monday.com is a cloud-based SaaS web application. It is commercial off-the-shelf (COTS), so no setup is required, and your data is stored with our Cloud Service Providers (CSP).
In this article, we answer common questions about privacy roles, governance and compliance, data hosting and retention, security controls (access, encryption, secure development, mobile), incident response and disaster recovery.
Privacy terminology
Some privacy and data protection laws, including the GDPR and CCPA, distinguish between two primary roles when collecting and processi ng personal data: data controllers and data processors. Under the CCPA, these are known as businesses and service providers.
A data controller (or business) determines the means and purposes for processing personal data.
A data processor (or service provider) is a party that processes data on behalf of the controller.
monday.com is the data controller (or business) of personal data relating to our customers, users, and website visitors. This is further detailed in our Privacy Policy.
monday.com is the data processor (or service provider) of personal data that our customers and users submit to the Services (for example, into boards and items within a monday.com account). We process this data solely on our customers’ behalf, in accordance with the Data Processing Addendum. The third parties we use to help us process this data are our sub-processors. A list of our sub-processors, including their hosting regions and the types of services they provide us with, is available here.
You can also subscribe to get email notifications about any updates to our sub-processors list through the link above.
FAQs
Governance risk and compliance
Privacy
Operational and application security
Incidents, availability, and disaster recovery
If you have any questions, please reach out to our team right here. We’re available 24/7 and happy to help.