Privacy Policy
1. Scope of this policy
This policy explains how eSolutions Softhouse Limited ("we", "us", "our") collects, uses, shares and protects personal data in connection with the ThreadDesk website at threaddesk.chat, the ThreadDesk application at app.threaddesk.chat, and the ThreadDesk chat widget that our customers embed on their own websites (together, the "Services").
It does not apply to third-party websites we link to. Those sites have their own policies and we are not responsible for them.
2. Our two roles: controller and processor
ThreadDesk handles personal data in two distinct capacities, and your rights differ depending on which applies.
- As a controller. When you visit our website, create a ThreadDesk account, contact us, or pay for a subscription, we decide why and how your personal data is processed. This policy governs that processing.
- As a processor. When a ThreadDesk customer embeds our widget on their site, the messages, names and email addresses that their visitors submit belong to that customer. We process that data only on the customer's documented instructions, under the Data Processing Agreement that forms part of our Terms and Conditions. The customer is the controller.
If you spoke to a company through a ThreadDesk chat widget and want your data deleted, contact that company directly. If they instruct us to act, we will. We will also pass your request on to them if you contact us instead.
3. Who is the data controller
Where we act as controller, the controller is:
eSolutions Softhouse Limited
Registered address: [REGISTERED ADDRESS]
Company registration number: [COMPANY NUMBER]
Privacy contact: [PRIVACY EMAIL]
EU Article 27 representative: [EU REPRESENTATIVE NAME AND ADDRESS — Cookietrust appoints IT Governance Europe Limited; confirm whether the same appointment covers ThreadDesk]
4. Personal data we collect
Personal data means information about an identified or identifiable person. It does not include data that has been anonymised so that the person can no longer be identified.
| Category | What it includes |
|---|---|
| Identity data | First and last name, username, job title, workspace or company name. |
| Contact data | Email address, and phone number where you choose to provide one. |
| Account data | Login credentials (passwords are stored hashed, never in plain text), account settings, plan and widget configuration. |
| Billing data | Billing name and address, VAT number, subscription and invoice history. Card details are handled by our payment provider and are never stored on our systems. |
| Conversation data | Chat messages, attachments, the AI's responses, handoff events and resolution notes. Where we act as processor, this belongs to our customer. |
| Knowledge data | Learnings and knowledge-base entries generated from resolved conversations, which may contain personal data if it appeared in the underlying conversation. |
| Technical data | IP address, browser type and version, device type, operating system, time zone and language settings. |
| Usage data | Pages visited, features used, conversation volumes and other product analytics. |
| Marketing data | Your preferences for receiving marketing from us and your communication preferences. |
We do not deliberately collect special category data (such as health, biometric, political or religious information). Please do not enter such information into a chat. If it reaches us incidentally within a conversation, we process it only as needed to provide the Services and delete it on request.
5. How we collect it
- Directly from you — when you create an account, fill in the widget's details form, email us, or subscribe to a plan.
- Automatically — through cookies and server logs as you use the Services.
- From our customers — where a customer has deployed our widget, we receive the conversation data their visitors submit.
- From third parties — our payment provider confirms transaction outcomes, and Slack provides workspace and user identifiers when you authorise the integration.
6. Legal bases for processing
Where we act as controller, we rely on one of the following:
- Performance of a contract — to create and run your account, provide the Services and take payment.
- Legitimate interests — to secure and improve the Services, prevent fraud and abuse, and market to existing business customers, provided your interests and rights do not override ours.
- Consent — for non-essential cookies and for marketing to you where consent is required. You can withdraw consent at any time.
- Legal obligation — to meet tax, accounting and other statutory requirements.
7. How we use personal data
- To provide, operate and maintain the Services, including routing conversations to Slack.
- To create and administer your account and process payments.
- To provide support and respond to your enquiries.
- To monitor, secure and improve the Services and diagnose faults.
- To send service messages about changes, outages, billing or security.
- To send marketing where permitted, with an opt-out in every message.
- To comply with legal obligations and enforce our terms.
We do not sell personal data.
8. AI processing and Learnings
ThreadDesk uses an AI model to draft answers from a knowledge base built from previous resolved conversations.
- Conversation content is sent to our AI provider, [AI PROVIDER NAME], to generate a response.
- [CONFIRM: whether the AI provider retains prompts, for how long, and whether customer content is excluded from training their models. State it plainly here — it is the question enterprise buyers ask first.]
- When a human resolves a conversation, ThreadDesk may create a "Learning" summarising the resolution. Learnings are stored against the customer's account and reused to answer similar questions. A Learning can contain personal data if it appeared in the source conversation. Customers can review and delete Learnings at any time.
