Effective date: April 20, 2026
This Privacy Policy explains how Context Desk (“we”, “us”) collects, uses, stores, shares and protects personal data when you use the Context Desk service (the “Service”). It applies to visitors to our marketing site and to customers using the dashboard.
For the personal data of our account holders (you, the customer), Context Desk is the data controller. For personal data contained inside the messages, orders, customers and other records that we process from your connected platforms (Shopify, Stripe, Zendesk, Intercom, Gmail, etc.), you are the controller and we act as your processor under a Data Processing Agreement.
Information you give us when you sign up or use the dashboard:
Customer Data we process on your behalf from connected platforms:
Information we collect automatically:
Where the GDPR applies we rely on the following lawful bases: (a) contract — to provide the Service you have signed up for; (b) legitimate interests — to secure the Service, prevent abuse, and improve our product; (c) legal obligation — for tax, accounting and compliance; (d) consent — for non-essential cookies and marketing emails, which you may withdraw at any time.
The Service uses a third-party large-language-model provider to generate reply drafts. The minimum context required for the draft is sent to the provider via their API. We have a data-processing agreement with the provider that prohibits them from using your data to train their models. AI-generated output is treated as Customer Data and is stored only in your tenant.
We use the following sub-processors. Each is bound by a data-processing agreement and EU Standard Contractual Clauses where applicable.
The list of sub-processors may change. Material changes will be communicated by email or in-app at least 14 days before they take effect, except where a replacement is required for security reasons.
Personal data may be transferred to and processed in countries outside your country of residence, including the United States. Where a transfer leaves the European Economic Area or the United Kingdom, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or the UK International Data Transfer Addendum.
We use a small number of strictly-necessary cookies for authentication, session management and CSRF protection. We do not use third-party advertising or tracking cookies. We may use a privacy-friendly first-party analytics tool (without cross-site tracking) to understand product usage; you can opt out from your browser settings.
We protect personal data with industry-standard controls including encryption in transit (TLS 1.2+), encryption at rest (AES-256), Postgres Row-Level Security to isolate tenants, hashed passwords, encrypted integration credentials, least-privilege access for staff, audit logging, and regular dependency and security scans. No system is perfectly secure; if we ever experience a breach affecting your data we will notify you without undue delay and within the timeframes required by applicable law.
Subject to applicable law (including GDPR and the CCPA / CPRA) you have the right to:
To exercise any of these rights, email support@contextdesk.app. We respond within 30 days. Account data export and deletion are also available self-service from Dashboard → Settings → Data.
The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this Privacy Policy from time to time. The “Effective date” at the top indicates when it was last revised. We will notify you of material changes by email or in-app at least 14 days before they take effect.
Questions, requests, or complaints? Email support@contextdesk.app.