Share & Listen App Terms and Conditions
Share & Listen is operated by Humanity Link B.V.
Humanity Link B.V. is a Dutch limited liability company (besloten vennootschap), with its registered office at Helperpark, Unit 2767, 9723ZA Groningen, the Netherlands, registered with the Dutch Commercial Register (Kamer van Koophandel) under number 93687842 (“Humanity Link”, “we”, “us”, or “our”).
This policy describes how we handle personal data through the Share & Listen app (“the Service”), which you install on your monday.com account to send broadcast messages and run AI-powered conversational surveys over SMS, WhatsApp, and RCS.
Because the Service is used by businesses to communicate with their own contacts, this policy addresses two different relationships, and the rules that apply depend on which one is relevant to you:
If you’re the monday.com account holder using the ServiceFor your own account and settings data — your admin/sender email addresses, messaging credentials, app settings, and usage/billing information — Humanity Link is the data controller. This policy governs that data directly.
If you’re a recipient of a message or survey sent through the ServiceFor data about you that the account holder collects through the Service — your phone number, name, responses, and similar information — Humanity Link acts only as a data processor / service provider, on the account holder’s instructions. The account holder is the controller of that data and is responsible for its own privacy notice to you and for having a lawful basis to contact you. If you have questions about how your data is used, please contact the organization that messaged you.
Information we collectAccount & settings data (we are the controller)
- Admin notification and sender email addresses you enter in Settings
- Your Twilio Account SID/Auth Token and SendGrid API key, which you provide so the Service can send messages and emails through your own Twilio and SendGrid accounts (encrypted at rest in monday.com‘s SecureStorage)
- Your monday.com OAuth authorization token (encrypted at rest in monday.com‘s SecureStorage)
- The sender phone numbers you configure
- App settings, feature toggles, and usage/billing metering data
Respondent & contact data (we process this on the account holder’s behalf)
- Recipient phone numbers
- Names, cities, countries, and any other fields present in contact lists imported via CSV or a monday.com board
- Survey responses and message/conversation transcripts, which are written to the account holder’s own monday.com board
- Consent and opt-out status for each contact
- AI-inferred profile attributes, where the account holder enables the optional Profile Builder feature — see “Automated processing & profiling” below
Technical dataThe Service does not set or read first-party cookies. Authentication uses short-lived JWT session tokens sent in the Authorization header, not cookies. The Service’s frontend stores one non-personal flag in your browser’s local storage, to remember whether you’ve dismissed a welcome banner.
Exception: the Service’s “How to Use” help page includes optional Loom video tutorials. These are click-to-load: no video player, cookie, or request to Loom is loaded until you actively click to play a specific video. If you do, Loom’s embedded player may set its own cookies or collect your IP address under Loom’s own privacy practices, independent of the Service.
Automated processing & profilingThe Service’s conversational survey agent uses AI (Google Gemini) to interpret free-text answers, ask relevant follow-up questions, and generate summaries and tags. If the account holder enables the optional Profile Builder feature, the same AI is also used to automatically extract structured attributes from a conversation into a contact profile. The account holder configures which attributes are captured; by default this can include name, age, gender, city, country, and freeform “needs” or “problems” fields.
This automated processing is not used to make legal or similarly significant decisions about any individual — it is limited to interpreting and organizing survey responses.
Note for account holders: freeform attributes like “needs” or “problems” can capture health-related or other special-category information under GDPR Article 9. If you configure the Profile Builder to collect this kind of information, you — as the controller of your respondents’ data — are responsible for ensuring you have a valid legal basis to do so.
How we use information
- Delivering broadcast and conversational messages over SMS, WhatsApp, and RCS
- Running AI-powered conversational surveys and generating summaries/tags written back to your monday.com board
- Translating survey content across languages
- Sending template-approval and survey-completion notification emails
- Enforcing plan quotas and usage-based billing
- Security, fraud prevention, and abuse detection
- Complying with legal obligations
Legal bases for processing (GDPR)
- Performance of a contract — to provide the Service to the account holder
- Legitimate interests — for security, fraud prevention, and improving the Service
- Consent — where the account holder’s own consent flows with their recipients apply (see “Consent & messaging” below)
- Legal obligation — where required by applicable law
Who we share information withWe do not sell personal information, and we do not share it for cross-context behavioral advertising.
