Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains how Kusterer & Müller GbR, doing business as Gorilla Apps (“Gorilla Apps,” “we,” “us” or “our”), processes Personal Data when you visit our websites, contact us or use one of our applications or services.

It applies to all websites and applications operated by Gorilla Apps unless a product-specific notice says otherwise. These Services include the Gorilla Apps website, Client Portal Builder, Spreadsheet Gorilla, Board to Website Widget, Exported Excel Cleaner and our public system-status page.

1. Who we are

The responsible business is:

Kusterer & Müller GbR (Gorilla Apps)
Hagbergstrasse 11
70188 Stuttgart
Germany
Email: hello@getgorilla.app

For processing where Gorilla Apps determines why and how Personal Data is used, Gorilla Apps is the Controller.

2. When we are a Controller and when we are a Processor

Our role depends on the processing activity:

  • Gorilla Apps as Controller. We act as Controller for our website, business contacts, support communications, app-installation and subscription administration, billing, security, fraud prevention, and product analytics used for our own business purposes
  • Gorilla Apps as Processor. When a customer uses a Gorilla Apps product to process content from its monday.com account or another connected service, the customer normally determines the purposes and means of that processing. The customer is the Controller and Gorilla Apps processes that Customer Data on the customer's instructions
  • Customer-selected platforms. Customers maintain their own relationships with platforms such as monday.com. Those platforms may process data under their own terms and privacy notices. A platform may also act as our Subprocessor for a specific hosting or developer-storage operation

If you use a customer-configured portal, widget, report or other service and want to exercise rights concerning Customer Data, contact the relevant customer first. We will assist that customer as required by our agreement and applicable law.

The Client Portal Builder Data Processing Addendum describes the data-processing terms that apply when Gorilla Apps processes personal data on a Customer's behalf.

3. Personal Data we process

The data we process depends on the product, its configuration and how you interact with us.

3.1 Information you provide directly

We may process:

  • Your name, email address, organization and job role
  • Support requests, messages, feedback and related correspondence
  • Account, billing and transaction information
  • Preferences for product, service and Subprocessor communications
  • Any other information you choose to provide to us

Please do not include sensitive or unrelated Personal Data in support messages.

The contact form on getgorilla.app collects first name, last name, email address, monday.com account slug, selected app and subject, and the message. Contao does not retain a database copy of the submission. It sends the message to the hello@getgorilla.app mailbox hosted by ALL-INKL.COM.

The public website at clientportalbuilder.com is also operated by Gorilla Apps. When you visit it, we and our infrastructure providers may process the website and technical information described in Section 3.2.

3.2 Website and technical information

When you visit our website or use our applications, we and our infrastructure providers may process:

  • IP address and approximate location derived from it
  • Browser, device and operating-system information
  • Requested pages or application routes, date and time
  • Referrer information
  • Request, trace and error identifiers
  • Response status, duration and diagnostic information
  • Security events and information used to prevent abuse

We do not use Google Analytics on getgorilla.app or clientportalbuilder.com.

We do not use this information to make decisions that produce legal or similarly significant effects about you.

3.3 monday.com app installation and lifecycle information

When a Gorilla Apps monday.com app is installed, used, subscribed to or uninstalled, we may process:

  • monday.com account and user identifiers
  • Installer name and email address
  • Account name, slug, country and plan or tier
  • App installation, uninstall, trial and subscription events and dates
  • Subscription and billing-status information supplied through monday.com

Event payloads stored in our application database are encrypted at the application layer. Account identifiers, event types and timestamps are not encrypted at that layer.

3.4 Customer Data accessed through connected services

Depending on the product and the customer's configuration, our applications may access or otherwise process:

  • monday.com board, workspace, item, column, update, comment and file data
  • Names, contact information, roles and other information placed in Customer Data
  • Board and report configuration, filters and templates
  • User and account identifiers and authorization tokens
  • Content selected for display, export, transformation or delivery

The customer controls which data it places in the connected platform and makes available to the product. Gorilla Apps does not require customers to submit Special Category Data or criminal-conviction data. Customers should not use a product for such data unless the processing is lawful and any required safeguards have been agreed.

3.5 Client Portal Builder

Client Portal Builder may process:

  • Client name, email address, password hash, account status and an optional account comment
  • Portal settings, content, filters and client-access rules
  • Portal, client-item and pseudonymous account identifiers
  • Optional Google Sign-In identity information
  • Signed session claims and authentication timestamps
  • Temporary uploads and cached image thumbnails
  • Request analytics containing paths, identifiers, method, duration and response status

Client names, email addresses and password hashes are stored in the customer's own monday.com account. Gorilla Apps does not maintain a separate application-database copy of those client account records.

