Privacy Policy
We take your privacy seriously. This policy explains what data we collect, why we collect it, and how you can control it.
Your data is never sold to third parties or used for advertising.
Export your data and delete your account at any time with one request.
We collect only what the product needs, and we honour data requests — see your rights below.
Traffic is encrypted with TLS, and sensitive credentials are encrypted in our database.
On this page
1. Who We Are
Mono ("we", "us", "our") is a SaaS platform for team and business operations. This Privacy Policy applies to all services offered through mono.com and any related applications.
We act as the data controller for personal data we collect directly from you. For data you input about your clients, employees, or other third parties into the platform, we act as a data processor on your behalf.
Contact: support@mono-sys.com
2. Data We Collect
We collect only what is necessary to provide and improve the Service.
Account & identity data
When you register, we collect your name, work email address, and company name. If you invite team members, we collect their email addresses.
Usage & activity data
We collect information about how you use the platform: pages visited, features used, actions taken, and timestamps. This is used to improve the product and detect security issues.
Device & technical data
We automatically collect your IP address, browser type and version, operating system, and time zone. We use this for security monitoring and service optimization.
Payment data
Subscriptions are paid by bank transfer against an invoice we issue. We do not take card payments, so we never receive or store card numbers. We retain your billing name, billing address, the bank details you supply for the transfer, and the invoice and payment records themselves, for legal and accounting purposes.
Content you create
All data you enter into Mono (projects, tasks, client records, contracts, time entries, HR records, etc.) is stored on your behalf. You remain the owner of this data.
Cookies & tracking
We use strictly necessary cookies to keep you signed in. We do not use advertising, tracking or analytics cookies, so there is nothing to opt out of.
3. How We Use Your Data
We use your data solely to:
- Provide the Service — authenticate you, store your content, and deliver platform features.
- Communicate with you — send transactional emails (account verification, password resets, billing receipts) and occasional product updates. You can unsubscribe from marketing at any time.
- Improve the product — analyze aggregated, anonymized usage patterns to guide our roadmap.
- Maintain security — detect fraud, abuse, and unauthorized access.
- Comply with legal obligations — retain financial records as required by law.
We do not sell your data. We do not use your content to train AI models. We do not share your data with advertisers.
4. Legal Basis for Processing
Where required by applicable law (e.g., GDPR), we rely on the following legal bases:
- Contractual necessity — processing needed to provide the Service you signed up for.
- Legitimate interests — security monitoring, fraud prevention, and product analytics (where not overridden by your rights).
- Consent — marketing communications and optional analytics cookies.
- Legal obligation — financial record retention.
6. Data Retention
We retain your data for as long as your account is active. When you delete your account:
- You have 30 days to export your data.
- After 30 days, your content is permanently deleted from our systems.
- Anonymized, aggregated analytics data may be retained indefinitely.
- Financial records are retained for 7 years as required by accounting law.
- Backup copies may persist for up to 90 days after deletion before being purged.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your personal data ("right to be forgotten").
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests.
- Restriction — request that we limit how we process your data.
- Withdraw consent — opt out of marketing or analytics cookies at any time.
To exercise any of these rights, email support@mono-sys.com. We will respond within 30 days. We may need to verify your identity before processing the request.
8. Security
We protect your data with:
- Traffic encrypted in transit (TLS), with sensitive credentials encrypted at rest in our database.
- Role-based access controls — employees access data only on a need-to-know basis.
- Automatic session timeouts and multi-factor authentication support.
In the event of a data breach affecting your data, we will notify you within 72 hours of becoming aware, as required by applicable law.
9. International Data Transfers
Our servers are located in the EU and/or United States. If you are located in the European Economic Area (EEA), your data may be transferred to countries outside the EEA. When we do so, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission.
10. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we post the revised policy on this page and update the "Last updated" date at the top, which always reflects the most recent revision. We encourage you to review this page periodically. Where a change materially reduces your rights and applicable law requires us to give you advance notice, we will do so before it takes effect.
12. Contact & Complaints
For privacy questions or to exercise your rights:
Email: support@mono-sys.com
Response time: within 30 days
If you are in the EU/EEA and believe we have not handled your data correctly, you have the right to lodge a complaint with your local data protection authority.
Questions? We're here to help.
Our team responds to all privacy enquiries within 30 business days.