Privacy Policy
Version 2026-08.2
- Service provider
- TO BE FILLED IN
- Registration number
- TO BE FILLED IN
- Registered office
- TO BE FILLED IN
- Contact for data protection
- support@dundesk.com
1. In which capacity we speak here
This document explains what personal data we process about you and the users of your account — account, business, subscription, support, security. For that data we are the controller.
Your guests' data, which you enter into the application, is a different matter: there you are the controller and we are the processor. Those rules are in the Data Processing Agreement.
2. What data we process about you
The user account. Name, email address, password (kept only in encrypted form, never in clear), interface language and preferences, a profile picture if you upload one, the account status and the date it was created.
The business. The name, tax identification number, address and billing details you declare, along with the users you add and their permissions.
The subscription. The chosen plan, its validity periods, payments and issued invoices, and the reminders sent before expiry.
Support. The tickets you open and the messages exchanged on them.
Security and operation. Open sessions (created, last used, IP address and browser), the activity journal of important actions in the account, the application's technical logs, and the record of your acceptance of the legal documents, with the date, IP address and browser.
Communications. The emails we send you from the application — address confirmation, password reset, the notifications you enabled and, if you ticked it, commercial communications.
3. Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Creating the account, providing the application, support | Performance of the contract |
| Invoicing and accounting records | Legal obligation |
| Application security, abuse prevention, technical and activity logs | Legitimate interest — protecting the service and its customers |
| Proof of acceptance of the legal documents | Legal obligation and legitimate interest |
| Commercial communications | Consent, withdrawable at any time |
4. Who else sees the data
We do not sell data and do not make it available to other customers. The following categories of provider may process it, strictly to help us deliver the service and only on our instructions:
- the server hosting provider;
- the email delivery provider;
- the invoicing provider;
- the payment processor, from the moment online payment opens in the application.
The concrete list of these providers is the one in the corresponding section of the Data Processing Agreement and is kept current there.
We may also disclose data to authorities where the law requires it.
5. Where the data is
Data is kept on servers in the European Union. We do not transfer data outside the European Economic Area. Should that change, this text is amended first, and any transfer takes place only with the safeguards the law requires.
6. How long we keep it
- While the account is open — account, business and usage data.
- 30 days after termination — to give you time to export your data; then it is deleted.
- 10 years — accounting records, as the law requires.
- Permanently — the record of acceptance of the legal documents, which is the proof of what was accepted and when; it survives the deletion of the account, without the data that directly identifies you.
- Short periods — technical logs and sessions, which rotate automatically.
7. What you can do yourself, from the application
On the account page, in the privacy section:
- Download all your data — you receive a password-protected archive by email, with everything about you in a machine-readable format;
- Delete your account — you confirm with a code sent by email, and the deletion runs after a 7-day grace period in which you can change your mind. The grace period exists so that a stolen session cannot destroy an account in silence;
- See your acceptance history — which document, which version, when.
Deleting the owner's account requires the business and the subscription to be closed first; the application tells you what is left to do.
8. Your rights
You have the right of access, rectification, erasure, restriction of processing, portability and objection, as well as the right to withdraw your consent where processing is based on it. You can exercise them from the application, where the button exists, or by writing to the address at the top of this page.
If you are unhappy with how we process your data, you may complain to us directly and you may address the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, www.dataprotection.ro.
9. Cookies
The application uses no tracking, advertising or behavioural analytics cookies. We use strictly what the application needs to work:
- a session cookie, which keeps you signed in;
- a language cookie, which remembers the language you chose;
- preferences kept in the browser's local storage — light or dark theme, the state of the menu, the way you arranged your lists. They never reach us.
10. Automated decisions
We take no decisions with legal effect on you by purely automated means, and we do no profiling.
11. Changes to this policy
We may change this policy. The version in force is the one shown at the top of this page. When a change is significant, the application asks you to accept it at your next sign-in.
12. Language
This document is written in Romanian and translated into English. In case of any discrepancy, the Romanian version prevails.