Your support data, handled the way we would want ours handled
Wootdesk stores customer conversations — the kind of data that leaves no room for carelessness. This page covers where it lives, who can reach it, and how you exercise your rights under the GDPR.
Last updated: 26 August 2026
Where the data lives
The application and the database run on dedicated servers inside the European Union. Nothing is replicated outside the bloc without a legal basis, and traffic between your browser and the platform travels over HTTPS with TLS, always.
- Infrastructure hosted on European Union territory
- Connections forced to HTTPS, with no downgrade to plaintext
- Database closed to the public internet, reachable only by the application
- Regular database backups, kept in the same region
How access is controlled
Most of the risk in SaaS is not the server, it is the front door. That is where the care goes.
- Passwords stored as bcrypt hashes — nobody, us included, can read yours
- Sessions in HttpOnly, Secure cookies with a pinned host scope
- Refresh tokens stored only as SHA-256 hashes
- CAPTCHA (Cloudflare Turnstile) on sign-in and sign-up
- Per-IP attempt limits; if the limiter is down, the request is refused rather than allowed
- Content-Security-Policy with a per-request nonce, no loose inline scripts
Your rights (GDPR and LGPD)
You are the controller of the data you put into Wootdesk; we are the processor. Any of these requests is handled within 30 days, free of charge:
Access
Receive a copy of the personal data we process on your behalf.
Rectification
Correct data that is incomplete, inaccurate or out of date.
Erasure
Delete the data for good, where no legal duty requires us to keep it.
Portability
Export your conversations and contacts in a machine-readable format.
Objection
Object to a specific processing activity or withdraw a consent you gave.
Transparency
Know who we share data with, and why.
Subprocessors
Third parties that process data so the service can work. Changes to this list are announced before they take effect.
| Service | Purpose | Data |
|---|---|---|
| Asaas | Billing and invoicing | Name, email, tax ID and payment details |
| WhatsApp Business API (Meta) | Sending and receiving messages | Message content on the WhatsApp channel |
| Cloudflare | CAPTCHA and abuse protection | IP address and browser signals |
| Google Analytics 4 | Usage metrics for the marketing site | Pseudonymised browsing data |
| Meta Pixel | Campaign measurement on the marketing site | Pseudonymised browsing data |
Retention and closing an account
While the account is active, the data stays available to your team. On closing it you can request permanent deletion and we complete it within 30 days — except for what tax law obliges us to keep (billing records).
Data Processing Agreement (DPA)
A DPA is available for customers who need the processing formalised under the GDPR. Ask through the privacy channel and we will send the draft.
What we do not have yet
We would rather say it here than let you find out later: Wootdesk holds no ISO 27001 certification and no SOC 2 report. If your procurement process requires one, talk to us before signing so we can look at other ways to give you assurance.
Privacy channel
Questions, data subject requests and security incidents all go to the same address, monitored on business days:
contato@wootdesk.com.brFound a vulnerability?
Write to the same address with reproduction steps. We take no legal action against anyone reporting in good faith who gives us time to fix it before going public.
Start with no credit card
Create the account, connect a channel and watch the platform work on your own data.