Legal

Data Processing Addendum

Last updated: 30 July 2026 Effective: 30 July 2026 Version: 1.0

In plain language

When your customers chat with your widget, you are the one deciding what happens to their data and we are simply carrying out your instructions. This document sets out what that means in practice: what we'll do, what we won't, how fast we'll tell you if something goes wrong, and what happens to the data when you leave.

You don't need to sign it. It becomes part of your agreement automatically as soon as your use of Desert Desk involves personal data. If your compliance team needs a countersigned copy for their file, email legal@desertdesk.app and we'll arrange one.

This summary is for orientation only. The numbered sections are the addendum.

Contents
  1. Application
  2. Definitions
  3. Roles of the parties
  4. Processing instructions
  5. Your obligations as controller
  6. Personnel and confidentiality
  7. Security measures
  8. Subprocessors
  9. Data subject requests
  10. Personal data breach
  11. Assistance and assessments
  12. Deletion and return
  13. Audits
  14. International transfers
  15. California terms
  16. Liability
  17. General
  18. Annex A — Processing details
  19. Annex B — Security measures

Application

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Desert Desk LLC (“Desert Desk”, “we”, “us”) and the customer that accepts those Terms (“Customer”, “you”).

It applies automatically and without signature wherever your use of the service involves the processing of personal data. No separate execution is required, and none is implied to be necessary.

Where this DPA conflicts with the Terms of Service on a matter of personal data, this DPA prevails. On all other matters, the Terms prevail.

Definitions

“Data Protection Laws” means all laws relating to the processing of personal data applicable to a party, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).

“Personal Data” means information relating to an identified or identifiable natural person that is processed by us on your behalf under the Terms.

“Processing” means any operation performed on Personal Data, whether automated or not.

“Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in applicable Data Protection Laws. “Business” and “Service Provider” under the CCPA correspond to Controller and Processor respectively.

“Subprocessor” means a third party engaged by us to process Personal Data on your behalf.

Capitalised terms not defined here have the meanings given in the Terms of Service.

Roles of the parties

You are the Controller. You determine the purposes and means of processing Personal Data submitted through the service — including what your widget asks for, how long conversations are retained, which integrations send data elsewhere, and who on your team may access it.

We are the Processor. We process Personal Data on your behalf, on your instructions, for the purpose of providing the service.

Where we process data about your own account administrators — their names, email addresses, authentication data, and billing contact details — we act as a Controller for that limited purpose, and our Privacy Policy governs it. This DPA does not cover that processing.

Processing instructions

We will process Personal Data only:

  • in accordance with your documented instructions, which comprise the Terms of Service, this DPA, your configuration of the service, and any further written instruction you give;
  • as necessary to provide, secure, and maintain the service; and
  • as required by law, in which case we will tell you before processing unless the law prohibits it.

We will not sell Personal Data, share it for cross-context behavioural advertising, retain or use it for any purpose other than providing the service, or combine it with data from other sources except as necessary to perform a business purpose you have permitted.

We do not use Personal Data to train artificial intelligence models, and we contract with our AI subprocessor on terms under which it does not train its models on data submitted through the service.

We will tell you if, in our opinion, an instruction infringes Data Protection Laws.

Your obligations as controller

You represent and warrant that:

  • you have a valid legal basis for the processing you instruct, and have given Data Subjects any notice their rights require — including that a chat widget is in use and that responses are generated by an AI service;
  • your instructions comply with Data Protection Laws;
  • you will not submit, or configure the service to solicit, special categories of personal data, payment card numbers, government identifiers, health information, or biometric data, as set out in the Acceptable Use Policy; and
  • you have configured retention, access permissions, and integrations appropriately for the data you process.

We provide the controls; the settings are yours. Where a longer retention period or a broader integration creates risk, that risk sits with you.

Personnel and confidentiality

We limit access to Personal Data to personnel who need it to provide or support the service. Those individuals are bound by confidentiality obligations that survive the end of their engagement, and receive guidance appropriate to their access.

We do not routinely access customer conversation content. Where access is necessary — to investigate a support request, an abuse report, or a security incident — it is limited to what the task requires and recorded in an audit log.

Security measures

We implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Those measures are described in Annex B.

