Effective date: July 1, 2026 | Last updated: July 1, 2026
CarbonApps LLC y Carbon Web Print LLC (doing business as CarbonWeb) are related entities. For the personal data we collect about you and your organization in connection with our Applications — account, administrator and end user, and marketing data — we act as joint controllers. For the data that passes through the Applications on your instructions (“Customer Data”), we act as your processor, not as a controller, as described in Section 3 and in the DPA. Throughout this policy, “we,” “us,” and “our” refers to both entities.
This policy covers the following types of Applications we offer on the monday.com platform:
monday.com automation and view apps — apps that add automations and board views within monday.com.
Third-party integration apps — apps that connect your monday.com account to an external service you subscribe to (for example a calling/dialer, SMS, accounting, or lead-sourcing service), including their associated automations, integrations, and views.
Board template solutions — pre-built board templates. For these we receive only the installation webhook and the installing administrator’s details; they are not billed and do not run automations or views. If a template bundles a separate app, that app installs and is purchased under its own agreement and is covered as one of the app types above.
A current list of our individual Applications is available on the monday.com Marketplace.
Contact us:
CarbonApps LLC (designated contact point): support@carbonapps.co Carbon Web Print LLC: contact@carbonweb.co
You may exercise your rights by contacting either entity.
Privacy contact: Privacy questions should be directed to support@carbonapps.co, where they will be handled by our internal privacy lead.
Our establishment. Carbon Web Print LLC and CarbonApps LLC are each established in the European Union.
This policy applies to personal data processed through any of our Applications. It covers data we collect about you as a customer, operational metadata, authentication credentials, and data that passes through our Applications during processing.
This policy does not cover:
For the customer data, contacts, messages, and call events that pass through our Applications: we are a processor acting on your instructions. You determine what data is processed, when, and for what purpose — through the automations, views, and integrations you configure. We do not decide what data is processed or why — you do.
For some Applications — board templates and Applications that operate solely through monday.com’s native automations — no data passes through us at all; it stays within monday.com under your own agreement with monday.com. For those Applications we are neither a processor nor a controller of that data.
For your customer information (installer data, account details, usage metadata, authentication credentials): CarbonApps LLC and Carbon Web Print LLC are joint controllers. We jointly determine what to collect, why, and how it is used.
Your data processing relationship is directly with us, not mediated by monday.com.
A Data Processing Agreement (DPA) governing this processor relationship, incorporating the requirements of Art. 28(3) GDPR, is available at carbonapps.co/legal/apps/dpa. The DPA is pre-executed by us and applies automatically from installation of any Application — no countersignature is required. Customers who require a separately executed copy may request one at support@carbonapps.co.
Two kinds of individuals interact with our Applications: the account administrator who enables an Application for an organization’s monday.com account, and end users who use the Application by creating automations or views. We collect the same personal data about both — their name, email address, job title, and country, together with a flag recording whether they are an administrator. The administrator’s details reach us via monday.com when the Application is enabled; an end user’s details are collected when they first create an automation or view. The difference between the two is one of role, not of the data we hold.
We use this information for:
Service delivery — maintaining your configuration and delivering the Application’s features. (Necessary to perform the contract for delivery of the service — Art. 6(1)(b).)
Product updates — new features, changelogs, and service updates for the Applications on your account or that you have used. (Legitimate interests in keeping customers and active users informed — Art. 6(1)(f). You can opt out at any time.)
CarbonApps marketing — product announcements and promotions about CarbonApps’ monday.com apps. If you are involved in evaluating or buying an Application that offers a paid plan, we send this on a soft opt-in basis — while you are deciding whether to buy and, once it is purchased, as an existing customer — and you can opt out at any time. If you begin using an Application your organization has already purchased, where you were not part of that purchase, we send you CarbonApps marketing only with your consent. For Applications that are entirely free with no paid option (such as our board templates), we send marketing only with your consent. We will give you an opportunity to opt out at or before the time we first contact you for marketing purposes, and every marketing communication will include a one-click opt-out. (Legitimate interests — Art. 6(1)(f), with the PECR soft opt-in exception (UK) and equivalent national ePrivacy law (EEA), for those who evaluate or purchase a paid Application; or your consent — Art. 6(1)(a) — for later users of an already-purchased Application and where no paid option exists.)
