ChaosDesk ChaosDesk

Datenschutzerklärung

Last updated: February 26, 2026

1. Introduction

ChaosDesk ("we", "us", or "our") operates the chaosdesk.eu platform, an embeddable helpdesk service for SaaS businesses. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.

ChaosDesk is operated from the Netherlands and is subject to Dutch and European Union data protection laws, including the General Data Protection Regulation (GDPR).

2. Data We Collect

Account Information

  • Name, email address, and password
  • Company name and address
  • Billing information (when payment features are active)

Support Ticket Data

  • Ticket content, descriptions, and replies
  • File attachments uploaded to tickets
  • Customer names and email addresses submitted via the widget or API
  • Ticket categories, priorities, and status information

Technical Data

  • IP address and browser type
  • Usage data and access logs
  • API usage data and webhook activity

3. How We Use Your Data

We process your personal data for the following purposes:

  • Providing helpdesk and ticket management services
  • Delivering the embeddable support widget on your websites
  • Processing API requests and webhook notifications
  • Managing your account, teams, and sites
  • Processing invoices and subscription billing
  • Improving our platform and developing new features
  • Communicating service updates and changes

4. Legal Basis for Processing

We process your data under the following legal bases (GDPR Article 6):

  • Contract performance — processing necessary to provide our helpdesk services
  • Legal obligation — record-keeping requirements under Dutch and EU law
  • Legitimate interest — platform improvement, security, and fraud prevention
  • Consent — for optional marketing communications

5. Data Sharing

We may share your data with:

  • Payment processors — billing data necessary to process your subscription payments
  • Infrastructure providers — data stored on secure EU-based servers
  • Email delivery services — for transactional emails and ticket notifications

We do not sell your personal data to third parties.

6. Data Retention

We retain your data for as long as your account is active. After account closure, data is retained for the legally required period (generally 7 years for financial records under Dutch law) and then securely deleted or anonymised.

7. Data Security

We implement appropriate technical and organisational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, and regular security reviews.

8. Your Rights

Under the GDPR, you have the right to:

  • Access your personal data (Article 15)
  • Rectify inaccurate data (Article 16)
  • Erase your data, subject to legal retention requirements (Article 17)
  • Restrict processing (Article 18)
  • Data portability (Article 20)
  • Object to processing (Article 21)
  • Withdraw consent at any time (Article 7)

To exercise any of these rights, contact us at [email protected].

9. Cookies

We use cookies to operate our platform. For detailed information, please see our Cookie Policy.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform.

11. Contact

For questions about this Privacy Policy or our data practices:

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.