GDPR Compliance

Last updated: February 1, 2026

Our Commitment to GDPR

Monytar is committed to protecting the privacy and rights of individuals in the European Economic Area (EEA). We comply with the General Data Protection Regulation (GDPR) and provide tools to help your organization meet its own GDPR obligations.

Data Processing

Monytar acts as a data processor on behalf of your organization (the data controller). We process personal data only as instructed by your organization and in accordance with our Data Processing Agreement (DPA).

Your Rights Under GDPR

  • Right of Access - Request a copy of all personal data we hold about you
  • Right to Rectification - Correct any inaccurate or incomplete personal data
  • Right to Erasure - Request deletion of your personal data ("right to be forgotten")
  • Right to Data Portability - Receive your data in a structured, machine-readable format
  • Right to Object - Object to processing of your personal data in certain circumstances
  • Right to Restrict Processing - Request limitation of processing of your personal data

Data Transfers

When transferring personal data outside the EEA, we use approved transfer mechanisms including Standard Contractual Clauses (SCCs) as approved by the European Commission, ensuring your data receives adequate protection regardless of where it is processed.

Data Protection Officer

Our designated Data Protection Officer can be reached at dpo@monytar.com for any GDPR-related inquiries, data subject access requests, or concerns about how we handle personal data.

Sub-processors

We maintain an up-to-date list of sub-processors who may access personal data in the course of providing our services. We ensure all sub-processors are bound by data processing agreements that meet GDPR requirements. Contact us for the current list.

Breach Notification

In the event of a personal data breach, we will notify affected organizations within 72 hours of becoming aware of the breach, in compliance with Article 33 of the GDPR, including details of the nature of the breach and recommended mitigation measures.