Data Processing Addendum
Last updated: July 27, 2026
Processor: Kusterer & Müller GbR, doing business as Gorilla Apps
Product: Client Portal Builder for monday.com
This Data Processing Addendum, including its annexes (the “DPA”), forms part of the agreement governing the Customer's use of Client Portal Builder for monday.com (the “Agreement”) between:
- The customer accepting the Agreement (the “Customer”)
- Kusterer & Müller GbR, doing business as Gorilla Apps, Hagbergstrasse 11, 70188 Stuttgart, Germany (“Gorilla Apps”)
This DPA applies when Gorilla Apps processes Customer Personal Data on the Customer's behalf in connection with Client Portal Builder (the “Services”). It takes effect on the date the Customer accepts the Agreement or the parties otherwise agree to this DPA (the “Effective Date”).
1. Definitions
1.1 “Applicable Data Protection Law” means Regulation (EU) 2016/679 (“GDPR”) and applicable EU or EEA Member State laws implementing or supplementing the GDPR.
1.2 “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processor,” “Special Category Data,” “Supervisory Authority,” and “Subprocessor” have the meanings given to them by Applicable Data Protection Law.
1.3 “Customer Personal Data” means Personal Data that Gorilla Apps processes as a Processor or Subprocessor on the Customer's behalf in providing the Services. It excludes Personal Data for which Gorilla Apps determines the purposes and means of processing as an independent Controller under Section 10.
1.4 “Standard Contractual Clauses” means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 or a replacement transfer mechanism approved under the GDPR.
2. Scope, roles and instructions
2.1 The Customer is a Controller of Customer Personal Data or a Processor acting on behalf of another Controller. Gorilla Apps is a Processor or, where the Customer is itself a Processor, a Subprocessor.
2.2 If the Customer acts as a Processor, the Customer confirms that the relevant Controller has authorized the Customer to appoint Gorilla Apps and Gorilla Apps' Subprocessors. The Customer remains the single point of contact for Gorilla Apps unless Applicable Data Protection Law requires otherwise.
2.3 Gorilla Apps will process Customer Personal Data only:
- On the Customer's documented instructions
- To provide, secure, support and maintain the Services as described in the Agreement, this DPA and the Customer's configuration of the Services
- To comply with other reasonable written instructions that are consistent with the Agreement
- Where Union or Member State law requires the processing, in which case Gorilla Apps will inform the Customer before processing unless the law prohibits that notice on important grounds of public interest
2.4 The Agreement, this DPA, the Customer's use and configuration of the Services, and written support requests are the Customer's complete documented instructions as of the Effective Date. Additional instructions that materially change the scope or cost of the Services require written agreement between the parties.
2.5 The subject matter, duration, nature and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.
2.6 Gorilla Apps will promptly inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Gorilla Apps may suspend the affected processing until the parties resolve the issue.
3. Gorilla Apps' obligations
Gorilla Apps will:
3.1 Ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
3.2 Implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, as described in Annex 2.
3.3 Taking into account the nature of the processing, assist the Customer through appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights.
3.4 Taking into account the nature of processing and the information available to Gorilla Apps, reasonably assist the Customer with the Customer's obligations concerning security, Personal Data Breaches, data protection impact assessments and prior consultation with Supervisory Authorities.
3.5 Maintain records and information sufficient to demonstrate compliance with this DPA and make them available to the Customer as described in Section 9.
3.6 Comply with Section 5 before appointing a Subprocessor.
3.7 Delete or return Customer Personal Data at the end of the Services as described in Section 8 and Annex 1, unless applicable law requires continued storage.
4. Customer obligations
4.1 The Customer is responsible for:
- The lawfulness, fairness and transparency of its processing
- Providing all required notices and obtaining any required consents or other lawful basis
- The accuracy, quality and legality of Customer Personal Data and the means by which it was obtained
- Configuring and using the Services in accordance with the Agreement and Applicable Data Protection Law
- Responding to Data Subjects and Supervisory Authorities, except for the assistance Gorilla Apps must provide under this DPA
- Ensuring its instructions do not cause Gorilla Apps to violate Applicable Data Protection Law
4.2 The Services are not designed for processing Special Category Data or criminal-conviction data. The Customer will not submit such data unless the parties have first agreed in writing on the processing and any additional safeguards it requires.
