Monolith Solutions
Privacy Policy
Privacy & Data Protection
Privacy Policy
This Privacy Policy explains how Monolith Solutions Inc. collects, uses, discloses, stores and protects
personal information when we operate our website, provide professional and managed services, and process
information through hosting, CRM, automation, analytics, communications and AI-enabled systems.
For information we collect for our own business purposes, Monolith generally determines why and how the
information is processed. When we process personal information inside a client website, CRM, hosted system,
workflow, application or campaign on a client’s instructions, the client generally determines the purposes
of that processing and Monolith acts as a service provider or processor.
Scope of This Policy
This Privacy Policy applies to personal information handled by Monolith Solutions Inc.
(“Monolith,” “we,” “us,” or “our”) in connection with our websites, forms, client relationships,
hosting and infrastructure services, web and software development, managed revenue operations, CRM
implementations, marketing services, communications systems, analytics, automation, artificial intelligence
services, technical support, consulting and related services (collectively, the “Services”).
This Policy applies to website visitors, prospective clients, client representatives, users who communicate
with us, and individuals whose personal information we process for our own business purposes. It also explains
our role when we process information on behalf of a client.
A client-specific agreement, data processing addendum, privacy notice or platform notice may provide additional
information. If a client controls the collection and use of your personal information, that client’s privacy
policy should be read together with this Policy.
Accountability & Privacy Officer
Monolith is responsible for personal information under its control and designates a Privacy Officer to oversee
privacy compliance, requests and complaints.
Calgary, Alberta, Canada
Email: info@monolithsolutions.ca
Telephone: 1-800-637-5090
Subject line for privacy requests: Privacy Request
We maintain privacy practices appropriate to the nature of our Services and may use employees, contractors and
service providers to assist with processing. Those parties receive access only as reasonably required for their
role and are expected to protect information appropriately.
Personal Information We Collect
The information we collect depends on how you interact with us and which Services are being used. We may collect
the following categories:
| Category | Examples | Typical Purpose |
|---|---|---|
| Identifiers & contact information | Name, business name, postal address, email address, telephone number, account identifiers and usernames. | Responding to inquiries, account administration, service delivery, support and communications. |
| Commercial & account information | Services purchased, quotes, proposals, subscriptions, project history, preferences, support records and client relationship information. | Providing Services, billing, relationship management, support and business administration. |
| Payment & transaction information | Billing contact, transaction amount, invoice status, payment method type and processor transaction identifiers. Full payment-card details are generally handled by payment processors rather than stored directly by Monolith. | Payment processing, accounting, fraud prevention, tax and financial records. |
| Technical, device & network information | IP address, browser, device type, operating system, referral URL, timestamps, user agent, server logs, authentication events and error logs. | Security, troubleshooting, fraud prevention, service reliability, analytics and system administration. |
| Usage, analytics & telemetry | Pages viewed, links or buttons used, session information, feature usage, conversion events, campaign attribution and performance data. | Analytics, service improvement, marketing measurement and user experience optimization. |
| Approximate location | Country, province/state, city or region inferred from IP address or provided in contact information. | Security, localization, analytics, service delivery and fraud prevention. |
| Professional & business information | Job title, employer, industry, business needs, organizational role and professional contact details. | B2B service delivery, proposals, account management and communications. |
| Communications & content | Emails, form submissions, chat messages, files, support requests, project instructions, meeting notes and other content you provide. | Responding to you, providing Services, documentation, support and project management. |
| Audio, voice or call information | Call metadata, voicemail, transcription, recordings or synthetic-voice interaction where a Service uses those features and applicable notice or consent requirements are satisfied. | Communications, service delivery, quality, documentation and automation. |
| Sensitive information | Information that may be considered sensitive under applicable law, but only where a Service or client workflow legitimately requires it. | Only for the disclosed service purpose and with safeguards appropriate to the sensitivity and legal requirements. |
| Client-controlled end-user data | Information stored in a client website, CRM, application, hosted database, automation, communications platform or other client-controlled system. | Processing on the client’s instructions to deliver the contracted Service. |
We do not require every category in every situation. We seek to limit collection to information reasonably
necessary for the identified purpose, contractual service, security need or legal obligation.
