1.Who this covers
This policy explains what NewDesk ("we") does with personal data in the NewDesk service: the desk, the chat widget with its voice and video calls, the AI assistant, the mobile app and this website.
It covers two kinds of people:
- Customers: you and your teammates, who open a desk and sign in to it. For your account data we are the controller.
- Your visitors: the people who use the widget on your website, write to your support address, or call your team. For their data we act on your instructions as your processor, and you are the controller. Their questions about their data go to you first; we help you answer them.
2.What we hold about customers
- Your name, email address, and a password we store only as a hash.
- Your organisation: its name, website, brand colour and logo, the widget settings you choose, and the teammates you invite with their names, aliases and photos.
- The pages of your website and the documents you train the assistant on, and the answers you teach it.
- Integrations you connect, such as an email address for inbound mail, a WhatsApp number, or a Stripe account, and the keys they need. Keys are stored encrypted.
- Billing records for the licence you buy.
- Sign-in records, the device tokens the mobile app registers for notifications, and the logs every web service keeps, which include IP addresses.
3.What the desk holds about your visitors
Only what the widget and your channels bring in, and only on your desk:
- Conversations: messages, files and voice notes they send, the assistant’s answers, and your team’s replies. An email address or name if they give one.
- Calls: who called, when, how long, and whether it was voice or video. Calls are not recorded.
- Bookings: the time chosen and the email address the confirmation goes to.
- Forms your widget shows, with the fields you asked for.
- Page views on the site where your widget is installed: the page address and title, the referrer, campaign tags in the address, screen size, language, time zone and browser, so your desk can show where a visitor came from and what they were looking at when they wrote.
- A session identifier and a rough device identifier the widget keeps in the browser’s storage, so that one visitor is one person across pages and visits. Neither is shared with anyone else, and neither is used for advertising.
We do not ask your visitors for more than you ask them for, and we do not build profiles of them across different customers' websites.
4.What we use it for
- Running the service: showing your team the queue, sending replies, ringing the right people, keeping bookings.
- Answering visitors with the AI assistant, which reads the conversation and the pages you trained it on to draft an answer.
- Telling you things: a call coming in, a note a teammate left you, a licence about to end, a change to the service. Marketing email to you only if you opt in, and you can stop it any time.
- Keeping the service safe: rate limits, abuse detection on outbound email, and investigating misuse.
- Understanding how the service is used, in aggregate, to improve it.
- Meeting legal obligations.
We do not sell personal data, we do not show advertising, and we do not use your data or your visitors' conversations to train AI models.
5.Our legal basis
Where data protection law asks for one: we process customers' data to perform our contract with them, and for our legitimate interest in keeping the service secure and improving it. We process visitors' data on the customer's instructions. Marketing email rests on consent. Where we must keep something by law, that is the basis.
7.Where it is kept
Our servers are in the United States and the European Union. Some of the services above are in other countries. Where data leaves the country it was collected in, we rely on the provider's standard contractual clauses or an equivalent lawful mechanism.
8.How long we keep it
- Your account and your desk’s data: for as long as the desk is open. After you close it we keep the data for 30 days so you can export it or change your mind, then delete it.
- Conversations, calls, bookings and visitor records: for as long as your desk is open. Ask us and we delete a visitor’s data across your desk.
- Backups: overwritten on their own cycle, within 30 days of the data being deleted from the live service.
- Server logs: 30 days.
- Billing records: as long as tax law requires.
10.Security
Traffic to and from the service is encrypted in transit. Passwords are hashed, integration keys are encrypted at rest, access inside the company is limited to the people who need it to run the service, and every API call is tied to the desk it belongs to, so one customer's data is never in another's queue. Calls are encrypted between the browser and our media servers.
No system is perfect. If we learn of a breach that affects you or your visitors, we tell you without undue delay and give you what you need to tell the people concerned. If you find a vulnerability, please write to security@newdesk.ai.
11.Your rights
Depending on where you live, you may have the right to see the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable form, to object to or restrict some processing, and to withdraw consent where consent is the basis. You also have the right to complain to your data protection authority.
Customers can do most of this in the desk. For the rest, write to hello@newdesk.ai from the address on your account and we answer within 30 days. Visitors should write to the business whose website they used; if they write to us, we pass the request on and help that business answer it.
The service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16 as a customer.
12.For customers: acting as your processor
When we hold your visitors' data we act only on your documented instructions, which are these terms and the settings you choose in the desk. We keep the data confidential, use the sub-processors listed above and tell you before adding one, help you with access and deletion requests and with security incidents, and delete or return the data when the desk closes. A signed data processing agreement is available on request from hello@newdesk.ai.
13.Changes and contact
When this policy changes we update the date at the top. For a change that matters we tell customers in the desk or by email before it takes effect.
Questions go to hello@newdesk.ai, security matters to security@newdesk.ai, or use the contact page. Our terms of service sit beside this policy.