Privacy Policy
Last updated: January 2025
1. Introduction
This Privacy Policy explains how Monocle, based in France ("we", "us", "our"), collects, uses, and protects your personal data when you use our observability platform ("Service").
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller for your personal data is:
Julien Ripouteau
SIRET: 82343993000012
1 Rue des rossignols
77320 Sancy-les-Provins, France
Email: contact@monocle.sh
3. Data We Collect
3.1 Account Data
When you create an account, we collect:
- Email address
- Name (optional)
- Profile picture (if you sign in with a social provider)
- Organization name
3.2 Usage Data
We automatically collect information about how you use our Service:
- IP address
- Browser type and version
- Pages visited and features used
- Date and time of access
3.3 Observability Data
You send us observability data from your applications, which may include:
- Application logs
- Distributed traces
- Exceptions and stack traces
- Performance metrics
Important: This data may contain personal data of your users. You are responsible for ensuring you have the appropriate legal basis to collect and transmit this data to us. See our Data Processing Agreement for details.
4. How We Use Your Data
We use your data to:
- Provide and maintain the Service
- Process your payments
- Send you important notifications about the Service
- Respond to your support requests
- Improve and optimize the Service
- Comply with legal obligations
5. Legal Basis for Processing
We process your personal data based on:
- Contract: Processing necessary to provide the Service you requested
- Legitimate interests: Improving our Service and preventing fraud
- Legal obligation: Compliance with applicable laws
- Consent: Where you have given explicit consent
6. Data Retention
We retain your data as follows:
- Account data: Until you delete your account
- Observability data: 90 days from ingestion
- Payment records: As required by law (typically 10 years)
7. Data Sharing
We share your data with the following third-party service providers:
- Cloudflare: CDN, DDoS protection, and object storage (R2)
- Hetzner: Server hosting (Germany)
- Stripe: Payment processing
All our service providers are bound by data processing agreements and comply with GDPR requirements.
8. International Transfers
Your data is primarily stored in the European Union (Hetzner, Germany). Some service providers may process data outside the EU. In such cases, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses.
9. Your Rights
Under GDPR, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data
- Restriction: Limit how we use your data
- Portability: Receive your data in a portable format
- Objection: Object to certain processing activities
To exercise these rights, contact us at contact@monocle.sh. We will respond within 30 days.
10. Cookies
We use the following cookies:
Essential Cookies
Required for the Service to function. These include:
- Session cookies for authentication
- Security cookies (CSRF protection)
Functional Cookies
Used to remember your preferences:
- Theme preference (dark/light mode)
- UI preferences
We do not use advertising or tracking cookies.
11. Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (TLS) and at rest
- Access controls and authentication
- Regular security assessments
- DDoS protection via Cloudflare
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
13. Contact & Complaints
For any questions about this Privacy Policy or to exercise your rights, contact us at:
Email: contact@monocle.sh
You also have the right to lodge a complaint with a supervisory authority. In France, this is the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr