Skip to content
MonsterOps logoMonsterOps®
About
Platform
Leadership meetingsRocks & objectivesBusiness metricsMonsterAI™Integrations
Resources
BlogLeadership assessmentFind your framework
PricingSign inGet started free ↗

MonsterOps Privacy Policy

Effective 25 September 2026

This Privacy Policy explains how HCG Partners GmbH, operating as MonsterOps, collects, uses, shares, and protects Personal Data through the MonsterOps website, application, APIs, Model Context Protocol tools, artificial intelligence features, integrations, support channels, and related services (the "Services").

This Privacy Policy should be read together with the MonsterOps Terms of Service and, where applicable, the MonsterOps Data Processing Agreement.

1 Who We Are

MonsterOps is operated by:

HCG Partners GmbH
Blegistrasse 11B
6340 Baar
Switzerland

Questions and data-protection requests may be sent to [email protected].

2 Our Data-Protection Roles

MonsterOps may act in different roles depending on why Personal Data is processed.

2.1 MonsterOps as a processor

When a Customer or an Authorized User submits Personal Data to the Services and MonsterOps processes it to provide the Services on the Customer's instructions, the Customer is normally the controller and MonsterOps is its processor. This may include Personal Data contained in Rocks, objectives, KPIs, Issues, To-Dos, meeting content, comments, organizational information, accountability charts, and uploaded files.

That processing is governed by the MonsterOps Data Processing Agreement. The Customer is responsible for its instructions, its lawful basis for the processing, and notices to the people whose Personal Data it places in MonsterOps.

2.2 MonsterOps as a controller

MonsterOps acts as a controller for Personal Data that it processes for its own purposes, including:

  • operating accounts, authentication, billing, and communications;
  • securing the Services and preventing fraud, abuse, chargebacks, unauthorized access, evasion of restrictions, and repeat registration;
  • operating the website, measuring its performance, and managing marketing preferences;
  • providing and improving support;
  • understanding how customers use the Services so MonsterOps can design, improve, and prioritize product features;
  • creating Aggregated Statistics as described in Section 8; and
  • complying with legal obligations and establishing, exercising, or defending legal claims.

For product review and Aggregated Statistics, MonsterOps acts as an independent controller as described in Sections 4.3, 6.1(e), and 8.2 of the Terms of Service.

3 Personal Data We Collect

Depending on how a person interacts with MonsterOps, we may collect the following categories.

3.1 Account and organization information

  • name, email address, role, and contact details;
  • company name, domain, team membership, and organizational relationships;
  • authentication information, account settings, and sign-in history; and
  • subscription, plan, and account-status information.

3.2 Customer Data

Customers and Authorized Users may submit information such as Rocks, objectives, KPIs and KPI values, Issues, To-Dos, meeting agendas, notes and summaries, comments, responsibilities, organizational information, and uploaded files. This information may include Personal Data about Authorized Users, employees, contractors, advisers, customers, or other people.

3.3 Billing and transaction information

We collect billing contact details, subscription history, invoices, payment status, and identifiers received from our payment provider, Stripe. Stripe processes complete payment-card details. MonsterOps does not store complete card numbers, but may retain payment-provider identifiers and card fingerprints or tokens for billing, security, and abuse prevention.

3.4 Support and communications

We collect support requests, emails, chat messages, call or meeting notes, attachments, feedback, and information about the page, feature, Account, or technical problem involved in a request.

3.5 Technical, usage, and security information

We may collect IP addresses, browser and device information, approximate location derived from an IP address, pages or features used, event timestamps, session and authentication events, integration activity, diagnostic information, error reports, and security or audit events.

3.6 Website, cookies, and marketing information

We may collect website visits, referral URLs, campaign information, cookie identifiers, newsletter subscriptions, and interactions with our communications. Section 15 explains our use of cookies and similar technologies.

3.7 Information from integrations and other sources

If a Customer connects an integration, API client, MCP client, identity provider, or other third-party service, MonsterOps may receive information and authorization tokens needed to operate that connection. We may also receive information from payment providers, service providers, publicly available business sources, and people who invite an Authorized User to an Account.

4 How We Use Personal Data and Our Legal Bases

The legal basis depends on the processing and the law that applies.

