← sebbi.pro
monop content · policy document · public

Data Protection &
Sovereignty Statement

Document: MC-POL-002 · Version 1.0 · Effective 20 July 2026
Owner: Justin Dobson, Founder, Monop Content · Review cycle: quarterly, and on any material change to data handling
Alignment: UK GDPR / EU GDPR · published at sebbi.pro/data-protection

1.The design principle: the safest data is the data we never hold

AILeash is built on aggressive data minimisation. Wherever the platform can do its job with a cryptographic fingerprint instead of content, it holds only the fingerprint. This is not a bolted-on privacy feature — it is the architecture:

2.What we process, and why

DataContentPurpose · lawful basis
Governed eventsuser_id (customer-supplied identifier), action label, amount, country code, device_id, two 0–1 risk signals, optional authority tokenDelivering the contracted decision and evidence service · performance of contract
Sealed chain recordsEvent, verdict, reasons, jurisdiction tag, timestamp, hashesThe tamper-evident evidence record that is the product itself · performance of contract; customers' legitimate interest in verifiable records
Account dataE-mail address, hashed API key, plan status, device countsAccount operation, alerts, billing · performance of contract
Billing dataHandled by Stripe; we hold no card numbersPayment collection · performance of contract
Notary sealsSHA-256 fingerprints; for identity seals marked public, the limited display fields the user chooses to include; masked payment display fieldsThe public notarisation service · consent (the user submits the seal)
Contact messagesWhat the sender chooses to writeResponding · legitimate interest
Pseudonymisation is a shared responsibility, stated plainly: the user_id and device_id fields are supplied by the customer. Our documentation instructs customers to send pseudonymous identifiers (e.g. user_4471), never names, e-mail addresses or other direct identifiers. Where a customer follows this, chain records contain no directly identifying personal data. Customers acting as controllers remain responsible for what they choose to transmit; Monop Content acts as processor for event data processed on customers' instructions.

3.What we deliberately do not hold

4.Where data lives, and the sovereign option

The hosted platform runs on Railway cloud infrastructure with the database on a persistent encrypted volume; connections are TLS-encrypted in transit; backups are taken daily. Sub-processors are listed in §7. Hosting region details and current sub-processor terms are available on request at justin@monopcontent.com.

Full data sovereignty is a product option, not a promise: organisations whose data cannot leave their own network can run the sovereign engine entirely on their own hardware — decisions, chain and database inside their building, licence validation fully offline, no phone-home. Under sovereign deployment, Monop Content processes nothing at all.

5.Retention — and the honest tension with an append-only chain

Account and billing data are retained for the life of the account plus the period required by tax and accounting law. Contact messages are retained only as long as needed to respond.

Chain records require an honest explanation rather than a boilerplate one. The chain is append-only by design — its evidential value exists precisely because records cannot be deleted or altered. This is why the platform is architected so that chain records should contain no directly identifying personal data: fingerprints, pseudonymous identifiers and hashes are sealed; content and identities are not. Where a valid erasure request nonetheless touches sealed data (for example, display fields a user chose to make public on an identity seal), we honour it by erasing the stored display data while the cryptographic fingerprint — which identifies no one — remains in the chain. This preserves both the data subject's rights and the integrity of the record for everyone else.

6.Data subject rights

Requests for access, rectification, erasure, restriction or portability go to justin@monopcontent.com and are answered within one calendar month. For event data processed on a customer's behalf, requests are handled with, and routed via, the customer as controller. UK data subjects may complain to the ICO; EU data subjects to their national supervisory authority.

7.Sub-processors

ProviderPurposeData touched
RailwayApplication hosting and database volumeAll hosted-platform data at rest and in transit
StripeBilling and payment processingBilling identity and payment card data (held by Stripe, not by us)
BrevoTransactional e-mail (alerts, receipts, contact)E-mail addresses and message content of e-mails sent

Sub-processors will not be added or changed without this document being updated — and each revision of this document is fingerprinted and sealed into the chain, so its history is tamper-evident.

8.Security measures, summarised

Honest maturity statement: Monop Content is an early-stage, single-operator company. This statement describes practices genuinely in operation today. We do not hold ISO 27001 or SOC 2 certification at this stage and will not imply otherwise; what we offer instead, unusually, is a platform whose core integrity claims any prospect can verify from outside before trusting us with anything.