In plain language
Four companies always touch data when you use Desert Desk: our host, our AI provider, our payment processor, and our email sender. Six more only get involved if you switch on an integration that sends data to them.
Every one of them is in the United States. Section 3 is the part to read if you're wondering whether connecting Salesforce or Google Sheets changes who sees what — it does, and it's your choice.
This summary is for orientation only. The numbered sections are the list.
Contents
About this list
A subprocessor is a third party we engage to process personal data on your behalf while providing the service. This page lists all of them, and it is the authoritative list referenced by our Data Processing Addendum.
We've split the list into two, because the distinction matters more than it usually gets credit for. Core subprocessors are engaged whenever anyone uses the service — you cannot opt out of them and still have a working product. Optional subprocessors are engaged only if you configure an integration that sends data to them, which means the decision is yours and you can reverse it.
All subprocessors named here process data in the United States.
Core subprocessors
Engaged for every customer, always.
| Subprocessor | Function | Data processed | Location |
|---|---|---|---|
| Railway Corp. | Application hosting, database, cache, and DNS. The infrastructure the product runs on. | All application data, including conversation content, account records, and configuration. | United States |
| Anthropic PBC | AI model inference and hosted knowledge base storage. Generates the agent's responses. | Conversation content, agent instructions, and uploaded knowledge base documents. | United States |
| Stripe, Inc. | Payment processing for wallet top-ups and membership subscriptions. | Billing contact details and payment card data. Card numbers are held by Stripe and never reach our systems. | United States |
| Resend (Plus Five Five, Inc.) | Transactional email delivery — receipts, security alerts, password resets, balance notices. | Account holder names, email addresses, and the content of those emails. | United States |
| Cloudflare, Inc. | Hosting for our public marketing site at www.desertdesk.app. | Marketing site visitor request data only. No customer or end-user application data reaches Cloudflare. | United States |
On Anthropic specifically, since it's the one people ask about: Anthropic does not train its models on inputs or outputs submitted through its business API by default. Your conversations and knowledge base are processed to generate responses for you, and for nothing else.
Optional subprocessors
Engaged only where you enable the relevant integration. Until you do, no data reaches these parties, and disabling the integration stops the flow going forward.
When you connect one of these, you are instructing us to send data there. That destination's own terms and privacy practices govern what happens to it after delivery, and you are responsible for having the right to send it.
| Subprocessor | Function | Data processed | Location |
|---|---|---|---|
| Salesforce, Inc. | Live-agent handoff, where you route conversations to Salesforce Messaging rather than the built-in helpdesk. | Conversation content and transfer context. | United States |
| Zapier, Inc. | Event delivery to your own tools via our Zapier integration. | Whatever the events you subscribe to contain — which may include transcripts and contact details. | United States |
| Google LLC | Writing resolved-conversation records to a Google Sheet you own. | Transcript content and contact details, written to your spreadsheet. | United States |
| Meta Platforms, Inc. | Messaging channel integration, where you connect a Meta messaging surface. | Conversation content exchanged over that channel. | United States |
| Atlassian (Statuspage) | Reading your public status page so the widget can show an incident banner. | None. This integration only reads public status information. No personal data is sent. | United States |
Things that look like subprocessors but aren't
For completeness, because these come up in security reviews:
- Google Fonts. Our pages request two typefaces from Google's font service. This reveals the visitor's IP address to Google as any font request would, but no personal data is processed on our behalf and no cookie is set.
- Public STUN servers. Voice calls inside a co-browsing session use public STUN infrastructure to help two browsers find each other. Audio travels directly between participants and never passes through these servers. No personal data is processed by them.
- Your own integration destinations. Where you configure a webhook pointing at your own systems, those systems are yours, not our subprocessors.
Safeguards
Before engaging a subprocessor we assess its security and privacy practices proportionately to what it will handle. Each is bound by a written agreement requiring it to process data only on documented instructions, to maintain appropriate security measures, and to protect confidentiality.
We remain responsible to you for our subprocessors' performance of their data protection obligations under our Data Processing Addendum.
Current state. Our diligence is a documented review of each provider's published security posture, terms, and compliance certifications. We do not currently run a formal recurring vendor-risk assessment programme with scheduled re-review — that's on the roadmap listed in our Trust Center. We'd rather say so than let a security questionnaire assume otherwise.
Changes and notice
When we add or replace a subprocessor, we update this page and advance the “Last updated” date at the top. That date is the authoritative record of when the list last changed.
For material changes affecting core subprocessors, we will also notify account administrators by email.
We deliberately do not promise a fixed advance-notice window. Many vendors commit to 30 days and quietly miss it. We don't yet have a subscription mechanism that would let us reliably deliver on that promise, so we're not making it. Building one is on our roadmap; until then, this page plus email to administrators is what we can actually honour.
Objecting to a change
If you have a reasonable, documented data-protection objection to a new subprocessor, tell us at privacy@desertdesk.app within 30 days of the change being published.
We will work with you in good faith to find an alternative — which may mean disabling the affected feature for your account, where that's technically possible. If we can't resolve it, you may terminate the affected part of the service and receive a refund of any unused prepaid balance attributable to it.
Objecting to a core subprocessor generally means objecting to the service itself, since the product cannot function without hosting or model inference. We'd rather be direct about that than imply flexibility we don't have.
Contact
- Subprocessor questions and objections
- privacy@desertdesk.app
- Postal address
- Desert Desk LLC
[NOTICE ADDRESS]