The legal basis applicable to a particular processing activity may depend on the circumstances, the nature of the Personal Information and applicable law. Where more than one legal basis is identified above, MONIT24 relies on the basis applicable to the particular processing activity; listing multiple possible bases does not mean that MONIT24 may freely substitute one basis for another.
Where MONIT24 relies on consent, consent may be withdrawn at any time without affecting processing lawfully carried out before withdrawal. MONIT24 does not treat mere use of the Services as consent where applicable law requires specific, freely given, informed and unambiguous consent.
Where processing of special categories of Personal Information is subject to Article 9 GDPR or the corresponding UK GDPR rules, MONIT24 will rely on an applicable Article 9 condition in addition to an appropriate Article 6 legal basis where required.
7. Disclosure of Personal Information
We may disclose Personal Information only as reasonably necessary for the purposes described in this Policy or as otherwise permitted or required by law. Categories of recipients may include:
hosting, cloud, infrastructure, data-center, network and telecommunications providers;
email, SMS, push-notification and communications providers;
payment, billing and subscription providers, including Stripe;
analytics, measurement, cookie-consent and website-technology providers;
security, anti-abuse, fraud-prevention, authentication and incident-response providers;
customer-support, communications and productivity providers;
affiliates, licensors, technology providers, contractors, subcontractors and suppliers supporting the Services;
professional advisers such as lawyers, accountants, auditors and insurers;
government authorities, regulators, courts and law-enforcement bodies where disclosure is required or permitted by law; and
parties involved in an actual or proposed financing, merger, acquisition, restructuring, reorganization, sale of assets or similar corporate transaction, subject to applicable safeguards.
Recipients may act as processors/service providers on our behalf or as independent controllers/businesses depending on the service and applicable law. We seek contractual, organizational and technical protections appropriate to the nature of the processing where required by law.
8. Stripe and Payment Processing
MONIT24 uses Stripe to process payments and administer payment-related aspects of subscriptions. Information necessary for a transaction may be transmitted to Stripe, including identifying and contact information, billing information, transaction information, IP address and other information required for payment processing, authentication, ledger management, fraud prevention, risk assessment and compliance.
Stripe may process certain Personal Information as a processor on behalf of MONIT24 and certain Personal Information as an independent controller, depending on the Stripe service and processing context. Stripe’s own privacy notices govern processing for which Stripe determines the purposes and means. MONIT24 does not control Stripe’s independent processing.
Stripe and its affiliates and service providers may process Personal Information internationally. Where Stripe processes Personal Information as an independent controller, Stripe is responsible for implementing transfer mechanisms and safeguards required by applicable law for such processing. Where Stripe processes Personal Information on behalf of MONIT24, MONIT24 relies on the contractual and transfer safeguards applicable to the relevant Stripe services and required by applicable law.
9. International Transfers
MONIT24 is established in the United States and provides Services internationally. Personal Information may therefore be processed in the United States, the European Economic Area and other countries in which MONIT24’s service providers, technology providers or subprocessors operate.
Where the GDPR, UK GDPR or other applicable law restricts international transfers, MONIT24 uses a lawful transfer mechanism where required, which may include an adequacy decision, the EU-U.S. Data Privacy Framework where available to and relied upon by the relevant recipient, Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement or UK Addendum, or another mechanism permitted by applicable law.
Where required, MONIT24 may implement supplementary contractual, technical or organizational measures. Individuals may contact us for information about applicable transfer safeguards and, where required by law, a copy or description of relevant safeguards, subject to lawful redactions.
10. Cookies and Similar Technologies
MONIT24 and its service providers may use cookies, pixels, local storage, SDKs and similar technologies for essential functionality, authentication, security, preferences, diagnostics, analytics, performance measurement and, where used, advertising or marketing.
Where applicable law requires consent, non-essential technologies are used only after the required consent has been obtained. Users may manage available choices through the cookie-consent interface and, where applicable, browser or device settings. Withdrawal of consent does not affect processing lawfully performed before withdrawal.
