Data processing agreement
Version 1.0 · Published
When CommonStudios processes employee data on a customer's behalf in Monoplan, the customer is generally the controller and CommonStudios the processor. A public information page is not an executed data processing agreement.
Enter into or obtain your agreement
Email contact@monoplan.io with your business name and registration number to obtain the agreement and annexes applicable to your use. Do not include employee data or sensitive information in the initial request. If you already use Monoplan and are unsure about your agreement, contact us to reconcile it.
The agreement must identify the parties, authorised representative, document version, effective date and customer instructions. Customer-specific annexes and signed agreements are not published on this website. A trial, login or payment does not itself demonstrate that a DPA has been executed.
Scope of the agreement
The purpose, duration and nature of processing must relate to features the customer actually uses. These may include employee administration, schedules, hours, absence, messages, documents, payroll data and agreed support.
Annexes must specify categories of individuals and data, access, safeguards, subprocessors, processing locations, any international transfers, and deletion or return on termination. GPS, sickness, national identification numbers, bank details and AI need specific scope; general wording does not permit every data category.
Instructions and assistance
CommonStudios must process data under documented lawful instructions and ensure confidentiality for people with access. The agreement must govern security, subprocessors, assistance with individual rights, breaches, impact assessments, audits and evidence. Instructions we consider inconsistent with data protection law must be raised with the customer.
Security, incidents and termination
The agreement must specify technical and organisational measures. Following a personal-data breach, CommonStudios must notify the customer without undue delay and assist with information needed to meet the customer's obligations.
Handling of active data, files, exports, backups and legally required preservation must be specified on termination. A desired deletion deadline is not evidence that every system and supplier copy has already been erased.
Framework and related information
GDPR Article 28 sets the requirements. The Danish Data Protection Agency's standard contractual clauses may be used with properly completed annexes. This page is not presented as those standard clauses or as legal approval.
See the supplier overview, security overview and employee information.
