Privacy

MONA Cloud Privacy Policy

This policy explains how The MONA Group collects and uses your data when you use MONA Cloud services. We collect account information, payment data, resource configurations, and technical data. This data is used to provide services, process payments, offer technical support, and ensure system security. You can contact us via email at [email protected] or call 1900 636 648 for privacy support.

This policy explains how The MONA Group collects and uses your data when you use MONA Cloud services. We collect account information, payment data, resource configurations, and technical data. This data is used to provide services, process payments, offer technical support, and ensure system security. You can contact us via email at [email protected] or call 1900 636 648 for privacy support.

Who is responsible for managing your data?

The MONA Group is the primary party responsible for your data. Our full legal name is MONA MEDIA Co., Ltd. The company was founded in 2016 and is headquartered in Ho Chi Minh City. Our business operations comply with the laws of the Socialist Republic of Vietnam.

When you use services on the https://monacloud.vn website, The MONA Group acts as the data controller. We are responsible for establishing technical safeguards to protect your data. We also decide how your data is collected and processed. The products covered by this policy include the entire MONA Cloud ecosystem.

This ecosystem includes server and application hosting services. The MONA Base database service and MONA Pass account management are also included. The MONA Cloud VND Wallet handles payments. Furthermore, the policy applies to the MONA Domain management service. The MONA Mail transactional email service and MONA Pay automated payment system also comply with this policy.

Finally, this policy applies to the MCP server named monacloud-mcp. The system includes a remote endpoint located at https://mcp.monacloud.vn/mcp. This endpoint allows AI assistants to call programming tools on behalf of users.

What data do we collect?

When you create an account via MONA Pass, we store your email address and display name. Your password is saved in a hashed format to ensure security. If you choose to log in using a Google or GitHub account, we only retrieve three pieces of information. These three pieces are your email address, display name, and avatar profile picture. When you enable two-factor authentication, we will save your TOTP key.

For wallet and payment transactions, we collect necessary transaction details. The data includes the deposit amount, time of execution, transfer note, and bank transaction code. Money is deposited via VietQR bank transfer. Funds are transferred to MONA's bank account opened at ACB bank. We absolutely do not store your card number. Wallet top-ups can only be made via bank transfer. The system does not require and does not support direct card payments.

When you use the service, we collect data regarding the resources you create. This includes the configurations of your servers, applications, and databases. Build logs and application deployment processes are also recorded. We store the source code you upload so the system can proceed with deployment. The data within your databases is also protected on our system. We only access this data when technical operations are required. We may also access it when we receive a direct support request from you.

If you register a .vn domain name, Vietnamese law via VNNIC requires a complete registrant declaration. This information includes a personal full name or organizational name. The declaration also requires a citizen identification number or tax code. You must also provide a physical address, phone number, and email address. The information will be transferred to the Registrar, MONA Host, and the VNNIC center. This is for the purpose of registering and maintaining your domain name. For international domain names, contact information is collected according to ICANN standards. This data is then transferred to international partner registrars.

If you reserve a domain name without creating an account, we collect your email and phone number. Consenting to receive marketing information is an optional choice. This checkbox is always left blank by default. You can withdraw this consent at any time via email.

Regarding the MONA Mail service, we collect the recipient's email address. The content of emails you send via the API is also processed. The system records email sending and receiving logs to report delivery status or bounce events. Technically, the system logs your IP address. User-agent information, API call times, and error codes are also stored. API logs never store passwords or security tokens.

What is your data used for?

We primarily use your data to provide and operate services within the MONA Cloud ecosystem. The core purpose is to ensure your servers, applications, and accounts run stably every day. This process includes allocating resources and maintaining continuous network connectivity.

Payment data is used to automatically confirm deposit transactions. We use this information to update your wallet balance. This data is also necessary to issue Value Added Tax invoices in accordance with the law. Technical data helps us detect software errors. This allows us to provide rapid technical support to you.

We use data to ensure system security and prevent fraudulent activities. One example is blocking automated clients from mass-creating accounts. We will send you service notifications when a service is about to expire. Notifications are also sent when your wallet balance is low or when technical issues occur. We only send promotional information when you have explicitly agreed to receive it.

How do AI assistants and MCP work with your data?

MONA Cloud provides standard MCP connections for you to work with advanced AI assistants. This list includes Claude, ChatGPT, Cursor, and Codex. When you connect an AI assistant to the service, the assistant will call the API using an OAuth token. You directly grant this permission through the MONA Pass management system.