Blocking or deleting certain technologies may affect functionality, authentication, preferences or performance. The specific technologies and retention periods shown in a cookie-consent interface or cookie notice may change as our website and providers change; the then-current interface or notice forms part of the information we provide about such technologies.
11. Marketing
Where permitted by applicable law, MONIT24 may use contact and account information to send information about MONIT24 products, Services, features, events or offers. We rely on consent where consent is required and may rely on legitimate interests or another lawful basis where permitted.
Marketing emails may be opted out of using the unsubscribe mechanism in the message or by contacting us. An opt-out from marketing does not prevent transactional, security, legal, billing, administrative or other non-marketing communications.
12. Sale, Sharing, Targeted Advertising and Sensitive Information
MONIT24 does not sell Personal Information for monetary consideration. We do not knowingly sell Personal Information of children.
Some U.S. privacy laws define “sale,” “sharing,” “targeted advertising” or similar concepts more broadly than ordinary usage and may treat certain advertising or cross-context behavioral technologies as covered activities. To the extent MONIT24 engages in an activity that is legally defined as sale, sharing or targeted advertising, MONIT24 will provide the notices and opt-out mechanisms required by applicable law.
MONIT24 does not use sensitive Personal Information to infer characteristics about individuals except where expressly disclosed and permitted by applicable law. Customers should not submit special-category, highly sensitive or regulated Personal Information unless necessary for an authorized use of the Services and legally permitted.
13. Automated Processing, Cybersecurity and Anomaly Detection
The Services may use automated rules, statistical methods, machine-learning or other automated techniques to detect anomalies, security events, operational conditions, abuse or fraud and to generate alerts, classifications, scores, findings or recommendations.
Unless expressly stated otherwise for a particular feature, MONIT24 does not use Personal Information under this Policy to make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect an individual. Where applicable law provides rights concerning qualifying automated decision-making or profiling, those rights may be exercised as described below.
14. Data Retention
MONIT24 retains Personal Information for no longer than reasonably necessary for the purposes for which it is processed, taking into account the nature and sensitivity of the information, operational and security needs, Customer instructions, applicable limitation periods, dispute and claims requirements, and legal, tax, accounting and regulatory obligations.
Account and relationship information may be retained while an Account or relationship is active and for an appropriate period thereafter;
transaction, billing and subscription records may be retained for legally required tax, accounting, anti-fraud and recordkeeping periods;
support and business communications may be retained for support, quality, security and claims-management purposes;
technical, monitoring and security logs may be retained for periods appropriate to operational, diagnostic, security and abuse-prevention needs;
marketing records may be retained until an opt-out or until no longer reasonably necessary, with suppression information retained as needed to honor the opt-out;
Customer Data processed as processor is retained according to Customer instructions, Service configuration, contractual requirements and applicable law.
Deletion from active systems may not result in immediate deletion from backups, archives, security logs or legally preserved records. Such copies may remain until overwritten or deleted in the ordinary course, subject to access restrictions and applicable law. MONIT24 may retain information where necessary to prevent fraud or abuse, comply with law, resolve disputes, enforce agreements, or establish, exercise or defend claims.
15. Data Security
MONIT24 uses technical and organizational measures designed to protect Personal Information against unauthorized or unlawful access, acquisition, alteration, disclosure, destruction or loss, taking into account the nature of the processing and reasonably foreseeable risks.
Measures may include access controls, authentication, encryption where appropriate, network and application security controls, logging, monitoring, backup mechanisms, vulnerability management, incident-response processes and organizational safeguards.
No system, transmission method or storage technology can be guaranteed to be completely secure. Accordingly, MONIT24 does not warrant or guarantee absolute security. Customers remain responsible for securing their Accounts, credentials, endpoints, integrations and Customer-controlled systems and for granting access only to authorized persons.
16. Privacy Rights
Depending on location and applicable law, individuals may have rights to request access, confirmation, correction, deletion, restriction, objection, portability, withdrawal of consent, information about processing, opt-out from certain sale/sharing/targeted advertising or profiling, and appeal of certain privacy-request decisions. Individuals may also have the right to lodge a complaint with a competent regulator or supervisory authority.
