Privacy Policy

Effective date: 12 September 2026

1. Who we are

This policy applies to Alejandro González Parra, operating as Delta Integrations, and to all products and services we provide, including apps published on the Freshworks Marketplace and monday.com App Marketplace.

Contact: support@delta-integrations.com

2. Scope of this policy

This policy covers all apps published by Delta Integrations on third-party marketplaces, including but not limited to the Freshworks Marketplace and the monday.com App Marketplace. All of our apps share the same fundamental architecture: they run entirely on the host platform's infrastructure, inside the customer's own accounts. This policy does not cover the internal practices of Freshworks, Inc. or monday.com, each of which has its own privacy policy. Our website sets no tracking cookies of its own; if that changes, we will publish a separate notice.

3. How our apps handle data

We receive no customer data. Our apps run entirely on the serverless platform of the marketplace where they are installed, inside the customer's own accounts. We operate no servers, no database, and no infrastructure of any kind. There is no mechanism by which customer data could reach us.

What an app reads and writes depends on its specific function, but is limited to data within the customer's own accounts on the relevant platform, such as:

  • Records, items, tickets, or tasks within the platform
  • Fields, statuses, and configuration values on those records
  • Comments, notes, or activity related to those records
  • File attachments associated with those records
  • The name and email address of the person who triggered an event, used only for attribution

Data moves only between the accounts that the customer's own administrator has configured. Nothing leaves the host platform's infrastructure.

4. Data retention

We retain nothing. Our apps may use the host platform's temporary storage (such as a key-value store) solely to prevent duplicate operations during processing. Any such temporary data contains no record content and expires automatically within seconds.

On uninstall there is nothing for us to delete, because nothing is held by us.

5. Credentials

Where an app requires API keys or tokens to connect accounts, those credentials are stored as secure installation parameters by the host platform. The platform encrypts them at rest and does not return them to the browser. Credentials are used only inside server-side request templates and never appear in the app's code or logs.

6. Logs

Our apps write to the host platform's application log. Log lines may contain record identifiers, environment names, error messages, and in some cases the name of a field and a truncated field value when that information is needed to explain why a record was not processed. Log lines do not contain credentials, record descriptions, or message content.

Logs are held by the host platform under its own retention schedule and are visible to the customer's administrators. We do not access them.

7. Customer's responsibility for data sharing

The customer's own administrator decides which data is shared and between which accounts. This is a configuration the customer controls. Where the accounts being connected belong to different organisations, the customer is responsible for having a lawful basis to transfer data between them.

8. Security

All traffic is carried over HTTPS. Credentials are stored encrypted by the host platform as secure parameters. Because we operate no infrastructure, we make no claims about data centres, backups, or breach-detection systems; those are entirely the host platform's responsibility.

9. Sub-processors

The only sub-processors involved are the marketplace platforms our apps run on (such as Freshworks, Inc. or monday.com), which provide the infrastructure and act as merchant of record for subscriptions. No data is sent to any analytics service, advertising network, artificial intelligence service, or any other third party.

10. Controller and processor status (GDPR)

Whether we act as a data controller, a data processor, or neither under the GDPR depends on facts that a lawyer familiar with your specific deployment should confirm. Because we do not receive or access customer data, a reasonable reading is that we are neither; however, the answer may differ depending on jurisdiction and on how the customer's accounts are structured. This question is deliberately left open pending legal advice.

11. Your rights under the GDPR

If you are located in the European Economic Area, you have rights including access to, rectification of, erasure of, and restriction of processing of your personal data. Because we do not hold any personal data ourselves, requests should be directed to the organisation running the account on the relevant platform, as that is where the data lives and where it can be acted upon.

12. Changes to this policy

If we make material changes to this policy, we will update the effective date above and, where we have a way to reach affected customers directly, we will notify them. Continued use of our apps after the effective date constitutes acceptance of the revised policy.

13. Contact

Questions about this policy: support@delta-integrations.com