ServeDesk

Privacy Policy

Last Updated: June 15, 2026

1. Introduction

ServeDesk (“ServeDesk”, “we”, “us” or “our”) is a multi-tenant, business-to-business (B2B) Software-as-a-Service (SaaS) customer-service and contact-centre platform operated by BrandLab Media. ServeDesk enables businesses to manage customer conversations, support cases, agents, teams, notifications, customer profiles and communications across multiple messaging channels, including WhatsApp and Facebook Pages / Messenger.

ServeDesk is designed for use by businesses and their authorised staff. Each business that signs up creates its own isolated organisation (“tenant”) within ServeDesk. This Privacy Policy explains how BrandLab Media handles information when a business (a “Customer”) uses ServeDesk, and how information belonging to that Customer’s own end-customers may be processed on the Customer’s behalf.

Because ServeDesk is a B2B platform, in most cases the business Customer is the controller of the end-customer information processed through the service, and BrandLab Media acts as a processor/service provider that processes that information on the Customer’s instructions.

2. Information We Collect

ServeDesk collects and processes the following categories of information:

  • Account information — the name, email address, organisation/company name and assigned role of each user who signs up for or is invited to a ServeDesk organisation.
  • Authentication information — passwords are stored only as salted, hashed credentials (using bcrypt); we do not store plaintext passwords. Session tokens are issued to keep users signed in.
  • Customer / contact information — names, email addresses, phone numbers and other contact details that a Customer enters into ServeDesk or that arrive through a connected channel.
  • Customer conversations and messages — the content of inbound and outbound messages managed within a case, including message text and delivery status.
  • WhatsApp data — messages and related metadata (such as the sender’s WhatsApp ID, profile name where provided, and message media references) received through an authorised Meta / WhatsApp Business integration.
  • Facebook Page / Messenger data — messages and related metadata (such as the page-scoped sender ID and message content) received through an authorised Meta integration.
  • Case information — case numbers, status, priority, categories, tags, internal notes, assignments and related workflow data.
  • Agent and team information — agent availability, capacity, team membership and assignment history used to route and manage work.
  • Uploaded media / files — where a channel delivers media (for example an image or document sent by an end-customer), ServeDesk stores the reference needed to retrieve and display that media through the authorised integration.
  • Technical information — IP address, browser and device information, and server logs with timestamps generated when the service is used.
  • Usage and diagnostic information — information about how the service is used, and audit records of significant actions, used to operate, secure and improve ServeDesk.

3. Information Received Through Meta

When a Customer chooses to connect a WhatsApp Business account, a Facebook Page or Messenger through Meta, ServeDesk may receive information and messages that Meta makes available through that authorised integration — for example inbound messages, the sender’s channel identifier, a profile name where provided, message media references, and delivery or read status updates.

ServeDesk only accesses the information necessary to provide the customer-service functionality the Customer has requested — namely receiving, displaying, routing and replying to conversations. ServeDesk does not request or collect information that the authorised integration does not actually provide, and it does not use Meta data for advertising or unrelated purposes.

4. How We Use Information

We use the information described above to:

  • Provide, operate and maintain the ServeDesk platform.
  • Manage customer conversations and support cases.
  • Assign and route conversations to the appropriate agents and teams.
  • Send and receive messages through connected channels such as WhatsApp and Messenger.
  • Authenticate users and manage accounts, roles and permissions.
  • Generate in-app notifications about new cases, messages and assignments.
  • Protect the service, detect and prevent fraud, abuse and unauthorised access.
  • Troubleshoot problems and improve the performance and features of the service.
  • Maintain audit logs of significant actions for security and accountability.
  • Comply with applicable legal obligations and enforce our agreements.

5. How We Share Information

We may share information in the following limited circumstances:

  • With the business/Customer that operates the relevant ServeDesk organisation, for whom the information is processed.
  • With authorised users and agents within that organisation, according to their assigned roles and permissions.
  • With service providers that we rely on to operate the platform (such as cloud hosting, database and analytics providers), under appropriate confidentiality and data-protection obligations.
  • With Meta where necessary to operate the WhatsApp and Facebook/Messenger integrations that the Customer has authorised.
  • With authorities or third parties where we are legally required to do so, or to protect the rights, safety and security of ServeDesk, our Customers or others.
  • In connection with a corporate transaction such as a merger, acquisition, financing or transfer of assets, where legally permitted and subject to this Privacy Policy.

We do not sell personal information.