4.3 The Customer will use reasonable security measures for its monday.com account, administrator access, portal configuration and credentials, and will promptly notify Gorilla Apps of suspected unauthorized access affecting the Services.
5. Subprocessors
5.1 The Customer gives Gorilla Apps general written authorization to engage the providers identified as Subprocessors in Annex 3 to process Customer Personal Data for the limited purpose of providing the Services. Providers identified only as customer-selected or independent third-party platforms are listed for transparency and are not appointed as Gorilla Apps' Subprocessors for those processing operations.
5.2 Gorilla Apps will enter into a written agreement with each Subprocessor that imposes data protection obligations providing materially equivalent protection to the obligations applicable to Gorilla Apps under this DPA, to the extent required by Applicable Data Protection Law.
5.3 Gorilla Apps remains responsible to the Customer for a Subprocessor's performance of its data protection obligations to the extent required by Applicable Data Protection Law.
5.4 Gorilla Apps will maintain a current public Subprocessor list and provide at least 15 days' advance notice before a new or replacement Subprocessor begins processing Customer Personal Data. A Customer may designate one or more addresses for these notices by emailing hello@getgorilla.app with the subject “Subprocessor change notifications” and identifying its legal name and monday.com account. Until the Customer designates an address, Gorilla Apps will send notice to the monday.com account or billing contact reasonably available to Gorilla Apps. The Customer is responsible for keeping its designated address current.
5.5 The Customer may object to a new or replacement Subprocessor on reasonable, documented data-protection grounds by notifying Gorilla Apps during the 15-day notice period. The parties will work in good faith to address the objection. If Gorilla Apps cannot provide the affected Services without that Subprocessor and cannot reasonably resolve the objection, the Customer may terminate the affected Services before the Subprocessor begins processing. Any refund will be governed by the Agreement.
6. International transfers
6.1 Gorilla Apps will not transfer Customer Personal Data to a country outside the European Economic Area, or permit access from such a country, unless the transfer complies with Applicable Data Protection Law.
6.2 Gorilla Apps may rely on an adequacy decision or another lawful transfer mechanism. Where required and no other valid transfer mechanism applies, Gorilla Apps will enter into the applicable Standard Contractual Clauses with the relevant data exporter or Subprocessor and implement supplementary measures where required by Applicable Data Protection Law.
6.3 At the Customer's reasonable request, Gorilla Apps will provide information reasonably necessary for the Customer to assess transfers of Customer Personal Data, subject to confidentiality and security restrictions.
6.4 Customer content and client account data stored in monday.com follow the Customer's selected monday.com EU, US, or Israel (IL) region. The limited operational systems described in Annex 1 use Cloudflare's global infrastructure, a Render PostgreSQL database in Oregon, United States, and a Gorilla Apps-managed backup server hosted by Hetzner in Finland. These operational systems are not partitioned by Customer region.
7. Personal Data Breaches
7.1 Gorilla Apps will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 To the extent the information is available, the notice will describe:
- The nature of the Personal Data Breach, including the affected categories of Data Subjects and data
- The likely consequences
- The measures taken or proposed to address and mitigate the Personal Data Breach
- A contact for follow-up information
7.3 Gorilla Apps may provide information in phases as it becomes available. Gorilla Apps' notice is not an admission of fault or liability.
7.4 Gorilla Apps will take reasonable steps to contain, investigate, mitigate and remediate a Personal Data Breach and will reasonably cooperate with the Customer's legally required notifications. The Customer is responsible for deciding whether to notify a Supervisory Authority, Data Subjects or third parties unless Applicable Data Protection Law assigns that responsibility to Gorilla Apps.
8. Return and deletion
8.1 During the term, the Customer may access, correct, export or delete Customer Personal Data through monday.com and the functionality of the Services, subject to the Agreement.
8.2 On termination of the Services, Gorilla Apps will, at the Customer's choice, delete Customer Personal Data or return it where technically available, and delete existing copies unless applicable law requires storage. Where return is not technically available for a category of operational data, Gorilla Apps will delete it.
8.3 When the Customer uninstalls the app, Gorilla Apps loses access to the Customer's monday.com account and the portal content and client account data stored there. That data remains under the control of the Customer and monday.com and is subject to their separate relationship; Gorilla Apps does not retain a separate application-database copy.
