How MontagemRoots handles personal data
Last updated:
MontagemRoots is a family-tree application. People use it to record their families, which means it holds data about living people who never entered it themselves and never agreed to be in it - cousins, in-laws, partners and children.
This page explains who holds that data, what it is, why we are allowed to hold it, how long it stays, who can see it and what you can do about it. It is written for that reader: you do not need an account to read it, and you do not need one to ask us to remove you.
If somebody has recorded you in their family tree and you want your details removed, you can ask without creating an account.
Ask to be removed from a family tree info@proceptio.comWho holds your data
MontagemRoots is operated by Proceptio, at montagemroots.com. For anything on this page, including a request about your own data, write to info@proceptio.com. That address reaches the people who run the service, and it is the one to use - there is no form you have to find first.
Two parties are involved in a family tree and they are not the same. Proceptio holds the data, secures it and answers requests about it. The person who created a tree decides what goes into it: they typed the names, and they choose who may read them.
A removal request is decided by a platform administrator rather than by the tree owner - otherwise your request would be judged by the very person who recorded you.
What a family tree holds about you
A record about a person can hold: names, including a birth surname, a patronymic and a nickname; sex; whether the person is living or deceased; dates and places of birth, death, marriage and other life events; relationships to other people in the tree; free-text notes; and photographs, documents and sources a member has attached.
Not every record holds all of that. Most hold a name and a couple of dates.
If you hold an account, we also hold your email address, your display name, your password stored only as a hash, the trees you belong to and your role in each, the time you last signed in, and a record of membership changes such as being invited and having access changed.
We do not ask for the special categories in Article 9 - health, religion, ethnic origin, politics, biometrics or sexual orientation - and this application has no field for them. A free-text note can be typed by anybody, so if you find such a detail written about you, tell us and we will remove it.
Why we are allowed to hold it
In plain words: we rely on our own legitimate interest in documenting family history, and NOT on your consent. We are not asking you to agree to this, and we are not pretending you already did. What you have instead is the right to object - say so and we will remove you.
For your account the basis is the contract you entered into by opening it (Article 6(1)(b)): without an email address and a password we cannot give you an account.
For the content of a family tree - including records about people who are not users - the basis is legitimate interests (Article 6(1)(f)). Documenting family history is an interest recognised in genealogy, and this product is built so that it does not override yours: a tree is private by default; a public tree publishes no person at all, only a surname, a family nickname, an origin and a count; a member who may not edit a tree sees a living person’s name and nothing else; and anybody, with an account or without one, can object and have their record removed.
Consent is used where consent is the honest description: linking a person in one tree to the same person in another needs consent from every source involved, and it can be refused.
Some processing is required of us rather than chosen by us - keeping a record of access and of the requests we have answered (Article 6(1)(c), with Article 5(2), which requires us to be able to demonstrate compliance).
How long it stays
A tree stays until its owner deletes it. Deletion is immediate and cannot be undone: the people, families, events, photographs and documents are destroyed, and what remains is a log of the shape of what was deleted - counts, who deleted it and when - holding no name and no date about anybody.
A record about one person is removed as soon as a request about it is upheld.
A request you send us is kept for 30 days after it is answered and then deleted, because those records are otherwise the longest-lived copy of exactly what somebody asked to have erased.
The security log - who signed in, who was given access to what - is currently not purged on a timer. Deleting that history has consequences for anybody who later asks who could read their record, so it is not on a default schedule.
Who can see it
A tree is private until its owner changes that. Private means it is not in the directory, cannot be searched, and cannot even be requested by anybody who is not a member.
An owner can make a tree public, which makes the tree - not the people in it - findable by signed-in accounts. What a stranger sees is the tree name, a family nickname, an origin and how many people it holds. Reading the contents always needs the owner to approve a request.
When an owner approves somebody, they choose how much that person may read: everything, or a name, the living-or-deceased status and, for people who have died, a birth and death year. At that level a living person stays a name and nothing else.
An owner can suspend sharing for a whole tree at any time. Every member except the owner then loses access on their next request, without deleting the record of who had it.
We do not sell data, we do not use it for advertising, and there is no third-party analytics or tracking on this site.
Children
A child in a family tree is treated exactly like any other living person: their record is withheld from members who may not edit the tree, they are never published, no photograph of them is shown to somebody granted names-and-basics access, and they never appear in an export at that level. We do not ask for anything about a child that a tree does not need - no school, no address, no health note.
A parent or guardian can object on a child’s behalf, through the same form, without an account, and it is decided by a platform administrator rather than by the relative who recorded them. We do not demand proof of guardianship first: asking for documents about a child in order to protect a child is the wrong trade.
We never rely on a child’s own agreement for anything, and this application builds no profiles, runs no advertising and makes no automated decisions about anybody - the risks that the rules on children are written for do not exist here.
Accounts are for adults.
Your rights
You can ask us for a copy of what we hold about you (Article 15), to correct it (Article 16), to delete it (Article 17), to restrict what we do with it while a question is open (Article 18), to object to our processing it at all (Article 21) and - where the basis is a contract or consent - to receive it in a portable form (Article 20).
You need no account for any of them and you do not have to explain why. Write to info@proceptio.com or use the removal form. The form does not ask you to sign in, and it does not tell you whether a matching person was found: an answer that varied would turn it into a way to search every private tree in the system.
We answer within one month. If a request needs longer than that, we will tell you inside the month why and how long.
Why nobody told you individually
Article 14 says that when personal data about you is obtained from somebody else, you should be informed. We have not written to each person recorded in a tree, and this is the explanation the law expects instead.
Most records about living people here carry no contact details at all - a name, a year, a village. Contacting somebody would mean finding them first, which would mean collecting more data about them than the record holds, and doing it for every person in every tree. Article 14(5)(b) allows a controller not to notify individually where that effort is disproportionate, on the condition that the information is made publicly available instead. This page is that publication, and it is deliberately readable without an account.
That condition has a second half we take seriously: relief from notifying is not relief from acting. Anybody can object here, without an account, in any of the four languages this application speaks, and a request is decided by a person rather than by a rule.
If we get it wrong
Tell us first, at info@proceptio.com, because most of what people want corrected here we can correct the same day.
You also have the right to complain to a data-protection authority. In Croatia that is the Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb. You may also complain to the authority in the country you live in.