Privacy isn't a checkbox. It's the default.

Many help desks add compliance once sales asks for it. Deskwoot started there: hosted in the EU, with the Data Processing Agreement written and ready to accept.

Your data lives in the EU on every plan

The app and its database run on servers in the Netherlands for every workspace, the free plan included. Where your data lives never depends on what you pay.

Hosted in the EU

Conversations, messages and contacts sit in a database in the EU. It is backed up every day, and each backup is kept for at least 7 days.

Encrypted in transit

Every connection uses TLS 1.2 or newer: the dashboard, the chat widget, the API, the database link and outgoing mail.

Credentials sealed with AES-256

Mail passwords, API keys and integration tokens you store with us are encrypted field by field with AES-256-GCM. Login passwords are kept only as bcrypt hashes.

Your customers' data, under your control

When someone asks what you hold about them, or wants it deleted, your team handles it from one page in the settings, without waiting for us.

Export on request

Find a contact by email and download what you hold about them as a JSON file, built at the moment of the request (Art. 15).

Erasure with a preview

Deskwoot shows exactly what an erasure will remove. You confirm by typing the email address again, and the data is gone right away (Art. 17).

30 days to change your mind

Deleting your workspace starts a grace period of 30 days. After it ends, conversations, contacts and files are deleted for good.

Every vendor named, every change announced

Annex B of the DPA lists each sub-processor with its purpose and region, from hosting and AI to email delivery and payments.

A public list

Anyone can read who processes data for us and what they receive, before signing anything.

Notice before changes

Before we add or replace a sub-processor, we tell you, so you can object before any data reaches it.

Safeguards for transfers

Vendors outside the EEA, such as email delivery and SMS, are bound by the EU Standard Contractual Clauses.

The smaller details procurement checks

None of these makes a headline. All of them come up in security reviews.

  • No AI training on your data

    Conversation content sent to our AI providers is used to answer, not to train their models. The DPAs confirm it in writing.
  • IP addresses masked after 30 days

    IP addresses stored in audit logs and visitor data are cut down to the network part once they are 30 days old.
  • Two factor authentication

    Anyone on your team can protect their login with an authenticator app. On Enterprise, admins can require it for everyone.
  • Audit log

    Sign ins, API token changes, plan changes and deletions are recorded with user, time and IP address.
  • Roles and permissions

    Owners, admins and agents get different rights. On Enterprise you can build custom roles with exactly the permissions you choose.
  • Consent where the law asks

    Visitors from the EU, EEA, UK and Switzerland get a cookie banner on our website. Our newsletter only starts after you confirm your address.

Procurement and GDPR questions

The short answers are here. For anything else, ask Fynn below.

Is Deskwoot GDPR compliant?

Yes. Your workspace data is hosted in the EU, every workspace can accept a Data Processing Agreement under Art. 28, we keep records of processing under Art. 30, and your team can export or erase a person's data from the settings whenever someone asks.

Where is my customer data stored?

The app and its database run in the EU (Netherlands) on every plan, the free plan included. A few vendors outside the EEA, such as email delivery and SMS, receive only what they need for their task. Annex B of the DPA lists each one with its region.

How do I sign the Data Processing Agreement (DPA)?

You don't need to email anyone. Read the DPA on our website, accept it in your workspace settings, and the PDF arrives by email. Annex A of the same document lists our technical and organisational measures under Art. 32.

How do we delete a customer's data when they ask?

Open the data requests page in your settings, find the contact by email and start an erasure. Deskwoot shows what will be deleted, you confirm by typing the address again, and the data is erased right away. That covers the right to erasure under GDPR Art. 17.

Does Deskwoot use my data to train AI models?

No. Conversation content goes to our AI providers only to generate replies, and it is not used to train their models. Our DPA and the providers' own DPAs confirm this in writing. Fynn answers from your help center and the sources you add in the Training Hub, scoped to your workspace.

Who are Deskwoot's sub-processors?

Annex B of the DPA names every sub-processor with its purpose and region. We tell you before a new one is added or replaced, so you can object first. Vendors outside the EEA are bound by the EU Standard Contractual Clauses.

What happens to my data if I close my Deskwoot account?

Deleting your workspace starts a grace period of 30 days, in case you change your mind or still want to export. On a paid plan, the 30 days start when your current billing period ends. After that, conversations, messages, contacts and files are deleted for good.

Is my data encrypted at rest and in transit?

In transit, yes: every connection uses TLS 1.2 or newer. On top of that, credentials you store with us, such as mail passwords, API keys and integration tokens, are encrypted field by field with AES-256-GCM, and login passwords are kept only as bcrypt hashes.

Privacy built in from day one

Deskwoot interactive demo