SECURITY AND PRIVACY

Your support data, handled the way we would want ours handled

Wootdesk stores customer conversations — the kind of data that leaves no room for carelessness. This page covers where it lives, who can reach it, and how you exercise your rights under the GDPR.

Last updated: 26 August 2026

Servers in the European Union
All traffic over HTTPS/TLS
Passwords hashed with bcrypt
GDPR and LGPD ready

Where the data lives

The application and the database run on dedicated servers inside the European Union. Nothing is replicated outside the bloc without a legal basis, and traffic between your browser and the platform travels over HTTPS with TLS, always.

  • Infrastructure hosted on European Union territory
  • Connections forced to HTTPS, with no downgrade to plaintext
  • Database closed to the public internet, reachable only by the application
  • Regular database backups, kept in the same region

How access is controlled

Most of the risk in SaaS is not the server, it is the front door. That is where the care goes.

  • Passwords stored as bcrypt hashes — nobody, us included, can read yours
  • Sessions in HttpOnly, Secure cookies with a pinned host scope
  • Refresh tokens stored only as SHA-256 hashes
  • CAPTCHA (Cloudflare Turnstile) on sign-in and sign-up
  • Per-IP attempt limits; if the limiter is down, the request is refused rather than allowed
  • Content-Security-Policy with a per-request nonce, no loose inline scripts

Your rights (GDPR and LGPD)

You are the controller of the data you put into Wootdesk; we are the processor. Any of these requests is handled within 30 days, free of charge:

Access

Receive a copy of the personal data we process on your behalf.

Rectification

Correct data that is incomplete, inaccurate or out of date.

Erasure

Delete the data for good, where no legal duty requires us to keep it.

Portability

Export your conversations and contacts in a machine-readable format.

Objection

Object to a specific processing activity or withdraw a consent you gave.

Transparency

Know who we share data with, and why.

Subprocessors

Third parties that process data so the service can work. Changes to this list are announced before they take effect.

ServicePurposeData
AsaasBilling and invoicingName, email, tax ID and payment details
WhatsApp Business API (Meta)Sending and receiving messagesMessage content on the WhatsApp channel
CloudflareCAPTCHA and abuse protectionIP address and browser signals
Google Analytics 4Usage metrics for the marketing sitePseudonymised browsing data
Meta PixelCampaign measurement on the marketing sitePseudonymised browsing data

Retention and closing an account

While the account is active, the data stays available to your team. On closing it you can request permanent deletion and we complete it within 30 days — except for what tax law obliges us to keep (billing records).

Data Processing Agreement (DPA)

A DPA is available for customers who need the processing formalised under the GDPR. Ask through the privacy channel and we will send the draft.

What we do not have yet

We would rather say it here than let you find out later: Wootdesk holds no ISO 27001 certification and no SOC 2 report. If your procurement process requires one, talk to us before signing so we can look at other ways to give you assurance.

Privacy channel

Questions, data subject requests and security incidents all go to the same address, monitored on business days:

contato@wootdesk.com.br

Found a vulnerability?

Write to the same address with reproduction steps. We take no legal action against anyone reporting in good faith who gives us time to fix it before going public.

Start with no credit card

Create the account, connect a channel and watch the platform work on your own data.