Privacy

Privacy for controlled client testing.

This draft explains what Monkey404 expects to collect and why during controlled client testing. It is not legal advice and should be reviewed by a UK solicitor before broader rollout.

Controller identity and contact

Monkey404 is operated by the Monkey404 team for small-business social media planning, approval, scheduling and managed publishing workflows.

Use the early access or support route published on this site to contact Monkey404 about privacy, access, correction or deletion requests.

Information we collect

Monkey404 may collect account details such as name, email address, workspace name, role, login records and support contact information.

The app may also store social account metadata, page or profile names, public URLs, customer notes, post captions, schedules, uploaded media, approval history, publishing attempts and safe status messages.

Why we use it

We use this information to create accounts, manage workspaces, prepare posts, show previews, schedule content, support managed publishing, troubleshoot failed attempts and respond to support requests.

Early access signup information is used to assess fit, prioritise onboarding and contact people about controlled client testing.

Legal bases

The likely legal bases include contract or pre-contract steps for account access and service delivery, legitimate interests for product support and security, and legal obligation where records must be retained.

Where consent is required for future optional analytics or marketing cookies, Monkey404 should ask before setting those non-essential cookies.

Third-party processors

Monkey404 relies on service providers for hosting, database, storage, email delivery, managed publishing operations and operational monitoring.

Customers should not share social account passwords in Monkey404. Publishing setup uses managed account connections and operational metadata rather than customer password collection.

International transfers

Some service providers may process data outside the UK. Before larger rollout, Monkey404 should confirm processor locations and transfer safeguards in a reviewed sub-processor list.

Controlled client testing should avoid storing unnecessary sensitive data in workspace notes, media or support messages.

Retention

Monkey404 should keep account, workspace, post, media, support and publishing records only for as long as needed for the service, security, support, billing records or legal reasons.

Deletion requests are reviewed so the correct records can be found and removed where appropriate. Some operational records may need limited retention for abuse prevention, accounting or dispute handling.

Your rights and ICO

UK users may have rights to access, correct, delete, restrict, object to or receive a copy of their personal data, depending on the circumstances.

If a privacy issue is not resolved, UK users can complain to the Information Commissioner Office. Monkey404 should still be contacted first so the issue can be investigated.

Security

Monkey404 uses account login, workspace access controls and operator-only areas to separate customer and administrative activity.

No public page or customer page should display provider credentials, private credentials, raw payloads or operational secrets.

Changes

This policy may change as Monkey404 moves from controlled client testing to broader launch. Material changes should be reflected on this page before wider use.

This page is a practical draft and should not be treated as formal legal advice.