Privacy Policy
Survey Flow sends satisfaction surveys to your customers and collects their answers, so it necessarily handles personal data. This policy sets out exactly what we hold, where it lives, who inside your company can see it, how long it stays, and what happens when you uninstall. Where something is retained rather than deleted, we say so and explain why. The same goes for text that is sent to a model, and for content that is written onto one of your boards and stays there after you uninstall.
Who is responsible for what
Two different relationships run through this product, and they carry different responsibilities.
You are the controller of your survey data. When you install Survey Flow on your monday.com account, you decide who receives a survey, what they are asked, and what happens to the answers. We process that data on your instructions and for no other purpose. We are your processor.
We are the controller of the suppression list. Every Survey Flow customer sends through the same email domain, so when someone unsubscribes or their mailbox rejects our mail, honoring that is our own obligation rather than yours.
Three things outlive an uninstall, and they are not alike. A seven day window holds your data before deletion runs, and then it is gone. Follow-up items stay on your own boards, where they are yours to keep or to remove. The third is this suppression list, and it is the only one we keep indefinitely, and the only one we keep for a purpose of our own. Section 8 covers the window and the list, and section 9 covers the items.
Recipients of a survey are your customers, not ours. We hold no relationship with them and we never contact them for our own purposes.
We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU General Data Protection Regulation (EU) 2016/679, and the monday.com marketplace developer terms.
What we handle
About the people who receive surveys
| Data | Where it comes from |
|---|---|
| Email address | The board column you nominate during setup |
| Display name, where one exists | The same source. Where no name exists, the email address is used as the label instead |
| Star rating, one to five | Submitted by the recipient |
| Written comments and answers to follow up questions | Submitted by the recipient. These are free text, so they contain whatever the writer chooses to include |
| Ticket title at the time the survey was sent | Your board. This is your content and may name a person or a situation |
| Delivery outcome, including bounces and complaints | Our email provider |
| Timestamps for send, response and link expiry | Generated by the app |
About your team
We store monday.com user identifiers for the agent assigned to each ticket, so that feedback can be attributed and shown to the right person. We read profile and time zone information from monday.com when rendering the dashboard, but we do not store your team members' names or email addresses.
That remains true of what we store. It is no longer the whole picture of what we disclose. When somebody asks one of our Sidekick skills for feedback, we resolve the assigned agent's monday.com display name at that moment and return it in the reply, next to the customer's comment. The name is not kept, but it does reach a chat surface that is not ours. Section 4 describes that path.
Where you configure a low rating alert, we store the identifier of the person to be notified.
Configuration you provide
Board and item identifiers, your trigger status and conditions, your questions and email wording, your sender display name and logo, and your exclusion list.
A logo has to be a PNG, JPEG or WebP, identified by its actual bytes rather than by what the upload declares, and anything over 256 KB is refused. We strip the metadata before storing it, which for a photograph means the location it was taken, the camera serial number, timestamps and editing history. That is the whole of what stripping does. The picture is untouched, so if you upload a team photo or a portrait of somebody, that is what we hold and what your customers see.
Surveys waiting to be sent
When your account reaches its monthly plan allowance, tickets that resolve are held rather than sent, so the survey is not lost. A held record holds a board identifier, an item identifier and a timestamp. No address, no name and no comment.
A note about the exclusion list
Addresses you add to the exclusion list are stored as you typed them, in plain form, because the app has to show them back to you for editing. Treat that list as customer data.
What we deliberately do not hold
- We do not log recipient email addresses. Log entries carry a short irreversible tag instead, enough to trace a delivery through support without exposing the address.
- Our job queue carries identifiers only. The table in section 6 lists exactly which identifiers, and what does not pass through it.
- We do not harvest board data. We read the columns you nominate and the items that reach your trigger status. There is one addition, and it is a lookup rather than a harvest: when somebody asks a Sidekick skill to find a ticket by name, we read item names on the boards you have configured, including items that never reached your trigger status, to work out which ticket is meant. No column value on those items is read, nothing from the lookup is stored, and what comes out of it is a single item identifier.
