Legal
Data Processing Agreement
Effective 15 August 2026
Roles
You are the controller of the conversations inside your workspace: you choose which WhatsApp numbers and mailboxes to connect and who on your team may read them. We are the processor and act only on your documented instructions, which are the settings you configure and the requests you make in writing. For your own account, support and billing records we are the controller.
What we process, and why
On your instruction we process the contents of the conversations you connect — message text, attachments, voice notes and the phone numbers, names and profile photos WhatsApp supplies with them — for the sole purpose of providing the shared inbox: syncing, storing, searching, assigning, transcribing and displaying them to the people you have authorised. We do not use your conversations to train models and we do not sell or share them.
Duration
We process for as long as your workspace exists. On deletion of a workspace, or on your written instruction, we delete or return the data as set out in the Privacy page.
Confidentiality
Access is restricted to the few people who need it to run and support the service, each under a confidentiality obligation. Support staff read a workspace only to answer a request from it or to investigate a fault, and that access is logged.
Security
Data is encrypted in transit and at rest. Media is held in private storage and served only through short-lived signed links. Access to the workspace is per-user with role-based permissions, two-factor authentication is available on every account, and administrative access to production is restricted and audited. Backups run continuously with point-in-time recovery.
Sub-processors
We use Microsoft Azure (hosting and storage, UAE North), Groq (speech-to-text for voice notes), Anthropic (the AI assist features, only when a user invokes them), Resend (transactional email) and Creem (payments, which never touches conversation content). We will tell you before adding a sub-processor that handles conversation content, and you may object.
Location and transfers
Conversation content is stored in the United Arab Emirates. Some sub-processors above process limited data outside it in order to perform their function; where that happens it is on the basis of the safeguards those providers offer.
Your people’s rights
You control the data, so you answer requests from the people in your conversations. Where you need us to help — to export, correct or delete something — ask and we will do it without charge and within a reasonable time. The product also lets a number’s owner mark conversations private or exclude them from storage entirely.
Personal chats
A connected WhatsApp number is usually also somebody’s personal phone. MajlisDesk lets its owner mark a conversation private, so it is visible only to them, or excluded, in which case it is never stored and anything already stored is deleted. This is a feature of the product, not a promise in a document.
Incidents
If we become aware of a breach affecting your data we will tell you without undue delay, and in any case within 72 hours of becoming aware, with what we know, what we are doing and what you may need to do.
Audit
On reasonable request we will provide the information needed to show we are meeting these obligations, and will co-operate with an audit that is proportionate and does not compromise other customers.
Deletion and return
On termination we delete your workspace data, or return it first if you ask. Ask before you cancel, so the export happens while the workspace is still open.