1. Roles
Monolith Corp (trading as Monolith Studio) is the controller for personal data collected on the Monolith Studio marketing site (enquiries, accounts for our own customers, cookie preferences).
For client-controlled customer, lead and marketing data held in a client portal or collected from a client’s live website, the client is ordinarily the controller and Monolith acts as processor when hosting or managing that data on the client’s documented instructions.
2. Processing scope
Typical processor activities include:
- hosting the client website and related assets;
- operating the client portal (catalogue, tickets, settings);
- enquiry and lead capture into portal records;
- customer records and campaign administration tools;
- first-party analytics and QR attribution collection for the client site;
- backups, support access and automation execution configured for that client.
3. Processor commitments
Where we act as processor we:
- process personal data only on documented client instructions;
- require confidentiality from people who access client data;
- apply appropriate technical and organisational security measures;
- use subprocessors only as described below and under equivalent obligations;
- assist with data subject rights requests referred by the client;
- notify the client without undue delay after becoming aware of a personal data breach;
- delete or return client personal data at the end of the service, subject to legal retention needs;
- make available information reasonably needed to demonstrate compliance.
4. Subprocessors
CategoryCurrent use
Hosting / infrastructureMonolith production server (nginx + Node.js) at monolith-studios.org
Application data storeSecured on-server JSON data directories for accounts, tickets, clients and analytics events
Email deliveryConnected only when a live provider (e.g. Resend or Postmark) is enabled for an engagement
SMS deliveryConnected only when Twilio or equivalent is enabled for an engagement
PaymentsStripe, only if payment processing is part of the engagement
SEO / search reportingGoogle Search Console API, only when a client site is connected
Material subprocessor changes for a live client engagement are communicated to that client with reasonable notice where the DPA requires it.
5. Security
Access to production systems is limited to authorised Monolith operators. Portal sessions use signed HTTP-only cookies. Transport uses HTTPS. Secrets are kept in server environment configuration, not in client-side code. Client data directories are permissioned for the service account. Backups and incident response follow the operational controls for the production host.
6. Marketing data
Consent and suppression data should travel with the customer record. Email and SMS eligibility are evaluated separately because the legal rules and consent history can differ by channel. Marketing sends must check the relevant consent or suppression record before dispatch.
7. Contact
Processing questions: privacy@monolith-corp.org. Commercial contracts and DPAs: hello@monolith-corp.org.