1. Who we are
MONOLITLABS is the trading name of PT MONOLIT LABS AGENCY, an entity established under the laws of the Republic of Indonesia with 0705260039259 and registered address at Subak Sari Street, Sri Khayangan Lane No. 98, Canggu Village/Subdistrict, North Kuta District, Badung Regency, Bali Province, ZIP Code: 80361(“MONOLITLABS,” “we,” “us,” or “our”).
For the personal data described in this Privacy Policy, MONOLITLABS acts as the Personal Data Controller unless we state otherwise.
Our Website is monolitlabs.ai. Privacy requests may be sent to contact@monolitlabs.ai.
2. Scope
This Privacy Policy explains how we process personal data when you:
- visit or interact with the Website;
- submit an enquiry or contact form;
- subscribe to marketing communications, if offered;
- interact with the Website chat assistant;
- communicate with us about a possible project;
- become a client, supplier, partner or business contact; or
- apply for a role with MONOLITLABS.
A Client Agreement, data-processing agreement or project-specific notice may provide additional terms. Where MONOLITLABS processes personal data solely on a client’s documented instructions, the client may be the Controller and MONOLITLABS may act as a Processor.
3. Personal data we collect
We collect only data reasonably relevant to the stated purpose.
A. Information you provide
Depending on how you interact with us, this may include:
- name;
- work email address;
- telephone or WhatsApp number;
- company, organization, role and job title;
- country, time zone and preferred meeting time;
- enquiry details, project needs, budget range and intended timeline;
- messages, chat-assistant questions and files you intentionally submit;
- communication preferences and consent records;
- proposal, contract, billing and transaction information if you become a client;
- project contacts, stakeholders and authorized system-access information;
- supplier, partner or professional-contact information; and
- application, CV, portfolio and recruitment information if you apply for a role.
We do not ask you to submit payment-card details, passwords, private keys, API keys, identity documents, regulated data or confidential production datasets through a public Website form or the chat assistant.
B. Information collected automatically
When you visit the Website, our systems and approved service providers may collect:
- IP address;
- browser, operating system and device type;
- language, time zone and approximate location derived from IP;
- referring page and requested URL;
- pages viewed, actions taken and date/time of access;
- cookie, session or similar identifiers;
- Website performance, error and security logs; and
- consent choices.
See “Cookies and similar technologies” below for the technologies in use.
C. Information from third parties
We may receive personal data from:
- a colleague or organization that refers or introduces you;
- scheduling, form, email, CRM or communication providers you use to contact us;
- social and professional networks when you interact with our public pages;
- publicly available business sources used for proportionate B2B research;
- service providers supporting fraud prevention, security or Website operations; and
- clients, suppliers and partners involved in a project or business relationship.
If you provide personal data about another person, you must have a lawful basis and authority to do so and provide them with any required notice.
4. Why we process personal data
We process personal data only where we have a lawful basis under applicable law.
| Purpose | Typical data | Typical lawful basis |
|---|---|---|
| Operate, secure and troubleshoot the Website | Technical, device, log and security data | Legitimate interests in reliable and secure operations; legal obligations where applicable |
| Respond to enquiries and arrange meetings | Identity, contact, company and enquiry details | Steps requested before a possible contract; legitimate interests; consent where required |
| Assess project fit and prepare proposals | Business needs, stakeholders, scope, timing and budget context | Steps requested before a contract; legitimate interests |
| Deliver and administer client work | Contact, contract, billing and project data | Performance of a contract; legal obligations; legitimate interests |
| Maintain business records and meet legal duties | Contract, transaction, communication and compliance records | Legal obligations; legitimate interests |
| Improve the Website, content and services | Usage, feedback and aggregated analytics | Legitimate interests; consent for optional analytics where required |
| Send marketing communications | Name, work email, organization, interests and consent record | Consent or another lawful basis permitted for B2B communications |
| Operate the chat assistant | Submitted message, contact details and relevant Website data | Consent; requested pre-contractual steps; legitimate interests, depending on the feature |
| Protect rights and prevent misuse | Enquiry, technical, security and communication data | Legitimate interests; legal claims; legal obligations |
| Review job applications | Identity, contact, employment and portfolio data | Requested pre-contractual steps; consent where required; legal obligations |
Where we rely on consent, you may withdraw it. Withdrawal does not affect processing that was lawful before withdrawal or processing supported by another lawful basis.
