Last updated: 2026-06-06
DayBrief: Data Processing Agreement (Art. 28 GDPR)
This Data Processing Agreement (“DPA”) forms part of the agreement between the Controller and the Processor for the use of the DayBrief application (“the App”) and is concluded pursuant to Article 28(3) GDPR.
1. Parties
- Processor: Kainabinoids GmbH, Carabelligasse 5/Haus 56, 1210 Wien, Österreich; FN 607246i, Handelsgericht Wien; UID ATU80796845; contact: daybrief@sitething.at (“Processor”).
- Controller: the organization that installs and configures DayBrief on its monday.com account (“Controller”). By installing the App, the Controller accepts this DPA.
2. Subject matter, duration, nature and purpose (Art. 28(3))
- Subject matter: processing of personal data on the Controller’s behalf solely to provide the DayBrief digest service.
- Duration: for as long as the App is installed on the Controller’s monday.com account; this DPA is co-terminous with that installation and survives only as needed for deletion (§5.8).
- Nature and purpose: reading the Controller’s monday board, item, and user data to determine which items are due for each person, and sending each person a scheduled email summary of their own due items. No other purpose.
- Types of personal data and categories of data subjects: see Annex 1.
3. Controller’s rights and obligations
- The Controller determines the purposes and means of processing and is responsible for the lawfulness of the data it makes available through its monday.com account.
- The Controller may give, amend, and withdraw documented instructions (the installation and the settings configured in the App are such instructions). Instructions beyond the App’s configuration must be given in writing to daybrief@sitething.at.
- The Controller has the audit rights in §5.9 and the termination rights in §7.
4. Processor: processing only on instructions (Art. 28(3)(a))
The Processor processes personal data only on the Controller’s documented instructions, including with regard to transfers, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law (Art. 28(3), last paragraph).
5. Processor obligations
- Confidentiality (Art. 28(3)(b)). The Processor ensures that persons authorized to process the personal data are bound by an obligation of confidentiality that survives the end of their engagement.
- Security (Art. 28(3)(c) / Art. 32). The Processor implements the technical and organizational measures set out in Annex 2, appropriate to the risk.
- Sub-processors (Art. 28(3)(d)). The Controller grants general authorization for the sub-processors listed in Annex 3. The Processor imposes data protection obligations on each sub-processor equivalent to those in this DPA. The Processor will inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance (by updating Annex 3 and notifying the App’s admin), giving the Controller the opportunity to object; if the Controller reasonably objects and the matter cannot be resolved, the Controller may terminate by uninstalling the App.
- Assistance with data subject rights (Art. 28(3)(e)). Taking account of the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests under Chapter III GDPR (Art. 15–22). Because the App retains no task content (Annex 2), most such requests are fulfilled by the Controller directly within monday.com; the Processor assists with any data it holds (App configuration) without undue delay.
- Assistance with Art. 32–36 (Art. 28(3)(f)). The Processor assists the Controller in ensuring compliance with the security, breach-notification, DPIA, and prior-consultation obligations, taking into account the nature of processing and information available to it.
- Personal data breach. The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data, providing the information available (nature, categories and approximate numbers affected, likely consequences, and measures taken or proposed), and assists the Controller with its own notification obligations.
- DPIA. The Processor provides the information reasonably necessary for the Controller’s data protection impact assessment and any prior consultation with the supervisory authority.
- Return or deletion (Art. 28(3)(g)). On termination (uninstallation), all processing and sending stop immediately and the OAuth access credentials are deleted at that point. Remaining stored configuration and delivery metadata are deleted upon reconnection or on request (within 30 days of such request), and existing copies are deleted unless Union or Member State law requires their retention. Task content is never retained, so there is nothing to return or delete on that account.
- Audit (Art. 28(3)(h)). The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. The Processor may satisfy this by providing relevant documentation and its sub-processors’ certifications; on reasonable prior notice (at least 30 days) and no more than once per year save for cause, the Controller may request a more detailed audit.
- Data location / international transfers. All processing takes place within the EU/EEA: App configuration and delivery metadata are stored in monday’s storage in the EU region, and email is sent via Mailjet’s EU infrastructure. The Processor does not transfer the Controller’s personal data outside the EU/EEA. Should that ever change, the Processor will first put in place a valid transfer mechanism (e.g., EU Standard Contractual Clauses) and inform the Controller.
6. Liability
Each party is liable in accordance with Art. 82 GDPR and the underlying agreement. The Processor is liable for damage caused by processing only where it has not complied with GDPR obligations specifically directed to processors or where it has acted outside or contrary to the Controller’s lawful instructions.
7. Term and termination
This DPA takes effect on installation of the App and ends when the App is uninstalled, subject to the deletion/return obligations in §5.8, which survive termination.
8. Governing law
This DPA is governed by Austrian law, to the extent not overridden by mandatory provisions of the GDPR. Place of jurisdiction is Vienna, Austria, to the extent legally permissible.
Annex 1: Details of processing
| Item | Detail |
|---|---|
| Categories of data subjects | Members and guests of the Controller’s monday.com account who are assigned items |
| Types of personal data (used transiently, not stored) | Name; email address; assigned item titles, due dates, and status; board names |
| Types of personal data (stored, configuration only) | Schedule preferences (timezone, send hour, weekdays, opt-out flag and server-owned “Unsubscribed since” timestamp); last-sent date per user; delivery metadata (user id, date, success/failure, provider message id or error code, item count) |
| Special categories (Art. 9) | None processed |
| Nature of processing | Reading assigned items across boards; classifying by due date/status; rendering and sending an email digest per person on a schedule |
| Purpose | Provide each person a scheduled email summary of their own due monday items |
| Duration | For the duration of the App installation |
Annex 2: Technical and organizational measures (Art. 32)
- Data minimization / no content retention. Task titles and due dates exist only in memory while a digest is rendered and sent, then are discarded. Only App configuration and delivery metadata (no content, no email bodies, no addresses) are stored.
- Encryption in transit. TLS to the monday API and to the email provider.
- Secrets management. Provider API keys are held in monday’s encrypted secret storage, never in source code.
- Access control. Access to read account data is limited to the minimum OAuth scopes required (
boards:read,users:read,account:read,me:read). Authenticated endpoints verify monday session tokens (settings) and Google-signed scheduler tokens (the digest cron). - Egress restriction. Outbound connections are limited to named hosts: monday’s own platform services (
api.monday.com,auth.monday.com,apps-storage.monday.com), the email provider Mailjet (api.mailjet.com), and Google’s public certificate endpoint (www.googleapis.com), which is contacted only to fetch Google’s published signing keys for verifying the scheduler’s signed cron token (no personal data is sent). No analytics, advertising, monitoring, or tracking domains. - Confidentiality / integrity / availability. Processing runs on monday Code (monday’s infrastructure); the Processor relies on monday’s and Mailjet’s certified controls (see Annex 3).
- Delivery log hygiene. The delivery log is capped and sanitized to metadata only.
- Deletion. On uninstall, OAuth access credentials are deleted immediately; remaining stored configuration and delivery metadata are deleted upon reconnection or on the Controller’s request (§5.8).
Annex 3: Authorized sub-processors
| Sub-processor | Role | Location | Safeguards |
|---|---|---|---|
| monday.com Ltd. | Platform host (monday Code), data source, configuration storage, billing | EU region of the Controller’s account | ISO 27001/27018, SOC 2 Type II, GDPR; own DPA. Risk-assessed Low |
| Mailjet SAS (a Sinch company) | Transactional email delivery | France / EU | ISO 27001, GDPR; own DPA. Risk-assessed Low |
Changes to this list are notified per §5.3.