How MunkiSee processes personal data on your organisation's behalf on cloud plans — instructions, security, sub-processors, breach notice, deletion. Forms part of the Terms of Service.
This DPA applies where MunkiSee processes personal data on the Customer's behalf — that is, on managed cloud plans. On self-hosted Enterprise deployments MunkiSee never touches activity data, so this DPA applies there only to the minimal account and licensing data we do process (administrator contact details, licence state, seat counts), not to Monitored-User activity data, which never reaches us.
This Data Processing Agreement ("DPA") forms part of the Terms of Service (or a separately signed agreement, together the "Agreement") between MunkiSee (the "Processor") and the Customer (the "Controller"). For all personal data in Customer Data, the Customer is controller and MunkiSee is processor. Where data-protection law of another jurisdiction uses different labels (e.g. "business" and "service provider"), the equivalent roles apply. If this DPA conflicts with the Agreement on a data-protection matter, this DPA prevails.
MunkiSee processes personal data to provide device-activity measurement and reporting as described in the Agreement, the documentation, and Annex A, for the duration of the Agreement plus the deletion period in clause 10. Processing consists of collection via the Agent, storage, aggregation into reports, display to authorised Administrators, scheduled report delivery, backup, and deletion.
MunkiSee processes personal data only on the Controller's documented instructions, which are: the Agreement, this DPA, and the configuration the Controller's Administrators set in the dashboard — schedules, out-of-hours mode, retention, calendar exclusions, report recipients, and user management. MunkiSee will inform the Controller if, in its opinion, an instruction infringes applicable data-protection law, and may suspend the instruction until resolved. MunkiSee will not use personal data in Customer Data for its own purposes, sell it, or use it to train machine-learning models.
Persons MunkiSee authorises to process personal data are bound by confidentiality obligations, and access is limited to what their role requires. Standing access to tenant data is limited to operating personnel for support and incident response, and administrative access is itself logged and protected by mandatory multi-factor authentication.
MunkiSee implements and maintains the technical and organisational measures in Annex B, and keeps them current against the state of the art. Because measures evolve, Annex B may be updated over time, provided the overall level of protection does not decrease.
The Controller gives general authorisation for the sub-processors in Annex C. MunkiSee will notify tenant Administrators of any intended addition or replacement in advance, giving the Controller the opportunity to object on reasonable data-protection grounds; if an objection cannot be resolved, the Controller may terminate the affected service with a pro-rata refund of prepaid fees. MunkiSee imposes data-protection obligations on each sub-processor no less protective than this DPA, and remains fully liable to the Controller for their performance.
Taking into account the nature of the processing, MunkiSee will assist the Controller with appropriate technical and organisational measures to fulfil data-subject requests (access, rectification, erasure, restriction, portability, objection) — in practice, most are self-service through the dashboard's user management, reporting, and purge tools — and will assist with the Controller's obligations regarding security, breach notification, impact assessments, and prior consultation, at the Controller's reasonable expense where the assistance goes beyond what the Service provides. If a data subject contacts MunkiSee directly, MunkiSee will refer the request to the Controller without undue delay and not respond substantively except as legally required.
MunkiSee will notify the Controller's Administrators without undue delay after becoming aware of a personal-data breach affecting Customer Data, and in any case in time for the Controller to meet its own statutory notification deadlines. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, supplementing in phases where full information is not yet available. MunkiSee will document breaches and its response, and will not characterise the Controller's notification obligations on its behalf.
MunkiSee will make available the information reasonably necessary to demonstrate compliance with this DPA — security documentation, sub-processor agreements' relevant terms, and completed security questionnaires — and will allow and contribute to audits, including inspections, conducted by the Controller or its mandated auditor, no more than once per year on at least 30 days' notice unless a supervisory authority or a breach requires otherwise. Audits must not access other customers' data; where an inspection would, MunkiSee may satisfy it by an independent third-party attestation covering the same controls.
During the Agreement, the Controller can export Customer Data at any time through the dashboard's reporting and backup tools. On termination or expiry, export remains available for 30 days, after which MunkiSee deletes the tenant database and its backups in the ordinary rotation, unless applicable law requires longer storage of specific records — in which case MunkiSee isolates the retained data and processes it for no other purpose. Deletion of a tenant is deletion of the database itself, not flagging rows in a shared store.
Customer Data is hosted in the region agreed at signup and is not transferred to another jurisdiction except as needed to provide the Service through Annex C sub-processors. Where a transfer from the EEA, UK, or Switzerland to a country without an adequacy decision occurs, the parties rely on the EU Standard Contractual Clauses (module 2, controller-to-processor), which are incorporated into this DPA by reference, with the technical measures of Annex B serving as the SCC security annex; the UK Addendum and Swiss adaptations apply where relevant. MunkiSee will notify the Controller if it can no longer meet its transfer obligations, and the Controller may then suspend the affected transfer.
Liability under this DPA is subject to the limitations of the Agreement, except where applicable data-protection law does not permit them to be limited. This DPA takes effect with the Agreement and remains in force as long as MunkiSee processes personal data on the Controller's behalf.
Continuous collection at approximately five-minute intervals during configured tracking windows; retention per plan limits and the Controller's configured retention window, enforced by automatic sweeps.
The current named list, with entities and regions for your tenant, is available on request via the contact form and is provided during procurement and security review.