SandPlane Privacy Statement


Effective and last updated: July 22, 2026 · Version 2026-07-22

This Statement explains how Monoceros s. r. o. ("Monoceros", "we", "us") handles personal data in connection with SandPlane. SandPlane is the product name; Monoceros is the legal provider and the entity responsible for the processing described here.

1. Our roles

Monoceros is a controller for website visitors, account contacts, billing administration, service security, support, optional analytics, and our own legal obligations. For personal data contained in financial records, invoices, email imports, integration data, and other content submitted by a business customer, the customer is normally the controller and Monoceros is its processor. That processing is governed by our Data Processing Addendum.

2. Data we process and where it comes from

  • Account and organisation data: name, work email, organisation, role, locale, account and tenant identifiers, password hash, authentication events, preferences, and authorised-user information.
  • Customer content: transactions, accounts, invoices, bills, statements, budgets, forecasts, counterparties, customer and supplier details, employee or stakeholder information, attachments, imported emails, audit records, and data supplied through enabled integrations.
  • Integration and credential data: provider identifiers, configuration, access tokens, API keys or encrypted credentials, sync status, webhook data, and imported records from services Customer chooses to connect.
  • Billing data: plan, subscription and transaction identifiers, billing status, country, currency, and limited payment metadata received from Paddle. Paddle, as merchant of record, receives and processes payment-card and billing details; Monoceros does not store full card details.
  • Technical and security data: IP address, device and browser information, timestamps, request and application logs, authentication and fraud signals, diagnostic events, and security incidents.
  • Support and feedback: messages, contact details, feedback, and information included in a support request.
  • Optional analytics: page and feature usage, coarse device information, event names, and limited event properties. We do not intentionally send financial record contents, filenames, transaction descriptions, amounts, bank details, or credentials to analytics providers.

We obtain data from you and your authorised users, your organisation, devices and browsers, Paddle, and third-party services that Customer chooses to connect. Customer is responsible for giving required notices to people whose data it submits.

3. Purposes and legal bases when we are controller

  • Contract and pre-contract steps: create and administer accounts, provide the Service, support users, manage plans, and communicate operational messages.
  • Legitimate interests: secure and troubleshoot the Service, prevent abuse, maintain audit trails, improve reliability, understand aggregate service performance, and establish or defend legal claims. We balance these interests against affected individuals' rights.
  • Consent: load optional PostHog and Vercel analytics. Consent can be rejected or withdrawn at any time through the persistent Cookie settings control without affecting core service access.
  • Legal obligations: retain tax and accounting records, respond to lawful requests, and meet security, corporate, and regulatory duties.

When we act as processor, Customer determines the legal basis and instructs the processing. Enabling an integration is a Customer instruction; it is not treated as GDPR consent from every person represented in the imported data.

Account identity, organisation, authentication, and billing-administration fields marked as required are necessary to enter into or perform the Service contract. Without them, we cannot create or secure the account, provision the selected region, or administer a paid subscription. Optional profile fields, analytics consent, and Customer-selected integrations are not required to create an account.

4. How we use personal data

  • provide financial operations, reporting, reconciliation, forecasting, and collaboration features;
  • authenticate users, enforce tenant isolation, maintain audit records, and protect the Service;
  • import, normalise, calculate, and present Customer-directed financial and operational data;
  • operate integrations and customer-selected artificial-intelligence providers;
  • administer subscriptions, billing, service communications, support, and incident response; and
  • improve performance and usability using optional, consent-based analytics.

SandPlane does not make solely automated decisions that produce legal or similarly significant effects about individuals. Suggested classifications, forecasts, anomaly flags, and generated outputs require Customer review. We do not sell personal data.

5. Providers and disclosures

We disclose data only as needed to service providers, Customer-authorised integrations, professional advisers, authorities where legally required, or a successor in a corporate transaction subject to appropriate safeguards. Our current infrastructure and service providers are maintained on the Subprocessors and Service Providers page.

Key providers include Amazon Web Services for regional application, database, object storage and email infrastructure; Vercel for frontend delivery; Paddle for merchant-of-record billing; PostHog and Vercel for optional analytics; Google reCAPTCHA for registration security; Featurebase for user-requested in-product support and feedback; and Sentry when enabled for privacy-filtered error monitoring. If Customer enables OpenAI, Google Gemini, or another supported AI provider, selected content is sent to that provider at Customer's direction.

6. Data location and international transfers

Customer selects an EU or US application region at registration. Regional Customer Data is hosted in AWS eu-central-1 (Frankfurt, Germany) or us-east-1 (Northern Virginia, USA). Frontend delivery, security, billing, support, and Customer-enabled integrations may process limited data outside that region.

Where GDPR-protected data is transferred outside the EEA to a country without an adequacy decision, we use an applicable safeguard such as the European Commission's Standard Contractual Clauses and supplementary measures where appropriate. Some providers may also rely on the EU-US Data Privacy Framework. Contact us for information about the safeguard relevant to a provider.

7. Retention

  • Active accounts and Customer Data: for the subscription term.
  • Post-termination export window: up to 30 days, unless an order form states otherwise; production copies are then scheduled for deletion.
  • Backups: removed through normal backup rotation, generally within 90 days, and isolated from ordinary use meanwhile.
  • Security and application logs: generally 14 to 90 days, longer only for an active incident or legal claim.
  • Billing, tax, and corporate records: for the period required by applicable Slovak law, normally up to 10 years.
  • Support and legal correspondence: normally three years after closure, longer where needed for a continuing relationship or claim.
  • Consent choice: 180 days, after which we ask again; analytics providers retain data according to our configured retention and their contracts.

Legal holds, fraud prevention, or a Customer's documented instruction may change these periods.

8. Security

We use access controls, tenant-level database protections, encryption in transit and at rest, encrypted storage for supported credentials, logging, backups, and incident procedures appropriate to the risk. No system is completely secure. Our Security page describes current controls without replacing the DPA.

9. Your rights

Depending on applicable law, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, withdraw consent, and complain to a supervisory authority. Consent withdrawal does not affect earlier lawful processing. Where we rely on legitimate interests, you may object based on your situation. We do not use personal data for direct marketing after an applicable objection.

Email privacy@sandplane.com. We respond without undue delay and normally within one month. Where permitted, we may extend by up to two further months and will explain the extension. We may verify identity and authority. For Customer Data processed on behalf of your organisation, contact that organisation first; we will assist it under the DPA.

You may complain to the Office for Personal Data Protection of the Slovak Republic or the authority where you live or work. UK residents may contact the ICO. Applicable US state rights are described in our US Privacy Notice.

10. Children

SandPlane is a B2B service and is not directed to people under 18. We do not knowingly create accounts for children.

11. Changes

We may update this Statement to reflect legal, provider, or product changes. We will update the date and give reasonable notice of material changes through the Service or account email.

12. Controller contact

Monoceros s. r. o. — provider of SandPlane
Doležalova 3424/15C, 821 04 Bratislava - mestská časť Ružinov, Slovakia
Company ID (IČO): 54 540 917 · VAT ID: SK2121723186
Privacy contact: privacy@sandplane.com