Privacy notice
Last updated 4 August 2026
MonOps is an agent that runs on your servers, so this notice has to answer two separate questions: what we process about you, and what the agent sends about your machines. They are handled differently.
Who is responsible
- controller
- Mati.Cloud, owner Matiula Sediqui
- legal form
- Einzelunternehmen (sole proprietorship)
- product
- MonOps
- address
- Bohlweg 51, 38100 Braunschweig, Germany
- contact
- [email protected]
- data protection officer
- none appointed — see below
No data protection officer is appointed. Under § 38 BDSG one is required where at least 20 people are permanently engaged in automated processing of personal data, or where the processing is of a kind that triggers a data protection impact assessment. Neither applies: this is a one-person business, and it processes machine telemetry rather than profiling individuals. If that changes, this section changes with it.
The important distinction: your data versus your machines
Most of what MonOps handles is not personal data at all. It is machine telemetry: how long work waited for a CPU, how much memory was reclaimed, which operations failed, how many packets were retransmitted. None of that describes a person.
Two kinds of telemetry can nevertheless contain personal data, and we would rather say so than pretend otherwise:
- Process command lines. The agent records which processes were running. If your own software passes tokens, customer identifiers or usernames as command-line arguments, those values appear in the process list.
- Requested log windows. MonOps does not ship your logs by default. When you ask it to slice a log window for a specific incident, that slice contains whatever your application logged — which may include personal data.
Redaction runs on your machine, before anything is transmitted, and is configurable per organisation. A field you exclude never crosses your network boundary, so a breach of our infrastructure cannot expose what we were never sent.
You are the controller for telemetry, we are the processor
You decide which machines run the agent, what it collects and what is redacted. Under the GDPR that makes you the controller for that telemetry and us your processor, acting on your instructions.
If your organisation needs a data processing agreement under Article 28 — most will — ask and we will provide one. For your own account and billing data, described below, we are the controller.
This website
Requesting a page necessarily transmits technical information your browser sends: IP address, user agent, referrer, and the time of the request. Our host processes this to deliver the page and to keep the service secure and available. Legal basis: Article 6 (1)(f), legitimate interests.
The site runs on ephemeral containers that keep no persistent log storage, so we do not build up a request history of our own. Our hosting provider keeps short-term logs at the network level to defend against abuse and denial-of-service traffic, which is theirs rather than ours and is not used to analyse visitors.
- analytics
- none — no analytics or tag manager of any kind
- cookies set by us
- none
- server log retention
- none by us — the site runs on ephemeral pods with no persistent log storage
There is no contact form on this site that stores anything. The contact page composes a message in your own mail client, so nothing is submitted to a database here and you keep a copy of what you sent.
§ 25 TDDDG requires consent before storing or accessing information on your device unless it is strictly necessary to deliver the service. This site stores nothing on your device — no cookies, no local storage, no analytics — so there is nothing to consent to, which is why you were not shown a banner.
Account and billing
To run an organisation on MonOps we process an email address, a hashed password or federated identity, the organisation name, plan and quota settings, and an audit log of privileged actions. Legal basis: Article 6 (1)(b), performance of a contract.
Payments are handled by a payment provider. Card details are processed by them and never reach our systems. We retain invoices as required by German commercial and tax law.
The audit log deliberately keeps no foreign key to the user who created an entry. Deleting an account does not quietly rewrite the record of what was done — which is normally the property an auditor cares about. On an erasure request the entries are de-identified rather than destroyed, so the history stays intact without naming a person.
Processors we use
- hosting and storage
- Hetzner Online GmbH, Germany
- payments
- none in use — see below
- transactional email
- none — this site sends no email
- mailbox
- self-hosted on Hetzner infrastructure, Germany
There is no payment processor today: this site takes no payment, and the contact form opens your own mail client rather than posting anywhere. When checkout is introduced, the payment provider will be named here before it goes live, not after.
The mailbox for [email protected] is self-hosted rather than run by a mail provider, so no third party reads that mail. Hetzner is still named above because it supplies the machine it runs on. Hosting, processing and probe infrastructure are inside the EU under an Article 28 processing agreement, and no third-party processor sits in the path of your telemetry. We do not sell personal data and do not share it for advertising.
How long things are kept
- fine-grained telemetry
- 3 days
- rolled-up metrics
- 90 days
- flight recorder dumps
- 7 days
- incident records
- 90 days
- account data
- while the organisation exists
- audit log
- retained, de-identified on erasure
- invoices and accounting records
- 10 years (§ 147 AO, § 257 HGB)
Telemetry ages out on its own rather than accumulating indefinitely. When an organisation closes, its data is deleted on this schedule. Statutory accounting records are the exception: we cannot delete those on request, and no provider honestly can.
Security
Data is encrypted in transit and at rest. Access is limited to people who need it to operate the service, and privileged actions are written to the audit log. Every agent must prove which organisation it belongs to before it can send or receive anything — there is no anonymous ingest path, and no route from one customer’s organisation to another’s telemetry.
No system is perfectly secure and we will not claim otherwise. The architecture and the specific guarantees are described on the security page.
If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours as required by Article 33, and affected people where Article 34 requires it.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Article 15)
- have inaccurate data corrected (Article 16)
- have data erased, where no legal retention duty applies (Article 17)
- restrict processing (Article 18)
- receive your data in a portable format (Article 20)
- object to processing based on legitimate interests (Article 21)
- withdraw consent at any time, where processing relies on consent (Article 7 (3))
Write to [email protected] and we will respond within one month. You can also complain to a supervisory authority. Ours is the Landesbeauftragte für den Datenschutz Niedersachsen, the authority for Lower Saxony, where the business is established. You may also complain to the authority where you live or work.
International transfers and children
Telemetry is processed inside the EU. If any processor named above operates outside the EEA, that transfer relies on an adequacy decision or on standard contractual clauses, and we will name it here rather than leave it implied.
MonOps is a tool for operating server infrastructure. It is not directed at children and we do not knowingly process the personal data of anyone under 16.
Changes to this notice
When this notice changes materially we will update the date at the top and, for changes that affect how your data is processed, tell account holders directly rather than relying on you noticing.
Something here unclear or wrong?
Tell us→