Back to Maxdesk

Maxdesk — Privacy Policy

Effective date: 10 July 2026

This Privacy Policy explains how MXG Infotech Private Limited ("MXG", "we", "us", "our"), of 17, 5th Main, 3rd Cross, Bengaluru 560004, India, collects, uses, discloses, and safeguards personal data in connection with the Maxdesk helpdesk service (the "Service").

This Policy is part of, and incorporated into, our Terms of Service.

1. Scope and our roles

The Service is used by business customers ("Customers") to operate their own helpdesks. This creates two different roles:

  • When we act as a processor. For personal data that a Customer submits to or generates in its Workspace (for example, data about the Customer's own end users contained in support tickets), the Customer is the controller / data fiduciary, and we act as a processor on the Customer's behalf. Our processing of that data is governed by our Data Processing Addendum, and this Privacy Policy does not apply to it except as stated there. If you are an end user of a Customer, please contact that Customer about their handling of your data.
  • When we act as a controller. For personal data we collect and use for our own purposes — including account registration and administration, billing, security, product analytics and improvement, marketing, and advertising — we act as an independent controller / data fiduciary, and this Privacy Policy applies.

2. Personal data we collect (as controller)

  • Account and contact data: name, email address, organisation name, role, and credentials.
  • Billing data: billing contact, transaction records, and limited payment metadata. Full card details are collected and stored by our payment processors (Razorpay and/or Stripe), not by us.
  • Usage and device data: log data, IP address, device and browser information, pages and features used, and diagnostic data.
  • Cookies and similar technologies: as described in Section 7, including for analytics and advertising.
  • Communications: messages you send us, including support requests.

3. How we use personal data (as controller)

We use personal data to: provide, operate, secure, and improve the Service; create and administer accounts; process payments and prevent fraud; serve and measure advertising on ad-supported Plans; communicate with you, including service and, where permitted, marketing messages; analyse and develop our products; and comply with law and enforce our Terms.

4. Legal bases (where applicable, e.g. EEA/UK)

Where required, we rely on: performance of a contract (to provide the Service); legitimate interests (to secure, analyse, improve, and market the Service, and to serve advertising, balanced against your rights); consent (for certain cookies, advertising, and marketing, where required); and legal obligation (to comply with law). Where we rely on consent, you may withdraw it at any time.

5. Advertising

Ad-supported Plans display advertising served by third-party advertising and publisher networks. These networks and their partners may use cookies and similar technologies to collect data about your device and activity in order to serve and measure ads, and may combine it with data from other sources. We do not control these networks' independent processing. Where required, we obtain consent before non-essential advertising cookies are set (see Section 7). You may also use ad-free (paid) Plans.

6. How we share personal data

We share personal data with:

  • Service providers / sub-processors who support the Service (including AWS hosting, payment processors, analytics, and AI providers). A current list of our sub-processors is maintained at https://www.maxdesk.ai/subprocessors.
  • AI providers, where you use AI Features. Data sent to AI Features is processed by those providers only to generate outputs and is not used to train or improve their models. See our Terms of Service, Section 4.
  • Advertising networks, as described in Section 5.
  • Payment processors (Razorpay and/or Stripe) to process transactions.
  • Legal, safety, and corporate reasons: to comply with law, respond to lawful requests, enforce our Terms, protect rights and safety, and in connection with a merger, acquisition, financing, or sale of assets.

We do not sell personal data for money. Certain sharing for advertising may constitute a "sale" or "sharing" under some US state laws; see Section 11 for your rights.

7. Cookies and similar technologies

We and our partners use cookies, SDKs, pixels, and similar technologies to operate the Service, remember preferences, analyse usage, and (on ad-supported Plans) serve and measure advertising. Cookies fall into: strictly necessary (always active), functional, analytics, and advertising categories. Where required by law, we display a consent banner and set non-essential cookies only with your consent, which you can change or withdraw at any time via our cookie settings. You can also control cookies through your browser. Blocking some cookies may affect functionality.

8. International data transfers

We operate globally and host on Amazon Web Services (AWS), which may store and process data in one or more regions we select. Personal data may be transferred to, and processed in, countries other than your own, including India and other jurisdictions that may not offer the same level of protection as your home country. Where such transfers involve personal data protected by EEA, UK, or other laws requiring safeguards, we implement an appropriate transfer mechanism (such as Standard Contractual Clauses or an equivalent), where required.

9. Data retention

We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Retention of Customer Data within Workspaces (including any rolling-retention limits) is governed by the applicable Plan and the Data Processing Addendum. Please review your Plan details.

10. Security

We maintain reasonable technical and organisational measures designed to protect personal data. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.

11. Your rights

Depending on your location, you may have rights to access, correct, update, delete, or port your personal data; to object to or restrict processing; to withdraw consent; to opt out of certain advertising, "sales", or "sharing"; and to lodge a complaint with a supervisory authority.

  • India (DPDP Act 2023): you may have rights of access, correction, completion, updating, and erasure, the right to nominate, and the right of grievance redressal, subject to the Act and Rules.
  • EEA / UK (GDPR / UK GDPR): the rights described above, including the right to complain to your supervisory authority.
  • California and other US states: rights to know, delete, correct, and opt out of "sale"/"sharing" and targeted advertising, without discrimination for exercising them.

To exercise your rights, contact us using Section 13. Where we act only as a processor for a Customer, we will refer your request to that Customer.

12. Children

The Service is intended for users 18 and older and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps.

13. Grievance Officer and contact

In accordance with applicable Indian law, our Grievance Officer is:

Mr. Suresh — Grievance Officer

MXG Infotech Private Limited

17, 5th Main, 3rd Cross, Bengaluru 560004, India

Email: maxdesk@mxginfotech.com

We will acknowledge and endeavour to resolve grievances within the timelines required by applicable law.

14. EU / UK Representative

Where required under Article 27 of the GDPR / UK GDPR, our appointed representative is:

Mr S Jain

16 Upper Woburn Place, London WC1H 0BS, United Kingdom

Email: sj@mxginfotech.com

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice. Your continued use after changes indicates acceptance.