Privacy Policy
ownadesk.com
How KeepFlow L.L.C-FZ gathers, applies, stores, discloses, and safeguards personal data around the ownadesk.com service.
Operator: KeepFlow L.L.C-FZ · Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Licence / Formation No. 2646796.01 / 2646796 · Effective date: 19 March 2026
Website: https://ownadesk.com
Primary contact: support@ownadesk.com
Maintained in English as the working text published on ownadesk.com.
This Privacy Policy sets out the practices of KeepFlow L.L.C-FZ (“KeepFlow”, “we”, “our”, or “us”) with respect to personal data handled through the ownadesk.com website and platform, its integrations, our support desk, our marketing activity, and every related service. It also summarises the entitlements that data protection legislation grants to individuals.
Where this policy applies and in what capacity we act
The policy reaches every channel through which personal data comes to KeepFlow. It covers data captured on the Website, in demo bookings, during sign-up and login flows, in contracting and invoicing, in support exchanges, and in the day-to-day running of the Services. It equally covers situations where you write to us, subscribe to our updates, join a webinar or event we host, or deal with us in any other professional setting.
Our role shifts with the context. For our own operations we determine why data is handled and therefore act as an independent controller. Where an agency, MSP, or other business client routes its support workload through the platform — ticket queues, dialogue histories, knowledge material, messages from its own end users, and comparable operational records — it is normally that client who decides the purpose and manner of processing. In that setting the client is the primary controller, and we act on its instructions within the limits of our contract with it, as a processor or service provider.
An End User who has spoken with a business running on our platform should address questions about the content of that exchange to the business itself in the first instance. Where appropriate, we help our client answer such requests.
What personal data we hold
Collection is confined to the categories a business service of this kind genuinely needs. The table below lists them together with typical examples.
| Category | Typical content |
|---|---|
| Identity and contact | Name, employer, position, work email, phone number, postal details, and similar professional coordinates. |
| Account and profile | Usernames, sign-in identifiers, authentication records, assigned roles and permissions, organisation details, saved preferences. |
| Billing and transactions | Billing address, plan and invoice history, payment state, tax particulars, and the limited payment details passed to us by payment processors. |
| Device and technical | IP address, browser and operating system details, device and session identifiers, timestamps, approximate location derived from IP, diagnostic logs. |
| Usage and analytics | Screens opened, feature activity, clicks and navigation routes, connection settings, consumption volumes, event records, aggregate statistics. |
| Support and correspondence | Messages addressed to us, call notes, email threads, feedback, survey answers, demo enquiries, tickets raised with our team. |
| Client platform material | Tickets, dialogue histories, helpdesk metadata, prompts and working instructions, knowledge sources, attachments, plus whatever else is run through the platform. |
| Marketing preferences | Subscription status, consent decisions, and records of how you engage with our mailings. |
| Cookies and similar tools | Data gathered by such technologies, detailed separately in the Cookie Policy. |
How the data reaches us
Personal data arrives over four routes. First, from you yourself: when you open an account, book a demo, take out a subscription, write to us, join an event, fill in a form, wire up an integration, or upload material. Second, automatically while the Website and Services are in use — via cookies, server logs, API calls, device signals, and other telemetry or diagnostics. Third, from our clients and their authorised users, for instance when they invite colleagues into a workspace, connect data sources, assemble teams, adjust integrations, or file support requests. Fourth, from outside parties: payment processors, analytics vendors, cloud and infrastructure suppliers, communication tooling, integration partners, resellers, identity providers, and publicly accessible business records.
Grounds and purposes of processing
Every processing operation rests on a legal basis the law recognises. Depending on the situation that basis is the performance of a contract, a statutory duty, our legitimate interest in running and developing the business, your consent, or another ground accepted by the applicable law.
Running the platform. We handle data to open and administer accounts, authenticate users, enforce access rules, and deliver the contracted functionality — and, on behalf of our clients, to take in, host, retrieve, and analyse their material and to produce Outputs from it.
Commercial administration. We take payments, manage subscriptions, raise invoices, keep the books and records the law demands, and work to stop payment fraud.
Reliability, safety, and support. We watch performance, trace faults, keep the platform secure, spot misuse, audit consumption, and raise the quality and stability of the Services; we also provide technical assistance, onboarding, training, and account-management help.
Dialogue with you. We send notices about your account, subscription, service updates, legal matters, and policy revisions; where the law and your own choices allow, we also send promotional mailings and measure how they perform.
Legal protection and corporate life. We meet statutory duties, enforce our contracts, raise or defend claims, protect our rights, and answer lawful demands from courts, regulators, and public bodies; we may also handle data for corporate transactions, internal reporting, due diligence, financing, and comparable legitimate operations, always with fitting safeguards in place.
