Soft Desk
Privacy Policy

Your Data, Handled Responsibly

Effective date: September 12, 2026

This policy applies to all users globally, with specific provisions for residents of the EEA/UK (GDPR) and California (CCPA/CPRA). Governing law: State of Delaware, USA.

This Privacy Policy describes how Soft Desk, Inc. ("we," "us," or "our") collects, uses, shares, and protects personal information when you access or use the Soft Desk platform and related services (collectively, the "Service"). It applies to all users worldwide, with additional provisions for residents of the European Economic Area, the United Kingdom, and the State of California. By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Service.

1Who We Are

Soft Desk, Inc. ("Company," "we," "us," or "our") is a corporation incorporated in the State of Delaware, United States of America. We operate Soft Desk, a cloud-based workforce management platform that provides attendance tracking, time logging, and project management services (the "Service").

For purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR,Soft Desk, Inc. is the data controller for personal data collected through the Service. Where we process personal data on behalf of your organization (e.g., your employees' records), we act as a data processor under a separate Data Processing Agreement (DPA) available upon request at privacy@soft desk.io.

Our registered office is located at: [COMPANY_ADDRESS], Wilmington, Delaware 19801, United States. Please replace this placeholder with your actual registered address before publishing.

2Information We Collect

We collect information in three ways: directly from you, automatically when you use the Service, and from your organization when it provisions your account.

A. Account & Identity Information

  • Full name, email address, username, and password (hashed and salted).
  • Profile photo (optional) and professional role/title.
  • Organization name, billing address, and VAT/tax identification number (for paid plans).

B. Workforce & Usage Data

  • Check-in and check-out timestamps, shift records, leave requests, and attendance status generated through your use of the attendance module.
  • Time entries: project name, task name, duration, billable flag, and notes you attach to each entry.
  • Project and task data: names, descriptions, deadlines, priority levels, assignment history, and completion status.
  • Team analytics data derived from the above (aggregated productivity metrics, weekly/monthly summaries).

C. Payment Information

  • Billing name, billing address, and the last four digits of a payment card. Full card numbers are processed and stored exclusively by our PCI-DSS-compliant payment processor (Stripe, Inc.) — we never store raw card numbers on our servers.

D. Technical & Device Data (Collected Automatically)

  • IP address, browser type and version, operating system, referring URLs, and device identifiers.
  • Log files recording pages visited, features used, timestamps, and error events.
  • Cookies and similar tracking technologies (see Section 10).

E. Communications

  • Email correspondence with our support team, feedback submissions, and survey responses.

Special Category / Sensitive Data: We do not intentionally collect special category personal data as defined under GDPR (e.g., health data, biometric data, racial or ethnic origin). Attendance records may in some jurisdictions constitute employment-related personal data. We process such data solely as directed by your organization as data controller.

3How We Use Your Information

We use personal data for the following purposes:

  • Providing the Service: Creating and managing accounts, processing attendance records and time entries, generating reports, and delivering all platform features.
  • Billing & Account Management: Processing subscription payments, issuing invoices, and managing plan changes or cancellations.
  • Customer Support: Responding to support tickets, troubleshooting technical issues, and diagnosing errors.
  • Security & Fraud Prevention: Monitoring for unauthorized access, detecting abuse, enforcing our Acceptable Use Policy, and protecting the integrity of the platform.
  • Product Improvement: Analyzing aggregate, de-identified usage patterns to improve performance, reliability, and feature design. We do not use individual identifiable data for model training without your explicit consent.
  • Legal Compliance: Fulfilling obligations under applicable US federal and state law, and responding to lawful requests from public authorities.
  • Communications: Sending transactional emails (password resets, billing receipts, security alerts) and, where you have consented or we have a legitimate interest, product updates and feature announcements. You may opt out of marketing communications at any time.

We do not sell, rent, or exchange your personal data for monetary or other consideration. We do not use your data to serve third-party targeted advertising.

4Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, we process your personal data under the following lawful bases pursuant to Article 6 of the GDPR:

  • Performance of a Contract (Art. 6(1)(b)): Processing necessary to deliver the Service you have subscribed to — account creation, attendance tracking, time logging, billing, and support.
  • Legitimate Interests (Art. 6(1)(f)): Security monitoring, fraud prevention, abuse detection, and aggregate product analytics where these interests are not overridden by your rights and freedoms.
  • Legal Obligation (Art. 6(1)(c)): Compliance with US and EU/UK legal requirements, including responding to lawful authority requests.
  • Consent (Art. 6(1)(a)): Optional marketing communications and non-essential cookies, where we request your prior consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.

