Privacy & POPIA

Privacy Notice

This Notice explains how CloudMonkey collects, uses, shares, protects, stores, and deletes personal information when you use the website, dashboard, and managed services.

Last updated: 4 July 2026

Privacy Contact

Entity
CloudMonkey (Pty) Ltd
Registration
2021/743645/07
Address
377 Rivonia Boulevard, Sandton, 2196, South Africa
Email
info@cloudmonkey.co.za

What We Collect

Account, billing, support, technical, tenant, domain, server, voice, security, website, and AI service information needed to operate CloudMonkey.

Why We Use It

To provide services, secure accounts, process payments, support customers, manage infrastructure, meet legal duties, and improve the platform.

Where It Goes

Data may be processed by CloudMonkey staff, approved subprocessors, cloud providers, email providers, payment providers, security tools, and AI infrastructure where needed.

Your Rights

You may ask to access, correct, delete, object to, or restrict certain personal information, subject to legal, security, billing, and service-record limits.

Personal Information

Data we may process

The exact data depends on the services you use, the integrations you connect, the support you request, and the information you choose to provide.

Account and contact data

Name, company, email address, phone number, login details, role, workspace, authentication records, and communication preferences.

Billing and commercial data

Customer name, invoice details, payment status, billing address, tax details where provided, quote history, subscriptions, service orders, and transaction references.

Support and service data

Tickets, messages, attachments, diagnostics, device or server details, logs, screenshots, requested changes, support notes, and service history.

Cloud, domain, and website data

Domain names, DNS records, hosting details, SSL records, website content, deployment metadata, backups, monitoring data, and infrastructure usage.

Microsoft 365, email, and security data

Tenant identifiers, user lists, licence information, security posture results, admin actions, mailbox security indicators, audit findings, and policy checks.

Voice, PBX, and AI data

Extensions, routing rules, call metadata, recordings where enabled, transcripts, prompts, AI knowledge base content, agent configuration, and workflow outputs.

Website and device data

IP address, browser, device details, cookies or similar identifiers, pages viewed, referral source, session data, and error or performance telemetry.

Use Of Data

Why we process information

Create and manage CloudMonkey accounts, workspaces, roles, authentication, and dashboard access.

Process quotes, orders, invoices, payments, subscriptions, refunds, collections, and tax or accounting records.

Provision, monitor, secure, maintain, support, suspend, restore, or terminate managed services.

Administer domains, hosting, websites, servers, DNS, SSL, backups, email tenants, Microsoft 365, security checks, voice services, and AI agents.

Investigate support requests, abuse reports, security incidents, billing disputes, service failures, and compliance issues.

Send service messages, billing notices, security alerts, onboarding instructions, legal notices, and operational updates.

Improve reliability, user experience, service quality, security controls, internal processes, and product planning.

Comply with legal, regulatory, tax, accounting, audit, consumer-protection, privacy, and law-enforcement obligations.

1. Responsible Party And Operator Roles

For CloudMonkey's own website, billing, account, security, marketing, and platform administration data, CloudMonkey is generally the Responsible Party.

For managed services where a customer asks CloudMonkey to process personal information on the customer's behalf, the customer is generally the Responsible Party and CloudMonkey acts as Operator under the customer's instructions.

A Data Protection Addendum may apply to managed services such as hosting, email administration, Microsoft 365 tenant checks, voice services, support, security monitoring, and AI workflows.

2. How We Collect Personal Information

We collect information directly from you when you create an account, request a quote, accept a service order, pay an invoice, submit a ticket, connect a provider, or use the dashboard.

We collect technical and service information automatically from the website, dashboard, logs, monitored systems, security tools, hosting infrastructure, support workflows, and connected services.

We may receive information from payment providers, identity providers, domain registries, cloud providers, email providers, voice providers, security vendors, referral partners, and other service providers involved in delivering CloudMonkey services.

3. Legal Grounds For Processing

We process personal information to perform contracts, take steps before entering contracts, comply with legal obligations, protect legitimate business and security interests, and where necessary based on consent.

Where we process personal information as Operator, we do so under the customer's documented instructions and the agreement that applies to the service.

You may withdraw consent where processing depends on consent, but this will not affect lawful processing that already happened or processing needed for contract, legal, security, billing, or record-keeping reasons.

