LEGAL / PRIVACY POLICYLAST UPDATED — 16 JULY 2026

PRIVACY POLICY

1. Who we are

MONOLITLABS is the trading name of PT MONOLIT LABS AGENCY, an entity established under the laws of the Republic of Indonesia with 0705260039259 and registered address at Subak Sari Street, Sri Khayangan Lane No. 98, Canggu Village/Subdistrict, North Kuta District, Badung Regency, Bali Province, ZIP Code: 80361(“MONOLITLABS,” “we,” “us,” or “our”).

For the personal data described in this Privacy Policy, MONOLITLABS acts as the Personal Data Controller unless we state otherwise.

Our Website is monolitlabs.ai. Privacy requests may be sent to contact@monolitlabs.ai.

2. Scope

This Privacy Policy explains how we process personal data when you:

  • visit or interact with the Website;
  • submit an enquiry or contact form;
  • subscribe to marketing communications, if offered;
  • interact with the Website chat assistant;
  • communicate with us about a possible project;
  • become a client, supplier, partner or business contact; or
  • apply for a role with MONOLITLABS.

A Client Agreement, data-processing agreement or project-specific notice may provide additional terms. Where MONOLITLABS processes personal data solely on a client’s documented instructions, the client may be the Controller and MONOLITLABS may act as a Processor.

3. Personal data we collect

We collect only data reasonably relevant to the stated purpose.

A. Information you provide

Depending on how you interact with us, this may include:

  • name;
  • work email address;
  • telephone or WhatsApp number;
  • company, organization, role and job title;
  • country, time zone and preferred meeting time;
  • enquiry details, project needs, budget range and intended timeline;
  • messages, chat-assistant questions and files you intentionally submit;
  • communication preferences and consent records;
  • proposal, contract, billing and transaction information if you become a client;
  • project contacts, stakeholders and authorized system-access information;
  • supplier, partner or professional-contact information; and
  • application, CV, portfolio and recruitment information if you apply for a role.

We do not ask you to submit payment-card details, passwords, private keys, API keys, identity documents, regulated data or confidential production datasets through a public Website form or the chat assistant.

B. Information collected automatically

When you visit the Website, our systems and approved service providers may collect:

  • IP address;
  • browser, operating system and device type;
  • language, time zone and approximate location derived from IP;
  • referring page and requested URL;
  • pages viewed, actions taken and date/time of access;
  • cookie, session or similar identifiers;
  • Website performance, error and security logs; and
  • consent choices.

See “Cookies and similar technologies” below for the technologies in use.

C. Information from third parties

We may receive personal data from:

  • a colleague or organization that refers or introduces you;
  • scheduling, form, email, CRM or communication providers you use to contact us;
  • social and professional networks when you interact with our public pages;
  • publicly available business sources used for proportionate B2B research;
  • service providers supporting fraud prevention, security or Website operations; and
  • clients, suppliers and partners involved in a project or business relationship.

If you provide personal data about another person, you must have a lawful basis and authority to do so and provide them with any required notice.

4. Why we process personal data

We process personal data only where we have a lawful basis under applicable law.

PurposeTypical dataTypical lawful basis
Operate, secure and troubleshoot the WebsiteTechnical, device, log and security dataLegitimate interests in reliable and secure operations; legal obligations where applicable
Respond to enquiries and arrange meetingsIdentity, contact, company and enquiry detailsSteps requested before a possible contract; legitimate interests; consent where required
Assess project fit and prepare proposalsBusiness needs, stakeholders, scope, timing and budget contextSteps requested before a contract; legitimate interests
Deliver and administer client workContact, contract, billing and project dataPerformance of a contract; legal obligations; legitimate interests
Maintain business records and meet legal dutiesContract, transaction, communication and compliance recordsLegal obligations; legitimate interests
Improve the Website, content and servicesUsage, feedback and aggregated analyticsLegitimate interests; consent for optional analytics where required
Send marketing communicationsName, work email, organization, interests and consent recordConsent or another lawful basis permitted for B2B communications
Operate the chat assistantSubmitted message, contact details and relevant Website dataConsent; requested pre-contractual steps; legitimate interests, depending on the feature
Protect rights and prevent misuseEnquiry, technical, security and communication dataLegitimate interests; legal claims; legal obligations
Review job applicationsIdentity, contact, employment and portfolio dataRequested pre-contractual steps; consent where required; legal obligations

Where we rely on consent, you may withdraw it. Withdrawal does not affect processing that was lawful before withdrawal or processing supported by another lawful basis.

