1 Who We Are
MonsterOps is operated by:
HCG Partners GmbH
Blegistrasse 11B
6340 Baar
Switzerland
Questions and data-protection requests may be sent to [email protected].
Effective 25 September 2026
This Privacy Policy explains how HCG Partners GmbH, operating as MonsterOps, collects, uses, shares, and protects Personal Data through the MonsterOps website, application, APIs, Model Context Protocol tools, artificial intelligence features, integrations, support channels, and related services (the "Services").
This Privacy Policy should be read together with the MonsterOps Terms of Service and, where applicable, the MonsterOps Data Processing Agreement.
MonsterOps is operated by:
HCG Partners GmbH
Blegistrasse 11B
6340 Baar
Switzerland
Questions and data-protection requests may be sent to [email protected].
MonsterOps may act in different roles depending on why Personal Data is processed.
When a Customer or an Authorized User submits Personal Data to the Services and MonsterOps processes it to provide the Services on the Customer's instructions, the Customer is normally the controller and MonsterOps is its processor. This may include Personal Data contained in Rocks, objectives, KPIs, Issues, To-Dos, meeting content, comments, organizational information, accountability charts, and uploaded files.
That processing is governed by the MonsterOps Data Processing Agreement. The Customer is responsible for its instructions, its lawful basis for the processing, and notices to the people whose Personal Data it places in MonsterOps.
MonsterOps acts as a controller for Personal Data that it processes for its own purposes, including:
For product review and Aggregated Statistics, MonsterOps acts as an independent controller as described in Sections 4.3, 6.1(e), and 8.2 of the Terms of Service.
Depending on how a person interacts with MonsterOps, we may collect the following categories.
Customers and Authorized Users may submit information such as Rocks, objectives, KPIs and KPI values, Issues, To-Dos, meeting agendas, notes and summaries, comments, responsibilities, organizational information, and uploaded files. This information may include Personal Data about Authorized Users, employees, contractors, advisers, customers, or other people.
We collect billing contact details, subscription history, invoices, payment status, and identifiers received from our payment provider, Stripe. Stripe processes complete payment-card details. MonsterOps does not store complete card numbers, but may retain payment-provider identifiers and card fingerprints or tokens for billing, security, and abuse prevention.
We collect support requests, emails, chat messages, call or meeting notes, attachments, feedback, and information about the page, feature, Account, or technical problem involved in a request.
We may collect IP addresses, browser and device information, approximate location derived from an IP address, pages or features used, event timestamps, session and authentication events, integration activity, diagnostic information, error reports, and security or audit events.
We may collect website visits, referral URLs, campaign information, cookie identifiers, newsletter subscriptions, and interactions with our communications. Section 15 explains our use of cookies and similar technologies.
If a Customer connects an integration, API client, MCP client, identity provider, or other third-party service, MonsterOps may receive information and authorization tokens needed to operate that connection. We may also receive information from payment providers, service providers, publicly available business sources, and people who invite an Authorized User to an Account.
The legal basis depends on the processing and the law that applies.
| Purpose | Typical Personal Data | Legal basis where required |
|---|---|---|
| Provide, operate, and maintain the Services | Account information, Customer Data, integrations, usage and diagnostic data | Performance of a contract; steps requested before entering a contract; Customer instructions where MonsterOps is a processor |
| Authenticate users and manage Accounts | Identity, contact, authentication, device, and security information | Performance of a contract; legitimate interests in secure account administration |
| Bill Customers and maintain financial records | Billing contacts, subscription history, payment-provider identifiers, invoices | Performance of a contract; legal obligations; legitimate interests in collecting amounts due |
| Provide support and resolve technical problems | Contact information, support communications, relevant Account and Customer Data, diagnostics | Performance of a contract; legitimate interests in customer service and reliable operation |
| Secure the Services and prevent abuse | IP addresses, domains, authentication events, device or network identifiers, payment-provider IDs, card fingerprints or tokens | Legitimate interests in security, fraud and abuse prevention, enforcing agreements, and protecting customers; legal obligations where applicable |
| Understand product use and improve MonsterOps | Usage information and, where necessary, relevant Customer Data reviewed under Section 6.1(e) of the Terms | Legitimate interests in understanding, designing, improving, and prioritizing the Services |
| Create Aggregated Statistics | Customer Data, usage information, KPIs and KPI values, objectives, Rocks, Issues, To-Dos, meeting activity, and operational trends | Legitimate interests in analytics, benchmarking, research, education, product improvement, and marketing, subject to the safeguards in Section 8 |
| Operate AI Features | Relevant prompts, Customer Data, Account context, and resulting output | Performance of a contract and Customer instructions for service features; legitimate interests where AI is used for MonsterOps' independent-controller purposes |
| Send service communications | Name, email address, Account and subscription information | Performance of a contract; legitimate interests in administering the Services |
| Send marketing communications | Name, business contact details, preferences, and engagement information | Consent where required; otherwise legitimate interests in marketing MonsterOps to business contacts |
| Display customer references | Customer company name and logo | Legitimate interests and the customer-reference terms in Section 5.5 of the Terms; Customers may opt out |
| Comply with law and handle disputes | Information relevant to the obligation, request, dispute, or claim | Legal obligations; legitimate interests in protecting legal rights |
Where we rely on legitimate interests, we consider the purpose, necessity, effects on individuals, reasonable expectations, and available safeguards. A person may object to this processing as described in Section 13.