Sources of Personal Information
We may obtain personal information from:
- you directly, including through forms, email, phone, meetings, checkout, support requests and account use;
- our clients, when a client asks us to operate or support a system containing personal information;
- your device or browser, through logs, cookies, pixels, analytics and similar technologies;
- service providers and integrations, such as payment processors, CRMs, advertising platforms, communications providers and authentication systems;
- business partners or referrals, where sharing is lawful;
- publicly available business sources, such as company websites, professional directories or public business listings; and
- other lawful sources disclosed at or before collection where required.
How We Use Personal Information
Depending on context, we may use personal information to:
- provide, configure, host, maintain and improve the Services;
- respond to inquiries, prepare proposals and manage client relationships;
- create and administer accounts, authentication, permissions and support;
- process payments, invoices, credits, taxes and accounting records;
- develop websites, software, integrations, automations and managed systems;
- deliver requested email, SMS, telephone, chat or other communications;
- operate CRM, lead-management, analytics and attribution workflows;
- provide AI-enabled features, transcription, summarization, classification or automation where part of the Service;
- protect accounts, infrastructure and users against fraud, abuse, malware and unauthorized access;
- monitor performance, troubleshoot problems and maintain system reliability;
- measure website and campaign performance and improve user experience;
- send service notices and, where permitted, marketing communications;
- enforce agreements and protect legal rights;
- comply with tax, accounting, regulatory, court-order and other legal obligations; and
- carry out another purpose that is disclosed and permitted by applicable law.
Consent & Legal Bases for Processing
The legal basis for processing depends on the jurisdiction and context. In Canada, we obtain consent where
required and may collect, use or disclose information without consent where authorized by law. We identify
purposes at or before collection where required and provide a reasonable opportunity to ask questions or
withdraw consent where consent is the applicable basis.
If the GDPR or similar legislation applies, our legal bases may include:
- contract — processing necessary to provide requested Services or take steps before entering a contract;
- consent — where you have made a valid choice, such as certain marketing or optional tracking;
- legitimate interests — such as B2B relationship management, security, fraud prevention, service improvement and ordinary analytics, where those interests are not overridden by your rights;
- legal obligation — where processing is required by law; and
- other lawful bases available for a specific situation under applicable legislation.
Where we process data solely on a client’s documented instructions, the client is generally responsible for
identifying the lawful basis for the underlying collection and use.
When Monolith Acts for a Client
If you submitted information to one of our clients through a website, application, CRM, campaign or workflow
that Monolith operates for that client, the client may be the organization responsible for deciding why the
information is collected and how it is used.
When acting as a service provider or processor, Monolith generally processes personal information to provide
contracted services and according to the client’s instructions, subject to legal and security requirements.
This may include hosting, database administration, CRM configuration, automation, customer communications,
technical support, analytics, backups and software maintenance.
If you want to exercise privacy rights concerning information controlled by a Monolith client, you should
ordinarily contact that client first. If you contact us directly, we may refer the request to the client or
assist the client in responding, as appropriate.
Client agreements may include additional processor obligations, deletion requirements, security controls and
subprocessor terms.
Cookies, Analytics & Tracking Technologies
Our websites and Services may use cookies, local storage, pixels, tags, SDKs and similar technologies.
These technologies may support:
- strictly necessary functions, such as security, session management and form operation;
- preferences and functionality, such as remembering choices;
- analytics and performance, such as understanding traffic, navigation and conversions; and
- advertising or attribution, where used, to measure campaigns or personalize advertising as permitted by law.
Where required, non-essential cookies or similar technologies are used only after the required choice or
consent mechanism is presented. You may also be able to control cookies through browser settings. Blocking
cookies may affect some website features.
Browser “Do Not Track” signals are not interpreted uniformly across the industry. Where applicable law
requires recognition of an opt-out preference signal such as Global Privacy Control (GPC),
we will treat a valid recognized signal as required by that law.
Artificial Intelligence & Automated Processing
Some Services may use third-party or internally configured artificial intelligence systems for tasks such as
drafting, classification, summarization, extraction, transcription, search, routing, analytics, chat,
voice interaction and workflow automation.
