Legal
Privacy policy
Last updated: August 24, 2026
DeviceDesk ("we", "us") provides device management and workforce-insight software. This policy explains what we collect, why, and the choices you have. The short version: we collect what the product needs to function, we don't sell it, and monitoring data belongs to the workspace that collected it.
What we collect
- Account data — name, work email, company, billing details.
- Device telemetry — for managed Android devices: model, OS version, installed applications, battery, uptime, last known location, and agent health. Collected on the check-in interval your workspace configures.
- Workforce activity — for Monitor-enrolled Windows machines: foreground application, active domain, and input-presence signals. We never record keystroke contents.
- Site analytics — basic, aggregate page analytics on this website. No advertising trackers.
How we use it
To operate the console you signed up for, bill accurately per active device or seat, secure the service, and respond when you write to us. We do not sell personal data, and we do not use workspace data to train models or build advertising profiles.
Employee data in monitored workspaces
Workspaces using Monitor act as the data controller for their team's activity data; DeviceDesk processes it on their instructions. Monitor is built to be visible: a persistent indicator appears on tracked machines and individuals can access their own data. Deploying it in a manner compliant with local employment and privacy law is the workspace's responsibility — we build for transparency, and we decline feature requests for covert collection.
Retention
Telemetry and activity data are retained per your workspace's retention setting. Account data is retained while your account exists and for the period legally required after closure. You can export your data before closing a workspace.
Security
All traffic is encrypted in transit with TLS. Device credentials are hashed at rest. Access to production systems is limited to the engineers who operate them, with audit trails.
Subprocessors
We use a small number of infrastructure providers (hosting, email delivery, payments) under data-processing agreements. Enterprise self-hosted deployments run entirely on your infrastructure and involve no DeviceDesk subprocessors.
Your rights
Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data. Write to [email protected] and we will respond within 30 days.
Changes
We'll post changes here and, for material ones, email workspace owners before they take effect.