HostDesk legal

Privacy Notice

This notice explains how HostDesk handles account, website-assistant, lead, usage, and support information.

1. Scope and roles

This Privacy Notice applies to Lenura Ventures Inc., a corporation incorporated under the laws of Canada, operating under the name HostDesk and the HostDesk websites, applications, reports, assistants, integrations, and support operations. It does not govern a Customer's independent privacy practices.

For account, billing, marketing, security, and direct support information, HostDesk determines why and how information is processed. For visitor conversations, connected website content, leads, and other data processed for a Customer, Customer generally determines the purpose and HostDesk generally acts as its processor or service provider. End users should direct requests about a Customer's assistant to that Customer first.

2. Information we collect

  • Account information, such as name, business identity, email, authentication identifiers, role, and legal acceptance records.
  • Subscription and transaction information, such as plan, billing status, invoices, payment-provider references, and tax information. HostDesk need not store complete payment-card numbers.
  • Customer Content, including connected public pages, uploaded documents, approved answers, policies, configuration, integration data, and communications.
  • Assistant and lead data, including questions, responses, source citations, refusal reasons, page URL, contact details voluntarily provided, and delivery status.
  • Device and usage information, such as IP-derived security data, browser and device type, timestamps, identifiers, feature events, error logs, and approximate location inferred from an IP address.
  • Support and communications information, including messages, feedback, call notes, and records required to resolve a request or enforce the Agreement.

3. Sources of information

We receive information directly from account users and website visitors; automatically from use of the Service; from websites and systems a Customer instructs us to scan or connect; from authentication, commerce, messaging, payment, analytics, and infrastructure providers; and from lawful public or commercial sources used for security, fraud prevention, or business administration.

4. Why we process information

  • Provide, personalize, maintain, support, and bill for the Service.
  • Authenticate users, activate workspaces, preserve contract evidence, and administer subscriptions.
  • Retrieve sources, generate and verify responses, capture requested leads, deliver messages, and produce reports and analytics.
  • Protect users, investigate abuse, prevent fraud, enforce limits and the Agreement, and maintain security and reliability.
  • Comply with law, respond to valid legal process, establish or defend legal claims, and complete corporate transactions.
  • Communicate about the Service and, where permitted, market HostDesk. Recipients may opt out of non-transactional marketing.
  • Create de-identified or aggregated statistics and improve the Service without training generalized models on Customer Content unless Customer separately opts in in writing.

6. How information is disclosed

HostDesk does not sell personal information for money and does not share it for cross-context behavioural advertising. HostDesk does not use Customer Content to train generalized models for other customers without separate written opt-in consent.

  • To Customer and its authorized users, including lead and conversation information generated on Customer's sites or channels.
  • To subprocessors that provide hosting, databases, AI inference, authentication, email, messaging, payments, monitoring, security, analytics, and support, subject to contractual restrictions appropriate to their role.
  • To integrations and third parties selected or directed by Customer.
  • To professional advisers, auditors, insurers, financing sources, and transaction counterparties under confidentiality duties.
  • To authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or establish and defend claims.
  • In a merger, financing, reorganization, insolvency, or sale of all or part of the business, subject to applicable notice requirements.

7. Retention

We retain information for as long as reasonably necessary to provide the Service, follow Customer-configured retention, meet legal and security obligations, resolve disputes, and enforce agreements. Different records have different periods. Customer Content is generally retained for the account term and a limited deletion or recovery period. Security logs may be retained longer where needed to investigate abuse.

Contract, billing, and legal acceptance evidence may be retained for the account term and the applicable limitation, tax, audit, or claims period, ordinarily up to seven years after the relationship ends. Backups are deleted on a rolling schedule unless preservation is legally required. De-identified information that cannot reasonably identify a person may be retained longer.

8. International processing

HostDesk and its subprocessors may process information in Canada, the United States, and other countries where they operate. Those countries may have different privacy laws. Where required, HostDesk uses contractual or other recognized safeguards for cross-border transfers.

9. Security

HostDesk uses administrative, technical, and organizational measures designed to protect information, including access controls, tenant isolation, encrypted transport, credential protections, logging, and retention controls appropriate to the Service. No system is completely secure. Customer must protect its credentials, configure the Service appropriately, and promptly report suspected incidents.

10. Rights and choices

Subject to local law, individuals may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent, and may appeal a denied request or complain to a privacy regulator. Rights are not absolute and identity verification may be required. Account users can manage some information and retention in the Service. End users whose information belongs to a Customer should contact that Customer; HostDesk will assist the Customer as required.

Requests concerning information HostDesk controls may be sent to solutions@hostdesk.ai. We will not discriminate against a person for exercising a privacy right. Authorized-agent requests must include proof of authority where law permits.

11. Cookies and similar technologies

HostDesk may use necessary cookies and local storage for authentication, security, preferences, and operation, and limited analytics technologies to understand Service performance. Where required, non-essential technologies are subject to notice and choice. Customer controls the cookies and notices on its own website, including those associated with its deployment of the widget.

12. Children and restricted information

HostDesk accounts are not for people under 18. The Service is not designed for child-directed collection or for processing protected health information, payment-card data, government identifiers, account passwords, biometrics, or other highly sensitive information unless HostDesk expressly agrees in writing. Customers must not configure the Service to collect such information without all required safeguards and approvals.

13. Updates and contact

We may update this notice and will identify the effective date and version. Material changes will be communicated through the Service, account email, or a new acceptance request where appropriate. Questions and requests may be sent to solutions@hostdesk.ai or Attn: Peter Lester, 1992 Lewis Turner Blvd, Suite 1067 #189, Fort Walton Beach, FL 32547, United States.