Privacy Policy

Last updated: July 2026

This policy explains in detail how HelloQuartz Ltd, trading as Monty (“Monty”, “we”, “our”, or “us”) collects, uses, stores, and shares information when you use our platform. Where this policy describes “you” it means both the business customer (“Client”) and any individual user operating within that Client's account.

1. Introduction

HelloQuartz Ltd operates the Monty platform — an AI sales development representative (SDR) for B2B teams. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our website and services (collectively, the “Service”). By accessing or using the Service, you agree to the terms of this policy.

2. Information We Collect

2.1 Account & Registration Data

  • Name, email address, and company name provided at sign-up
  • Profile information (avatar, role within your organisation)
  • Organisation/workspace details

2.2 Billing & Payment Data

Payment processing is handled entirely by Stripe. We store only your Stripe customer ID, subscription plan, status, and invoice records. We never store raw card numbers or full payment instrument details on our own systems.

2.3 Connected Email Accounts (Gmail / Microsoft Outlook)

When you connect a Gmail or Microsoft Outlook/Exchange mailbox, we obtain OAuth access tokens that allow us to read inbound emails, compose and send outbound emails on your behalf, and collect bounce and non-delivery reports (NDRs). Access tokens are stored encrypted in our database. We access only the email threads necessary to operate your configured campaigns — we do not index or read unrelated messages. You can revoke access at any time through your email provider's account settings or from the Monty dashboard.

2.4 Lead & Contact Records

You or Monty's automated agents may create records for prospective business contacts. These records may include:

  • Business name, job title, email address, phone number, and LinkedIn URL
  • Company information (industry, size, website)
  • AI-generated summaries and lead quality scores
  • Enrichment data retrieved from third-party sources (see Section 5)
  • Full conversation history (emails sent and received)
  • Campaign status and interaction history

Lead and contact records are created and owned by you as the Client. They are processed under a separate legal basis and controller relationship (see Section 10).

2.5 Voice Profile & Writing Samples

When you create a voice profile, we store your chosen tone descriptors, example phrases, phrases to avoid, and custom instructions. When you edit an AI-generated draft, we record the original and corrected versions (a “draft correction”) to improve future output quality. Your most recent corrections are injected into subsequent generation prompts. Corrections are retained for up to 90 days by default. Writing samples you upload (e.g., example emails, playbooks) are stored and embedded for retrieval.

2.6 Knowledge Base Documents

You may upload documents (Markdown, plaintext, PDF, DOCX) to the Monty knowledge base. These are chunked, embedded, and stored in our database. They are used solely to generate contextually relevant email drafts for your account.

2.7 CRM Integration Data

If you connect a CRM such as HubSpot, Pipedrive, or Salesforce, we synchronise lead, contact, and deal records bidirectionally. Data exchanged includes names, emails, company names, statuses, and custom fields you configure. Data imported from your CRM is subject to this policy.

2.8 Copilot Conversations

When you use the Monty Copilot (AI assistant chat), your messages and Monty's responses are stored to maintain conversation context and allow you to review past sessions. You can delete these via the GDPR data deletion endpoint (see Section 12).

2.9 Usage & Technical Data

  • IP address, browser type, and device information associated with requests
  • Feature interactions and session durations (activity events log)
  • API request logs including timestamps, endpoints, and HTTP status codes
  • Error events and diagnostic traces
  • Email tracking events: open timestamps (pixel), click timestamps, IP address, and user-agent of the recipient (see Section 7)

2.10 AI & LLM Usage Metadata

We log LLM usage spans containing token counts, model name, action type, and estimated cost. We do not log the content of prompts or model responses in our observability system.

