iDeskPrivacy Policy
Last updated: August 29, 2026
This Privacy Policy explains how Digital Dreams Systems ("we", "us", "our") collects, uses, and protects information when you use iDesk (the "Service") — including the agent workspace and the customer support portal, wherever hosted, such as idesk.digitaldreamssystems.in.
1. Information we collect
We collect the following categories of information as part of operating the Service:
- Agent account information — name, work email, and password. Passwords are stored as a one-way cryptographic hash (bcrypt); we never store or have access to your plaintext password.
- Organization information — your organization's name and workspace address (subdomain), submitted at signup.
- Customer/requester information — name, email, phone number, and company, submitted by your organization's customers when they raise a support request, either directly or through your organization's agents.
- Ticket content — messages, internal notes, tags, custom field values, and file attachments associated with support requests.
- Connected-channel messages — email and WhatsApp messages your organization sends and receives through the Service become part of ticket content (see "Third-party service providers" below for how these channels work).
- Sign-in with Google — if you use "Continue with Google," we receive your name, email address, and Google account identifier from Google to create or match your account. We never receive or store your Google password.
- Security and audit data — sign-in timestamps and IP addresses, kept to detect and investigate unauthorized access.
2. How we use information
- To provide and operate the Service — creating, routing, and tracking support tickets.
- To enforce service-level agreements (SLA) your organization configures.
- To send notifications your organization has enabled (e.g. ticket acknowledgements, password resets).
- To provide optional AI-assisted features (e.g. ticket summarization, knowledge-base search) — these run on a self-hosted language model operated by us, not a third-party AI vendor, and are never a requirement for core functionality; if unavailable, the Service continues to work normally without them.
- To maintain security, detect abuse, and investigate incidents.
- To improve the Service.
3. Third-party service providers
We use a small number of third-party providers to operate specific features. We do not sell your data, and we do not share it with advertisers or data brokers.
- Google (Gmail API, Google Drive, Google Sign-In) — your organization's support email is sent and received through a shared mailbox we operate, and file attachments are stored in a Google Drive account we operate, isolated per organization. If Google Sign-In is enabled, Google also verifies your identity when you sign in that way.
- Interakt (WhatsApp Business Solution Provider) — if your organization uses WhatsApp, messages are sent and received through Interakt's platform on our behalf.
Each provider processes data under its own privacy terms in addition to this policy.
4. Data storage and security
- Data for every organization is logically isolated using database-enforced Row-Level Security, in addition to application-level checks, so one organization's data is never visible to another.
- Passwords are hashed (bcrypt); they are never stored or logged in plaintext.
- Sign-in uses short-lived access tokens plus a hashed, revocable refresh token — we do not store your session tokens in plaintext.
- API keys and third-party credentials are stored server-side only and never exposed to your browser.
5. Cookies and local storage
We do not use advertising or cross-site tracking cookies. To keep you signed in, the Service stores your session token in your browser's local storage — this data stays on your device and is not shared with third parties.
6. Data retention
We retain your organization's data for as long as your account remains active. If you'd like your organization's data exported or deleted, contact us using the details below — we currently handle these requests manually rather than through a self-service tool.
7. Your rights
Depending on your location, you may have rights to access, correct, or request deletion of your personal information. To exercise these rights, contact us at the address below.
8. Children's privacy
The Service is not directed at, and we do not knowingly collect information from, children under 16.
9. Changes to this policy
We may update this policy from time to time. We'll update the "Last updated" date above when we do; continued use of the Service after a change means you accept the updated policy.
10. Contact us
Questions about this policy, or a request regarding your data, can be sent to contact@digitaldreamssystems.in.
This policy describes iDesk as currently operated. It is provided as a general reference and is not a substitute for advice from qualified legal counsel about your specific compliance obligations.