Privacy Policy
What DeskcommCRM collects, why we collect it, and the choices you have.
Last updated: September 14, 2026
1. Overview
This Privacy Policy explains what information deskcommcrm.lol ("DeskcommCRM", "we", "us") collects when you use the service, why we collect it, and the choices you have. It covers the website, the console, the agent runtime and the conversation records kept on your workspace.
2. Information we collect
We keep the data we collect to the minimum needed to run the desk.
- Account data from Google sign-in: your name, email address, profile image URL and the Google account identifier.
- Workspace data: company name, seats, connected WhatsApp numbers and the material you upload to the knowledge base.
- Conversation data: inbound and outbound messages, the checks applied to each outbound message, and the resulting lead, funnel and audit records for your workspace.
- Subscription and billing data: your plan, billing interval, subscription status and identifiers issued by our payment processor. We never receive or store your full card number.
- Usage data: AI message volume, features used and technical events needed to keep the service reliable.
- Technical data: IP address, browser and device type, and timestamps, collected in server logs for security and abuse prevention.
3. What we do not do
We do not ask for your Google password, we do not read your Google files or contacts, and we do not train models on your conversations. We do not sell your personal information or the records of your workspace.
4. How we use your information
We use the information described above to create and secure your account, to run the agent and the console, to process subscription payments, to answer support requests, to detect abuse and fraud, and to comply with legal obligations.
5. Your responsibilities as the workspace owner
You decide which conversations the desk handles and which personal data your customers share with you. You are the controller of that customer data; we process it on your instructions to provide the service. Your agreement with your customers should tell them that automation may answer and that conversations are recorded.
6. Cookies and local storage
We use essential cookies and local storage to keep you signed in, to remember your preferences and to protect forms against cross-site request forgery. You can clear them in your browser, but signing in depends on them.
7. Service providers
We share limited data with the providers that make the service work. Each provider processes data under its own terms and only for the purposes we describe.
- Google - sign-in and account identity.
- Stripe - subscription billing, invoices and payment method handling.
- WhatsApp Business messaging providers - delivery of the messages your desk sends and receives.
- Cloud hosting, model inference and database providers - running the application, the agent and the records.
8. Retention
Conversation and audit records are kept for as long as your workspace exists, so the history stays auditable, and are deleted or anonymised after account closure in line with our backup cycle. Billing records are kept as long as accounting, tax, dispute resolution and legal compliance require. Server logs are kept for a short operational window and then deleted.
9. Security
We use encryption in transit, access controls and least-privilege practices to protect your data. Workspace data is isolated per account. No system is perfectly secure, so we cannot promise absolute security, but we limit what we store to reduce the impact of any incident.
10. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal information, to object to certain processing, and to lodge a complaint with a supervisory authority.
To exercise these rights, email support@deskcommcrm.lol. We may need to verify that the request comes from the workspace owner. Requests about customer data inside your workspace are handled by you as the controller, with our assistance where the law requires it.
11. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards such as standard contractual clauses.
12. Children
The service is not intended for children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes and contact
We may update this policy as the service evolves. Material changes are reflected by the "Last updated" date above.
Questions about privacy can be sent to support@deskcommcrm.lol.