Rights are subject to the conditions, limitations and exceptions provided by applicable law. MONIT24 may need to verify identity, authority and jurisdiction before acting on a request and may request information reasonably necessary for verification. Where legally permitted, an authorized agent may act on an individual’s behalf subject to appropriate verification.
Requests may be submitted to contact@monit24.com. MONIT24 will respond within the period required by applicable law. We may deny, limit or charge for a request where applicable law permits us to do so, for example where a request is manifestly unfounded, excessive, unverifiable, conflicts with another person’s rights, or falls within a statutory exception.
Where MONIT24 processes relevant Personal Information solely on behalf of a Customer, MONIT24 may refer the request to the Customer and will provide assistance required by applicable law and applicable data-processing terms.
17. Additional Information for EEA Individuals
Where the GDPR applies, individuals may exercise the rights provided by Articles 15–22 GDPR, subject to their statutory conditions and exceptions, including access, rectification, erasure, restriction, data portability, objection and rights concerning qualifying automated decision-making.
An individual has the right to object at any time to processing of Personal Information for direct marketing purposes. Where processing is based on legitimate interests, an individual may object on grounds relating to their particular situation, subject to the conditions of applicable law.
Individuals may lodge a complaint with a competent EEA supervisory authority, in particular in the Member State of habitual residence, place of work or place of the alleged infringement. MONIT24’s EU Representative identified in Section 2.1 may also be contacted regarding GDPR matters.
18. Additional Information for UK Individuals
Where UK GDPR applies, individuals have the rights provided by UK data-protection law, subject to applicable conditions and exceptions, and may lodge a complaint with the UK Information Commissioner’s Office. If MONIT24 is required to appoint a UK representative, the applicable representative details will be made available as required by law.
19. Additional Information for U.S. State Privacy Laws
This Section applies only to the extent a U.S. state comprehensive privacy law applies to MONIT24 and to the relevant individual or processing. Depending on applicable law, residents may have rights to confirm processing, access, correct, delete or obtain a portable copy of Personal Information, and to opt out of qualifying sale, sharing, targeted advertising or profiling.
For purposes of applicable U.S. state privacy laws, the categories of Personal Information MONIT24 may collect are described in Section 3, the purposes are described in Section 5, and the categories of recipients are described in Section 7. Retention criteria are described in Section 14.
Where required, MONIT24 will provide a method to appeal a refusal to act on a privacy request and will provide legally required information regarding further complaint options. MONIT24 will not unlawfully discriminate against an individual for exercising applicable privacy rights.
20. California Privacy Notice
This Section supplements this Policy only if and to the extent the California Consumer Privacy Act, as amended (“CCPA”), applies to MONIT24 and the relevant Personal Information.
During the preceding 12 months, depending on the relevant interaction, MONIT24 may have collected categories including identifiers; customer-record information; commercial information; Internet or other electronic-network activity; approximate geolocation; professional or employment-related information where provided; inferences; and sensitive Personal Information where voluntarily provided or technically necessary for a requested Service.
MONIT24 collects and uses those categories for the business and commercial purposes described in Section 5 and may disclose them to the categories of recipients described in Section 7. MONIT24 retains categories of Personal Information according to the criteria in Section 14.
California residents may have rights to know/access, correct and delete Personal Information and to opt out of qualifying sale or sharing, subject to statutory conditions and exceptions. If MONIT24 uses or discloses sensitive Personal Information in a manner that triggers a statutory right to limit, MONIT24 will provide the required mechanism.
Nothing in this Section constitutes an admission that MONIT24 is subject to the CCPA in circumstances where statutory applicability thresholds, exemptions or exclusions are not satisfied.
21. Children’s Privacy
The Services are not directed to children. A person must be at least 18 years old and have the legal capacity required under the Terms and Conditions to create an Account or use the Services as a contracting Customer.
MONIT24 does not knowingly collect Personal Information from children in violation of applicable law. If you believe a child has unlawfully provided Personal Information to MONIT24, contact us so that we can review the matter and take action required by law.