3. How We Use Your Information

  • Provide, operate, and improve the Service
  • Generate personalised outreach email drafts on your behalf using AI
  • Enrich lead profiles using third-party data providers (see Section 5)
  • Verify contact details and monitor bounces to protect your domain reputation
  • Train your personalised voice profile from writing samples and corrections
  • Process subscription payments and manage your credit balance
  • Maintain audit trails of approvals, sends, and system events
  • Respond to support requests and account inquiries
  • Send transactional communications (billing, security, policy changes)
  • Detect and prevent fraud, abuse, spam, or security incidents
  • Comply with applicable legal obligations

4. AI & Large Language Model Processing

4.1 What We Send to Model Providers

Monty uses third-party large language models — principally Anthropic (Claude) and OpenAI — to generate email drafts, lead summaries, intent classifications, and voice profile analysis. When performing these tasks, we may send the following to those providers:

  • Email body content and conversation history (last 5 messages of relevant threads)
  • Lead profile data (name, company, title, enrichment data)
  • Your voice profile settings (tone, example phrases, recent corrections)
  • Business context from your knowledge base
  • Email subject lines and sender identity

4.2 Model Training

Your data is not used to train model providers' models. We operate under API usage terms which, by default, do not permit training on customer inputs. We do not opt in to any provider training programmes.

4.3 Voice Learning (Local)

Monty's voice improvement loop (learning from your draft edits) is performed locally — corrections are stored in our database and injected into future prompts. No fine-tuning of any external AI model occurs using your correction data.

4.4 Rate Limiting & Controls

All LLM calls are protected by an admission controller that enforces per-client and global request limits. A system-wide kill switch can pause all AI activity instantly (see Section 9).

5. Third-Party Data Enrichment

5.1 Apify (Lead Deep Research)

When you request lead deep research, we query multiple data sources through the Apify platform including LinkedIn profile data, company website content, contact verification, and news feeds. Returned data includes professional profile information, company intelligence, verified contact details, and real-time activity signals. This data is cached in our database and linked to the lead record. Deep research costs 4 credits per lookup. You control when research is triggered.

5.2 Contact & Email Verification

Partial enrichment options can verify a recipient's contact details (such as email address and phone number) through the same Apify pipeline before outreach. Where email validation is enabled for your account, we may additionally submit the recipient's email address (and no other personal data) to ZeroBounce to verify its validity and assess deliverability risk before sending. Combined with bounce monitoring and automatic mailbox pausing, this protects your domain reputation and reduces bounce rates.

5.3 HubSpot, Pipedrive & Salesforce

If you connect a CRM integration, contact and deal data is exchanged between Monty and that CRM in accordance with their respective privacy policies and your data processing agreements with them.

6. Cookies & Local Storage

6.1 Session Cookies

We use Supabase-managed HttpOnly, Secure session cookies for authentication. These cookies contain a JWT access token and refresh token. They are essential for the Service to function. Access tokens are short-lived (typically 1 hour); refresh tokens rotate on use and expire per our authentication provider's session policy.

6.2 Local Storage

We use browser local storage for UI state only (e.g., dismissing informational banners). No personally identifiable information is stored in local storage.

6.3 Analytics Cookies

We use privacy-preserving, cookieless analytics on our marketing site. We do not use third-party advertising or cross-site tracking cookies (no Google Analytics, Mixpanel, Segment, or similar). If this changes, we will update this policy and obtain consent where required.

7. Email Tracking

Outreach emails sent via Monty contain the following tracking mechanisms, which apply to the recipients of those emails (your prospects):

  • Open tracking pixel: A 1×1 transparent image is embedded in the HTML email body. When the email is opened, we record the timestamp, IP address, and user-agent of the device that loaded the image.
  • Click tracking: URLs within the email body are redirected through our tracking endpoint before forwarding to the destination. We record the timestamp, clicked URL, IP address, and user-agent.

You are responsible for ensuring your use of email tracking complies with applicable law in your jurisdiction and the jurisdictions of your recipients (including GDPR, PECR, and CASL requirements regarding electronic tracking). We provide tracking as a tool; legal compliance is your obligation.

