Approvals Pro

Privacy Policy

How the Approvals Pro application for monday.com handles data. Written to match what the application actually does, rather than to cover every eventuality.

Effective: 30 August 2026Published by: TidalTech Software Co., Ltd.Contact: [email protected]
This policy covers the Approvals Pro application. TidalTech's separate policy for the corporate website is at tidaltechsoft.com/en/privacy.html.

1. Two different roles, and why it matters

We handle two kinds of data and our responsibility differs between them.

Approval content — you are the controller, we are the processor. When your organisation raises an approval, the request, the decisions, and the audit trail belong to your organisation. We process them on your instruction, for the sole purpose of running the approval, and for no purpose of our own. We do not analyse them, mine them, train anything on them, or look at them except when you ask us to help with a specific problem.

Feedback you send us — we are the controller. The application has a feedback form. What you type in it comes to us, and section 5 says exactly what that includes.

2. What the application stores about people

Approvals Pro records who took part in an approval. Specifically, for each participant it stores:

  • monday user ID
  • Name
  • Email address
  • Team name and job title, where monday holds them

These are copied at the moment the approval is raised and never updated. This is deliberate and it is the point of the product: an approval is a record of who committed to something at the time they committed to it. If we resolved names live, an approval signed by a manager who later changed department would silently start showing their new department, and a record that rewrites itself is not a record. The same applies to delegations, which store both the person who is away and the person standing in for them.

Alongside the people, an approval holds the title and body you write, the name and ID of the monday item it concerns, timestamps, and references to any attached files.

3. What the application does not store

  • The contents of attached files. Files pass through memory only long enough to be hashed and handed to monday, which stores them. We keep the file name, its size, monday's asset ID, and a SHA-256 fingerprint — the fingerprint being what lets the audit trail prove the file has not been altered. The bytes are fetched from monday, never from us.
  • Your monday board or item content, beyond the item's name and ID.
  • Passwords. There are none. Authentication is monday's.
  • Cookies of any kind. No session cookie, no tracking cookie, no analytics cookie. Credentials travel in an HTTP header for the duration of a request.
  • Payment or card details. Billing is monday's; see section 7.

4. Legal basis for processing

Where the GDPR applies:

  • For approval content, our processing is carried out on behalf of your organisation under Article 28. Your organisation determines the purpose and relies on its own legal basis, ordinarily legitimate interests in running its internal approvals.
  • For feedback you choose to send us, our basis is legitimate interests in supporting and improving the application (Article 6(1)(f)).
  • For the credentials we hold in order to operate at all, our basis is performance of a contract (Article 6(1)(b)).

A Data Processing Agreement is available on request at [email protected].

5. Feedback

The in-application feedback form sends us:

  • What you wrote, and whether you marked it a problem or an idea
  • A contact address, only if you supply one — it is optional, and plenty of reports need no reply
  • Your monday account ID and account slug, your monday user ID, and the board and item you were on when you wrote it
  • The application version and your browser's user-agent string
  • Any screenshots you choose to attach. Attaching one is entirely optional and nothing is captured automatically: you select the images, the application shows you what you have selected, and it tells you before sending that the images will be sent to us. A screenshot may contain whatever was on your screen, so review it before attaching.

This goes to a monday board inside our account, so that we can act on it. We use it to fix and improve the application, and to reply to you if you asked us to. We do not use it for marketing.

Apart from feedback you deliberately send, no content from your account reaches us.

6. Where data is stored, and who else sees it

Everything the application stores is held in monday's own storage, scoped to your account, on monday's infrastructure. We do not operate a database.

We use no third parties at all. No analytics provider, no error-reporting service, no content delivery network, no external mail provider, no sub-processor of any kind. The application talks to monday's API and to nothing else. Consequently there is no list of sub-processors to publish, because the list is empty.

Your data's physical location is determined by monday, not by us.

7. Payment

Subscriptions are sold, charged and managed by monday, through the monday marketplace. We never see, receive or store your card details or billing address. What we receive from monday is the fact of whether your account's subscription is active, which is the only thing the application needs in order to know whether to work.

8. Retention and deletion

When you uninstall Approvals Pro, everything it holds for your account is deleted immediately. Not scheduled, not within a window — the uninstall notification from monday triggers the deletion directly.

That includes every approval, every decision, every audit trail, your saved approval paths, delegations, wording customisations, subscription state, and the credentials we held to act for you. Nothing is retained for analytics or for a grace period.

Deletion is verified by test, not assumed: the deletion routine is exercised against a seeded account and checked for completeness.

While the application remains installed, approvals are retained indefinitely, because a permanent record is what they are for. You may delete an individual approval's item in monday at any time.

Application logs are retained by monday code under its platform retention period. Logs contain identifiers — an account ID, a user ID, a request ID — and error messages. They contain no names, no email addresses, no approval titles or bodies, no decision comments and no file names. This is enforced by an automated check over the source rather than by good intentions.

9. Your rights

Where the GDPR or comparable law applies, you have the right to access, correct, delete, export and restrict the processing of your personal data, and to object to it.

For approval content, exercise these rights with your own organisation, which controls that data. We will assist them promptly with any request they pass to us. If you contact us directly about approval content, we will refer you to the account administrator rather than act unilaterally, because acting on one participant's request to alter a shared record would be acting against the organisation whose record it is.

For feedback you sent us, contact us at [email protected] and we will act on it directly.

You may also complain to your local supervisory authority.

10. International transfers

The application runs on monday's own infrastructure. It is deployed to monday's United States, European Union, Australia and Israel regions, and monday determines which region serves a given account. An account's data is held by the region monday assigns to it; we neither choose that region nor move data between regions.

For accounts monday assigns to its European Union region, data remains within that region. Where an account is served from a region outside the EEA, the transfer arises from monday's own platform arrangements rather than from any onward transfer by us, since we operate no infrastructure of our own and use no sub-processors.

11. Children

Approvals Pro is a workplace tool, sold to organisations. It is not directed at children and we do not knowingly process children's data.

12. Changes to this policy

If we change this policy materially we will update the effective date above and publish the new version at the same address. Continued use after a change constitutes acceptance of it.

13. Contact

TidalTech Software Co., Ltd.
186-186 Bis Nguyễn Thị Minh Khai, Phường Võ Thị Sáu, Quận 3, Ho Chi Minh City, Vietnam
[email protected]