22. Third-Party Websites, Integrations and Services
The Services may link to, integrate with or depend on third-party websites, applications, platforms or services. This Policy does not govern independent processing performed by those third parties. Their own notices and terms govern processing for which they determine the purposes and means. MONIT24 is not responsible for the privacy practices of independent third parties except to the extent responsibility cannot lawfully be excluded.
23. Legal Requests and Protection of Rights
MONIT24 may preserve, access, use or disclose Personal Information where reasonably believed necessary or appropriate to comply with applicable law or valid legal process; respond to competent authorities; protect the rights, property, systems or safety of MONIT24, its technology or service providers, Customers, users or third parties; investigate fraud, abuse or security incidents; enforce agreements; or establish, exercise or defend legal claims.
Where legally permitted and reasonably appropriate, MONIT24 may seek clarification, narrow, object to or challenge governmental or other legal requests that it reasonably considers unlawful, excessive, invalid or outside the requesting authority’s jurisdiction. Nothing in this Policy requires MONIT24 to challenge a request where MONIT24 determines that doing so would be unlawful, impracticable, disproportionate or contrary to legitimate interests.
24. Corporate Transactions
Personal Information may be disclosed, transferred or otherwise processed as part of due diligence or an actual or proposed merger, acquisition, financing, investment, reorganization, bankruptcy, sale of assets, transfer of business, change of control or similar transaction, subject to applicable law. A successor or acquiring entity may continue to process Personal Information consistently with this Policy unless and until a different notice is lawfully provided.
25. Changes to this Privacy Policy
MONIT24 may update this Policy from time to time to reflect changes in the Services, processing practices, providers, technology, law or regulatory guidance. The “Last Updated” date identifies the most recent revision.
Where applicable law requires additional notice or consent for a material change, MONIT24 will provide such notice or obtain such consent. Otherwise, the updated Policy applies from its stated effective date. Prior versions may be retained where required by law or for legitimate recordkeeping purposes.
26. Contact
Questions, complaints and privacy requests may be directed to:
MONIT24 LLC
30 N Gould St, STE R
Sheridan, Wyoming 82801
United States
Email: contact@monit24.com
For GDPR matters, where Article 27 GDPR applies, you may also contact:
Monit24.pl Sp. z o.o. — EU Representative
Plac Wolnica 13/10
31-060 Kraków, Poland
Email: kontakt@monit24.pl
APPENDIX 1
GLOBAL DATA PROCESSING ADDENDUM
to the MONIT24 LLC Privacy Policy
This Global Data Processing Addendum (“DPA”) forms part of the Agreement governing Customer’s use of the Services where and to the extent MONIT24 processes Customer Personal Data on behalf of Customer as a processor, service provider, contractor or equivalent entity under Applicable Data Protection Law. By entering into or using the Services under the Agreement, Customer agrees to this DPA where applicable.
DPA 1. Definitions and Scope
“Applicable Data Protection Law” means privacy, data-protection and data-security law applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, the California Consumer Privacy Act as amended (“CCPA”), and other applicable U.S. state comprehensive privacy laws. “Customer Personal Data” means Personal Information or personal data processed by MONIT24 on behalf of Customer in connection with the Services. “Controller,” “processor,” “business,” “service provider,” “contractor,” “data subject,” “consumer,” “processing,” and equivalent terms have the meanings given by Applicable Data Protection Law.
This DPA applies only to processing in which Customer determines the purposes and essential means of processing and MONIT24 processes Customer Personal Data on Customer’s behalf. It does not apply to processing for which MONIT24 independently determines the purposes and means, which is governed by the Privacy Policy and Applicable Data Protection Law.
If this DPA conflicts with the Agreement regarding processing of Customer Personal Data, this DPA controls to the extent necessary to comply with Applicable Data Protection Law. Except for such conflict, the Agreement, including its limitations, exclusions, allocation of risk, dispute provisions and protections for MONIT24 Parties, remains in effect to the maximum extent permitted by law.
DPA 2. Details of Processing
The subject matter of processing is the provision, operation, support, security and maintenance of the Services requested by Customer. Processing continues for the term of the Agreement and for any additional period in which Customer Personal Data is retained or processed in accordance with the Agreement, Customer instructions or law.