Why we handle it
Everything above exists to run the product you configured: deciding whether a survey should be sent, sending it, collecting the answer, showing it to you and to the agent who handled the work, and notifying someone when a rating falls below the threshold you set.
We do not sell personal data. We do not use it to train models. We do not use it for advertising, profiling, or any purpose of our own beyond operating and supporting the service.
Some of that content is sent to a model to be read or written about, though never to train one. Section 4 sets out which features do it, what each one sends, what turns them on, and what monday.com says happens to the text afterwards.
For customers in the EEA and the UK, our lawful basis for processing on your behalf is the performance of our contract with you. You remain responsible for establishing the lawful basis on which you survey your own customers. Our own retention of suppression data rests on legitimate interests, specifically the interest in not repeatedly emailing people who have asked us to stop or whose mailbox has rejected our mail.
What we send to AI, and when
Some of what your customers write is sent to monday.com's AI to be read or written about. This section says which features do that, exactly what each one sends, and what we know and do not know about where it goes next.
Four paths lead to a model. Three of them, the ones in the table, are switched off until you switch them on: the AI question mode defaults to off, and labelling is off unless you turn it on. If you leave both alone, no comment and no answer is ever sent to a model by any of the three, and turning either one on is a decision to send what the table describes. The fourth path is not gated on anything, and it is set out after the table.
| Feature | When it runs | What is sent |
|---|---|---|
| Opening question | Before the customer has typed anything | The ticket title, how many days the ticket took to close, and the rating. There is no comment yet, so no comment is sent |
| Probe question | Live, while the customer is still answering | The ticket title, days to close, the rating, the comment exactly as written, and the conversation so far |
| Labelling | After the survey is submitted, with nobody present | The ticket title, days to close, the rating, the comment exactly as written, and every answer exactly as written |
Nothing is redacted, truncated or summarised first. We pass no recipient email address and no display name as a field of any of these requests. But a comment is free text, so if your customer types their own address or phone number into it, that goes verbatim with everything else, and a ticket title carries whatever your board carries.
A fourth path, which no setting controls
Survey Flow also publishes two skills to monday.com's Sidekick assistant. One finds feedback; the other creates a follow-up item from a response. The one that finds feedback returns, for each response it matches, the comment exactly as written, every follow-up answer run together, the CSAT score, the ticket title, a date, and the assigned agent's monday.com display name, which is one of your own staff. That reply is handed to Sidekick, which writes its answer out of it.
So customer comments reach a model here too, on a path of its own. Unlike the three features above, this one is not gated on any setting. Anyone who can invoke the skill, which means an admin or a board owner, reaches it. Section 5 covers where the answer then appears and who can read it.
What happens to it once it leaves
All four paths call monday.com's AI, so the text goes to monday.com first. monday.com states in its AI Trust Center that it does not use input or output to train models and does not allow anyone else to, and that it reaches large language models through managed APIs from Microsoft Azure and AWS Bedrock under zero retention policies. The text therefore does not stop at monday.com. It leaves monday.com's own infrastructure, and the monday.com row of the table in section 6 records that routing.
Two limits on that are worth stating rather than leaving you to assume they were checked.
- The AI Trust Center describes monday AI as a product. It says nothing specific about run_prompt, which is the call our app actually makes, or about the API generally. Reading it as covering that call is a reasonable inference and it is the one we have made in writing this section, but it is our inference and not something monday.com has stated.
- A sixty day internal access window for AI data appears in search results about monday.com. We could not find it on the AI Trust Center itself, so we are not asserting it and we do not know whether it applies here. We would rather say that than repeat a figure we cannot source.
Who can see it
This section matters more than most, because it determines who inside your own company sees your customers' contact details. Read it before rolling Survey Flow out to a wide group.
Agents can see who left a given response. The per agent dashboard shows each response alongside the recipient it came from. Where a display name exists, the display name appears. Where the app holds only an email address, the email address appears. This is what makes per agent feedback useful, and it is more exposure than some teams expect.
Low rating alerts carry the same information. Whoever you nominate receives a monday.com notification identifying the ticket and the customer who left the rating, whether or not that person ever opens Survey Flow.
