Back to Survey Flow

Privacy Policy

Survey Flow, operated by AIVERY LABS PTY LTD. Last updated 7 October 2026.

Survey Flow sends satisfaction surveys to your customers and collects their answers, so it necessarily handles personal data. This policy sets out exactly what we hold, where it lives, who inside your company can see it, how long it stays, and what happens when you uninstall. Where something is retained rather than deleted, we say so and explain why. The same goes for text that is sent to a model, and for content that is written onto one of your boards and stays there after you uninstall.

Who is responsible for what

Two different relationships run through this product, and they carry different responsibilities.

You are the controller of your survey data. When you install Survey Flow on your monday.com account, you decide who receives a survey, what they are asked, and what happens to the answers. We process that data on your instructions and for no other purpose. We are your processor.

We are the controller of the suppression list. Every Survey Flow customer sends through the same email domain, so when someone unsubscribes or their mailbox rejects our mail, honoring that is our own obligation rather than yours.

Three things outlive an uninstall, and they are not alike. A seven day window holds your data before deletion runs, and then it is gone. Follow-up items stay on your own boards, where they are yours to keep or to remove. The third is this suppression list, and it is the only one we keep indefinitely, and the only one we keep for a purpose of our own. Section 8 covers the window and the list, and section 9 covers the items.

Recipients of a survey are your customers, not ours. We hold no relationship with them and we never contact them for our own purposes.

We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU General Data Protection Regulation (EU) 2016/679, and the monday.com marketplace developer terms.

What we handle

About the people who receive surveys

DataWhere it comes from
Email addressThe board column you nominate during setup
Display name, where one existsThe same source. Where no name exists, the email address is used as the label instead
Star rating, one to fiveSubmitted by the recipient
Written comments and answers to follow up questionsSubmitted by the recipient. These are free text, so they contain whatever the writer chooses to include
Ticket title at the time the survey was sentYour board. This is your content and may name a person or a situation
Delivery outcome, including bounces and complaintsOur email provider
Timestamps for send, response and link expiryGenerated by the app

About your team

We store monday.com user identifiers for the agent assigned to each ticket, so that feedback can be attributed and shown to the right person. We read profile and time zone information from monday.com when rendering the dashboard, but we do not store your team members' names or email addresses.

That remains true of what we store. It is no longer the whole picture of what we disclose. When somebody asks one of our Sidekick skills for feedback, we resolve the assigned agent's monday.com display name at that moment and return it in the reply, next to the customer's comment. The name is not kept, but it does reach a chat surface that is not ours. Section 4 describes that path.

Where you configure a low rating alert, we store the identifier of the person to be notified.

Configuration you provide

Board and item identifiers, your trigger status and conditions, your questions and email wording, your sender display name and logo, and your exclusion list.

A logo has to be a PNG, JPEG or WebP, identified by its actual bytes rather than by what the upload declares, and anything over 256 KB is refused. We strip the metadata before storing it, which for a photograph means the location it was taken, the camera serial number, timestamps and editing history. That is the whole of what stripping does. The picture is untouched, so if you upload a team photo or a portrait of somebody, that is what we hold and what your customers see.

Surveys waiting to be sent

When your account reaches its monthly plan allowance, tickets that resolve are held rather than sent, so the survey is not lost. A held record holds a board identifier, an item identifier and a timestamp. No address, no name and no comment.

A note about the exclusion list

Addresses you add to the exclusion list are stored as you typed them, in plain form, because the app has to show them back to you for editing. Treat that list as customer data.

What we deliberately do not hold

Why we handle it

Everything above exists to run the product you configured: deciding whether a survey should be sent, sending it, collecting the answer, showing it to you and to the agent who handled the work, and notifying someone when a rating falls below the threshold you set.

We do not sell personal data. We do not use it to train models. We do not use it for advertising, profiling, or any purpose of our own beyond operating and supporting the service.

Some of that content is sent to a model to be read or written about, though never to train one. Section 4 sets out which features do it, what each one sends, what turns them on, and what monday.com says happens to the text afterwards.

For customers in the EEA and the UK, our lawful basis for processing on your behalf is the performance of our contract with you. You remain responsible for establishing the lawful basis on which you survey your own customers. Our own retention of suppression data rests on legitimate interests, specifically the interest in not repeatedly emailing people who have asked us to stop or whose mailbox has rejected our mail.

