Skip to content
Crystal Desk
Legal

GDPR Compliance

Last updated: January 1, 2026

Crystal Desk (“we,” “us,” or “our”) is committed to protecting the personal data of everyone who uses our platform — whether you’re a customer, a member of a customer’s team, or a visitor to our website. This page explains how we collect, use, store, and protect personal data in line with the General Data Protection Regulation (GDPR), and what rights are available to you as a data subject.

This page is a plain-English summary of our data protection practices. It works alongside our Privacy Policy and Terms of Service, which govern the full legal relationship between you and Crystal Desk.

Introduction

GDPR applies to any organization that processes the personal data of individuals in the European Union, regardless of where that organization is based. While Crystal Desk is headquartered in India, we apply GDPR-aligned practices across our platform for every customer and user, not just those in the EU — we believe good data protection shouldn’t depend on where you happen to be.

Data Controller

For data submitted directly to Crystal Desk (account information, billing details, support requests), Crystal Desk acts as the data controller. For content your organization uploads into the platform — tickets, scripts, media files, and similar workflow data — your organization is the data controller, and Crystal Desk acts as a data processor on your behalf, under the terms of our Data Processing Addendum (available on request).

Data We Collect

  • Account data — name, work email, role, and organization, collected when you or your admin creates a user account.
  • Workflow content — tickets, custom field values, comments, and uploaded media, submitted by your team as part of using the platform.
  • Usage data — pages visited, features used, and general interaction patterns, used to improve the product and diagnose issues.
  • Technical data — IP address, browser type, and device information, collected automatically for security and performance purposes.
  • Billing data — plan, billing address, and payment method details, processed through our payment providers (we do not store full card numbers ourselves).

Depending on the data and context, we rely on one of the following legal bases:

  • Contract performance — processing needed to provide the service you or your organization signed up for.
  • Legitimate interest — improving the platform, preventing fraud, and maintaining security, balanced against your rights.
  • Consent — for optional communications like product newsletters, which you can withdraw at any time.
  • Legal obligation— where we’re required to retain or disclose data by applicable law.

How We Use Your Data

We use personal data to operate the platform (authentication, assignment, notifications), provide support, send necessary service communications, improve product features, and meet legal and security obligations. We do not sell personal data, and we do not use customer workflow content to train AI models outside of the specific AI Agent features you choose to enable within your own account.

Data Retention

Account and workflow data is retained for as long as your subscription is active. If you cancel, your data is retained for 30 days to allow export, after which it is permanently deleted from production systems. Billing records are retained longer where required by tax and accounting law.

International Data Transfers

Crystal Desk is hosted on AWS infrastructure in the ap-south-1 (Mumbai) region by default. Enterprise customers may configure alternative storage locations (see Storage Providers). Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards with our sub-processors.

Your Rights Under GDPR

If you are located in the EU (or wherever GDPR-equivalent rights apply), you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data, subject to legal retention requirements.
  • Restriction — limit how we process your data in certain circumstances.
  • Portability — receive your data in a structured, commonly-used format.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — for any processing based on consent, at any time.
  • Lodge a complaint — with your local data protection supervisory authority.

To exercise any of these rights, contact us at [email protected]. If your organization is the data controller for workflow content, we’ll direct requests about that content to your organization’s admin where appropriate.

Sub-Processors & Third Parties

We share data with a limited set of sub-processors, strictly to operate the platform:

  • Amazon Web Services — infrastructure hosting and default media storage.
  • Amazon SES — transactional email delivery.
  • WhatsApp Business — optional notification delivery, where enabled.
  • ElevenLabs — AI voice generation, only when a workflow is configured to use it.
  • Anthropic (Claude) — AI Agent features and the Deck Analyzer.

Each sub-processor is bound by a data processing agreement requiring GDPR-equivalent protections.

Data Security

We use AES-256 encryption at rest and TLS in transit, role-based access controls, and row-level tenant isolation to keep customer data secure and separated. See Pricing for details on which security features are available at each plan tier.

Cookies

Our website uses a minimal set of cookies for authentication, theme preference, and basic analytics. See our Cookie Policy for the full breakdown and how to manage your preferences.

Children’s Data

Crystal Desk is a business-to-business product intended for use by working professionals. We do not knowingly collect personal data from anyone under the age of 16.

Changes to This Policy

We may update this page as our practices or applicable law evolve. Material changes will be communicated to account admins by email. The “last updated” date at the top of this page always reflects the most recent revision.

Contact & Complaints

For any question about this policy or to exercise your data rights, reach out to our data protection team at [email protected] or via our Contact page. If you believe we haven’t addressed your concern adequately, you have the right to lodge a complaint with your local data protection supervisory authority.