5. Sensitive and confidential information
The public Website is not designed to collect specific or sensitive personal data.
Do not send health data, biometric data, criminal records, financial-account credentials, identity documents, private keys, passwords, confidential datasets or personal data belonging to your customers through a public form, email or the chat assistant unless we have agreed an appropriate lawful and secure process.
If a project requires sensitive or regulated information, the data categories, roles, safeguards, retention and transfer arrangements must be addressed in the Client Agreement or a separate data-processing agreement before access is provided.
6. Cookies and similar technologies
The Website uses the following technologies.
Essential technologies
- Local storage in your browser for your theme preference and, if you use the chat assistant, a session identifier and your conversation transcript. The transcript is stored on your own device and can be cleared through the chat or your browser.
- Hosting, security and load managementthrough our infrastructure providers (see “When we share personal data”).
Optional technologies
- Google Tag Manager is used to manage measurement tags. Tags loaded through it (such as Google Analytics) may set cookies or similar identifiers to help us understand Website usage and performance. Where the law of your location requires consent for these technologies, they must operate only after an appropriate consent choice.
- Embedded map tiles from CARTO / OpenStreetMap on the contact page. Loading map imagery sends your IP address to the tile provider.
Fonts are self-hosted; viewing the Website does not send requests to third-party font services.
You can use the Website’s cookie controls, when available, or your browser settings to reject or remove optional cookies. Blocking essential technologies may affect Website functionality. If advertising or retargeting technologies are introduced, this Policy and the consent interface will be updated before activation.
7. Automated and AI-assisted processing
If you use the Website chat assistant, we process the information you submit using MONOLITLABS systems (an automation platform we operate) and approved AI or cloud service providers (OpenAI, Anthropic).
We do not intend to make decisions producing legal or similarly significant effects about Website visitors solely through automated processing.
Automated output may be reviewed by our team to respond to your enquiry, assess fit, improve quality or protect the Website. Do not submit confidential or sensitive information unless the feature explicitly states that it is approved for that purpose.
8. When we share personal data
We may share personal data only as reasonably necessary with:
- Hosting and infrastructure:Amazon Web Services (website hosting and content delivery; static media served from the Asia Pacific / Singapore region);
- Enquiry handling: our own database and self-hosted CRM, where contact-form submissions are stored, and Google (Gmail SMTP) for sending enquiry-confirmation emails from contact@monolitlabs.ai;
- Measurement: Google (Tag Manager and analytics tags as described above);
- Chat assistant: our self-hosted automation platform (n8n) and the approved AI provider noted in Section 7;
- professional advisers such as lawyers, accountants, auditors and insurers;
- government, regulatory, judicial or law-enforcement authorities where required or lawfully requested;
- counterparties and advisers involved in a merger, financing, restructuring or sale, subject to appropriate confidentiality and legal safeguards; and
- clients, suppliers or partners where necessary for an agreed project and legally permitted.
Service providers may process personal data only for authorized purposes and must be subject to appropriate contractual, confidentiality and security obligations.
We do not sell personal data.
9. Client project data
During a client engagement, MONOLITLABS may receive access to personal data controlled by the client.
The Client Agreement or data-processing agreement should specify:
- whether MONOLITLABS acts as Controller, Processor or both for different activities;
- the categories of data and individuals;
- documented processing instructions;
- authorized subprocessors;
- confidentiality and security responsibilities;
- international transfers;
- incident reporting;
- assistance with individual rights; and
- return, deletion or retention at the end of the engagement.
This public Privacy Policy does not replace a project-specific data-processing agreement.
10. International transfers
Our service providers or project collaborators may process personal data outside Indonesia. For example, Website media is served from Singapore, and Google services may process data in other countries.
Before transferring personal data internationally, we will use a mechanism permitted by applicable Indonesian law, which may include:
- confirming an equivalent or higher level of protection in the receiving jurisdiction;
- implementing adequate and binding safeguards; or
- obtaining consent where the required protection or safeguards are not otherwise available.
