What this means in plain language.
We process your data per Indian DPDP Act 2023. We don't sell it. Export or deletion requests: [email protected] or /dsr-request.
Access
Request a copy of all personal data we hold about you, in a readable format with the source and purpose for each category.
Rectify
Correct anything inaccurate, incomplete or out of date. We propagate corrections to active sub-processors.
Erase
Have your data deleted, subject only to legal retention obligations and active contractual disputes.
Port
Receive your data in a structured, machine-readable format you can import into another service.
Restrict
Pause our processing while a query is open — we will hold the data without using it.
Object
Object to specific processing — including automated decisions and direct marketing — at any time.
TL;DR — What this means in plain language.#
- India-first; multi-country posture. DPDP Act 2023 is enforced for every Indian tenant by default. GDPR (EU/UK), HIPAA (US healthcare) are available now via signed DPA / BAA on request. UAE PDPL and Singapore PDPA arrive in 2027.
- We collect only what we need to run Wendesk for you — your account identity, what your team uploads, billing metadata, and basic product telemetry.
- We are a Controller for visitor data and account-holder data; we are a Processor for the Customer Data tenants upload to their workspaces.
- We never sell or rent personal data. We share it only with vetted sub-processors under signed DPAs; you receive 30 days advance notice via in-app banner and email; tenant right to object and terminate applies before any new sub-processor is engaged.
- You own it. Access, correct, delete, port, withdraw consent, or object — any time. We respond within 7 working days; legal cap is 30 days standard; 7 days for India DPDP critical paths.
- Encryption everywhere. AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit. Default region AWS Mumbai (ap-south-1).
- Real humans answer. Data Protection Officer and Grievance Officer at [email protected] — Acknowledged within 24 hours, resolved within 30 days (per DPDP §8(9) and §13).
1. Who we are#
This Privacy Policy is published by Fourteen Cloud Pvt Ltd, a private limited company incorporated in India with its registered office in Jaipur, Rajasthan. We trade under the brand name "Wendesk" and use "we", "us", and "our" throughout this document to refer to Fourteen Cloud Pvt Ltd. Wendesk is a multi-tenant Software-as-a-Service customer relationship management platform that bundles WhatsApp messaging, content publishing, voice agents, payments, and an integration marketplace for Indian and global small-to-medium businesses.
This policy applies to all data we handle through www.wendesk.com, app.wendesk.com, branded tenant subdomains, the marketplace at www.wendesk.com/m/*, our WhatsApp Business surface, the MCP server at mcp.wendesk.com, the platform-admin surface at wd-admin.wendesk.com, and any sales, support, or marketing communications we send. It explains what we collect, why we collect it, how we share it, how long we keep it, and the rights you have over it.
We act in two distinct legal capacities depending on the data in question. For visitors to our marketing site, prospects, candidates, and the people who hold accounts directly with us (workspace owners, billing contacts, individual signups), we are the Controller (the "Data Fiduciary" under India's Digital Personal Data Protection Act 2023). For the data tenants upload to their workspaces about their own contacts, leads, customers, and team members ("Customer Data"), we act as a Processor (or "Data Processor" under DPDP) on the tenant's documented instructions, under a Data Processing Addendum that forms part of our subscription agreement.
This policy does not cover websites, marketplaces, or storefronts our tenants operate using Wendesk. When you interact with one of those experiences as an end-customer, the tenant is the Controller and you should consult that tenant's own privacy notice. We will help you reach the right tenant on request.
2. Data we collect#
We try hard to collect only what we genuinely need. The categories below describe everything we may process across the lifecycle of your relationship with Wendesk, grouped by source.
-
Account data — full name, work email, mobile number, business name, GSTIN or other tax ID where applicable, role inside your organisation, password hash (where the legacy email/password method is still in use), MFA secrets, OTP delivery records, and SSO claims (Google, Microsoft, or other identity provider profile fields you authorise).
-
Customer Data uploaded by tenants — leads, contacts, accounts, deals, activities, conversations, files, and custom fields a tenant or its users add to a workspace. We process this only on the tenant's instructions; the tenant is the Controller.