A follow-up item puts the response onto one of your boards. When a response is turned into a follow-up item, the update on that item carries the rating and the date it was given, the labels still outstanding, the comment exactly as written under the heading “What the customer wrote”, and every follow-up question that was answered, with its answer. The item's name is the label followed by the ticket title, so the ticket title itself turns up in board views, in search results and in notifications. No recipient email address is included anywhere in it; that was deliberately left out.
Who can read that is a different question from who can use Survey Flow, and the answer is wider. It is whoever can see the destination board, which is that board's membership on monday.com, set by whoever administers it, and unconnected to who can open the app. An item created from a response is legible to people the app itself would never show it to, so choose the destination board with that in mind. Section 9 explains what happens to these items when you uninstall, which is nothing.
Sidekick answers land outside the app. When somebody asks a Sidekick skill for feedback, the answer is composed out of the comments, answers, scores, ticket titles and agent display names described in section 4, and it appears in a monday.com chat transcript. How long that transcript is kept, and who else can read it, is governed by monday.com rather than by us.
Beyond your own account, access is limited to us. A small number of our personnel can access survey data where it is necessary to operate or support the service, and our sub processors can access it only to the extent needed to provide their part of it.
We may also disclose personal information to our contractors and professional advisors where they need it to do work for us, to courts, regulators and law enforcement where the law requires it, and to a successor entity if our business or assets are transferred. We do not sell, rent or trade personal data, and we do not disclose it for any other purpose.
Where it is stored, and who else is involved
Survey data is stored outside monday.com, in a managed Postgres database. monday.com has confirmed in writing that this is acceptable for this app, subject to the security conditions described in section 7, in support ticket #5047188 dated 29 July 2026.
Your board configuration is held in the same database, alongside the survey records. Per item survey state and uploaded logos are stored in monday.com's own storage, inside your account. Your monday.com access tokens are held in monday.com's encrypted secure storage and never leave our backend.
Sub processors
| Provider | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Neon, operated by Neon, LLC, a Databricks, Inc. company | Managed Postgres. Holds survey records, ratings, comments and recipient labels | AWS us-east-1 | Standard contractual clauses, Modules Two and Three, with the UK Addendum for UK transfers and Swiss modifications. The Databricks data processing addendum deems them incorporated for any restricted transfer, rather than only if another mechanism fails. It names no Data Privacy Framework certification. The governing terms are the Product Specific Schedule (Neon) under the Databricks Master Cloud Services Agreement |
| Resend | Sends the survey emails, and reports bounces and complaints. This is the active sending provider | United States. Resend's region setting controls where mail is sent from, not where data is stored | EU and UK standard contractual clauses. Resend's own data processing agreement additionally states it has certified to the US Department of Commerce under the EU-U.S. Data Privacy Framework and the UK Extension |
| Amazon SES | A second fully integrated sending path, selectable by configuration. Not currently able to send, pending AWS production access | us-east-1 | Standard contractual clauses, applied by the AWS Service Terms by default rather than on request. AWS is also covered by Amazon.com's Data Privacy Framework certification |
| Amazon SNS | Carries bounce and complaint notifications for mail sent through SES. Receives data only while SES is the sending provider | us-east-1 | Standard contractual clauses, applied by the AWS Service Terms by default rather than on request. AWS is also covered by Amazon.com's Data Privacy Framework certification |
| Upstash QStash | Job queue. Carries board, item and monday account identifiers. No recipient address, no name, no survey content | AWS us-east-1 | Upstash's own data processing agreement states it relies on the Data Privacy Framework, with the standard contractual clauses incorporated by reference if required |
| monday.com | Application hosting, configuration storage, token storage. Object storage for any logo you upload. AI processing: the requests described in section 4 are sent to monday.com's AI through run_prompt, and monday.com states that it routes them onward to large language models at Microsoft Azure and AWS Bedrock | United States | You have a direct agreement with monday.com. The transfer mechanism for that processing sits in monday.com's own data processing addendum, not in this policy. The same is true of the onward routing to Microsoft Azure and AWS Bedrock, which happens inside monday.com's supply chain rather than ours |
Both bounce and complaint routes stay mounted at all times, so that handling a rejection never depends on which provider sent the message. Resend and Amazon SES each report through their own separate lane, and Resend's is the lane carrying data today. Amazon SES cannot send until AWS grants production access, so it produces no bounces, Amazon SNS has nothing to deliver, and AWS receives no recipient addresses or delivery outcomes at present. What is unconditional is the route being mounted, not data arriving at it. That changes the moment production access is granted and one configuration value is switched, which requires no code change from us.
