Monoy

Privacy Policy

Last updated August 23, 2026

Who controls this data

Ghostudio Limited, registered in Cyprus, is the data controller for practitioner account data, and acts as data processor on behalf of practitioners for patient data entered into Monoy.

What data we collect

Practitioner data: name, specialty, phone number, email (collected at signup for billing and contact, not used for login), and subscription and billing details.

Patient data: name, phone number, date of birth, intake form responses, appointment history, visit notes, instructions received, documents uploaded, and message history, all scoped to the practitioner who added them, never shared across practices.

Legal basis for processing

Patient data includes special category health data under GDPR Article 9. Processing this data relies on explicit consent from the patient, captured and timestamped at booking or intake.

Where data is hosted

Data is hosted with the following providers:

  • Database, authentication, and file storage: Supabase, Frankfurt, Germany (eu-central-1). Scheduling and appointment data lives here natively, no separate scheduling infrastructure or vendor.
  • AI processing: Anthropic Claude API. This processing is covered by Anthropic's Data Processing Addendum, incorporated into Anthropic's Commercial Terms of Service and including Standard Contractual Clauses for the EU-to-US transfer. Data is processed on Anthropic's US infrastructure; Anthropic does not currently offer EU data residency for direct API access, which Monoy is tracking as a longer-term infrastructure question rather than a live compliance gap.
  • Messaging: Twilio, for SMS and, from V2, WhatsApp
  • Billing: Stripe

Data Processing Agreements are in place with Supabase and Stripe. Twilio's Data Processing Addendum, incorporated into Twilio's Terms of Service and including the EU Standard Contractual Clauses by default, applies to messaging processing (available at twilio.com/en-us/legal/data-protection-addendum or upon request).

International data transfers

Where a sub-processor is located outside the European Economic Area, or where processing involves a transfer of data outside the EEA, such transfers are made subject to Standard Contractual Clauses (SCCs) approved by the European Commission, or another valid transfer mechanism, as required by GDPR Chapter V. This is confirmed for both Twilio and Anthropic, whose Data Processing Addenda each include the EU Standard Contractual Clauses by default. Anthropic's processing itself still takes place on US infrastructure rather than within the EEA, a separate open question from the transfer mechanism itself, see "Where data is hosted" above.

How long we keep data

If a practitioner cancels or their subscription lapses, practice and patient data is retained for 90 days from the date of cancellation or lapse, then permanently deleted, except where retention is separately required by the practitioner's own medical recordkeeping obligations. Administrator seat access is revoked immediately upon removal by the practitioner; administrator account data is deleted on the same 90-day schedule as the associated practice. Patients can request erasure of their own data at any time, subject to any legal retention obligations on the practitioner's own recordkeeping requirements under medical practice regulation. Soft deletion marks records for removal, and data is permanently removed after the retention window.

Patient rights

Patients have the right to:

  • Access their data via the patient portal
  • Request correction of inaccurate data
  • Request erasure, subject to the practitioner's own legal retention obligations
  • Request a copy of their data in a portable format
  • Object to processing
  • Withdraw consent given for processing at any time

Requests can be made via the patient portal or by contacting the practitioner directly, or by emailing support@monoy.doctor for consent withdrawal specifically. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.

Children's data

Where a patient is under the age of 14, processing relies on consent given by a parent or legal guardian on the patient's behalf, captured and timestamped at booking or intake in the same manner as adult consent. Where a patient is between 14 and 18, the patient may provide consent directly, consistent with Cyprus Law 125(I)/2018, unless the specific medical context requires guardian involvement under separate healthcare consent rules.

Security measures

See our Data Security page for full detail. In summary, data is encrypted at rest and in transit, documents are served via short-lived signed URLs, and access is enforced at the database level through Row Level Security, not application logic alone.

Supervisory authority

Practitioners and patients in Cyprus can lodge a complaint with the Cyprus Commissioner for Personal Data Protection. Contact details for other jurisdictions will be added as Monoy expands.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal requirements.

Contact

Data protection questions can be sent to support@monoy.doctor.