Data Processing Agreement — Leave & PTO Tracker

Last updated: 2 September 2026

This Data Processing Agreement ("DPA") governs the processing of personal data by the Leave & PTO Tracker app for monday.com ("the app"), supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland ("we", "us", "the Processor"). It forms part of the Terms of Service and should be read with the Privacy Policy.

How this DPA is entered into. This DPA applies automatically between us and your organisation from the moment the app is installed on your monday.com account, for as long as it remains installed. No signature is required for it to be binding. If your legal team needs a countersigned copy, or needs it attached to your own paper, email help@saoirsesoftware.com and we will sign and return it.

1. Roles

Your organisation — the monday.com customer that installed the app — is the data controller. It decides what leave entitlements apply, who may approve, and what is recorded about an absence. We are the data processor: we process data only to make the app work, and only on your instructions.

Your instructions are given through the app itself and through this DPA. We will not process data from your monday.com account for any other purpose — not for our own analytics, not for product research, not for marketing, and not for training any machine-learning or AI model. We do not sell personal data and receive no payment from anyone for access to it.

2. What is processed

The app keeps one record per monday.com account. The table below is the whole of what that record contains.

Subject matter Recording requests for time off, the decision taken on each, and the leave balance that follows from them, for the people in your monday.com account.
Duration For as long as the app is installed on your monday.com account.
Nature and purpose Storing and displaying leave requests and decisions; calculating entitlement, carry-over and remaining balance; showing who is away on which days; and producing a year report for the people allowed to approve.
Categories of data subject People who hold a user account on your monday.com account and who open the app, request time off, or take a decision on somebody else's request.
Written down (1) — the requests and decisions One line per request, containing:
  • the monday.com user ID of the person the request belongs to;
  • the leave type — annual, sick, unpaid, other (see special category data below);
  • the start and end date, whether it is a half day, and the number of working days counted;
  • the status — waiting, approved, turned down, cancelled;
  • an optional free-text note from the person requesting;
  • the date and time the request was made;
  • the monday.com user ID of the person who decided, when they decided, and the free-text reason where a request was turned down, which the app requires.
Written down (2) — the people For each person who has opened the app: their monday.com user ID and the display name monday.com reports for them, so the screens can show names rather than numbers. The record also has fields for a per-person leave profile (their own yearly entitlement, days carried over, employment start date and holiday country); in the current version the screens set those values for the company as a whole, so the per-person fields remain empty.
Written down (3) — the company settings The country whose public holidays apply, the days of leave per year, the carry-over rule, any per-type limits, and the list of monday.com user IDs allowed to approve. An account that sets nothing still works.
Written down (4) — the subscription status What monday.com reports about your subscription, so the app can check at runtime whether it is running, as monday.com requires every app to do: plan identifier, whether it is a trial, the date it runs to, the billing period, the pricing version, the seat limit and which notice was last received. This is account-level, not personal, and contains no payment details of any kind — no card, no billing address, no amount. monday.com handles all payment; none of it reaches the app.
Read and immediately discarded When your account installs or uninstalls the app, or changes its subscription, monday.com sends the app a notice containing the email address, name and country of the person who clicked and your account's name and web address. The app reads only the kind of notice and the numeric account ID and discards the rest — it is written neither to storage nor to a log line. This is enforced by the code and covered by the automated test suite, which fails if any other field starts being kept.
Never stored No email addresses, phone numbers, profile pictures, job titles or team memberships. No content from your boards — no items, columns, updates or files; the app does not hold the monday.com permissions that would let it read them. No monday.com account name or web address. No passwords, tokens or payment details. No analytics, no tracking, no cookies of ours, and nothing stored in the user's browser.
Special category data Yes, and it is stated plainly rather than buried. "Sick leave" is one of the four leave types, so a record that a named person was on sick leave between two dates is data concerning health under Article 9 GDPR. It exists because an absence app that cannot distinguish sick days from holidays cannot compute a balance or a per-type limit. As controller, you are responsible for the lawful basis — typically Article 9(2)(b), employment and social security law, in the context of the employment relationship.

What the app does about it: the leave type, the requester's note and the reason for a refusal are removed from the response on the server, before it reaches the browser of any colleague who is not the person concerned and is not an approver. To everyone else the entry reads simply "Time off", with dates only. This is a rule of the calculation engine, not of the screen, and it is proven by the automated test suite.