8.4 Unless the Customer gives a contrary written instruction before termination, the Customer instructs Gorilla Apps to delete the remaining Customer Personal Data in Gorilla Apps' operational systems in accordance with Annex 1. Gorilla Apps will run its operator-reviewed account cleanup process at least once each calendar month. During each run, Gorilla Apps will delete operational data for accounts that have uninstalled the app, have not reinstalled it and have no active subscription. A verified deletion request will be reviewed and, where no continuing contractual or legal basis requires retention, completed no later than the next monthly cleanup run, except for:
- Data that remains in the Customer's own monday.com account and is controlled by the Customer and monday.com
- Data in backups that cannot reasonably be isolated, which will remain protected and be deleted according to the applicable backup cycle
- Data that Gorilla Apps must retain under applicable law, which will be isolated from further processing except as legally required
8.5 On request, Gorilla Apps will provide written confirmation that deletion under this Section has been completed.
9. Information and audits
9.1 Gorilla Apps will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. Gorilla Apps may satisfy requests initially through current security documentation, architecture descriptions, questionnaires, third-party reports or other relevant materials.
9.2 If those materials are not reasonably sufficient, the Customer may conduct one audit in any 12-month period, and additional audits following a Personal Data Breach or where a Supervisory Authority requires one. Audits must:
- Be requested with at least 30 days' written notice unless urgent circumstances make that impracticable
- Occur during normal business hours
- Be limited to systems, records and personnel relevant to the Customer's processing
- Avoid unreasonable disruption and risks to other customers or Gorilla Apps' security
- Be conducted by the Customer or an independent auditor that is not a competitor of Gorilla Apps and is bound by confidentiality
9.3 The Customer will bear its audit costs. Gorilla Apps may charge reasonable costs for assistance beyond the information it ordinarily makes available, unless the audit identifies a material breach of this DPA by Gorilla Apps.
9.4 Nothing in this Section requires Gorilla Apps to disclose information that would compromise another customer's confidentiality, reveal security-sensitive information without appropriate safeguards, or violate applicable law.
10. Gorilla Apps as an independent Controller
10.1 This DPA does not apply to Personal Data for which Gorilla Apps independently determines the purposes and means of processing, such as business contact, billing, fraud-prevention, legal-compliance and direct customer-support records, except to the extent those activities are performed solely on the Customer's documented instructions.
10.2 Gorilla Apps will process such Personal Data in accordance with its Privacy Policy and Applicable Data Protection Law. If the same data is used both to provide the Services on the Customer's instructions and for a separate Controller purpose, this DPA applies to the Processor activity only.
11. Liability
11.1 Each party's liability arising from this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent Applicable Data Protection Law prohibits such limitation.
11.2 Nothing in this DPA limits a Data Subject's rights or either party's liability to a Supervisory Authority under Applicable Data Protection Law.
12. Order of precedence, term and governing law
12.1 If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. Standard Contractual Clauses prevail over this DPA to the extent of any conflict concerning a transfer governed by those clauses.
12.2 This DPA remains in effect while Gorilla Apps processes Customer Personal Data, including during any post-termination retention period.
12.3 Amendments required to comply with a change in Applicable Data Protection Law may be made on written notice, provided they do not materially reduce the protection of Customer Personal Data.
12.4 The governing-law and dispute-resolution provisions of the Agreement apply to this DPA, without prejudice to rights that cannot lawfully be restricted. The Agreement currently applies German law and provides for jurisdiction in Stuttgart, Germany.
13. Contact and acceptance
13.1 Data protection notices and requests under this DPA may be sent to:
Kusterer & Müller GbR (Gorilla Apps)
Hagbergstrasse 11
70188 Stuttgart
Germany
Email: hello@getgorilla.app
13.2 The Customer's notice address is the account or billing contact associated with its monday.com account unless it designates another address in writing. To designate addresses specifically for Subprocessor notices, the Customer must follow the email-registration process in Section 5.4. If a designated message is returned as undeliverable, Gorilla Apps may use another account or billing contact reasonably available to it.
13.3 This DPA may be accepted electronically, incorporated into the Agreement by reference, or signed in counterparts. A Customer requiring a countersigned copy may request one at the address above.
Annex 1 — Details of processing
A. Subject matter and purpose
Processing necessary to provide Client Portal Builder, which allows the Customer to configure a client-facing portal connected to its monday.com account; authenticate portal users; retrieve and display Customer-selected monday.com content; permit Customer-configured interactions with that content; process temporary file uploads; support optional Google login; operate, secure, troubleshoot and improve the Services; and manage the app lifecycle.
