Privacy Policy
Data controller: CALADESK. Contact: privacidad@caladesk.com.
1. Controller and dual role
CALADESK is a support ticketing platform that client companies use to handle their own customers' requests by email. With respect to account data (users, companies, configuration, billing), CALADESK acts as the data controller. With respect to the content of tickets and emails that each client company enters into the platform (messages, attachments, and data about their own customers), CALADESK acts as a data processor: it processes that data on behalf of and under the instructions of the client company, which is the controller of that data towards its own customers.
2. Data we collect
- Account data: name, email address, encrypted password, and, if enabled, multi-factor authentication (MFA) data.
- Ticket and customer email content: the messages, attachments, and contact details that client companies receive from their own customers and that the platform organizes into tickets.
- Technical metadata: IP address, access date and time, and activity logs necessary for the security and operation of the service.
3. Purposes and legal basis
We process this data to: provide the ticket management service, authenticate users and protect accounts, provide technical support, and comply with legal obligations. The legal basis is the performance of the service contract with the client company, our legitimate interest in the security of the platform, and compliance with applicable legal obligations.
4. Recipients and subprocessors
To operate the service we rely on external providers (for example, for email and hosting) that act as subprocessors. The full list is available on the Providers page.
5. Retention
We retain data for as long as the account and contracted service remain active, and afterwards for the period necessary to comply with legal obligations or resolve disputes. Detailed retention periods by data type are documented separately.
6. Your rights
You may exercise your rights of access, rectification, erasure, portability, objection, and restriction of processing over your personal data at any time by writing to privacidad@caladesk.com. We will respond within the timeframes required by applicable law. If a request concerns ticket data entered by a client company, we may redirect you to that company, which is the controller of that data.
7. International transfers
Some of our providers (for example, email providers) may process data outside your country of residence, including in the European Union and the United States. In those cases we require adequate data protection safeguards in accordance with applicable law.
8. Security
We apply reasonable technical and organizational measures to protect data, including encryption of secrets at rest (for example, mail connection credentials), optional multi-factor authentication (MFA) for accounts, and planned use of HTTPS in production to protect data in transit.
9. Cookies
We use only strictly necessary cookies for the site to function. See the Cookie Policy for details.
10. Changes to this policy
We may update this policy when our practices or applicable law change. The current version and its date are shown at the top of this page. If the change is significant, we will ask for your acceptance again.
11. Applicable regulation
This policy is based on the principles of the European Union's General Data Protection Regulation (GDPR), which in practice also covers the requirements of Panama's Law 81 on Personal Data Protection and the California CCPA, among other applicable data protection laws.