1. Data Controller
ViralMonkey Ltd (incorporating England and Wales, June 2026). Registered office: [PLACEHOLDER]. ICO registration: [to be inserted]. Contact: privacy@viralmonkey.ai
2. Processing Activities and Legal Basis
| Activity | Data | Legal basis | Opt out? |
|---|---|---|---|
| Waitlist registration | Email, plan preference | Consent — Art. 6(1)(a) | Yes — unsubscribe anytime |
| Account login / auth | Email, hashed password | Contract — Art. 6(1)(b) | No — core function |
| Platform OAuth tokens | OAuth tokens, platform handle | Contract — Art. 6(1)(b) | Yes — disconnect anytime |
| Voice Fingerprint | Post history → style profile | Contract — Art. 6(1)(b) | Partial — delete in settings |
| AI generation | Topic + style profile (no PII in prompts) | Contract — Art. 6(1)(b) | No — core function |
| Platform publishing | Approved content + OAuth token | Contract — Art. 6(1)(b) | Yes — per-action approval |
| Subscription billing | Email → Stripe (no card data) | Contract + legal obligation — Art. 6(1)(b)(c) | No |
| Usage analytics | Anonymised events (PostHog EU) | Legitimate interest — Art. 6(1)(f) | Yes — Settings → Privacy |
| Trial fraud prevention | Device hash (non-reversible) | Legitimate interest — Art. 6(1)(f) | No — trial integrity |
| Security logging | IP, metadata (90d auto-delete) | Legitimate interest — Art. 6(1)(f) | No |
3. Data Minimisation
- Post history: Fetched once for Voice Fingerprint, then discarded. Only the style profile is stored.
- AI prompts: No PII ever included. Only topic + anonymous style profile.
- Card data: Never processed or stored by ViralMonkey. Stripe only.
- Device fingerprint: One-way hash only. Cannot be reversed. Deleted after 90 days.
- Security logs: Auto-deleted after 90 days.
4. Infrastructure and Transfer Safeguards
| System | Provider | Location | Safeguard |
|---|---|---|---|
| Core infrastructure (all AWS services) | AWS | EU-West Ireland / Frankfurt EU | No transfer outside EU |
| Product analytics | PostHog | EU cloud EU | No transfer outside EU |
| CDN / DDoS | Cloudflare | EU edge nodes EU edge | EU nodes used |
| Payment | Stripe | US SCCs | UK-US adequacy + SCCs |
| Platform API | X Corp | US SCCs | X Developer Agreement + SCCs |
| Trend data (no PII) | TweetAPI.io | US No PII | No personal data transmitted |
| Fraud prevention | FingerprintJS / AWS | US/EU SCCs/EU | SCCs + EU infra where possible |
SCCs approved by the UK ICO are used for all non-adequate-country transfers. Copies available on request.
5. Your Rights
We acknowledge all requests within 5 business days and fulfil within 30 calendar days (up to 3 months for complex requests — we’ll notify you).
EU residents: you may exercise GDPR rights with your national supervisory authority. California residents: additional CCPA rights apply — we do not sell data. Contact privacy@viralmonkey.ai.
6. Breach Response
- Risk assessment within 24 hours of becoming aware of a breach
- ICO notification within 72 hours if risk to individuals is identified
- Direct notification to affected users without undue delay if high risk to them specifically
- Notification includes: what happened, data involved, steps taken, what you should do
- Report a suspected breach: security@viralmonkey.ai
7. Future Platforms
When TikTok, Instagram, YouTube, and LinkedIn are added, this document will be updated before each integration goes live, with 14 days’ email notice of material changes.
ICO: ico.org.uk · Reg: [to be inserted] · Registered office: [PLACEHOLDER]
UK ICO · Wycliffe House, Water Lane, Wilmslow SK9 5AF · 0303 123 1113