Controller and scope
MonTech Group, UAB is responsible for personal data processed through the Mon app, website, customer support, compliance workflows, and MonCore-powered operational systems, except where another regulated provider acts as an independent controller for its own legal obligations. This policy explains processing under GDPR - Regulation (EU) 2016/679 and other applicable data protection law.
Data we process
- Identity and contact details, including name, date of birth, address, nationality, phone number, email address, and identity document information.
- Verification data, including identity-check results, selfie or liveness evidence, applicant references, risk outcomes, and recovery recheck evidence.
- Account and transaction data, including account identifiers, IBAN information, card identifiers, balances, transactions, beneficiaries, device sessions, and support evidence.
- Security data, including device identifiers, IP addresses, login records, failed authentication attempts, fraud signals, session history, and audit trails.
- Support and complaint data, including messages, uploaded documents, notes, status updates, and resolution history.
- Website data, including essential cookie data and technical logs.
Why we process data
We process personal data to onboard customers, verify identity, provide accounts and card services, authenticate access, process transactions, prevent fraud, comply with AML and sanctions obligations, support account recovery, respond to support cases, investigate complaints, maintain records, improve security, and meet legal, regulatory, issuer, card scheme, tax, accounting, and audit obligations.
Legal bases
Depending on the processing activity, we rely on contract performance, legal obligation, legitimate interests, consent where required, and protection of vital or important interests in security or fraud contexts. Legitimate interests include fraud prevention, system security, support quality, service integrity, and auditability.
Sharing
We may share data with regulated issuer and payment-service providers, identity verification providers, card scheme and payment networks, banks, open-banking providers, communications providers, cloud and infrastructure providers, analytics and security providers, legal and professional advisers, law enforcement, regulators, auditors, and other parties where required by law or necessary to provide Mon.
International transfers
Where data is processed outside the EEA, we use appropriate safeguards such as adequacy decisions, standard contractual clauses, contractual protections, access controls, encryption, and vendor due diligence where required.
Retention
We retain data for as long as necessary to provide the service and meet legal, regulatory, AML, tax, accounting, dispute, audit, fraud prevention, and security obligations. Some records may be retained after account closure where required by law or legitimate compliance needs.
Your rights
You may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, withdraw consent, and lodge a complaint with a supervisory authority. Some requests may be limited where we must retain records for legal, AML, fraud prevention, audit, or dispute purposes. Requests can be submitted through in-app support.