-
Usage and product telemetry — pages and features you load, button clicks at an event level, query response times, error reports, audit-trail entries (who did what, when, from which IP), API request metadata, and BullMQ job execution records. Used to operate, secure, and improve the service.
-
Device and connection data — IP address, approximate location derived from IP, browser and OS user-agent, screen size, language, and referring URL. Captured automatically when you load any Wendesk surface.
-
Cookies and similar storage — see our separate Cookie Policy for the named-by-name list. Includes session cookies, CSRF tokens, language preference, and (with consent) analytics and marketing identifiers.
-
Communications — emails, support tickets, in-app chat threads, scheduled-call notes, recordings of training calls or demos (where you have consented), and feedback you submit through the in-app NPS or survey widgets.
-
Payment metadata — invoice number, plan, amount, currency, GST split, last-4 digits and brand of the card used, UPI handle masked, Razorpay or Stripe transaction reference, refund history. We never store full card numbers, CVV, or full bank account numbers — those are tokenised by our PCI-DSS-certified payment partners.
-
AI prompts, completions, and outputs. Two distinct posture levels apply, and the relevant level is determined by which provider key your workspace is using:
- Platform-quota AI (Wendesk-supplied keys via the quota router) — we log the prompt sent to the model, the response returned, the model used, the token count, the latency, and the cost. Prompt and completion content default to 30-day retention for quality, debugging, and abuse-prevention; tenants on Pro and above can shorten this window to 7 days.
- BYOK AI (you supply your own OpenAI / Anthropic / Google key) — we log only metadata: model used, token count, latency, cost, and a hash of the prompt for abuse-prevention. We do not record prompt content or completion content under BYOK. Your key is encrypted with the same AES-256-GCM envelope as integration credentials and is never returned by any endpoint.
In both cases, we do not use customer prompts or completions to train models without separate, written, opt-in consent. Healthcare-tenant PHI is auto-redacted before any inference call regardless of key source.
-
Voice-call data (Voice Agent solution) — call metadata (caller and called number, duration, route, provider, outcome), transcripts (where transcription is enabled), and recordings (where recording is enabled by the tenant). Healthcare tenants have stricter retention and PHI redaction.
-
Marketing-engagement data — newsletter subscription status, email open and click events (server-confirmed only — we do not embed tracking pixels by default), webinar registrations, content downloads, and event attendance.
-
Data third parties tell us — delivery receipts and message metadata from WhatsApp Business Platform and other channel providers; transaction confirmations from Razorpay, Stripe, and tax authorities; identity attestations from SSO and OAuth providers; enrichment and verification signals from compliance vendors used for anti-fraud checks.
We do not knowingly collect special-category data (health, biometric, sexual orientation, political opinion, religion). If a tenant in a regulated industry chooses to process such data inside their workspace — for example, a clinic recording diagnoses — that activity is governed by the tenant's own legal basis, sector compliance commitments, and the Data Processing Addendum we sign with them.
What each Wendesk solution actually collects
Wendesk ships seven solutions plus two sub-modules. Tenants enable only the ones they need, and each one processes a specific data shape. The table below is a precise mapping — the policy answer to "what does this feature send where?"
