Privacy policy
Last updated
This policy explains what personal data AgentlyDesk handles, why, and what you can ask us to do with it. It covers the AgentlyDesk website (agentlydesk.com), the operator console and the chat widget that our customers place on their websites.
Who we are
[Legal entity name and registered address — to be provided]
You can reach us about anything in this policy at [email protected].
Two different roles
For our customers, the businesses that use AgentlyDesk, we decide how their account data is used, and this policy applies directly.
For visitors who chat on a customer's website, we process the conversation on behalf of that business. The business decides why it offers chat and what it does with the conversation, and its own privacy policy applies too. If you chatted on a website that uses AgentlyDesk, the quickest way to exercise your rights is to contact that website; we will help them answer you.
What we collect
Workspace and operator accounts
- Name, e-mail address and role (owner, admin or agent) of each operator.
- The password and the two-factor recovery codes, stored only as one-way hashes, and the two-factor secret, stored encrypted.
- Workspace settings, site configuration and an audit log of changes made in the workspace.
Conversations through the widget
- The messages exchanged and any images the visitor or operator shares.
- The address of the page the visitor is on while chatting.
- A name and e-mail address when the visitor enters them (for example in the offline form), or when the website signs a logged-in user's identity. A name or e-mail from an identity that fails verification is not saved.
- An anonymous visitor ID, so a returning visitor can continue their conversation.
- The visitor's IP address, stored only as a salted hash. We use it to apply rate limits and bans without keeping the address itself.
- Internal notes operators write, which visitors never see.
Early-access requests
When you fill in the early-access form we store what you entered (name, e-mail, and optionally company, website, team size, plan and message), your browser's user agent and a salted hash of your IP address. We use it only to reply to you and to set up your workspace.
E-mail you send us
If you write to us, we keep the correspondence so we can answer and follow up.
How we use it
- To run the service: deliver messages, show conversations to your team and send the e-mails you ask for, such as transcripts, offline-message notifications and invitations.
- To keep it secure: sign-in and two-factor checks, rate limits, bans and the audit log.
- To reply to requests and support questions.
We do not sell personal data, and we do not use conversations for advertising.
Cookies and browser storage
- This website sets no cookies. If you choose a light or dark theme, the choice is saved in your
browser's local storage under
agentlydesk-theme. - The console uses a session cookie to keep operators signed in. It is required for the console to work.
- The widget sets no cookies. It keeps the anonymous visitor ID in the browser's local storage, and remembers which automatic messages it has already shown during the current browser session.
Who else processes data
We use a small number of service providers, only to run AgentlyDesk:
- a hosting provider, for the servers and the database;
- an e-mail delivery provider, for the messages the service sends.
They process data on our instructions and may not use it for their own purposes. Ask us for the current list at [email protected].
How long we keep it
- Closed conversations are deleted automatically once the site's retention period is up, 365 days by default.
- Account and workspace data is kept while the workspace exists and deleted when it is closed, unless the law requires us to keep a record.
- Early-access requests are kept while we are in touch about your request. You can ask us to delete yours at any time.
How we protect it
Secret keys and two-factor secrets are encrypted at rest, every operator signs in with a second factor, and each workspace is isolated from every other. The security page describes the controls in detail.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to receive a copy, and to object to or restrict how it is used. Write to [email protected] from the address the request is about, and say what you would like us to do. We may need to confirm it is you before we act. You can also complain to your local data protection authority.
Children
AgentlyDesk is a tool for businesses and is not directed at children.
Changes to this policy
When we change this policy we update the date at the top. If a change affects how we use customer data, we tell workspace owners by e-mail before it takes effect.