Privacy Policy

This policy explains how Protodesk handles personal data when you visit our website, create an account, use our applications, or communicate through a workspace operated by one of our customers.

Updated August 17, 2026 6 min read
Privacy Policy

Key takeaways

  • Protodesk uses personal data to provide, secure, support, and improve the service.
  • Workspace owners control the customer conversations and contacts they place in Protodesk; Protodesk processes that content on their behalf.
  • We do not sell personal data or use customer conversation content for cross-context behavioral advertising.

Scope and our role

This policy applies to Protodesk websites, mobile and web applications, support communications, and related services. For account, billing, website, and product-usage data, Protodesk generally acts as the organization responsible for deciding how that data is processed. For customer contacts, conversations, attachments, knowledge-base content, and channel data submitted to a workspace, the workspace owner determines the purpose of processing and Protodesk processes the data to provide the service. If you are a customer of a business using Protodesk, that business is normally the best first contact for a request about your conversation data.

Personal data we collect

  • Account and workspace data, including name, email address, profile image, authentication identifiers, role, team membership, language, timezone, and workspace settings.
  • Customer-support content, including contact details, conversations, message metadata, attachments, internal notes, labels, categories, and knowledge-base material supplied through connected channels.
  • Subscription and transaction data, including plan, billing status, invoices, credit usage, and transaction identifiers. Payment card details are handled by the payment provider and are not stored by Protodesk.
  • Device, diagnostic, and usage data, including application version, device and browser type, IP address, timestamps, feature interactions, crash information, and security events.
  • Communications you send to Protodesk, including support requests, privacy requests, feedback, and survey responses.

How we receive data

We receive data directly from you, from workspace owners and teammates, from customers who contact a connected support channel, from integrations you choose to connect, and automatically from the devices and browsers used to access the service. Connected providers may include email providers, Meta services for WhatsApp, website chat, Google or Apple sign-in, and other integrations explicitly enabled by a workspace.

Why we use personal data

  • Provide accounts, workspaces, shared inboxes, messaging, search, notifications, billing, and customer support.
  • Authenticate users, enforce permissions, prevent abuse, investigate incidents, and protect the service and its users.
  • Operate optional AI features, including triage, summaries, reply suggestions, translations, knowledge retrieval, and configured automations.
  • Maintain reliability, diagnose errors, measure product performance, and improve features and usability.
  • Send service, security, billing, and product communications and comply with legal obligations.

AI processing

When a workspace enables an AI feature, Protodesk sends the minimum relevant prompt, conversation context, knowledge-base excerpts, and instructions needed to OpenRouter and the selected model provider. Outputs may be stored with the related conversation or operational record so users can review the result, measure quality, and investigate errors. AI output can be inaccurate and should be reviewed when the workflow requires human judgment. Protodesk does not use workspace customer content to train a shared Protodesk model, and provider handling remains subject to our provider agreements and configuration.

When we disclose data

We disclose personal data only as needed to operate the service, follow your instructions, or meet legal and security obligations. Recipients may include cloud hosting and storage providers, authentication and push-notification providers, email and communication providers, payment and billing providers, analytics and error-monitoring providers, AI infrastructure and model providers, professional advisers, and authorities when disclosure is legally required. If Protodesk is involved in a merger, financing, acquisition, reorganization, or sale of assets, data may be transferred subject to appropriate confidentiality and notice requirements.

International transfers

Protodesk and its service providers may process data in countries other than the country where you live. Where required, we use recognized transfer mechanisms and contractual protections and assess providers based on the data and processing involved.

Retention

We keep personal data only for as long as needed for the purposes described here. Retention depends on the workspace lifecycle, contractual commitments, backup cycles, security requirements, dispute resolution, and legal obligations. Workspace content is generally retained while the workspace is active and for a limited period after deletion or termination before removal from active systems and routine backups, unless a longer period is required by law or requested under an applicable agreement. De-identified information may be retained when it can no longer reasonably identify a person.

Security

We use administrative, technical, and organizational safeguards designed to protect personal data, including authenticated access, workspace isolation, encrypted transport, restricted service credentials, and monitoring. No system is completely secure. You are responsible for protecting account credentials, configuring workspace access appropriately, and notifying us promptly of suspected unauthorized access.

Your choices and rights

Depending on your location and subject to legal exceptions, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of personal data, and to withdraw consent where processing relies on consent. You may also have the right to complain to a local data-protection authority. California residents may have rights to know, correct, or delete personal information and to receive equal service when exercising applicable rights. Protodesk does not sell personal information or share it for cross-context behavioral advertising. We may ask for information needed to verify your identity and authority before completing a request.

Cookies, analytics, and device permissions

Our website and applications use essential local storage and similar technologies for authentication, security, language, theme, and session preferences. We may use limited analytics to understand site and product reliability. Mobile notifications, photos, files, or other device access are used only after the operating system grants the relevant permission, and permissions can be changed in device settings.

Children

Protodesk is a business service and is not directed to children. You must be legally able to enter into the Terms of Service to create an account. If you believe a child has provided personal data to Protodesk contrary to this policy, contact us so we can investigate and take appropriate action.

Changes to this policy

We may update this policy as the product, providers, or legal requirements change. We will post the revised policy with a new effective date and provide additional notice when a change materially affects how personal data is handled.

Contact

For privacy questions or requests, email privacy@protodesk.io. For workspace customer-conversation data, please identify the workspace or business you contacted so we can route the request appropriately. This policy is intended to describe our current practices clearly and does not limit rights provided by applicable law.