- We do not use customer conversation content to train models that serve other customers.
No decision producing legal or similarly significant effects is made about you solely by automated means. When the AI is not confident, the conversation is handed to a human.
9. Slack integration
When you connect a Slack workspace, we receive an access token plus the workspace, channel and user identifiers needed to post and read messages in the channel you nominate. Conversation content is delivered into that Slack channel, at which point Slack's own terms and privacy policy also apply to that copy of the data. Revoking the ThreadDesk app in Slack stops further delivery; it does not delete messages already posted there.
10. Cookies and similar technologies
Cookies are small text files placed on your device. We use them as follows:
| Cookie | Purpose | Duration |
|---|---|---|
chatbotDisclaimer | Records that you have acknowledged the chat disclaimer, so it is not shown again. | 365 days |
| Session and authentication cookies | Keep you signed in to the ThreadDesk application and protect against request forgery. | Session, or until sign-out |
| [ANALYTICS COOKIES, IF ANY] | [PURPOSE] | [DURATION] |
Essential cookies are required for the Services to function. Any non-essential cookies are set only with your consent. Most browsers let you block or delete cookies through their settings; blocking essential cookies may stop parts of the Services working.
We do not respond to "Do Not Track" browser signals, as no common standard for them has been agreed.
11. Sub-processors and disclosure
We share personal data with the following categories of recipient, each under a written contract that restricts them to processing it on our instructions:
| Recipient | Purpose | Location |
|---|---|---|
| Cloudflare | Website and widget delivery, CDN, DDoS protection | [REGION] |
| Slack Technologies | Delivering conversations into your Slack workspace | [REGION] |
| [AI PROVIDER] | Generating AI responses | [REGION] |
| [HOSTING PROVIDER] | Application and database hosting | [REGION] |
| [PAYMENT PROVIDER] | Subscription billing and payment processing | [REGION] |
| [EMAIL PROVIDER] | Transactional and service email | [REGION] |
We may also disclose personal data to professional advisers, to a buyer in connection with a sale or reorganisation of our business, or where required by law, a court order or a regulator.
12. International transfers
Some of the recipients above are located outside the UK and the European Economic Area. Where personal data is transferred to such a country, we rely on [ADEQUACY DECISION / STANDARD CONTRACTUAL CLAUSES / UK INTERNATIONAL DATA TRANSFER ADDENDUM — specify which applies to each recipient] to ensure an equivalent level of protection.
13. Data retention
We keep personal data only for as long as we need it for the purposes set out in this policy.
- Chat history — retained for 24 hours on the Free plan. On paid plans: [RETENTION PERIOD FOR PRO AND BUSINESS].
- Account data — kept while your account is active, then deleted within [PERIOD] of closure.
- Billing records — retained for [PERIOD] to meet tax and accounting obligations.
- Learnings — retained until deleted by the customer or the account is closed.
When determining retention periods we consider the volume, nature and sensitivity of the data, the potential harm from unauthorised disclosure, the purposes for which we process it, and applicable legal requirements.
14. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit using TLS, hashed password storage, access controls limiting personal data to staff who need it, and logging of administrative access. No system is completely secure, but we maintain procedures to deal with any suspected breach and will notify you and the relevant regulator where the law requires it.
15. Your data protection rights
Subject to conditions and exemptions in applicable law, you have the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request erasure of your personal data;
- object to processing based on our legitimate interests;
- request restriction of processing;
- request transfer of your data to you or another provider;
- withdraw consent at any time, where we rely on consent.
To exercise a right, contact [PRIVACY EMAIL]. We will respond within one month; if your request is complex we may extend this and will tell you if so. There is no fee unless the request is manifestly unfounded or excessive. We may ask you to verify your identity first.
Where we act as processor for one of our customers, we will forward your request to that customer, who is responsible for answering it.
16. Age of users
The Services are intended for business use and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
17. Complaints
If you are unhappy with how we have handled your personal data, please contact us first so we can try to resolve it. You also have the right to complain to a data protection supervisory authority — in particular [LEAD SUPERVISORY AUTHORITY], or the authority in your country of residence or work.
18. Changes to this policy
We may update this policy from time to time. The effective date at the top shows when it was last revised. If we make a material change, we will notify account holders by email or through the Services before it takes effect.
19. Contact us
eSolutions Softhouse Limited — ThreadDesk
General enquiries: [email protected]
Privacy enquiries: [PRIVACY EMAIL]
Postal address: [REGISTERED ADDRESS]