1. Scope
This policy describes how NovessaWorks ERP Sync (the “App”) processes information when a customer connects monday with an Odoo 19 environment that has External API access enabled.
2. Information processed
monday account and user metadata
Account ID, user ID, board/group/column identifiers and mapping configuration, plus monday item IDs required to maintain synchronization identity.
Odoo configuration metadata
Odoo HTTPS base URL, optional database name, detected version/API capability and Odoo record identifiers used for synchronization identity.
Authentication credentials
monday OAuth access/refresh tokens and Odoo API keys are stored using monday secure storage capabilities and are not intentionally returned through normal settings APIs.
Sync and reliability metadata
Deterministic sync keys, source/target fingerprints, pagination cursor, schedule cadence/batch size, bounded run history and sanitized error/conflict records.
Business data in transit
Configured Odoo Contact, CRM Opportunity, Project and Task fields may be transmitted to monday; configured safe monday fields may be transmitted back to Odoo. The App is not designed to maintain a separate full copy of Odoo business records.
3. Purposes
Information is processed to authenticate the installed account, connect Odoo, discover boards and mappings, synchronize configured records, avoid duplicates, detect unsafe conflicts, execute schedules, provide diagnostics/history/support, enforce Marketplace subscription or trial access, and meet security or legal obligations.
4. Storage and security
The App uses monday-hosted services for app hosting, API access and secure storage. Controls include OAuth authorization code with PKCE S256, signed monday JWT verification, HTTPS-only Odoo connections, input validation and write allowlists, conflict checks, secret redaction, HSTS and Content Security Policy.
5. Service providers and third parties
- monday.com and monday-hosted app infrastructure — app hosting, API access, storage and scheduling.
- Customer-configured Odoo environment — the business-system endpoint selected by the customer.
- cdn.jsdelivr.net — browser delivery of the monday SDK where used by the deployed frontend.
6. Data retention
Configuration and synchronization metadata is retained only while needed to provide the installed App. Run and issue history is bounded by implementation limits. Platform logs follow the retention configuration of the services used by the deployed release.
7. Uninstall and deletion
When an authenticated uninstall event is received, the App attempts immediate cleanup of tracked application data, credentials and schedule metadata. Where monday Marketplace rules require a post-deauthorization deletion period, permanent deletion is completed within the applicable platform deadline unless valid written consent authorizes longer retention.
Deletion requests may be sent to [email protected].
8. Customer responsibilities
Customers choose the Odoo environment, least-privilege integration credentials, boards and fields to map, and remain responsible for lawful processing and internal permissions for configured business data.
9. International processing
monday and customer-configured Odoo environments may process data in provider- or customer-selected regions. Customers should review the regional and contractual terms of those independent platforms.
10. Children’s data
The App is a business productivity integration and is not directed to children.
11. Changes
This policy may be updated for product, legal, security or platform changes. The effective date will change when a material revision is published.
12. Contact
Provider / legal entity: Francisco Lopez Mercado
Brand: NovessaWorks
Location: Estado de Mexico, Mexico
Email: [email protected]