CarbonWeb consulting marketing — information about monday.com consulting services from Carbon Web Print LLC. Sent only if you explicitly opt in via the link in your welcome install email (administrators) or first-use email (end users). (Your consent — Art. 6(1)(a).)
Additional communications for account administrators. Because the organization — not the individual user — is the party that subscribes to and enables our Applications, the account administrator acts as the organization’s representative and additionally receives:
Operational and service messages — installation confirmations, quota alerts, and entitlement enforcement for the account. (Necessary to perform the contract — Art. 6(1)(b).)
Governance notices — changes to our Terms of Service and similar contractual or service notices, which the administrator receives on behalf of the organization. Acceptance of changes to our terms is the organization’s, governed by those terms; the administrator is a notice recipient, not an individual acceptor. (Necessary to perform the contract with the organization — Art. 6(1)(b).)
These administrator communications are operational and contractual in nature, not marketing, and continue regardless of your marketing preferences. End users do not receive them. A single person may be both an administrator and an end user; in that case we hold one set of personal data about them and apply whichever uses are relevant to each role.
We do not handle billing. Billing for our Applications is managed by the monday.com Marketplace, and we do not send billing or payment communications.
Providing administrator and end user information is a contractual requirement to use the Applications; without it, we cannot install or maintain the Application.
When an Application is enabled, monday.com’s installation webhook also sends us information about the organization’s monday.com account itself — the account name, account slug, account size, plan type, and account country. This information describes the subscribing organization, not an individual, and in most cases is not personal data under GDPR (Art. 4(1)). It can constitute personal data where the account belongs to a sole trader or otherwise identifies an individual — for example, where the account name or slug contains a person’s name — in which case we treat it under the same lawful bases and protections as the administrator and end user information above.
We use account information to identify the subscribing organization, apply the correct plan entitlements and quotas, and administer the account. (Necessary to perform the contract — Art. 6(1)(b); and, where applicable, legitimate interests in account administration — Art. 6(1)(f).)
When automations run, we collect two distinct categories of metadata:
Account-level usage metrics — automation IDs, function executed, and aggregate counts associated with your monday.com account. We use this for entitlement and quota enforcement against your plan, for capacity planning, and to let you review your account’s usage trends — including when deciding whether your plan still fits your usage. These metrics are retained for 12 months, and are aggregated at the account level and not used to identify individual users. (Legitimate interests in enforcing plan entitlements, capacity planning, and providing usage visibility — Art. 6(1)(f).)
Automation execution audit logs — we track these by account, board, automation ID, and the user the automation runs as, to enable customers to audit our Applications’ activity on their behalf. (Legitimate interests in enabling customers to audit our Applications’ activity on their behalf and in meeting our processor accountability obligations under Arts. 28(3)(h) and 30 — Art. 6(1)(f).)
For Applications that integrate with third-party services you subscribe to, individual users authenticate directly with the third-party service through our Application. We store authentication credentials (encrypted at rest) along with the user IDs needed to link the authentication to the correct user on both platforms.
We use these credentials solely to communicate with the third-party service on the user’s behalf. Credentials are not used for marketing or shared for any other purpose. (Necessary to perform the contract for delivery of the service — Art. 6(1)(b).)
Our Applications process various types of data on your behalf that we do not permanently store. This includes customer data, contact information, messages, call events, and other content that flows through our Applications during automation execution or third-party integration operations.
This data may be held briefly while awaiting processing — typically seconds to minutes. It is encrypted in transit and while held in a processing queue; during active processing it is held transiently in memory and is not persisted. No data in this category is retained beyond the time necessary to complete the operation.
We store configuration data necessary for the operation of our Applications on an account and per-user basis, such as settings, preferences, and automation parameters. This data describes how you have configured the Application but does not include your board item content. For Applications hosted on monday code (the monday.com platform’s developer-hosting environment), this configuration data is stored in monday.com’s Developer Storage rather than in our own systems. (Necessary to perform the contract for delivery of the service — Art. 6(1)(b).)