Our front end loads no third party service. There is no analytics tool, no tag manager, no external font or script host, and no error reporting vendor.
Data is stored and processed in the United States, and we are incorporated in Australia. If you are in the EEA, the UK or Switzerland, your data is therefore transferred outside your region. The transfer mechanism column above records what each provider publishes as available for those transfers.
One limit on that column is worth stating plainly. The Data Privacy Framework entries for Resend and Upstash are each taken from that provider's own data processing agreement, and we were not able to reach the US Department of Commerce register to corroborate them. The standard contractual clauses are on a different footing. Each provider's data processing addendum forms part of the agreement already in force rather than something we would have to accept separately, and each deems the clauses entered into and signed by both parties, so those mechanisms are in effect rather than merely offered.
If you need a signed data processing addendum consistent with Article 28 of the GDPR, ask us and we will provide one.
How it is protected
- Encrypted at rest. Survey data is encrypted with AES-256. Keys are managed through AWS KMS with rotation, access to them is restricted and logged. Our database provider holds SOC 2 Type 1 and Type 2.
- Encrypted in transit. All traffic uses TLS 1.2 or 1.3. Our database connections additionally require TLS and bind authentication to the encrypted channel.
- Credentials. No secret is stored in our source code. All credentials live in monday.com's secret store and are read at runtime.
- Access tokens. Your monday.com tokens are held only in monday.com's encrypted secure storage, scoped per account, refreshed with rotation, never sent to any browser or third party, and never written to a log.
- Isolation. Every record is scoped to your account, and every query filters on it.
- Input handling. Database queries are parameterised throughout. Submitted ratings, comments and answers are validated and bounded. Text placed into outbound email is escaped, so a comment or ticket title cannot inject content into a message.
- Survey links. Each link carries a signed single use token bound to one survey, and expires after a number of days you choose, fourteen by default.
No system is perfectly secure, and we cannot guarantee the security of information transmitted over the internet. If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it, and give you what you need to meet your own notification obligations.
How long we keep it
While your installation is active, survey records are kept so your dashboard and reports continue to work. You can delete individual responses at any time, and uninstalling triggers the process described in section 9.
Your configuration and your stored responses live as long as your installation does, and then for seven days longer. Uninstalling defers deleting them rather than performing it, and reinstalling inside those seven days brings them back. Some things are deleted at once even so, and there is one case where a rating is lost outright; the first of the three entries below sets out both. Section 9 describes what runs when the window closes.
Held surveys run on a clock of their own, and uninstalling does not pause it. A held record is kept for at least 60 days, measured from when it was held, and a daily sweep removes the ones past that point, so how long any single record lasts depends on when it crosses. That sweep keeps running through the seven day window, with no exception for accounts that have uninstalled.
The two clocks are unrelated, which is easiest to see at the edges. A record that was already 58 days old when you uninstalled is deleted on the second day of the window, not the seventh. One held the day before you uninstalled is still there when the window closes, and goes then with everything else.
Three things we keep on purpose
Your configuration and your stored responses, for seven days after you uninstall. Your settings and your survey responses, including the comments people wrote, stay in our database for seven days after an uninstall and are then deleted. What the window holds is every response, rating, comment and answer, your held records, your board configuration including your questions, your branding text and your exclusion list, and the logo you uploaded. Reinstall inside the window and all of that is still there. Let it close and it is gone, and a later install starts from nothing.
Some things are deleted at once regardless, because they depend on an authorization that uninstalling revokes: the per item working data in monday.com's own storage, the index that points your boards at your account, and our copy of your access token. Reinstalling rebuilds those. It does not recover them.
