1. Who is responsible

The controller for the processing described here is Maxapp GmbH, registered address, Switzerland, reachable at privacy@livedesk.sh. LiveDesk is a product of Maxapp GmbH.

Where an IT company uses LiveDesk to support its own customers, that company is the controller for the conversations and sessions it runs, and Maxapp GmbH is its processor. This policy covers our own processing.

2. What we process

2.1 Account and organisation

  • Email address, name and a hash of your password, or the identifier your provider returns if you sign in with Google.
  • Whether your email address has been verified, and when.
  • Your organisation's name, its address on our service, and the branding it applies to its own customer pages.

2.2 Support conversations

  • Messages between a technician and a customer, and the name and any contact detail the customer types into the page.
  • A record of each screen sharing session: who asked, who allowed it, whether control was granted, and when it ended.
  • For managed devices, the machine's name and a record of every connection made to it.

2.3 Technical

  • Server logs, including IP addresses, needed to run and secure the service.
  • Session cookies that keep you signed in.

3. What we never process

We do not receive or store the contents of a screen. Screen images and the keyboard and mouse input sent back travel directly between the technician's browser and the customer's computer and are encrypted end to end. When a direct connection cannot be established, the traffic is relayed through our infrastructure, and in that case the relay carries ciphertext it cannot read. Nothing about the picture is written down at either end by us.

We do not record sessions, and we do not sell or share personal data for advertising.

4. Why we process it

  1. To provide the service you have asked for, which is our performance of the contract with you.
  2. To keep an accurate record of consent and of what happened in each session, which is a legitimate interest of ours and of the customer whose screen was shared, and in many cases a legal obligation of the IT company using the product.
  3. To keep the service secure and to prevent abuse, which is a legitimate interest.

5. Cookies

LiveDesk sets session cookies and nothing else. They keep you signed in and protect the forms you submit, and the service does not work without them. We do not use analytics, advertising, or any third party tracking, so there is nothing to consent to and no consent banner. If that ever changes, this section will change first and consent will be asked for before anything is set.

6. Where it is processed

Database and authentication
Supabase, with the database located in Zurich, Switzerland.
Edge, signalling and relay
Cloudflare, which routes the connection and relays encrypted traffic when a direct connection fails.
Website hosting and downloads
hosting provider, and object storage for the signed installers.

These are our processors, engaged under contract and permitted to process personal data only on our instructions. Where a transfer leaves Switzerland or the EEA it is covered by standard contractual clauses.

7. How long we keep it

Account and organisation data is kept while the account exists and deleted when it is closed. Conversations and session records are kept for as long as the organisation that owns them keeps them, because they are that organisation's records rather than ours. Server logs are kept for retention period. The audit trail cannot be edited, which is the point of it, but it is deleted with the organisation.

8. Your rights

You can ask us for a copy of your personal data, for it to be corrected or deleted, for processing to be restricted, and for your data in a portable form. You can object to processing we base on a legitimate interest. Write to privacy@livedesk.sh and we will answer within 30 days.

If you are not satisfied you can complain to the Swiss Federal Data Protection and Information Commissioner, or to the supervisory authority of the EU or EEA country you live in.

9. Changes

When this policy changes we update the date at the top. If a change materially affects how we handle your data we will tell you before it takes effect.