When troubleshooting issues, we may enable diagnostic logging that captures data from your actual use of the Application. We do this only with your explicit consent (Art. 6(1)(a)), with filters scoped to the specific issue being diagnosed. Logging is automatically disabled at the end of the debug session; you may also withdraw consent at any time by contacting support@carbonapps.co.
Diagnostic logs are retained for 90 days, then automatically purged. You remain the controller of any personal data contained in the customer data that is captured and are responsible for ensuring the relevant individuals have appropriate notice of this processing, where applicable. For that customer data, your enablement of diagnostic logging is a documented processing instruction under the DPA, and we act as your processor; consent under Art. 6(1)(a) is the basis for the personal data involved for which we are controllers.
monday.com identifies only the person who originally enabled an Application to us, and that is the contact we use for the account and governance notifications described above. Because that person may later leave your organization, change roles, or otherwise become unreachable, your account administrator may nominate one or more designated contacts — naming either themselves or another person — so that these notifications continue to reach a responsible recipient:
A designated contact’s details are a name and email address — either an administrator’s own details, which we already hold, where an administrator names themselves, or another person’s details that your administrator provides to us. We use them solely to send the notifications the contact has been designated for; a contact may be designated for one or both types. A designated contact is a notice recipient: where a governance notice concerns a change to our Terms of Service or other terms, acceptance of that change is the organization’s, governed by those terms, and is not an individual act we ask of the contact. Designated contacts are not added to marketing. (Legitimate interests in keeping a reachable point of contact for the account and directing the notices your organization has chosen — Art. 6(1)(f).)
Designation is voluntary — it is your administrator’s decision. If a designated contact is removed, the relevant notifications revert to the account administrator.
Where we obtain a designated contact’s details from your administrator rather than from the contact directly, we notify that contact by email within one month (Art. 14(3)). To stop receiving notifications, ask your account administrator to remove your designation, or exercise your data subject rights with us directly (see Section 13).
When you contact us for support, we collect the information you provide — typically your name, email address, and description of the issue, along with any data you share to help diagnose the problem. We may use your email address to identify your monday.com account and the Applications you use in order to assist you more effectively. Support communications are processed solely to respond to and resolve your request. (Necessary to perform the contract for delivery of the service — Art. 6(1)(b).)
Our Applications are general-purpose business tools and are not designed or authorized for sensitive personal data. You must not use our Applications to process — or direct, submit, or route through them — any of the following:
We are not a HIPAA business associate, offer no Business Associate Agreement, and make no claim of HIPAA compliance. Because we process this data content-blind (Section 11) and only transiently (Section 4.5), we cannot inspect, detect, or filter it — keeping it out of our Applications is your responsibility as the controller. This restriction is in addition to monday.com’s own restrictions on sensitive data, and its binding form is set out in our Data Processing Agreement (Section 5).
Separately, the personal data you process through our Applications must comply with your own agreement with monday.com.
The table below summarizes the lawful bases we rely on by persona and purpose.
