Privacy Policy
Effective date: 3 August 2026
Last updated: 3 August 2026
1. Who we are
Onedesk Pro is a customer messaging platform operated by Typetech IT, a registered software development company in Bangladesh.
Legal business name: Typetech IT
Trade licence number: TRAD/DNCC/015541/2024
Registered address: 6th floor, House 1054, Road 7, Avenue 8, Mirpur DOHS, Dhaka, Bangladesh
Privacy contact: info@typetechit.com
General contact: info@typetechit.com · +8801758080030
In this policy, "we", "us" and "our" mean Typetech IT. "Onedesk Pro" or "the Service" means our customer messaging platform and any related websites, applications and APIs.
2. Two different roles we play
This policy covers two distinct situations. Which one applies to you changes what rights you have and who you should contact.
When you are our customer (a business that subscribes to Onedesk Pro)
We act as a data controller for your account information — the details you give us when you sign up, your billing records, and how you use the platform. We decide how that information is handled, and this policy governs it directly.
When you are a customer of one of our customers (an end user)
If you sent a WhatsApp, Messenger, Instagram or web chat message to a business that uses Onedesk Pro, we act as a data processor on that business's behalf. That business is the data controller. We store and display your message so their team can reply, and we act only on their instructions. If you want your data corrected or deleted, contact that business directly, or contact us and we will route your request to them.
3. Information we collect
3.1 Account information (from our subscribing businesses)
- Name, business name, email address and phone number
- Login credentials, stored only as a salted hash
- Billing and payment details, processed by our payment provider — we do not store full card numbers
- Team member names, email addresses and role assignments
- Support tickets and correspondence with us
3.2 Platform Data from Meta and other messaging providers
When a business connects its messaging channels to Onedesk Pro, we receive and process the following on that business's behalf:
- Message content — text, images, files, audio and other media sent to or from the business account
- Sender identifiers — the page-scoped ID, Instagram-scoped ID, WhatsApp phone number, or web chat visitor identifier of the person messaging the business
- Sender profile information — display name and profile picture, where the platform provides it
- Message metadata — timestamps, delivery and read status, message IDs, and the channel the message arrived on
- Business account information — the names, IDs and access tokens of the pages, WhatsApp Business accounts and Instagram accounts our client has connected
- Template and campaign records — message templates our client has registered and their approval status
3.3 Technical information
- IP address, browser type, device type and operating system
- Pages viewed, features used, and timestamps of activity
- Error logs and diagnostic data
- Cookies and similar technologies used to keep you logged in and to remember your preferences
4. How we use Platform Data
We use Platform Data obtained from Meta and other messaging providers only to deliver the messaging service to the business that owns the account. Specifically:
- To display incoming conversations in that business's inbox
- To let that business's authorised team members send replies
- To create and update contact records in that business's own contacts list within Onedesk Pro
- To assign conversations to team members and support AI replies the business has enabled
- To provide technical support to that business when they request it
- To detect and prevent abuse, spam and security incidents
What we do not do with Platform Data
- We do not sell, licence or rent Platform Data to anyone
- We do not share one client's data with another client
- We do not use Platform Data for advertising, ad targeting or audience building
- We do not use Platform Data to build profiles of individuals for any purpose beyond the service described above
- We do not use Platform Data to train machine learning models for external use or for the benefit of anyone other than the client whose data it is
- We do not transfer Platform Data to data brokers, information brokers or monetisation platforms
- We do not use Platform Data to determine eligibility for credit, insurance, employment, housing or education
- We do not attempt to re-identify de-identified data, or combine Platform Data with data from other sources to identify individuals
5. Legal basis for processing
Where data protection law requires a legal basis, we rely on:
- Contract — processing necessary to provide the Service to our subscribing businesses
- Legitimate interests — securing our platform, preventing fraud and abuse, and improving reliability, balanced against the rights of the individuals concerned
- Consent — where you have given it, for example for marketing emails, which you may withdraw at any time
- Legal obligation — where we must retain or disclose data to comply with applicable law
For end-user message data, the legal basis is determined by the business that controls it, not by us.
6. Who we share data with
We share data only in these circumstances.