We may update our security measures provided the overall level of protection is not reduced.

Current state. We have not completed a third-party penetration test or a SOC 2 audit, and we make no such claim anywhere in this document. Annex B describes measures actually in place. Our Trust Center lists what remains outstanding, and we would rather you decide with that information than discover it during procurement.

Subprocessors

You give general authorisation for us to engage Subprocessors. Our current Subprocessors are listed at desertdesk.app/subprocessors, which forms part of this DPA and is the authoritative list.

We will:

  • impose data protection obligations on each Subprocessor no less protective than those in this DPA;
  • remain fully liable to you for each Subprocessor's performance of those obligations;
  • update the Subprocessor page when we add or replace one, advancing its “Last updated” date; and
  • additionally notify account administrators by email of material changes to core Subprocessors.

You may object to a new Subprocessor on reasonable, documented data protection grounds within 30 days of publication, following the process in section 7 of the Subprocessor List. We do not commit to a fixed advance-notice period, for the reason stated on that page.

Data subject requests

The service gives you direct tooling to respond to most requests without involving us: search conversations by content, export a single conversation for an access request, and delete a conversation permanently on a Data Subject's behalf. Your end users can also delete their own conversation from the widget, or use a saved private link to do so later from any device.

Where a Data Subject contacts us directly about data we process on your behalf, we will not respond substantively. We will forward the request to you without undue delay and assist you in responding, taking into account the nature of the processing.

We will provide reasonable assistance with rights of access, correction, deletion, portability, restriction, and objection, insofar as you cannot address them through the service yourself.

Personal data breach

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf.

Our notification will describe, to the extent known at the time:

  • the nature of the breach, including the categories and approximate number of Data Subjects and records concerned;
  • the likely consequences;
  • the measures taken or proposed to address it and mitigate its effects; and
  • a contact point for further information.

Where the full picture isn't available within that window, we will notify you with what we have and provide the rest as it emerges rather than delaying the first notification until the investigation is complete.

We will cooperate with you and take reasonable steps to assist your own investigation and any notification obligations you owe. Notifying regulators or Data Subjects is your responsibility as Controller.

Our Incident Response & Data Breach page describes how we classify and handle incidents in practice.

Assistance and assessments

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority, and will answer security questionnaires within a reasonable time.

We may charge for assistance that goes materially beyond what is reasonably necessary, and will tell you before doing so.

Deletion and return

You may export Personal Data from the admin portal at any time during your subscription.

On termination, we retain your data for a grace period so you can export it or reactivate, then permanently delete it. Deletion cascades across every record associated with your account and is irreversible.

Personal Data that passes your configured retention window is anonymised automatically during the subscription — message content is permanently overwritten and cannot be recovered by anyone, including us.

Backups held by our hosting Subprocessor age out on their own cycle, during which deleted data may persist in them. We do not restore from backup to recover deleted customer data.

We may retain Personal Data where required by law, in which case we continue to protect it under this DPA and process it only for the purpose requiring retention.

Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written questions about our processing and security measures.

We do not currently hold a third-party audit report or certification to offer in place of that. Where an on-site or third-party audit is genuinely required by Data Protection Laws applicable to you, we will discuss a mutually agreeable scope, timing, and cost in good faith, limited to once in any twelve-month period unless a regulator requires otherwise.

Any audit is subject to confidentiality obligations and must not compromise the security or privacy of other customers.

International transfers

We process Personal Data in the United States. All Subprocessors listed on our Subprocessor page operate there.

Current state, stated plainly. Desert Desk is presently built for United States customers. We have not implemented Standard Contractual Clauses, we have not appointed an EU or UK representative, and we have not completed a transfer impact assessment. If you are subject to the EU or UK GDPR and need a compliant transfer mechanism, we are not currently able to offer one, and you should treat that as a genuine limitation. Building this out is on our roadmap.

California terms

This section applies where you are a Business and we are a Service Provider under the CCPA.

We certify that we understand and will comply with the restrictions in this section. We will not:

  • sell or share Personal Data;
  • retain, use, or disclose Personal Data for any purpose other than performing the services specified in the Terms, or as otherwise permitted by the CCPA;
  • retain, use, or disclose Personal Data outside the direct business relationship between us; or
  • combine Personal Data with information received from another source, except as permitted for a business purpose you have authorised.

