Intery AB
Privacy policy
How Monvio handles personal data, what we keep, for how long, and your rights under the GDPR.
Version 2026-09-11
Who is responsible
Intery AB, org. no. 559267-8717, 442 41 Kungälv, Sweden ("we") is the data controller for the personal data described in this policy. You reach us at hello@monvio.io.
When an organisation uses Monvio for its own team, that organisation decides what its members put on boards and is the controller for that content; we process it on the organisation's behalf under our Data Processing Agreement. This policy still applies to the account data we hold about you as a person.
What we collect
- Account data: name, email address, password (stored as a hash, never readable by us), profile image URL if you add one, handwriting font and cursor colour, the version of the terms you accepted and when.
- Sign in with Google: your Google account id, name, email and profile picture, received from Google when you choose that option.
- Content: boards and everything on them (notes, drawings, comments, votes, reactions, action items), templates you publish, team and organisation names, invitations you send (the invitee's email address).
- Usage data: which boards you opened and when, actions recorded in your organisation's activity log (for example "board created"), notifications sent to you.
- Billing data: your organisation's plan, invoices, discounts, invoicing name and address and VAT id entered by the owner. We do not store card numbers.
- Technical data: IP address and browser details in short-lived server logs, and the cookies described in the cookie policy.
- Support: emails you send us.
Why we use it and on what legal basis
- To provide the service you signed up for: accounts, boards, realtime collaboration, notifications, invitations (performance of a contract, GDPR art. 6(1)(b)).
- To keep the service secure and working: logs, rate limits, abuse prevention, backups (legitimate interest, art. 6(1)(f)).
- To bill organisations on a paid plan and keep accounting records (contract and legal obligation, art. 6(1)(b) and (c); Swedish bookkeeping law requires invoices to be kept for seven years).
- To understand how the product is used and improve it, using Google Analytics on our public pages and in the app, only after you agree in the cookie banner (consent, art. 6(1)(a)). You can withdraw consent at any time under "Cookie settings".
- To answer your emails (legitimate interest).
- We do not sell personal data, do not use it for advertising, and do not make automated decisions with legal effect about you.
Who sees your data
People in your organisation see what the product shows them: your name, avatar and email to the members and admins of organisations and teams you belong to, and your contributions on boards you share. Guests invited to a single board see your name and contributions on that board only. During a meeting a host can hide author names on notes ("hide identities"); the names stay in the document, so a host can show them again, and only hosts can export a board or open its history.
If you create a personal access token for an AI agent (Settings > Profile), the agent reads and changes boards under your own account with exactly your access, and every change it makes is recorded in the organisation's activity log with the token's name; you can revoke the token at any time.
We use the following companies to run the service. Each one processes data only on our instructions, under a data processing agreement, and only for the purpose listed.
| Company | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Hosting of the web application and its API | USA (servers in Frankfurt, EU) | EU-US Data Privacy Framework |
| Neon Inc. | PostgreSQL database | USA (data stored in Frankfurt, EU) | EU-US Data Privacy Framework and standard contractual clauses |
| Fly.io Inc. | Realtime collaboration server (WebSocket) | USA (servers in Amsterdam, EU) | Standard contractual clauses |
| Resend Inc. | Transactional email (verification, invitations, notifications) | USA | EU-US Data Privacy Framework |
| Google LLC | Sign in with Google (only if you use it); Google Analytics 4 (only with your consent) | USA | EU-US Data Privacy Framework |
| Atlassian Pty Ltd | Jira Cloud integration (only for organisations that connect it) | Australia / EU | Standard contractual clauses |
Transfers outside the EU
Our servers and database are located in the EU (Frankfurt and Amsterdam). Some of our providers are US companies and may access data from the US for support or operations. Those transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses, as listed above. You can ask us for a copy of the safeguards.
How long we keep it
- Account data: until you delete your account. Deleting it erases your name, email, picture and sign-in methods immediately; contributions you made to other people's boards stay attributed to "Deleted user" so their content keeps working.
- Organisation content: until the organisation or the board is deleted by its owner or admins. Board history used by the Time Machine keeps a bounded number of snapshots per board (200 by default; the operator can set it between 10 and 2,000), older ones are deleted as new ones are taken.
- Deleted data remains in encrypted database backups for up to 7 days.
- Invoices and billing records: 7 years after the end of the financial year, as Swedish bookkeeping law requires.
- Server logs: 30 days. Email delivery logs at our email provider: 30 days.
- Activity log entries in an organisation: as long as the organisation exists.
Your rights
Under the GDPR you can ask us to access, correct, delete or restrict the personal data we hold about you, object to processing based on legitimate interest, and receive the data you gave us in a machine-readable format. Consent for analytics can be withdrawn at any time in "Cookie settings".
Most of this you can do yourself: Profile settings lets you edit your details, download a copy of your personal data and delete your account; owners can export or delete their whole organisation under Organisation settings. For anything else email hello@monvio.io; we answer within one month.
If you think we handle your data unlawfully you can complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), https://www.imy.se, or to the authority in the EU country where you live.
Security
Data is encrypted in transit (TLS) and at rest at our hosting providers. Passwords are hashed. Access to production systems is limited to the people who run the service and protected by two-factor authentication. Boards are only reachable by the people the organisation or the board owner gave access to, and the realtime server re-checks that access every minute. Details of the technical measures are in our Data Processing Agreement.
Children
Monvio is a tool for work and study and is not directed at children. You must be at least 16 to create an account.
Changes
We update this policy when the product or the law changes. The date at the top tells you which version you are reading. For material changes we notify you by email or in the app before they apply.
Contact
Intery AB, org. no. 559267-8717, 442 41 Kungälv, Sweden. Email: hello@monvio.io. We have not appointed a data protection officer; privacy questions go to the same address.