One thing the window does not cover at all, and we would rather name it than write “everything” and be wrong in the case that matters most to the person it happened to. When somebody submits a rating, it rests for a moment in a lock in monday.com's storage before it is written to our database. That lock is deleted immediately on every uninstall path, for the same reason as the items above. So if one of your customers rates in the minutes before you uninstall, and their record has not been written yet, that rating is gone and no reinstall brings it back. It is a narrow race rather than a routine outcome, but it is a real one.
This is for your convenience, not because we need it. We do not use the data during that window: no surveys are sent, no dashboard is reachable, and existing survey links stop working until you reinstall. Uninstalling to troubleshoot, or uninstalling on the wrong account, would otherwise mean rebuilding your questions, your branding and your exclusion list from nothing, and that is the only reason the window exists.
If you want it gone sooner, ask us and we will delete it immediately. There is no in-product control we can point you at for this, because by then the app has been removed from your account, so the route is to write to us. See section 14.
Suppression entries. When someone unsubscribes, or their mailbox hard bounces, or they report a message as spam, we record that against a one way cryptographic hash of their address. We keep it after you uninstall, and it is shared across all Survey Flow customers, because every customer sends through the same email domain and a complaint against that domain has to be honored for everyone. Deleting it would let a later installation email somebody who has already asked us to stop.
We want to be precise about what hashing does here. A hashed email address is pseudonymous data under the GDPR, not anonymous data. Somebody who already holds a candidate address can hash it and check for a match. Hashing means we cannot read the list to recover addresses, and it does not put the data outside the scope of data protection law. We do not claim otherwise.
Completion markers. A small record noting that a given survey was answered, so the same person is not asked twice about the same ticket. It is stored against an opaque identifier in monday.com’s storage inside your account, and it is deleted when you uninstall, together with the per item working data described above. It is not kept for the seven day window. The only case in which one outlives the uninstall is the one in section 9 where your authorization is already gone, and then it expires by itself within 92 days.
We should be equally precise about what that marker holds. Almost always it holds the identifier and nothing else. The exception is when our database is unreachable at the moment somebody submits a rating. The marker then carries the rating itself, including the score, the comment and any answers, because for that period it is the only copy of what the person told you. It is shrunk back to the identifier once the record is written. So there are windows in which a completion marker does hold personal data, and we would rather describe them than call the marker empty and be wrong some of the time.
What happens when you uninstall
We will not tell you that everything is deleted, because that would not be true in every case. The accurate answer has four parts, and the first thing to say is that most of it does not happen on the day you uninstall.
The normal case
When you uninstall or revoke authorization, we receive a notification from monday.com and record your account as due for deletion seven days later. The things listed in section 8 as going at once do go at once: the per item working data, the board index, the survey lock and our copy of your access token. Your board configuration and your survey responses are left where they are, and if you reinstall inside those seven days the deletion is cancelled and they come back. That is the window described in section 8.
When the seven days expire, the deletion sequence runs over whatever is still there, in a deliberate order.
- Survey records in our external database are deleted first, because that is the part held outside monday.com and it must not depend on anything that could fail.
- Any uploaded logo in monday.com storage is swept next.
- Your board configuration goes last, because it is the only record of which boards to look for a logo on.
What was deleted on the day you uninstalled, in monday.com’s storage, is confirmed by searching for what remains rather than by counting successful delete calls, because a delete call reports success even for something that was never there.
Aside from the suppression entries described in section 8, and the follow-up items described next, this removes your data.
Follow-up items on your boards stay
Nothing in the product deletes or archives a follow-up item. There is no delete call and no archive call anywhere in it. Items created from your responses stay on your board after you uninstall, with the comment, the answers, the rating and the ticket title in them, and they stay there permanently unless somebody on your team removes them. Deleting our own survey records, which we do, does not touch them, because the copy inside the item is a second copy and it lives on your board rather than on our systems.
That is a choice rather than an oversight, so here is the reasoning behind it. A follow-up item is work one of your admins created on your own board. It is the same kind of object as a task they wrote themselves, and once it exists it has its own life on your team's board: it may since have been assigned to somebody, commented on, moved, edited, or built into how you work. Deleting all of it at uninstall would destroy that work, without asking, on the way out. We would rather leave the item where its owner put it and tell you plainly that it is still there.
