Legal
Privacy
Effective 11 August 2026
Who we are
MajlisDesk provides a shared WhatsApp and email inbox for teams. In this policy “MajlisDesk”, “we” and “us” mean the company that operates the MajlisDesk service and this website. For the conversations inside your workspace you are the controller and we are the processor — you decide which numbers and mailboxes to bring in, and we hold and serve that content on your instructions. For your own account, support and billing records we are the controller. Every privacy question or request goes to support@majlisdesk.com.
Information you give us
Creating a workspace collects your name, work email, and a password we keep only as a hash — never in a form we could read back. Inviting a teammate collects their name, email and the role you give them. On a paid plan we hold the company and contact details needed to issue an invoice; we do not store card numbers. When you connect a WhatsApp number or a mailbox we store the credentials that keep that connection alive, and mailbox secrets are encrypted before they are written down.
Conversations in your inbox
To run a shared inbox we hold the messages, attachments, contact names and numbers, labels, internal notes, tickets, assignments and custom properties that pass through the numbers and mailboxes you connect. Connecting a number imports the history already on it, which is why we tell people to connect the number they actually use for business rather than a personal one. This content is yours. We process it to give you the service and for nothing else: we do not sell it, we do not use it for advertising, and we do not train AI models on it.
Information we collect automatically
Using the product writes ordinary operational records — IP address, browser and device type, the pages and actions used, and timestamps — which we keep to run the service, investigate faults and spot abuse. We also record connection health for every number you link: when it dropped, how often it reconnected, whether media is still arriving. That is how we can tell you a number needs attention before you notice it yourself.
How we use your information
To operate and secure the product, sync and route conversations, enforce the roles and visibility rules you set, pace outbound sending so a number behaves like a person, provide support, issue invoices, prevent abuse, and decide what to build next. Nothing on that list involves selling your data or handing your conversations to an advertiser.
How WhatsApp and email connect
You connect your own WhatsApp number by scanning a QR code, and MajlisDesk then runs as a linked device on your account — the same mechanism WhatsApp Web uses. That means we hold the session key material that keeps the link alive, and that you can unlink it from your phone at any moment without asking us. This is not the WhatsApp Business API, and MajlisDesk is not affiliated with, endorsed by, or operated by WhatsApp or Meta. Mailboxes connect through Gmail or Zoho using an authorisation you grant yourself and can withdraw at your provider. Because you reply from the inbox, that authorisation covers reading and sending on the mailbox you chose, and nothing outside it. Where a provider will not issue such a grant, a mailbox can be connected with an app-specific password instead, which we encrypt before storing.
Where your data lives
MajlisDesk runs on Microsoft Azure in the UAE North region. Messages, contacts, tickets and settings sit in a managed PostgreSQL Flexible Server; attachments sit in Blob Storage; queues and short-lived state sit in Managed Redis. All three are in that one region, reachable only over TLS, and the database accepts connections from our own servers and nowhere else.
Media and the links that serve it
Photos, voice notes, videos and documents are written to a private storage container, under a key that begins with your workspace. Nothing in that container is publicly readable. A file reaches your screen either through our own API, which re-checks your role before a single byte moves, or through a signed link that covers exactly one file, permits reading only, and stops working within minutes — so there is no permanent URL to leak. One limit worth knowing: WhatsApp itself drops media from its servers after roughly a month, so a photo or voice note older than that cannot be pulled in when you first connect a number. Message text backfills at any age.
Voice notes and transcription
Speech-to-text turns voice notes, audio files and the speech inside videos into text you can read and search. When a recording is transcribed, its audio is sent to a third-party transcription provider — currently Groq — which returns text we store beside the message. Video is stripped to its audio track on our own servers first, so the picture never leaves them. Nothing is transcribed until it is asked for, on the recording it was asked for; a transcript is deleted when its message is deleted; and if your workspace never asks, no audio of yours goes anywhere. Transcription is a platform feature we switch on, not a per-workspace setting — if you would rather it never ran on your recordings, tell support@majlisdesk.com and we will exclude your workspace.
AI features
Chat summaries and suggested replies are produced by sending the recent messages of the chat you are looking at to Anthropic, whose Claude models write the text. That happens only when someone with the right role asks for it, only for the chat they asked about, and only on a plan that includes it. Separately, you can connect MajlisDesk to your own AI assistant. Doing so takes an owner or admin, who is shown exactly what is being granted — reading chats, contacts, history, labels, tickets and shared files. Replying is a separate permission that is never granted by default: unless the person connecting explicitly allows it, the assistant can read and cannot send. Where it is allowed, it can send one message to one existing conversation at a time and can never start one. The connection can be revoked from your settings at any time, and every call is re-checked against it. What that assistant then does with what it reads is governed by its own provider’s terms. In every case the model returns an answer and nothing more: your conversations are not used to train anyone’s model.
