Legal

Privacy Policy

Last Updated: September 16, 2026

Last Updated: September 16, 2026

Privacy Policy & Data Protection Standards

At AI Agent Desk, safeguarding your company documents, customer inquiries, and proprietary knowledge is our highest priority. This Privacy Policy details how data is ingested, strictly tenant-isolated, encrypted, and automatically purged.

1

Information We Ingest & Secure

We collect only operational data required to deliver high-accuracy customer service automation:

Account Authentication

Verified email address, full name, and avatar fetched securely through Google OAuth 2.0.

Knowledge Base Documents

PDF, DOCX, and TXT files ingested for your AI agent. Files are encrypted and stored in isolated cloud buckets.

Support Tickets & Chat Transcripts

Conversations between website visitors and your AI widget, including customer contact details and human escalation tickets.

Integration Credentials & BYOK Keys

Notification recipient emails, WhatsApp phone numbers, and custom OpenAI/Claude/Gemini API keys stored with AES-256 encryption.

2

Strict Data Usage & Zero Model Training

  • To index Knowledge Base documents specifically for your website workspace to generate grounded, cited AI responses.
  • To deliver real-time ticket escalation alerts to your designated team email and WhatsApp alert numbers.
  • Zero Public Model Training: We NEVER sell your data or use your private support tickets and documents to train public foundational AI models.
3

Domain Transfer Isolation & 30-Day Hard Purge

In compliance with GDPR data minimisation and multi-tenant security principles, our platform enforces strict data boundaries:

Domain Transfer Privacy Protection

When a website domain is claimed by a new verified owner via HTML Meta Tag or DNS verification, previous support tickets, chat logs, uploaded files, and WhatsApp credentials belonging to the former registrant are never exposed or transferred.

Automated 30-Day Permanent Purge

Archived workspaces are held for a 30-day dispute buffer. After 30 days, an automated system cron permanently purges all database records, vector embeddings, customer chat logs, and cloud storage files.

4

Encryption & Security Standards

All communications between your website chat widget, client browsers, and backend microservices are encrypted in transit via TLS 1.3 / HTTPS. Proprietary API keys and sensitive customer records are encrypted at rest using AES-256 bit encryption.