Legal
Privacy Policy
What we collect, what we deliberately cannot see, and what you can demand from us.
Last updated 28 July 2026
1. Who we are
SisiDesk provides persistent cloud workspaces streamed to a browser. This policy covers sisidesk.com and the SisiDesk control plane. For any question about this policy, or to exercise a data right, write to privacy@sisidesk.com.
2. Data we collect
We collect the minimum needed to run accounts, workspaces and billing:
- Account data: name, email address, company, authentication identifiers and password hashes (or a Google account identifier where you sign in with Google).
- Workspace metadata: workspace names, operating system, size, region, status and last activity time.
- Session and usage records: start and end times, minutes consumed, region, client type and computed cost.
- Device records: a device label, platform, and a fingerprint used to recognise trusted devices for session handoff.
- Audit events: security-relevant actions taken in your account, retained so you can review them.
- Support correspondence you send us, and waitlist submissions where you provided them.
3. What we do not collect
We do not read the contents of your workspace. Document indexing, optical character recognition and embedding generation execute inside your workspace instance, within the tenant boundary. The control plane has no read path into workspace storage, and we do not use any workspace content to train models — on any tier.
4. How we use data
- To provision, run, suspend and restore your workspaces.
- To meter usage accurately and produce invoices you can reconcile.
- To authenticate you and detect account abuse or fraudulent use.
- To provide support you have requested, and to send service and security notices.
- To meet legal, tax and accounting obligations.
We do not sell personal data, and we do not share it with advertisers or data brokers.
5. Legal bases
Where the GDPR or a comparable regime applies, we rely on: performance of a contract (to deliver the service you subscribed to), legitimate interests (service security, abuse prevention, product reliability), legal obligation (tax and accounting records), and consent where we ask for it explicitly, such as marketing email — which you may withdraw at any time.
6. Support access to your workspace
Our staff cannot enter a running workspace unilaterally. Support access requires an explicit, time-boxed grant initiated by you, is limited to the duration you set, and is written to your audit log where you can inspect it afterwards.
7. Sub-processors
We use a small number of vendors to deliver the service. Each is bound by a data processing agreement and is restricted to the categories of data listed:
- Cloud infrastructure provider — hosts workspace instances, persistent volumes and the control plane database.
- Streaming and session transport provider — carries encoded session pixels and input events; does not retain session content.
- Payment processor — handles card details and invoicing; SisiDesk never stores full card numbers.
- Transactional email provider — delivers account, security and billing notifications.
We will give notice through the account owner's email before adding a sub-processor that materially changes where or how personal data is processed.
8. International transfers
You choose the region where each workspace runs, and workspace data stays in that region. Control-plane metadata may be processed elsewhere; where that involves a cross-border transfer, we rely on Standard Contractual Clauses or an equivalent lawful mechanism.
9. Retention
- Account records: retained while your account is active, then deleted within 90 days of closure.
- Workspace volumes: retained for 30 days after a subscription lapses or a workspace is deleted, then permanently destroyed.
- Usage and billing records: retained for up to 7 years where tax law requires it.
- Audit events: retained for 12 months, or longer where you have a compliance requirement.
10. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to lodge a complaint with your supervisory authority. Email privacy@sisidesk.com and we will respond within 30 days.
11. Security
Workspaces are isolated per tenant, data is encrypted in transit and at rest, and access to production systems is role-scoped and logged. Our practices are described in more detail on the security page.
12. Changes to this policy
We will post any change here and update the date above. Material changes are announced to account owners by email at least 14 days before they take effect.