Privacy Policy

Privacy Policy

Last Update: 03 Dec, 2025

Quick Summary

This brief summary is provided for convenience only and does not replace the full, legally binding terms and conditions set out in this Privacy Policy.

Desku.io processes Personal Data in order to operate, maintain, and secure its website, platform, and associated Services. In particular:

List dot icon
We collect categories of Personal Data from website visitors, platform Users, and End-Users who interact with Customer communication channels.
List dot icon

We use this data to deliver, support, secure, and improve the Service.

List dot icon
We do not sell Personal Data under any circumstances.

For detailed information about the types of Personal Data we process, how we use it, and the rights available to individuals, please review the full Policy below.

Definitions

For the purposes of this Privacy Policy, the following terms have the meanings set out below:

List dot icon

“AI/ML Models”

Artificial intelligence or machine learning systems used within the Service to provide automated suggestions, insights, summaries, classifications, routing, or other assistive outputs.

List dot icon

“Controller”

The entity that determines the purposes and means of Processing Personal Data.

List dot icon

“Cookies & Trackers”

Small text files, scripts, and similar technologies used to enable session management, enhance performance, ensure security, and analyze activity across the website and platform.

List dot icon

“Customer”

A business entity, organization, or authorized individual who accesses or uses the Service. The person creating the account represents that they have authority to bind the Customer.

List dot icon

“Customer Data”

Any data submitted, transmitted, stored, or generated by Customers or their End-Users through use of the Service.

List dot icon

“Documentation”

All written or digital instructions, help articles, onboarding guides, product descriptions, and technical materials provided by Desku.

List dot icon

“Effective Date”

The date at which changes related to the Service, or Policies, or Terms & Conditions become effective. Continued usage of the Service after the Effective Date denotes acceptance of said changes.

List dot icon

“End-User”

Any individual who interacts with a Desku.io Customer through integrated communication channels such as messaging platforms, chat widgets, or email.

List dot icon

“Personal Data”

Any information relating to an identified or identifiable natural person. This may include, but is not limited to, names, contact details, account information, communication content, identifiers, and any data associated with an individual profile.

List dot icon

“Processor”

An entity that processes Personal Data on behalf of a Controller and in accordance with documented instructions.

List dot icon

“Processing”

Any operation performed on Personal Data, whether or not by automated means. Examples include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, transmission, dissemination, restriction, erasure, or destruction.

List dot icon

“Service”

The Desku.io platform and all associated tools, features, and interfaces, including HelpDesk services, Live Chat, OmniChannel messaging, AI functionality, automation tools, analytics, integrations, and administrative components.

List dot icon

“Subscription”

The paid plan, free plan, trial plan, or any tiered access purchased or activated by the Customer, including all limits, features, and billing terms described in the applicable Order Form or Pricing page.

List dot icon

“Subprocessor”

A third-party appointed by Desku.io to process Personal Data strictly in accordance with Desku.io’s instructions and the Controller’s direction.

Introduction & Contact Information

This Privacy Policy describes how Desku.io (“we,” “us,” or “our”) collects, uses, stores, and safeguards Personal Data when individuals interact with our website, platform, or any connected integrations. It also outlines the rights available to individuals under applicable data protection laws and explains Desku.io’s obligations as a Controller or Processor of Personal Data.

Legal Entity: [Insert Full Legal Entity Name]

Registered Address: 4023 Kennett Pike #50230, Wilmington Delaware 19807, United States

Privacy Contact Email: support@desku.io

For additional details regarding our security controls and practices, please refer to our Security page

For requirements governing acceptable use of our Service, please review our Acceptable Use Policy (AUP)

Scope of This Policy

This Privacy Policy applies to all Personal Data processed by Desku.io in connection with the operation of its website, platform, integrations, and related services. It covers the following categories of individuals:

1. Website Visitors

Individuals who visit or interact with the Desku.io website, including those who browse pages, access Documentation, download resources, or subscribe to newsletters.

2. Platform Users

Individuals who access or operate accounts within the Desku.io platform, including administrators, agents, team members, and account owners.

3. End-Users

Individuals who communicate with Desku.io Customers through integrated channels, which may include:

List dot icon

WhatsApp

List dot icon

Facebook Messenger

List dot icon

Instagram Messaging (where applicable)

List dot icon

Telegram

List dot icon

Shopify stores

List dot icon

WooCommerce stores

List dot icon

Slack (where conversations are forwarded into Desku.io)

List dot icon

Email or web chat integrations

List dot icon

Other supported platforms and communication channels

This Privacy Policy applies to all Personal Data processed through the Desku.io Service, its integrations, and any connected applications.