Gorilla Apps does not maintain a separate application-database copy of the Customer's client account records. Client names, email addresses and password hashes are stored in the Customer's own monday.com account. Limited operational data is processed outside that storage as described below.
B. Duration
For the term of the Agreement and the retention periods in Section F below, unless the Customer instructs Gorilla Apps to delete data earlier and the Agreement and Applicable Data Protection Law permit that deletion.
C. Nature of processing
Collection, receipt, access, retrieval, transmission, routing, organization, storage, caching, encryption, hashing, authentication, display, consultation, logging, analysis, restriction, deletion and destruction, as necessary to provide and secure the Services.
D. Categories of Data Subjects
Depending on the Customer's use of the Services:
- Customer personnel, monday.com users, administrators and app installers
- The Customer's clients, prospective clients, suppliers, contractors and other business contacts
- Authorized and attempted users of a Customer-configured client portal
- Individuals whose Personal Data the Customer chooses to place in monday.com boards, items, updates, files, forms or other content made available through a portal
E. Categories of Customer Personal Data
Depending on the Customer's configuration and content:
- Portal and monday.com content: Names, contact details, organization and role information, board and item content, updates, comments, files, images, status information and any other Personal Data the Customer chooses to expose through the portal
- Client account data: First and last name, email address, password hash, optional account comment, account status and identifiers
- Google login data, when enabled by the Customer: Google account identifier stored in the Customer's monday.com account; email address handled transiently for identity matching and hashing; display name and profile-image URL carried in the signed session token
- Authentication and session data: Portal identifier, client item identifier, pseudonymous account identifier, authentication method, signed session claims and timestamps
- Temporary uploads and cached media: Uploaded files, file metadata, image thumbnails and related object keys
- Pseudonymous analytics: Request path, portal identifier, client item identifier, pseudonymous account identifier derived from a truncated hash of the email address, request method, duration and response status
- App lifecycle and subscription data: monday.com account identifier; install, uninstall, trial and subscription event type and date; encrypted event payloads that may include app installer name and email, country, account name and slug, account tier and subscription details
- Security and application logs: Timestamps, request and trace identifiers, portal or account identifiers, error and diagnostic information, and IP addresses on the monday-side app-management path. The client-portal application logger does not intentionally add end-user IP addresses or user-agent strings, although infrastructure providers may process network metadata at the edge
F. Storage locations and retention
| Data category | System and location | Retention / deletion |
|---|---|---|
| Portal content and client account data | Customer's monday.com account in the Customer's selected monday.com EU, US, or Israel (IL) region | Controlled through the Customer's monday.com account and app settings. Gorilla Apps' access is lost on uninstall. The Customer and monday.com may retain or delete data under their separate relationship. |
| monday.com access token | monday.com-managed HashiCorp Vault | For the app installation lifecycle; access is revoked or lost on uninstall. |
| Signed session token | Secure, HTTP-only browser cookie; claims are processed by Gorilla Apps | Individual access tokens expire after five minutes. Sessions have a seven-day absolute maximum that renewal does not extend. |
| Temporary file uploads | Cloudflare R2 / global infrastructure | Up to 24 hours under the configured lifecycle rule. |
| Cached image thumbnails | Cloudflare R2 / global infrastructure | Up to six days under the configured lifecycle rule. |
| Pseudonymous request analytics | Cloudflare Analytics Engine / global infrastructure | Up to 90 days. |
| Portal routing and registry metadata | Cloudflare D1 / not partitioned by Customer region | The cleanup process runs at least once each calendar month. Eligible account data is deleted during the next run after uninstall, provided the account has not reinstalled and has no active subscription. |
| Rate-limit counters | Cloudflare KV / global infrastructure | Credential-login counters expire after ten minutes. |
| App lifecycle and subscription events | Render PostgreSQL in Oregon, United States, through Cloudflare Hyperdrive; Render uses Amazon RDS | The cleanup process runs at least once each calendar month. Eligible account data is deleted during the next run after uninstall, provided the account has not reinstalled and has no active subscription. |
| Workers Logpush application-log archive | Cloudflare R2 / global infrastructure | Up to 90 days under the configured lifecycle rule. Logs may include monday-side administrator IP addresses and other request, error and diagnostic metadata. |
| Cloudflare Workers Observability logs | Cloudflare Workers Logs / global infrastructure | Up to seven days on the Workers Paid plan. |
| Cloudflare Workers metrics | Cloudflare Workers metrics / global infrastructure | Up to three months. Metrics are aggregated operational telemetry rather than application log messages. |
| Gorilla Apps-managed PostgreSQL backups | Hetzner Online GmbH / Finland | Up to three months. These backups may contain the app lifecycle and subscription-event data held in the production PostgreSQL database. |
| Render-managed PostgreSQL backups | Render Services, Inc. / Oregon, United States | Up to seven days. |
G. Special Category Data
No Special Category Data or criminal-conviction data is intentionally required by the Services. The Customer must not submit such data unless separately agreed in writing under Section 4.2.
