M
Monfimo

Privacy Policy

Last updated: March 30, 2026

1. Data Controller

The controller of your personal data is Przemek Zakoscielny, conducting business at Kanadyjska 28, 32-087 Zielonki, Poland (hereinafter referred to as "Monfimo", "we", "us", or "our").

For any privacy-related inquiries, please contact us at: support@monfimo.com

2. Data We Collect

We collect and process the following categories of personal data:

3. Purposes and Legal Bases for Processing

3.1 Service Delivery (Article 6(1)(b) GDPR)

We process your account data, financial documents, and usage data to provide and maintain the Monfimo service — including account registration, AI-powered data extraction from your uploaded documents, financial reconciliation, and dashboard functionality. Data is retained for the duration of your account.

3.2 Payment Processing (Article 6(1)(b) GDPR)

We process billing data to handle subscriptions and payments for paid plans. Payment card details are processed directly by Stripe and are not stored on our servers.

3.3 Tax and Legal Obligations (Article 6(1)(c) GDPR)

We process billing and account data for invoicing, accounting records, and compliance with applicable tax regulations. Data is retained for the period required by law.

3.4 Legal Claims (Article 6(1)(f) GDPR — Legitimate Interest)

We may process your data for the establishment, exercise, or defence of legal claims. Data is retained for the applicable statutory limitation period.

3.5 Website Analytics (Article 6(1)(f) GDPR — Legitimate Interest)

We use Google Analytics to understand how visitors interact with our website — including visitor numbers, pages viewed, time spent, and traffic sources. This helps us improve the service. Data is retained until the purpose is achieved or you object to processing.

3.6 Customer Communication (Article 6(1)(f) GDPR — Legitimate Interest)

We process your contact data to respond to inquiries and provide customer support via email. Data is retained for the applicable limitation period.

4. AI Document Processing

When you upload documents to Monfimo, we use third-party AI services — specifically Google Gemini and Anthropic Claude APIs — to extract structured data (such as contractor names, invoice numbers, amounts, tax, and currency) from your financial documents.

Document content is sent to these API providers solely for the purpose of data extraction. We rely on their data processing agreements and privacy commitments. Neither Google nor Anthropic use your data to train their public models when accessed through their APIs.

5. Data Recipients

Your personal data may be shared with the following categories of recipients:

6. International Data Transfers

Your data is primarily stored on servers located within the European Economic Area (Hostinger VPS). However, some of our third-party service providers — including Google, Anthropic, and Stripe — may process data on servers located outside the EEA, including in the United States.

When data is transferred outside the EEA, we ensure an appropriate level of protection through standard contractual clauses adopted by the European Commission or other legally recognised safeguards under GDPR Article 46.

7. Your Rights

Under the GDPR (Articles 15–21), you have the following rights regarding your personal data:

We will respond to your request within one month. This period may be extended by up to two additional months for complex or numerous requests.

To exercise any of these rights, contact us at: support@monfimo.com

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes described in this policy:

9. Cookies and Tracking Technologies

Our website uses cookies — small text files stored on your device — to ensure proper functionality and to analyse website usage.

You can manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the website.

10. Server Logs

Our hosting provider automatically collects server log data, including your IP address, timestamp, browser and operating system information, and pages requested. This data is used solely for server administration and security purposes and is not linked to your identity.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. Your uploaded financial documents are stored on a private, self-hosted VPS server. We do not share your data with third parties beyond those listed in this policy.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated "Last updated" date. For material changes, we will notify you via email if you have a Monfimo account.

13. Contact

If you have any questions about this Privacy Policy or our data processing practices, please contact us at:
support@monfimo.com