If you want them gone, they are yours to remove. They are ordinary monday.com items on a board you control, and what your customer wrote is in the item's updates.
One case where a little survives
If your monday.com authorization has already expired or been revoked by the time you uninstall, we can no longer authenticate to the storage inside your account, so the items listed in section 8 as deleted at once cannot all be deleted. Rather less turns on that than it used to, because your board configuration now lives in our own database rather than in yours. When it happens:
- All survey records in our external database are still deleted in full.
- Your board configuration is still deleted in full, using our own credentials. That covers your exclusion list, which holds email addresses in plain form, the labels of any conditions you set on a people column, which are the names of your own staff, and the identifier of anyone nominated for a low rating alert. None of it depends on your authorization still being valid.
- Per item survey state, including completion markers, expires by itself within 92 days.
- A webhook registration record remains. It holds no personal data.
What is left in this case sits in monday.com's own storage inside your own account rather than on our systems, and we attempt the deletion regardless in case the stored token is still accepted. It is a shorter list than it once was, but we would still rather state the limitation plainly than describe deletion as complete when it is not.
If you want deletion confirmed
Write to us and we will run the deletion again and tell you what was found. See section 14.
Your rights, and the rights of the people you survey
If you are a monday.com customer using Survey Flow, you can export your survey data, delete individual responses, or delete everything by uninstalling. Write to us if you would like help with any of these.
If you received a survey from a company using Survey Flow and want your data corrected or deleted, the company that surveyed you controls it and is best placed to act. Contact them first. If you cannot reach them, or you would rather come to us, write to us and we will help, and pass the request on where we need their instruction.
Every survey email carries an unsubscribe link, and using it stops further surveys from that sender immediately. Depending on where you live you may also have rights of access, correction, deletion, restriction, portability and objection.
We acknowledge any privacy request within 5 business days and respond substantively within 30 days, unless the request is complex enough to justify longer, in which case we will tell you.
If you think we have mishandled your personal information, please raise it with us first. You can also complain to a regulator: residents of Australia to the Office of the Australian Information Commissioner, and residents of the EEA or the UK to their national supervisory authority.
Cookies and tracking
Survey Flow sets no cookies. Not in the app, not on the survey page, not on the unsubscribe page. There is no analytics, no tracking pixel, no advertising technology, and no third party script of any kind.
Authentication inside monday.com uses a session token supplied by monday.com rather than a cookie. The survey page authenticates through a signed token in its own link.
Our backend is hosted on monday.com’s infrastructure, which uses Cloudflare. Cloudflare may set its own __cf_bm bot-management cookie on responses from that host. It is set by the hosting layer, not by Survey Flow, and our code neither sets nor reads it. Cloudflare classifies it as strictly necessary; it expires after 30 minutes of inactivity.
Our emails contain no tracking pixel. We know that a message was delivered, bounced or reported as spam because the email provider tells us. We do not track whether it was opened.
Links to other sites
Our documentation, marketplace listing and app interface may link to websites we do not run. This policy does not cover them, and we are not responsible for how they handle your data.
Changes to this policy
Non material changes, such as clarifications and corrections, are reflected in the date at the top of this page.
Material changes, such as adding a sub processor or changing what we retain, are different. We will tell active customers by email and update the marketplace listing, rather than relying on you to notice. We will do that at least 14 days before the change takes effect, which is the same notice the terms of service give for a material change to them. This policy forms part of that agreement, so the two run on one clock rather than on two.
Contact us
Email support@aiverylabs.com, or open a request at our support portal.
Survey Flow is operated by AIVERY LABS PTY LTD, ABN 89 696 967 209 and ACN 696 967 209, a company incorporated in Western Australia, Australia.
Surveys are sent from noreply@survey.aiverylabs.com, which is the address to allow if your mail filtering is strict.
This policy describes how Survey Flow handles data. It does not replace or modify monday.com's own privacy policy, which separately governs the monday.com platform.