Privacy policy
Version 1.0 · Published
This policy covers CommonStudios' processing of personal data for its own purposes in connection with Monoplan. It concerns visitors, contacts, customers and users when we administer our own customer relationship, support and security.
Controller and contact
CommonStudios, CVR no. 39125307, Denmark, is controller for these purposes. Contact contact@monoplan.io about privacy, rights or our business details.
Your employer is generally controller for employee data in its Monoplan workspace. We process that data under customer instructions. See employee information and the data processing agreement.
Information, purposes and legal grounds
- Enquiries, demos and waitlist: name, work email, telephone, business, registration number and information you submit. We use it to respond and follow up. The basis is our legitimate interest in relevant business dialogue (GDPR Article 6(1)(f)), or steps before a contract where you are personally the contracting party (Article 6(1)(b)). Marketing consent is separate and can be withdrawn.
- Customer and account administration: identity, work contact, business relationship, access and agreement details. We administer the service under a contract with an individual contracting party (Article 6(1)(b)) or our legitimate interest in managing the business customer's agreement and contacts (Article 6(1)(f)).
- Payment and accounting: billing details, subscription, transaction references and payment status. Grounds are the contract where you are a contracting party and statutory accounting duties (Article 6(1)(b) and (c), according to purpose). The payment provider handles card details.
- Operations, security and support: contact, case content and necessary technical details, such as time, IP address, browser and error or access information. Our own operational and security purposes rely on the legitimate interest in protecting and maintaining the service (Article 6(1)(f)). Support involving customer employee data instead follows customer instructions.
- Optional analytics and ad measurement: technical usage and referral information to measure traffic and outcomes. The basis is consent (Article 6(1)(a)) where optional measurement is used. See analytics and cookies below.
Information comes from you, your organisation's administrator, payment and authentication providers, and public business registers when registration lookups are used. Do not submit employee registers or sensitive information in website forms. Necessary contact and agreement information may be required to respond or provide the service; optional measurement is not required.
Recipients and transfers
Authorised CommonStudios personnel and relevant hosting, authentication, database, payment and email providers may receive information for these purposes. Analytics and advertising recipients depend on your choices. We do not sell personal data.
The supplier overview describes services and matters still requiring account-specific reconciliation. Recipients and support may be outside the EU/EEA. A particular transfer mechanism or EU-only processing must not be assumed from a supplier's name. Contact us about the specific processing and relevant safeguards.
Retention
Retention follows purpose. Enquiries and sales dialogue are assessed according to whether dialogue remains active and information is needed for follow-up. Account details follow the customer relationship and necessary closure; support data follows the case and documentation needs. Security records are assessed according to troubleshooting, misuse and incidents.
Accounting records are generally retained for five years after the end of the relevant financial year. Necessary information may be retained longer for a specific legal obligation or legal claim. A minimal opt-out record may be kept to respect your wish not to be contacted.
We have not yet documented a common automatic deletion deadline across every system and supplier copy. Contact us about the specific period or an erasure request. Backups, exports and information already sent need separate assessment; this policy does not promise that they are erased at the same time as an account.
Analytics and cookies
You can separately allow ChatGPT ad measurement in Cookie settings. With this choice, we keep an ad reference and a random attribution token for up to 30 days. When you create a business trial, we send the ad reference, timestamp and a random event identifier to OpenAI to measure the ad's result. This measurement contains no email or employee data, and we opt the event out of future personalization. Cookie settings lets you stop future delivery; events already sent are not automatically withdrawn.
If you actively choose “Allow”, monoplan loads Google Analytics 4 to understand traffic, popular landing pages and conversions to the waitlist. Google Analytics and our own event measurement are not loaded if you select “Necessary only”.
With analytics consent, we measure page views, CTA clicks, form views, form starts, submission attempts and validation errors. We do not send names, email addresses, business names, CVR numbers, free text, session IDs or URL parameters to Google Analytics. Google Analytics may set cookies such as _ga to distinguish between visits and sessions. These cookies can generally be stored for up to two years.
You can change or withdraw your consent at any time via “Cookie settings” under Legal. When you withdraw consent, we stop Google Analytics and try to remove Analytics cookies from the monoplan domain.
See the separate cookie policy.
Your rights
You may request access, correction, erasure and restriction, and object to processing based on legitimate interests. Data portability applies where its conditions are met. Consent can be withdrawn without affecting the lawfulness of earlier processing. Objections to direct marketing are respected.
Write to the contact address above. We may request necessary information to verify your identity. We normally respond within one month; where the rules permit an extension, we explain why. Statutory retention and others' rights may limit rights. You may complain to the Danish Data Protection Agency or your competent supervisory authority.
This policy does not authorise automated decisions with significant effects on employees. Employers must describe any such processing in their own notice.
Updates
The version and publication date appear above. We update this information when processing changes and provide relevant separate notice of material changes. An update does not itself constitute new consent.