8. Autonomous & Scheduled Activity

Monty includes autonomous execution features that can operate without a user being actively logged in:

  • Heartbeat Engine: When enabled (off by default), a background process runs on a configurable schedule to proactively process tasks without user action.
  • Campaign Scheduler: When enabled (off by default), approved campaigns can send emails automatically according to a schedule you define.
  • Autonomy Mode:Your account can operate in “Autonomous” or “Assisted” mode. In Assisted mode, all AI-generated emails require explicit human approval before sending. In Autonomous mode, emails matching your configured rules may be sent automatically. You control this setting and can pause it at any time.

All autonomous actions are logged in the activity event audit trail with timestamps and action types.

9. Global Kill Switch & External API Controls

We maintain a system-wide pause control that, when activated, immediately halts all outbound API calls including email sends (Gmail and Microsoft), AI model requests, and lead enrichment. All blocked attempts are logged with reason and timestamp. This mechanism is used for planned maintenance, security responses, and compliance holds.

10. Legal Bases for Processing (GDPR)

Where the GDPR applies, we process personal data on the following legal bases:

  • Contract performance: Processing your account data, billing information, and email account integration data is necessary to deliver the Service.
  • Legitimate interests: Processing usage analytics, audit logs, and fraud prevention data where these interests are not overridden by your privacy rights. Lead enrichment — supplementing a contact record with information from third-party sources — also rests on legitimate interests, assessed in a written legitimate interest assessment, and is subject to the absolute right to object described in Section 12.
  • Legal obligation: Retaining billing and transaction records as required by financial regulations.
  • Consent: Where we ask for it explicitly and you agree — for example optional analytics cookies. We do not treat continued use of the Service as consent.

We are the data controller for the account data of your users (name, email, profile, login and usage records). Regarding the lead and contact records you create and store in Monty: you are the data controller for those records, and we process them as your data processor under a Data Processing Agreement (DPA) available upon request.

11. Sharing of Information

We do not sell your personal data. We share data only as follows:

  • Sub-processors: Third-party services listed in Section 13 who process data on our behalf under binding data processing agreements.
  • Legal requirements: When required by law, regulation, court order, or governmental request.
  • Business transfers: In the event of a merger, acquisition, or asset sale, with prior notice to you and continuation of equivalent protections.
  • Protection of rights: To enforce our Terms of Service or protect the rights, safety, or property of Monty, our users, or third parties.

12. Your Rights & Data Requests

Depending on your location, you may have rights under GDPR, CCPA, or other applicable law:

  • Right to access the personal data we hold about you
  • Right to correct inaccurate or incomplete data
  • Right to erasure (“right to be forgotten”)
  • Right to restrict or object to processing
  • Right to data portability
  • Right to withdraw consent at any time (where processing is consent-based)

Data export: You can export your personal data (user profile, activity events, copilot conversations, notifications) via the account settings page or by requesting it at hello@montyai.co.

Data deletion: You can request deletion of your personal data (profile, chat history, activity log, notification settings). Note that lead, contact, campaign, and billing records are owned by the Client organisation, not the individual user, and follow separate retention rules. Billing/audit records may be retained as required by law.

Correction: You can correct your name, phone number and avatar from the account settings page. Your email address is your login identity — contact us to change it, so we can verify the request first.

Restriction and objection: You can ask us to stop processing your data while keeping the record intact — for example if you dispute its accuracy. A restriction stops outbound sending, enrichment and AI processing for that record; it does not delete anything, and we will tell you before we lift one. Objection to direct marketing is absolute: we act on it immediately and do not weigh it against our own interests.

If you are a lead or contact in a customer’s workspace: that customer is the data controller for your record, not us. Contact them directly. If you reach us instead, we will help them respond — we can produce a full copy of what their workspace holds about you, and erase it on their instruction.

