Helmdesk

Privacy Policy

Last updated August 3, 2026

Draft — pending legal review. This is written to accurately describe how Helmdesk actually works today, but has not yet been reviewed by legal counsel. Treat it as a working draft, not a finalized policy, until that review is complete.

Overview

This policy describes how Kwii Digital Technologies ("Helmdesk," "we," "us") collects, uses, and shares information when you use the Helmdesk platform — the marketing site you're reading now, the agent and tenant-admin dashboard, the client support portal, and the embeddable live chat widget. It applies to three kinds of people: visitors to this marketing site, agents and administrators who use Helmdesk to run support for their own organization, and end clients who submit tickets or chat with support through a Helmdesk-powered portal or widget.

If your organization is a Helmdesk customer, you (the customer) are the data controller for the ticket and client data you put into the system, and Helmdesk acts as your data processor for that content. This policy covers our processor obligations as well as our own use of data as a controller (for example, for this marketing site and our own billing).

Information we collect

Account and contact information

  • Name, email address, and role for anyone with a Helmdesk login (agents, tenant admins, tenant users).
  • Name, email, company, and message content submitted through this site's contact/demo-request form.

Support content

  • Ticket subjects, messages, attachments, tags, and status history.
  • Live chat transcripts, including messages sent by anonymous website visitors using an embedded widget.
  • Knowledge base articles and the "was this helpful" feedback left on them.

Technical and usage data

  • IP address, for rate limiting and abuse prevention on public endpoints (login, the contact form, the chat widget).
  • Standard web server logs (timestamps, request paths, response codes).

Cookies and local storage

We use your browser's local storage to keep you signed in (a session token) and to remember your cookie-consent choice on this marketing site. See our Cookie Policyfor the full breakdown of what's essential versus optional.

How we use it

  • To operate the ticketing, live chat, and knowledge base features you or your organization signed up for.
  • To respond to support requests, demo requests, and general inquiries.
  • To send transactional notifications about your own tickets (created, replied to, resolved) and, if you've opted in, a satisfaction survey after resolution.
  • To detect and prevent abuse — rate limiting, fraud prevention, and security monitoring.
  • To improve the product, using aggregated or de-identified usage patterns where possible.

We do not sell personal information, and we do not use ticket or chat content to train third-party AI models beyond the specific, per-request use described below.

Third-party processors

We rely on a small number of specialist vendors to run Helmdesk. Each only receives the data it needs to do its job:

  • Brevo — sends transactional emails (ticket notifications, password resets, satisfaction surveys) and, separately, holds the marketing contact list built from this site's demo-request form.
  • Postmark — receives inbound email sent to a tenant's support address and turns it into a ticket.
  • Anthropic (Claude) — when a tenant's agent uses AI-assisted ticket triage or reply drafting, the relevant ticket thread (excluding internal-only notes) is sent to Anthropic's API for that single request. This feature is optional and only invoked when an agent clicks to use it.
  • Stripe — processes invoice payments for tenants who use Helmdesk's billing feature. We never see or store full card numbers ourselves.
  • Hetzner — our infrastructure hosting provider; all application servers and databases run on Hetzner's infrastructure.
  • Cloudflare — provides DNS and certificate automation for custom domains connected to a tenant's portal.
  • Remote-access / video support tooling — Helmdesk plans to integrate a remote-assist and video-support vendor (see our Features page). This section will be updated with the specific vendor and data flow before that feature ships.

Data retention

We retain ticket, chat, and knowledge base data for as long as your organization's account is active, so your team retains its own support history. If your organization closes its account, we retain data for a limited period to allow for export or reactivation, then delete it, except where we're required to keep records for legal or accounting reasons (for example, invoice records).

Demo-request and contact-form submissions are retained for as long as reasonably useful for following up with you, and deleted or anonymized on request.

Your rights

Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you. If you're an end client of one of our customers (for example, you submitted a ticket to an MSP that uses Helmdesk), the fastest path is usually to contact that organization directly, since they control the account — but you're welcome to contact us too and we'll route your request appropriately.

To exercise any of these rights, contact us using the details below.

How we protect your data

Every customer's data is isolated at the database level using row-level security policies, not just application-level checks — one organization's tickets and client data are not reachable by another organization's account, enforced by Postgres itself. All traffic to Helmdesk is encrypted in transit via TLS. See our Security page for more detail.

Children's privacy

Helmdesk is a business-to-business support tool and is not directed at, or knowingly used to collect information from, children.

Changes to this policy

We'll update the "last updated" date at the top of this page when this policy changes, and for material changes, we'll make a reasonable effort to notify active account administrators directly.

Contact us

For any privacy question or request, email privacy@helmdesk.ca.