必要 Cookie 用于保持登录状态;分析功能仅在您同意后启用。请参阅我们的 隐私政策

← Back to Monqez AI

Data Processing Agreement

Last updated: June 22, 2026

This DPA is a template provided for transparency and forms part of our Terms of Service. It is not legal advice. If you need a counter-signed copy for your records, email support@monqezai.io.

1. Parties, roles & how this DPA applies

This Data Processing Agreement ("DPA") forms part of, and is governed by, the Monqez AI Terms of Service ("Agreement") between you ("Customer") and المنقذ المبدع للبرمجة, trading as Monqez AI ("Monqez", "we"). It applies where, in using the platform, we process personal data on your behalf — for example your end-customers’ names, contact details and messages, or the leads you collect. For that data you are the controller and we are the processor. (For your own account data we are the controller; see the Privacy Policy.) If there is a conflict on data-protection matters, this DPA prevails over the rest of the Agreement.

2. Subject-matter, duration, nature & purpose

We process personal data only to provide, secure, support and maintain the platform and the features you enable, for the duration of the Agreement and until data is deleted or returned under Section 10. The nature of the processing includes storing, organising, transmitting, analysing and generating content (including AI-generated replies and drafts) as needed to deliver the service.

3. Types of personal data & categories of data subjects

You decide what data you put into the platform. Typically this includes: contact details (names, emails, phone numbers), message and conversation content, sales leads and CRM records, and knowledge-base content you upload. Categories of data subjects typically include your customers, prospects, leads and contacts. You must not upload special-category data unless you have a lawful basis and have configured the service appropriately.

4. Our obligations as processor (GDPR Art. 28(3))

We will:

  • process the personal data only on your documented instructions (including for transfers), which the Agreement, this DPA and your use of the platform’s settings constitute — unless we are required to do otherwise by law, in which case we will tell you first where legally permitted;
  • ensure persons authorised to process the data are under a duty of confidentiality;
  • implement and maintain the technical and organisational security measures described in Section 7;
  • engage sub-processors only under Section 5, and impose data-protection obligations on them equivalent to those in this DPA;
  • taking into account the nature of the processing, assist you with appropriate measures to fulfil your obligation to respond to data-subject requests (Section 9);
  • assist you in ensuring compliance with your obligations on security, breach notification, data-protection impact assessments and prior consultation (GDPR Art. 32–36);
  • delete or return the personal data at the end of the service under Section 10; and
  • make available the information reasonably necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, as set out in Section 11.

5. Sub-processors

You give us general authorisation to engage sub-processors to help deliver the service. Our current sub-processors are listed at monqezai.io/subprocessors. We keep that list up to date and, where required, will give you advance notice before a new sub-processor that processes your personal data starts, so you can object on reasonable data-protection grounds. We remain responsible to you for any sub-processor’s performance of its data-protection obligations.

6. International data transfers

The platform is hosted in the European Union (Frankfurt, Germany). Some sub-processors may process data outside the EEA/UK. Where personal data is transferred out of the EEA/UK, we rely on an adequacy decision where one exists, or on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. A copy of the relevant safeguards is available on request.

7. Security measures (GDPR Art. 32)

Taking into account the state of the art and the risks, we maintain measures that currently include:

  • multi-tenant isolation — every record is scoped to the owning account and checked on every read and write, so one customer cannot access another’s data;
  • encryption in transit (TLS 1.2+ with HSTS) for all traffic to the platform;
  • encryption at rest with AES-256-GCM for sensitive fields such as connected-channel credentials, SMTP credentials and API tokens; databases and backups are kept in our isolated, EU-hosted environment;
  • passwords hashed with bcrypt; access to administrative tools restricted by role-based permissions;
  • an internal audit log of administrative actions and of any support "view-as" (impersonation) sessions; routine support tools redact customer conversation content and mask connected credentials;
  • we do not use your content to train third-party AI providers’ public models, and we never train shared models across customers.

8. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information you reasonably need to meet your own notification obligations.

9. Data-subject requests

If we receive a request from one of your data subjects (e.g. to access or delete data), we will, where lawful, refer them to you rather than respond directly, and we will provide reasonable assistance so you can respond — including through the platform’s own tools.

10. Deletion & return

On termination of the service, or earlier on your request, we will delete or return the personal data we process on your behalf. We erase personal data within 30 days and remove it from routine backups within a further 90 days, except where we are required by law to retain certain records (see the Privacy Policy).

11. Audit & information

On reasonable written request, we will make available the information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits or inspections conducted by you or an auditor you mandate. Audits are subject to reasonable notice, confidentiality, and minimising disruption to our operations and to other customers’ data.

12. Liability & governing law

Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement. This DPA is governed by the same law and dispute-resolution terms as the Agreement.

13. How to put a signed DPA in place

This page sets out the terms we apply. If your organisation requires a counter-signed DPA (for example for procurement or your own compliance records), email support@monqezai.io and we will arrange one.

AboutSecurityPrivacyRefund PolicyTermsSub-processors