Data Controller vs Data Processor

Desku.io may act as either a Data Controller or a Data Processor, depending on the nature of the Personal Data Processing activity. The applicable role determines Desku.io’s responsibilities under data protection laws.

When Desku.io Acts as a Data Controller

Desku.io acts as the Controller when it determines the purposes and means of Processing Personal Data for its own business operations. This includes Processing carried out for:

List dot icon

Operating and maintaining the marketing website.

List dot icon

Managing account registration, authentication, and password-related workflows.

List dot icon

Administering billing, invoicing, and Subscription management.

List dot icon

Performing analytics to improve and enhance the Service and User experience.

List dot icon

Communicating platform updates, Service notifications, and security-related messages.

List dot icon

Implementing fraud prevention measures and maintaining platform security.

When acting as a Controller, Desku.io independently decides how and why Personal Data is processed.

When Desku.io Acts as a Data Processor

Desku.io acts strictly as a Processor when Customers use the platform to manage their own Customer Support and communications. In this capacity, Desku.io processes Personal Data on behalf of the customer, including:

List dot icon

Support tickets and Customer service conversations.

List dot icon

End-User messages received through integrated communication channels.

List dot icon

Customer contact details, order information, and historical records from systems such as Shopify or WooCommerce.

List dot icon

Files, attachments, media, and metadata submitted by End-Users.

In these scenarios, the Customer determines the purpose and means of Processing. Desku.io processes Personal Data only in accordance with the Customer’s documented instructions and the terms and conditions outlined in Desku.io’s Data Processing Agreement (DPA).

Information We Collect

Desku.io collects and processes different categories of Personal Data depending on how individuals interact with the Service. The types of information collected include:

a. Information Provided Directly

This category includes Personal Data that Users knowingly submit to Desku.io, such as:

List dot icon

Account registration details (e.g. name, email address, company information, and password).

List dot icon

Billing and payment-related contact information, as well as Subscription preferences.

List dot icon

Content submitted via tickets, conversations, forms, surveys, and chat widgets.

List dot icon

Uploaded files, attachments, media, screenshots, and similar materials.

List dot icon

Workspace configuration data, including settings, roles, permissions, and User-level preferences.

b. Automatically Collected Data

When accessing the website or platform, Desku.io may automatically collect technical and usage-related information, including:

List dot icon

Device identifiers, browser type and version, IP address, and timezone.

List dot icon

Operating system details, hardware characteristics, and login timestamps.

List dot icon

Session identifiers, authentication tokens, and security/access logs.

List dot icon

Platform usage analytics (e.g. navigation patterns, feature interactions, performance metrics).

List dot icon

Error logs and diagnostic data used for debugging, Service monitoring, and system stability.

c. Information Received From Third Parties

Desku.io may receive Personal Data from third-party services when Users connect external tools or authenticate using supported identity providers. This may include:

List dot icon

User profile information from login services such as Google or Facebook.

List dot icon

Analytics or performance metadata from monitoring tools.

List dot icon

Contact or order data imported from ecommerce systems such as Shopify or WooCommerce.

List dot icon

Messaging data from integrated communication channels (e.g. sender ID, message content, media attachments).

List dot icon

Authentication information from connected platforms (e.g. Shopify or Google OAuth).

d. Data Received From Customer Platforms

When Customers integrate Desku.io with their own systems or communication channels (e.g. Shopify, WooCommerce, WhatsApp, Telegram, Facebook Messenger, Slack, HubSpot, etc), Desku.io may receive:

List dot icon

Customer names, contact details, and communication identifiers.

List dot icon

Order and transaction details.

List dot icon

Conversation histories and message content.

List dot icon

Metadata required for routing, Processing, or managing interactions.

Facilitating communication between Customers and their End-Users across supported messaging platforms.

How We Use Your Information

Desku.io Processes Personal Data for the purposes necessary to operate, maintain, secure, and improve the Service. Specifically, Personal Data may be used for the following purposes:

List dot icon
Operating and maintaining the Service, including core platform functionality, integrations, and communication channels.
List dot icon
Facilitating communication between Customers and their End-Users across supported messaging platforms.
List dot icon
Personalizing the User experience, including the configuration of workspace settings, roles, permissions, and User preferences.
List dot icon
Monitoring platform security, preventing fraud, and maintaining system integrity, including logging, authentication, and incident detection.
List dot icon
Managing billing, accounting, invoicing, and Subscription administration, including notifications relating to payments or changes in account status.
List dot icon
Providing Customer Support, responding to inquiries, and offering technical assistance.
List dot icon
Conducting analytics to evaluate Service usage, performance, and feature adoption, and to improve functionality and reliability.
List dot icon
Sending required administrative or transactional communications, such as service updates, security alerts, or legally required notices.