The nature and purpose of processing may include collection, receipt, access, recording, organization, storage, hosting, transmission, retrieval, consultation, analysis, monitoring, testing, alerting, anomaly detection, security analysis, troubleshooting, support, backup, deletion and other operations necessary to provide, secure and support the Services.
Categories of data subjects may include, depending on Customer’s use of the Services:
Customer personnel, contractors, representatives and authorized users;
users, customers, prospective customers or other individuals interacting with systems or resources monitored by Customer;
individuals whose identifiers, communications, transaction data, network data, logs or other information appear in monitored resources, test scenarios, responses, alerts or security events; and
other individuals whose Personal Data Customer chooses or causes to be processed through the Services.
Types of Customer Personal Data may include, depending on Customer configuration and use:
identifiers and contact information;
account, user, device, network and online identifiers, including IP addresses;
authentication information, tokens, credentials or test-account information supplied by Customer;
URLs, request and response data, headers, logs, events, timestamps and technical telemetry;
transaction, application, monitoring, availability, performance and diagnostic information;
security events, anomaly data, alerts, findings and related metadata;
content or other Personal Data incidentally contained in monitored resources, synthetic transactions, responses or logs.
Customer determines the actual categories and volume of Customer Personal Data submitted to or generated through the Services. Unless expressly agreed in writing, the Services are not intended for Customer to submit special categories of personal data under Article 9 GDPR, highly sensitive personal data, government identification numbers, protected health information or other specially regulated data except where technically necessary for an authorized monitoring scenario and Customer has established all required legal bases and safeguards.
DPA 3. Customer Instructions and Responsibilities
Customer instructs MONIT24 to process Customer Personal Data as necessary to provide, secure, maintain and support the Services; to perform Customer-configured monitoring, testing, alerting and cybersecurity functions; to comply with documented instructions submitted through the Services or agreed in writing; and to comply with applicable law.
Customer is responsible for the lawfulness, accuracy and appropriateness of its instructions and Customer Personal Data, and represents that it has all rights, permissions, legal bases, notices and authorizations required to provide Customer Personal Data to MONIT24 and instruct the processing contemplated by the Agreement.
Customer is responsible for determining whether the Services are suitable for Customer’s processing, configuring the Services appropriately, limiting Customer Personal Data to what is reasonably necessary, responding to data subjects where Customer is responsible for doing so, and complying with obligations applicable to Customer as controller or business.
If MONIT24 reasonably believes a Customer instruction violates Applicable Data Protection Law, MONIT24 may inform Customer and suspend the affected processing until the instruction is clarified, modified or confirmed to be lawful, except where law prohibits such notice. MONIT24 is not required to provide legal advice concerning Customer’s instructions.
DPA 4. MONIT24 Processing Obligations
– process Customer Personal Data only on documented Customer instructions, including with regard to transfers, unless processing is required by applicable law; where legally permitted, MONIT24 will inform Customer of such legal requirement before processing;
– ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
– implement and maintain technical and organizational measures designed to provide a level of security appropriate to the risk, taking into account the nature of the Services and processing;
– reasonably assist Customer, taking into account the nature of processing and information available to MONIT24, with Customer’s obligations concerning data-subject rights, security, breach notification, data-protection impact assessments and prior consultation, to the extent required by law;
– delete or return Customer Personal Data after termination or expiration as provided in this DPA and the Agreement, unless law requires retention;
– make available information reasonably necessary to demonstrate compliance with applicable processor obligations, subject to the audit provisions below.
DPA 5. Security
MONIT24 will maintain technical and organizational safeguards appropriate to the risk presented by processing, which may include, as appropriate to the relevant Service, access controls, authentication, encryption where appropriate, logging, monitoring, network and application security controls, backup and recovery measures, vulnerability management, incident-response processes and organizational security controls.
Customer acknowledges that security is a shared responsibility and that no service can eliminate all risk. Customer is responsible for securing Customer-controlled systems, credentials, endpoints, accounts and integrations, and for notifying MONIT24 of material security requirements that are not reasonably apparent from Customer’s ordinary use of the Services.