6. Third-Party Services

ServeDesk relies on the following categories of third-party services to operate. We only mention services that the platform actually uses:

  • Meta Platforms — the WhatsApp Business Cloud API and the Facebook Messenger Platform (Graph API), and the Facebook JavaScript SDK used during the optional one-click channel-connection flow.
  • Cloud hosting and database infrastructure — providers that host the ServeDesk application and store its data (including a managed MongoDB database).
  • Product analytics — in our production environment we use privacy-conscious usage analytics to understand aggregate product usage and performance.

These providers process information only as needed to deliver their services to us and are subject to their own terms and privacy commitments.

7. WhatsApp and Facebook / Messenger Data

  • Businesses voluntarily authorise each WhatsApp, Facebook Page or Messenger connection from within ServeDesk.
  • ServeDesk communicates only through authorised Meta APIs.
  • Integration access tokens and credentials are encrypted and stored securely on the server.
  • Integration credentials are never exposed to ordinary users or returned to the browser after a connection is made.
  • An administrator can disconnect an integration at any time from the ServeDesk Channels settings.
  • Disconnecting an integration stops future access through that connection. Information already stored within the ServeDesk organisation remains subject to the Customer’s configuration and to applicable retention and legal requirements.

8. Data Security

BrandLab Media implements technical and organisational measures designed to protect information in ServeDesk, including:

  • Authenticated access using signed session tokens and bcrypt-hashed passwords.
  • Role-based access control that limits what each user can see and do.
  • Strict organisation/tenant isolation so that one organisation’s data is not accessible to another.
  • Server-side handling of integration credentials, which are not exposed to end users.
  • Encryption of stored integration access tokens.
  • Encryption in transit using HTTPS/TLS for connections to the deployed service.
  • Validation of the authenticity of inbound webhook requests from Meta.
  • Audit logging of significant actions to support security and accountability.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not claim any specific security certification unless and until it has actually been obtained.

9. Data Retention

We retain information for as long as necessary to provide the service, maintain appropriate business records, comply with legal obligations, resolve disputes and enforce our agreements. Retention periods vary depending on the type of information and the purpose for which it is processed.

Where appropriate, a Customer may request deletion of information within their organisation, subject to legitimate legal and business retention requirements. When information is no longer required, we take reasonable steps to delete or anonymise it.

10. Customer / Business Responsibilities

Businesses that use ServeDesk share responsibility for privacy compliance and are responsible for:

  • The information they choose to enter into or process through ServeDesk.
  • Providing appropriate privacy notices to their own end-customers.
  • Having a valid lawful basis to collect and process their end-customers’ information.
  • Managing their connected Meta accounts, pages, numbers and permissions.
  • Configuring their agents, teams and access permissions appropriately.

These responsibilities do not remove BrandLab Media’s own obligations as the operator of ServeDesk. We each remain responsible for the parts of the service within our respective control.

11. User Rights and Privacy Requests

Depending on your location and applicable law, you may have rights to access, correct, delete or restrict the use of personal information, to object to certain processing, or to request a copy of your information. You may also ask questions about how your personal information is handled.

If you are an end-customer of a business that uses ServeDesk, please direct your request to that business in the first instance, since they generally control your information. We will support our Customers in responding to such requests.

To make a privacy request or ask a question, contact us at privacy@brandlab-media.com. We will respond within a reasonable timeframe and in accordance with applicable law.

12. Cookies and Similar Technologies

ServeDesk uses only the browser storage technologies needed to operate the service. Specifically, we use browser local storage to hold your authentication session token so you remain signed in, and to remember basic in-app preferences.

When an administrator uses the optional one-click channel-connection flow, the Facebook JavaScript SDK may set cookies as part of the Meta sign-in process. ServeDesk does not use advertising or cross-site tracking cookies.

13. International Data Transfers

ServeDesk and its service providers may process and store information in countries other than the country in which you are located. Those countries may have data-protection laws that differ from those in your jurisdiction. Where required, we take steps to ensure that international transfers are subject to appropriate safeguards.

14. Children's Privacy

ServeDesk is a business service intended for use by organisations and their authorised staff. It is not directed to children, and we do not knowingly collect personal information directly from children. If you believe a child has provided information to us, please contact us so we can take appropriate action.

15. Changes to the Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or the service. When we make material changes, we will update the “Last Updated” date at the top of this page and, where appropriate, provide additional notice. We encourage you to review this policy periodically.

16. Contact

This service and this Privacy Policy are operated by BrandLab Media. If you have questions, concerns or requests regarding this Privacy Policy or your personal information, please contact the ServeDesk privacy team at privacy@brandlab-media.com.

ServeDesk uses cookies and browser local storage to keep you signed in, keep the service secure, and remember basic preferences. We do not use advertising or cross-site tracking cookies. See our Privacy Policy.