For processing of employee attendance data by organizations, we act as a data processor under Article 28 GDPR. The relevant lawful basis (typically Art. 6(1)(b) or 6(1)(c)) is determined by the organization as data controller.

5Data Sharing & Disclosure

We do not sell your personal data. We share personal data only in the following circumstances:

A. Service Providers (Sub-processors)

We engage trusted third-party service providers who process data solely on our behalf under written data processing agreements:

  • Cloud Hosting: Amazon Web Services (AWS) — servers located in the United States.
  • Payment Processing: Stripe, Inc. — handles payment card data under PCI-DSS compliance.
  • Transactional Email: SendGrid / Twilio — for system-generated emails.
  • Error Monitoring: Sentry — anonymized error and performance diagnostics.
  • AI Language Models (optional assistant only): Anthropic, Google (Gemini), OpenAI — receive pseudonymised, identifier-free content as described in section 5F.

An up-to-date list of sub-processors is available upon written request to privacy@soft desk.io.

B. Your Organization

If your account was provisioned by an employer or organization, authorized administrators within that organization can access your profile, attendance records, time entries, and project activity as permitted by their plan and role configuration.

C. Legal Requirements & Safety

We may disclose personal data when required by applicable law, regulation, judicial process, or governmental authority (including US federal and state law), or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Soft Desk, Inc., our users, or the public.

D. Business Transfers

In the event of a merger, acquisition, asset sale, or reorganization, personal data may be transferred to the successor entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

E. With Your Consent

We may share your data with third parties when you explicitly direct us to do so or when you have given us your prior consent.

F. AI Assistant and Language Model Providers

Soft Desk includes an optional AI assistant (chat and voice). When you use it, the request is processed by a third-party language model provider chosen by you or by the platform: Anthropic, Google (Gemini) or OpenAI. These providers act as processors under their respective API data-processing terms and do not use your content to train their models.

No identifying personal data is sent to these providers. Before any request leaves our servers, a privacy layer:

  • Removes identifiers. Email addresses, phone numbers, postal addresses, usernames, profile photos, bank and payment details are stripped from every piece of data and redacted from free text, including from the message you type.
  • Pseudonymises people and clients. Every person and client is replaced by a neutral code (for example, a person becomes "P12"). The provider only ever sees the code. Real names are restored on our servers before a reply is shown or spoken to you.
  • Never sends your mailbox. The assistant has no access to your connected email accounts. Email content, subjects and senders are never included in a request to a language model provider.
  • Sends only the work content you ask about. To answer, the assistant may send the text of the tasks, notes, projects, invoice line items, calendar event titles or documents you ask it to work with, with names inside that text replaced by codes as above. Please avoid placing sensitive personal data of others in free-text fields if you do not want it processed by the assistant.

If you bring your own API key for a provider, requests are sent under your own agreement with that provider, with the same privacy layer applied. You can stop using the assistant at any time; doing so ends all processing by language model providers for your account.

6International Data Transfers

Soft Desk is headquartered and primarily operates in the United States. If you are located outside the United States, your personal data will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on the following transfer mechanisms as approved under GDPR Chapter V:

  • Standard Contractual Clauses (SCCs): The European Commission's 2021 standard contractual clauses (for controller-to-processor and processor-to-processor transfers) are incorporated into our Data Processing Agreement and sub-processor agreements.
  • UK International Data Transfer Agreement (IDTA): For transfers from the UK we rely on the UK IDTA or the UK Addendum to the EU SCCs.

For users in other jurisdictions, we apply appropriate contractual or organizational safeguards consistent with the laws of those countries. To receive a copy of the relevant transfer safeguards, contact privacy@soft desk.io.

7Data Retention

We retain personal data for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.

  • Active Accounts: Account data, workforce records, and time entries are retained for the duration of your subscription and for up to 90 days after account closure, to allow for reinstatement or data export.
  • Billing Records: Transaction records, invoices, and financial data are retained for 7 years in compliance with US Internal Revenue Service (IRS) regulations and applicable state tax law.
  • Security Logs: Access and security event logs are retained for 12 months for fraud detection and incident response purposes.
  • Backup Data: Encrypted backups may persist for up to 30 days after deletion before being permanently purged from our systems.
  • Legal Hold: Where personal data is subject to a legal hold, dispute, regulatory inquiry, or court order, we will retain the data until such matter is fully resolved.

After the applicable retention period, data is securely deleted or irreversibly anonymized. You may request earlier deletion subject to our legal obligations; see Section 9 for your rights.