| Solution / surface | Data processed | Sub-processors involved |
|---|---|---|
| CRM | Contacts, leads, accounts, deals, activities, custom fields, attachments. Industry overlay fields (RERA project ID, ICD-10 hint, FSSAI licence, GST HSN, etc.). | MongoDB Atlas Mumbai |
| Pipeline (CRM sub-module) | Stage transitions, deal value, win/loss reasons, close date predictions. | MongoDB Atlas Mumbai · pgvector for similarity |
| WhatsApp Growth Hub | Inbound + outbound message bodies, attachments, delivery receipts, template approvals, customer-care window timers, opt-in records. | Meta WhatsApp Business Platform · Twilio (fallback) · MongoDB Atlas |
| AI Voice Agent (Early access) | Caller / callee numbers, call duration, route, provider, outcome, transcripts (when enabled), recordings (when enabled by tenant). Healthcare retention 6 years; default 90 days. | Tata Tele Smartflo · Jio Eva · Twilio · Plivo · Exotel · Knowlarity · MyOperator · AWS Connect · Sarvam AI (Indic STT/TTS) |
| Content Studio | Brand-voice prompts, draft posts, generated images, scheduled publish times. Logged per AI Quota Router posture above. | OpenAI / Anthropic / Google AI / AWS Bedrock / Sarvam AI |
| Social Sharing | Connected social account tokens (encrypted), scheduled posts, engagement metrics returned by each platform. | Meta · X · LinkedIn · YouTube · Instagram (per the connected platform) |
| Marketplace | Product catalog, cart, order, payment metadata, end-customer storefront browsing data, RFQ threads. | Razorpay (tokenisation) · Typesense (search) · MongoDB Atlas |
| Email Marketing (Upcoming) | Subscriber lists, segmentation rules, drip campaigns, open/click events, bounce reports. | MSG91 · AWS SES (planned) |
| App Store (system sub-module) | Per-integration credentials (encrypted with tenant DEK), connection status, sync events. 90 integrations across CRM, accounting, e-commerce, telephony, support, marketing. | Per-integration vendor (each under signed DPA) |
MCP server (mcp.wendesk.com) | Authenticated AI agent calls into tenant data via Model Context Protocol. Audit-logged per call: actor, tenant, tool, arguments, response code. | MongoDB Atlas · same per-tenant DEK |
CA Partner portal (cabal.wendesk.com) | Verified Chartered Accountants accessing tenant financial-reporting data only (invoices, GST returns, P&L) under a scoped permission set; never CRM or operational data. | PostgreSQL master + MongoDB billing namespace only |
| Admin Support impersonation (L3 acting as L4–L7) | Every L3 session logged in ImpersonationSession: actor, target tenant, target user, written reason, duration, every action taken inside the session. Surfaced to the tenant in the monthly compliance digest. | PostgreSQL master only |
| Custom domain (Pro+ tenants) | DNS configuration, SSL certificate provisioning. Wendesk does not see tenant traffic outside the platform layer; Cloudflare for SaaS handles the TLS edge. | Cloudflare for SaaS |
This list reflects what the platform actually does today and what is planned (early-access and upcoming entries marked accordingly). When a new solution or integration ships, the entry lands in this table before the feature is enabled in production.
3. How we use it#
We process personal data only for purposes that are clearly explained, lawful, and proportionate. The table below lists each purpose against its lawful basis under the Digital Personal Data Protection Act 2023 ("DPDP"), the EU and UK General Data Protection Regulations ("GDPR"), and equivalent laws in other jurisdictions where they apply.
| Purpose | What we do | Lawful basis |
|---|---|---|
| Service delivery | Create and run your workspace, authenticate users, route messages, store data, sync integrations. | Performance of contract |
| Billing and invoicing | Charge subscription fees, calculate usage overages, issue GST-compliant invoices, process refunds. | Performance of contract; legal obligation |
| Customer support | Respond to tickets, troubleshoot bugs, escort impersonation sessions when you request hands-on help. | Performance of contract; legitimate interest |
| Security and abuse prevention | Detect credential stuffing, prevent fraud, rate-limit, monitor for malicious workloads, run audit logs. | Legitimate interest; legal obligation |
| AI features (when you use them) | Run prompts through approved providers, log outputs for quality, enforce per-tenant quota. | Performance of contract; consent (for opted-in features) |
| Product analytics and improvement | Aggregate usage patterns, identify bottlenecks, prioritise roadmap items. | Legitimate interest |
| Marketing communications | Send newsletters, product updates, and event invitations to those who have opted in. | Consent; legitimate interest (for existing customer soft opt-in) |
| Legal and regulatory compliance | Respond to lawful requests, retain billing records, honour DSR requests, file statutory reports. | Legal obligation |
| Corporate transactions | Limited disclosure to advisors and acquirers under NDA in the event of a merger, acquisition, or financing. | Legitimate interest |
We do not engage in solely automated decision-making that produces legal or similarly significant effects on you without human oversight. AI features that score or rank leads are advisory only — a human user must act on them.
We do not use Customer Data — the data tenants upload — for any purpose other than delivering, supporting, and securing the service for that tenant. We do not aggregate Customer Data across tenants for benchmarks or product analytics unless every contributing tenant has separately consented in writing.
