← minidesk

Privacy Policy

Last updated 29 July 2026

Who we are

minidesk is a business software platform operated by Minidesk Sdn Bhd (Malaysia). It lets a business connect its messaging channels — WhatsApp, email and others — and use an AI assistant that can answer questions and take actions on the business's own data.

This policy explains what personal data we handle, why, and what you can ask us to do about it. It is written to meet the Personal Data Protection Act 2010 (Malaysia) and the requirements of the platform providers we connect to.

Two roles, and why the difference matters

For our own customers (businesses that sign up for minidesk): we are the data user. We decide how their account data is handled, and this policy governs it directly.

For the people those businesses talk to (their customers, staff and contractors): we are a data processor acting on the business's instructions. We store and process those conversations so the business can run its operations. If you were messaged by a business using minidesk and want your data removed, contact that business first — they control it. You can also write to us and we will pass the request on and act on it.

What we collect

  • Account details — name, email address, phone number and company details of the people who sign up for and administer a minidesk account.
  • Messages and attachments — the content of conversations sent to or from a connected channel, including WhatsApp messages, the sender's phone number and WhatsApp profile name, images, documents and voice notes.
  • Business records — whatever the business chooses to store or connect, such as contacts, orders, invoices or job records.
  • Technical logs — IP address, browser type, timestamps and error traces, kept to keep the service running and to investigate abuse.

We do not buy personal data from third parties, and we do not run advertising on minidesk.

What we use it for

  • Delivering the service — routing messages, storing records, and running the AI assistant that answers questions about them.
  • Authenticating users and enforcing who is allowed to see what.
  • Support, billing, and telling you about material changes to the service.
  • Security, fraud prevention, and meeting our legal obligations.

We do not sell personal data. We do not use customer message content to train our own or any third party's general-purpose AI models.

Automated processing and AI

minidesk uses AI models to read, summarise and answer questions about the data in a business's account, and may draft replies on the business's behalf. Content is sent to our AI providers only to produce that response; under our agreements with them it is not retained for model training.

AI output can be wrong. It is a working tool, not a decision-maker. Actions that carry consequence can be held for human approval before they fire, and every action is recorded against the person or system that authorised it.

Who we share it with

We use a small set of service providers to run minidesk. Each is bound by contract to process data only on our instructions:

  • Meta Platforms — WhatsApp Business Platform, for sending and receiving WhatsApp messages.
  • Supabase — database and file storage, hosted in Singapore.
  • Vercel — application hosting and content delivery.
  • Cloudflare — DNS and network protection.
  • Resend — transactional email delivery.
  • AI model providers— to generate the assistant's responses.

We will also disclose data where the law requires it, or to establish or defend a legal claim.

Where it is stored

Primary data storage is in Singapore. Some providers listed above operate globally, so data may be processed outside Malaysia. Where that happens we rely on those providers' contractual data protection commitments.

How long we keep it

Account and business records are kept for as long as the account is active, and for up to 90 days after it closes so the account can be recovered if the closure was a mistake. After that they are deleted or irreversibly anonymised.

Technical logs are kept for up to 12 months. Records we are legally required to retain — invoices and tax records, for example — are kept for the period the law requires.

Security

Data is encrypted in transit and at rest. Access between businesses is separated at the database level, not by application code alone, and that separation is covered by an automated test suite that runs on every change. Staff access to production data is limited to what is needed to operate and support the service.

Your rights

Under the PDPA you may ask us to:

  • tell you what personal data of yours we hold;
  • correct it if it is wrong or incomplete;
  • delete it, where we are not required to keep it;
  • limit how it is processed, or withdraw a consent you gave.

Write to privacy@minidesk.co. We respond within 21 days. If your data is held by a business using minidesk rather than by us directly, we will forward your request to that business and support them in acting on it.

Children

minidesk is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe we have, write to us and we will delete it.

Changes to this policy

We may update this policy as the service changes. The date at the top shows the current version. If a change materially affects how we handle your data, we will tell account administrators by email before it takes effect.

Contact

Minidesk Sdn Bhd
Malaysia
privacy@minidesk.co