8Security

We implement industry-standard technical and organizational security measures designed to protect your personal data against unauthorized access, disclosure, alteration, or destruction:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
  • Encryption at Rest: Databases containing personal data are encrypted at rest using AES-256.
  • Password Storage: Passwords are hashed using bcrypt with a unique salt; we never store plaintext passwords.
  • Access Controls: Internal access to production systems is restricted on a least-privilege basis, enforced by multi-factor authentication (MFA) and role-based access control (RBAC).
  • Vulnerability Management: We conduct regular security assessments, dependency audits, and penetration tests. Critical patches are applied within 72 hours of discovery.
  • Incident Response: We maintain a documented incident response plan. In the event of a personal data breach that triggers mandatory notification under applicable law (including GDPR Art. 33/34 and applicable US state breach notification laws), we will notify affected parties and relevant supervisory authorities within the legally required timeframes.

No security system is impenetrable. We encourage you to use strong, unique passwords, enable any available multi-factor authentication, and notify us immediately at security@soft desk.io if you suspect unauthorized account activity.

9Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, submit a verified request to privacy@soft desk.io. We will respond within the timeframe required by applicable law (generally 30–45 days).

A. Rights Under GDPR (EEA, UK & Switzerland)

  • Right of Access (Art. 15): Obtain a copy of the personal data we hold about you and information about how we process it.
  • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your personal data where we no longer have a lawful basis to retain it.
  • Right to Restriction of Processing (Art. 18): Ask us to limit how we process your data in certain circumstances (e.g., while accuracy is contested).
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV) and transmit it to another controller.
  • Right to Object (Art. 21): Object to processing based on legitimate interests or for direct marketing purposes at any time.
  • Rights Related to Automated Decision-Making (Art. 22): We do not make solely automated decisions that produce significant legal effects. If we ever do, you have the right to human review.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local supervisory authority (e.g., the Data Protection Authority in your EU member state, the ICO in the UK, or the FDPIC in Switzerland).

B. Rights Under California Privacy Law (CCPA / CPRA)

California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the sources, purposes, and third parties with whom we share it.
  • Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising. No opt-out is required, but we provide this disclosure for transparency.
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond those permitted by the CPRA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA/CPRA rights.

To submit a verifiable consumer request, email privacy@soft desk.io with the subject line "California Privacy Request." We may need to verify your identity before processing your request.

C. General Rights (All Users)

  • You may update your account information at any time via your account settings.
  • You may request an export of your time entries and attendance data at any time.
  • You may unsubscribe from marketing emails by clicking "Unsubscribe" in any marketing email or contacting us directly.
  • Organization administrators may manage employee data access, roles, and deletion through the admin console.

10Cookies & Tracking Technologies

We use cookies and similar technologies (local storage, session tokens) to operate the Service, remember your preferences, and maintain your authenticated session.

  • Strictly Necessary Cookies: Required for authentication sessions, CSRF protection, and core platform functionality. These cannot be disabled without breaking the Service.
  • Functional Cookies: Remember your language preferences, dashboard layout settings, and theme choices.
  • Analytics Cookies: Aggregate, anonymized data about feature usage and page performance (e.g., via a self-hosted analytics tool). No third-party behavioral tracking is used.

We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies for marketing purposes.

Where required by law (e.g., EU ePrivacy Directive, UK PECR), we obtain your consent before placing non-essential cookies. You may withdraw consent or manage cookie preferences at any time via your browser settings or our in-app preference center.

11Children's Privacy

The Service is intended for use by businesses and professionals and is not directed to children under the age of 13 (or, where applicable under local law, under the age of 16 for EU residents under the GDPR). We do not knowingly collect personal data from individuals under these ages.

In compliance with the Children's Online Privacy Protection Act (COPPA), if we become aware that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will take prompt steps to delete that information from our systems.

If you believe we have collected information from a child under 13, please contact us immediately at privacy@soft desk.io.

Organization administrators are responsible for ensuring that any employee accounts created in their workspace comply with applicable minimum age requirements in their jurisdiction.

12Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page.
  • Display a notice within the platform (in-app banner or dashboard notification) at least 30 days before the changes take effect for material changes.
  • Send an email notification to registered account holders for significant changes that affect your rights.

Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the updated terms. If you do not agree with any changes, you may close your account before the effective date.

We encourage you to review this Policy periodically. Previous versions are available upon request from privacy@soft desk.io.

13Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:

  • Privacy Inquiries & Rights Requests: privacy@soft desk.io
  • Security Incidents: security@soft desk.io
  • Legal & Compliance: legal@soft desk.io
  • Mailing Address: Soft Desk, Inc. — Attn: Privacy Team, [COMPANY_ADDRESS], Wilmington, Delaware 19801, United States

For EU/EEA data subjects who wish to contact our EU Representative or escalate a complaint to a supervisory authority: we will appoint an EU Representative pursuant to Art. 27 GDPR prior to processing EU personal data at scale. Contact details will be published here upon appointment.

We are committed to working with you to resolve any privacy concerns. If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

14Google User Data (Gmail, Calendar, Drive, Contacts)

Soft Desk lets you connect one or more Google accounts so that you can read and send email, see your meetings, and open your files inside the app. Connecting a Google account is optional: every Soft Desk feature that does not involve your Google data works without it. This section explains exactly what we request from Google, why, and what happens to that data. It applies in addition to the rest of this Policy.

14.1 What we request and why

When you connect a Google account we ask Google for permission, through Google's own sign-in screen, to use the following (each permission is called a "scope"):

  • Basic profile (openid, email): your email address, so the app can label the connected account and tell your accounts apart.
  • Gmail (https://mail.google.com/): to show your mailbox inside Soft Desk (inbox, labels, threads, attachments, drafts), to send and reply to email from the app, to move, label, archive and delete messages, and to detect replies to invoices you sent. This is the full Gmail scope because the app offers complete mailbox management, including permanent deletion, when you ask for it.
  • Google Calendar (calendar.events): to list your upcoming meetings in the Meetings and Today pages, open the meeting link, and let the assistant tell you what is on your day. Only your primary calendar is read.
  • Google Drive (drive): to list, open, upload, share, move and delete files in the Documents area, and to attach Drive files where the app supports it.
  • Contacts and directory (contacts.readonly, contacts.other.readonly, directory.readonly): to show names and avatars for the people in your email threads and meeting invitations, and to suggest recipients when you compose.

You can connect only the products you want. Each Google product (Gmail, Calendar, Drive) is a separate connection with its own consent screen.

14.2 How we use Google user data

Google user data is used only to provide the features you see: displaying your mail, calendar events, files and contact names to you, and carrying out the actions you take in the app (sending an email, creating an event link, uploading a file). We do not use Google user data for advertising, we do not sell it, we do not use it to build profiles of you, and we do not use it to develop, improve or train any machine-learning or artificial-intelligence model, whether ours or a third party's.

AI assistant: the optional assistant (section 5F) has no access to your mailbox, files or contacts. It cannot read, summarise or send email, and no email content, attachment or Drive file is ever sent to an AI provider. The only Google-derived data the assistant can see is the list of your calendar meetings for a day (titles and times), and it is pseudonymised before it reaches a model, as described in section 5F.

14.3 Where the data lives and for how long

  • Access and refresh tokens that Google issues for your account are stored on our servers, encrypted at rest with a key that is not stored alongside the data. They are used solely to call Google on your behalf.
  • Email, calendar and Drive content is not copied into our database. It is fetched from Google when you open a page and shown to you; short-lived server caches (minutes) and your browser's local cache are used only to make the app fast.
  • Attachments you add to an outgoing email are held in our storage only until the message has been sent or the draft is discarded, then deleted.
  • Invoice read-receipt detection stores, per invoice, the timestamp of the first reply found in your mailbox, never the reply's content.
  • Server logs record request metadata (route, status, timing, your user id), never the content of your mail, files or events; they are kept for 30 days.

14.4 Sharing

We share Google user data only with the infrastructure providers that run the Service (hosting and database, storage for outgoing attachments) under contracts that restrict them to processing it for us, and only as needed to deliver the feature you are using. We do not share it with any other third party, and we do not transfer it to any other application. We may disclose it if required by law, as described in section 5.

14.5 Revoking access and deletion

  • In Soft Desk: open Connectors and click Disconnect on the account. We ask Google to revoke the token and permanently delete the stored tokens immediately. Any attachments still staged for sending are deleted at the same time.
  • In your Google Account: you can remove Soft Desk's access at any time at myaccount.google.com/permissions. The app will then show the account as needing to be reconnected.
  • Account deletion: deleting your Soft Desk account deletes every connected Google account's tokens and all data derived from them.

14.6 Google API Services User Data Policy

Soft Desk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we only use Google user data to provide or improve user-facing features that are prominent in the app, we do not transfer it except as needed to provide those features, for security, or to comply with law, we do not use it for advertising, and humans do not read it except with your explicit consent, for security purposes, to comply with law, or after it has been aggregated and anonymised.