Security & GDPR
Version 1.0 · Published
Monoplan brings together schedules, employee information, working time and work-related communication. This overview describes responsibilities and security considerations without promising that incidents can never occur.
Access according to need
Customers must grant access according to responsibilities and keep memberships current. Remove access when employees leave or change duties; an employment change does not itself prove that all access has been removed.
Monoplan uses Clerk for authentication and backend controls for organisation data access. Available login and security settings depend on configuration. This page does not claim that every account has MFA enabled or that every access scenario is independently certified.
Minimise data and copies
Collect and share only necessary information. Keep diagnoses, national identification numbers, bank details and other sensitive information out of ordinary fields, chat, document uploads and AI prompts. See acceptable use.
Exports, downloads, emails and push messages can create copies outside Monoplan. Customers and users must protect these copies and consider lock-screen previews. Revoking access does not automatically erase previously downloaded copies.
Operations, support and breaches
Public Monoplan services use HTTPS. Authorised support must be limited to the specific case and necessary data. Never send passwords, API keys or full employee records in an ordinary support request.
Report suspected vulnerabilities or breaches to contact@monoplan.io, including the time, affected feature and a description without sensitive values. We will arrange an appropriate channel for necessary evidence. Handling and notification follow applicable rules and the executed agreement.
Retention, exports and erasure
Retention and deletion must follow the purpose and agreed instructions. Archiving, deactivation, deleting a definition and deleting its values are different actions. Backups, logs, devices and external recipients may hold separate copies.
Contact us about specific return or deletion requests. This overview does not promise automatic erasure of all copies by a particular date or a particular recovery time. Such requirements need to be specified and verified in the relevant agreement and operations.
Responsibilities
The customer is generally controller for employee processing. CommonStudios is processor for customer data and has its own duties; customer responsibility does not exempt CommonStudios. Our own purposes, such as contact and billing, are described in the privacy policy.
We make no ISO, SOC or general GDPR certification claim here. See the data processing agreement and supplier overview for the agreement's scope.