Sub-processors
These are the companies that can touch your data and what each one is for. Microsoft Azure hosts all of it — database, storage, cache and servers — in the UAE. Google or Zoho are involved only if you connect a mailbox with them, and only for that mailbox. Resend delivers our transactional email, such as a password-reset code. Groq transcribes audio when a recording is transcribed. Anthropic generates summaries and suggested replies when someone asks for one. If you connect your own AI assistant, its provider joins this list for as long as the connection lasts, and you chose it. On this marketing website, Google Analytics 4 and Microsoft Clarity measure traffic. Each is bound to handle data only as we instruct. We will tell you before adding a sub-processor that changes this picture, and support@majlisdesk.com will always give you the current list.
Who can see your data
Inside your workspace, your team sees what their role and your visibility rules allow. Between workspaces there is no path at all: the boundary is written into every database query rather than applied afterwards as a filter someone could forget. Number masking, switched on per conversation, hides customer phone numbers from anyone who is not an owner or admin, so an agent can work a chat without ever reading the number. On our side, access to production systems is limited to the people who need it to keep the service running, and it exists for support and fault-finding, not for reading your conversations.
International transfers
Your workspace data is stored and processed in the United Arab Emirates. It leaves that region only when a feature you enabled sends it somewhere — a mailbox you connected, an audio file going for transcription, a chat going to a model for a summary — and those providers may process it outside the UAE. Where the law requires a transfer safeguard, we rely on the data-protection terms in our agreements with them.
Legal bases
Where data-protection law applies, we process your data to perform our contract with you, on the basis of our legitimate interest in running and securing the service, to meet legal obligations, and — where required — with your consent. For the people in your conversations, the lawful basis for messaging them is yours to hold, not ours; we handle that content on your instructions.
Keeping and deleting data
We keep your workspace data while your account is active. Settings → Data holds three tools you can use without asking us: export your contacts as a CSV, export your contacts, chats and messages as a JSON file, and delete all data. The last one takes an owner, makes you type your workspace name first, and cannot be undone — it removes your contacts, chats, messages and any transcripts of them, and the stored files those messages pointed at are left with nothing that can address them. Tickets and email threads are kept on purpose, because they usually outlive the chat that started them; ask support@majlisdesk.com if you want those gone too, or the whole workspace closed and deleted. Disconnecting a number or a mailbox simply stops new data arriving and leaves the history where it is. Behind all of this the database keeps a fourteen-day point-in-time recovery window and storage keeps a fourteen-day soft-delete window, so a deletion works its way through our backups within about two weeks rather than instantly. Where accounting or legal rules oblige us to keep an invoice record, we keep that and nothing more.
Your rights and how to use them
You can ask for a copy of your data, to correct it, to delete it, to restrict or object to a use of it, or to receive it in a portable form. Export and delete-all are already in the product, so you can act on most of this yourself and immediately. For anything else, email support@majlisdesk.com from the address on your account and we will answer within thirty days. If your request is about data held by one of our customers — a message you sent to a business that uses MajlisDesk — we will point you to that business, because the content is theirs to act on. You can also complain to the data-protection authority where you live.
Security
Everything travels over TLS. The database and storage are encrypted at rest by the platform, mailbox secrets are encrypted again by us before they are written, passwords are stored only as bcrypt hashes, and the database accepts traffic from our own servers alone. Accounts can turn on two-factor authentication with an authenticator app, and roles limit what each person can reach. We hold no security certification today — no SOC 2, no ISO 27001 — and we would rather say so than let a badge imply something we have not been through. No system is perfectly secure; if a breach affects your data we will tell you promptly and tell you what we actually know.
Data processing agreement
If your organisation needs a written data-processing agreement covering us as your processor, ask support@majlisdesk.com and we will provide one.
Cookies and analytics
The product sets the cookies needed to keep you signed in, and nothing else. This marketing website runs two tools: Google Analytics 4, which counts visits and shows which pages get read, and Microsoft Clarity, which records how a session moved through the page — scrolling, clicking, and a replay of the visit, with text you type masked by default. Both load when the page opens. If you would rather not be measured, Google publishes a browser opt-out add-on and any tracker-blocking extension will stop both. Neither builds a profile of you, and neither runs inside the product.
Children
MajlisDesk is a business tool. It is not intended for anyone under 18, and we do not knowingly collect data from children.
Changes to this policy
We may update this policy as the product changes. We will move the effective date above and, for anything material — a new sub-processor, a new category of data, a change in where it is stored — tell you in the app or by email before it takes effect.
Language
This policy is provided in English and Arabic for convenience. If there is any conflict between the two, the English version prevails.