Candor Candor
Legal

Data Processing Agreement

Where you (the account) are the controller and Candor is the processor of the board and item data our apps handle for you.

Last updated: 31 August 2026

This DPA is incorporated into the Terms of Service and applies whenever a Candor App processes personal data on your behalf. You are the controller; datadir s. r. o. is the processor.

1. Subject matter and duration

We process personal data only to provide the Apps you've installed, for as long as they're installed, plus the short wind-down period in section 7.

2. Nature and purpose

Reading and writing board and item data (boards, items, subitems, columns and metadata) and, where a feature needs it, limited end-user data — solely to deliver that App's function.

3. Categories of data and data subjects

  • Data subjects: the account's members and the people its work involves (approvers, document signers, ticket contacts).
  • Data: board and item configuration and content; and, per feature, identifiers such as an approver's monday identity, a signer's email address, or a ticket contact. We minimise this to what the feature requires.

4. Our obligations

  • Process only on your documented instructions (installing and configuring an App is such an instruction).
  • Ensure personnel are bound by confidentiality.
  • Apply appropriate technical and organisational security measures (section 6).
  • Assist you with data-subject requests and with your security, breach, and impact-assessment obligations.
  • Notify you without undue delay after becoming aware of a personal-data breach.

5. Sub-processors

You authorise the sub-processors below. We'll give notice of any intended change and a chance to object.

Sub-processorPurposeLocation
monday.com LtdThe platform your account runs on, and — via monday code — the cloud that hosts the app and any data it storesPer monday.com's terms & sub-processors
Transactional notification / email relaySending notifications or emails for apps that send them (e.g. approval reminders)Named here before any such app goes live

6. Security measures

  • Tenant isolation — an app's stored data is scoped per account and per app, so no account's install can read another's data.
  • Verified requests — the monday session that renders a view is verified against the app's client secret, and every inbound webhook is checked against its signing secret before it's acted on.
  • Dependable, auditable state — where an app owns a decision (an approval, an envelope status) that state is app-owned so it isn't silently overwritten; Approval Flows keeps an immutable audit log.
  • Encryption in transit; access on least-privilege; hosting on monday code.

7. Return and deletion

On uninstall, or on your request, we delete or return the personal data we process for you, except where the law requires retention.

8. International transfers

The apps and their stored data are hosted on monday code (monday.com's cloud). monday.com's own data-residency and international-transfer safeguards apply to that hosting.

9. Audits

On reasonable request and notice, we'll make available the information needed to demonstrate compliance with this DPA.

Questions about this DPA: support@candor.datadir.co. Company details: Legal notice.