Roles
For customer workspace content, media and social account metadata, the customer will often decide the purpose and content of processing.
Monkey404 acts as a service provider for the workflow: hosting, storing, previewing, scheduling, supporting and handing off approved content.
Processing instructions
Monkey404 should process customer data to provide the service, support users, investigate failures, protect the platform and comply with lawful obligations.
Customers should not add unnecessary sensitive data to posts, media, notes or support messages.
Sub-processors
Monkey404 uses infrastructure, storage, email, managed publishing and operational providers to run the service.
A reviewed sub-processor list should be maintained before broader rollout, including provider purpose, location and transfer safeguards where relevant.
Security
Monkey404 uses workspace permissions, operator-only routes, credential safeguards and deployment safety checks to reduce operational risk.
Security measures should continue to be reviewed as more clients are onboarded.
Deletion or return
When a customer leaves, Monkey404 should delete or return workspace data where appropriate, subject to legal, accounting, dispute, abuse-prevention and backup-retention limits.
Deletion requests should identify the account email, workspace and scope of the request so records can be found safely.
Incidents
Monkey404 should investigate suspected data incidents promptly and notify affected customers where legally required.
Monitoring, support mailbox ownership and incident runbooks should be completed before broad public rollout.