Legal
Privacy Policy
Last Updated: September 16, 2026
Privacy Policy & Data Protection Standards
At AI Agent Desk, safeguarding your company documents, customer inquiries, and proprietary knowledge is our highest priority. This Privacy Policy details how data is ingested, strictly tenant-isolated, encrypted, and automatically purged.
Information We Ingest & Secure
We collect only operational data required to deliver high-accuracy customer service automation:
Verified email address, full name, and avatar fetched securely through Google OAuth 2.0.
PDF, DOCX, and TXT files ingested for your AI agent. Files are encrypted and stored in isolated cloud buckets.
Conversations between website visitors and your AI widget, including customer contact details and human escalation tickets.
Notification recipient emails, WhatsApp phone numbers, and custom OpenAI/Claude/Gemini API keys stored with AES-256 encryption.
Strict Data Usage & Zero Model Training
- To index Knowledge Base documents specifically for your website workspace to generate grounded, cited AI responses.
- To deliver real-time ticket escalation alerts to your designated team email and WhatsApp alert numbers.
- Zero Public Model Training: We NEVER sell your data or use your private support tickets and documents to train public foundational AI models.
Domain Transfer Isolation & 30-Day Hard Purge
In compliance with GDPR data minimisation and multi-tenant security principles, our platform enforces strict data boundaries:
When a website domain is claimed by a new verified owner via HTML Meta Tag or DNS verification, previous support tickets, chat logs, uploaded files, and WhatsApp credentials belonging to the former registrant are never exposed or transferred.
Archived workspaces are held for a 30-day dispute buffer. After 30 days, an automated system cron permanently purges all database records, vector embeddings, customer chat logs, and cloud storage files.
Encryption & Security Standards
All communications between your website chat widget, client browsers, and backend microservices are encrypted in transit via TLS 1.3 / HTTPS. Proprietary API keys and sensitive customer records are encrypted at rest using AES-256 bit encryption.