Data Processing Agreement
Where you (the account) are the controller and Candor is the processor of the board and item data our apps handle for you.
Last updated: 31 August 2026
This DPA is incorporated into the Terms of Service and applies whenever a Candor App processes personal data on your behalf. You are the controller; datadir s. r. o. is the processor.
1. Subject matter and duration
We process personal data only to provide the Apps you've installed, for as long as they're installed, plus the short wind-down period in section 7.
2. Nature and purpose
Reading and writing board and item data (boards, items, subitems, columns and metadata) and, where a feature needs it, limited end-user data — solely to deliver that App's function.
3. Categories of data and data subjects
- Data subjects: the account's members and the people its work involves (approvers, document signers, ticket contacts).
- Data: board and item configuration and content; and, per feature, identifiers such as an approver's monday identity, a signer's email address, or a ticket contact. We minimise this to what the feature requires.
4. Our obligations
- Process only on your documented instructions (installing and configuring an App is such an instruction).
- Ensure personnel are bound by confidentiality.
- Apply appropriate technical and organisational security measures (section 6).
- Assist you with data-subject requests and with your security, breach, and impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal-data breach.
5. Sub-processors
You authorise the sub-processors below. We'll give notice of any intended change and a chance to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| monday.com Ltd | The platform your account runs on, and — via monday code — the cloud that hosts the app and any data it stores | Per monday.com's terms & sub-processors |
| Transactional notification / email relay | Sending notifications or emails for apps that send them (e.g. approval reminders) | Named here before any such app goes live |
6. Security measures
- Tenant isolation — an app's stored data is scoped per account and per app, so no account's install can read another's data.
- Verified requests — the monday session that renders a view is verified against the app's client secret, and every inbound webhook is checked against its signing secret before it's acted on.
- Dependable, auditable state — where an app owns a decision (an approval, an envelope status) that state is app-owned so it isn't silently overwritten; Approval Flows keeps an immutable audit log.
- Encryption in transit; access on least-privilege; hosting on monday code.
7. Return and deletion
On uninstall, or on your request, we delete or return the personal data we process for you, except where the law requires retention.
8. International transfers
The apps and their stored data are hosted on monday code (monday.com's cloud). monday.com's own data-residency and international-transfer safeguards apply to that hosting.
9. Audits
On reasonable request and notice, we'll make available the information needed to demonstrate compliance with this DPA.
Questions about this DPA: support@candor.datadir.co. Company details: Legal notice.