Versión 2026-07-30

ES · EN

Privacy Policy

Data controller: CALADESK. Contact: privacidad@caladesk.com.

1. Controller and dual role

CALADESK is a support ticketing platform that client companies use to handle their own customers' requests by email. With respect to account data (users, companies, configuration, billing), CALADESK acts as the data controller. With respect to the content of tickets and emails that each client company enters into the platform (messages, attachments, and data about their own customers), CALADESK acts as a data processor: it processes that data on behalf of and under the instructions of the client company, which is the controller of that data towards its own customers.

2. Data we collect

3. Purposes and legal basis

We process this data to: provide the ticket management service, authenticate users and protect accounts, provide technical support, and comply with legal obligations. The legal basis is the performance of the service contract with the client company, our legitimate interest in the security of the platform, and compliance with applicable legal obligations.

4. Recipients and subprocessors

To operate the service we rely on external providers (for example, for email and hosting) that act as subprocessors. The full list is available on the Providers page.

5. Retention

We retain data for as long as the account and contracted service remain active, and afterwards for the period necessary to comply with legal obligations or resolve disputes. Detailed retention periods by data type are documented separately.

6. Your rights

You may exercise your rights of access, rectification, erasure, portability, objection, and restriction of processing over your personal data at any time by writing to privacidad@caladesk.com. We will respond within the timeframes required by applicable law. If a request concerns ticket data entered by a client company, we may redirect you to that company, which is the controller of that data.

7. International transfers

Some of our providers (for example, email providers) may process data outside your country of residence, including in the European Union and the United States. In those cases we require adequate data protection safeguards in accordance with applicable law.

8. Security

We apply reasonable technical and organizational measures to protect data, including encryption of secrets at rest (for example, mail connection credentials), optional multi-factor authentication (MFA) for accounts, and planned use of HTTPS in production to protect data in transit.

9. Cookies

We use only strictly necessary cookies for the site to function. See the Cookie Policy for details.

10. Changes to this policy

We may update this policy when our practices or applicable law change. The current version and its date are shown at the top of this page. If the change is significant, we will ask for your acceptance again.

11. Applicable regulation

This policy is based on the principles of the European Union's General Data Protection Regulation (GDPR), which in practice also covers the requirements of Panama's Law 81 on Personal Data Protection and the California CCPA, among other applicable data protection laws.