Privacy Policy
1. Overview and controller
This Privacy Policy explains how Hummingdesk Ltd ("we", "us", "our") collects, uses, and protects personal information when you use our platform, visit our website, or communicate with us.
Hummingdesk Ltd is the data controller for information collected via our website and platform.
Our Data Protection Officer can be reached at help@hummingdesk.com.
2. Information we collect
Information you provide directly
- Account information (name, email, company name, job title)
- Billing information (payment method, billing address) processed via Stripe
- Communication with us (support tickets, emails, form submissions)
- Content you submit through the Service (tickets, KB articles, macros)
Information collected automatically
- Device and browser information (IP address, browser type, operating system)
- Usage data (pages visited, features used, timestamps)
- Cookies and similar technologies (see our Cookie Policy)
Information from third parties
- Channel integrations (Gmail, Outlook, Slack, WhatsApp) provide message content when you authorise them
- Payment processor confirms transaction success without sharing full card details
3. How we use your data
We use personal information to:
- Provide, maintain, and improve the Service
- Process transactions and manage billing
- Send transactional emails (account, billing, security)
- Provide customer support and respond to enquiries
- Detect, investigate, and prevent fraudulent or unauthorised activity
- Comply with legal obligations
- Send marketing communications where you have opted in (you can unsubscribe at any time)
4. Legal basis for processing
We process personal data on the following bases:
- Contract: To provide the Service you have subscribed to
- Legitimate interests: To operate our business, prevent fraud, improve our Service
- Consent: For marketing communications and non-essential cookies
- Legal obligation: To comply with UK and EU law
5. Sharing and disclosure
We do not sell personal information. We share personal data only with:
- Service providers (AWS for infrastructure, Stripe for payments, Postmark for transactional email, PostHog for product analytics) — all bound by data processing agreements
- Legal authorities when required by law, court order, or to protect our rights
- Business transfers in the event of a merger, acquisition, or sale of assets (with prior notice to affected users)
6. Data retention
We retain personal data for as long as you have an active account. When you close your account, we delete personal data within 30 days, except:
- Billing records: retained for 7 years to comply with UK tax law
- Audit logs: retained for 90 days for security purposes
- Backups: purged within 90 days
7. Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Multi-tenant isolation with per-customer encryption keys
- Access controls with multi-factor authentication for all employees
- Regular security audits and penetration testing
- SOC 2 Type II certification (in progress)
No system is completely secure. We will notify affected users and the relevant supervisory authority of any personal data breach within 72 hours as required by GDPR.
8. Your rights (GDPR)
Under UK GDPR you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Erase your personal data (subject to legal retention requirements)
- Restrict processing in certain circumstances
- Data portability — receive your data in a machine-readable format
- Object to processing based on legitimate interests
- Withdraw consent at any time where consent is the basis for processing
To exercise any of these rights, email help@hummingdesk.com. We will respond within 30 days.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
9. International transfers
Personal data is primarily stored in AWS eu-west-2 (London). Where data is transferred outside the UK/EEA (for example, sub-processors in the United States), we rely on:
- UK-approved adequacy decisions where available
- Standard Contractual Clauses (SCCs) with EU-UK addenda
- Additional safeguards including encryption and access controls
10. Contact
For any privacy-related question, contact our Data Protection Officer at help@hummingdesk.com.