1. Introduction & Data Controller
Your privacy matters to us. This Privacy Policy describes how Piensi LTD ("Piensi", "we", "us", or "our") processes personal data in connection with the Monolite service available at getmonolite.com and any related websites, mobile experiences, and APIs (collectively, the "Service").
For the purposes of the European Union General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the United Kingdom GDPR, Piensi LTD is the data controller of personal data collected about Organizers, account holders, and visitors to the public website.
When Organizers run Events using the Service, the Organizer is the data controller of the participant data that they collect, and Piensi LTD acts as a data processor on the Organizer's behalf. Participants should consult the relevant Organizer's notices for the specific purposes of that Event.
2. Scope of this Policy
This policy applies to all personal data we process about Users of the Service. It does not apply to third-party websites or services we link to, which have their own privacy notices.
3. Information We Collect
3.1 Information you provide
- Account data: name, email address, password (stored as a one-way cryptographic hash), profile picture or avatar, optional biographical fields, language preference, and authentication identifiers.
- Workspace and event data: Workspace name, member roles, event titles, questions, answer options, time limits, scoring rules, branding, and any media uploaded for use during Events.
- Participant data: display name, optional photo or avatar, responses submitted during an Event, scores earned, and the unique session identifier created when joining via QR code or link.
- Communications: the content of messages you send to our support team and any feedback you provide.
3.2 Information we collect automatically
- Technical data: IP address, device type, browser type and version, operating system, screen size, language, time zone, referring URL, and timestamps.
- Usage data: pages and features you interact with, actions you take (such as creating an Event or answering a question), error reports, and performance metrics.
- Cookies and local storage: small files and values used to keep you signed in, remember preferences, and secure the Service. See Section 13.
3.3 Information from third parties
- Authentication providers (such as Google) may share basic profile information (name, email, avatar) with us when you choose to sign in with them.
- Payment providers may share limited transaction data (such as the last four digits of your card and the country) if you purchase a paid plan. Full card data is processed by the payment provider, not by us.
4. How We Use Information
We use personal data for the following purposes:
- Service delivery: to create and authenticate accounts, host Workspaces, run Events in real time, calculate scores, display leaderboards, and generate post-event reports.
- Account management: to communicate with you about your account, respond to support requests, and send important service notices.
- Improvement and analytics: to understand how the Service is used, to diagnose bugs, to measure performance, and to design new features. Where possible we use aggregated or pseudonymized data.
- Security and fraud prevention: to detect and prevent unauthorized access, abuse, and violations of our Terms.
- Marketing: with your consent, to send occasional product updates and offers. You can unsubscribe at any time.
- Legal compliance: to comply with applicable law, respond to lawful requests from authorities, and enforce our agreements.
5. Legal Bases for Processing (GDPR Article 6)
When the GDPR or UK GDPR applies, we rely on the following legal bases to process your personal data:
- Performance of a contract (Art. 6(1)(b)) - to provide the Service you have requested, including account creation, running Events, and processing payments.
- Legitimate interests (Art. 6(1)(f)) - to secure the Service, prevent fraud and abuse, improve features, perform aggregate analytics, and communicate important non-marketing information. We balance these interests against your rights and freedoms.
- Consent (Art. 6(1)(a)) - for non-essential cookies (where applicable), optional marketing communications, and any sensitive data you choose to provide.
- Legal obligation (Art. 6(1)(c)) - to comply with tax, accounting, and other legal requirements.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
6. Sharing & Disclosure
We do not sell your personal data. We share it only as described below:
- Service providers (processors): we use carefully selected vendors to host our infrastructure, manage authentication and databases, send transactional email, process payments, run analytics, and provide customer support. These vendors are bound by written data-processing agreements and may only process personal data on our instructions.
- Organizers: when you join an Event as a Participant, the Organizer will receive your display name, your responses, and your scores. The Organizer is a separate controller of that data.
- Other Participants: Event leaderboards, public answers, and similar features may display your display name and score to other Participants in that Event.
- Legal and safety: we may disclose personal data when we believe in good faith that disclosure is necessary to comply with a legal obligation, respond to a lawful request from a public authority, protect our rights or property, or protect the safety of Users or the public.
- Business transfers: if Piensi LTD is involved in a merger, acquisition, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will notify you of any such change and the choices you may have.
