1. Who this policy is about
HelpDesk is used by businesses to talk to their customers on WhatsApp. So there are two groups of people:
- Our customers: the businesses that use HelpDesk, and the people in their teams who sign in. For their account details, we decide how the data is used.
- Their customers: the people who exchange WhatsApp messages with those businesses. For this data the business decides how it is used; we only store and process it for that business, on its instructions.
2. What we collect
| Kind of data | What it includes |
|---|---|
| Account details | Name, email address, role and department of each team member; the business’s name. Passwords are stored only as a one-way hash, which cannot be read back. |
| WhatsApp account details | The identifiers of the WhatsApp Business account and phone numbers a business connects, the numbers’ display names, quality ratings and messaging limits, and the access token Meta issues, which we store encrypted. |
| Conversations | Messages sent and received through the connected numbers, with their time and delivery status, and the pictures, videos, voice notes and documents attached to them. |
| Contacts | The phone number and WhatsApp profile name of each person who exchanges messages with the business, anything the business adds about them (such as tags and its own fields), and whether they have opted out of marketing messages. |
| Technical data | IP address, browser type and the time of sign-ins and requests, kept in security and server logs. |
We do not ask for, and the service is not designed for, sensitive data such as health or payment-card details. Businesses should not use it to collect them.
3. Data we receive from Meta
When a business connects its WhatsApp Business account, we receive data from the WhatsApp Business Platform: incoming messages and media, delivery and read receipts, message template status, and the account and phone number details listed above. We use this data only to provide the service to that business. We do not sell it, do not use it for advertising, do not build profiles of people from it, and do not combine one business’s data with another’s.
4. How we use data
- To show a business its conversations and let its team reply.
- To send the messages, templates and campaigns the business asks us to send.
- To honour opt-outs: a contact who opts out is left out of campaigns.
- To keep the service safe: signing people in, preventing abuse, and watching quality ratings and block rates so that misuse of WhatsApp is stopped early.
- To measure each workspace’s use against its plan, and to bill for it.
- To answer support requests and to tell account owners about changes to the service.
- To meet legal obligations.
5. Who we share data with
We share personal data only with the suppliers needed to run the service:
| Supplier | Why |
|---|---|
| Meta (WhatsApp Business Platform) | Every WhatsApp message is delivered through Meta. Meta handles it under its own terms and privacy policy. |
| Cloudflare | Storage of files and backups, domain name services, and the check against automated sign-ups on the sign-up form. |
| Our hosting provider | The servers the application and its databases run on. |
| Our email delivery provider | Sending account emails, such as invitations and sign-up confirmation. |
We may also disclose data when the law requires it, or to protect the rights and safety of our customers and the public. We do not sell personal data to anyone.
6. How data is protected
- All connections to the service are encrypted (HTTPS).
- WhatsApp access tokens are encrypted before they are stored.
- Each business’s data is kept apart from every other’s, and every request is checked against the workspace it belongs to.
- Files are stored privately. A file is shown only to a signed-in team member who is allowed to see the conversation it belongs to.
- Our own staff reach the administration panel only with a password and a second factor, and their actions are recorded.
No system is perfectly secure. If a breach affects your data, we will tell you without undue delay.
7. How long data is kept
- While a workspace is open, its conversations, contacts and files are kept so the business can use them.
- When a workspace is closed, its data is kept for 30 days, so that the owner can ask for it to be restored, and is then deleted.
- Backups are kept on a rolling schedule of up to eight weeks. Deleted data leaves the backups as they expire.
- Server logs are kept for a short time and overwritten automatically.
8. Your rights and choices
- If you use HelpDesk at work, you can ask your workspace owner, or us, to see, correct or delete your account details.
- If you messaged a business that uses HelpDesk, that business holds your data. Ask it to show, correct or delete what it holds about you, or to stop messaging you. You can also write to us; we will pass your request to the business and help it respond.
- You can stop marketing messages from a business at any time by telling it so on WhatsApp, or by blocking it.
The steps for deleting data are on the data deletion page.
9. Cookies
This website sets no cookies and uses no analytics or advertising trackers. The application sets only the cookies needed to keep a team member signed in and to protect the session. The sign-up form uses Cloudflare Turnstile to tell people from automated programs.
10. Where data is processed
Data may be stored and processed in countries other than the one you are in, including where our suppliers operate. Wherever it is processed, it is protected as this policy describes.
11. Children
The service is for businesses. It is not meant for children, and we do not knowingly collect account details from anyone under 18.
12. Changes to this policy
We may update this policy. The date at the top shows when it last changed. If a change is significant we will tell workspace owners before it takes effect.
13. Contact
Questions and requests about personal data:
- Email: support@helpdesk.com.pk