All Processing is carried out in accordance with the roles described under this Privacy Policy and applicable data protection laws.

Where the General Data Protection Regulation (GDPR) applies, Desku.io processes Personal Data under one or more of the lawful bases set out in Article 6 of the Regulation. The specific legal bases relied upon include:

List dot icon

Consent

Used for Processing activities that are optional and require explicit permission, such as the use of non-essential cookies or the receipt of marketing communications. Individuals may withdraw consent at any time.

List dot icon

Contractual Necessity

Applied when the Processing of Personal Data is required to enter into or perform a contract with the individual or the organization they represent. This includes providing access to, and functionality within, the Service.

List dot icon

Legitimate Interests

Used for Processing necessary to support Desku.io’s legitimate business interests, provided such interests are not overridden by the rights and freedoms of the individual. Examples include platform security, fraud prevention, Service improvement, analytics, and internal administrative purposes.

List dot icon

Legal Obligations

Applied when Processing is required to comply with applicable laws, including obligations related to taxation, financial reporting, security, or requests from competent authorities.

Desku.io ensures that all Processing activities are grounded on a valid legal basis and carried out in accordance with the requirements of the GDPR.

AI & Machine Learning Data Usage

Desku.io uses AI and machine learning (“AI/ML Models”) to support and automate certain functions within the Service. These features are designed to enhance User workflows, improve efficiency, and reduce manual workload. This section sets out how Personal Data may be processed in connection with AI-driven functionality.

AI Processing Activities

AI/ML Models within the Service may perform Processing activities such as:

List dot icon

Classifying messages or tickets into categories (e.g. “refund request,” “order issue”).

List dot icon

Generating summaries of conversations, tickets, or support threads.

List dot icon

Suggesting replies based on Customer-defined workflows, historical interactions, or workspace configurations.

List dot icon

Routing messages to appropriate agents, teams, or departments.

List dot icon

Identifying sentiment, urgency, or intent to assist with prioritization and workflow management.

Types of Data Used by AI

To support these features, AI/ML Models may process:

List dot icon

Message content and conversation text.

List dot icon

Metadata such as timestamps, channel identifiers, and tags.

List dot icon

Customer-defined fields, forms, or classifications.

List dot icon

Relevant portions of conversation history necessary to provide contextual outputs.

Transparency and Safeguards

Desku.io applies the following commitments to ensure responsible and compliant use of AI technologies:

List dot icon

Anonymized or pseudonymized data is used wherever feasible, consistent with operational requirements.

List dot icon

Personal Data is not used to train public, shared, or third-party foundation models.

List dot icon

AI outputs are generated solely based on Customer-specific data and context; models do not rely on training data from other Customers.

List dot icon

Customers may enable, disable, or configure AI features through workspace settings, subject to the capabilities of their plan.

List dot icon

All Processing associated with AI functionality occurs within secure environments that follow the technical and organizational measures described in this Privacy Policy and the Desku.io Security Page.

Desku.io’s use of AI/ML Models is designed to remain consistent with applicable data protection laws, including requirements relating to transparency, purpose limitation, and data minimization.

Cookies & Tracking Technologies

Desku.io uses cookies and similar tracking technologies (“Cookies & Trackers”) to operate the website and platform, enable core functionality, enhance performance, and analyze usage. These technologies may collect certain information automatically when individuals interact with the Service.

The categories of Cookies & Trackers used include:

List dot icon

Essential Cookies

Required to operate the website and platform, enable session management, maintain security, and ensure the proper functioning of login and authentication workflows. These cookies cannot be disabled through cookie preferences.

List dot icon

Performance and Analytics Cookies

Used to collect aggregated usage statistics, monitor platform performance, identify errors, and help improve functionality.

List dot icon

Marketing and Retargeting Cookies

Used on the marketing website to measure campaign effectiveness, personalize content, and deliver relevant advertising. These cookies are not used within the operational Desku.io platform.

