##Scope
This notice covers three different flows of data, and they are worth keeping separate because the obligations differ.
- Agent data - device and software state collected from machines inside a customer workspace.
- Workspace content - tickets, checklists, licence records and the audit log, created by the customer and the people who write in.
- Account and website data - the details of the people who sign up, pay and get in touch.
##Who controls what
For agent data and workspace content, the customer is the controller and we are the processor. The customer decides which devices carry the agent, who has access, what is collected from the people who write in, and how long any of it is kept beyond our defaults. We act on their instructions.
For account and website data we are the controller, because that relationship is ours: the signup, the billing, the support conversation.
##What the agent collects
The complete list. If a field is not here, the agent does not send it.
##What is never collected
These are not settings that default to off. The capability is absent from the agent, which is a different and stronger statement.
- Screen contents, screenshots or screen recording
- Keystrokes or any input capture
- Clipboard contents
- Personal files - documents, photos, downloads, desktop contents
- Browser history, bookmarks or saved credentials
- Camera or microphone input
- Geographic location, including for a device flagged as lost
- Network traffic contents, packet captures or intercepted TLS
- Idle time, activity scores or any productivity measure
##Ticket content
When a person writes in, we hold what they sent: their name and address on the channel they used, the text of the request, any attachment, and the correspondence that followed. People describe their own circumstances in support requests, so this can contain more than the customer intended to collect.
We do not use ticket content to train models for anyone else. Similar-ticket matching and suggested fixes operate only within the workspace that created the records. No workspace benefits from another workspace's history, and no shared model is derived from it.
###WhatsApp intake
Where a customer enables WhatsApp intake, the message and its attachments reach us through a messaging provider acting as a subprocessor. The sender's phone number is held so the message can be attributed to a person and so replies thread correctly.
##Account data
Name, work email address, company name, role, approximate device count, plan, and the content of anything sent through the signup or contact forms. Payment is handled by our payment provider; we see the billing name, country, invoice history and the last four digits of a card, and never the full number.
##This website
No advertising trackers, no third-party analytics scripts and no cross-site profiling. Server logs record requests, with IP addresses retained for 14 days for abuse prevention and aggregated afterwards.
Form submissions include a signed arithmetic challenge to keep automated submissions out. The challenge is stateless and sets no cookie.
##Why we hold it
We do not sell data, we do not share it for advertising, and we do not build profiles for marketing. Nobody is added to a mailing list by signing up or getting in touch.
##Who it is shared with
Only the subprocessors needed to run the service - hosting, transactional email, the messaging provider behind WhatsApp intake, error monitoring and payment processing. Each is named on the subprocessors page with what it handles and where.
Our own staff cannot read a customer workspace. Support access requires a written request from a workspace admin, is scoped to a time window, and is recorded in that workspace's audit log as it happens.
##Where it is stored
A region is chosen when a workspace is created and is fixed afterwards. Data stays in that region, including for support. In transit everything uses TLS 1.3 with the agent pinning our certificate; at rest the database and its backups are encrypted with AES-256.
##How long it is kept
##Your rights
Depending on where you live you may have the right to access what is held about you, correct it, have it deleted, restrict or object to its processing, and receive it in a portable form.
If your employer or a service provider uses this product, they are the controller of the agent and workspace data about you. Ask them first - they can answer immediately and they hold the access. We will support them in responding, and we will refer a request we receive directly on to them rather than acting unilaterally on their data.
For account data, where we are the controller, get in touch through the contact page and we will respond within 30 days.
##Telling your staff
If you are deploying the agent across a company, you have an obligation to tell the people whose devices carry it. The Never collected list above is written to be quoted directly in an internal note, and doing so on the day of rollout prevents a suspicion that is far more expensive to undo later.
##If something goes wrong
A personal data breach affecting a workspace is reported to that workspace's admins without undue delay and within 72 hours of us becoming aware, with what we know at the time rather than a holding statement. Service incidents, including ones with no data impact, are written up publicly on the status page.