Who may receive the data
Selling personal data, in the ordinary sense of the phrase, is not something we do. Disclosure is confined to the recipient groups below, goes no further than the purposes in this policy require, and is backed by fitting contractual and organisational protections.
| Recipient group | Reason for access |
|---|---|
| Group and affiliated companies | Where relevant to delivering the Services, corporate administration, compliance, finance, or support. |
| Vendors and subprocessors | Hosting, infrastructure, analytics, security, communications, support tooling, payment handling, identity management, model inference, and other operational tasks performed for us. |
| Connected integrations | Third-party services you decide to link to the platform, with data exchanged at your direction. |
| Professional advisers | Lawyers, accountants, insurers, auditors, and financing counterparties, each bound by confidentiality. |
| Public authorities | Regulators, law enforcement, tax bodies, and other authorities where the law requires or permits the disclosure. |
| Deal counterparties | Actual or prospective buyers, investors, or merger parties in a corporate transaction, under fitting confidentiality arrangements. |
Transfers across borders
Your data may be handled outside the jurisdiction in which you live. Storage and processing can take place in the United Arab Emirates and in any other country where we or our vendors operate, and the laws there may differ from those of your home country.
Where the applicable law calls for it, we put fitting transfer safeguards in place — adequacy mechanisms, contractual protections, or another transfer tool the law recognises. By supplying personal data and using the Services you accept that such cross-border handling can occur as this policy describes.
How the data is protected
Protection is layered, but no safeguard is absolute. We keep reasonable administrative, technical, and organisational measures aimed at preventing unlawful or unauthorised access, loss, misuse, alteration, or disclosure. Depending on the context these include access controls, role-scoped permissions, logging, encryption in transit and — where fitting — at rest, vetting of suppliers, incident-response procedures, and internal confidentiality rules.
No online transmission or electronic storage can be made perfectly safe, so absolute security cannot be promised. On your side, you are expected to use strong credentials, grant no more access than necessary, configure permissions sensibly, and keep your own protective controls in order while using the Services.
Should a breach touch personal data under our responsibility, we will act as the applicable law and our contracts require, sending notifications wherever the law makes them mandatory.
How long the data is kept
Data stays with us only while a purpose for it remains. We hold it as long as reasonably needed to run the Services, keep business records, satisfy legal duties, settle disputes, enforce contracts, deter fraud, and defend our rights and the rights of others.
The exact period turns on the kind of data, the plan in force, technical and operational constraints, and legal or contractual demands. Once a record is no longer required, it is erased, anonymised, or moved to secure archives consistent with the law and our retention practice.
Rights available to you
Data protection law gives you enforceable entitlements over your own data. Depending on the jurisdiction and the processing context, these can include obtaining a copy of your data, having inaccurate or incomplete records corrected, erasure, restriction of processing, portability, objection to particular processing, and revoking a consent you previously gave. You may also lodge a complaint with the supervisory authority competent for you.
To invoke a right, write to support@ownadesk.com or use the contact channels listed on the Website. We may ask for details needed to confirm who you are and to pin down what exactly you are requesting. Where we hold the data purely as a processor for one of our clients, we may pass your request to that client or help it respond, in line with what our contract provides.
Exercising a right will never be held against you. Bear in mind, though, that these rights are not unconditional: statutory exceptions, technical constraints, or duties obliging us to keep certain records can narrow them.
Promotional messages
You decide whether marketing reaches you. Where the law allows, we may send service announcements, product news, invitations to events, offers, and similar material. Every such message carries an unsubscribe link, and you can also withdraw by contacting us directly at any moment.
Opting out of promotion does not stop operational mail: messages needed to run your account, deliver the Services, answer support requests, or satisfy legal duties will still be sent.
Cookies and similar technologies
Tracking technologies on the Website are governed by a dedicated document. Together with our partners we rely on cookies, local storage, pixels, SDKs, and comparable tools to keep the Website and Services running, remember your choices, measure usage, refine functionality, and — where relevant — support marketing. The Cookie Policy describes the types involved and the controls open to you.
External services and links
Third-party resources follow their own rules, not ours. The Website and Services may point to outside sites, documentation repositories, helpdesks, communication channels, file-storage providers, and other tools. Their privacy, security, and content practices are outside our responsibility, so review their notices before dealing with them or switching on an integration.
Minors
The platform is built for business use, not for children. We do not knowingly gather children’s data in breach of the law. If you suspect a child has passed personal data to us improperly, let us know and we will take fitting steps.
Amendments to this policy
This document evolves with the law, the technology, and the business. Material revisions are published on the Website, and where fitting we add notice inside the Services or by email. The effective date shown at the top marks when the current wording took force.
How to reach us
Questions about this policy go straight to the operator. Contact KeepFlow L.L.C-FZ at support@ownadesk.com or in writing at Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.