What we send to AI, and when

Some of what your customers write is sent to monday.com's AI to be read or written about. This section says which features do that, exactly what each one sends, and what we know and do not know about where it goes next.

Four paths lead to a model. Three of them, the ones in the table, are switched off until you switch them on: the AI question mode defaults to off, and labelling is off unless you turn it on. If you leave both alone, no comment and no answer is ever sent to a model by any of the three, and turning either one on is a decision to send what the table describes. The fourth path is not gated on anything, and it is set out after the table.

FeatureWhen it runsWhat is sent
Opening questionBefore the customer has typed anythingThe ticket title, how many days the ticket took to close, and the rating. There is no comment yet, so no comment is sent
Probe questionLive, while the customer is still answeringThe ticket title, days to close, the rating, the comment exactly as written, and the conversation so far
LabellingAfter the survey is submitted, with nobody presentThe ticket title, days to close, the rating, the comment exactly as written, and every answer exactly as written

Nothing is redacted, truncated or summarised first. We pass no recipient email address and no display name as a field of any of these requests. But a comment is free text, so if your customer types their own address or phone number into it, that goes verbatim with everything else, and a ticket title carries whatever your board carries.

A fourth path, which no setting controls

Survey Flow also publishes two skills to monday.com's Sidekick assistant. One finds feedback; the other creates a follow-up item from a response. The one that finds feedback returns, for each response it matches, the comment exactly as written, every follow-up answer run together, the CSAT score, the ticket title, a date, and the assigned agent's monday.com display name, which is one of your own staff. That reply is handed to Sidekick, which writes its answer out of it.

So customer comments reach a model here too, on a path of its own. Unlike the three features above, this one is not gated on any setting. Anyone who can invoke the skill, which means an admin or a board owner, reaches it. Section 5 covers where the answer then appears and who can read it.

What happens to it once it leaves

All four paths call monday.com's AI, so the text goes to monday.com first. monday.com states in its AI Trust Center that it does not use input or output to train models and does not allow anyone else to, and that it reaches large language models through managed APIs from Microsoft Azure and AWS Bedrock under zero retention policies. The text therefore does not stop at monday.com. It leaves monday.com's own infrastructure, and the monday.com row of the table in section 6 records that routing.

Two limits on that are worth stating rather than leaving you to assume they were checked.

Who can see it

This section matters more than most, because it determines who inside your own company sees your customers' contact details. Read it before rolling Survey Flow out to a wide group.

Agents can see who left a given response. The per agent dashboard shows each response alongside the recipient it came from. Where a display name exists, the display name appears. Where the app holds only an email address, the email address appears. This is what makes per agent feedback useful, and it is more exposure than some teams expect.

Low rating alerts carry the same information. Whoever you nominate receives a monday.com notification identifying the ticket and the customer who left the rating, whether or not that person ever opens Survey Flow.

A follow-up item puts the response onto one of your boards. When a response is turned into a follow-up item, the update on that item carries the rating and the date it was given, the labels still outstanding, the comment exactly as written under the heading “What the customer wrote”, and every follow-up question that was answered, with its answer. The item's name is the label followed by the ticket title, so the ticket title itself turns up in board views, in search results and in notifications. No recipient email address is included anywhere in it; that was deliberately left out.

Who can read that is a different question from who can use Survey Flow, and the answer is wider. It is whoever can see the destination board, which is that board's membership on monday.com, set by whoever administers it, and unconnected to who can open the app. An item created from a response is legible to people the app itself would never show it to, so choose the destination board with that in mind. Section 9 explains what happens to these items when you uninstall, which is nothing.

Sidekick answers land outside the app. When somebody asks a Sidekick skill for feedback, the answer is composed out of the comments, answers, scores, ticket titles and agent display names described in section 4, and it appears in a monday.com chat transcript. How long that transcript is kept, and who else can read it, is governed by monday.com rather than by us.

Beyond your own account, access is limited to us. A small number of our personnel can access survey data where it is necessary to operate or support the service, and our sub processors can access it only to the extent needed to provide their part of it.

We may also disclose personal information to our contractors and professional advisors where they need it to do work for us, to courts, regulators and law enforcement where the law requires it, and to a successor entity if our business or assets are transferred. We do not sell, rent or trade personal data, and we do not disclose it for any other purpose.

Where it is stored, and who else is involved

Survey data is stored outside monday.com, in a managed Postgres database. monday.com has confirmed in writing that this is acceptable for this app, subject to the security conditions described in section 7, in support ticket #5047188 dated 29 July 2026.