We will notify you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorised use.

Liability

Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions in the Terms of Service, and any reference there to a party's aggregate liability means aggregate liability under the Terms and this DPA combined.

General

This DPA takes effect when you accept the Terms of Service and continues until we cease processing Personal Data on your behalf. Sections that by their nature should survive termination do so.

We may update this DPA to reflect changes in law, our processing, or our Subprocessors, provided no update materially reduces the protections it provides. Material changes are notified as described in the Terms.

This DPA is governed by the law and subject to the venue stated in the Terms of Service.


Annex A — Processing details

Subject matter and duration

Provision of the Desert Desk customer-support platform, for the duration of your subscription plus the post-termination grace period described in section 12.

Nature and purpose

Hosting, storage, transmission, and AI-assisted processing of customer-support conversations; routing conversations to human agents; generating satisfaction analytics; and delivering data to integrations you configure.

Categories of Data Subjects

  • Your end users who interact with the chat widget.
  • Your personnel who use the admin portal or act as live agents.

Categories of Personal Data

  • Conversation content — messages exchanged between an end user and the AI agent or a human agent, including anything the end user chooses to type.
  • Contact details — where you enable the optional pre-chat form, the fields you configure it to request.
  • Technical identifiers — an opaque browser-generated session identifier and IP address.
  • Feedback — satisfaction ratings, reason tags, and free-text comments.
  • Agent identity — names of your personnel who participate in a conversation.
  • Co-browsing screen content — only where an end user explicitly accepts a co-browsing request; relayed live, never stored.

Special categories

None are requested or intended. The Acceptable Use Policy prohibits configuring the service to solicit them. Where an end user volunteers such information unprompted in free text, it is processed as ordinary conversation content and subject to the same retention and deletion controls.

Frequency

Continuous, for the duration of the subscription.

Retention

Determined by you, between 30 and 180 days, defaulting to 90. Conversations past that window are anonymised automatically each night.

Annex B — Security measures

The following measures are in place today. Our Trust Center lists measures that are not.

Access control and authentication

  • Passwords hashed using bcrypt; never stored or transmitted in readable form.
  • Multi-factor authentication available on every account, with per-user trusted-device tokens and recovery codes.
  • Role-based access control with per-permission grants configurable by account administrators.
  • Session timeouts: 8-hour sliding idle limit, 30-day absolute maximum.
  • Email alerts to account holders on sign-in from an unrecognised browser.

Tenant isolation

  • Customer data separated by PostgreSQL row-level security policies enforced at the database layer, not solely in application code.
  • Every tenant-scoped query carries an organisation filter in addition to the database-level policy.
  • A permanent automated test asserts isolation holds.

Data protection

  • TLS encryption in transit across the platform.
  • Stored third-party integration credentials encrypted at rest using symmetric encryption.
  • Automatic detection and masking of payment-card-like strings in conversation content; unmasking requires an explicit permission grant plus a written justification, and is logged.
  • Configurable retention with automated nightly anonymisation.
  • Co-browsing sessions mask form inputs by default; screen content is relayed live and never written to storage or logs.

Application security

  • Rate limiting on authentication, chat, and public endpoints.
  • Protection against server-side request forgery on customer-supplied webhook destinations, verified at both configuration and delivery time.
  • Cryptographically signed webhook payloads so recipients can verify authenticity.
  • Cross-origin restrictions on application interfaces.
  • Output sanitisation on rendered content.

Monitoring and accountability

  • Immutable audit log of sensitive administrative actions recording actor, action, and timestamp.
  • Justification required and recorded for high-sensitivity actions including unmasking and data export.
  • Application and infrastructure logging, with logs deliberately excluding conversation content.

Operational

  • Managed hosting infrastructure with provider-maintained physical and network security.
  • Database migrations applied automatically before deployment, with additive-first discipline to support rolling releases.
  • Health-checked rolling deployments.
  • Automated test suite executed before release.
  • Two-stage account offboarding — reversible archive, then irreversible cascading purge including cleanup of external resources.