The two free-text fields can still hold whatever a person types. The app tells users so on the screen where they type, and the controller should instruct staff not to enter diagnoses or medical details.

3. Where the data is held, and international transfers

The app runs on monday code, monday.com's own hosting for marketplace apps, in the European Union region, and stores your account's record in the storage that platform provides. There is no server of ours anywhere in the path, no database of ours and no backup of ours.

We carry out no international transfer of your data, because we never receive it outside that platform. Any transfer that occurs is monday.com's own, under monday.com's terms with you and monday.com's own transfer safeguards.

4. Sub-processors

We use one sub-processor for the data in the app:

Sub-processorWhat it doesWhere
monday.com Ltd (and its group companies) Provides the marketplace, the hosting that runs the app, and the storage that holds the record described in section 2. monday.com's European Union region.

monday.com is already your own data processor for monday.com itself, under the agreement you hold directly with them, and their own sub-processors apply under that agreement. We add no other sub-processor: no analytics provider, no error-reporting service, no hosting provider of ours, no AI service.

One thing to be aware of separately: if you or your staff email our support address, that correspondence sits in a Google-hosted mailbox, which processes it as a sub-processor of that correspondence only. It never contains data pulled out of your monday.com account unless you choose to put it in the email yourself.

If we ever intend to add or replace a sub-processor, we will publish the change on this page and update the date at the top at least 30 days before it takes effect. If you object on reasonable data-protection grounds within that period, you may uninstall the app and end this DPA; billing stops under monday.com's rules.

5. Security measures

The app's security rests on a deliberate design decision: it holds little, it holds it in one place, and it has nowhere else to send it. Concretely:

Being straight about the limits: we hold no security certification — no ISO 27001, no SOC 2 — and we do not claim one. We do not run a bug bounty programme or commission penetration tests. What we offer instead is a much smaller attack surface than an app with its own servers, and the platform-level assurances monday.com publishes for apps hosted on its own infrastructure.

6. Who can see what

7. Helping you meet your own obligations

Because we hold no copy of your data, everything you need you can do yourself, immediately, inside the app. We will assist where you cannot.

8. Deletion at the end

When your account uninstalls the app, monday.com notifies the app and the app erases your account's record immediately and automatically. We keep no copy anywhere, because we never had one, so there is nothing further for us to return or destroy. If you require written confirmation of deletion, ask and we will provide it.

Export first if you need the record. Everything is erased, including the year report; the export takes one click and is yours to keep.

9. Personal data breach

If we become aware of a personal data breach affecting personal data processed through the app, we will notify you without undue delay and in any event within 72 hours of becoming aware. The notice will describe what we know, the likely consequences and what is being done. We will assist you with your own notification duties under Articles 33 and 34 GDPR.

Two honest points about how that notice reaches you. First, the app deliberately stores no email addresses, so we will contact you using the contact details monday.com provides to us for your subscription, and any address you have written to us from. If you want breach notices to reach a specific mailbox — a security team, a DPO — email that address to us and we will record it against your subscription. Second, because the data lives in monday.com's infrastructure and not ours, a breach of the underlying platform would be detected and notified by monday.com under your agreement with them, and we would very likely learn of it at the same time you do.

10. Information and audit

On reasonable written request, and no more than once a year unless a breach or a supervisory authority requires otherwise, we will provide the information you need to verify our compliance with this DPA — what the app stores, which permissions it holds, and how the access rules work. Being straight again: as a sole trader we cannot host an on-site audit, and there is no infrastructure of ours to inspect. For the platform layer, monday.com's own published compliance material is the applicable evidence.

11. Liability, term and law

This DPA takes effect on installation and ends when the app is uninstalled and any remaining data is deleted, whichever is later. Where its terms conflict with the Terms of Service on a matter of data protection, this DPA prevails. The liability limits in the Terms of Service apply to this DPA, except where the GDPR does not permit them to. This DPA is governed by the laws of Ireland.

12. Changes

If this DPA changes, the date at the top changes and the new version is published here. For changes that reduce your protections, or that add or replace a sub-processor, we give 30 days' notice on this page before they take effect.

13. Contact

Leave & PTO Tracker is supplied by Kauê Natan Gonçalves Bidim, trading as Saoirse Software, in Ireland. Data protection questions, requests under this DPA and security reports all go to help@saoirsesoftware.com. Emails reach the person who writes the code.

← Back to Leave & PTO Tracker