain, investigate, mitigate, and remediate the breach; and
  • a contact for follow-up.

MonsterOps may provide information in phases as it becomes available. Notification is not an admission of fault or liability. MonsterOps will reasonably assist the Customer with legally required notifications and communications.

6.3 Compliance assistance

Taking account of the nature of the processing and information available to MonsterOps, MonsterOps will provide the assistance required by Applicable Data Protection Law with the Customer's security assessments, data-protection impact assessments, and prior consultations, but only to the extent they relate to Customer Personal Data processed under this DPA. MonsterOps may charge reasonable fees for assistance beyond its standard documentation and support, provided it informs the Customer of the fees in advance. MonsterOps will not charge for assistance required because of its breach of this DPA.

6.4 Compliance information and audits

MonsterOps will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer must first use MonsterOps' then-current DPA, security documentation, Subprocessor information, written questionnaire responses, and any available independent audit reports or certifications.

Only where that information is insufficient to demonstrate compliance with Applicable Data Protection Law may the Customer request an audit. The parties will first use a remote document review. An onsite inspection is permitted only where the remote review is insufficient and the inspection is required by Applicable Data Protection Law.

An audit may occur no more than once in any 12-month period, must be conducted by an independent auditor that is not a MonsterOps competitor, and requires at least 30 days' written notice. It must occur during normal business hours, avoid unreasonable disruption, be limited to processing relevant to Customer Personal Data, and protect MonsterOps' and other customers' confidentiality and security. MonsterOps may coordinate or consolidate substantially similar audit requests.

The Customer bears all audit costs and will reimburse MonsterOps for reasonable assistance beyond standard documentation and support, with any fees disclosed in advance. These limitations do not apply where a competent supervisory authority requires otherwise, or where an additional audit is reasonably necessary following a Personal Data Breach affecting Customer Personal Data or credible evidence of MonsterOps' material non-compliance with this DPA.

7 International transfers

7.1 Transfer mechanisms

Before making a Restricted Transfer, MonsterOps will use a lawful transfer mechanism, which may include an adequacy decision, the Swiss-U.S. or EU-U.S. Data Privacy Framework where the recipient is certified, the EU Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, or another mechanism recognized under Applicable Data Protection Law.

7.2 EU Standard Contractual Clauses

Where a Restricted Transfer from the European Economic Area to MonsterOps is not covered by another valid transfer mechanism, the standard contractual clauses in the Annex to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs") are incorporated into this DPA as follows:

  • Module Two applies where the Customer is a controller and MonsterOps is a processor;
  • Module Three applies where the Customer is a processor and MonsterOps is a subprocessor;
  • Clause 7 (Docking Clause) applies;
  • in Clause 9(a), Option 2 applies and the notice period is 14 days;
  • the optional language in Clause 11 does not apply;
  • in Clause 17, the EU SCCs are governed by the law of Ireland;
  • in Clause 18(b), disputes will be resolved by the courts of Ireland;
  • the competent supervisory authority under Clause 13 is determined in accordance with that clause;
  • Section 1 and the Agreement complete Annex I.A;
  • Appendix A completes Annex I.B;
  • Appendix C completes Annex II; and
  • Appendix B completes Annex III.

If this Section conflicts with the EU SCCs, the EU SCCs prevail.

7.3 United Kingdom transfers

For a Restricted Transfer governed by the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 in force from 21 March 2022 ("UK Addendum"), is incorporated into this DPA. The parties' information and the selected EU SCC modules are set out in this DPA and the Agreement; Appendix B identifies authorized Subprocessors; and Appendix A and Appendix C provide the processing description and security measures. The mandatory clauses of the UK Addendum apply, and either party may end the UK Addendum as permitted by it.

7.4 Swiss transfers

For a Restricted Transfer governed by the Swiss FADP, the EU SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner. References to the EU GDPR include the Swiss FADP to the extent applicable; references to EU Member State law are understood to include Swiss law; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and Swiss Data Subjects may enforce their rights in Switzerland. Where both the EU GDPR and Swiss FADP apply, these adaptations do not displace the EU requirements that also apply.

7.5 Further measures

The parties will reasonably cooperate with transfer-risk assessments and supplementary measures required by Applicable Data Protection Law. MonsterOps will ensure that onward transfers by its Subprocessors are subject to corresponding safeguards.

8 Return, deletion, and retention

8.1 Export and deletion

At the end of the Services, the Customer may export available Customer Personal Data or request its deletion, subject to identity verification and applicable legal exceptions. Unless the Customer requests earlier deletion, Customer Personal Data will remain available for export for at least 30 days following expiration or termination, except where access is restricted because of unlawful activity, a security threat, or a legal prohibition. MonsterOps will delete Customer Personal Data from active systems within 90 days after the export period ends.