Purpose Typical Personal Data Legal basis where required
Provide, operate, and maintain the Services Account information, Customer Data, integrations, usage and diagnostic data Performance of a contract; steps requested before entering a contract; Customer instructions where MonsterOps is a processor
Authenticate users and manage Accounts Identity, contact, authentication, device, and security information Performance of a contract; legitimate interests in secure account administration
Bill Customers and maintain financial records Billing contacts, subscription history, payment-provider identifiers, invoices Performance of a contract; legal obligations; legitimate interests in collecting amounts due
Provide support and resolve technical problems Contact information, support communications, relevant Account and Customer Data, diagnostics Performance of a contract; legitimate interests in customer service and reliable operation
Secure the Services and prevent abuse IP addresses, domains, authentication events, device or network identifiers, payment-provider IDs, card fingerprints or tokens Legitimate interests in security, fraud and abuse prevention, enforcing agreements, and protecting customers; legal obligations where applicable
Understand product use and improve MonsterOps Usage information and, where necessary, relevant Customer Data reviewed under Section 6.1(e) of the Terms Legitimate interests in understanding, designing, improving, and prioritizing the Services
Create Aggregated Statistics Customer Data, usage information, KPIs and KPI values, objectives, Rocks, Issues, To-Dos, meeting activity, and operational trends Legitimate interests in analytics, benchmarking, research, education, product improvement, and marketing, subject to the safeguards in Section 8
Operate AI Features Relevant prompts, Customer Data, Account context, and resulting output Performance of a contract and Customer instructions for service features; legitimate interests where AI is used for MonsterOps' independent-controller purposes
Send service communications Name, email address, Account and subscription information Performance of a contract; legitimate interests in administering the Services
Send marketing communications Name, business contact details, preferences, and engagement information Consent where required; otherwise legitimate interests in marketing MonsterOps to business contacts
Display customer references Customer company name and logo Legitimate interests and the customer-reference terms in Section 5.5 of the Terms; Customers may opt out
Comply with law and handle disputes Information relevant to the obligation, request, dispute, or claim Legal obligations; legitimate interests in protecting legal rights

Where we rely on legitimate interests, we consider the purpose, necessity, effects on individuals, reasonable expectations, and available safeguards. A person may object to this processing as described in Section 13.

5 Administrative Access to Customer Data

Authorized MonsterOps personnel and contractors may access Customer Data only for the purposes listed in Section 6.1 of the Terms of Service, including requested support, technical troubleshooting, security and abuse investigations, legal compliance, product review, or written Customer instructions.

Access is restricted to personnel and contractors whose role requires it. They must be bound by confidentiality obligations and use two-factor authentication. MonsterOps removes access when a person's role changes or their employment or engagement ends.

MonsterOps personnel and contractors will not create, change, or delete Customer Data except when the Customer asks them to or when necessary to restore service or contain a Security Incident.

6 Artificial Intelligence

MonsterOps uses artificial intelligence and machine-learning features to provide functions such as answers to questions, meeting summaries, recommendations, automated assistance, and customer support. AI Features may be initiated by an Authorized User, configured by a Customer, run automatically as part of the Services, or used by authorized MonsterOps personnel and contractors to query relevant Customer Data when necessary to provide requested support or diagnose a technical problem. Support use is subject to the administrative-access safeguards in Section 5.

When an AI Feature runs, MonsterOps may transmit the Customer Data and Account context relevant to that task to an AI provider, including OpenAI or Anthropic. MonsterOps uses commercial or API services whose applicable terms restrict the provider from using submitted business data to train shared models unless the Customer expressly directs or opts in to that use.

MonsterOps does not use Customer Data to train shared artificial intelligence models. AI-generated analyses used for MonsterOps' research, benchmarking, or marketing must first qualify as Aggregated Statistics under Section 8.

AI output may be inaccurate or incomplete and is intended to assist human judgment. MonsterOps does not use AI Features to make employment, legal, financial, or other decisions that produce legal or similarly significant effects on behalf of a Customer.

The availability of workspace-wide AI disablement and other AI controls depends on the applicable plan. Disabling MonsterOps AI Features does not control an AI service independently connected by a Customer through an integration, API, or MCP client.

Current AI providers, processing purposes, and processing locations are identified in the MonsterOps Subprocessor List.

7 Product Research and Improvement

MonsterOps may review how Customers use the Services, including relevant Customer Data where necessary, to understand workflows, identify friction, diagnose product weaknesses, and design, improve, or prioritize features.

For this purpose, MonsterOps acts as an independent controller and relies on its legitimate interests in improving the Services. The administrative-access safeguards in Section 5 apply. Product research does not authorize MonsterOps to publish identifiable Customer Data, customer-specific results, meeting content, or confidential business information.