4. Sharing & sub-processors#
We share personal data only with carefully vetted sub-processors that are necessary to operate the service, and only to the minimum extent each one needs to perform its function. Every sub-processor is bound by a written Data Processing Agreement that imposes confidentiality, purpose limitation, security, audit, and breach-notification obligations no weaker than the obligations we owe to you.
The canonical, always-current list of our core sub-processors — with category, purpose, and hosting location — appears below and is also published on the dedicated sub-processors page. Additional categories (analytics, marketing, customer-support tooling, KYC, and professional advisors) are listed further down for completeness.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | Compute, RDS PostgreSQL, S3, KMS, Bedrock | AWS Mumbai (ap-south-1) |
| MongoDB Atlas | Database | Tenant business data (CRM, content, integrations) | AWS Mumbai (ap-south-1) |
| ClickHouse Cloud | Analytics database | High-volume activity logs (non-PII) | AWS Mumbai (ap-south-1) |
| Razorpay | Payments | Card tokenisation, UPI, net-banking, subscription billing | India |
| MSG91 | SMS gateway | OTP and transactional SMS | India |
| Twilio | Voice / messaging | WhatsApp Business API, voice fallback, programmable SMS | USA / Ireland (per region) |
| OpenAI | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Anthropic | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Google AI | AI inference | Gemini completions when routed via quota router | USA / Ireland |
| AWS Bedrock | AI inference | Default LLM provider for India tenants (Claude, Llama, Titan) | AWS Mumbai (ap-south-1) |
| Sarvam AI | AI inference | Indic-language LLM and TTS for vernacular features | India |
| Firebase | Authentication | Phone OTP delivery and Google OAuth for L7 marketplace customers | USA / multi-region |
| Cloudflare | CDN, DNS, WAF | DDoS mitigation, edge cache, custom-domain SSL for white-label tenants | Global edge |
| Typesense | Search | Full-text search index for marketplace and CRM (no PII indexed) | AWS Mumbai (ap-south-1) |
Beyond the 13 core sub-processors, we engage the following service classes on a need-to-know basis: Analytics and observability — self-hosted PostHog for product analytics, Sentry for error tracking, CloudWatch for logs and metrics; Marketing platforms (marketing site only) — LinkedIn Insight, Google Ads conversion API (server-side), and a transactional email vendor for newsletter delivery; Customer support tooling — our own Wendesk workspace plus a vetted help-desk provider for ticket triage; Compliance and identity verification — KYC and sanctions-screening vendors used for high-tier plan verification; Professional advisors — auditors, lawyers, and tax advisors under professional confidentiality.
We provide 30 days advance notice via in-app banner and email; tenant right to object and terminate applies before any new sub-processor is engaged for tenant data. We will work in good faith to resolve any well-founded objection, including by offering an alternative provider where commercially reasonable.
Never sold. We do not sell, rent, lease, or trade personal data for advertising, profiling, list-building, or any third-party commercial purpose. We have not done so in the last 12 months and have no plans to. The only disclosures we make outside our sub-processor chain are when we are legally compelled to (court order, regulator notice) or when you specifically direct us to (e.g., exporting your data to a tool you operate).
5. Retention#
We retain personal data only as long as we have a clear, lawful purpose to hold it. The defaults below are the maximum periods we keep each data category; tenant administrators can shorten most of them through workspace settings, and Data Subject Rights ("DSR") erasure requests override these defaults except where retention is mandated by law (for example, tax records).
| Data type | Retention | Justification |
|---|---|---|
| Active workspace data | Lifetime of subscription + 90-day grace | Service delivery and recovery from accidental cancellation |
| Account data after closure | 30 days read-only export window, then deletion within 60 further days | Recovery and contractual wind-down |
| Billing records, invoices, tax filings | 8 years | Indian Income Tax Act, Companies Act, GST statutory record-keeping |
| Security audit logs | 7 years (Pro and Enterprise) / 1 year (Free, Base, Starter, Growth) | Compliance, forensics, incident response |
| Marketing email lists | 24 months from last engagement | Legitimate interest, consent freshness |
| Encrypted backups | Rolling 35-day window | Disaster recovery |
| AI prompt and completion logs | 30 days default; configurable down to 7 days | Quality, debugging, abuse prevention |
| Voice-call recordings | 90 days default; 6 years for healthcare; deletable on demand | Service quality, regulatory compliance |
| Support tickets and chat threads | 3 years from closure | Service quality, recurring-issue analysis |
| Anonymised aggregate analytics | Indefinitely | Aggregate cannot identify individuals |
When the retention period ends, we either irreversibly delete the data or anonymise it so that re-identification is no longer practicable. Deletion runs nightly through automated jobs; backups roll out of scope on the schedule above.
