Ir al contenido
MonthDocs

Política de privacidad

Por ahora, este documento solo está disponible en inglés.

This Privacy Policy explains how ("we", "us") processes personal data when you visit our website or use MonthDocs (the "Service"), a web application that helps accounting and bookkeeping firms collect documents from their clients. It describes what the Service actually does today.

1. Who is responsible

  • Website visitors and firm accounts (owners and staff of accounting firms): we are the controller.
  • Data about a firm's clients and the documents they upload: the accounting firm decides what is collected and why and is the controller. We process this data only on the firm's instructions, as its processor, under a data processing agreement.

Contact: , , . E-mail: [email protected].

2. Data we process

2.1 Website visitors

  • Always (technically necessary): the pages you request and technical data your browser sends (IP address, browser type, language) are processed to deliver and protect the website. Our web server and security logs may contain IP addresses.
  • Only if you choose "Accept analytics": we use our own, first-party analytics. It records the pages you view, the time spent on each page, how far you scroll, which links and buttons you click, the website that referred you (domain only), campaign parameters in the link (utm_source, utm_medium, utm_campaign), your approximate country, and your device type, browser and operating system. It uses a random visitor ID and a random visit ID stored in your browser. We do not store your IP address in analytics, we do not combine analytics with your account, and we do not share analytics data with third parties.

2.2 Firm accounts

  • Name, e-mail address, password (stored only as a one-way hash), language and time-zone preference, two-factor authentication settings (the secret is encrypted, recovery codes are hashed).
  • Firm details: firm name, settings, trial and subscription status.
  • Audit log of important actions (sign-ins, uploads, downloads, acceptances, rejections, role changes), including the IP address of the request.

2.3 Clients of accounting firms (processed on behalf of the firm)

  • Contact data entered by the firm: name, company name, e-mail address, phone number, language and time zone.
  • Documents you upload and their metadata (original file name, size, type, upload time, review status and any rejection reason written by the firm).
  • Sign-in events and the IP address of uploads and sign-ins (audit log).

3. Purposes and legal bases

  • Providing the Service to firms and their clients (performance of a contract).
  • Security: preventing abuse, rate limiting, audit logs (legitimate interests; legal obligations where applicable).
  • Transactional e-mails such as sign-in links and invitations (performance of a contract).
  • Website analytics: only with your consent, which you can withdraw at any time.
  • Legal obligations, for example keeping records of our own invoices.

We do not sell personal data. We do not use client documents for advertising or to train machine-learning models. We do not use advertising or third-party tracking cookies.

4. Cookies and browser storage

NamePurposeDurationType
monthdocs-sessionKeeps you signed in and remembers your language during a visit.120 minutes of inactivityNecessary
XSRF-TOKENProtects forms against cross-site request forgery.Same as the sessionNecessary
remember_web_…Keeps a firm user signed in, only if "Remember me" was ticked.Up to 400 daysNecessary
monthdocs_consentStores your cookie choice.12 monthsNecessary
monthdocs_vid (local storage)Random visitor ID for analytics.Until you clear it or withdraw consentAnalytics (consent)
monthdocs_sid (session storage)Random visit ID for analytics.Until the browser tab is closedAnalytics (consent)

You can change your choice at any time with the link at the bottom of every page. Choosing "Necessary only" stops analytics and removes the analytics IDs from your browser.

5. Storage, security and retention

  • Documents are kept in private storage and are only available through authenticated, authorised requests. Accounting firms are strictly separated from each other. Sign-in links are single-use and expire after 30 minutes.
  • Website analytics are deleted automatically after 13 months.
  • Audit log entries are deleted automatically after 365 days.
  • Firm and client data, including documents, are kept while the firm's account exists and are handled according to the firm's instructions. Firms can export their records at any time.
  • When a firm closes its account, its data, including all documents, is deleted within 90 days, unless we are legally required to keep specific records longer. Deleted data disappears from our backups within a further 35 days.
  • Records of our own invoices are kept as long as tax and accounting law requires.

6. Service providers (sub-processors) and international transfers

We use the following service providers, who process personal data only on our instructions and under written data processing agreements:

ProviderPurposeLocation
Hostinger International Ltd.Application hosting and database
ADM.TOOLS (Ukraine.com.ua)Delivery of transactional e-mailsUkraine
Cloudflare, Inc.Content delivery, DDoS protection and encryption in transitGlobal network (USA)

If personal data is transferred to a country that does not offer an adequate level of protection under the law that applies to you, we rely on appropriate safeguards such as standard contractual clauses. You can ask us for a copy of the relevant safeguards. We will announce changes to this list in advance on this page.

7. Your rights

Depending on the law that applies to you, you may have the right to access, correct or delete your personal data, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting earlier processing. If you are a client of an accounting firm, please contact that firm first - it controls your documents. You can always write to us at [email protected]. You may also have the right to lodge a complaint with a data protection supervisory authority.

8. Children

The Service is intended for businesses and is not directed at children.

9. Changes

We will update this policy when the Service changes and show the date of the latest version below.

Última actualización: 29 de septiembre de 2026