Privacy Policy
This Privacy Policy explains how Zertix Studio collects and uses information through Deskio AI.
1. Information We Collect
- Conversation data — messages exchanged between customers and the AI assistant, including detected sentiment.
- Booking & lead data — information customers provide during a conversation (e.g. age, budget, preferences) relevant to the business's service.
- Uploaded documents — files customers voluntarily upload (e.g. identification documents for insurance applications).
- Business account data — information a business provides when registering (name, address, services, contact details).
2. How We Use Information
Information is used to operate the assistant (generate relevant responses, track bookings), to give business owners visibility into their own leads and conversations via their dashboard, and to improve the reliability of the service.
3. AI Processing
Message content and relevant business context may be processed through secure third-party AI infrastructure providers to generate responses and support language, classification, and conversation features. These providers process information only as needed to provide the service and under appropriate contractual and security safeguards.
4. Sub-processors & Third-Party Services
To provide Deskio AI, we may use the following service providers and integrations. The exact services enabled for an account depend on the business's configuration:
- Third-party AI infrastructure providers: customer messages and relevant business context may be processed to generate assistant responses and related language features.
- Messaging and communications providers: when a business connects supported messaging channels, message content and delivery metadata may be processed so messages can be sent and received.
- Third-party calendar APIs: when a business connects a calendar, authorization data and event availability may be processed to check busy/free times and create, update, or cancel appointments at the business's request.
- Third-party email integration (Gmail): when a business connects their Gmail inbox, incoming customer email content may be processed so the assistant can read and reply to those emails automatically, using the same AI that answers other connected channels.
- Hosting, storage, and security providers: account, conversation, upload, authentication, notification, and security data may be processed by infrastructure providers required to host and protect the service.
We require service providers to process information only for the services they provide and to maintain appropriate safeguards. Provider names and processing arrangements may change as the platform evolves.
5. Data Retention
Conversation, booking, and document data is retained for as long as the associated business account is active, so business owners can review their history. Businesses may request deletion of their data.
6. Data Sharing
We do not sell customer or business data. Data is shared with third-party service providers only to the extent necessary to operate, secure, and support the service, or where required by law.
7. Security
We use reasonable technical and organizational measures designed to protect information, including access controls, authentication safeguards, encryption in transit where supported, monitoring, backups, and processes intended to limit access to authorized personnel and service providers. No method of transmission or storage is completely secure.
8. Your Choices
Customers interacting with a Deskio AI assistant can request that a business delete their conversation history by contacting that business directly.
For information stored in your browser, see our Cookie Policy for the categories we use and instructions to manage or revoke local storage and cookie preferences.
9. Security Incidents & Breach Notification
If we confirm a security breach involving personal data, we will investigate, contain, and document it. We will notify affected business customers without undue delay and in accordance with applicable breach-notification laws. Where the business is the controller, it remains responsible for notifying affected individuals and regulators when required; we will provide reasonable information and assistance so it can meet those obligations.
10. European Users (GDPR) & UK Users (UK GDPR / Data Protection Act 2018)
If you are located in the European Economic Area or Switzerland, the General Data Protection Regulation (GDPR) gives you certain rights over your personal data. If you are located in the United Kingdom, the UK GDPR and the Data Protection Act 2018 give you the equivalent rights. In this context, the business using Deskio AI to talk to you is generally the data controller, and Zertix Studio acts as a data processor, handling data on that business's behalf and under its instructions.
Depending on your circumstances, you may have the right to:
- Request access to the personal data we hold about you;
- Request correction of inaccurate or incomplete data;
- Request erasure of your data ("right to be forgotten");
- Restrict or object to certain processing of your data;
- Receive a copy of your data in a portable format;
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact the business you spoke with directly — they hold the underlying relationship with you. If you're unable to reach them, you can also contact Zertix Studio. Where personal data is processed outside your region (for example, by our AI model provider), we take reasonable steps to ensure it's handled with a comparable level of protection.
11. California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you the right to:
- Know what categories of personal information we collect, use, and disclose, and for what purpose;
- Request deletion of personal information we hold about you;
- Request correction of inaccurate personal information;
- Opt out of the "sale" or "sharing" of personal information — as stated above, Deskio AI does not sell or share personal information, so there is nothing to opt out of;
- Not be discriminated against for exercising any of these rights.
To exercise these rights, contact the business you interacted with, or reach out to Zertix Studio directly. We may need to verify your identity before fulfilling certain requests.
12. Google API Data Usage & Disclosures
Deskio AI accesses and uses Google Calendar data solely to provide automated appointment scheduling and calendar syncing for businesses and their users.
- Scope of Access: We only access your Google Calendar events to read busy/free time slots, create new appointment bookings, and update or cancel existing appointments as requested by you.
- Limited Use Requirements: Zertix Studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- Limited Use: Google user data obtained via calendar APIs is used only for the calendar features requested by the business and is not used to train AI models.
- No Data Sale: We do not sell, rent, or transfer your Google Calendar data to any third parties or advertisers.
If a business chooses to connect their Gmail inbox, the same policy applies to that Gmail access:
- Scope of Access: We only access a connected Gmail inbox to read incoming customer emails and send automated replies on the business's behalf, as configured by that business.
- Limited Use: Gmail data obtained this way is used only to provide the email-reply feature requested by the business, adheres to the same Google API Services User Data Policy and Limited Use requirements linked above, and is not used to train AI models.
- No Data Sale: We do not sell, rent, or transfer Gmail data to any third parties or advertisers.
13. US Health Information (HIPAA) — Dental Businesses
If you are a dental practice or other healthcare provider based in the United States, some of the information exchanged through Deskio AI (such as symptoms, treatment reasons, or appointment details) may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). In that relationship, your practice is generally the HIPAA-covered entity, and Zertix Studio would act as your business associate for the PHI you choose to process through the platform.
Not every account is automatically HIPAA-regulated — dental clinics vary in what patient information they route through the assistant. If your practice requires a signed Business Associate Agreement ("BAA") to use Deskio AI in a HIPAA-compliant manner, contact Zertix Studio before submitting PHI through the platform. Until a BAA is executed between your practice and Zertix Studio, you should not submit PHI you are not comfortable processing under our standard terms, and you remain responsible for determining whether your use of the service complies with your own HIPAA obligations.
Where a BAA is in place, it — not this Privacy Policy — governs the handling of PHI, including required safeguards, breach-notification timelines, and permitted uses; in the event of a conflict specific to PHI, the BAA controls.
14. US Telephone & SMS Communications (TCPA)
If you are located in the United States, some communications sent through Deskio AI — such as appointment confirmations, reminders, or priority alerts — may be delivered by SMS/text message or automated phone call. The federal Telephone Consumer Protection Act ("TCPA") regulates automated and prerecorded calls and texts sent to US phone numbers.
Where a business uses Deskio AI to send you SMS or automated communications, that business is responsible for obtaining any consent required under the TCPA before doing so — for example, by capturing your consent when you provide your phone number through the chat. If you no longer wish to receive text messages from a business using Deskio AI, you can typically reply STOP to opt out, or contact the business directly. Message and data rates from your mobile carrier may apply.
Zertix Studio provides the underlying messaging infrastructure but is not the party initiating contact with you. The business you're communicating with is responsible for TCPA compliance in how it uses the platform to reach its customers.
15. Contact
Privacy questions can be directed to Zertix Studio.