Deskfinch Privacy Policy
Last updated: 8 October 2026
Who is responsible
Deskfinch is a customer support service operated by Premex AB, company registration 559253-4134, Jerikovägen 12, 141 32 Huddinge, Sweden. This policy covers deskfinch.com, the Deskfinch dashboard and our hosted support interfaces.
Premex AB is the controller for our account administration, service security, communications and support provided to you as our customer. When a business uses Deskfinch to support its own customers, that business determines the purpose of its support conversations and is normally the controller; we process those conversations on its behalf. Its privacy notice applies to its support relationship with you. A processing agreement, where required, governs that processing; this policy does not replace it.
Contact us through the Deskfinch support form or at contact@premex.se. Privacy requests can also be sent to our data protection contact at dpo@premex.se.
Information we handle
- Account information: email address, user ID, profile details supplied by your sign-in provider, verification status, sign-in records, accepted terms version and newsletter preference. Email/password credentials are handled by Firebase Authentication. Optional Google or GitHub sign-in supplies identity information for your account. GitHub authorisation can also request organisation and repository permissions shown on GitHub's authorisation screen.
- Workspace configuration: product settings, website details, integration credentials, connected workspace or repository identifiers, and mappings between customers and conversations.
- Support information: the name, email, subject, message, replies and identifiers supplied through a form, chat or integration. Please avoid sending passwords, access tokens or unnecessary sensitive information in support messages.
- Operational information: request and conversation identifiers, errors, security records and technical connection information. Network delivery, authentication providers and hosting logs can involve IP addresses and browser information.
- Browser storage: session and customer identifiers that support sign-in and access to conversations. See our Cookie Policy.
We obtain information from you, your sign-in provider, your organisation's administrators and the support backends connected to Deskfinch.
Why we use information
Where we act as controller, our purposes and GDPR legal bases are:
| Purpose | Legal basis |
|---|---|
| Create your account, provide the service and answer your service requests | Performance of our contract with you, or steps you request before entering one |
| Administer an organisation's account and communicate with its representatives | Our legitimate interest in providing and managing the organisation's service |
| Protect accounts, prevent abuse, diagnose faults and maintain service reliability | Our legitimate interest in operating a secure, reliable service |
| Meet legal obligations and respond to lawful requests | Compliance with an applicable legal obligation |
| Establish, exercise or defend legal claims | Our legitimate interest in protecting legal rights |
| Send optional newsletters or product announcements | Your consent, which you can withdraw without affecting your account |
Information needed to authenticate an account or deliver a support request is necessary for that function. You can browse public information without creating an account. Newsletter sign-up is optional. We do not sell personal information or use support conversations for advertising.
When processing a customer's support conversations on its behalf, we follow its documented instructions and the applicable processing agreement; the customer is responsible for establishing the legal basis for its support activity.
Where conversations and account data live
The Deskfinch application and service database run on infrastructure operated by Premex. The database holds account records, configuration, integration credentials and conversation mappings.
You choose where the original conversation history is stored: your Slack workspace, GitHub repository or a backend you develop and connect through the Support SPI. Deskfinch reads and transmits messages to provide the hosted interface and temporarily buffers live delivery events, which can include message content. Choosing a custom backend does not mean messages bypass Deskfinch.
Firebase Authentication, provided by Google, handles dashboard identity and sign-in. Optional Google and GitHub sign-in services also process information under their own terms. Connected Slack, GitHub and custom backends receive the information required for the integration you select. Their access controls and retention settings affect the original conversations.
For support that you send directly to Deskfinch, we use Deskfinch with our own connected Slack workspace to manage and answer your request.
Anonymous usage counts
We count fixed categories such as page views, demo steps and Start free clicks to understand which features are useful. These application events contain an event category, a fixed source or backend category where relevant, and a timestamp. They contain no visitor ID, cookies, IP address, referrer, message text or form contents. We do not combine these counts into individual browsing profiles.
We skip these events when your browser sends Do Not Track or Global Privacy Control. This does not disable storage required for sign-in or support. Technical request handling and security logs are separate from these usage counts.
Who can receive information
Access is limited to the people and providers involved in operating, supporting and protecting the service, and to the connected backends selected by the customer. An organisation's administrators and support team may access its support data through those systems.
We may disclose information when required by law or necessary to establish, exercise or defend legal claims. If the service changes ownership, relevant information may be transferred with the service, subject to applicable law and appropriate notice. We do not make support conversations public as part of operating Deskfinch.
International processing
Our use of Firebase Authentication and a customer's choice of Google, GitHub, Slack or another backend can involve processing outside the EU/EEA, including in the United States. Deskfinch is not an EU-only data-location commitment.
Google describes its transfer arrangements, including the EU–US Data Privacy Framework, in its Firebase privacy information. Other providers' arrangements depend on the service and customer configuration. Where we are responsible for a restricted transfer, an applicable GDPR transfer mechanism is required, such as an adequacy decision or standard contractual clauses with any necessary supplementary measures. Contact us for information about the providers and safeguards relevant to your setup, or before connecting a service with specific location requirements.
How long information is kept
- Account and configuration records are kept while needed to provide and administer the account. On an account-closure or deletion request, we assess and remove information no longer needed, subject to legal obligations, security needs and the handling of legal claims.
- Original support conversations follow the retention settings of the connected backend. Closing a Deskfinch account does not automatically delete that history. The customer controls deletion in its backend; contact that business about its support records.
- Live delivery events expire after one hour and are removed by periodic database maintenance. This is the live buffer's retention period, not a promise that every backup copy or backend conversation is deleted within one hour.
- Anonymous usage events are retained for up to 90 days in the live event table and then removed by periodic maintenance.
- Temporary MCP authorisation state expires after ten minutes; authorisation codes expire after five minutes.
- Our own support requests and security records are kept for as long as needed to resolve the matter, maintain security and meet applicable legal requirements.
- Recovery copies and backups can remain after deletion from the live system. They are restricted to recovery and necessary operational or legal purposes; deletion requests are considered when handling retained copies and restoring data.
Firebase maintains its own authentication retention and deletion process, described in its privacy information. Contact us to request account deletion or details of the retention applicable to your information.
Your choices and rights
Depending on applicable data protection law and the circumstances, you may request access, correction, deletion, restriction or portability of your personal data. You may object to processing based on legitimate interests. You may withdraw newsletter consent at any time through your account preference or by contacting us; this does not affect processing before withdrawal.
Send requests through our support form or to dpo@premex.se. We may need proportionate information to verify your identity. Where GDPR applies, we normally respond within one month, with any permitted extension explained to you.
For a conversation with another business using Deskfinch, contact that business first. We assist it with requests concerning information processed on its behalf.
You can complain to the Swedish Authority for Privacy Protection, IMY, or another competent supervisory authority. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.
Children and updates
Deskfinch's dashboard is intended for people managing a service or business, not for children. Customers are responsible for the audience of their own support interfaces and for any additional requirements concerning children.
We update this notice when our practices change, show the date above and provide additional notice of material changes where required. Related documents: Terms & Conditions and Cookie Policy.