3.6 Spreadsheet Gorilla

Spreadsheet Gorilla may process:

  • Board and template identifiers
  • Spreadsheet and report templates, formulas, filters and configuration
  • monday.com account, user, integration and automation identifiers
  • Encrypted monday.com authorization tokens
  • Automation names, status, timing and result information
  • Board data used to generate a spreadsheet or table
  • The name and email address of an automation creator
  • Recipient email addresses and generated spreadsheet or table content when a customer configures email delivery

Automated spreadsheet jobs run on Google Cloud infrastructure. When email delivery is selected, the message and any generated attachment are sent through Twilio SendGrid. We also use Twilio SendGrid to deliver transactional application emails, such as an introduction email after Client Portal Builder is installed.

3.7 Board to Website Widget

Board to Website Widget may process:

  • monday.com account and board identifiers
  • Widget configuration, presentation settings and filters
  • Board metadata, items, files and other content selected for publication
  • Widget paths, asset identifiers and execution information

The customer chooses what to publish. Published widget data and assets are stored in Cloudflare R2 so they can be displayed on the customer's selected website.

3.8 Exported Excel Cleaner

Exported Excel Cleaner processes the selected spreadsheet in the user's browser. The spreadsheet content is not uploaded to the Gorilla Apps backend for conversion. We still process limited app-installation, subscription, security and technical information as described elsewhere in this Policy.

3.9 System-status page

Our public system-status page at status.getgorilla.app is hosted by Hetzner and displays service availability, incident information and maintenance notices. It does not require a user account. When you visit it, we and our infrastructure providers may process the website and technical information described in Section 3.2.

4. Why we process Personal Data

Purpose Typical data Legal basis where the GDPR applies
Provide and operate our Services Account, configuration, Customer Data and technical information Performance of a contract; for Customer Data, processing on the Controller's documented instructions
Authenticate users and manage access Account identifiers, tokens, credentials, session and security information Performance of a contract and our legitimate interest in protecting the Services
Provide support and communicate about the Services Contact details, messages and diagnostic information Performance of a contract and our legitimate interest in supporting customers
Manage installations, subscriptions and billing Installer, account, lifecycle, subscription and transaction information Performance of a contract, compliance with legal obligations and our legitimate interest in administering our business
Deliver customer-configured reports and messages Recipient addresses, report content and delivery information Performance of a contract and processing on the customer's instructions
Secure, monitor and troubleshoot the Services Logs, network information, identifiers, errors and security events Our legitimate interests in security, fraud prevention, reliability and establishing or defending legal claims
Understand and improve product performance Pseudonymous usage and performance information Our legitimate interest in improving and maintaining the Services
Send marketing communications Contact details and communication preferences Consent where required; otherwise our legitimate interest, subject to applicable direct-marketing rules and your right to object
Comply with law and protect legal rights Information relevant to the legal requirement or claim Compliance with legal obligations and our legitimate interest in protecting legal rights

Where we rely on legitimate interests, we consider the necessity of the processing and its impact on individuals. You may object to processing based on legitimate interests as described in Section 10.

If we ask for information required to enter into or perform a contract and you do not provide it, we may be unable to provide the relevant Service. Other information is optional unless we say otherwise.

5. Where the data comes from

We receive Personal Data:

  • Directly from you
  • From the customer or organization through which you use a Service
  • From monday.com or another customer-selected platform when an app is installed, authorized or used
  • From users who configure portals, widgets, reports, recipients or other workflows
  • Automatically from browsers, devices and infrastructure used to access the Services
  • From service providers supporting payments, communications, security and service delivery

We do not buy Personal Data from data brokers.

6. Who receives Personal Data

We disclose Personal Data only where necessary for the purposes described in this Policy, on a customer's instructions, or where required by law.

6.1 Company-wide list of service providers, Subprocessors and platforms

The providers relevant to one or more Gorilla Apps products currently include:

Provider Purpose and role Processing location
ALL-INKL.COM — Neue Medien Münnich, owner René Münnich Hosts getgorilla.app, the public website at clientportalbuilder.com, the Contao contact-form delivery and the hello@getgorilla.app mailbox Germany
monday.com Ltd. and applicable affiliates Customer-selected platform for monday.com accounts, boards and APIs; also provides monday Code hosting and developer storage for certain app operations Customer-selected EU, US, or Israel (IL) region for regional Customer Data; limited global processing may apply under monday.com's terms
Cloudflare, Inc. and applicable affiliates Network delivery, Workers, D1, KV, R2, Analytics Engine, Hyperdrive, logging, monitoring and security Global network, including the EEA and United States
Render Services, Inc. Hosts our PostgreSQL app-lifecycle and operational database using Amazon RDS Oregon, United States
Hetzner Online GmbH Hosts Gorilla Apps-managed PostgreSQL backups and status.getgorilla.app Finland, within the EEA
Google Cloud EMEA Limited and applicable Google affiliates, including Google LLC Runs Spreadsheet Gorilla automation jobs United States, currently us-central1
Twilio Ireland Limited and applicable Twilio affiliates, including Twilio Inc., for Twilio SendGrid Delivers transactional application emails, including customer-configured Spreadsheet Gorilla emails and attachments Global, including the United States
Google identity services Optional customer-configured Google Sign-In for Client Portal Builder Global, including the United States
YouTube, provided by Google Optional video content on our documentation pages; the connection is initiated only after the visitor chooses to load the video Global, including the United States

