GDPR Compliance
Last updated: March 1, 2026
ByteDesk, Inc. ("ByteDesk," "we," "us," or "our") is committed to complying with the European Union's General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland. This page explains how we meet our obligations under the GDPR.
Our Commitment
We believe data protection matters. ByteDesk works to process personal data lawfully, fairly, and transparently, and to align privacy practices with the services and platform access we provide.
Data We Process
In the context of GDPR, ByteDesk acts as both a data controller and a data processor depending on the relationship:
- As a Data Controller: We collect and process personal data from our customers (account holders) for purposes such as account management, billing, service communications, and platform improvement.
- As a Data Processor: When our customers use ByteDesk to manage their own contacts, leads, and customer data, we process that data on their behalf according to their instructions and our Data Processing Agreement.
The categories of personal data we process include names, email addresses, phone numbers, IP addresses, usage data, billing information, and any other data our customers choose to store within the platform.
Legal Basis for Processing
We process personal data only when we have a valid legal basis under Article 6 of the GDPR:
- Contract Performance: Processing necessary to provide our services, manage your account, and fulfill our contractual obligations to you.
- Legitimate Interest: Processing for purposes such as improving our platform, preventing fraud, and ensuring network security, where our interests do not override your fundamental rights.
- Consent: Processing based on your explicit consent, such as receiving marketing communications or enabling optional analytics cookies. You may withdraw consent at any time.
- Legal Obligation: Processing necessary to comply with applicable laws, regulations, or legal proceedings.
Your Rights Under GDPR
If you are located in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:
- Right of Access (Article 15): You may request a copy of the personal data we hold about you, along with information about how it is processed.
- Right to Rectification (Article 16): You may request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17): You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
- Right to Restriction (Article 18): You may request that we restrict processing of your data under certain circumstances, such as when you contest the accuracy of the data.
- Right to Data Portability (Article 20): You may request a structured, machine-readable copy of your personal data to transfer to another service provider.
- Right to Object (Article 21): You may object to processing based on legitimate interests or for direct marketing purposes.
- Right Not to Be Subject to Automated Decisions (Article 22): You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you.
To exercise any of these rights, please contact us at privacy@bytedesk.ai. We will respond to your request within 30 days where required by applicable law.
Privacy Contact
For GDPR and privacy-related requests, you can contact ByteDesk at:
- Email: privacy@bytedesk.ai
- Mail: ByteDesk, Inc., 548 Market St, Suite 35000, San Francisco, CA 94104
Data Processing Agreements
For customers who require a Data Processing Agreement (DPA) in accordance with Article 28 of the GDPR, ByteDesk provides a pre-signed DPA that covers the scope of data processing, security measures, sub-processor usage, data breach notification procedures, and data subject rights. Our DPA is available upon request and can be executed electronically. Contact legal@bytedesk.ai to obtain a copy.
International Data Transfers
ByteDesk is headquartered in the United States. When personal data is transferred from the EEA, UK, or Switzerland to countries outside these regions, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): We use the European Commission's approved Standard Contractual Clauses as the primary mechanism for cross-border data transfers.
- Supplementary Measures: We implement additional technical and organizational safeguards, including encryption, access controls, and data minimization practices.
- Transfer Impact Assessments: We conduct transfer impact assessments to evaluate the legal framework of recipient countries and ensure an adequate level of protection.
Sub-processors
ByteDesk engages a limited number of sub-processors to assist in providing our services. All sub-processors are bound by data processing agreements that impose data protection obligations consistent with the GDPR. We maintain an up-to-date list of sub-processors and notify customers of any changes at least 30 days in advance, giving you the opportunity to object. Current sub-processors include cloud infrastructure providers, payment processors, and email delivery services.
Security Measures
We use technical and organizational safeguards designed to reduce the risk of unauthorized access, alteration, disclosure, or destruction:
- Encryption for sensitive data in transit and at rest where appropriate.
- Role-based access controls with the principle of least privilege.
- Security reviews, logging, and operational controls appropriate to the service.
- Incident response procedures with 72-hour breach notification to supervisory authorities as required by Article 33 of the GDPR.
- Employee and contractor access practices intended to protect customer data.
Contact Us About Privacy
If you have questions about our GDPR compliance practices, wish to exercise your data protection rights, or want to file a complaint, please contact us:
- Email: privacy@bytedesk.ai
- Mail: ByteDesk, Inc., 548 Market St, Suite 35000, San Francisco, CA 94104
- Or visit our Contact page.
You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights under the GDPR have been violated.
Have Questions About GDPR Compliance?
Contact ByteDesk if you need to discuss data privacy concerns.