We will also apply any mandatory contractual, security or notice requirements relevant to the transfer.
11. Retention
We retain personal data only for as long as necessary for the stated purpose, legal obligations, dispute management and security.
| Data category | Retention |
|---|---|
| General enquiries that do not become projects | Up to 24 months after the last meaningful interaction |
| Marketing subscription and consent records | Until withdrawal or up to 24 months after the last meaningful engagement, plus a minimal suppression record where necessary |
| Website analytics | Up to 14 months, unless configured for a shorter period |
| Security and server logs | Up to 12 months, unless a longer period is required to investigate an incident |
| Chat-assistant conversations | Up to 12 months, unless converted into a project record or deleted sooner |
| Unsuccessful proposals | Up to 24 months after the proposal expires or discussions end |
| Client contracts, invoices and required accounting/tax records | For the period required by Indonesian law and any applicable Client Agreement |
| Active project data | For the engagement and agreed support period, followed by return, deletion or defined archival retention |
| Recruitment applications | Up to 12 months after the process ends, unless you consent to a longer talent-pool period |
We may retain limited information for longer where required by law, necessary for legal claims, or needed to record an opt-out. Data may remain temporarily in protected backups until the normal backup cycle completes.
12. Security
We use reasonable technical and organizational measures appropriate to the nature and risk of the personal data we process. Measures may include access controls, authentication, least-privilege access, encryption where appropriate, logging, backups, vendor review, confidentiality obligations and incident procedures.
No Internet transmission or storage system is completely secure. You are responsible for using approved secure channels and not sending credentials or sensitive data through public Website features.
13. Your rights
Subject to applicable Indonesian law and lawful exceptions, you may have the right to:
- receive clear information about our identity, purposes, lawful basis and accountability;
- complete, update or correct inaccurate personal data;
- access and obtain a copy of personal data about you;
- request the end of processing, deletion or destruction of personal data;
- withdraw consent;
- object to decisions based solely on automated processing that have legal or similarly significant effects;
- request proportionate restriction or delay of processing;
- obtain or transmit personal data in a commonly usable, machine-readable format where applicable; and
- bring a claim and seek compensation for unlawful processing.
Submit a recorded request to contact@monolitlabs.ai. We may ask for information necessary to verify your identity and authority. We will respond within the period required by applicable law and explain any lawful refusal or limitation.
If your request relates to data we process solely for a client, we may direct the request to that client or assist the client according to our agreement.
14. Direct marketing
Where permitted, we may send relevant B2B updates or service information.
You can unsubscribe using the link in the message or by contacting contact@monolitlabs.ai. We may retain minimal information necessary to respect your opt-out.
We will not sell your personal data or send unrelated third-party marketing using your contact details.
15. Children
The Website and our business services are intended for business users and are not directed to children.
We do not knowingly seek personal data from children through the Website. If you believe a child has submitted personal data, contact us so we can investigate and take appropriate action under applicable law.
16. Personal-data incidents
If a personal-data protection failure occurs, we will investigate, contain and document it and provide legally required notifications to affected individuals and the competent authority within the applicable period.
Please report suspected privacy or security incidents to contact@monolitlabs.ai without sending passwords, private keys or unnecessary personal data.
17. Third-party websites
The Website may contain links to third-party websites and services. Their privacy practices are governed by their own policies. We encourage you to review those policies before providing personal data.
18. Changes to this Policy
We may update this Privacy Policy when our Website, providers, processing activities or legal obligations change.
We will post the updated version and revise the “Last updated” date. Where required by law, we will provide additional notice or obtain renewed consent before a material change takes effect.
19. Contact
For privacy questions, rights requests or complaints:
- Personal Data Controller: PT MONOLIT LABS AGENCY, trading as MONOLITLABS
- Email: contact@monolitlabs.ai
- Registered address: Subak Sari Street, Sri Khayangan Lane No. 98, Canggu Village/Subdistrict, North Kuta District, Badung Regency, Bali Province, ZIP Code: 80361
- Website: monolitlabs.ai