5. Sensitive and confidential information

The public Website is not designed to collect specific or sensitive personal data.

Do not send health data, biometric data, criminal records, financial-account credentials, identity documents, private keys, passwords, confidential datasets or personal data belonging to your customers through a public form, email or the chat assistant unless we have agreed an appropriate lawful and secure process.

If a project requires sensitive or regulated information, the data categories, roles, safeguards, retention and transfer arrangements must be addressed in the Client Agreement or a separate data-processing agreement before access is provided.

6. Cookies and similar technologies

The Website uses the following technologies.

Essential technologies

  • Local storage in your browser for your theme preference and, if you use the chat assistant, a session identifier and your conversation transcript. The transcript is stored on your own device and can be cleared through the chat or your browser.
  • Hosting, security and load managementthrough our infrastructure providers (see “When we share personal data”).

Optional technologies

  • Google Tag Manager is used to manage measurement tags. Tags loaded through it (such as Google Analytics) may set cookies or similar identifiers to help us understand Website usage and performance. Where the law of your location requires consent for these technologies, they must operate only after an appropriate consent choice.
  • Embedded map tiles from CARTO / OpenStreetMap on the contact page. Loading map imagery sends your IP address to the tile provider.

Fonts are self-hosted; viewing the Website does not send requests to third-party font services.

You can use the Website’s cookie controls, when available, or your browser settings to reject or remove optional cookies. Blocking essential technologies may affect Website functionality. If advertising or retargeting technologies are introduced, this Policy and the consent interface will be updated before activation.

7. Automated and AI-assisted processing

If you use the Website chat assistant, we process the information you submit using MONOLITLABS systems (an automation platform we operate) and approved AI or cloud service providers (OpenAI, Anthropic).

We do not intend to make decisions producing legal or similarly significant effects about Website visitors solely through automated processing.

Automated output may be reviewed by our team to respond to your enquiry, assess fit, improve quality or protect the Website. Do not submit confidential or sensitive information unless the feature explicitly states that it is approved for that purpose.

8. When we share personal data

We may share personal data only as reasonably necessary with:

  • Hosting and infrastructure:Amazon Web Services (website hosting and content delivery; static media served from the Asia Pacific / Singapore region);
  • Enquiry handling: our own database and self-hosted CRM, where contact-form submissions are stored, and Google (Gmail SMTP) for sending enquiry-confirmation emails from contact@monolitlabs.ai;
  • Measurement: Google (Tag Manager and analytics tags as described above);
  • Chat assistant: our self-hosted automation platform (n8n) and the approved AI provider noted in Section 7;
  • professional advisers such as lawyers, accountants, auditors and insurers;
  • government, regulatory, judicial or law-enforcement authorities where required or lawfully requested;
  • counterparties and advisers involved in a merger, financing, restructuring or sale, subject to appropriate confidentiality and legal safeguards; and
  • clients, suppliers or partners where necessary for an agreed project and legally permitted.

Service providers may process personal data only for authorized purposes and must be subject to appropriate contractual, confidentiality and security obligations.

We do not sell personal data.

9. Client project data

During a client engagement, MONOLITLABS may receive access to personal data controlled by the client.

The Client Agreement or data-processing agreement should specify:

  • whether MONOLITLABS acts as Controller, Processor or both for different activities;
  • the categories of data and individuals;
  • documented processing instructions;
  • authorized subprocessors;
  • confidentiality and security responsibilities;
  • international transfers;
  • incident reporting;
  • assistance with individual rights; and
  • return, deletion or retention at the end of the engagement.

This public Privacy Policy does not replace a project-specific data-processing agreement.

10. International transfers

Our service providers or project collaborators may process personal data outside Indonesia. For example, Website media is served from Singapore, and Google services may process data in other countries.