| Purpose | Account administrator | End user |
|---|---|---|
| Service delivery | Contract — Art. 6(1)(b) | Contract — Art. 6(1)(b) |
| Administrator operational & governance communications (incl. Privacy Policy / ToS change notices) | Contract — Art. 6(1)(b) | — |
| Account (organization) information | Contract — Art. 6(1)(b) / legitimate interests — Art. 6(1)(f) | — |
| Product updates | Legitimate interests — Art. 6(1)(f) | Legitimate interests — Art. 6(1)(f) |
| CarbonApps marketing | Evaluating/buying a paid-plan app, and afterwards as existing customer: soft opt-in — Art. 6(1)(f) + PECR/ePrivacy (EEA/UK). Later users of an already-purchased app, or free-only apps (e.g. templates): consent — Art. 6(1)(a) | Evaluating/buying a paid-plan app, and afterwards as existing customer: soft opt-in — Art. 6(1)(f) + PECR/ePrivacy (EEA/UK). Later users of an already-purchased app, or free-only apps: consent — Art. 6(1)(a) |
| CarbonWeb consulting marketing | Consent — Art. 6(1)(a) | Consent — Art. 6(1)(a) |
| Notifications to designated contacts (usage and governance notices) | Legitimate interests — Art. 6(1)(f) | — |
| Diagnostic logging | Consent — Art. 6(1)(a) | Consent — Art. 6(1)(a) |
| Runtime metadata / audit logs | Legitimate interests — Art. 6(1)(f) | Legitimate interests — Art. 6(1)(f) |
| Configuration data | Contract — Art. 6(1)(b) | Contract — Art. 6(1)(b) |
| Support communications | Contract — Art. 6(1)(b) | Contract — Art. 6(1)(b) |
| Marketing suppression & preference records | Legal obligation — Art. 6(1)© | Legal obligation — Art. 6(1)© |
| Erasure-request records | Legal obligation — Art. 6(1)© | Legal obligation — Art. 6(1)© |
| Material privacy-policy change notices | Contract — Art. 6(1)(b) (governance communications) | Legal obligation — Art. 6(1)© (Art. 12) |
Necessary to deliver the service covers: service delivery and account communications, authentication with third-party services on your behalf, and configuration data.
Legitimate interests (Art. 6(1)(f)) covers: product updates, CarbonApps marketing to those who evaluate or purchase a paid Application (soft opt-in), runtime metadata, account (organization) information, and notifications to designated contacts. We have carried out a balancing assessment for each, and the relevant factors differ by purpose:
You can object to legitimate-interest processing at any time (Art. 21). For direct marketing the objection is absolute — we will stop on request. For the other purposes, we will honor an objection unless we can demonstrate compelling legitimate grounds or the processing is necessary to provide the service you have installed or to meet our accountability obligations (such as the automation audit logs described below).
Your consent (Art. 6(1)(a)) covers: CarbonWeb consulting marketing, diagnostic logging of customer data, and CarbonApps marketing to later users of an Application your organization has already purchased, or where you have installed only a free Application with no paid option (such as a board template).
Legal obligation (Art. 6(1)©) covers: marketing suppression and preference records, which we keep because the law requires us to honor your objections and opt-outs permanently (Art. 21 GDPR; applicable ePrivacy rules) and to be able to demonstrate that we have (Art. 5(2)); erasure-request records, kept to confirm an erasure request was honored and to prevent accidental re-collection (Art. 17); and notices to end users of material changes to this policy (Art. 12).
Automation execution audit logs also rely on legitimate interests (Art. 6(1)(f)) — we keep them to enable customers to audit our Applications’ activity on their behalf and to meet our accountability obligations as a processor (Arts. 28(3)(h) and 30).
Some of our Applications integrate with third-party services that you subscribe to independently (for example calling/dialer, SMS, accounting, or lead-sourcing services). These services are not our sub-processors. You have your own accounts, your users authenticate directly using their own credentials, and you control what data flows between your monday.com board and the third-party service.
We facilitate the connection on your instructions. Each third-party service’s handling of your data is governed by your own agreement with that service and its own privacy policy, which you can find via the service or the app’s monday.com Marketplace listing.
Some integrated services have characteristics you should account for as the controller of the data you route to or from them:
CarbonApps LLC and Carbon Web Print LLC jointly determine the purposes and means of processing personal data collected through our Applications. We maintain a joint controller arrangement that governs our responsibilities.
Division of responsibilities:
Marketing: Both entities may market their respective products and services to you — CarbonApps markets monday.com apps, CarbonWeb markets monday.com consulting. CarbonApps marketing operates on a soft opt-in basis for those who evaluate or purchase one of our paid Applications (continuing afterwards as existing-customer marketing, with an opt-out at any time), and on a consent basis otherwise — for example for someone who only later uses an Application the organization already purchased, or who has installed only a free board template; CarbonWeb consulting marketing requires your separate explicit consent. The two channels are independent — opting out of one does not affect the other. You can manage your preferences at any time via the link in any of our emails.
