Skip to content
MonthDocs

Legal information

Operator

Data processing terms

These terms apply when a firm ("Customer") uses MonthDocs to process personal data of its clients and staff ("Customer Personal Data"). The Customer is the controller; is the processor. They form part of the Terms of Service.

  1. Subject and duration. Processing is limited to providing the Service: storing, displaying and transmitting documents and contact data, sending the e-mails the Customer configures, and securing the Service, for as long as the Customer's account exists and until deletion as set out below.
  2. Categories. Data subjects: the Customer's clients and their contacts, and the Customer's staff. Data: names, e-mail addresses, phone numbers, language and time-zone preferences, uploaded documents (which may contain financial and payroll information), and related metadata and audit records.
  3. Instructions. We process Customer Personal Data only on the Customer's documented instructions, given through the Service and these terms, unless the law requires otherwise; in that case we inform the Customer unless the law forbids it.
  4. Confidentiality. Everyone authorised to process Customer Personal Data is bound to confidentiality. Our support staff do not open client documents.
  5. Security. We maintain appropriate technical and organisational measures, including strict separation between customers, private encrypted-at-rest document storage, access only through authorised requests, single-use expiring sign-in links, two-factor authentication for administrators, audit logging and regular backups.
  6. Sub-processors. The Customer authorises the sub-processors listed below. We impose equivalent data protection obligations on them and inform the Customer of intended changes at least 30 days in advance by e-mail and on this page; the Customer may object and close the account.
    ProviderPurposeLocation
    Hostinger International Ltd.Application hosting and database
    ADM.TOOLS (Ukraine.com.ua)Delivery of transactional e-mailsUkraine
    Cloudflare, Inc.Content delivery, DDoS protection and encryption in transitGlobal network (USA)
  7. Assistance. Taking into account the nature of the processing, we help the Customer respond to data subject requests (the Customer can view, export and delete data in the Service) and with security, breach notification and impact assessments.
  8. Personal data breaches. We notify the Customer without undue delay, and where possible within 48 hours, after becoming aware of a breach affecting Customer Personal Data, with the information reasonably available to us.
  9. Deletion and return. The Customer can export its data at any time. After the account is closed, Customer Personal Data is deleted within 90 days, unless the law requires us to keep it.
  10. Audits. We make available the information necessary to demonstrate compliance with these terms and allow for reasonable audits, on at least 30 days' notice, at the Customer's cost, and without access to other customers' data.

Security contact

Please report security issues to [email protected]. We do not take legal action against good-faith reports that avoid privacy violations and service disruption.

Last updated: September 29, 2026