Before transferring personal data internationally, we will use a mechanism permitted by applicable Indonesian law, which may include:

  • confirming an equivalent or higher level of protection in the receiving jurisdiction;
  • implementing adequate and binding safeguards; or
  • obtaining consent where the required protection or safeguards are not otherwise available.

We will also apply any mandatory contractual, security or notice requirements relevant to the transfer.

11. Retention

We retain personal data only for as long as necessary for the stated purpose, legal obligations, dispute management and security.

Data categoryRetention
General enquiries that do not become projectsUp to 24 months after the last meaningful interaction
Marketing subscription and consent recordsUntil withdrawal or up to 24 months after the last meaningful engagement, plus a minimal suppression record where necessary
Website analyticsUp to 14 months, unless configured for a shorter period
Security and server logsUp to 12 months, unless a longer period is required to investigate an incident
Chat-assistant conversationsUp to 12 months, unless converted into a project record or deleted sooner
Unsuccessful proposalsUp to 24 months after the proposal expires or discussions end
Client contracts, invoices and required accounting/tax recordsFor the period required by Indonesian law and any applicable Client Agreement
Active project dataFor the engagement and agreed support period, followed by return, deletion or defined archival retention
Recruitment applicationsUp to 12 months after the process ends, unless you consent to a longer talent-pool period

We may retain limited information for longer where required by law, necessary for legal claims, or needed to record an opt-out. Data may remain temporarily in protected backups until the normal backup cycle completes.

12. Security

We use reasonable technical and organizational measures appropriate to the nature and risk of the personal data we process. Measures may include access controls, authentication, least-privilege access, encryption where appropriate, logging, backups, vendor review, confidentiality obligations and incident procedures.

No Internet transmission or storage system is completely secure. You are responsible for using approved secure channels and not sending credentials or sensitive data through public Website features.

13. Your rights

Subject to applicable Indonesian law and lawful exceptions, you may have the right to:

  • receive clear information about our identity, purposes, lawful basis and accountability;
  • complete, update or correct inaccurate personal data;
  • access and obtain a copy of personal data about you;
  • request the end of processing, deletion or destruction of personal data;
  • withdraw consent;
  • object to decisions based solely on automated processing that have legal or similarly significant effects;
  • request proportionate restriction or delay of processing;
  • obtain or transmit personal data in a commonly usable, machine-readable format where applicable; and
  • bring a claim and seek compensation for unlawful processing.

Submit a recorded request to contact@monolitlabs.ai. We may ask for information necessary to verify your identity and authority. We will respond within the period required by applicable law and explain any lawful refusal or limitation.

If your request relates to data we process solely for a client, we may direct the request to that client or assist the client according to our agreement.

14. Direct marketing

Where permitted, we may send relevant B2B updates or service information.

You can unsubscribe using the link in the message or by contacting contact@monolitlabs.ai. We may retain minimal information necessary to respect your opt-out.

We will not sell your personal data or send unrelated third-party marketing using your contact details.

15. Children

The Website and our business services are intended for business users and are not directed to children.

We do not knowingly seek personal data from children through the Website. If you believe a child has submitted personal data, contact us so we can investigate and take appropriate action under applicable law.

16. Personal-data incidents

If a personal-data protection failure occurs, we will investigate, contain and document it and provide legally required notifications to affected individuals and the competent authority within the applicable period.

Please report suspected privacy or security incidents to contact@monolitlabs.ai without sending passwords, private keys or unnecessary personal data.

17. Third-party websites

The Website may contain links to third-party websites and services. Their privacy practices are governed by their own policies. We encourage you to review those policies before providing personal data.

18. Changes to this Policy

We may update this Privacy Policy when our Website, providers, processing activities or legal obligations change.

We will post the updated version and revise the “Last updated” date. Where required by law, we will provide additional notice or obtain renewed consent before a material change takes effect.

19. Contact

For privacy questions, rights requests or complaints:

  • Personal Data Controller: PT MONOLIT LABS AGENCY, trading as MONOLITLABS
  • Email: contact@monolitlabs.ai
  • Registered address: Subak Sari Street, Sri Khayangan Lane No. 98, Canggu Village/Subdistrict, North Kuta District, Badung Regency, Bali Province, ZIP Code: 80361
  • Website: monolitlabs.ai