Information submitted to an AI-enabled workflow may be transmitted to the AI or cloud provider required to
perform the requested function. We seek to configure providers and workflows in a manner appropriate to the
Service and sensitivity of the information. Third-party providers process data under their own contractual
and technical terms.
Monolith does not intentionally use Client Confidential Information to train a general-purpose Monolith model
for unrelated customers unless the client expressly agrees. We may, however, use de-identified or aggregated
operational information where permitted by law and contract.
Unless expressly disclosed for a particular Service, Monolith does not use solely automated decision-making
about direct Monolith website users that produces legal or similarly significant effects. Client-created
systems may implement automated decision workflows under the client’s responsibility and instructions.
How We Disclose Personal Information
We may disclose personal information to the following categories of recipients when reasonably necessary:
- cloud, hosting, CDN and cybersecurity providers;
- CRM, automation, project-management and productivity platforms;
- email, SMS, telephone, chat and communications providers;
- analytics, attribution and advertising technology providers where used;
- payment processors, financial institutions and accounting providers;
- AI, transcription, speech, search and data-processing providers where used;
- developers, contractors and professional specialists who require access to perform Services;
- lawyers, accountants, insurers and other professional advisers;
- our clients, where information is collected or processed on their behalf;
- law enforcement, regulators, courts or government authorities where disclosure is required or lawfully authorized; and
- a purchaser, successor or transaction adviser in connection with a merger, financing, restructuring, sale or transfer of all or part of the business, subject to appropriate confidentiality and legal requirements.
Service providers are authorized to process information for the purposes associated with the Service and are
expected to protect information under contractual, legal or professional obligations appropriate to their role.
Sale, Sharing & Targeted Advertising
Monolith does not sell personal information for money as a data-broker business.
Certain advertising, analytics or attribution technologies can be treated as a “sale,” “sharing,” or processing
for targeted advertising under some U.S. state privacy laws even when no money changes hands. If we engage in
activity that is legally treated that way and a law applicable to you gives you an opt-out right, we will provide
the required method to opt out and will recognize qualifying universal opt-out signals where required.
We do not knowingly sell or share personal information of children in circumstances where an opt-in is legally required.
Processing Outside Canada & International Transfers
Monolith is based in Alberta, Canada. We use cloud, communications, software and AI service providers that may
process personal information outside Canada.
Purpose: Cloud hosting, software-as-a-service, CRM and automation, communications, analytics,
payment processing, security, productivity tools, AI processing and technical support, depending on the Service.
A service-specific provider may process information in another country or region. Where Alberta law requires
notice of a service provider outside Canada, we will make the required country and purpose information available
at or before collection, through this Policy, a form notice, an Order/SOW, a data processing addendum or another
appropriate notice. Questions about foreign service providers may be directed to our Privacy Officer.
Information processed outside your jurisdiction may be subject to the laws of that location and may be accessible
to courts, law enforcement or government authorities in accordance with local law.
Where the GDPR or another law requires a specific international-transfer mechanism, we may rely on an adequacy
decision, Standard Contractual Clauses, a recognized certification or framework, contractual safeguards, or
another lawful transfer mechanism as appropriate.
Data Retention
We retain personal information only as long as reasonably necessary for the identified purpose, to provide and
secure the Services, satisfy contractual commitments, comply with legal or tax obligations, resolve disputes and
enforce agreements. Retention can vary by service and platform.
| Information Type | General Retention Approach |
|---|---|
| Inquiry and prospective-client records | Generally up to 3 years after the last substantive interaction, unless an ongoing relationship or legal need requires longer. |
| Client, contract, invoice and business records | For the relationship and generally up to 7 years afterward where reasonably required for accounting, tax, contractual or legal records. |
| Website analytics and technical identifiers | Generally up to 26 months, subject to provider settings, security needs and cookie choices. |
| Security, access and diagnostic logs | Generally up to 24 months unless required longer for investigation, security, audit or legal purposes. |
| Marketing contact information | Until consent is withdrawn, an opt-out is received, or the information is no longer reasonably required. A minimal suppression record may be retained to honour an opt-out. |
| Client-controlled operational data | According to the applicable client agreement, platform settings and client instructions. Active copies may be deleted after service termination, subject to transition periods and backup cycles. |
| Backups | Backups are overwritten through ordinary backup cycles and may persist temporarily after deletion from active systems. Typical cycles may range from approximately 30 to 120 days depending on the system. |
We may retain information longer where necessary for a legal hold, dispute, investigation, security event,
statutory requirement or other lawful purpose. When information is no longer required, we take reasonable steps
to delete, destroy or de-identify it.