Twilio & SendGridUsed under the account holder’s own Twilio and SendGrid account and credentials. Messages and emails are transmitted under the account holder’s direct contractual relationship with those providers — we do not route messages through an account of our own.
Google (Gemini, Cloud Translation)Run under our own Google Cloud account, as our sub-processor, to interpret survey responses, generate summaries, and translate content.
monday.comThe Service is built on monday.com‘s platform. Boards, app storage, and secure storage used by the Service are hosted on monday.com‘s infrastructure, scoped to your own account.International data transfers
Humanity Link is established in the European Union. Twilio, SendGrid, and Google process data in the United States. Where personal data is transferred outside the EEA/UK, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses and/or the relevant provider’s certification under the EU-U.S. Data Privacy Framework, as applicable.
Data retentionWe retain personal data for as long as your account remains active. When your account is uninstalled, we automatically delete the survey, contact, template, settings, and session records associated with your account from monday.com‘s app storage, delete your stored Twilio/SendGrid credentials, and revoke your monday.com authorization token.
A limited set of technical operational records (such as error-recovery queues and job-status logs) are not automatically deleted by this process. You may request deletion of any remaining personal data, including these records, by contacting us at support@humanity.link, and we will complete such deletion within 30 days.
Your rights under GDPRIf you are located in the EEA, UK, or Switzerland, you have the right to:
- Access the personal data we hold about you
- Request rectification of inaccurate data
- Request erasure of your data
- Request restriction of processing
- Receive your data in a portable format
- Object to processing based on legitimate interests
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority — for example, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), or your own local EU/EEA data protection authority
To exercise any of these rights, contact support@humanity.link. We have not appointed a Data Protection Officer, as one is not currently required for the nature and scale of our processing.
Your privacy rights in the United StatesIf you are a California resident, the CCPA/CPRA gives you additional rights.
In the preceding 12 months, we have collected the following categories of personal information: identifiers (name, phone number, email address), contact information, commercial/usage information (subscription and quota usage), and inferences (AI-generated summaries and tags). Where an account holder enables the optional Profile Builder feature, this may also include protected-classification-adjacent information such as age, gender, or location. We collect this information directly from account holders and their contacts, for the purposes described in “How we use information” above, and we share it with the service providers described in “Who we share information with.” We do not sell or share personal information as those terms are defined under the CCPA/CPRA.
California residents have the right to know what personal information we collect, to delete it, to correct inaccurate information, to opt out of the sale or sharing of personal information (we do not sell or share it), to limit the use of sensitive personal information, and to not be discriminated against for exercising these rights. To submit a request, contact contact@humanity.link; we may need to verify your identity before fulfilling a request. You may also designate an authorized agent to submit a request on your behalf.
Residents of other US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, and Utah) have similar rights, which can be exercised through the same contact.
Consent & messagingAccount holders are responsible for obtaining valid consent before messaging their own contacts through the Service. Messaging is subject to applicable law, including the U.S. Telephone Consumer Protection Act (TCPA).Recipients can opt out of further messages at any time by replying with any of the Service’s configured opt-out keywords (by default: STOP, UNSUBSCRIBE, CANCEL, QUIT, OPTOUT, OPT-OUT, or END). Opt-out status is recorded and honored for all future messages from that account.
Cookies & trackingThe Service does not use first-party cookies and does not run any first-party analytics or advertising trackers. Authentication uses short-lived JWT tokens in the Authorization header, and the frontend stores a single, non-personal “welcome banner dismissed” flag in your browser’s local storage.As noted above, the “How to Use” help page includes optional, click-to-load Loom video tutorials. Loom’s embedded player, and any cookies or IP collection under Loom’s own privacy practices, only loads if and when you actively click to play a specific video — it is never loaded automatically.
Data securityEach account’s data is isolated using that account’s own monday.com OAuth token, so access to one account’s data requires that account’s own credentials. Sensitive credentials (Twilio, SendGrid, and monday.com OAuth tokens) are encrypted at rest in monday.com‘s SecureStorage. Application logs mask phone numbers and email addresses and never record message content as text.
Children’s privacyThe Service is a business tool intended for use by organizations to communicate with their own contacts, and is not directed to children. We do not knowingly collect personal data from children.
Changes to this policyWe may update this policy from time to time.
Contact usHumanity Link B.V.Helperpark, Unit 27679723ZA Groningen, the NetherlandsDutch Commercial Register (KVK): 93687842Email: contact@humanity.link