Effective date: July 1, 2026 | Last updated: July 1, 2026
This page lists the Customer Data sub-processors for the CarbonApps monday.com Applications — the third parties we engage to process the data that passes through the Applications on your instructions, where we act as your processor under the Data Processing Agreement (DPA).
We give at least 14 days’ notice before adding or replacing a sub-processor. To object, contact support@carbonapps.co within that period.
For Applications hosted on our own cloud infrastructure, monday.com is the platform the Applications run on and is not a Customer Data sub-processor. For Applications hosted on monday code (the monday.com platform’s developer-hosting environment), monday.com Ltd acts as a Customer Data sub-processor and is listed below. Third-party services that you subscribe to and connect through the Applications (for example PhoneBurner, RingCentral, Freshbooks, or Dux-Soup) are not our sub-processors — they are independent services you engage directly.
The service providers we engage as joint controllers for account, administrator/end-user, and marketing data are separate from the Customer Data chain and are described by category in our Privacy Policy.
These process Customer Data on your documented instructions under the DPA. Customer Data is processed transiently and is not persistently stored except for consent-based diagnostic logs (see the DPA). monday.com Ltd applies only to Applications hosted on monday code. You can tell which Applications those are from the Security & Compliance section of each Application’s monday.com Marketplace listing, which denotes them as “hosted by monday.com.”
| Sub-processor | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Amazon Web Services, Inc. (AWS) | Cloud hosting and infrastructure for the Applications hosted on our own infrastructure; transient processing of Customer Data during automation, view, and integration execution | Any Customer Data the customer directs through the Applications (transient) | United States | EU Standard Contractual Clauses in AWS’s data processing addendum, with application-layer encryption under keys we control as a supplementary measure |
| monday.com Ltd | Developer-hosting (monday code) for the Applications hosted on monday code: transient processing of Customer Data during execution, plus storage of those Applications’ configuration and authentication credentials in monday storage. monday code is monday.com’s own infrastructure; monday.com manages its encryption and keys (SOC 2 / ISO 27001 certified) | Configuration and authentication credentials for the monday-code-hosted Applications; transient Customer Data during execution | Israel (with monday.com’s own onward hosting in the United States) | Israel adequacy decision (Art. 45 GDPR) for the transfer to monday.com Ltd; monday.com’s onward transfers to its own sub-processors (Amazon Web Services and Google LLC, United States) under monday.com’s Standard Contractual Clauses, per the monday.com Developer Storage data processing addendum |
Our own infrastructure is located in the United States, and Customer Data processed on it is handled there transiently. Applications hosted on monday code instead run on monday.com’s Developer Storage infrastructure: monday.com Ltd (Israel, with monday.com’s own onward hosting in the United States) stores those Applications’ configuration and credentials and manages their encryption, while the customer board data they process remains transient.
The transfer safeguard for a sub-processor in a third country is the Standard Contractual Clauses (or other Article 46 GDPR safeguard) in that provider’s data processing agreement, or an adequacy decision where one applies. A copy of the safeguards relied upon for your data is available on request at support@carbonapps.co.