Your board configuration is held in the same database, alongside the survey records. Per item survey state and uploaded logos are stored in monday.com's own storage, inside your account. Your monday.com access tokens are held in monday.com's encrypted secure storage and never leave our backend.

Sub processors

ProviderPurposeLocationTransfer mechanism
Neon, operated by Neon, LLC, a Databricks, Inc. companyManaged Postgres. Holds survey records, ratings, comments and recipient labelsAWS us-east-1Standard contractual clauses, Modules Two and Three, with the UK Addendum for UK transfers and Swiss modifications. The Databricks data processing addendum deems them incorporated for any restricted transfer, rather than only if another mechanism fails. It names no Data Privacy Framework certification. The governing terms are the Product Specific Schedule (Neon) under the Databricks Master Cloud Services Agreement
ResendSends the survey emails, and reports bounces and complaints. This is the active sending providerUnited States. Resend's region setting controls where mail is sent from, not where data is storedEU and UK standard contractual clauses. Resend's own data processing agreement additionally states it has certified to the US Department of Commerce under the EU-U.S. Data Privacy Framework and the UK Extension
Amazon SESA second fully integrated sending path, selectable by configuration. Not currently able to send, pending AWS production accessus-east-1Standard contractual clauses, applied by the AWS Service Terms by default rather than on request. AWS is also covered by Amazon.com's Data Privacy Framework certification
Amazon SNSCarries bounce and complaint notifications for mail sent through SES. Receives data only while SES is the sending providerus-east-1Standard contractual clauses, applied by the AWS Service Terms by default rather than on request. AWS is also covered by Amazon.com's Data Privacy Framework certification
Upstash QStashJob queue. Carries board, item and monday account identifiers. No recipient address, no name, no survey contentAWS us-east-1Upstash's own data processing agreement states it relies on the Data Privacy Framework, with the standard contractual clauses incorporated by reference if required
monday.comApplication hosting, configuration storage, token storage. Object storage for any logo you upload. AI processing: the requests described in section 4 are sent to monday.com's AI through run_prompt, and monday.com states that it routes them onward to large language models at Microsoft Azure and AWS BedrockUnited StatesYou have a direct agreement with monday.com. The transfer mechanism for that processing sits in monday.com's own data processing addendum, not in this policy. The same is true of the onward routing to Microsoft Azure and AWS Bedrock, which happens inside monday.com's supply chain rather than ours

Both bounce and complaint routes stay mounted at all times, so that handling a rejection never depends on which provider sent the message. Resend and Amazon SES each report through their own separate lane, and Resend's is the lane carrying data today. Amazon SES cannot send until AWS grants production access, so it produces no bounces, Amazon SNS has nothing to deliver, and AWS receives no recipient addresses or delivery outcomes at present. What is unconditional is the route being mounted, not data arriving at it. That changes the moment production access is granted and one configuration value is switched, which requires no code change from us.

Our front end loads no third party service. There is no analytics tool, no tag manager, no external font or script host, and no error reporting vendor.

Data is stored and processed in the United States, and we are incorporated in Australia. If you are in the EEA, the UK or Switzerland, your data is therefore transferred outside your region. The transfer mechanism column above records what each provider publishes as available for those transfers.

One limit on that column is worth stating plainly. The Data Privacy Framework entries for Resend and Upstash are each taken from that provider's own data processing agreement, and we were not able to reach the US Department of Commerce register to corroborate them. The standard contractual clauses are on a different footing. Each provider's data processing addendum forms part of the agreement already in force rather than something we would have to accept separately, and each deems the clauses entered into and signed by both parties, so those mechanisms are in effect rather than merely offered.

If you need a signed data processing addendum consistent with Article 28 of the GDPR, ask us and we will provide one.

How it is protected

No system is perfectly secure, and we cannot guarantee the security of information transmitted over the internet. If we become aware of a breach affecting your data, we will notify you without undue delay and in any event within 72 hours of becoming aware of it, and give you what you need to meet your own notification obligations.

How long we keep it

While your installation is active, survey records are kept so your dashboard and reports continue to work. You can delete individual responses at any time, and uninstalling triggers the process described in section 9.

Your configuration and your stored responses live as long as your installation does, and then for seven days longer. Uninstalling defers deleting them rather than performing it, and reinstalling inside those seven days brings them back. Some things are deleted at once even so, and there is one case where a rating is lost outright; the first of the three entries below sets out both. Section 9 describes what runs when the window closes.

