Tuesday
Tuesdayby NoCodeMinute

Last updated: June 12, 2026

Data Processing Addendum

Purpose

This Data Processing Addendum explains how NoCodeMinute LLC processes personal data for customers using Tuesday. It is intended to support customers that need a data processing agreement for GDPR, UK GDPR, California privacy laws, or similar privacy frameworks.

Roles

For account, billing, security, and service administration data, NoCodeMinute LLC generally acts as a controller or business. For workspace, board, item, file, public form, workflow, and message content that customers add to Tuesday, NoCodeMinute LLC generally acts as a processor or service provider, and the customer acts as the controller or business.

Customer Instructions

We process customer content to provide, secure, maintain, support, and improve Tuesday, and according to the customer's configuration of boards, public forms, workflows, invites, files, and shared links. We do not sell customer content.

Subject Matter and Duration

  • Subject matter: operation of Tuesday as a web-based workspace, board, form, file, chat, and workflow service.
  • Duration: the period during which the customer uses Tuesday, plus any retention period needed for backups, logs, billing, security, dispute resolution, or legal obligations.
  • Categories of data subjects: account users, invited board members, public form submitters, workflow email recipients, and other people whose information customers add to Tuesday.
  • Categories of personal data: account identifiers, contact details, workspace content, board data, item data, messages, public form submissions, uploaded files, workflow metadata, billing metadata, device/request logs, and support communications.

Customer Responsibilities

  • Use Tuesday only for lawful purposes and provide any required notices or consents to data subjects.
  • Avoid collecting highly sensitive regulated data unless NoCodeMinute LLC has agreed in writing to support that use.
  • Configure board sharing, public form links, workflow recipients, and file access appropriately.
  • Respond to privacy requests where the customer controls the relevant personal data.
  • Keep account credentials secure and promptly remove users who should no longer have access.

No Sensitive Regulated Workflows

Tuesday is not designed for HIPAA, PCI card storage, FERPA, GLBA, or similar regulated-data workflows. Customers must not use Tuesday to store medical records, full payment card numbers, Social Security numbers, tax IDs, student education records, legal case files, or similar highly sensitive regulated records unless we have agreed in writing to support that use.

Subprocessors

We use subprocessors to operate Tuesday. Current subprocessors are listed on the Subprocessors page. We remain responsible for subprocessors we engage to process customer content on our behalf.

Security Measures

  • Use of Firebase Authentication, Google Cloud/Firebase infrastructure, Firestore security rules, Storage rules, and app-level access controls.
  • Encryption in transit using HTTPS/TLS and encryption at rest provided by Google Cloud and Firebase services.
  • Role-based board access controls for owners, editors, and viewers.
  • Restricted public form submission paths with rate limiting, upload size limits, content-type checks, and rich text sanitization.
  • Operational access limited to people and systems that need access to operate, support, secure, or troubleshoot Tuesday.

International Transfers

Tuesday uses service providers that may process data in the United States and other locations. Where required, customers and NoCodeMinute LLC will rely on legally recognized transfer mechanisms, such as Standard Contractual Clauses or other applicable safeguards.

Assistance With Requests

We will provide reasonable assistance for privacy requests, security inquiries, deletion, export, or access questions where the relevant data is controlled through Tuesday and the request is technically feasible.

Security Incidents

If we become aware of a confirmed security incident involving customer content, we will investigate and notify affected customers without undue delay when required by applicable law.

Deletion and Return

Customers may delete account and board data through Tuesday where available or request assistance through the Data Requests page. Some information may remain for a limited period in backups, logs, billing records, unsubscribe records, abuse-prevention records, or records we must retain for legal, security, or operational reasons.

Contact

NoCodeMinute LLC
1752 E Lugonia Ave
Ste 117 #1441
Redlands, CA 92374
United States
privacy@nocodeminute.com