Effective Date: August 19, 2025
Monze Digital Solutions ("we," "our," or "us") is fully committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR) and other applicable data protection laws. This comprehensive guide outlines how we comply with GDPR requirements and explains your rights as a data subject.
The GDPR applies to the processing of personal data of individuals located in the European Economic Area (EEA), regardless of where the processing takes place. As a global service provider, we ensure GDPR compliance for all our users, providing the same high level of data protection worldwide.
This document should be read in conjunction with our Privacy Policy, Terms of Service, and Cookie Policy, which together form our comprehensive data protection framework.
Company: Monze Digital Solutions
Address: 22 4th St #602, San Francisco, CA 94103, United States
Email: dpo@monze.net
Phone: (415) 821-4241
EU Representative: For matters related to GDPR compliance, EU residents can contact our EU representative at eu-representative@monze.net
As the data controller, we determine the purposes and means of processing your personal data. We have appointed a Data Protection Officer (DPO) who oversees our data protection activities and serves as your primary contact for GDPR-related matters.
Under GDPR, we must have a valid legal basis for processing your personal data. We process your data based on the following legal grounds:
Processing necessary to provide our e-signature services and fulfill our contractual obligations to you:
Processing for our legitimate business interests, balanced against your rights and freedoms:
We conduct regular legitimate interest assessments to ensure our interests do not override your fundamental rights and freedoms.
Processing based on your explicit, freely given consent:
You can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Processing required to comply with legal obligations:
In rare circumstances, we may process data to protect vital interests, such as preventing harm to individuals or responding to emergency situations.
Under GDPR, you have comprehensive rights regarding your personal data. These rights are not absolute and may be subject to certain limitations, but we are committed to facilitating their exercise wherever possible:
You have the right to obtain confirmation of whether we process your personal data and, if so, access to:
How to exercise: Submit a request through your account settings or contact our DPO. We may require identity verification.
You have the right to have inaccurate personal data corrected and incomplete data completed. This includes:
How to exercise: Update information directly in your account settings or contact us with the correct information.
You have the right to have your personal data erased in certain circumstances:
Limitations: We may retain data where necessary for legal compliance, exercising legal claims, or other legitimate purposes.
You can request restriction of processing in specific situations:
Effect: We will store the data but not process it further without your consent or for specific legal purposes.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller when:
Available formats: JSON, CSV, or other standard formats. We can also transmit data directly to another controller where technically feasible.
You have the right to object to processing based on:
Marketing opt-out: Use unsubscribe links in emails or update your communication preferences in account settings.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. If we use automated decision-making, you have the right to:
Our email communication practices are designed to fully comply with GDPR requirements:
Legal Basis: Contract performance and legitimate interest
Essential service communications necessary for account management and service delivery:
Opt-out: You cannot opt out of essential transactional emails as they are necessary for service delivery. However, you can close your account to stop receiving them.
Legal Basis: Explicit consent (Article 6(1)(a))
Promotional communications sent only with your explicit consent:
Consent management: We use double opt-in for marketing subscriptions and maintain detailed records of consent, including timestamp, IP address, and consent method.
Our consent management practices ensure GDPR compliance:
We implement state-of-the-art technical measures to protect your personal data:
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place:
We use the European Commission's approved Standard Contractual Clauses for transfers to countries without adequacy decisions, including additional safeguards where necessary.
We prioritize transfers to countries with European Commission adequacy decisions, such as Canada, Japan, and the UK.
For intra-group transfers, we maintain binding corporate rules approved by relevant data protection authorities.
We conduct Transfer Impact Assessments (TIAs) to evaluate the level of protection in destination countries and implement additional safeguards where necessary, including enhanced encryption, access controls, and contractual protections.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
Active accounts: Retained while your account is active
Closed accounts: Deleted within 90 days unless legal retention applies
Legal compliance: Up to 7 years for tax and regulatory requirements
User-controlled: According to your account settings and preferences
Legal documents: Retained as required by applicable laws
Audit trails: 7 years for legal and compliance purposes
Email communications: 3 years for customer service purposes
Marketing data: Until consent is withdrawn or 3 years of inactivity
Support tickets: 5 years for quality assurance and legal protection
We use automated systems to ensure data is deleted according to our retention schedules. You will receive notifications before data deletion where appropriate, and you can request early deletion subject to legal and contractual obligations.
We maintain comprehensive procedures for detecting, investigating, and responding to data breaches:
We will notify the relevant supervisory authority within 72 hours of becoming aware of a breach likely to result in risk to rights and freedoms, including all required information under Article 33 GDPR.
We will notify affected individuals without undue delay when a breach is likely to result in high risk to their rights and freedoms, providing clear information about the breach and recommended actions.
You can exercise your GDPR rights through multiple channels:
Access your account settings to manage many rights directly, including data access, rectification, and communication preferences.
Send detailed requests to our Data Protection Officer at dpo@monze.net with "GDPR Rights Request" in the subject line.
Mail written requests to our Data Protection Officer at 22 4th St #602, San Francisco, CA 94103, United States.
To process your request efficiently, please provide:
If you have concerns about our data processing practices, please contact us first:
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you:
Website: edpb.europa.eu
Find your local supervisory authority through their website
Our lead supervisory authority for EU operations
Website: dataprotection.ie
Email: info@dataprotection.ie
We regularly review and update this GDPR Compliance guide to reflect:
Material changes will be communicated through email notifications, website announcements, and account notifications. We encourage you to review this guide periodically to stay informed about your rights and our practices.
For all GDPR-related inquiries, requests, or complaints, please contact:
Data Protection Officer
Monze Digital Solutions
22 4th St #602
San Francisco, CA 94103
United States
Email: dpo@monze.net
Phone: (415) 821-4241
EU Representative: eu-representative@monze.net
Business Hours: Monday - Friday, 9:00 AM - 6:00 PM PST
Emergency Contact: For urgent data protection matters, call our 24/7 security hotline at (415) 821-4241 ext. 911