Privacy Policy

Last updated September 10, 2026

NexDesk provides managed IT services to businesses. This policy explains what information we collect when you visit nexdesk.ai, when your company becomes a client, and when your team files support tickets through Slack or Microsoft Teams — and what we do with it.

1. Who we are

NexDesk is a managed IT service provider serving small and midsize businesses in the New York tri-state area. For the purposes of privacy law, we act in two different roles depending on the data.

For visitors to our website and for prospects who contact us, we are the controller — we decide what we collect and why. For data inside a client's environment (support tickets, device inventory, user directories), we act as a processor on that client's behalf, handling the data under our services agreement with them and on their instructions.

If you are an employee of a NexDesk client and want your data corrected or deleted, contact your own IT or HR administrator first. They direct us on what to do with their organization's data.

2. Information we collect

We collect different information depending on how you interact with us.

Website visitors
Pages viewed, referring URL, approximate location derived from IP address, browser and device type, and timestamps. We record IP addresses in our own analytics and in server logs.
Contact form
Name, email address, company name, phone number if you provide one, and whatever you write in the message field.
Website chatbot
The text of your conversation with the assistant on our site. Conversations are processed by a third-party AI model to generate replies (see Section 5).
Support tickets
The content of messages your team sends in Slack or Microsoft Teams to open or discuss a ticket, the sender's platform user ID and display name, thread and channel identifiers, timestamps, attachments, and any resolution notes our engineers add.
Device and asset inventory
Hardware and software inventory for managed devices — make, model, serial number, assigned user, location, warranty and support status, purchase price, and lifecycle dates.
Client portal accounts
Name, work email address, role within the organization, hashed password, and session activity including login timestamps and originating IP address.
Billing
Company billing contact, invoice line items, amounts, payment status, and copies of invoices — including invoices generated by third-party tools and uploaded to our system.

3. How we use it

  • ·To deliver the managed IT services your company has contracted us for — resolving tickets, managing devices, administering accounts.
  • ·To authenticate you and keep your session secure, including rate-limiting and blocking IP addresses that show signs of credential-stuffing or brute-force attempts.
  • ·To respond to sales enquiries submitted through our contact form or chatbot.
  • ·To generate and collect on invoices.
  • ·To understand which parts of our website are useful, and to improve them.
  • ·To meet legal, tax, and contractual obligations.

We do not sell personal information. We do not share it with advertising networks or data brokers, and we do not use client ticket content to train AI models.

4. Slack and Microsoft Teams

Support tickets are filed in your own Slack workspace or Microsoft Teams tenant. This is worth being specific about, because it means data crosses between systems.

In Slack, our app receives messages in the channels it has been added to. In Microsoft Teams, our bot receives a message in a channel only when someone @-mentions it, and receives all messages in a one-to-one chat with the bot. In both cases, we store the message content, sender identity, and thread metadata in our own database so the ticket has a durable record after the chat history rolls off.

Our bot does not read channels it has not been added to, and in Teams channels it does not receive messages that do not mention it. Slack and Microsoft each apply their own privacy terms to the data while it sits on their platform; our handling of what we receive is governed by this policy and by our agreement with your company.

When your organization stops using NexDesk, removing our app from Slack or Teams stops all further collection immediately. Data already stored is handled per Section 7.

5. Service providers we share data with

We use a small number of vendors to run the service. Each receives only what it needs to do its job.

Amazon Web Services
Hosting, database, and file storage for the platform, in the US East region. Uploaded invoice PDFs are stored in Amazon S3.
Amazon SES
Delivery of transactional email — contact form notifications and system notices.
Amazon Bedrock
Powers the website chatbot. Conversations are processed to generate a reply. AWS does not use Bedrock inputs or outputs to train its models.
Slack Technologies
Where ticket conversations happen, for clients on Slack.
Microsoft
Azure Bot Service and the Microsoft Teams platform, for clients on Teams. Also Microsoft 365 where we administer it on a client's behalf.
Google Workspace
Our own business email and internal documents.

We may also disclose information if legally required to — a subpoena, court order, or comparable legal process — or where necessary to investigate a security incident. Where we are permitted to notify the affected client before disclosing, we will.

6. Cookies and tracking

Our marketing site does not use advertising or cross-site tracking cookies. We use first-party analytics that records page views and IP addresses on our own infrastructure; nothing is sent to a third-party advertising platform.

The client portal and staff console use strictly necessary session cookies to keep you signed in. These cannot be disabled without breaking authentication.

7. How long we keep data

  • ·Support tickets and their message content: for the duration of the engagement plus two years, so historical issues can be referenced.
  • ·Asset and device inventory: for the duration of the engagement, then deleted or exported to the client on request.
  • ·Billing records and invoices: seven years, to meet tax and accounting requirements.
  • ·Portal accounts: deactivated when the engagement ends; deleted within 90 days unless the client asks us to retain them.
  • ·Contact form submissions: two years.
  • ·Website analytics and server logs: 13 months.
  • ·Chatbot conversations: 90 days.

A departing client can request a full export of their ticket history, asset inventory, and documentation at any point during the engagement or within 30 days of it ending.

8. Security

Data is encrypted in transit with TLS and at rest in our AWS-hosted database and storage. Access to client data is limited to NexDesk staff who need it to deliver the service, and portal sessions are scoped so users only ever see their own organization's data.

We log authentication attempts and automatically block IP addresses showing brute-force patterns. Administrative credentials for client environments are stored in an encrypted secrets store, not in tickets or documentation.

No system is perfectly secure. If we become aware of a breach affecting a client's data, we will notify that client without undue delay and support their own notification obligations.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, and to object to certain processing. New York does not currently have a comprehensive consumer privacy statute, but we extend these rights to anyone who asks, regardless of location.

To exercise them, email privacy@nexdesk.ai. We will respond within 30 days. We may need to verify your identity first, and if you are an employee of a client organization we will generally need to route the request through that organization's administrator.

We do not discriminate against anyone for exercising a privacy right.

10. Children

NexDesk sells to businesses. Our services are not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.

11. International transfers

Our infrastructure is hosted in the United States. If you are contacting us from outside the US, your information will be transferred to and processed in the US, where privacy law differs from your home jurisdiction.

12. Changes to this policy

We will update this page when our practices change, and revise the date at the top. For changes that materially affect how we handle client data, we will notify affected clients directly rather than relying on this page alone.

13. Contact

Privacy questions, requests, and complaints: privacy@nexdesk.ai. General enquiries: hello@nexdesk.ai. You can also reach us through the contact form on this site.