Privacy Policy — Item Approval Workflow

Last updated: 6 September 2026

Item Approval Workflow is an app for monday.com that records who signed off an item, and which version of that item they signed off. This page explains exactly what the app stores, where it stores it, who can read it, and the three ways to erase it.

The short version

The app keeps one record per board, held in the app's own storage inside monday.com's cloud, in the European Union region. That record holds the approvals and the decisions taken, the rule the board runs on, and — because this is the part that makes the product work — a snapshot of the columns it watches, so it can tell whether an item changed after it was approved. It holds no names, no email addresses and no payment details. There is no server of ours anywhere, no database of ours, and no way for us to look at your data.

What the app stores

1. The approval on an item

When someone sends an item for approval, approves it, or sends it back, the current state is stored in the app's record for that board. It holds:

The one free-text field, said plainly. Sending an item back requires a written reason, and that sentence is stored, because a refusal without a reason is not an audit trail. It is the only free text a person types into this app. It is written by a colleague and read by colleagues, and it is also posted to the item's Updates, so treat it exactly as you would an ordinary update: do not type personal details, health information or anything else sensitive into it.

2. The snapshot of the columns being watched — this is board content

A monday.com item has no version number of its own, so the app makes one. Each time it looks at an item it records, alongside the version number and the date:

Stated without softening it: this means some of your board content is stored by the app. It has to be — telling somebody which column changed since an approval is not possible from a number alone, and "the approval fell and we will not say why" is the exact complaint this app was built to fix. Three things limit it, and they are properties of the code rather than promises here:

If a watched column contains personal data — a People column, or a text column somebody typed a name into — then that value is inside the snapshot. If that matters for your organisation, exclude that column from the watched list on the Setup tab; the approval engine works exactly the same way.

3. The rule the board runs on

Set on the Setup tab by someone who can edit the board: who signs off by default (monday.com user IDs), whether any one signature is enough or everybody has to sign, and which columns count as a change. A board that sets nothing still works — the app needs no configuration to run.

4. The subscription status

So that the app knows whether your subscription is running — which monday.com requires every app to check for itself — it keeps what monday.com tells it about your plan: the plan identifier, whether it is a trial, the date it runs to, monthly or yearly, the pricing version, the seat limit, and which notice it last received. No payment details of any kind — no card, no billing address, no invoice, no amount. Those never reach the app: monday.com handles all payment.

5. The authorisation key for your account

At installation your account authorises the app once, and monday.com issues it a key. That key is held per account, in the platform's own encrypted vault, and is used only on the server, to read the item being decided and to post the decision to that item's Updates. It is never sent to the browser, never returned in a response and never written to a log. It is deleted when the app is uninstalled.

What the app never stores

The one place personal data is offered to us, and refused

When your account installs or uninstalls the app, or changes its subscription, monday.com sends the app a notice. That notice contains the email address, name and country of the person who clicked, along with your account's name and web address.

The app reads two things from it — what kind of notice it is, and the numeric account ID — and discards everything else. It is not written to storage and it is not written to a log line either, because a log is exactly where a leak goes unnoticed. This is a property of the code, not an intention: the file that handles those notices says so at the top, and the automated test suite fails if it starts keeping more.

Artificial intelligence — what happens, and what does not

The app publishes six actions that the assistant already living in your monday.com account can call: what is waiting for me, send this item for approval, approve it, send it back with a reason, what changed since it was approved, and how a board is doing. The intelligence is monday.com's, not ours.

Where the data lives

The app runs on monday code, monday.com's own hosting for marketplace apps, in the EU region, and it stores its records in the storage that platform gives it. That is the whole of it:

Who can see what

Erasing it — the three ways

None of these marks anything as deleted and keeps it.

Erasing is never blocked by billing. Even with a lapsed subscription, both erase routes keep working — a data protection right does not queue behind an invoice.

When a person is erased, the decision stays

Erasing a person removes their identity from the app's records, in both places that hold one, and treats each differently:

Both halves matter, and the second one is the one that is easy to get wrong: a signature carries the line it belongs to as well as the name of who signed, and both hold the same user ID. The app replaces the line with an opaque key so the name cannot be reconstructed from it, and keeps one line per signature so that two erased people never merge into one and lose a decision.

How long it is kept

For as long as the app is installed. The app does not thin out or delete old decisions on its own — an audit trail that silently drops last year is worse than no audit trail — so what is there is what your organisation put there, until it is erased by one of the routes above. Deleting an item in monday.com does not delete the record of the decisions taken on it; that is what makes it an audit trail rather than a label.

Your rights

If you are in the European Union or the United Kingdom, the GDPR gives you the right to access, correct, export or delete your personal data. The company that installed the app is the data controller; we are its processor. In practice everything the app holds about you sits inside your own employer's board record, so the quickest route for any request is your own monday.com administrator, who can list it and erase it without us. You can also write to us at the address below.

For your legal team, the Data Processing Agreement sets out the same facts in the form the GDPR asks for (Article 28), and applies automatically from installation.

Changes

If this policy changes, the date at the top changes with it and the new version is published here before it takes effect.

Contact

Item Approval Workflow is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Questions about this policy — or a request to see or delete data — go to help@saoirsesoftware.com.

← Back to Item Approval Workflow