8 Aggregated Statistics

MonsterOps may calculate statistics about how the Services are used across its customer base, including free and trial Accounts. Examples include the number of meetings held, the share of users who are active, common KPI categories, Rock completion trends, the average number of milestones per objective, and how operational results change over time.

Aggregated Statistics may be calculated from Customer Data, but:

  • each figure disclosed outside MonsterOps combines data from Accounts belonging to at least 10 different Customers;
  • the figure does not disclose underlying Customer Data, such as individual KPI values, meeting notes, or the text of Issues; and
  • no Customer, Authorized User, or individual can be identified without disproportionate effort.

MonsterOps may use, publish, and disclose Aggregated Statistics on its website and in reports, white papers, and marketing materials. Aggregated Statistics created under these safeguards are not Customer Data. MonsterOps does not sell Customer Data or Aggregated Statistics.

9 How We Share Personal Data

MonsterOps may share Personal Data in the following circumstances.

9.1 Service providers and Subprocessors

We use providers for hosting, infrastructure, databases, authentication, payments, analytics, communications, customer support, error monitoring, integrations, and AI processing. They may process Personal Data only for the relevant services and subject to contractual data-protection obligations. Current providers and relevant processing locations are identified in the MonsterOps Subprocessor List.

9.2 Customer-directed integrations

When a Customer enables an integration, API client, MCP client, or other third-party service, MonsterOps may exchange Customer Data with that service as directed by the Customer. The third party's terms and privacy practices apply to its independent processing.

9.3 Professional advisers

We may share information with lawyers, accountants, auditors, insurers, and other professional advisers who are subject to confidentiality obligations.

9.4 Legal, safety, and enforcement purposes

We may disclose information when reasonably necessary to comply with law or a binding legal request; protect the rights, safety, and security of MonsterOps, Customers, users, or others; investigate fraud or abuse; or establish, exercise, or defend legal claims.

9.5 Corporate transactions

Information may be disclosed in connection with a financing, reorganization, merger, acquisition, or sale of all or part of our business or assets, subject to appropriate confidentiality and data-protection safeguards.

9.6 Customer references

Unless a Customer requests anonymity, MonsterOps may use the Customer's company name and logo as described in Section 5.5 of the Terms. Testimonials, case studies, other trademarks, and identifiable Customer Data require prior permission.

MonsterOps does not sell Customer Data, Personal Data, or Aggregated Statistics.

10 International Data Transfers

MonsterOps is based in Switzerland. Personal Data may be processed in Switzerland and in other countries where MonsterOps or its service providers operate, which may include the European Economic Area, the United Kingdom, and the United States.

Where required, MonsterOps uses recognized safeguards for international transfers, such as an adequacy decision, the European Commission's Standard Contractual Clauses with applicable Swiss or UK adaptations, the Swiss-U.S. and EU-U.S. Data Privacy Framework where the recipient is certified, or another lawful transfer mechanism. Additional information is available in the Data Processing Agreement and Subprocessor List.

11 Data Retention and Deletion

MonsterOps retains Personal Data only for as long as reasonably necessary for the purpose for which it was collected, including the following periods or criteria.

  • Customer Data: retained while the Account is active. Following expiration or termination, Customer Data remains available for export for at least 30 days unless access is restricted for unlawful activity, a security threat, or a legal prohibition. MonsterOps will delete Customer Data from active systems within 90 days after the export period ends. Encrypted backups may remain until they expire through the ordinary backup cycle.
  • Account and contact information: retained while needed to administer the Account, provide support, manage the relationship, resolve disputes, and comply with law.
  • Billing and accounting records: retained for the period required by applicable accounting, tax, and commercial laws, which may be up to 10 years under Swiss law.
  • Security and abuse-prevention records: limited email addresses or domains, IP addresses, device or network identifiers, payment-provider IDs, and payment-card fingerprints or tokens may be retained for as long as reasonably necessary to prevent fraud, abuse, chargebacks, unauthorized access, evasion of restrictions, or repeat registration; comply with law; resolve disputes; or enforce agreements. Access is restricted, and these records are not used for marketing.
  • Support and operational records: retained for as long as reasonably necessary to resolve requests, maintain service history, train support personnel, improve support, prevent abuse, and establish or defend claims.
  • Marketing information: retained until the person unsubscribes, withdraws consent where consent applies, successfully objects, or the information is no longer needed for marketing.
  • Technical and security logs: retained according to their operational and security purpose, sensitivity, and risk, then deleted or anonymized when no longer needed.
  • Aggregated Statistics: may be retained after the underlying Customer Data is deleted because they are subject to the safeguards in Section 8 and do not identify Customers or individuals.

