MONARCH / LEGAL
Privacy Policy
Draft policy text supplied for Monarch Cyber Solutions, ForgeAI, Repuvo, and Rubato. Attorney and operational review remain required before publication.
1. Introduction
This Privacy Policy explains how Monarch Cyber Solutions ("Monarch," "we," "us," or "our") collects, uses, discloses, and protects information in connection with our website and our three products: ForgeAI, Repuvo, and Rubato (together, the "Services").
By using our website or any of our Services, you agree to the collection and use of information as described in this policy. If you do not agree with this policy, please do not use our Services.
2. Who This Policy Covers
This is a single policy covering the Monarch corporate website and all three products, because each product handles data differently:
- ForgeAI is a physical AI appliance installed on your own premises. By design, ForgeAI processes documents, prompts, and outputs locally, on hardware you own. Monarch does not have access to the content processed by your ForgeAI unit.
- Repuvo is a hosted SaaS product that sends messages on behalf of business customers to their own customers, and processes reviews and related data as part of that service.
- Rubato is designed as a local-first content production system. Customer brand context, drafts, and media assets can live on your own machine or controlled environment rather than on Monarch's servers.
Where a section applies to only one product, it says so explicitly.
[Confirm: no remote telemetry, usage logging, or diagnostic data collection exists beyond what's disclosed in Section 3 below.]
3. Information We Collect
3.1 Information You Provide Directly
- Contact form submissions (name, company, email, phone, message)
- Demo and early-access requests
- Account registration information for Repuvo or Rubato
- Support and installation communications
- Content you submit to us in the course of using a Service, such as a Rubato brand context file you choose to store on our infrastructure rather than locally
3.2 Information Collected Automatically
- Standard website analytics (pages visited, time on site, referring source, and general device/browser information)
- Cookies and similar tracking technologies (see Section 11)
- Server logs for the corporate website and any hosted product dashboards
3.3 ForgeAI — Data We Do and Don't Collect
ForgeAI is installed and operated on your own hardware, at your location. We do not collect, store, or have access to the documents, prompts, queries, or AI-generated outputs processed by your ForgeAI unit. That data stays on the physical hardware inside your building, consistent with the product's core design.
What we do collect in connection with ForgeAI:
- Installation and delivery logistics (shipping address, site contact, installation scheduling)
- Hardware identifiers for warranty, support, and maintenance purposes, such as serial number
- Support ticket content you choose to share with us
- Billing information for the one-time hardware purchase and the recurring support plan
[Confirm before publishing: if the support plan includes any remote diagnostics, health monitoring, or update-delivery mechanism that transmits any data off the unit — even non-content metadata like uptime or error codes — that must be disclosed here specifically, since it would otherwise contradict the "your data never leaves your building" claim made elsewhere on the site.]
3.4 Repuvo — Data We Collect, Including About Your Customers
Repuvo involves two distinct categories of personal data:
(a) Your account data, as our direct customer: business name, contact information, billing information, and your Google Business Profile connection.
(b) Your customers' data, which you provide to us so Repuvo can contact them on your behalf: name, phone number, and/or email address, plus the content of their responses (sentiment and review text) when they reply to a Repuvo message.
If you are a customer of a business that uses Repuvo, Repuvo processes your contact information and any response you provide on behalf of that business, not on our own behalf. That business is responsible for having your consent to be contacted about your service experience. Questions about why you received a message should go to the business you interacted with; Repuvo's role is described in Section 4 below.
3.5 Rubato — Data We Collect
Rubato is designed to keep customer context, drafts, media assets, and workflow configuration on your own machine or controlled environment wherever possible. Where you choose to use hosted features, such as cloud-based media rendering or storing brand context on our infrastructure rather than locally, we collect and store that content for the purpose of operating the Service. We also collect reviewer decisions and feedback within the Review Queue for the purpose of the product's learning/memory feature, as described on the Rubato product pages.
4. SMS and Text Messaging (Repuvo)
This section applies specifically to Repuvo's text-message review-request feature.
Consent. Repuvo sends text messages to a business's customers on that business's behalf, to ask about their experience and, where applicable, request a review. Each business using Repuvo is responsible for obtaining proper prior express consent from its own customers before those customers are contacted through Repuvo — Repuvo does not supply or substitute for that consent. Consistent with current FCC guidance, consent is collected and registered on a per-business basis rather than as a shared or generic opt-in covering multiple companies.
Message frequency. Message frequency varies based on the business's usage of the Service.
Message and data rates. Message and data rates may apply, per the recipient's mobile carrier plan.
