Intery AB

Data processing agreement

For organisations: how Intery AB processes personal data on your behalf, as required by GDPR article 28.

Version 2026-09-11

1. Parties and scope

This agreement is between the organisation that uses Monvio (the "Customer", controller) and Intery AB, org. no. 559267-8717, 442 41 Kungälv, Sweden (the "Provider", processor). It forms part of the terms of service and applies whenever the Provider processes personal data contained in the Customer's boards, teams and member lists. It is accepted by the organisation's owner on the Customer's behalf when the organisation is created or when this version is published; a signed copy is available on request.

2. What is processed

  • Subject matter: hosting and operation of a collaborative whiteboard service.
  • Duration: for as long as the Customer has an organisation, plus the backup period of up to 7 days after deletion.
  • Nature and purpose: storage, display, synchronisation between participants, backup, export, notification emails, and the integrations the Customer switches on.
  • Data subjects: the Customer's employees, contractors and guests, and anyone named on the Customer's boards.
  • Categories of data: names, email addresses, profile pictures, board content of any kind the Customer chooses to enter, usage records. The service is not intended for special categories of data (health, political opinions and similar); the Customer must not enter such data.

3. The Provider's obligations

  • Process personal data only on the Customer's documented instructions, which are the terms, this agreement and the use of the product's features; inform the Customer if an instruction appears to break the law.
  • Ensure that people with access are bound by confidentiality.
  • Apply the security measures in section 5.
  • Engage sub-processors only as set out in section 4.
  • Help the Customer respond to data subject requests, through the product's export and deletion features and by email.
  • Help the Customer with security, breach notification and impact assessments as far as the Provider has the information.
  • Notify the Customer without undue delay, and at the latest within 48 hours of becoming aware, of a personal data breach affecting the Customer's data.
  • Delete or return all personal data at the end of the service, through the Customer's export and deletion features, and delete remaining copies when backups expire, unless the law requires keeping them.
  • Make available the information needed to show compliance and allow audits, at most once a year on 30 days' notice, at the Customer's cost, in a way that does not endanger other customers' data.

4. Sub-processors

The Customer authorises the sub-processors listed below. The Provider will announce additions or replacements at least 30 days in advance by email to the organisation's owner; the Customer may object on reasonable grounds, in which case either party may end the service for that organisation without penalty.

Sub-processors
CompanyPurposeLocationTransfer safeguard
Vercel Inc.Hosting of the web application and its APIUSA (servers in Frankfurt, EU)EU-US Data Privacy Framework
Neon Inc.PostgreSQL databaseUSA (data stored in Frankfurt, EU)EU-US Data Privacy Framework and standard contractual clauses
Fly.io Inc.Realtime collaboration server (WebSocket)USA (servers in Amsterdam, EU)Standard contractual clauses
Resend Inc.Transactional email (verification, invitations, notifications)USAEU-US Data Privacy Framework
Google LLCSign in with Google (only if you use it); Google Analytics 4 (only with your consent)USAEU-US Data Privacy Framework
Atlassian Pty LtdJira Cloud integration (only for organisations that connect it)Australia / EUStandard contractual clauses

5. Security measures

  • Encryption in transit (TLS 1.2 or higher) and at rest at the hosting providers.
  • Passwords hashed with a modern algorithm; sessions stored server-side and revocable; email verification for new accounts; rate limits on authentication and API endpoints.
  • Authorisation on every request: organisation and team roles, board access levels, re-checked on the realtime server every minute; read-only access for viewers.
  • Content Security Policy with per-request nonces, strict security headers, upload type sniffing and size limits.
  • Production access limited to named people with two-factor authentication; secrets stored in the hosting providers' secret stores, never in the code repository.
  • Encrypted backups by the database provider with point-in-time recovery; deploys are automated from reviewed code.
  • Audit trails: organisation activity log, billing event log, product setting changes.

6. Transfers

Data is stored in the EU. Where a sub-processor may access data from outside the EU, the transfer is covered by the EU-US Data Privacy Framework or the standard contractual clauses, as listed in section 4.

7. Liability and law

The liability provisions and governing law of the terms of service apply to this agreement.

8. Notices

Notices from the Customer go to hello@monvio.io. Notices from the Provider, including sub-processor changes and breach notifications, go to the email address of the organisation's owner.