Privacy policy
Last updated August 31, 2026
This policy explains what data fikadesk collects, why we collect it, how long we keep it, and the choices you have. It applies to the fikadesk managed cloud and to this website.
Who this policy applies to
fikadesk plays two roles under data protection law. For the account data of the people who sign up to use the Service, we are the controller. For the end-user data our customers submit through the Service, the customer is the controller and we act as a processor on their instructions. This policy describes both.
When you contact a company that uses fikadesk, that company decides what data it collects about you and why. Its own privacy policy applies to that data, and you should direct requests about it to that company. We describe what we do with it on their behalf below.
Data we process
Account data covers the people who run the Service: names, email addresses, roles, and password hashes. We use it to create accounts, sign people in, and reach them about their account.
Billing data is collected by Paddle, our merchant of record. Paddle collects your name, billing address, and payment details and shares a record of your subscription and invoices with us. We do not see your full card number.
Customer data is what you and your end users submit through the Service: conversations, message bodies, attachments, contact details such as names, email addresses and phone numbers, and help center articles. We process it only to provide the Service and on your instructions.
Technical data is what the Service logs as it runs: IP addresses, timestamps, error reports, and request metadata. We use it to keep the Service running and to investigate abuse and failures.
Purposes and legal bases
We process account data to perform our contract with you, which covers signing you in and sending service messages. We process technical data on the basis of our legitimate interest in securing and operating the Service. We process customer data as a processor, under the Data Processing Agreement, so the lawful basis is the one you hold with your end users.
We do not sell personal data, and we do not run advertising. We do not send marketing email. We process data only where the law, a contract, or our legitimate interest permits it, and we keep that processing to what the purpose needs.
Retention
We keep account data while your account is open, and delete it after the account is closed and its workspace is deleted.
Customer data is retained according to the retention window configured for your workspace. The window has a 30 day minimum. Conversations and their messages are deleted once they pass the window, along with the files attached to them. A message that never became a conversation, such as a bounced or unrouteable email, ages out on the same window.
Contact exports have a separate 7 day lifetime. The archive is deleted automatically once that period ends.
Technical logs are kept for the time needed to operate and secure the Service, and are not kept longer than that purpose requires.
Deletion
The Service ships deletion controls. You can redact an individual message, erase a contact and the messages they authored, delete a conversation, or delete the whole workspace. Deleting a workspace removes the rows and files it holds. Deleting a contact blanks their identifying fields and redacts the messages they sent, which keeps the conversation readable without the personal data.
You can also export everything the workspace holds about one contact. The export is a JSON archive available for 7 days, which gives your end users a way to exercise their access and portability rights through you.
If an end user asks us directly to erase their data, we direct them to the customer that collected it, because the customer controls that data. We will help a customer complete an erasure request with the controls above.
International transfers
We store and process data in the regions chosen for our infrastructure, which are listed on the subprocessors page. Where a subprocessor is located outside the European Economic Area or the United Kingdom, we rely on the EU Standard Contractual Clauses, and the UK equivalent where it applies, to keep the transfer lawful.
Security
Data in transit is protected with TLS. We depend on our hosting and storage providers for encryption at rest, and we restrict access to customer data to the people who need it to run the Service. The Data Processing Agreement lists the technical and organizational measures in more detail.
Your rights
Depending on where you live, you may have rights to access, correct, or delete your personal data, to receive a copy in a portable format, and to object to or restrict processing. If you have an account with us, write to [SUPPORT EMAIL] and we will respond within the time the law allows.
If you are an end user of one of our customers, ask that customer first. They hold your data and decide how to answer. Where a request reaches us, we pass it to the customer and help them act on it. You can also complain to your local data protection authority if you think we have not handled your data lawfully.
Children
The Service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, tell us at [SUPPORT EMAIL] and we will delete it.
Changes
We may update this policy as the Service changes. Material changes come with notice through the Service or by email. The date at the top of the page shows the latest revision.
Contact
Privacy questions and requests go to our data protection contact at [DPO CONTACT]. You can also write to [COMPANY ENTITY], [REGISTERED ADDRESS].