Privacy Policy

Last updated: 17 August 2026

1. Company information

Monotree ApS
CVR no.: 40567720
Address: Christian IX's Gade 6, 1. th
Postcode and city: 1111 København K
Email: contact@monotree.com
Phone: +45 3111 0003

2. When are we a controller, and when are we a processor?

Monotree has two different roles, and which one applies decides who you should contact about your data.

We are the data controller for the information we collect ourselves — when you fill in a contact form, sign up for an event, write to us or visit monotree.com.

We are a data processor for all content and information our customers place in the platform about their own employees. Here the employer providing the app is the data controller and decides the purpose of the processing. If you are an employee and want access to or deletion of your data, contact your employer — we assist your employer in meeting the request.

3. What personal data do we process?

As a controller we process ordinary contact details: name, email address, phone number, company and job title, along with the content of your enquiry. When you visit the website we also process technical information such as IP address and browser type.

If you complete our contact form, we collect and store the information you provide — name, email address and optionally phone number. It is stored in our CRM system HubSpot and used to contact you with a view to booking a demo.

As a processor we handle the data the customer places in the platform in order to run features such as news, chat, handbooks, courses, shift plans, events and feedback. That is typically name, contact details, department, job title and activity in the app. The scope is set by the data processing agreement with each customer.

We do not collect special categories of personal data as part of normal operation, and the platform is not intended to hold them.

4. Purposes and legal bases

We do not sell personal data. We do use marketing tools on the website that share information about your visit with the third parties named in section 5. That only happens if you have accepted it in the cookie banner.

5. Processors, analytics and marketing

This section covers monotree.com. The sub-processors we use to deliver the platform to our customers are a separate list: each customer receives it as part of their data processing agreement and is notified of changes there. Nothing below is part of that list.

Processors. The following process data on our behalf under a data processing agreement:

Website analytics. The following tools collect statistics about the use of monotree.com and load on page view:

Marketing. The following tools load only if you accept marketing cookies in the cookie banner. They share information about your visit with the third party in question, which uses it to measure and target advertising:

Data may also be disclosed where we are legally required to do so, or where it is necessary to establish or defend a legal claim.

6. Transfers to third countries

Some of the recipients named in section 5 process data outside the EU/EEA, as marked there. Where that happens it takes place on a valid transfer basis — an adequacy decision from the European Commission, such as the EU-US Data Privacy Framework, or the EU’s standard contractual clauses with the necessary supplementary measures.

7. How long do we keep data?

Contact form enquiries are kept for up to 12 months after the last contact if no customer relationship results. If one does, the data is kept for as long as the agreement runs.

Accounting records are kept for five years from the end of the financial year they relate to, as required by the Danish Bookkeeping Act.

For data we process as a processor, what has been agreed with the customer applies. Under our standard terms the customer retains access to the system for 30 days after the subscription ends and can export data in a standard format during that period. 120 days after the subscription expires, all data is permanently deleted. See the terms and conditions.

8. Security

We have put in place technical and organisational measures providing a level of protection appropriate to the risk — including need-based access control, encryption of data in transit and at rest, logging, and ongoing testing and review of security.

Monotree holds an ISAE 3000 assurance report issued by BDO Danmark. In the event of a personal data breach we notify affected customers without undue delay so they can meet their own notification obligations.

9. Your rights

Under the GDPR you have the right:

These rights may be subject to conditions and exceptions. If your request concerns data we process for your employer, please contact the employer, see section 2.

10. Cookies

We use cookies and similar technologies on monotree.com in three categories:

Your choice is stored locally in your browser. You can change it at any time by clearing the site data in your browser, after which the cookie banner appears again.

11. Complaints

If you are unhappy with how we process your personal data we would like to hear from you first. You can also complain to the Danish Data Protection Agency, Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk.

12. Changes to this privacy policy

We update this policy when our processing of personal data changes. The version in force at any time is available on this page, stating when it was last updated.

13. Contact

Questions about this privacy policy or about our processing of personal data can be directed to support@monotree.com.