DPA 6. Personal Data Breaches
MONIT24 will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data for which notification to Customer is required by Applicable Data Protection Law. Such notice does not constitute an admission of fault or liability.
Taking into account information available to MONIT24, MONIT24 will provide information reasonably required for Customer to meet applicable breach-notification obligations and will provide reasonable cooperation required by law. Customer remains responsible for determining whether notification to any authority, individual or other person is required and for the content and timing of Customer’s notifications, except where law places that responsibility on MONIT24.
DPA 7. Subprocessors
Customer grants MONIT24 general written authorization to engage affiliates and third parties as subprocessors to process Customer Personal Data in connection with the Services. MONIT24 will impose on each subprocessor data-protection obligations no less protective than those applicable to MONIT24 under this DPA with respect to the processing performed by that subprocessor, to the extent required by Applicable Data Protection Law.
MONIT24 may maintain or make available a current list of material subprocessors or otherwise provide information about subprocessors upon reasonable request where required by law. Where Applicable Data Protection Law requires advance notice of an intended addition or replacement of a subprocessor, MONIT24 will provide such notice through a reasonable electronic mechanism, publication, account notice or other method permitted by law.
Where Customer has a statutory right to object to a new subprocessor, Customer must submit a documented objection based on reasonable data-protection grounds within the applicable notice period. The parties will seek a commercially reasonable solution. If no reasonable solution is available, MONIT24 may discontinue the affected feature or Customer may terminate the affected Service to the extent required by applicable law. Customer may not use a subprocessor objection solely to obtain commercial concessions or avoid payment obligations.
MONIT24 remains responsible for a subprocessor’s performance of its data-protection obligations to the extent required by Applicable Data Protection Law, subject to the liability framework of the Agreement to the maximum extent permitted by law.
DPA 8. Data Subject and Consumer Requests
Taking into account the nature of processing, MONIT24 will provide reasonable assistance required by Applicable Data Protection Law to enable Customer to respond to requests concerning Customer Personal Data. If MONIT24 receives a request directly from a data subject or consumer concerning Customer Personal Data for which Customer is responsible, MONIT24 may direct the requester to Customer and, where appropriate and legally permitted, notify Customer.
MONIT24 will not independently respond to such a request on Customer’s behalf except on Customer’s documented instruction or where required by law. Customer is responsible for verifying requests and determining the substantive response.
DPA 9. Deletion and Return
Upon termination or expiration of the applicable Services, and at Customer’s choice to the extent required by Applicable Data Protection Law, MONIT24 will delete or return Customer Personal Data and delete existing copies, unless applicable law requires retention. Customer must communicate any legally available choice to return Customer Personal Data within the applicable retrieval period and using the export, retrieval or other return mechanisms reasonably made available by MONIT24. If Customer does not timely exercise an applicable right to request return, MONIT24 may proceed with deletion in accordance with the Agreement and its ordinary retention and deletion procedures, to the extent permitted by Applicable Data Protection Law.
Deletion from active systems may not immediately remove Customer Personal Data from backups, disaster-recovery copies, security records or immutable logs. Such residual copies may be retained until overwritten or deleted in the ordinary course, remain protected under this DPA, and not be restored except for legitimate recovery, security or legal purposes.
DPA 10. Audits and Compliance Information
MONIT24 will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. To the extent an audit right is required by Applicable Data Protection Law, Customer may exercise it subject to the safeguards in this Section.
Where reasonably sufficient, Customer will first rely on current third-party certifications, audit reports, security documentation, questionnaires or other compliance information made available by MONIT24. If additional audit activity is legally required and the available information is insufficient, Customer may request an audit no more than once in any 12-month period, unless a Personal Data Breach or competent supervisory authority reasonably requires additional review.
Audits must be conducted on reasonable prior written notice, during normal business hours, without unreasonable interference with MONIT24 or other customers, and subject to confidentiality, security, access-control and third-party restrictions. Customer may not access information relating to other customers, penetration-test systems without express written authorization, or obtain MONIT24 or third-party trade secrets beyond what applicable law requires.