Authorized MonsterOps personnel and contractors may access Customer Data only for the purposes listed in Section 6.1 of the Terms of Service, including requested support, technical troubleshooting, security and abuse investigations, legal compliance, product review, or written Customer instructions.
Access is restricted to personnel and contractors whose role requires it. They must be bound by confidentiality obligations and use two-factor authentication. MonsterOps removes access when a person's role changes or their employment or engagement ends.
MonsterOps personnel and contractors will not create, change, or delete Customer Data except when the Customer asks them to or when necessary to restore service or contain a Security Incident.
MonsterOps uses artificial intelligence and machine-learning features to provide functions such as answers to questions, meeting summaries, recommendations, automated assistance, and customer support. AI Features may be initiated by an Authorized User, configured by a Customer, run automatically as part of the Services, or used by authorized MonsterOps personnel and contractors to query relevant Customer Data when necessary to provide requested support or diagnose a technical problem. Support use is subject to the administrative-access safeguards in Section 5.
When an AI Feature runs, MonsterOps may transmit the Customer Data and Account context relevant to that task to an AI provider, including OpenAI or Anthropic. MonsterOps uses commercial or API services whose applicable terms restrict the provider from using submitted business data to train shared models unless the Customer expressly directs or opts in to that use.
MonsterOps does not use Customer Data to train shared artificial intelligence models. AI-generated analyses used for MonsterOps' research, benchmarking, or marketing must first qualify as Aggregated Statistics under Section 8.
AI output may be inaccurate or incomplete and is intended to assist human judgment. MonsterOps does not use AI Features to make employment, legal, financial, or other decisions that produce legal or similarly significant effects on behalf of a Customer.
The availability of workspace-wide AI disablement and other AI controls depends on the applicable plan. Disabling MonsterOps AI Features does not control an AI service independently connected by a Customer through an integration, API, or MCP client.
Current AI providers, processing purposes, and processing locations are identified in the MonsterOps Subprocessor List.
MonsterOps may review how Customers use the Services, including relevant Customer Data where necessary, to understand workflows, identify friction, diagnose product weaknesses, and design, improve, or prioritize features.
For this purpose, MonsterOps acts as an independent controller and relies on its legitimate interests in improving the Services. The administrative-access safeguards in Section 5 apply. Product research does not authorize MonsterOps to publish identifiable Customer Data, customer-specific results, meeting content, or confidential business information.
MonsterOps may calculate statistics about how the Services are used across its customer base, including free and trial Accounts. Examples include the number of meetings held, the share of users who are active, common KPI categories, Rock completion trends, the average number of milestones per objective, and how operational results change over time.
Aggregated Statistics may be calculated from Customer Data, but:
MonsterOps may use, publish, and disclose Aggregated Statistics on its website and in reports, white papers, and marketing materials. Aggregated Statistics created under these safeguards are not Customer Data. MonsterOps does not sell Customer Data or Aggregated Statistics.
MonsterOps may share Personal Data in the following circumstances.
We use providers for hosting, infrastructure, databases, authentication, payments, analytics, communications, customer support, error monitoring, integrations, and AI processing. They may process Personal Data only for the relevant services and subject to contractual data-protection obligations. Current providers and relevant processing locations are identified in the MonsterOps Subprocessor List.