Scope: This arrangement covers data collected through our Applications only. If you separately engage Carbon Web Print LLC for consulting, that is an independent relationship governed by its own privacy policy.
The essence of our joint controller arrangement is summarized in this section. The full arrangement is available on request at support@carbonapps.co.
We use third-party service providers that process personal data on our behalf as our processors (Art. 28), each engaged under a written data processing agreement and, where the provider is in a third country, an appropriate transfer safeguard (see Section 9). The categories of recipients are: cloud hosting and infrastructure providers; email-delivery providers (for marketing, transactional, and operational messages); a CRM and marketing-automation/workflow provider; and a support-desk provider. The sub-processors that process the data passing through the Applications on your instructions (Customer Data) — where we act as your processor — are listed and governed separately under our Data Processing Agreement, which provides advance notice of, and a right to object to, changes.
Our infrastructure is located in the United States, and your personal data is processed there. Carbon Web Print LLC is established in the European Union, and the movement of personal data between its EU operations and the United States systems of the same companies is internal to our organization — it is not a disclosure to any other organization and is not a restricted transfer under Chapter V GDPR.
A restricted transfer arises where your personal data is disclosed to one of our service providers in a third country. Each of those transfers is protected by the safeguards in that provider’s data processing agreement — the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum, and equivalent Swiss safeguards — and a copy of the safeguards relied upon for your data is available on request at support@carbonapps.co. For customer data we process on your instructions, the Standard Contractual Clauses incorporated into our customer Data Processing Agreement remain the standing safeguard whether or not any adequacy framework is in force.
Our service providers and sub-processors maintain their own transfer safeguards under their respective data processing agreements. For data you direct to third-party services you subscribe to through our Applications, you are responsible for ensuring your own agreements with those services include appropriate transfer safeguards.
Our Applications run inside the monday.com interface and do not set cookies or use local storage. Any cookies present in your browser while using our Applications are set by monday.com, not by us.
We maintain technical and organizational measures to protect personal data, including encryption of data in transit and at rest, application-layer encryption — under keys we own and control — of the personal information stored in our own systems (name, email address, job title), encryption of stored authentication credentials, access controls on customer data, and no persistent storage of data that passes through our Applications.
For Applications hosted on monday code (the monday.com platform’s developer-hosting environment), those Applications’ configuration and credential data is stored and encrypted by monday.com under its own technical and organizational measures (SOC 2 and ISO 27001 certified) rather than in our systems; the board data those Applications process is still handled transiently and is not persistently stored. You can identify these Applications from the Security and Compliance section of their monday.com Marketplace listing, which denotes them as “hosted by monday.com.”
Data that passes through (customer data, contacts, call events, SMS) is not retained beyond the seconds to minutes needed to complete processing.
Authentication credentials are deleted on uninstall or when the user disconnects from the third-party service.
Administrator and end user information (Section 4.1) and account (organization) information (Section 4.2) used for service delivery is deleted within 30 days of uninstallation or account closure, unless retention is required by law. Contact information you have provided for marketing purposes is retained until you opt out — uninstallation does not automatically remove you from marketing communications. You can opt out at any time via the link in any of our emails.
Configuration data is retained while the associated Application features remain active, then deleted.
Diagnostic logs are retained for 90 days, then automatically purged.
Account-level usage metrics (see Section 4.3) are retained for 12 months, then deleted. This period lets you review your account’s usage trends against your plan and lets us enforce entitlements and plan capacity. These metrics are aggregated at the account level and do not identify individual users.
Automation execution audit logs (see Section 4.3) are retained for 90 days — aligned with the minimum retention period under the monday.com Marketplace Listing Terms — to support our processor accountability under GDPR Articles 28 and 30 and to enable customers to audit our Applications’ activity on their behalf. After 90 days, execution logs are automatically purged.
Designated contact data is deleted when the account administrator removes the designation, or within 30 days of uninstallation or account closure, whichever comes first.
Support records are retained for three years from the date of the last interaction on the ticket, then deleted.
Marketing opt-out records: If you opt out of marketing, we keep a record to identify your email address so we know not to contact you again. We use this record only to honor opt-outs — not for any other purpose.
