Privacy notice

Last updated 28 August 2026

This notice sets out what personal data miniDesk.ai collects, why we hold it, and what you can ask us to do with it. It covers the website, the dashboard, the chat widget, and the API.

1Who is responsible

miniDesk.ai is operated by MP Enterprise, SIREN 838786085, registered in France. For the data you enter into your workspace we are the processor and you are the controller: it is your data, we hold it on your behalf. For your own account and billing details we are the controller. Write to hello@minidesk.ai for anything in this notice.

2What we collect

Only what the product needs to run. There is no advertising network, no data broker and no sale of anything to anyone.

  • Account data: your name, email address, password hash, workspace name and the role you hold in each workspace.
  • Workspace content: tickets, messages, attachments, customer records, knowledge base articles and anything else you or your customers write into the product.
  • Billing data: plan, invoices and payment status. Card numbers are handled by Stripe and never reach our servers.
  • Usage data: message and AI counters per billing period, which is how quotas are enforced.
  • Product analytics: which pages and features get used, and when, so we can see what works. Only if you accept analytics cookies, and it is tied to an account id rather than to your name or address.
  • Technical logs: IP address, browser, timestamps and error traces, kept so we can debug and spot abuse.

4AI processing

When the assistant drafts a reply, searches your knowledge base or summarises a ticket, the relevant text is sent to our model provider so it can produce an answer. The provider we use can change as models improve; the one in use today is named in the sub-processor list below. We do not train models on your content, and we only use providers who commit to the same. Drafts are generated on demand and the provider does not keep them beyond what is needed to return the response.

5Who else sees it

A short list of sub-processors, each doing one job.

  • Stripe, for payments and invoicing.
  • Mistral, for AI features.
  • PostHog, for product analytics, on their EU servers.
  • Cloudflare, for inbound email routing and for protecting the service from attack.
  • Hetzner, for the servers and backups that run the product.

6Where your data lives

The database, file storage and outbound mail server are ours and run inside the European Union. Some sub-processors listed above may process data outside the EU. Where they do, the transfer is covered by the European Commission's standard contractual clauses. We can send you the current list of sub-processors and the country each one operates in.

7How long we keep it

Data is deleted when it stops being needed, not when someone remembers to ask.

  • Workspace content stays for as long as the workspace exists. When a workspace is deleted we stop processing it immediately and erase it permanently within 60 days.
  • Account data is erased when you close your account, apart from what we must keep for accounting.
  • Invoices and accounting records are kept for 10 years, which French commercial law requires.
  • Technical logs are rotated within 90 days.

8Your rights

You can ask us to give you a copy of your data, correct it, erase it, restrict what we do with it, hand it over in a portable format, or stop processing based on legitimate interest. Email hello@minidesk.ai and we will answer within one month. If you are unhappy with the answer you can complain to the CNIL, the French data protection authority, at cnil.fr. If your request concerns data inside somebody else's workspace, we will pass it to them, because they control it and we do not.

9Security

Traffic is encrypted in transit, passwords are hashed, backups are encrypted at rest, and access to production is limited to the people who need it. API credentials are shown once and can be revoked at any time, and revocation takes effect on the next request. No system is perfect: if a breach ever affects your data we will tell you and the CNIL within the 72 hours the GDPR allows.

10Cookies

Two kinds, and only the first is set without asking. Strictly necessary cookies keep you signed in and keep a chat conversation alive across a page reload; those need no consent. Analytics cookies are set by PostHog and only after you press Accept on the cookie banner. Press Reject and none are written, no measurement runs, and the site works exactly the same. The choice is stored once for this site and the dashboard together, so you are only asked once, and you can change it here at any time. We do not run advertising or cross-site tracking cookies of any kind.

Your cookie choice

Accept turns analytics cookies on. Reject turns them off, wipes any already set, and reloads the page so nothing is left behind.

11Children

miniDesk.ai is a tool for businesses and is not aimed at children. We do not knowingly collect data from anyone under 16. If you believe we have, write to us and we will erase it.

12Changes to this notice

If we change something material we will email account owners and update the date at the top of this page before the change takes effect.

Contact us