Privacy Statement
Your personal data is handled and secured with care. We comply in all cases with the General Data Protection Regulation (GDPR).
Montisoro records your data to inform you about relevant developments. Under no circumstances is permission granted to other companies or institutions to use your data.
We are fully transparent about the data we use and record. No fine print, no hidden agenda.
We never share your data with other parties for commercial purposes. Not today. Not tomorrow. Not under any circumstance.
Recording personal data and special categories of personal data is necessary for the performance of an agreement in the field of guiding and developing individuals, whether or not employed by an organization.
Each processing activity serves one clear purpose. We never collect more than we need for it.
Data is stored on servers within the European Union (AWS, EU region), encrypted in transit and at rest. Access is strictly limited to authorised staff, with authentication and two-factor verification. With Casey AI the case manager stays in charge — there are no solely automated decisions with legal effect.
We never share this data with other parties for commercial purposes.
Consent is given freely and unambiguously, as the person concerned is informed in advance about which data we wish to receive and why.
Independent of context, jurisdiction or agreement, these three rights always remain yours.
The person concerned always has the right to see how we use the data. One email is enough, no form, no barrier.
The person concerned has the right to erasure: the complete deletion of personal data. We carry this out without questions.
For every new processing activity we explain in advance which data we wish to receive and why, so that consent always remains free and unambiguous.
For every type of interaction we know exactly what we record and why.
You complete the fit check; we send you the result and report by email.
You calculate your absence cost; the substantiated report is emailed to you.
You book a diagnostic call via the scheduler. We use your data only to confirm and prepare the appointment.
On behalf of the employer we manage files during incapacity for work. Health data is strictly shielded and processed only on the proper legal basis.
The site works without optional cookies. We activate Google Analytics 4 and Microsoft Clarity only if you allow analytics cookies.
Functional storage keeps only necessary preferences, such as your language and cookie choice. You do not need to accept optional cookies to use the website.
Analytics cookies and similar storage are activated only after you give explicit consent. You can change your choice at any time through Cookie preferences in the footer.
Our own cookieless counter records limited technical visit data. If you allow analytics cookies, we also use Google Analytics 4 for aggregated traffic and conversion measurement and Microsoft Clarity for click and scroll heatmaps and session recordings.
Clarity is configured to mask sensitive input. We do not use session recordings to read information you enter in forms. The site also respects your browser's Do-Not-Track setting.
To make the site work we keep a few preferences locally in your browser (not cookies): your cookie preference, your language and your progress in the calculator, fit check or booking planner.
This data stays on your device and is never used to track you.
We process on the basis of: contract (art. 6.1.b) for the fit check, calculator and booking; legal obligation (art. 6.1.c) for reintegration; legitimate interest (art. 6.1.f) for our limited cookieless website measurement; and consent (art. 6.1.a) for Google Analytics 4 and Microsoft Clarity. Health data is processed only on your explicit consent or the exemptions for employment and social-security law (art. 9.2.b/h GDPR).
Absence and reintegration files contain health data. In Storm these are strictly shielded and viewed only by authorised case managers. The medical assessment stays with the occupational physician.
File data is kept for the duration of the agreement and any legally required retention period thereafter. Lead and contact data is kept for a maximum of 24 months after your last contact. Our own cookieless website measurement is aggregated; optional analytics data is subject to the configured retention periods in Google Analytics 4 and Microsoft Clarity.
We use carefully selected sub-processors: AWS (hosting), Supabase (database), Microsoft 365 (email & calendar) and transactional email services (Mandrill, Amazon SES, Resend). After you consent to analytics, we also use Google Analytics 4 and Microsoft Clarity. These parties process data within the limits of their services and our agreements.
Within the EU in principle. Where a sub-processor processes outside the EU, this happens under the standard contractual clauses (SCCs).
The controller is Montisoro BV, Tisseltstraat 25, 1880 Ramsdonk (BE0733840137), at hello@montisoro.com. You may lodge a complaint with the Belgian Data Protection Authority (Drukpersstraat 35, 1000 Brussels — contact@apd-gba.be). On a data breach with risk, we notify the DPA within 72 hours.