Service providers (sub-processors) who help us run the platform. Each is bound by contract to protect the data and use it only for the services they provide to us:
| Provider | Purpose | Location |
|---|---|---|
| Cloud hosting providers contracted by Typetech IT | Application hosting and managed databases (PostgreSQL, MongoDB) | As contracted with each provider |
| S3-compatible object storage | Media and file storage for messages and uploads | As contracted with the storage provider |
| Transactional email providers configured for the account | System and notification emails | As configured per client or by Typetech IT |
| Meta Platforms, Inc. | WhatsApp, Messenger and Instagram messaging APIs | United States |
Messaging platforms — Meta Platforms, Inc. and other channel providers, to the extent necessary to send and receive messages through their APIs. Their handling of that data is governed by their own privacy policies.
Legal and safety — where we are required by law, court order or a valid request from a public authority, or where disclosure is necessary to protect our rights, safety, or the safety of others.
Business transfers — if Typetech IT is involved in a merger, acquisition or sale of assets, data may transfer as part of that transaction. We will notify affected customers in advance.
We do not sell personal data to third parties under any circumstances.
7. International data transfers
Our infrastructure is hosted with cloud providers selected by Typetech IT. Our company is based in Bangladesh. If you are located elsewhere, your data will be transferred to and processed in these locations.
Where transfers involve personal data of individuals in the European Economic Area or United Kingdom, we rely on Standard Contractual Clauses or another lawful transfer mechanism, and apply appropriate technical and organisational safeguards.
8. How long we keep data
| Data type | Retention period |
|---|---|
| Message content and conversation history | For as long as the client's account is active, or until the client deletes the conversation. |
| Contact records in the client's contacts list | For as long as the client's account is active, or until the client deletes the record. |
| Account and billing records | For the life of the account, plus 7 years afterwards to meet tax and accounting obligations. |
| Technical and security logs | 90 days. |
| Backups | 30 days, after which they are overwritten. |
When a client closes their account, we delete their data — including all Platform Data associated with it — within 30 days, except where we are legally required to keep specific records for longer. Deletion propagates to backups within the backup retention window above.
Access tokens for connected Meta accounts are revoked immediately on disconnection or account closure.
9. How we protect data
- All data is encrypted in transit using TLS 1.2 or higher
- Access tokens and secrets are stored encrypted and are never exposed in logs or to client users
- Where our hosting and storage providers offer industry-standard encryption at rest, that protection applies to data stored with them
- Each client's data is logically separated; our application enforces tenant isolation on every request
- Access to production systems is limited to named engineering staff, requires multi-factor authentication, and is logged
- Staff access to client data is granted only where necessary for support, and only with the client's knowledge
- We review access permissions regularly and revoke them when staff change roles or leave
- We maintain an incident response process and will notify affected clients without undue delay if a breach affecting their data occurs
No system is perfectly secure, and we cannot guarantee absolute security. We commit to the measures above and to prompt, honest communication if something goes wrong.
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct data that is inaccurate or incomplete
- Delete your data, subject to our legal retention obligations
- Restrict or object to certain processing
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local data protection authority
To exercise any of these, email info@typetechit.com. We respond within 30 days. We may ask you to verify your identity before acting on a request.
If you are an end user whose message data is held on behalf of a business using Onedesk Pro, please contact that business directly. If you cannot reach them, contact us and we will forward your request to them and assist where we are permitted to.
11. Cookies
We use cookies that are strictly necessary to keep you signed in, maintain your session, and secure the platform against cross-site request forgery. We also use limited analytics cookies to understand how the platform is used.
You can control cookies through your browser settings, but disabling strictly necessary cookies will prevent you from logging in.
12. Children
Onedesk Pro is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If we learn we have collected such data, we will delete it. If you believe a child's data has been provided to us, contact info@typetechit.com.
13. Changes to this policy
We may update this policy as our service or the law changes. We will post the revised version here with an updated date, and for material changes we will notify account holders by email at least 14 days before the change takes effect.
14. Contact us
Typetech IT
6th floor, House 1054, Road 7, Avenue 8, Mirpur DOHS, Dhaka, Bangladesh
Privacy: info@typetechit.com
General: info@typetechit.com
Phone: +8801758080030