Security Safeguards
We use administrative, technical and organizational safeguards appropriate to the sensitivity, volume, format
and context of the information. Depending on the Service, safeguards may include:
- access controls and role-based permissions;
- multi-factor authentication where supported and appropriate;
- encryption in transit and, where supported, encryption at rest;
- password and credential-management practices;
- logging, monitoring, backups and recovery processes;
- security updates, vulnerability management and service-provider controls;
- confidentiality obligations and access on a need-to-know basis; and
- incident-response and breach-assessment processes.
No internet-connected system can be guaranteed completely secure. You are also responsible for protecting your
credentials, devices and account access and for notifying us promptly if you suspect unauthorized access.
Privacy & Security Incidents
We investigate suspected privacy or security incidents and take reasonable steps to contain, remediate and assess
them. Where an incident triggers a legal notification obligation, we will notify the appropriate regulator,
affected organization or individuals as required by applicable law.
For example, where Alberta’s Personal Information Protection Act applies, a breach that creates a real risk of
significant harm may require notification to the Office of the Information and Privacy Commissioner of Alberta.
Where Monolith acts as a processor for a client, we will provide incident information to the client as required
by the applicable agreement and law. Where GDPR requirements apply, applicable controller and processor breach
obligations will be followed.
Your Privacy Rights & How to Exercise Them
Depending on where you live and the law applicable to the processing, you may have the right to:
- ask whether we hold personal information about you;
- request access to personal information and information about its use or disclosure;
- request correction of inaccurate or incomplete information;
- request deletion or erasure in circumstances provided by law;
- withdraw consent where processing is based on consent, subject to legal or contractual limits;
- object to or restrict certain processing;
- request portability of eligible information;
- opt out of certain sale, sharing, targeted advertising or profiling where applicable;
- limit certain uses of sensitive personal information where applicable;
- appeal a privacy-request decision where applicable law provides that right; and
- complain to an appropriate privacy regulator.
Submitting a Request
Send a written request to
info@monolithsolutions.ca
with the subject Privacy Request. Describe the information or right involved and provide
enough detail for us to identify the relevant records.
We may verify your identity before fulfilling a request. We will use verification information only for
verification, security and recordkeeping associated with the request. If an authorized agent submits a request
where permitted by law, we may request proof of authority and may verify your identity directly where allowed.
We respond within the period required by applicable law. Some requests may be limited by legal exceptions,
privilege, security, another person’s privacy, contractual recordkeeping requirements or other lawful grounds.
We will explain a refusal where required.
Canada & Alberta Privacy Rights
Monolith is an Alberta private-sector organization and may be subject to Alberta’s
Personal Information Protection Act (PIPA) and, depending on the activity and jurisdiction,
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) or other
applicable provincial privacy legislation.
Under Alberta PIPA, individuals may request access to their personal information and request correction of
errors or omissions. A formal access or correction request should be made in writing. Monolith will respond
within the legally required period, which under Alberta PIPA is generally 45 calendar days unless an authorized
extension applies.
If you are dissatisfied with our response, you may contact the
Office of the Information and Privacy Commissioner of Alberta (OIPC). Where PIPEDA applies,
you may also have the right to complain to the Office of the Privacy Commissioner of Canada.
California Privacy Notice
This section applies only if and to the extent the California Consumer Privacy Act, as amended by the California
Privacy Rights Act (CCPA/CPRA), applies to Monolith’s processing of your personal information.
Not every business or processing activity falls within the CCPA/CPRA.
The categories described in Section 3 constitute our general notice of categories collected. Depending on the
interaction, these may correspond to CCPA categories such as identifiers, commercial information, internet or
electronic network activity, geolocation information, professional information, audio information, inferences
and sensitive personal information.