For closed workspaces, the platform default is a 90-day frozen window after unsubscribe. After 90 days the workspace is hard-deleted from primary stores automatically; encrypted backups roll out within a further 35 days. During the 90-day grace window, tenants can request immediate hard-delete by written instruction to [email protected]; a self-service toggle inside the workspace dashboard is planned for 2026 H2. Data Subject Rights ("DSR") erasure requests are honoured immediately regardless of this default, except where retention is mandated by law (e.g. GST and Income Tax records per the table above).
6. Your rights at a glance#
Wherever you are based, you have meaningful rights over the personal data we process about you. Under India's Digital Personal Data Protection Act 2023 (Section 11–14), the EU and UK General Data Protection Regulations (Articles 15–22), and the California Consumer Privacy Act and its successors, the rights below are recognised. We honour them globally as a baseline — even if your local law would give you fewer.
| Right | Description |
|---|---|
| 01 — Access | Request a copy of all personal data we hold about you, in a readable format with the source and purpose for each category. |
| 02 — Rectify | Correct anything that is inaccurate, incomplete, or out of date. We will propagate corrections to active sub-processors. |
| 03 — Erase | Have your data deleted, subject only to legal retention obligations and active contractual disputes. |
| 04 — Port | Receive your data in a structured, commonly used, machine-readable export (JSON or CSV) for re-use elsewhere. |
| 05 — Object | Object to processing based on legitimate interest — including profiling, marketing, and analytics — at any time. |
| 06 — Withdraw | Withdraw any consent you previously gave, at any time, without penalty and without affecting prior lawful processing. |
You also have the right to nominate another individual to exercise these rights on your behalf in the event of incapacity or death (DPDP Section 14), and the right to a clear grievance-redressal mechanism (DPDP Section 13). California residents have the additional right to opt out of the "sale" or "sharing" of personal information; we do not sell or share, but the toggle is available regardless.
To exercise any right, log in and visit the in-app Privacy & Data Requests page (the fastest path), or write to [email protected] from the address on file. We acknowledge requests within 72 hours, respond substantively within 7 working days, and will under no circumstances exceed the 30-day legal deadline. We may ask you to verify your identity before fulfilling a request — typically by re-authenticating in the app or confirming a code we send to your registered mobile or email.
If you believe we have not handled your request properly, please first contact our Grievance Officer at [email protected]; if unresolved, you may complain to the Data Protection Board of India under the DPDP Act, your supervisory authority in the EU/UK, or the California Privacy Protection Agency, as applicable.
7. Data residency & international transfers#
Wendesk's primary data-residency region is AWS Mumbai (ap-south-1). Encrypted backups are kept in a second Indian region. Some of our sub-processors operate from outside India — typically the European Union, the United Kingdom, the United States, or Singapore — to deliver services that are not equivalently available in India (for example, certain AI inference providers, global payment processors, or international SMS gateways).
When personal data crosses jurisdictions, we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses (2021 modules where applicable), the UK International Data Transfer Addendum, adequacy decisions where one exists, and supplementary technical and organisational measures including the encryption posture stated below, key management through AWS KMS with envelope encryption, strict access controls with audit logging, and contractual prohibitions on government access requests outside lawful procedure.
Encryption
All tenant data is protected with AES-256-GCM with AWS KMS-managed Customer Managed Keys; per-tenant DEK; TLS 1.3 in transit. Each tenant is issued a dedicated data encryption key (DEK) wrapped by a Customer Managed Key (CMK) in AWS KMS; integration credentials and AI BYOK keys are encrypted with the same envelope and never logged.
