Progressify
Approvals Desk

Privacy policy

This policy explains how Progressify handles data when your monday account installs and uses Approvals Desk.

Provider and scope

Approvals Desk is provided by Progressify. This policy covers the app; the separate website privacy policy covers visits to progressify.com.au.

Data the app uses

  • monday account and user identifiers, role and view-only state
  • board, item and subitem identifiers needed to authorize and attach approvals
  • approver and delegate identifiers, workflow rules, decisions, timestamps, notes and rejection reasons
  • Standard templates and scheduled leave-cover settings
  • encrypted OAuth credentials, scheduler checkpoints and notification-delivery metadata

Do not place passwords, credentials, highly sensitive personal information or regulated data in approval notes or rejection reasons.

Why the app uses this data

Progressify processes this data only to provide, secure, support and troubleshoot approval workflows, verify access, deliver seated-user monday notifications, run supported-region leave cover and meet legal obligations. We do not sell app data, use it for advertising or train AI models with it.

monday permissions

  • me:read — confirm the current account, user and role
  • boards:read — verify access to the current board, item or subitem
  • users:read — show active seated users for approver and delegate selection
  • notifications:write — notify seated monday users about approval work

Storage, regions and security

The app runs on monday code and stores app records in monday-managed DocumentDB infrastructure in the account's assigned US, EU, AU or IL region. Progressify does not operate a separate customer database. OAuth credentials are additionally encrypted with AES-256-GCM and bound to the exact account and user. Approval events are ordered and hash-chained for tamper detection; this does not make them immutable.

Automated leave-cover scheduling is unavailable in IL. Manual delegation, templates and other Standard workflows remain available there.

Third-party services

Runtime connections are limited to monday.com APIs, OAuth and hosted infrastructure, plus Google's public signing-key endpoint to verify scheduler identity. The Google request contains no approval or customer content. The app does not use third-party analytics, advertising, AI or email-delivery services.

Logs

monday code captures HTTP and application logs for operations and security. The app is designed not to log secrets, authorization tokens, approval content or personal email addresses. Progressify does not export or maintain a separate app-log archive; monday controls the hosted log retention period.

Retention and deletion

  • Approval history, templates and leave settings remain while the app is installed unless the related workflow or configuration is deleted.
  • Delivered notification payloads are removed after 30 days; dead-letter payloads are removed after 90 days.
  • Disconnect removes the applicable stored OAuth credential and scheduler ownership.
  • Uninstall purges the account's Approvals Desk records. If automatic cleanup needs recovery, Progressify will complete deletion within 10 days of termination unless retention is legally required or the account gives explicit written consent.

Your choices and questions

Your monday account administrator controls installation, plan and removal. To request access, correction or deletion help, or ask a privacy question, email info@progressify.com.au. We may need the app name, account and a safely redacted identifier to verify the request.

Policy changes

We may update this policy when the app or legal requirements change. Material changes will be communicated through the app, marketplace or service contact channel where required.

Provider: AUSSIEKEYS PTY LTD · ABN 67 652 651 977 · Last updated: 23 August 2026