7. International Data Transfers
We operate globally, and our service providers may be located in countries outside your country of residence, including outside the European Economic Area (EEA) or the United Kingdom. When we transfer personal data internationally, we put appropriate safeguards in place, such as:
- transfers to countries recognized by the European Commission or the UK government as providing an adequate level of protection;
- the European Commission's Standard Contractual Clauses (and, where relevant, the UK International Data Transfer Addendum) with our processors;
- supplementary technical and organizational measures, such as encryption in transit and access controls.
You can request more information about these safeguards by contacting anil@getmonolite.com.
8. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy and to comply with our legal obligations. Our typical retention periods are:
- Account data: while your account is active and for up to twelve (12) months after closure, to support reactivation and to defend against legal claims.
- Workspace and event content: while the Workspace exists; deleted content is purged from our active systems within thirty (30) days and from backups within an additional ninety (90) days.
- Event analytics and reports: up to twenty-four (24) months after the Event, after which they are aggregated or deleted.
- Server and security logs: typically up to ninety (90) days, longer where required for security investigations.
- Billing records: retained as long as required by applicable tax and accounting law (typically six to ten years).
You may request earlier deletion of your personal data; see Section 9.
9. Your Rights
Subject to applicable law, you have the following rights with respect to your personal data:
- Right of access - to obtain confirmation of whether we process your personal data and a copy of that data.
- Right to rectification - to have inaccurate or incomplete personal data corrected.
- Right to erasure ("right to be forgotten") - to have your personal data deleted in certain circumstances.
- Right to restriction - to have processing restricted in certain circumstances.
- Right to data portability - to receive your personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object - to object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent - where processing is based on consent.
- Right to lodge a complaint - with the data-protection supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
10. How to Exercise Your Rights
You can exercise most rights directly from your account settings (for example, updating your profile or deleting your account). For requests that require manual processing, please contact anil@getmonolite.com. We may need to verify your identity before responding.
We will respond to your request within thirty (30) days of receipt. In complex cases, we may extend that period by up to two additional months and will inform you of the extension and the reasons for it.
If you are a Participant who joined an Event run by an Organizer, please contact that Organizer first, as they control the personal data processed for that Event. We will assist Organizers in responding to such requests where required.
11. Security
We take the security of your personal data seriously and implement technical and organizational measures designed to protect it, including:
- encryption in transit using TLS for all connections to the Service;
- encryption at rest for our primary databases provided by our infrastructure partners;
- row-level security in our database so that Users can only access the data they are authorized to see;
- password hashing with industry-standard algorithms;
- role-based access controls and the principle of least privilege for our staff;
- regular software updates, dependency monitoring, and security reviews;
- logging and monitoring for unusual activity.
No system can be guaranteed to be 100% secure. If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of it, and we will notify affected Users without undue delay where required by law.
12. Children's Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal data from children under that age without the verifiable consent of a parent or legal guardian. If you believe a child has provided personal data to us without such consent, please contact anil@getmonolite.com and we will take appropriate steps to delete it.
13. Cookies & Local Storage
We use a minimal set of cookies and browser-storage entries:
- Strictly necessary: required to keep you signed in, remember your workspace selection, secure the Service, and remember accessibility preferences. These cannot be disabled without breaking core functionality.
- Functional: used to remember preferences such as language and theme.
- Analytics: we use Google Analytics 4 to understand anonymous usage patterns (pages viewed, key conversions such as sign-up and subscription) so we can improve the Service. IP anonymisation is enabled and we do not share this data for advertising purposes.
We do not currently use advertising cookies and we do not allow third parties to use cookies on our website to build advertising profiles of you.
You can control cookies through your browser settings, but disabling strictly necessary cookies will prevent you from using key parts of the Service.
14. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy notices before providing them with any personal data.
15. Automated Decision-Making
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you. Scoring within Events is deterministic - it follows the rules configured by the Organizer - and is not used to profile Users beyond the context of that Event.
16. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, legal requirements, or the Service. When we make material changes, we will provide a reasonable notice - for example, by email or by an in-product notice - before they take effect. The "Last updated" date at the top of this page indicates the most recent revision.
17. Contact & Data Protection Officer
For privacy questions, requests to exercise your rights, or any other matter relating to this policy, please contact:
Data Protection contact for the Monolite service
Privacy & DPO: anil@getmonolite.com
Legal: anil@getmonolite.com
Support: anil@getmonolite.com
If you are based in the EEA, the United Kingdom, or Switzerland and consider that our processing of your personal data infringes data-protection law, you have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.