For detailed information on the specific cookies used, their purposes, and how to manage your cookie preferences, please refer to our Cookie Policy

Third-Party Integrations

Desku.io provides optional integrations with various third-party platforms to support Customer workflows and communication channels. These integrations may include, but are not limited to:

List dot icon

Shopify

List dot icon

WooCommerce

List dot icon

Slack

List dot icon

WhatsApp

List dot icon

Facebook Messenger

List dot icon

Telegram

List dot icon

HubSpot

When a Customer enables one or more of these integrations, Personal Data may be transferred between Desku.io and the connected third-party systems as required to operate the integration. Depending on the integration and Customer configuration, the categories of data exchanged may include:

List dot icon

Contact and profile information

List dot icon

Email logs or communication history (as configured by the Customer)

List dot icon

Order or transaction details

List dot icon

Customer or End-User profiles

List dot icon

Conversation logs and message content

List dot icon

Channel-specific identifiers and metadata

Desku.io only requests the permissions necessary to operate each integration, and the required access scope is disclosed to the Customer during the connection or authorization process. Customers remain responsible for ensuring that any third-party integrations they activate comply with applicable laws and their own privacy obligations.

Subprocessors & Who We Share Data With

Desku.io engages certain third-party service providers (Subprocessors) to support the delivery, operation, and security of the Service. These Subprocessors may process Personal Data on Desku.io’s behalf and strictly in accordance with Desku.io’s documented instructions and contractual obligations.

Types of Subprocessors used may include:

List dot icon

Cloud hosting and infrastructure providers

List dot icon

Email and notification delivery services

List dot icon

Payment processors and billing service providers

List dot icon

Customer communication and messaging channel providers

List dot icon

Analytics, monitoring, and logging tools

All Subprocessors engaged by Desku.io are required to:

List dot icon
Enter into GDPR-aligned Data Processing Agreements (DPAs) with Desku.io.
List dot icon
Implement appropriate technical and organizational security measures.
List dot icon

Comply with all applicable data protection and privacy laws.

List dot icon

Process Personal Data only for the specific purposes required to deliver the contracted Service.

A current list of approved Subprocessors is available upon request. Customers may contact Desku.io through the designated privacy email address to obtain the most recent version of the Subprocessor List.

Payment Information Handling

Payments for Desku.io Subscriptions are processed exclusively through trusted third-party payment service providers such as Stripe, PayPal, or comparable entities. These providers are independently certified as PCI-DSS compliant, meaning that they meet the security standards required for handling payment card information.

Desku.io does not store or process full Credit Card numbers, CVV codes, or other sensitive payment credentials. All payment details are transmitted directly to the relevant payment provider using secure, encrypted channels.

Desku.io may retain limited billing-related metadata necessary for:

List dot icon
Account administration
List dot icon
Invoicing and Subscription management
List dot icon

Tax, audit, and legal compliance obligations

No sensitive payment information is stored on Desku.io’s systems at any time.

Data Security Measures

Desku.io implements robust technical and organizational measures to protect Personal Data against unauthorized access, alteration, disclosure, or destruction. These measures are designed to ensure a level of security appropriate to the nature of the data processed and the risks associated with the Service.

Technical Measures

Desku.io applies a layered security approach that includes:

List dot icon
Encryption in transit using TLS 1.2 or higher.
List dot icon
Encryption at rest using AES-256 or equivalent standards.
List dot icon
Regular vulnerability scanning, security testing, and prompt application of patches.
List dot icon
Secure backups and disaster recovery mechanisms to maintain availability and data integrity.
List dot icon
Role-based access controls (RBAC) and enforced authentication measures.
List dot icon
Network isolation, firewall protections, and controlled ingress/egress points.
List dot icon
Continuous system monitoring and automated alerting for potential threats.
List dot icon
Secure development practices, including code reviews and adherence to security-first engineering standards.

Organizational Measures

To support technical safeguards, Desku.io maintains internal controls that include:

List dot icon

Access restrictions limiting Personal Data access to authorized personnel on a need-to-know basis.

List dot icon

Employee confidentiality obligations and secure handling protocols.

List dot icon

Security and privacy training for staff involved in Processing Personal Data.

List dot icon

Logging and audit trails to track access and system activity.

List dot icon

Documented incident response procedures for identifying, containing, and responding to security events.

For a detailed overview of Desku.io’s security posture, please refer to our Security Page

International Data Transfers

When Personal Data is transferred outside the region from where it was originally collected (including transfers from the EU, EEA, or UK), Desku.io implements safeguards designed to ensure an equivalent level of protection in line with applicable data protection laws.

Desku.io relies on the following mechanisms and controls:

List dot icon

Standard Contractual Clauses (SCCs):

Transfers to third countries are governed by the European Commission-approved SCCs or UK IDTA/Addendum, as applicable.

List dot icon

Data Minimization:

Only the minimum amount of Personal Data necessary for the intended purpose is transferred.

List dot icon

Regional Data Hosting (where available):

Certain data may be stored or processed in regional data centres to support residency preferences.

List dot icon

Additional Technical and Organizational Measures:

These may include encryption, access controls, network restrictions, and audit logging to strengthen protection during and after transfer.