8.2 Backups

Encrypted backups may remain for up to 30 days after deletion from active systems. Until expiry, backups will remain protected, will not be restored except for disaster recovery, security, or legal requirements, and will not be used for another purpose. If a backup is restored, applicable deletion instructions will be reapplied.

8.3 Subprocessors and legal retention

MonsterOps will require Subprocessors to delete or return Customer Personal Data in accordance with their applicable contractual obligations. MonsterOps may retain Customer Personal Data where required by law, but only for the required data and period and subject to continued protection. MonsterOps will provide reasonable confirmation of deletion on request.

8.4 Independent-controller records

This Section does not govern Personal Data that MonsterOps retains as an independent controller under the Privacy Policy, including legally required accounting records and limited security or abuse-prevention records.

9 Order of precedence and effect

9.1 Precedence

This DPA takes precedence over conflicting provisions of the Agreement concerning the processing of Customer Personal Data on the Customer's behalf. Applicable mandatory transfer clauses take precedence over this DPA. The Agreement otherwise remains unchanged.

9.2 Duration

This DPA remains effective for as long as MonsterOps processes Customer Personal Data on the Customer's behalf.

9.3 Updates

MonsterOps may update this DPA where reasonably necessary to comply with law, regulatory guidance, or changes to the Services. MonsterOps will give reasonable advance notice of a material change unless an immediate change is required by law or security. An update will not materially reduce the protection of Customer Personal Data.

Appendix A - Description of processing

Item Description
Subject matter Providing the MonsterOps business-management, execution, meeting, and collaboration Services.
Duration and frequency Throughout the Agreement, continuously or when Authorized Users, automated features, integrations, or authorized support personnel invoke processing, followed by the export, deletion, and backup periods in Section 8.
Nature of processing Collection, recording, organization, storage, retrieval, consultation, display, calculation, modification, transmission, synchronization, AI inference, support access, export, restriction, and deletion.
Purposes Account access; organization and team management; meetings and agendas; To-Dos, Issues, Rocks, objectives, milestones, and KPIs; collaboration; notifications; Customer-directed integrations; AI assistance and summaries; troubleshooting; security; and support.
Data Subjects Customer administrators, employees, contractors, advisers, invited users, meeting participants, support contacts, and other individuals whose information the Customer or its Authorized Users include in the Services.
Identity and Account data Names, business email addresses, profile photographs, user and organization identifiers, roles, team and organization membership, invitations, and authentication-related records.
Customer content Accountability charts, business plans, values, role descriptions, To-Dos, Issues, Rocks, objectives, goals, milestones, KPIs, meeting agendas and notes, attendance, comments, files, and change history, to the extent they contain Personal Data.
Technical and usage data IP addresses, timestamps, browser and device information, session and request metadata, authentication and event records, diagnostic information, and approximate location derived from IP address.
Support and AI data Support messages and attachments; questions and prompts; relevant page, team, organization, and Customer Data context; authorized tool results; generated answers and summaries; and feedback scores.
Optional integration data Authorization tokens, third-party identifiers, and Customer Personal Data needed to operate each Customer-directed integration.
Special categories and regulated data The Services are not designed for protected health information, complete payment-card details, government-classified information, or other data subject to specialized regulatory requirements. Free-text Customer content may contain special-category or sensitive Personal Data. The Customer is responsible for determining whether submission is lawful and appropriate and for providing any additional instructions and safeguards required by law.

The Customer may further specify the subject matter, duration, nature, purposes, Personal Data, and Data Subjects through its use and configuration of the Services and documented instructions consistent with the Agreement.

Appendix B - Authorized Subprocessors

The following providers may process Customer Personal Data to provide the functions described below. Access is limited to data reasonably necessary for the relevant function. Optional providers receive Customer Personal Data only when the relevant feature is used.

