1. Who is responsible for your information
The data controller for this website is Monolith Corp, trading as Monolith Studio. Correspondence address: United Kingdom — correspondence via hello@monolith-corp.org. Website: https://monolith-studios.org/. Privacy contact: privacy@monolith-corp.org.
2. Information we may collect
Depending on how you use the site, we may collect:
- contact and business details you submit (name, email, phone, company, project brief);
- account credentials and portal activity when you sign in;
- support tickets, change requests and related messages;
- technical data such as IP address, browser type, pages viewed and approximate location derived from IP;
- cookie preference choices and, where enabled, first-party analytics events;
- billing metadata if a payment integration is used for your engagement;
- for client portals: customer/lead records, catalogue content, QR campaign events and site analytics that you or your team enter or that your live site sends to our collector.
3. Why we use it
PurposeTypical lawful basis
Respond to enquiries and prepare proposalsSteps before a contract / legitimate interests
Deliver contracted design, development and care servicesContract
Operate accounts, security, billing and supportContract / legitimate interests / legal obligations
Improve website performance and understand usageConsent where required for non-essential analytics; otherwise legitimate interests where lawful
Send email or SMS marketingConsent, soft opt-in where available, or another lawful route where applicable
Process client customer/lead data in the portal on a client’s instructionsProcessor role under the client’s instructions (see data processing page)
4. Marketing preferences
Email and SMS preferences are treated separately. Where consent is required, it is a clear positive choice and can be withdrawn later. Marketing messages identify the sender and provide a simple way to opt out. Suppression records may be retained so an opt-out can be respected. You can manage preferences at /unsubscribe.
5. Cookies and similar technologies
Strictly necessary storage is used for security, sessions and remembering cookie choices. Analytics or marketing technologies are not activated until the appropriate consent has been obtained where required. See the cookie notice.
6. Sharing and processors
We use service providers only as needed to run the studio and portal. Current categories:
- Hosting and infrastructure — the Monolith Studio application and related static client sites are hosted on our production server (Linux, nginx, Node.js) at monolith-studios.org;
- Application data storage — account, ticket, client and analytics event data are stored as secured files on that server under access controls for the Monolith service account;
- Email — transactional or marketing email providers (for example Resend or Postmark) only when connected for a live engagement; otherwise enquiry mail is handled manually via our support inbox;
- Payments — Stripe only if payment processing is enabled for a specific engagement;
- Search / SEO tooling — Google Search Console or similar only when a client site is connected for SEO reporting;
- Professional advisers — accountants or lawyers where disclosure is necessary and appropriate.
We do not sell personal data. Third-party analytics tags (for example Google Analytics, Plausible or PostHog) are not loaded on the Monolith Studio marketing site unless you consent and a provider is actively connected.
7. International transfers
Primary hosting for this deployment is in the United Kingdom / European Economic Area region used by our server provider. If a connected supplier processes personal data outside the UK, we use an appropriate transfer mechanism such as an adequacy regulation or UK International Data Transfer Agreement / standard contractual clauses, depending on the destination and supplier.
8. Retention
Record typeRetention
Website enquiries that do not become clientsUp to 24 months from last meaningful contact, then deleted or anonymised
Client contracts, invoices and project correspondenceDuration of the engagement plus up to 6 years (UK limitation periods / accounting)
Portal accounts and support ticketsDuration of the service, then up to 12 months after closure unless a longer legal need applies
First-party analytics events (client site collector)Up to 26 months in identifiable or pseudonymous form, then aggregated or deleted
Cookie consent choices (browser)Until cleared by you, or about 180 days for the acknowledgement cookie
Marketing consent and suppression recordsWhile the preference is active, and suppression for at least 3 years after opt-out
Server access logsTypically up to 90 days unless needed longer for security investigation
9. Your rights
Depending on the circumstances, people may have rights including access, correction, deletion, restriction, portability, objection and withdrawal of consent. Requests can be sent to privacy@monolith-corp.org or submitted via privacy rights. We aim to respond within one month. You may also complain to the UK Information Commissioner’s Office (ICO).
10. Automated decisions
The Monolith Studio site and client portal do not make solely automated decisions that produce legal or similarly significant effects about individuals. Pricing estimates are planning tools only.
11. Children
This site is aimed at businesses and adults evaluating professional services. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact privacy@monolith-corp.org.
12. Changes
We update this notice when services, processors or legal requirements change. The “last reviewed” date at the top of this page shows when it was last checked. Material new uses of personal data will be explained before they begin where the law requires.