To the extent permitted by law, Customer will bear its own audit costs and reimburse MONIT24 for reasonable costs of audit assistance that materially exceeds ordinary compliance support, unless the audit identifies a material breach by MONIT24 of its obligations under this DPA.
DPA 11. International Transfers
Customer authorizes MONIT24 to process Customer Personal Data in the United States, the European Economic Area and other locations used by MONIT24 or authorized subprocessors, subject to Applicable Data Protection Law.
Where a restricted international transfer requires an approved transfer mechanism, the parties will rely on an applicable adequacy decision, recognized certification framework, standard contractual clauses, UK transfer mechanism or other lawful mechanism.
Where the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 are required for a transfer, the applicable SCCs, including the appropriate module, selections and completed annexes, as made available by MONIT24 or otherwise entered into by the parties, will form part of this DPA and the Agreement. The parties will provide and maintain the information reasonably necessary to complete the applicable SCCs and annexes as required by law.
Nothing in this DPA modifies the SCCs in a manner prohibited by their terms. In the event of a conflict between the SCCs and this DPA or the Agreement concerning a transfer governed by the SCCs, the SCCs will prevail to the extent of that conflict.
DPA 12. U.S. Service Provider / Contractor Terms
Where an applicable U.S. state privacy law treats Customer as a business/controller and MONIT24 as a service provider, contractor or processor with respect to Customer Personal Data, MONIT24 will process such data for the limited and specified purposes described in the Agreement and this DPA and will comply with applicable statutory restrictions on retaining, using, disclosing, selling or sharing such data.
MONIT24 will not sell Customer Personal Data or share it for cross-context behavioral advertising where prohibited for a service provider or contractor, and will not combine Customer Personal Data with personal information received from or on behalf of another person or collected from MONIT24’s own interaction with a consumer except where permitted by applicable law.
Customer may take reasonable and appropriate steps required by applicable law to help ensure MONIT24 uses Customer Personal Data consistently with Customer’s obligations, subject to the audit and confidentiality safeguards of this DPA. If MONIT24 determines it can no longer meet an applicable service-provider, contractor or processor obligation, it will provide notice where required by law.
DPA 13. Assistance; Additional Services
MONIT24 will provide assistance expressly required of a processor under Applicable Data Protection Law, taking into account the nature of processing and information available to MONIT24. Requests that require custom development, extensive data reconstruction, bespoke reporting, legal analysis, repeated manual work or professional services beyond MONIT24’s mandatory processor obligations may be subject to reasonable fees if permitted by law and agreed with Customer.
DPA 14. Liability and Allocation of Risk
The liability, exclusions, disclaimers, indemnities, claim procedures, limitations of liability and allocation of risk in the Agreement apply to this DPA and processing under it to the maximum extent permitted by Applicable Data Protection Law. Nothing in this DPA limits liability or rights that cannot lawfully be limited by contract.
For clarity, this DPA does not create a separate or additional aggregate liability cap unless mandatory law requires otherwise. Any amounts arising under this DPA are included within, and not in addition to, the applicable aggregate liability limits under the Agreement to the maximum extent permitted by law.
DPA 15. Term and Termination
This DPA becomes effective when it applies to processing under the Agreement and remains in effect for as long as MONIT24 processes Customer Personal Data on Customer’s behalf. Provisions that by their nature must survive termination, including confidentiality, deletion/return, audit limitations, international-transfer safeguards and liability provisions, survive for as long as required by applicable law or necessary to give them effect.
DPA 16. Order of Precedence and Changes Required by Law
If Applicable Data Protection Law requires a provision that is not expressly stated in this DPA, the parties intend this DPA to be interpreted to include the minimum mandatory requirement to the extent legally permissible. If a provision of this DPA is invalid or unenforceable, the remainder remains effective and the provision will be interpreted or modified only to the minimum extent necessary to comply with mandatory law.
MONIT24 may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, regulatory requirements, transfer mechanisms, Services or subprocessors, provided that an update does not materially reduce mandatory data-protection protections applicable to Customer Personal Data. Where law requires notice, consent or a different amendment mechanism, MONIT24 will comply with that requirement.
DPA Schedule 1 — Processing Description