Opt-out. Recipients may reply STOP to opt out of future messages, or use any other reasonable method to indicate they no longer wish to be contacted, such as replying "unsubscribe," "remove me," or a similarly clear request. Reply HELP for help.
Quiet hours. Messages are sent only between 8:00 AM and 9:00 PM in the recipient's local time zone.
Carrier disclaimer. Carriers are not liable for delayed or undelivered messages.
[Attorney note: as of early 2026, the FCC's "revoke-all" rule has been delayed to January 31, 2027, and is not yet in effect. This section should be revisited before that date. Confirm current status before publishing and periodically thereafter.]
5. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Services
- Process transactions and manage billing
- Respond to inquiries, demo requests, and support needs
- Send Repuvo review requests on behalf of our business customers, as described in Section 4
- Improve our products and website
- Communicate with you about your account or our Services
- Comply with legal obligations
We do not use ForgeAI customer content (Section 3.3) or locally-stored Rubato content (Section 3.5) for any purpose, because we do not have access to it.
6. How We Share Information
We do not sell personal information.
We may share information with:
- Service providers who help us operate the business, such as hosting, payment processing, email delivery, and SMS carrier/messaging infrastructure for Repuvo, bound by contractual obligations to protect it
- Legal and safety purposes, where required by law, subpoena, or to protect the rights, property, or safety of Monarch, our customers, or others
- Business transfers, in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections
[Attorney note: for Repuvo's template-based dispute document workflow, confirm what record information, if any, a customer shares with that customer's own lawyer for review before the document is sent.]
7. Data Retention
We retain information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements.
[Attorney/ops note: specific retention periods per data category — account data, support tickets, Repuvo message logs, and Rubato hosted content — should be defined here once actual retention practices are set.]
8. Data Security
We use reasonable administrative, technical, and physical safeguards designed to protect information from unauthorized access, use, or disclosure. ForgeAI's on-premise, locally-processed design means the data it processes never transits our infrastructure at all. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
[Do not claim SOC 2, HIPAA, or similar compliance certifications here unless Monarch actually holds them. Use accurate language such as "designed to support your organization's compliance requirements" instead.]
9. Your Privacy Rights
Depending on where you live, you may have rights including:
- Right to know/access what personal information we've collected about you
- Right to delete personal information we've collected
- Right to correct inaccurate personal information
- Right to opt out of the sale or sharing of personal information (we do not sell personal information, as noted in Section 6)
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising any of these rights
- Right to appeal a denied privacy request
To exercise any of these rights, contact us at [PRIVACY EMAIL]. We'll verify your request and respond within the timeframe required by applicable law.
[Attorney note: this list reflects the CCPA/CPRA framework. As of 2026, 20 states have their own comprehensive privacy laws with meaningful differences — this section needs a jurisdiction-by-jurisdiction review once the customer base is known.]
10. Automated Decision-Making and AI
ForgeAI, Repuvo, and Rubato all involve AI-generated content or output. Where our Services use automated processing to generate content, drafts, or responses, a human review step is built into the workflow before anything is finalized or published. We do not use automated decision-making to make legal or similarly significant decisions about individuals without human involvement.
[Attorney note: California's CCPA regulations added specific automated decision-making technology disclosure and opt-out requirements effective January 2026. This is a starting point, not a complete ADMT disclosure, and should be reviewed against current regulations before publication.]
11. Cookies and Tracking Technologies
Our website uses cookies and similar technologies for analytics and to understand how visitors use our site. You can control cookies through your browser settings.
[Add a specific cookie table/category breakdown once analytics and marketing tools are finalized, and add a cookie consent banner if targeting states or visitors that require one.]
12. Third-Party Links and Services
Our website and Services may contain links to third-party sites, such as Google Business Profile or social media platforms Rubato publishes to, that are not operated by us. We are not responsible for the privacy practices of those third parties.
13. Children's Privacy
Our Services are not directed to individuals under 18, and we do not knowingly collect personal information from children. If we learn we've collected information from a child, we will delete it.
14. International Users
[If Monarch's customers, Repuvo's end-recipients, or Rubato users could be located outside the United States, this section needs to address international data-transfer mechanisms. This remains a placeholder pending confirmation of whether that is in scope.]
15. Changes to This Policy
We may update this Privacy Policy from time to time. We'll post the updated version here with a new "Last Updated" date, and for material changes, we'll provide additional notice where required by law.
16. Contact Us
Questions about this Privacy Policy or your data:
Monarch Cyber Solutions1838 SE 1st Street
Cape Coral, FL 33990
aperez@monarchcybersolutions.net