Held surveys run on a clock of their own, and uninstalling does not pause it. A held record is kept for at least 60 days, measured from when it was held, and a daily sweep removes the ones past that point, so how long any single record lasts depends on when it crosses. That sweep keeps running through the seven day window, with no exception for accounts that have uninstalled.

The two clocks are unrelated, which is easiest to see at the edges. A record that was already 58 days old when you uninstalled is deleted on the second day of the window, not the seventh. One held the day before you uninstalled is still there when the window closes, and goes then with everything else.

Three things we keep on purpose

Your configuration and your stored responses, for seven days after you uninstall. Your settings and your survey responses, including the comments people wrote, stay in our database for seven days after an uninstall and are then deleted. What the window holds is every response, rating, comment and answer, your held records, your board configuration including your questions, your branding text and your exclusion list, and the logo you uploaded. Reinstall inside the window and all of that is still there. Let it close and it is gone, and a later install starts from nothing.

Some things are deleted at once regardless, because they depend on an authorization that uninstalling revokes: the per item working data in monday.com's own storage, the index that points your boards at your account, and our copy of your access token. Reinstalling rebuilds those. It does not recover them.

One thing the window does not cover at all, and we would rather name it than write “everything” and be wrong in the case that matters most to the person it happened to. When somebody submits a rating, it rests for a moment in a lock in monday.com's storage before it is written to our database. That lock is deleted immediately on every uninstall path, for the same reason as the items above. So if one of your customers rates in the minutes before you uninstall, and their record has not been written yet, that rating is gone and no reinstall brings it back. It is a narrow race rather than a routine outcome, but it is a real one.

This is for your convenience, not because we need it. We do not use the data during that window: no surveys are sent, no dashboard is reachable, and existing survey links stop working until you reinstall. Uninstalling to troubleshoot, or uninstalling on the wrong account, would otherwise mean rebuilding your questions, your branding and your exclusion list from nothing, and that is the only reason the window exists.

If you want it gone sooner, ask us and we will delete it immediately. There is no in-product control we can point you at for this, because by then the app has been removed from your account, so the route is to write to us. See section 14.

Suppression entries. When someone unsubscribes, or their mailbox hard bounces, or they report a message as spam, we record that against a one way cryptographic hash of their address. We keep it after you uninstall, and it is shared across all Survey Flow customers, because every customer sends through the same email domain and a complaint against that domain has to be honored for everyone. Deleting it would let a later installation email somebody who has already asked us to stop.

We want to be precise about what hashing does here. A hashed email address is pseudonymous data under the GDPR, not anonymous data. Somebody who already holds a candidate address can hash it and check for a match. Hashing means we cannot read the list to recover addresses, and it does not put the data outside the scope of data protection law. We do not claim otherwise.

Completion markers. A small record noting that a given survey was answered, so the same person is not asked twice about the same ticket. It is stored against an opaque identifier in monday.com’s storage inside your account, and it is deleted when you uninstall, together with the per item working data described above. It is not kept for the seven day window. The only case in which one outlives the uninstall is the one in section 9 where your authorization is already gone, and then it expires by itself within 92 days.

We should be equally precise about what that marker holds. Almost always it holds the identifier and nothing else. The exception is when our database is unreachable at the moment somebody submits a rating. The marker then carries the rating itself, including the score, the comment and any answers, because for that period it is the only copy of what the person told you. It is shrunk back to the identifier once the record is written. So there are windows in which a completion marker does hold personal data, and we would rather describe them than call the marker empty and be wrong some of the time.

What happens when you uninstall

We will not tell you that everything is deleted, because that would not be true in every case. The accurate answer has four parts, and the first thing to say is that most of it does not happen on the day you uninstall.

The normal case

When you uninstall or revoke authorization, we receive a notification from monday.com and record your account as due for deletion seven days later. The things listed in section 8 as going at once do go at once: the per item working data, the board index, the survey lock and our copy of your access token. Your board configuration and your survey responses are left where they are, and if you reinstall inside those seven days the deletion is cancelled and they come back. That is the window described in section 8.

When the seven days expire, the deletion sequence runs over whatever is still there, in a deliberate order.

What was deleted on the day you uninstalled, in monday.com’s storage, is confirmed by searching for what remains rather than by counting successful delete calls, because a delete call reports success even for something that was never there.

