Last updated: 2026-06-06

DayBrief: Data Processing Agreement (Art. 28 GDPR)

This Data Processing Agreement (“DPA”) forms part of the agreement between the Controller and the Processor for the use of the DayBrief application (“the App”) and is concluded pursuant to Article 28(3) GDPR.

1. Parties

2. Subject matter, duration, nature and purpose (Art. 28(3))

3. Controller’s rights and obligations

4. Processor: processing only on instructions (Art. 28(3)(a))

The Processor processes personal data only on the Controller’s documented instructions, including with regard to transfers, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other data protection law (Art. 28(3), last paragraph).

5. Processor obligations

  1. Confidentiality (Art. 28(3)(b)). The Processor ensures that persons authorized to process the personal data are bound by an obligation of confidentiality that survives the end of their engagement.
  2. Security (Art. 28(3)(c) / Art. 32). The Processor implements the technical and organizational measures set out in Annex 2, appropriate to the risk.
  3. Sub-processors (Art. 28(3)(d)). The Controller grants general authorization for the sub-processors listed in Annex 3. The Processor imposes data protection obligations on each sub-processor equivalent to those in this DPA. The Processor will inform the Controller of any intended addition or replacement of a sub-processor at least 30 days in advance (by updating Annex 3 and notifying the App’s admin), giving the Controller the opportunity to object; if the Controller reasonably objects and the matter cannot be resolved, the Controller may terminate by uninstalling the App.
  4. Assistance with data subject rights (Art. 28(3)(e)). Taking account of the nature of the processing, the Processor assists the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests under Chapter III GDPR (Art. 15–22). Because the App retains no task content (Annex 2), most such requests are fulfilled by the Controller directly within monday.com; the Processor assists with any data it holds (App configuration) without undue delay.
  5. Assistance with Art. 32–36 (Art. 28(3)(f)). The Processor assists the Controller in ensuring compliance with the security, breach-notification, DPIA, and prior-consultation obligations, taking into account the nature of processing and information available to it.
  6. Personal data breach. The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller’s data, providing the information available (nature, categories and approximate numbers affected, likely consequences, and measures taken or proposed), and assists the Controller with its own notification obligations.
  7. DPIA. The Processor provides the information reasonably necessary for the Controller’s data protection impact assessment and any prior consultation with the supervisory authority.
  8. Return or deletion (Art. 28(3)(g)). On termination (uninstallation), all processing and sending stop immediately and the OAuth access credentials are deleted at that point. Remaining stored configuration and delivery metadata are deleted upon reconnection or on request (within 30 days of such request), and existing copies are deleted unless Union or Member State law requires their retention. Task content is never retained, so there is nothing to return or delete on that account.
  9. Audit (Art. 28(3)(h)). The Processor makes available to the Controller all information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. The Processor may satisfy this by providing relevant documentation and its sub-processors’ certifications; on reasonable prior notice (at least 30 days) and no more than once per year save for cause, the Controller may request a more detailed audit.
  10. Data location / international transfers. All processing takes place within the EU/EEA: App configuration and delivery metadata are stored in monday’s storage in the EU region, and email is sent via Mailjet’s EU infrastructure. The Processor does not transfer the Controller’s personal data outside the EU/EEA. Should that ever change, the Processor will first put in place a valid transfer mechanism (e.g., EU Standard Contractual Clauses) and inform the Controller.

6. Liability

Each party is liable in accordance with Art. 82 GDPR and the underlying agreement. The Processor is liable for damage caused by processing only where it has not complied with GDPR obligations specifically directed to processors or where it has acted outside or contrary to the Controller’s lawful instructions.

7. Term and termination

This DPA takes effect on installation of the App and ends when the App is uninstalled, subject to the deletion/return obligations in §5.8, which survive termination.

8. Governing law

This DPA is governed by Austrian law, to the extent not overridden by mandatory provisions of the GDPR. Place of jurisdiction is Vienna, Austria, to the extent legally permissible.


Annex 1: Details of processing

ItemDetail
Categories of data subjectsMembers and guests of the Controller’s monday.com account who are assigned items
Types of personal data (used transiently, not stored)Name; email address; assigned item titles, due dates, and status; board names
Types of personal data (stored, configuration only)Schedule preferences (timezone, send hour, weekdays, opt-out flag and server-owned “Unsubscribed since” timestamp); last-sent date per user; delivery metadata (user id, date, success/failure, provider message id or error code, item count)
Special categories (Art. 9)None processed
Nature of processingReading assigned items across boards; classifying by due date/status; rendering and sending an email digest per person on a schedule
PurposeProvide each person a scheduled email summary of their own due monday items
DurationFor the duration of the App installation

Annex 2: Technical and organizational measures (Art. 32)

Annex 3: Authorized sub-processors

Sub-processorRoleLocationSafeguards
monday.com Ltd.Platform host (monday Code), data source, configuration storage, billingEU region of the Controller’s accountISO 27001/27018, SOC 2 Type II, GDPR; own DPA. Risk-assessed Low
Mailjet SAS (a Sinch company)Transactional email deliveryFrance / EUISO 27001, GDPR; own DPA. Risk-assessed Low

Changes to this list are notified per §5.3.