DATA PROCESSING
Data Processing Addendum
A plain-language summary of how Monroe processes data on your behalf. The signed DPA is available on request.
Private beta notice. The signed DPA is provided as a standalone document for enterprise customers. To request the latest version under review, email legal@getmonroe.com. What follows is a summary of the intended terms.
Roles
For data Monroe processes on your behalf through your authorized connectors, you are the Data Controller and Monroe is the Data Processor. For data Monroe collects directly to operate the Service (e.g., your account information), Monroe is the Controller.
Subprocessors
Monroe maintains a current list of subprocessors, with regions, on the canonical sub-processor table at getmonroe.com/security. We notify Customers 30 days before adding a new subprocessor and provide an objection mechanism.
Security measures
- HTTPS for public traffic and encrypted production storage by default.
- Least-privilege connector scoping; tenant isolation reviewed during Enterprise onboarding.
- Third-party penetration testing planned before general availability.
- SOC 2 Type I in progress with Vanta (Q3 2026 target); Type II to follow.
- Incident response and notification commitments documented in the signed agreement.
International transfers
For transfers of personal data outside the EEA or UK, Monroe expects to rely on Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where applicable. Data residency requirements are reviewed during Enterprise onboarding.
Data subject requests
Monroe will assist Customer in fulfilling data subject requests (access, deletion, portability) within statutory timeframes. Requests should be initiated through Customer’s account or via privacy@getmonroe.com.
Audit rights
Customer audit rights are defined in the signed DPA or MSA. Until a SOC 2 report is available, Monroe can provide architecture and control evidence under NDA where appropriate.
Termination
On termination, Monroe will, at Customer’s choice, return or delete all personal data within 30 days, except as required by law.