Compliance
Last updated 10 September 2026
What an IT company needs from a supplier before putting it in front of its own customers: who is responsible for what, where the data sits, and what we can and cannot evidence.
1. Roles
When you use LiveDesk to support your customers, you are the controller of the personal data in those conversations and sessions, and Maxapp GmbH is your processor. We process it on your instructions and for no purpose of our own.
For your own account and organisation data we are the controller. The privacy policy covers that side.
2. Law
- Swiss Federal Act on Data Protection, as the law of the country the company and the database are in.
- EU General Data Protection Regulation, where you or your customers are in the EU or EEA.
- Transfers outside Switzerland and the EEA, where a processor requires them, are covered by standard contractual clauses.
3. Data residency
Conversations, session records and account data live in Postgres in Zurich, Switzerland. Signalling and the relay run on Cloudflare's network, which is global by design, and the relay carries only encrypted traffic it cannot read. Screen contents are never stored anywhere, by anyone, which is the part that matters most and the reason it is stated three times across this site.
4. Sub-processors
The current list is in section 6 of the privacy policy. We will give notice before adding one, so you have an opportunity to object.
5. Data processing agreement
A DPA is available on request from legal@livedesk.sh. It is not yet published as a standard document you can sign online.
6. Consent and the duty that comes with it
The product asks the person at the machine before anything is shared, and keeps a record of the answer that cannot be edited. That record is designed to be the evidence you need. It is not, on its own, a lawful basis: having the permission of the person responsible for a computer before you connect to it remains your obligation, and it is set out in section 5 of the terms.
7. What we cannot evidence
We hold no SOC 2 report, no ISO 27001 certificate and no independent audit. If your procurement process requires one of those today, we are not yet a supplier you can use, and we would rather say so here than in the fourth week of a questionnaire.
8. Questions
Security questionnaires, DPAs and specific questions go to legal@livedesk.sh. Technical detail on how the product enforces consent is on the security page.