Not every provider receives data from every product. We require processors we appoint to protect Personal Data under appropriate contractual terms. Providers identified as customer-selected platforms or independent Controllers process data under their own terms for those activities.

The table above is our current company-wide list of service providers and, where they process Customer Personal Data on our behalf, Subprocessors. It also identifies customer-selected platforms and independent Controllers that are not Subprocessors for the relevant processing activity.

Client Portal Builder customers may subscribe to advance Subprocessor-change notices by emailing hello@getgorilla.app with the subject “Subprocessor change notifications” and identifying their legal name and monday.com account.

6.2 Other disclosures

We may also disclose relevant information:

  • To professional advisers subject to confidentiality obligations
  • Where necessary to comply with law, a court order or a lawful request from an authority
  • To establish, exercise or defend legal claims
  • To protect individuals, our customers, Gorilla Apps or the public from material harm
  • As part of a merger, restructuring, financing or transfer of all or part of our business, subject to appropriate safeguards

We do not sell Personal Data.

7. International transfers

Gorilla Apps is established in Germany. The public websites at getgorilla.app and clientportalbuilder.com are hosted by ALL-INKL.COM in Germany, and the public system-status page is hosted by Hetzner in Finland. Some other providers and systems operate outside the European Economic Area.

Portal content and client account data stored in monday.com follow the customer's selected monday.com EU, US, or Israel (IL) region. Cloudflare operates a global network. Render hosts the PostgreSQL lifecycle-event database in Oregon, United States, and Spreadsheet Gorilla automation jobs currently run in Google Cloud's us-central1 region. Hetzner-hosted database backups are stored in Finland.

Where the GDPR restricts an international transfer, we use a lawful transfer mechanism. Depending on the provider and transfer, this may include an adequacy decision, participation in the EU-US Data Privacy Framework where applicable, or the European Commission's Standard Contractual Clauses together with supplementary measures where required.

For Google Cloud, our contracting entity is Google Cloud EMEA Limited in Ireland. Transfers of Personal Data to Google LLC in the United States are currently covered by Google LLC's participation in the EU-US Data Privacy Framework. Google's Cloud Data Processing Addendum incorporates the European Commission's Standard Contractual Clauses for restricted transfers where an applicable alternative transfer solution is unavailable or does not cover the transfer.

For Twilio SendGrid, our contracting entity is Twilio Ireland Limited in Ireland. Where Twilio Inc. processes Personal Data in the United States, Twilio's Data Protection Addendum gives priority to Twilio Inc.'s participation in the EU-US Data Privacy Framework. The Addendum incorporates the European Commission's Standard Contractual Clauses for restricted transfers where required. Twilio's Binding Corporate Rules do not apply to the SendGrid services.

8. How long we retain data

We retain Personal Data only for as long as necessary for the relevant purpose, contractual relationship and legal obligations. Retention varies by product and data category.