Indian government rules under the DPDP Act may, from time to time, restrict transfers of personal data to certain countries by notification. Where such a restriction applies, we will reroute or restrict the relevant processing accordingly.
Enterprise customers with specific data-residency obligations (for example, HIPAA-aligned, PCI-DSS-aligned, or government-sector workloads) can pin their primary storage and processing to a specific region under a written contract — typically a dedicated MongoDB cluster in the chosen region, with corresponding sub-processor restrictions agreed in the order form.
8. Children#
Wendesk is a business-to-business platform built for businesses and the staff who run them. The service is not directed at children, and we do not knowingly collect personal data from anyone under the age of 18 (the DPDP Act's definition of a child). DPDP-mandated verifiable parental or guardian consent would apply for any child whose data is processed by us, but we expect this scenario to be rare and we have built no specific child-onboarding flow.
If you believe a child's personal data has been provided to us — for example, included in a tenant's contact import, or used to create an account — please write to [email protected]. We will investigate, suspend processing during investigation, and delete the data without undue delay. We will also notify the affected workspace administrator so the tenant can correct the source.
9. Changes to this policy#
We update this Privacy Policy when our practices change, when we add or remove a sub-processor that materially affects how data flows, when laws change, or when we identify ways to make the document clearer. We track every change in the version history at the bottom of the document and archive past versions at /legal/archive.
Material changes — for example, a new processing purpose, a substantively different retention period, or a new sub-processor in a new jurisdiction — are emailed to all workspace administrators at least 30 days before they take effect, with a redline diff so you can see exactly what is changing. Continuing to use Wendesk after the effective date of a change constitutes acceptance, but if you disagree you may close your workspace and export your data without penalty during the notice window.
Non-material changes (typo fixes, broken-link repairs, restructuring without substantive effect) are published immediately and noted in the version footer.
10. Contact, Grievance Officer & breach notification#
For all privacy questions, requests, and grievances, please reach out using the details below. We treat every privacy email as a priority and route it to a real human reviewer.
Fourteen Cloud Pvt Ltd (operator of the Wendesk platform)
Registered office: Jaipur, Rajasthan, India
Data Protection Officer: [email protected]
Grievance Officer (DPDP Act, Section 13): [email protected]
General queries: [email protected]
Legal notices: [email protected]
For postal correspondence, please email us first to confirm the current registered-office address and the recipient name; this avoids your letter being delayed in transit.
Grievance SLA: We acknowledge every privacy grievance within 24 hours and resolve within 30 days (standard) or 7 days (DPDP critical paths per §8(9) and §13). If your complaint remains unresolved after 30 days, you may escalate to the Data Protection Board of India, your EU/UK supervisory authority, or the California Privacy Protection Agency, as applicable.
Grievance Officer.
Wendesk's designated grievance contact is reachable at [email protected]. Every grievance is acknowledged within 24 hours and resolved within 30 days (per DPDP Section 8(9) and Section 13). The full grievance form lives at /grievance.
Breach notification: In the event of a personal data breach affecting your data, we will notify the relevant supervisory authority within the regime-specific window below (per GDPR Art. 33; DPDP equivalent notification obligation; HIPAA Breach Notification Rule). We will notify affected individuals without undue delay where the breach is likely to result in high risk to rights and freedoms. Notifications will include: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed to address the breach.
Breach notification.
| Regime | To regulator | To affected person |
|---|---|---|
| DPDP (India) | 72 hours to the Data Protection Board | Without undue delay; via in-app banner + email |
| GDPR (EU/EEA) | Without undue delay; within 72 hours to the lead supervisory authority | Without undue delay where high risk to rights and freedoms |
| HIPAA (US healthcare) | As Business Associate, Wendesk notifies the Covered Entity without unreasonable delay and within 60 days of discovery (45 CFR §164.410); the Covered Entity then notifies HHS, individuals, and (≥500 records in a state) media per §164.404 | Customer-facing notice runs from the Covered Entity; Wendesk supplies forensic detail under the BAA |
Privacy Policy v5.0 · Reviewed 2026-05-06 · Effective 2026-05-06
See all policies at /policies