Last updated: 2026-06-06

DayBrief: Privacy Policy

1. Who we are

DayBrief (“the App”) is operated by:

We are an Austrian company; the App is distributed through the monday.com marketplace.

2. Our role under the GDPR

When an organization installs DayBrief on its monday.com account, that organization is the data controller for the data DayBrief processes on its behalf. DayBrief acts as a data processor under Article 28 GDPR, processing personal data solely to provide the digest service and only on the controller’s documented instructions (the installation and the settings the admin configures).

A Data Processing Agreement (Auftragsverarbeitungsvertrag) under Art. 28 GDPR applies to every controller and is incorporated by reference into the App’s terms. See our Data Processing Agreement.

3. What data we process, and why

DayBrief reads, transiently, the data needed to build each person’s digest:

DataSourcePurposeStored?
User name + email addressmonday account (via users:read)Address the digest to the right personFetched live from monday at each send via users:read; never stored (zero recipient PII at rest)
Board namesmonday account (via boards:read)Group items by board in the emailNot retained
Item titles, due dates, status, assigneemonday boards (via boards:read)Determine which items are due for whom and list themNot retained (processed in memory during the send and discarded)
Schedule preferences (timezone, send hour, weekdays, opt-out status and server-owned “Unsubscribed since” timestamp)Set by the account admin / userDecide when to send each person’s digestStored in monday storage (config only)
Last-sent date per userGenerated by the AppPrevent sending the same digest twice in a dayStored in monday storage
Delivery metadata (user id, date, success/failure, provider message id or error code, item count)Generated by the AppMeasure delivery reliability and support troubleshootingStored in monday storage (no item titles, no email bodies, no addresses)

We do not retain task content. Item titles and due dates exist only in memory while a digest is being rendered and sent, then are discarded when the request ends.

We do not process payment data: monday.com handles all billing, tax, and payment.

We do not use analytics or advertising trackers, and the App sets no cookies.

No automated decision-making. DayBrief carries out no automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Art. 22 GDPR. It only selects each person’s due items by date and status and emails them a summary on the schedule the account configures.

We process the above as a processor on the documented instructions of the controller (Art. 28 GDPR). The controller’s own legal basis for using DayBrief is typically its legitimate interest in keeping its team informed of their tasks (Art. 6(1)(f)) or the performance of its internal work organization.

5. Sub-processors

To deliver the service we use:

A current sub-processor list is maintained at Sub-processors and in our Data Processing Agreement. We will inform controllers of changes to sub-processors in line with the DPA.

6. Data location and transfers

App configuration and delivery metadata are stored in monday’s storage within the region of the customer’s monday account. Email is sent via Mailjet’s EU infrastructure. We do not transfer personal data outside the EU/EEA for our own purposes.

7. Retention

On uninstall, all processing and sending stop immediately and the OAuth access credentials are deleted at that point. Remaining stored configuration and delivery metadata are deleted upon reconnection or on request. Task content was never stored at all, so there is nothing to recover.

8. Security

9. Data subject rights

Every individual has the following rights under the GDPR:

Because we act as a processor, individuals should direct these requests to the controller (the organization whose monday account is used). We assist the controller in fulfilling such requests as required by Art. 28(3)(e). As stated in section 3, DayBrief performs no automated decision-making under Art. 22, so no related right is engaged.

A recipient can opt out at any time by clicking the one-click unsubscribe link in every digest email, or by using the personal “Manage your digest” link in the footer (no monday login required). Opt-out takes effect immediately. Digest enrollment is controlled by the account admin acting as controller; an admin may re-enable an opted-out recipient only through a confirmation step that shows the opt-out date. Self-service unsubscribe and preference management via the personal /manage link is always available to recipients.

10. Supervisory authority

Controllers and data subjects may lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Wien: dsb.gv.at.

11. Contact

Questions about this policy or the App’s data handling: daybrief@sitething.at.

12. Changes

We will update this page when the App’s data handling changes and note the date above.