We never receive your original password from AI assistant applications. You have full management rights and can revoke this access permission at any time. Revoking access is easily done right inside the MONA Pass management page. Our system only receives tool call commands from the AI assistant. We also receive the necessary parameters to execute that command.

The detailed conversation content between you and the AI assistant belongs to the AI platform you are using. Anthropic or OpenAI manages this data according to their policies. MONA does not collect or store these conversations. We absolutely do not use customer data to train any AI models. You can use programming assistants without worrying about your internal data being taken for machine learning.

Which third parties is your data shared with?

We only share data with third parties for the purpose of directly providing services to you. We strictly commit to never selling your data to any individual or organization. Sharing is limited to the minimum necessary for the services to function.

For domain name services, your information is shared with the Registrar and the VNNIC management organization. ACB Bank receives transaction data to reconcile funds deposited into our account. Cloudflare is a partner that provides domain name resolution services. They also provide solutions to protect the system against denial-of-service attacks.

Your data also resides on the systems of data center infrastructure providers. These physical servers are located in Vietnam. Providers of electronic invoicing solutions also receive necessary information. This is for the purpose of issuing valid VAT invoices. Additionally, we will provide data to state agencies when there is a valid legal request.

Where is your data stored and for how long?

MONA Cloud servers are located in secure data centers in Vietnam. However, you can actively choose a different storage region for your resources. These regions include Hong Kong, Singapore, Australia, or the United States. Your data will be accurately stored in the region you selected.

Your account data is kept on the system until you request account deletion. However, payment receipts and VAT invoices will be retained for 10 years. This storage is to strictly comply with accounting laws. Technical system logs are stored for a maximum period of 90 days.

For data in temporary sandbox environments, it will be automatically deleted after 24 hours. When you manually delete a resource, the related data will be removed from our system. If you have enabled backups, the backups of that resource will be processed. Backups will be retained or deleted according to the exact schedule you configured beforehand.

What rights do you have regarding your data?

You have the right to access the system to view and modify your personal data at any time. You can also download the information you have provided to us. This feature helps you take full control of your information.

If you previously agreed to receive marketing messages, you have the right to withdraw this consent. Unsubscribing from emails can be done through a link in the email. You also have the right to request us to delete your account when you no longer need the service. Please note that MONA must still retain payment receipts in accordance with the law.

To exercise these rights, please send a formal request via email. The receiving email address is [email protected]. We commit to receiving and responding to your request within 7 working days. We are always ready to assist in protecting your legitimate rights.

How do we protect your data?

Your password is always hashed using strong one-way algorithms. All data transmitted over the network is encrypted via the TLS protocol. This applies to all data transmission routes between you and the servers. Server authentication credentials are provided only through a specialized endpoint. This endpoint always has strict monitoring and logging systems.

In internal operations, we apply the strictest access control policies. The system always records access logs to track operational activities. We pay special attention to operations involving critical customer data. Our employees are granted permissions only when their work truly requires it.

If a data breach unfortunately occurs, we will act immediately. MONA commits to notifying affected users via email. The notification timeframe is within 72 hours from the moment we confirm the incident. We will guide you through the necessary steps to protect your account and data.

What is the policy for minors?

MONA Cloud services are designed for adult individuals and businesses. Users must be at least 18 years old to have legal capacity. You must reach this age to create an account and use our services.

We do not intentionally collect personal information from children under the required age. If you discover that someone under 18 has provided information, please notify us immediately. We will investigate the information. Afterward, we will promptly remove the related data from the system.

When is this policy updated?

We may update and modify this privacy policy from time to time. Any changes to the policy will be publicly posted on this website.

When a new version is available, we will clearly state the effective date at the bottom of the page. If there are major changes that affect your rights, we will notify you separately. An email notification will be sent to you before the new policy takes effect. You should occasionally check this page. This helps you stay informed of the latest information promptly.

How to contact us?

If you have any questions about this privacy policy, please contact us immediately. You can send an email outlining your concerns to [email protected].

Alternatively, you can also call our hotline at 1900 636 648. Our support team will answer your questions directly. We are always ready to answer any inquiries regarding data protection.

Effective Date

Effective Date: 19/09/2026.

Vietnamese version: Chính sách quyền riêng tư. Terms of use: /dieu-khoan.