Last updated: 2026-06-06
DayBrief: Privacy Policy
1. Who we are
DayBrief (“the App”) is operated by:
- Kainabinoids GmbH
- Registered address: Carabelligasse 5/Haus 56, 1210 Wien, Österreich
- Firmenbuchnummer: FN 607246i, Handelsgericht Wien
- UID: ATU80796845
- Contact: daybrief@sitething.at
- Managing director / Geschäftsführer: Kai Juszko
- Data Protection Officer (Art. 13(1)(b)): We are not legally required to appoint a Data Protection Officer and have not done so; our processing is not on a scale or of a nature that triggers Art. 37 GDPR. Direct any data-protection questions to the contact above.
We are an Austrian company; the App is distributed through the monday.com marketplace.
2. Our role under the GDPR
When an organization installs DayBrief on its monday.com account, that organization is the data controller for the data DayBrief processes on its behalf. DayBrief acts as a data processor under Article 28 GDPR, processing personal data solely to provide the digest service and only on the controller’s documented instructions (the installation and the settings the admin configures).
A Data Processing Agreement (Auftragsverarbeitungsvertrag) under Art. 28 GDPR applies to every controller and is incorporated by reference into the App’s terms. See our Data Processing Agreement.
3. What data we process, and why
DayBrief reads, transiently, the data needed to build each person’s digest:
| Data | Source | Purpose | Stored? |
|---|---|---|---|
| User name + email address | monday account (via users:read) | Address the digest to the right person | Fetched live from monday at each send via users:read; never stored (zero recipient PII at rest) |
| Board names | monday account (via boards:read) | Group items by board in the email | Not retained |
| Item titles, due dates, status, assignee | monday boards (via boards:read) | Determine which items are due for whom and list them | Not retained (processed in memory during the send and discarded) |
| Schedule preferences (timezone, send hour, weekdays, opt-out status and server-owned “Unsubscribed since” timestamp) | Set by the account admin / user | Decide when to send each person’s digest | Stored in monday storage (config only) |
| Last-sent date per user | Generated by the App | Prevent sending the same digest twice in a day | Stored in monday storage |
| Delivery metadata (user id, date, success/failure, provider message id or error code, item count) | Generated by the App | Measure delivery reliability and support troubleshooting | Stored in monday storage (no item titles, no email bodies, no addresses) |
We do not retain task content. Item titles and due dates exist only in memory while a digest is being rendered and sent, then are discarded when the request ends.
We do not process payment data: monday.com handles all billing, tax, and payment.
We do not use analytics or advertising trackers, and the App sets no cookies.
No automated decision-making. DayBrief carries out no automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Art. 22 GDPR. It only selects each person’s due items by date and status and emails them a summary on the schedule the account configures.
4. Legal basis
We process the above as a processor on the documented instructions of the controller (Art. 28 GDPR). The controller’s own legal basis for using DayBrief is typically its legitimate interest in keeping its team informed of their tasks (Art. 6(1)(f)) or the performance of its internal work organization.
5. Sub-processors
To deliver the service we use:
- monday.com (monday.com Ltd.): the platform the App runs on. The data already resides in the customer’s monday account; the App’s backend runs on monday’s infrastructure (“monday Code”). See monday’s privacy policy and sub-processor list.
- Mailjet (Mailjet SAS, a Sinch company, France/EU): transmits the rendered digest email to each recipient. The email Mailjet handles contains the recipient’s email address and their own task titles + due dates, for the purpose of delivery. Mailjet is EU-based and acts under its own GDPR-compliant data processing terms. See Mailjet’s privacy policy.
A current sub-processor list is maintained at Sub-processors and in our Data Processing Agreement. We will inform controllers of changes to sub-processors in line with the DPA.
6. Data location and transfers
App configuration and delivery metadata are stored in monday’s storage within the region of the customer’s monday account. Email is sent via Mailjet’s EU infrastructure. We do not transfer personal data outside the EU/EEA for our own purposes.
7. Retention
- Configuration (schedule, preferences): kept until the App is uninstalled or the setting is removed.
- Delivery metadata: kept as a rolling log of the most recent deliveries (capped), then overwritten.
- Task content: never retained.
On uninstall, all processing and sending stop immediately and the OAuth access credentials are deleted at that point. Remaining stored configuration and delivery metadata are deleted upon reconnection or on request. Task content was never stored at all, so there is nothing to recover.
8. Security
- Provider API keys are held in monday’s encrypted secret storage, never in code.
- Outbound connections are limited to a small set of named hosts: monday’s own platform services (
api.monday.com,auth.monday.com,apps-storage.monday.com), the email provider Mailjet (api.mailjet.com), and Google’s public certificate endpoint (www.googleapis.com). The call towww.googleapis.comis a read-only fetch of Google’s published signing keys, used solely to verify the Google-signed token that monday’s scheduler sends when triggering the digest cron; no personal data is sent to Google. There are no analytics, advertising, monitoring, or tracking domains. - Delivery logs are sanitized to exclude any task content, email bodies, or addresses.
- Access to read account data is limited to the minimum OAuth scopes required (
boards:read,users:read,account:read,me:read). - Authenticated endpoints verify monday session tokens (settings) and Google-signed scheduler tokens (the digest cron).
- Signed-token public pages (
/unsubscribeand/manage) use HS256 tokens that are non-enumerating; the uninstall webhook is verified before processing.
9. Data subject rights
Every individual has the following rights under the GDPR:
- the right of access (Art. 15),
- the right to rectification (Art. 16),
- the right to erasure (Art. 17),
- the right to restriction of processing (Art. 18),
- the right to data portability (Art. 20),
- the right to object to processing (Art. 21), and
- the right to withdraw consent at any time (Art. 7(3)).
Because we act as a processor, individuals should direct these requests to the controller (the organization whose monday account is used). We assist the controller in fulfilling such requests as required by Art. 28(3)(e). As stated in section 3, DayBrief performs no automated decision-making under Art. 22, so no related right is engaged.
A recipient can opt out at any time by clicking the one-click unsubscribe link in every digest email, or by using the personal “Manage your digest” link in the footer (no monday login required). Opt-out takes effect immediately. Digest enrollment is controlled by the account admin acting as controller; an admin may re-enable an opted-out recipient only through a confirmation step that shows the opt-out date. Self-service unsubscribe and preference management via the personal /manage link is always available to recipients.
10. Supervisory authority
Controllers and data subjects may lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde (DSB), Barichgasse 40-42, 1030 Wien: dsb.gv.at.
11. Contact
Questions about this policy or the App’s data handling: daybrief@sitething.at.
12. Changes
We will update this page when the App’s data handling changes and note the date above.