Erasure request records: If you exercise your right to erasure (Art. 17), we delete your personal data and keep a minimal record to identify your email address and the date of erasure. We use this record only to confirm we have honored your request and to ensure we do not accidentally re-collect or re-process your data — not for any other purpose.
If you later reinstall and use one of our Applications, we will collect personal data again under a fresh service relationship. Any marketing opt-out from before your erasure remains in effect — to receive marketing again, you would need to opt in explicitly through the email preferences link in our emails.
If you are an active user and request deletion, we will delete everything not necessary to deliver the service (such as removing you from marketing). To delete all data, uninstall the Application.
You have the right to:
You may exercise these rights against either CarbonApps LLC or Carbon Web Print LLC. Contact support@carbonapps.co (preferred) or contact@carbonweb.co; either will accept and process your request. We will respond without undue delay and within one month of receipt, extendable by up to two further months for complex or numerous requests (Art. 12(3)). We may need to verify your identity before responding, using the minimum information necessary.
For data that passes through our Applications: We do not store it, with one limited exception: where you enable diagnostic logging (Section 4.7), customer data captured for that purpose is held in our logs for up to 90 days before automatic deletion. You are the controller of that data, so rights requests concerning it — including erasure — should be directed to you and handled through your own processes; we will assist to the extent technically possible. For diagnostic logs that assistance is bounded — the logs are scoped to minimize what is captured and are automatically purged at the end of the retention period, but our shared logging infrastructure does not permit deleting individual records before then. Rights requests relating to data held by monday.com or any third-party service you connect through our Applications should be directed to those services or handled through your own processes as data controller.
Scope: A rights request covers data processed under this policy only. If you also have a consulting relationship with Carbon Web Print LLC, contact them separately for data related to that engagement.
Automated decision-making: We do not engage in automated decision-making, including profiling, that produces legal effects or similarly significant effects concerning you (Art. 22).
You have the right to lodge a complaint with your local data protection supervisory authority. For individuals in the EU/EEA, a directory of national supervisory authorities is available at edpb.europa.eu. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet, datatilsynet.dk). For individuals in the UK, contact the Information Commissioner’s Office at ico.org.uk. For individuals in Switzerland, contact the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
California (CCPA/CPRA): You have the right to know what personal information we collect about you, to delete it, to correct it, and to non-discrimination for exercising your rights. To submit a request, contact support@carbonapps.co. We will respond within 45 days.
We do not sell or share your personal information as those terms are defined under CCPA/CPRA, and we do not use or disclose sensitive personal information beyond what is necessary to provide our services.
Categories collected: Identifiers (name, email, user IDs, account slug), professional information (job title, admin status), internet or electronic activity (automation metadata), and geolocation (country-level only).
Categories of third parties we disclose PI to: Our service providers (processors) — cloud hosting and infrastructure, email delivery, CRM and marketing automation, and support-desk providers — each engaged under a written contract. Third-party services you connect through our Applications are independent controllers you subscribe to directly — we do not disclose your personal information to them; you direct data to them as controller.
Retention: See Section 12 for retention periods applicable to each category.
Other US states with privacy laws: Similar rights apply. Appeal any decision by contacting support@carbonapps.co.
Our Applications are business-to-business services and are not directed to, marketed to, or made available for use by anyone under 18, and we do not knowingly provide them for use by anyone under 18. A customer remains responsible for any personal data of children or other minors it processes through the Applications — including having a lawful basis, obtaining any consents required under applicable law, and complying with its own agreement with monday.com (which restricts the categories of data permitted on the platform).
We may update this policy from time to time. We will communicate material changes by email to the active individuals whose personal data we hold under this policy — both account administrators and end users — because such changes concern you as a data subject (Art. 12). The “Last Updated” date above will reflect changes, and the current version is always available at the link published with each Application. Prior versions are available on request.
CarbonApps LLC (designated contact point) Email: support@carbonapps.co
Carbon Web Print LLC (joint controller) Email: contact@carbonweb.co
EU Establishment Carbon Web Print LLC and CarbonApps LLC are each established in the European Union.