Provider / service Purpose and Customer Personal Data Processing locations Provider documentation
Heroku / Salesforce Application and background-service hosting; managed PostgreSQL database hosting and backups through Heroku Postgres and PGBackups; Customer Personal Data handled by the hosted application, database, backups, and operational logs. United States Heroku terms; Privacy
Cloudflare - R2 Private storage of profile photographs and associated object identifiers. United States Customer DPA; Privacy
Pusher / Bird - Channels Real-time collaboration, presence, and updates, including user and channel identifiers, names, cursor positions, and event payloads. United States DPA; Subprocessors
Postmark - AC PM LLC / ActiveCampaign Transactional email delivery, including authentication messages, invitations, reminders, digests, and calendar invitations; sender and recipient data, message content, attachments, and delivery metadata. United States DPA; Subprocessors
BugSnag / SmartBear Error and performance monitoring and troubleshooting; error reports, stack traces, release and environment information, session and request metadata, and Personal Data included in diagnostic reports. United States DPA; Subprocessors
OpenAI - API AI assistance, automated Service functions, and support responses; prompts, relevant Customer Personal Data and Account context, authorized tool results, and generated responses. Global; distributed globally DPA; Subprocessors
Anthropic - Claude API AI-generated meeting digests, organization summaries, automated Service functions, support, and other AI Features; prompts, meeting notes, activity records, names, relevant Customer content, and generated responses. United States for storage by default; processing may occur in the United States, Europe, Asia, and Australia unless otherwise configured or agreed Commercial terms; Privacy Center
Slack / Salesforce - MonsterOps workspace Internal handling of Customer support, feedback, and technical incidents; contact information, organization and team details, support content, AI questions and answers, error details, tool names, and feedback scores. United States DPA; Privacy
Crisp Customer support chat and ticket handling; contact details, support messages, attachments, and associated browser and page information. European Union, with additional locations used by Crisp's disclosed subprocessors Subprocessors; Privacy
Google Workspace Customer support and business correspondence; contact details, email messages, calendar information, and attachments containing Customer Personal Data. Global; distributed globally across Google Cloud data centers Data Processing Amendment; Subprocessors

Stripe and other providers used solely for MonsterOps' billing, accounting, direct marketing, or other independent-controller activities are outside this DPA and are described in the Privacy Policy.

Customer-directed integrations that the Customer independently contracts for, enables, or connects through the Services, API, MCP tools, or automation platforms are not MonsterOps Subprocessors merely because the Services transmit data to them on the Customer's instructions.

Appendix C - Technical and organizational measures

MonsterOps maintains the following measures, taking account of the nature, scope, context, and purposes of processing and the risks to individuals. Measures may evolve as described in Section 4.2.

Area Measures
Governance and confidentiality Personnel and contractors with access to Customer Personal Data are bound by confidentiality obligations. Access is removed when a person's role changes or their employment or engagement ends.
Identity and access control Unique user authentication; organization and team authorization controls; two-factor authentication for MonsterOps personnel and contractors with administrative access; restriction of administrative access to the purposes in Section 6 of the Terms.
Transport security HTTPS/TLS for access to the Services and transmission to integrated providers. Database connections require TLS 1.2 or higher.
Encryption at rest and secrets Production database storage is encrypted at rest by Heroku. Backups retained through Heroku PGBackups are encrypted at rest. Objects and metadata stored in Cloudflare R2 are encrypted using AES-256 with Cloudflare-managed encryption keys.
Tenant and application controls Logical organization and team access controls; private profile-photo storage; authenticated access through the Services; protection against unauthorized cross-customer access.
Logging, diagnostics, and monitoring Designated sensitive request parameters are filtered from application request logs. The Services use application logging and error monitoring, and record selected authentication events and changes to supported application records.
Secure development and change management Development uses version control, GitHub vulnerability scanning, automated static security analysis, and automated tests covering application behavior and selected authentication and authorization controls.
Incident response Procedures to identify, contain, investigate, remediate, and notify Personal Data Breaches; cooperation with legally required Customer notifications.
Vendor management Risk-appropriate review of Subprocessors; written data-protection obligations; transfer safeguards; and monitoring of material changes.
Retention and erasure Export, active-system deletion, backup expiry, legal-retention controls, and Subprocessor deletion obligations as described in Section 8.
MonsterOps®

Company

  • About us
  • Blog
  • Pricing
  • Integrations

Product

  • MonsterAI
  • Leadership Meetings
  • Rocks
  • KPIs

Tools

  • Leadership assessment
  • Best BOS for You
  • Do-it-yourself calculator

Reviews

  • Ninety
  • Bloom Growth
  • EOS One

Compare

  • vs Ninety
  • vs Strety
  • vs EOS One
  • vs Bloom Growth
Users love us

Stay in the loop

Let's keep in touch

Take the gremlins out of your business. Subscribe to our newsletter for the latest updates, tips, and exclusive offers.

By signing up, you agree to our Privacy Policy and Terms of Service. We may send you occasional newsletters and promotional emails about our products and services. You can opt out at any time.

© 2025-2026 MonsterOps® - MonsterOps® is a Business Operating System for companies that want clarity, accountability, and growth without adding complexity.

EOS® and the Entrepreneurial Operating System® are registered trademarks of EOS Worldwide, LLC. MonsterOps is not affiliated with or endorsed by EOS Worldwide.

Terms & ConditionsPrivacy
Made in
Switzerland