Privacy Policy
Last updated: 22 January 2026
1. Introduction
Monolog Technologies Ltd (“we”, “us”, or “our”) operates Monolog, a compliance, accounting, and governance platform for businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our services.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Data Controller
The data controller responsible for your personal data is:
Monolog Technologies LtdLimassol, Cyprus
Email: privacy@monolog.one
3. Personal Data We Collect
We collect the following categories of personal data:
3.1 Account Information
- Email address
- Name
- Password (encrypted)
- Profile information
3.2 Organization Data
- Company name and registration details
- Tax identification numbers
- Director and shareholder information
- Ultimate Beneficial Owner (UBO) details
- Contact and address information
3.3 Financial Data
- Invoices and expense records
- Bank account information (via PSD2 banking connections)
- Transaction history
- VAT and tax filing data
3.4 Technical Data
- IP address
- Browser type and version
- Device information
- Usage data and analytics
4. How We Use Your Data
We process your personal data for the following purposes:
4.1 Service Delivery (Contract Performance)
- Providing our compliance, accounting, and governance services
- Managing your account and organization
- Processing financial transactions and generating reports
- Sending service-related notifications
4.2 Legal Obligations
- Tax compliance and reporting
- Anti-money laundering (AML) requirements
- Regulatory compliance
4.3 Legitimate Interests
- Improving our services and user experience
- Security monitoring and fraud prevention
- Analytics and service optimization
4.4 Consent
- Marketing communications (where applicable)
- Optional analytics and cookies
5. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR:
- Contract: Processing necessary to perform our services to you (Article 6(1)(b))
- Legal obligation: Processing required by law, such as tax and AML regulations (Article 6(1)(c))
- Legitimate interests: Processing for our legitimate business interests, such as security and service improvement (Article 6(1)(f))
- Consent: Where you have given explicit consent for specific processing activities (Article 6(1)(a))
6. Data Sharing and Recipients
We may share your personal data with:
- Service providers: Cloud hosting (Supabase), payment processing (Stripe), email services (Resend), error monitoring (Sentry)
- Banking partners: For PSD2-compliant banking integrations (e.g. Bank of Cyprus)
- Legal authorities: When required by law or to protect our rights
- Professional advisors: Lawyers, accountants, and auditors as needed
We do not sell your personal data to third parties.
7. International Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data Processing Agreements with all sub-processors
8. Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements:
- Account data: Retained while your account is active and for 30 days after a deletion request
- Financial records: 7 years (as required by Cyprus tax law)
- Compliance documents: As required by applicable regulations
- Usage logs: 90 days
9. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access (Article 15): Request a copy of your personal data
- Right to Rectification (Article 16): Correct inaccurate or incomplete data
- Right to Erasure (Article 17): Request deletion of your personal data
- Right to Restriction (Article 18): Limit how we process your data
- Right to Data Portability (Article 20): Receive your data in a machine-readable format
- Right to Object (Article 21): Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where consent is the legal basis
To exercise any of these rights, please contact us at privacy@monolog.one or use the data management features in your account settings.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS) and at rest
- Row-Level Security (RLS) policies for data isolation
- Regular security assessments and monitoring
- Access controls and authentication mechanisms
- Encrypted storage of sensitive credentials (OAuth tokens)
11. Cookies
We use cookies and similar technologies to provide and improve our services, including analytics (Microsoft Clarity, Google Tag Manager). You can manage cookie preferences through your browser settings.
12. Children’s Privacy
Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the “Last updated” date. We encourage you to review this Privacy Policy periodically.
14. Complaints
If you have concerns about how we handle your personal data, please contact us first. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
For Cyprus, the supervisory authority is the Commissioner for Personal Data Protection: www.dataprotection.gov.cy.
15. Contact Us
For any questions about this Privacy Policy or our data practices, please contact us:
Monolog Technologies LtdLimassol, Cyprus
Email: privacy@monolog.one
See also our Terms of Service.