To exercise any right, contact hello@montyai.co. We will respond within 30 days (GDPR) or 45 days (CCPA) of receiving a valid request.

13. Sub-Processors

We use the following sub-processors who may process personal data on our behalf:

ServicePurposeData SharedLocation
SupabaseDatabase & authenticationAll stored dataEU / US
StripePayments & billingBilling info, subscriptionUS
AnthropicAI text generationEmail content, lead profiles, voice dataUS
OpenAIAI text generation & embeddingsEmail content, lead profiles, voice dataUS
Google (Gmail API)Email read & sendMailbox contentsUS
Microsoft (Graph API)Email read & send (Outlook)Mailbox contentsUS / EU
ApifyLead enrichment & deep researchName, email, LinkedIn URLUS / EU
ZeroBounce (optional)Email validation, when enabledEmail addressUS
HubSpot (optional)CRM syncLead & contact dataUS
Pipedrive (optional)CRM syncLead & contact dataEU
Salesforce (optional)CRM syncLead & contact dataUS

14. Data Retention

We retain data as follows:

  • Account & profile data: Retained while your account is active, and for 90 days after a workspace is suspended for non-payment — read-only, with two warnings by email before it is deleted (Terms, Section 23.4). Deleted or anonymised on verified deletion request.
  • Email message bodies (synced mailbox content): The full text of synced emails is erased 90 days after the message was received. The envelope (sender, recipient, subject, timestamps) is retained for threading and audit.
  • Conversation & message history: Envelope and metadata retained indefinitely unless explicitly deleted by the Client. Client-owned data.
  • Draft corrections (voice learning): Retained for up to 90 days by default.
  • Billing records & credit ledger: Retained indefinitely as required by financial/legal obligations. The credit ledger is append-only.
  • Security & compliance audit log: Retained indefinitely for compliance and dispute resolution. This is a restricted-access record of administrative actions, not a behavioural profile.
  • In-product activity feed: Deleted 90 days after the event.
  • Email tracking & message events: Event records are retained as part of message history; personal data attached to those events is erased after 90 days.
  • Copilot conversations: Retained while your account is active; deletable via data deletion request.
  • Transient processing queues (Redis streams): Working queues are retained for 3 days and processing results for 7 days. Records that fail processing move to a dead-letter queue retained for up to 30 days so the failure can be diagnosed and replayed.

These windows are enforced automatically by a scheduled retention job, not by manual housekeeping. Where a window is stated as a number of days, data past that age is erased on the next nightly run.

15. Security

We implement industry-standard safeguards: encryption at rest and in transit (TLS), HttpOnly and Secure session cookies, role-based database access controls (read-only vs. write roles enforced at PostgreSQL level), Row-Level Security (RLS) policies scoped to client and user, API rate limiting, encrypted storage of OAuth tokens and credentials, and a kill switch for external API activity. No method of internet transmission is 100% secure; we cannot guarantee absolute security but will notify you of any confirmed breach as required by applicable law.

16. International Data Transfers

Your data may be processed in countries other than your own, including the United States. Where we transfer data outside the European Economic Area (EEA), we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or adequacy decisions recognised by the European Commission. Data stored in Supabase is hosted in the EU by default.

17. Children's Privacy

The Service is intended for business use only and is not directed at individuals under 18. We do not knowingly collect data from minors. If you believe we have inadvertently done so, contact us immediately.

18. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email and by updating the “Last updated” date at the top of this page. Continued use of the Service after the effective date of changes constitutes your acceptance of the revised policy.

19. Contact & Data Protection Enquiries

For privacy requests, questions about this policy, or to request a Data Processing Agreement (DPA):

HelloQuartz Ltd, trading as Monty
Registered in England and Wales, company number 16465861
Registered office: 1 The Granthams, Lincoln, LN2 3SP, United Kingdom
hello@montyai.co

You also have the right to lodge a complaint with your local supervisory authority (in the UK: the ICO at ico.org.uk).