H. Frequency
Continuous or as initiated by the Customer, its authorized users and portal users during the term of the Agreement; lifecycle and retention operations occur as needed.
Annex 2 — Technical and organizational measures
The measures below describe the current Client Portal Builder architecture. Gorilla Apps may update them as technology and risks evolve, provided the overall protection of Customer Personal Data is not materially reduced.
1. Data minimization and architecture
- Client names, email addresses and password hashes are stored in the Customer's own monday.com account rather than in a separate Gorilla Apps application database
- Gorilla Apps uses limited routing metadata and pseudonymous analytics outside monday.com to operate and monitor the Services
- Google login is optional and enabled per portal. The email address is used transiently for verification and identity matching; Gorilla Apps stores a derived account identifier rather than the raw email in its analytics system
- Operational datasets are separated by purpose, including routing, rate limiting, cached media, analytics and lifecycle events
2. Regional storage and infrastructure
- Portal content and client account data follow the Customer's selected monday.com EU, US, or Israel (IL) region
- Cloudflare provides the global application-delivery and operational-data infrastructure. D1, KV, R2, Analytics Engine and Hyperdrive are not all partitioned by Customer region
- Render Services, Inc. hosts the PostgreSQL lifecycle-event database using Amazon RDS in its Oregon, United States region. Cloudflare Hyperdrive provides the connection from the event-processing service to that database
- monday.com access tokens are held in monday.com-managed HashiCorp Vault rather than in the application database
3. Encryption, hashing and secrets
- Network traffic to the Services is encrypted in transit using HTTPS/TLS
- Client passwords are hashed using scrypt with a per-password random salt and are compared using a timing-safe comparison
- App lifecycle event payloads are encrypted at rest using AES-256 with a random initialization vector. Account identifiers, event types and timestamps in that database are not encrypted at the application layer
- Session tokens are cryptographically signed using a server-side secret held outside the client application
- Production credentials and infrastructure secrets are restricted to authorized systems and personnel
4. Authentication and session security
- Credential-login attempts are rate-limited to five failed attempts in ten minutes per portal and email address
- Client-portal access tokens expire after five minutes and carry a seven-day absolute maximum expiry that renewal does not extend
- Session verification checks the cryptographic signature, issuer, subject and absolute expiry
- Session cookies are configured as secure and HTTP-only with an appropriate SameSite setting for the embedded and client-facing architecture
- Google login verifies the Google identity token and requires a verified email address
5. Access control and confidentiality
- Access to production systems and Customer Personal Data is limited to personnel who require it to operate, secure or support the Services
- Authorized personnel are subject to confidentiality obligations
- Administrative access uses individual accounts and multi-factor authentication where supported
- Access is removed promptly when no longer required
6. Logging, monitoring and resilience
- Application logs are used for security, reliability and troubleshooting. Portal-side logs are keyed to portal and pseudonymous account identifiers rather than intentionally adding end-user IP addresses
- The monday-side administrative path may include the administrator's IP address in application logs. Cloudflare may also process network metadata at the edge
- Workers Trace Event logs are exported through Cloudflare Logpush to a Cloudflare R2 bucket and retained for up to 90 days under a lifecycle rule
- Cloudflare Workers Observability retains Workers Logs for up to seven days on the Workers Paid plan. Workers metrics remain available for up to three months
- Pseudonymous request analytics record paths, identifiers, method, duration and status, but not the contents of monday.com boards
- Service health and production errors are monitored
- Gorilla Apps creates PostgreSQL database backups, stores them on a Hetzner-hosted server in Finland and retains them for up to three months. Render separately retains managed PostgreSQL backups or point-in-time recovery data for up to seven days
7. Secure development and vulnerability management
- Source changes are maintained in version control and undergo review and automated checks appropriate to the change
- Dependencies and infrastructure are updated in response to material security risks