Data category Retention or deletion criteria
Customer Data held in the customer's monday.com account Controlled by the customer and monday.com under their separate relationship. Gorilla Apps generally loses access when the app is uninstalled.
Client Portal Builder client account data Stored in the customer's monday.com account. Gorilla Apps does not retain a separate application-database copy.
Client Portal Builder temporary uploads Up to 24 hours
Client Portal Builder cached thumbnails Up to six days
Client Portal Builder pseudonymous request analytics Up to 90 days
Client Portal Builder operational data after uninstall An operator-reviewed cleanup runs at least once each calendar month and removes eligible data for accounts that have not reinstalled and have no active subscription
Board to Website Widget published content and settings Until the customer unpublishes or deletes the widget, or the account becomes eligible for uninstall cleanup; scheduled cleanup checks for accounts uninstalled for more than five days
Exported Excel Cleaner spreadsheet content Processed locally in the browser and not retained by the Gorilla Apps backend
Spreadsheet Gorilla templates, encrypted tokens, signals, execution information and lifecycle events Retained while the app remains installed or the account has an active subscription. An operator-reviewed cleanup runs at least once each calendar month. It deletes these records for accounts that have been uninstalled for more than five days, have not reinstalled and have no active subscription.
App lifecycle and subscription events For the installation and subscription lifecycle and then according to the applicable product cleanup process
ALL-INKL website access logs Up to seven days under ALL-INKL's published standard retention period, unless longer retention is necessary to investigate an attack or misuse
Cloudflare Workers Observability logs Up to seven days on our current Workers plan
Application-log archive in Cloudflare R2 Up to 90 days
Cloudflare Workers metrics Up to three months; these are aggregated operational metrics rather than application log messages
Google Cloud Run job files Generated files exist in the job instance's in-memory file system while the job runs and do not persist after the instance stops
Google Cloud application and service logs Up to three months
Twilio SendGrid message bodies and attachments Ordinarily retained only as long as required for delivery, which may take up to 72 hours. Twilio may retain random content samples for up to seven days for fraud prevention, security and troubleshooting.
Twilio SendGrid recipient data and message metadata Most recipient data, message activity and metadata time out after approximately 30 days and are deleted within a maximum of approximately 37 days. Twilio may retain pseudonymized email-event data, which may remain re-identifiable with a recipient, for up to one year for security, fraud detection, anti-abuse and network protection.
Render-managed PostgreSQL backups Up to seven days
Gorilla Apps-managed PostgreSQL backups stored by Hetzner Up to three months
Contact-form and support messages The form submission is not retained in the Contao database. It is delivered to the hello@getgorilla.app mailbox. Routine messages are deleted within 24 months after the conversation ends. Messages required for an active customer relationship, a legal obligation, a dispute or a legal claim may be retained for the applicable period.
Billing, tax and transaction records For the period required by applicable commercial and tax law

When data in backups cannot reasonably be isolated, it remains protected from ordinary use and is deleted through the applicable backup cycle. We may retain specific information for longer where required by law or necessary to establish, exercise or defend legal claims.

9. Security

We use appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.

Measures include access controls, encryption in transit, application-layer encryption for selected stored data, secure secret handling, password hashing, short-lived signed sessions, rate limiting, logging, monitoring, backups, vulnerability management and an approved incident-response process.

No method of transmission or storage is completely secure. More information about Client Portal Builder is available on our Security page.

10. Your rights

Depending on applicable law and the circumstances, you may have the right to:

  • Obtain information about our processing and a copy of your Personal Data
  • Correct inaccurate or incomplete Personal Data
  • Request deletion of Personal Data
  • Restrict processing
  • Receive data you provided in a portable format
  • Object to processing based on legitimate interests or to direct marketing
  • Withdraw consent at any time, without affecting processing already carried out
  • Lodge a complaint with a Supervisory Authority

These rights may be subject to legal conditions and exceptions.

To exercise a right concerning data for which Gorilla Apps is the Controller, contact hello@getgorilla.app. We may need information sufficient to verify your identity and locate the relevant data.

If Gorilla Apps processes the data only on behalf of one of our customers, we may refer your request to that customer or ask you to contact it directly.

Our competent Supervisory Authority is generally:

The State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI Baden-Württemberg)
Heilbronner Straße 35
70191 Stuttgart
Germany
Visit the LfDI Baden-Württemberg website

You may also have the right to contact another Supervisory Authority, particularly in the EEA country where you live or work or where an alleged infringement occurred.

11. Marketing communications

You may opt out of marketing emails at any time by using the unsubscribe mechanism in the message or contacting us. We may still send non-marketing communications needed to provide a Service, administer an account, communicate security matters or comply with law.

12. Children

Our Services are intended for organizations and business users and are not directed to children. We do not knowingly collect Personal Data directly from children through our website for our own purposes.

Customer Data may nevertheless concern individuals of different ages if a customer places that information in a connected platform. For that processing, the customer is responsible for determining whether the processing is lawful and for providing any required notices or obtaining any required authorization.

13. Automated decision-making

Gorilla Apps does not use Personal Data as a Controller to make solely automated decisions that produce legal effects or similarly significantly affect individuals.

Customers may configure filters, automations and other rules in our products or in connected platforms. The customer is responsible for the purpose and configuration of those rules where it acts as Controller.

15. Changes to this Policy

We may update this Policy to reflect changes to our Services, processing or legal obligations. We will post the updated version with a revised date. Where required by law or contract, we will provide additional notice of material changes.

16. Contact

Questions, privacy requests and complaints may be sent to:

Kusterer & Müller GbR (Gorilla Apps)
Hagbergstrasse 11
70188 Stuttgart
Germany
Email: hello@getgorilla.app