Aside from the suppression entries described in section 8, and the follow-up items described next, this removes your data.

Follow-up items on your boards stay

Nothing in the product deletes or archives a follow-up item. There is no delete call and no archive call anywhere in it. Items created from your responses stay on your board after you uninstall, with the comment, the answers, the rating and the ticket title in them, and they stay there permanently unless somebody on your team removes them. Deleting our own survey records, which we do, does not touch them, because the copy inside the item is a second copy and it lives on your board rather than on our systems.

That is a choice rather than an oversight, so here is the reasoning behind it. A follow-up item is work one of your admins created on your own board. It is the same kind of object as a task they wrote themselves, and once it exists it has its own life on your team's board: it may since have been assigned to somebody, commented on, moved, edited, or built into how you work. Deleting all of it at uninstall would destroy that work, without asking, on the way out. We would rather leave the item where its owner put it and tell you plainly that it is still there.

If you want them gone, they are yours to remove. They are ordinary monday.com items on a board you control, and what your customer wrote is in the item's updates.

One case where a little survives

If your monday.com authorization has already expired or been revoked by the time you uninstall, we can no longer authenticate to the storage inside your account, so the items listed in section 8 as deleted at once cannot all be deleted. Rather less turns on that than it used to, because your board configuration now lives in our own database rather than in yours. When it happens:

What is left in this case sits in monday.com's own storage inside your own account rather than on our systems, and we attempt the deletion regardless in case the stored token is still accepted. It is a shorter list than it once was, but we would still rather state the limitation plainly than describe deletion as complete when it is not.

If you want deletion confirmed

Write to us and we will run the deletion again and tell you what was found. See section 14.

Your rights, and the rights of the people you survey

If you are a monday.com customer using Survey Flow, you can export your survey data, delete individual responses, or delete everything by uninstalling. Write to us if you would like help with any of these.

If you received a survey from a company using Survey Flow and want your data corrected or deleted, the company that surveyed you controls it and is best placed to act. Contact them first. If you cannot reach them, or you would rather come to us, write to us and we will help, and pass the request on where we need their instruction.

Every survey email carries an unsubscribe link, and using it stops further surveys from that sender immediately. Depending on where you live you may also have rights of access, correction, deletion, restriction, portability and objection.

We acknowledge any privacy request within 5 business days and respond substantively within 30 days, unless the request is complex enough to justify longer, in which case we will tell you.

If you think we have mishandled your personal information, please raise it with us first. You can also complain to a regulator: residents of Australia to the Office of the Australian Information Commissioner, and residents of the EEA or the UK to their national supervisory authority.

Cookies and tracking

Survey Flow sets no cookies. Not in the app, not on the survey page, not on the unsubscribe page. There is no analytics, no tracking pixel, no advertising technology, and no third party script of any kind.

Authentication inside monday.com uses a session token supplied by monday.com rather than a cookie. The survey page authenticates through a signed token in its own link.

Our backend is hosted on monday.com’s infrastructure, which uses Cloudflare. Cloudflare may set its own __cf_bm bot-management cookie on responses from that host. It is set by the hosting layer, not by Survey Flow, and our code neither sets nor reads it. Cloudflare classifies it as strictly necessary; it expires after 30 minutes of inactivity.

Our emails contain no tracking pixel. We know that a message was delivered, bounced or reported as spam because the email provider tells us. We do not track whether it was opened.

Our documentation, marketplace listing and app interface may link to websites we do not run. This policy does not cover them, and we are not responsible for how they handle your data.

Changes to this policy

Non material changes, such as clarifications and corrections, are reflected in the date at the top of this page.

Material changes, such as adding a sub processor or changing what we retain, are different. We will tell active customers by email and update the marketplace listing, rather than relying on you to notice. We will do that at least 14 days before the change takes effect, which is the same notice the terms of service give for a material change to them. This policy forms part of that agreement, so the two run on one clock rather than on two.

Contact us

Email support@aiverylabs.com, or open a request at our support portal.

Survey Flow is operated by AIVERY LABS PTY LTD, ABN 89 696 967 209 and ACN 696 967 209, a company incorporated in Western Australia, Australia.

Surveys are sent from noreply@survey.aiverylabs.com, which is the address to allow if your mail filtering is strict.

This policy describes how Survey Flow handles data. It does not replace or modify monday.com's own privacy policy, which separately governs the monday.com platform.