Subject to applicable exceptions, California residents may have the right to:
- know the categories and specific pieces of personal information collected;
- know the categories of sources, purposes and recipients;
- request deletion;
- request correction;
- opt out of the sale or sharing of personal information;
- limit certain uses or disclosures of sensitive personal information where the statutory right applies; and
- exercise these rights without unlawful discrimination.
We do not sell personal information for monetary consideration. If our use of advertising or analytics
technology is deemed “sharing” or a “sale” under California law, we will provide an applicable opt-out method
and honour qualifying opt-out preference signals as required.
Other U.S. State Privacy Rights
Privacy laws in a growing number of U.S. states provide rights to residents when statutory applicability
thresholds and definitions are met. Depending on the state, rights may include confirmation, access, correction,
deletion, portability, opting out of sale, targeted advertising or certain profiling, sensitive-data controls,
non-discrimination and an appeal process.
We will honour rights required by a law applicable to Monolith and the particular processing. Some state laws
exclude or treat differently information processed solely in a business-to-business, employment, financial,
healthcare or other exempt context.
Where legally required, recognized universal opt-out mechanisms may be used to communicate an applicable opt-out choice.
EEA, United Kingdom & Similar GDPR Rights
If the GDPR, UK GDPR or a materially similar law applies to our processing, you may have rights including
access, rectification, erasure, restriction, portability, objection, withdrawal of consent and rights concerning
certain automated decisions.
Where required, our privacy notice identifies the purpose of processing, categories of personal data, lawful
basis, recipients, retention criteria and international-transfer information. You may object at any time to
processing of your personal data for direct marketing.
If you believe your rights have not been respected, you may lodge a complaint with the data protection
supervisory authority in your country or region. Where international transfer safeguards are required, Monolith
may use Standard Contractual Clauses or another lawful mechanism.
Email, SMS, Telephone & Marketing Choices
We may send communications necessary to operate an account, deliver a Service, provide security information,
issue invoices, coordinate a project or respond to a request.
Marketing email, SMS or other commercial electronic messages are sent only where permitted by applicable law,
including Canada’s anti-spam requirements where applicable. Marketing messages will include identification and
an unsubscribe method where required. You may withdraw marketing consent at any time.
Opting out of marketing does not prevent us from sending transactional, security, legal or service messages
that are reasonably necessary for an existing relationship.
Children’s Privacy
Monolith’s general website and business Services are not directed to children under 13 and are intended primarily
for business users and adults. We do not knowingly collect personal information from children under 13 through
our general website without legally required authorization.
If a client project is specifically designed to process information about minors, the client is responsible for
identifying applicable age, consent and parental-notice requirements, and Monolith will implement agreed
safeguards appropriate to its role. If you believe a child has provided personal information to us improperly,
contact our Privacy Officer.
Third-Party Websites & Services
Our websites or Services may link to or integrate with third-party websites, applications or platforms.
Their privacy practices are governed by their own policies. We are not responsible for independent third-party
privacy practices except to the extent the law assigns responsibility to us for our selection or use of a service
provider.
De-Identified & Aggregated Information
We may create or use aggregated, statistical or de-identified information that does not reasonably identify an
individual, for analytics, security, benchmarking, service improvement and business planning. Where applicable
law regulates de-identified data, we will maintain it in de-identified form and will not attempt to re-identify
it except as permitted by law, such as to test de-identification or security controls.
Changes to This Privacy Policy
We may update this Policy to reflect changes in our Services, technology, vendors, legal requirements or privacy
practices. The “Last Updated” date will show when the Policy was revised.
If a change materially affects how we use personal information already collected, we will provide additional
notice or obtain consent where required by applicable law. We do not use a policy update to retroactively create
a new incompatible purpose where the law requires additional consent or notice.
Contact Us & Privacy Complaints
Questions, access or correction requests, consent withdrawals and privacy complaints may be sent to:
Calgary, Alberta, Canada
Email: info@monolithsolutions.ca
Telephone: 1-800-637-5090
Website: monolithsolutions.ca
We will investigate privacy complaints in good faith and provide information about available escalation or
regulatory options where required.