List dot icon

Transfer Risk Assessments (TRAs):

Desku.io conducts assessments where required to verify that transfer arrangements maintain an adequate level of protection.

List dot icon

Restricted Access:

Access to Personal Data is limited strictly to authorized personnel with a documented business need.

Desku.io ensures that all international transfers are subject to appropriate safeguards and remain consistent with GDPR, UK GDPR, and other applicable data protection laws.

Data Retention

Desku.io retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce agreements.
Active Accounts

Personal Data associated with an active Subscription is retained for as long as the Customer continues to use the Service. This includes data required to operate work-spaces, support communication channels, maintain account history, and provide Customer Support.

Deleted Accounts

When an account is deleted by the Customer or terminated:

List dot icon

Most Personal Data is removed from active systems within [insert retention timeframe].

List dot icon

Residual data may remain in encrypted backups for a limited period as part of disaster recovery and business continuity protocols.

List dot icon

Certain information (such as billing records or payment metadata) may be retained where required by tax, accounting, anti-fraud, or regulatory obligations.

Legal & Compliance Requirements

Desku.io may retain specific categories of Personal Data for longer where necessary to:

List dot icon

Meet statutory retention periods under applicable laws

List dot icon

Detect or prevent fraud or abuse

List dot icon

Maintain security, audit, and access logs

List dot icon

Comply with accounting or financial reporting obligations

Once retention periods expire, Desku.io securely deletes or anonymizes the data in line with industry standards.

Data Subject Rights (GDPR + CCPA)

Depending on your location and the privacy laws that apply to you, you may have specific rights regarding the Personal Data we process. These may include:

List dot icon
Right of Access – Request a copy of your Personal Data.
List dot icon
Right to Rectification – Correct or update inaccurate or incomplete information.
List dot icon
Right to Erasure (Right to Be Forgotten) – Request deletion of Personal Data under certain conditions.
List dot icon
Right to Restrict Processing – Ask us to limit how your data is used.
List dot icon
Right to Data Portability – Obtain your data in a structured, commonly used, machine-readable format.
List dot icon
Right to Object – Object to Processing based on legitimate interests or to direct marketing.
List dot icon
Right to Withdraw Consent – Withdraw consent at any time when Processing is based on consent.
List dot icon
CCPA Opt-Out Rights – Opt out of “Do Not Sell/Share” where applicable under California law.

Desku.io will honour these rights in accordance with applicable laws and will not discriminate against individuals for exercising them.

Exercising Your Rights

To submit a Privacy Request or exercise any of your data rights, you can contact us through one of the following:
List dot icon
In-app Support Portal: Available within your Desku.io account

To protect the security of Personal Data, we may require reasonable steps to verify your identity before Processing your request.

Data Breach Notification Policy

If Desku.io becomes aware of a Personal Data breach, we will respond in accordance with applicable data protection laws, including GDPR where relevant. Our commitments include:

List dot icon
Timely Notification: We will notify affected Customers without undue delay once a breach involving their Personal Data is confirmed.
List dot icon
Regulatory Compliance: Where GDPR applies, we will follow the required reporting timeframes and obligations under Articles 33 and 34.
List dot icon
Breach Details: We will provide clear information regarding the nature of the breach, the categories of data involved, the potential impact, and the steps taken or proposed to address the incident.
List dot icon
Guidance for Customers: We will supply recommended actions Customers may take to protect their data or accounts.
List dot icon
Communication Methods: Notifications will be delivered via email, in-app messages, or account alerts, depending on severity and urgency.

Desku.io maintains internal procedures to detect, investigate, contain, and remediate security incidents promptly and thoroughly.

Children’s Privacy

The Desku.io Service is not directed to, or intended for use by, individuals under:

List dot icon
13 years of age in the United States (in line with COPPA), and
List dot icon
16 years of age in regions governed by the GDPR, unless a lawful exception applies.

Desku.io does not knowingly collect, process, or store Personal Data from children who fall below these age thresholds. If we become aware that Personal Data has been collected from a child in violation of this policy, we will take steps to promptly delete that information.

Parents or guardians who believe that a child has provided Personal Data to Desku.io may contact us so that appropriate action can be taken.

Changes to This Policy

Desku.io may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Service improvements.

When updates occur:

List dot icon
The Effective Date / Last Updated field at the top of this page will be revised.
List dot icon
Users may be notified through email, in-dashboard alerts, or updates on our website.
List dot icon

Prior versions may be archived and made available upon request for reference.

Your continued use of the Service after any updates take effect will constitute your acceptance of the revised Privacy Policy and will be governed by this Policy and our Terms of Service.