When a Customer enables an integration, API client, MCP client, or other third-party service, MonsterOps may exchange Customer Data with that service as directed by the Customer. The third party's terms and privacy practices apply to its independent processing.
We may share information with lawyers, accountants, auditors, insurers, and other professional advisers who are subject to confidentiality obligations.
We may disclose information when reasonably necessary to comply with law or a binding legal request; protect the rights, safety, and security of MonsterOps, Customers, users, or others; investigate fraud or abuse; or establish, exercise, or defend legal claims.
Information may be disclosed in connection with a financing, reorganization, merger, acquisition, or sale of all or part of our business or assets, subject to appropriate confidentiality and data-protection safeguards.
Unless a Customer requests anonymity, MonsterOps may use the Customer's company name and logo as described in Section 5.5 of the Terms. Testimonials, case studies, other trademarks, and identifiable Customer Data require prior permission.
MonsterOps does not sell Customer Data, Personal Data, or Aggregated Statistics.
MonsterOps is based in Switzerland. Personal Data may be processed in Switzerland and in other countries where MonsterOps or its service providers operate, which may include the European Economic Area, the United Kingdom, and the United States.
Where required, MonsterOps uses recognized safeguards for international transfers, such as an adequacy decision, the European Commission's Standard Contractual Clauses with applicable Swiss or UK adaptations, the Swiss-U.S. and EU-U.S. Data Privacy Framework where the recipient is certified, or another lawful transfer mechanism. Additional information is available in the Data Processing Agreement and Subprocessor List.
MonsterOps retains Personal Data only for as long as reasonably necessary for the purpose for which it was collected, including the following periods or criteria.
We may retain information for longer when required by law, a legal hold, a dispute, or a binding order.
MonsterOps maintains reasonable administrative, technical, and organizational safeguards designed to protect Personal Data, including access controls, authentication protections, confidentiality obligations, encryption, monitoring, backups, vulnerability management, and incident-response procedures as appropriate to the Services and risk.
No online service can guarantee absolute security. MonsterOps will notify an affected Customer without undue delay after becoming aware of a Security Incident affecting that Customer, as described in the Terms and Data Processing Agreement.
Depending on applicable law, a person may have the right to:
Requests may be sent to [email protected]. We may verify the requester's identity and authority before responding. Rights may be subject to legal exceptions, including obligations to retain information and the rights of other people.
Where MonsterOps processes Personal Data solely on a Customer's behalf, the request should normally be directed to that Customer. MonsterOps will assist the Customer as required by the Data Processing Agreement and applicable law.
Individuals in Switzerland may contact the Federal Data Protection and Information Commissioner. Individuals in the EEA or United Kingdom may contact the supervisory authority where they live or work.
MonsterOps does not sell or share Personal Data as those terms are defined under applicable US state privacy laws.
Residents of US states with applicable privacy laws may exercise the rights described in Section 13 by contacting [email protected].
MonsterOps uses cookies and similar technologies that are necessary to operate the website and Services, including to maintain sessions, authentication, settings, and security.
We measure website and product usage with analytics configured to work without storing cookies or persistent identifiers on the visitor's device.
Visitors can block or delete cookies through their browser settings. Blocking strictly necessary cookies may prevent parts of the website or Services from working.
MonsterOps may send product news, educational content, surveys, event information, and offers where permitted by law. A recipient may unsubscribe from marketing emails using the link in the message.
Unsubscribing from marketing does not stop operational communications about an Account, billing, security, support, or changes to the Services or legal terms.
The Services are intended for business users who are at least 18 years old. MonsterOps does not knowingly collect Personal Data directly from children. If we learn that a child has provided Personal Data directly to MonsterOps contrary to this policy, we will take reasonable steps to delete it.
The Services may contain links to or integrations with third-party services. Their privacy policies govern their independent processing. MonsterOps does not control those services and recommends reviewing their terms and privacy practices before enabling an integration or providing information.
MonsterOps may update this Privacy Policy from time to time and will post the revised version with an updated effective date. MonsterOps will give reasonable advance notice by email or in the Services before a material change takes effect, unless an immediate change is required by law, security, or a third-party dependency.
Questions, requests, or complaints about this Privacy Policy or MonsterOps' privacy practices may be sent to:
HCG Partners GmbH
Blegistrasse 11B
6340 Baar
Switzerland
[email protected]