1. Purpose
This Confidentiality & File Handling Policy explains Monument’s baseline contractual and operational approach to non-public Client information and project materials. It supplements the Terms of Service. A separately signed NDA, Data Processing Agreement, or other written agreement may add or replace requirements for a specific engagement.
2. What Monument May Receive
Depending on the assignment, Monument may receive drafts, reports, internal documents, business data, spreadsheets, presentations, notes, branding, research, images, correspondence, prior work, links, instructions, and other source material. The Client should send only information reasonably relevant to the assignment.
3. Baseline Confidentiality Commitment
Monument treats non-public business information supplied in connection with an assignment as confidential information and will:
- Use it only to evaluate, provide, administer, support, quality-check, and document the requested services.
- Restrict access to persons and service providers with a legitimate need for the assignment or Monument’s business operations.
- Use commercially reasonable safeguards appropriate to the nature of the information and size of the business.
- Not publicly disclose non-public Client materials without authorization, except as permitted by the Terms or required by law.
4. How Project Information Is Used
Project information may be used for evaluating the assignment, producing the deliverable, communicating with the Client, quality assurance, billing and transaction records, support, security, fraud prevention, dispute resolution, and legal or recordkeeping requirements.
5. Who May Process Information
Monument may use professional tools and third-party service providers reasonably necessary for hosting, payments, email, file sharing or storage, business productivity, document production, analytics, security, and AI-enabled production assistance where appropriate. Access is limited to what is reasonably necessary for the applicable function.
6. Transfer and Storage
Depending on the services and tools used, information may be transmitted to or stored by third-party providers. Monument does not promise a particular data-residency location unless separately agreed in writing before the Client sends restricted information.
7. Security
Monument uses commercially reasonable safeguards appropriate to the nature of the information and the size of the business. No internet, email, cloud, file-sharing, or storage system can be guaranteed completely secure. Monument will investigate suspected security incidents involving information in its control and will provide notices required by applicable law.
8. Sensitive and Restricted Information
Unless specifically arranged in advance, Clients should not send passwords, login credentials, Social Security numbers, full payment-card information, bank login credentials, protected medical information, classified information, export-controlled information, or highly restricted regulated information.
Monument does not claim HIPAA compliance, SOC 2 certification, PCI certification, ISO certification, or government clearance unless that changes and is expressly confirmed in writing.
9. Special Requirements
If a Client has vendor approval, security, data-residency, confidentiality, regulatory, retention, deletion, or other special handling requirements, the Client must raise them before sending the affected information or before production begins. Monument may decline information or work requiring controls it does not currently provide.
10. Retention and Deletion
Project materials may be retained while reasonably necessary to provide and support the services, maintain records, resolve disputes, comply with law, protect security, or preserve legitimate business records. Where reasonably practicable and legally permitted, a Client may request deletion of project materials Monument no longer needs.
11. Exceptions and Compelled Disclosure
Confidentiality obligations do not apply to information that becomes public without Monument’s breach, was lawfully known before disclosure, is independently developed without use of the Confidential Information, is lawfully received from another source, or must be disclosed by law or legal process.
Where legally permitted and reasonably practicable, Monument will use commercially reasonable efforts to notify the Client before disclosing Confidential Information in response to compulsory legal process.
12. Portfolio, Publicity, Names and Logos
Monument will not publicly use a Client’s non-public deliverables, confidential materials, name, logo, testimonial, or case study without permission. There is no automatic portfolio license for private Client work.
13. Contact
Questions about confidentiality or file handling may be sent to samuel@monumentdocuments.com.