What we do with your customers' data.
When you run a support desk on QuickDesk, we handle personal data that belongs to your customers. This page is the agreement covering that: what we process, who helps us, how it is protected, and what happens when you leave. It sits alongside the privacy policy and forms part of the terms of service.
Who is responsible for what
The processor under this agreement is Arched, which operates QuickDesk, of Harrison House, Sheep Walk, Langford Road, Biggleswade, SG18 9RB.
You are the controller of your customers' personal data: you decide why it is collected and what happens to it. We are the processor: we handle it on your behalf, only to run the service you have asked us to run, and only on your instructions. Using QuickDesk in the ordinary way is that instruction. If we ever believe an instruction would break data protection law, we will say so rather than quietly carry it out.
Whose data, and what kind
The people are your customers and the visitors to your website who start a chat or send you an email, and the members of your own team who use the desk.
The data is what a support conversation involves: a name and email address where the person gives one, the content of chat messages and emails including any attachments, and basic technical information such as the page a chat started on. If you connect a Shopify store, we also read a matching customer's name, email address and recent order summary so your agent can answer order questions without leaving the ticket. We do not receive card or payment details.
Why, and for how long
We process it for one purpose: providing the support desk to you. Not for advertising, not for training models, not for sale to anyone. We keep account and conversation data while your account is active, attachments for the period your plan states (30 days on Starter, 90 days on Pro), and we remove data after a short recovery window once an account closes. You can export your data at any time from Settings.
Who else is involved
We use a small number of providers to run the service, and they are bound by equivalent obligations to the ones on this page:
- Stripe, for billing.
- Amazon Web Services (London), to send and receive support email.
- OpenRouter and the model provider it routes to, only when an agent asks for an AI draft.
- Google Analytics, for optional analytics on our own site.
- Shopify, where you have connected a store, for the order lookup described above.
If we add or replace one, we will update this page. Tell us at contact if you want to be notified directly when that happens.
How it is protected
This is a description of what is actually in place, not a wish list:
- Traffic is encrypted in transit.
- The database is encrypted at rest, on its own encrypted storage.
- Database backups are encrypted.
- Access credentials we hold for connected platforms are encrypted before they are stored.
- Who on your team can see what is enforced on the server, not hidden in the interface.
- Access to production data is restricted to the people who need it, protected by strong password requirements, and logged.
- Test data and live data are kept apart.
- We keep a written security incident response policy and a plan for preventing data loss.
If something goes wrong
If we become aware of a breach affecting personal data we process for you, we will tell you without undue delay, with what we know about what happened, who is affected and what we are doing about it, so that you can meet your own reporting duties.
Helping you meet your obligations
If one of your customers asks for a copy of their data, or asks you to delete it, we will help you answer. Where a connected platform sends us that request on your behalf we act on it automatically. We will also give you the information you reasonably need to show a regulator or an auditor how their data is handled.
Where the data lives
QuickDesk is built and hosted in the United Kingdom. Some of the providers listed above operate outside the UK, and where they do, transfers rely on the safeguards those providers have in place, such as standard contractual clauses.
When you leave
Close your workspace and we delete the personal data we hold for you after the recovery window, other than anything we are legally required to keep, such as billing records. Export first if you want a copy.
Accepting this
Creating a QuickDesk workspace accepts this agreement along with the terms of service, so there is nothing to sign. If your organisation needs a countersigned copy, ask us at contact and we will arrange it.