- Security issues are triaged according to severity and remediated in a risk-based timeframe
- Production and non-production environments and credentials are separated
8. Incident response
- Gorilla Apps maintains procedures for identifying, containing, investigating, remediating and documenting security incidents under its approved Security Incident Response Plan
- Evidence and relevant logs are preserved as appropriate during an investigation
- The Customer is notified of a Personal Data Breach as required by Section 7
9. Deletion and disposal
- Customer-controlled deletion functions remove client account data from monday.com storage
- Uninstalling the app causes Gorilla Apps to lose access to the Customer's monday.com account and the portal content and client account data stored there. Gorilla Apps does not retain a separate application-database copy of those records
- At least once each calendar month, an operator-reviewed cleanup tool identifies accounts that uninstalled the app, did not reinstall and have no active subscription. On approval, it deletes portal custom hostnames, portal secure-storage entries, D1 routing and portal records, and PostgreSQL app lifecycle events for the account
- Cloudflare lifecycle rules remove temporary uploads and cached thumbnails according to Annex 1
10. Review and improvement
- Gorilla Apps reviews the appropriateness of these measures in light of changes to the Services, identified risks and security incidents
- Material changes that reduce protection are governed by the Agreement and this DPA
Annex 3 — Authorized Subprocessors and third-party platforms
| Provider | Role and purpose | Data involved | Processing location / transfer safeguard |
|---|---|---|---|
| monday.com Ltd. and applicable affiliates | Customer-selected platform for the Customer's monday.com account, boards and APIs; Gorilla Apps Subprocessor for monday Code hosting and developer storage, including secure storage for app access tokens | Portal and board content, client account data, access token, account and portal identifiers | Customer-selected EU, US, or Israel (IL) region for regional Customer Data; limited global processing may apply under monday.com's terms. The monday Code terms state that monday.com processes End User Data on the app developer's behalf under the monday Developer Storage DPA. |
| Cloudflare, Inc. and applicable affiliates | Workers, network delivery, D1, KV, R2, Analytics Engine and Hyperdrive connection services | Requests and network metadata, routing records, temporary files, cached thumbnails, rate-limit counters, pseudonymous analytics, encrypted lifecycle payloads in transit to the database | Global network, including the EEA and United States. Cloudflare's published DPA relies on the EU-US Data Privacy Framework where applicable and incorporates the EU Standard Contractual Clauses as a fallback transfer mechanism. |
| Google LLC and applicable regional affiliates | Optional customer-configured Google Sign-In identity service; independent controller/third-party identity provider rather than a Gorilla Apps Subprocessor | Google identity token, email address during verification, Google account identifier, display name and profile-image URL | Global, including the United States and applicable regional Google entity. The Customer supplies the Google client ID and enables the feature; portal users choose whether to sign in with Google. The Google APIs Terms incorporate Google's Controller-Controller Data Protection Terms. |
| Render Services, Inc. | Hosting the PostgreSQL app lifecycle and subscription-event database using Amazon RDS; database access is routed through Cloudflare Hyperdrive | monday.com account identifier, event type and timestamp, encrypted event payload containing installer, account and subscription details | Oregon, United States. Render's published DPA relies on the EU-US Data Privacy Framework where applicable and incorporates the EU Standard Contractual Clauses as a fallback transfer mechanism. |
| Hetzner Online GmbH | Hosting the Gorilla Apps-managed PostgreSQL backup server | Backups of the app lifecycle and subscription-event database | Finland, within the EEA. |
The infrastructure providers' own Subprocessors may also process data under their respective agreements with Gorilla Apps. Relevant provider disclosures are available from the respective providers.
For clarity:
- The Customer selects and maintains its own relationship with monday.com for the monday.com account and Customer Data held there. monday.com is treated as Gorilla Apps' Subprocessor only for the monday Code and developer-storage operations that monday.com performs on Gorilla Apps' behalf
- Google Sign-In is an optional third-party identity service configured with a Google client ID supplied by the Customer. Google is not treated as Gorilla Apps' Subprocessor for that controller-to-controller service