Legal
How NTV LTD uses personal information to run and secure Monocrawl.
Effective
Version
Controller
Privacy requests
01NTV LTD, trading as Monocrawl, is the controller of personal information used to create accounts, supply the service, bill customers, secure systems and handle enquiries. Its registered office is Amelia House, Crescent Road, Worthing, West Sussex, England, BN11 1QR; company number 11364012.
This Notice applies under the UK GDPR and Data Protection Act 2018 as amended, including relevant changes made by the Data (Use and Access) Act 2025.
02This Notice covers visitors, account users, prospective and current customers, people who contact us, and security events involving the service. It does not govern a customer’s independent use of API results.
Personal information appearing in third-party or publicly accessible source data is addressed separately in the Public Data and Data Sources Notice. Depending on the processing, a customer may be an independent controller of its downstream use.
0304Contract and steps before a contract
We use account, request, billing, subscription, job, monitor, webhook and support information to open the account, authenticate you, execute requested calls, meter credits, take payment, provide receipts, deliver webhooks and provide support.
Legal obligations
We keep and disclose information where necessary for tax, accounting, company, consumer, payment, sanctions, law-enforcement or data-protection duties.
Legitimate interests
We use proportionate service and security information to prevent fraud and abuse, defend systems, investigate incidents, diagnose failures, enforce the Terms, understand reliability and improve the service. Our interests are providing a secure commercial API and protecting customers and upstream resources. We balance those interests against the impact on people and use less identifying information where practical.
Consent
Where we introduce optional marketing or non-essential storage requiring consent, consent will be requested separately and can be withdrawn. Current authentication and checkout storage does not rely on marketing consent.
05We receive information from you, your organisation, your browser or API client, Stripe, authentication providers you choose, security and infrastructure services, and the third-party source or upstream provider named or implied by the endpoint.
For public-source information about someone who is not a customer, categories typically include public profile identifiers, public posts or comments, public engagement figures and related metadata. Sources include official APIs, independent API providers and publicly accessible pages. Exact provenance varies by endpoint and response; see the Public Data Notice.
07The primary database region is Ireland and application execution is configured in London. Some suppliers are headquartered or provide support and onward processing outside the UK. Where UK personal information is transferred to a country without UK adequacy regulations, we require an applicable safeguard such as the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful transfer mechanism, together with risk assessment where required.
Calling an endpoint may send a target to an upstream in another country. Do not submit confidential information or unnecessary personal information as a query.
08Deletion first disables auto-recharge and cancels an active Stripe subscription; if Stripe does not confirm cancellation, local erasure is aborted. Legal holds, disputes, fraud prevention or tax duties may require limited information to be kept longer.
09Controls include hashed API keys, encrypted transport, scoped authentication, optional two-factor authentication, revocable sessions, body-size limits, distributed rate limiting, signed webhooks, audit records, private-network blocking for customer-supplied fetch targets and restricted database access.
No internet service can guarantee absolute security. Use unique credentials, enable two-factor authentication, restrict and rotate keys, and report suspected incidents through the security category without sending secrets.
10Depending on the circumstances, you may ask for access, correction, erasure, restriction, portability, or an explanation of processing; object to processing based on legitimate interests; withdraw consent; and complain to a supervisory authority. Rights are not absolute and we may need identity evidence or retain information required by law.
For direct marketing, an objection is unconditional. For legitimate-interest processing, we will stop unless compelling legitimate grounds override your interests, rights and freedoms or the information is needed for legal claims. Public-data suppression requests are handled under the Public Data Notice.
We do not currently make solely automated decisions about customers that produce legal or similarly significant effects.
12Submit a privacy request at our recorded contact route; choose “Privacy/data rights”. It accepts requests without an account and provides a reference. Postal requests may be sent to NTV LTD, Amelia House, Crescent Road, Worthing, West Sussex, England, BN11 1QR.
You may complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We would appreciate the chance to address the issue first, but you do not have to contact us before the ICO.
This Notice may change as processors or features change. We will publish the new version and date, and give appropriate notice of a material change.