Legal

Privacy Policy

This Privacy Policy explains how TrustDesk collects, uses, shares, and protects personal information when you use the TrustDesk platform, our website at trustdesk.net, and related services.

Last updated: July 23, 2026

1. Introduction

TrustDesk ("TrustDesk", "we", "us") is committed to protecting your privacy. This policy describes the personal information we process, why we process it, and the choices and rights you have.

It applies to our website, the TrustDesk platform, and any related services that link to this policy. Where TrustDesk processes personal data on behalf of a customer, that processing is also governed by our Data Processing Addendum.

2. Information we collect

Information you provide: your name, work email, company, role, and any details you share when you create an account, request a demo, contact support, or complete a form.

Account and authentication data: credentials, single sign-on identifiers, security settings, and audit logs generated as you use the platform.

Customer content: documents, evidence, policies, and other material you or your team upload to your workspace. This content is processed on your instructions and is addressed in our Data Processing Addendum.

Usage, device, and cookie data: log data, IP address, browser and device information, and information collected through cookies and similar technologies, described in our Cookie Policy.

3. How we use information

We use personal information to provide, operate, and maintain the service; authenticate users; respond to requests; and send service-related communications.

We process data to secure the platform, detect and prevent incidents and abuse, improve and develop features, and meet our legal and contractual obligations.

Where you have opted in, we may send product updates and marketing communications. You can withdraw consent at any time.

4. Legal bases for processing

Where the EU/UK GDPR applies, we rely on one or more of the following legal bases: performance of a contract, our legitimate interests (such as securing and improving the service), your consent, and compliance with legal obligations.

Where the India Digital Personal Data Protection Act (DPDP) applies, we process personal data on the basis of your consent or other legitimate uses permitted by law.

5. Our role: controller and processor

For our website, marketing, and account administration, TrustDesk acts as a data controller.

For customer content processed within a workspace, TrustDesk acts as a data processor and processes that data only on the documented instructions of the customer, who is the controller. These arrangements are governed by our Data Processing Addendum.

6. Sharing and subprocessors

We do not sell personal information. We share it only with vetted subprocessors — such as hosting, email delivery, analytics, and support providers — who help us deliver the service under appropriate data protection terms.

We may also disclose information where required by law or to protect the rights, safety, and security of TrustDesk, our customers, and the public. A current list of subprocessors is available on request and through our Trust Center.

7. International transfers

Where personal data is transferred across borders, we rely on recognized safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

Enterprise customers may be able to select a data residency region for their workspace.

8. Data retention

We retain personal information only for as long as necessary to provide the service, comply with our legal obligations, resolve disputes, and enforce our agreements.

When data is no longer needed, we delete or anonymize it. Customer content is retained and deleted in accordance with your subscription and our Data Processing Addendum.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal information; to object to or restrict certain processing; and to withdraw consent where processing is based on consent.

You also have the right to lodge a complaint with your local data protection authority. To exercise any of these rights, contact us at privacy@trustdesk.com.

10. Data security

Data is encrypted in transit and at rest, access is role-based and audit-logged, and our platform is independently assessed against leading frameworks. Learn more on our Information Security & Trust page.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated through the service or by other appropriate means, and the "Last updated" date above will be revised.

12. Contact us

Questions about this policy, or to exercise your rights, contact privacy@trustdesk.com. To report a security or privacy incident, contact security@trustdesk.com.