4. Sharing And Subprocessors

We share personal information only where needed to provide services, operate the platform, meet legal duties, protect rights or security, process payments, manage infrastructure, or support customers.

Subprocessors may include hosting, DNS, domain, email, payment, identity, analytics, monitoring, backup, security, ticketing, communication, voice, AI, and software infrastructure providers.

We require staff, contractors, and relevant providers to handle personal information confidentially and only for authorised purposes.

5. Cross-Border Processing

Some providers used for cloud hosting, payment, security, email, support, analytics, voice, or AI may process information outside South Africa.

Where personal information is transferred outside South Africa, CloudMonkey relies on appropriate contractual protections, customer instructions, consent where applicable, adequacy-type safeguards, or transfer mechanisms allowed by POPIA.

Service orders or DPAs may provide more specific details about hosting regions, subprocessors, and cross-border processing for a particular customer service.

6. Security Measures

CloudMonkey uses reasonable technical and organisational safeguards such as access controls, role-based permissions, authentication controls, logging, backups, encryption where appropriate, secure administration practices, and staff confidentiality measures.

No system can be made perfectly secure. Customers must also protect passwords, recovery accounts, administrator access, API keys, domain access, tenant permissions, endpoint devices, and data shared with CloudMonkey.

If you suspect unauthorised access to a CloudMonkey account, connected tenant, domain, mailbox, server, PBX, or AI workflow, contact us immediately.

7. Retention

We keep personal information for as long as needed to provide services, maintain business records, comply with legal and tax obligations, resolve disputes, detect abuse, secure systems, and preserve audit evidence.

Backups, logs, signed agreements, invoices, service records, security records, and support records may be retained for different periods depending on operational, legal, accounting, and security requirements.

When information is no longer needed, we delete, anonymise, archive, or restrict it using reasonable processes.

8. AI, Recordings, And Sensitive Information

Customers must not submit special personal information, confidential third-party data, regulated records, or sensitive business data into AI, support, voice, or website workflows unless the service is designed for that use and the applicable agreement allows it.

Where call recording, transcription, AI knowledge bases, or monitoring features are enabled, customers are responsible for ensuring they have the required notices, permissions, and lawful basis for their own users, staff, callers, and data subjects.

CloudMonkey may use upstream AI infrastructure to provide AI services, but customer-specific inputs and knowledge bases should be handled according to the applicable service order and DPA.

9. Cookies And Similar Technologies

CloudMonkey may use cookies, local storage, session storage, and similar technologies to keep you signed in, remember preferences, protect forms, detect abuse, measure performance, and improve the website.

Some cookies are necessary for security and account functionality. Browser settings may allow you to block or delete cookies, but doing so can affect the dashboard and checkout experience.

10. Security Compromises

If we have reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will assess the incident and notify affected customers or Responsible Parties as required by POPIA and the applicable agreement.

Where a customer is the Responsible Party, CloudMonkey's role is to notify and assist the customer so the customer can assess its own regulator and data subject notification duties.

11. Contact

For privacy requests, POPIA questions, or data protection notices, contact CloudMonkey at info@cloudmonkey.co.za. Billing-related privacy questions may also be sent to billing@cloudmonkey.co.za.

Please include enough information for us to verify your identity and locate the relevant account, invoice, domain, tenant, ticket, or service record.

Your Rights

Privacy requests

We may need to verify your identity before actioning a request. Some requests may be limited by law, contract, billing records, security logs, backups, or the rights of another person.

Access

Ask whether we hold your personal information and request access to it, subject to identity verification and lawful limits.

Correction

Ask us to correct or update inaccurate, outdated, incomplete, or misleading personal information.

Deletion

Ask us to delete personal information where we no longer need it and no legal, security, billing, dispute, backup, or service reason requires retention.

Objection

Object to certain processing where POPIA allows it, including some direct marketing or processing based on legitimate interests.

Complaint

Contact us first so we can investigate. You may also complain to the Information Regulator of South Africa where applicable.

Document status: This Privacy & POPIA Notice is published for CloudMonkey website, dashboard, customer onboarding, support, billing, managed services, connected tenants, and AI workflows from 4 July 2026.