We may retain information for longer when required by law, a legal hold, a dispute, or a binding order.

12 Security and Security Incidents

MonsterOps maintains reasonable administrative, technical, and organizational safeguards designed to protect Personal Data, including access controls, authentication protections, confidentiality obligations, encryption, monitoring, backups, vulnerability management, and incident-response procedures as appropriate to the Services and risk.

No online service can guarantee absolute security. MonsterOps will notify an affected Customer without undue delay after becoming aware of a Security Incident affecting that Customer, as described in the Terms and Data Processing Agreement.

13 Privacy Rights and Choices

Depending on applicable law, a person may have the right to:

  • request access to Personal Data and information about its processing;
  • correct inaccurate or incomplete Personal Data;
  • request deletion of Personal Data, subject to the retention periods and exceptions described in Section 11;
  • restrict or object to processing;
  • receive Personal Data in a portable format;
  • withdraw consent at any time, without affecting processing already performed;
  • object at any time to direct marketing; and
  • lodge a complaint with a competent data-protection authority.

Requests may be sent to [email protected]. We may verify the requester's identity and authority before responding. Rights may be subject to legal exceptions, including obligations to retain information and the rights of other people.

Where MonsterOps processes Personal Data solely on a Customer's behalf, the request should normally be directed to that Customer. MonsterOps will assist the Customer as required by the Data Processing Agreement and applicable law.

Individuals in Switzerland may contact the Federal Data Protection and Information Commissioner. Individuals in the EEA or United Kingdom may contact the supervisory authority where they live or work.

14 United States Privacy Rights

MonsterOps does not sell or share Personal Data as those terms are defined under applicable US state privacy laws.

Residents of US states with applicable privacy laws may exercise the rights described in Section 13 by contacting [email protected].

15 Cookies and Similar Technologies

MonsterOps uses cookies and similar technologies that are necessary to operate the website and Services, including to maintain sessions, authentication, settings, and security.

We measure website and product usage with analytics configured to work without storing cookies or persistent identifiers on the visitor's device.

Visitors can block or delete cookies through their browser settings. Blocking strictly necessary cookies may prevent parts of the website or Services from working.

16 Marketing Communications

MonsterOps may send product news, educational content, surveys, event information, and offers where permitted by law. A recipient may unsubscribe from marketing emails using the link in the message.

Unsubscribing from marketing does not stop operational communications about an Account, billing, security, support, or changes to the Services or legal terms.

17 Children

The Services are intended for business users who are at least 18 years old. MonsterOps does not knowingly collect Personal Data directly from children. If we learn that a child has provided Personal Data directly to MonsterOps contrary to this policy, we will take reasonable steps to delete it.

18 Third-Party Services and Links

The Services may contain links to or integrations with third-party services. Their privacy policies govern their independent processing. MonsterOps does not control those services and recommends reviewing their terms and privacy practices before enabling an integration or providing information.

19 Changes to This Privacy Policy

MonsterOps may update this Privacy Policy from time to time and will post the revised version with an updated effective date. MonsterOps will give reasonable advance notice by email or in the Services before a material change takes effect, unless an immediate change is required by law, security, or a third-party dependency.

20 Contact

Questions, requests, or complaints about this Privacy Policy or MonsterOps' privacy practices may be sent to:

HCG Partners GmbH
Blegistrasse 11B
6340 Baar
Switzerland
[email protected]

MonsterOps®

Company

  • About us
  • Blog
  • Pricing
  • Integrations

Product

  • MonsterAI
  • Leadership Meetings
  • Rocks
  • KPIs

Tools

  • Leadership assessment
  • Best BOS for You
  • Do-it-yourself calculator

Reviews

  • Ninety
  • Bloom Growth
  • EOS One

Compare

  • vs Ninety
  • vs Strety
  • vs EOS One
  • vs Bloom Growth
Users love us

Stay in the loop

Let's keep in touch

Take the gremlins out of your business. Subscribe to our newsletter for the latest updates, tips, and exclusive offers.

By signing up, you agree to our Privacy Policy and Terms of Service. We may send you occasional newsletters and promotional emails about our products and services. You can opt out at any time.

© 2025-2026 MonsterOps® - MonsterOps® is a Business Operating System for companies that want clarity, accountability, and growth without adding complexity.

EOS® and the Entrepreneurial Operating System® are registered trademarks of EOS Worldwide, LLC. MonsterOps is not affiliated with or endorsed by EOS Worldwide.

Terms & ConditionsPrivacy
Made in
Switzerland