HelloDesk

Privacy policy

Last updated: 24 September 2026

This policy explains which personal data HelloDesk processes, why, who it is shared with, how long it is kept and which rights you have. It covers the website hello-desk.eu, the HelloDesk web and mobile apps, and the assistants that businesses run with HelloDesk on their own channels. HelloDesk is operated by Nomad Inno Ltd ("Nomad Inno", "we", "us").

1. Who we are

Nomad Inno Ltd, Northlink Business Centre, Level 2, Burmarrad Road, Naxxar NXR 6345, Malta.

For any question or request about your personal data, write to hello-bongu@nomadinno.com.

2. Our two roles

Controller. We decide how we process the data of the people who use HelloDesk for our customers (their staff), of our business contacts and of visitors to our website. For that data, we are the controller.

Processor. When a business (our "customer") uses HelloDesk to answer its own customers by WhatsApp, Messenger, Instagram, SMS, phone, web chat or email, we process those conversations on its behalf and only on its instructions. The business is the controller and we are its processor. If you contacted a business that uses HelloDesk, you can send your requests to that business directly; we help it answer them. You can also write to us and we will pass your request on.

3. Data we process

Account data (staff of our customers): name, email address, phone number, language, role, company, date of last login, notification preferences and the push-notification token of your device.

Company data: company name, legal name, VAT or registration number, address, phone number and email address.

Conversation data (people who contact a business): the messages and photos you send, the replies of the assistant and of the business's staff, the name or profile name provided by the channel, your phone number, WhatsApp ID, Messenger or Instagram user ID or email address, and the details you give during a request (for example the date, time and number of people for a booking).

Phone calls: your phone number and what you say. Calls are converted to text in real time and only the text is kept. We do not record or store the audio of calls.

Emails and forms: when a business connects its mailbox or a form, the sender, recipients, subject and text of the emails and form entries that the assistant handles (see section 4).

Knowledge content: the documents, web pages and opening hours that the business provides so that the assistant can answer.

Technical data: security and operating logs of our servers. The HelloDesk apps contain no advertising and no analytics or tracking tools.

4. Google user data

A business can connect a Google account to HelloDesk so that its assistant handles its emails, its form responses and its documents. This section describes exactly what we do with the data we obtain through Google APIs.

Gmail: we read the emails that match the rules set by the business (a label, the inbox or chosen senders): the sender, recipients, subject, message identifiers and the text of the message. We do not download attachments. We add labels to the emails we have processed, create drafts that the business can review, and send the replies that the business has approved or chosen to send automatically.

Google Drive (read only): we read the files in the folder chosen by the business (documents, spreadsheets, PDFs, text files and images) to build its assistant's knowledge base.

Google Sheets (read only): we read the new rows of the response sheet linked by the business, in order to answer form submissions.

Email address of the Google account: to show which account is connected.

How we use this data: only to provide the features that the business has turned on, that is answering its emails and form submissions, and answering its customers from its own documents. We do not use Google user data for advertising, we do not sell it and we do not use it to build user profiles.

Artificial intelligence: to write a reply or index a document, the relevant text is sent to Mistral AI, our AI provider, which processes it only on our instructions. Neither we nor Mistral AI use Google user data to develop, improve or train generalised AI or machine-learning models.

Sharing: Google user data is shared only with the providers needed to run these features (Supabase for hosting and storage, Mistral AI for processing, see section 9), under contract and for this purpose only. We do not transfer it to anyone else, unless required by law or as part of a merger or acquisition, in which case you will be informed beforehand.

Human access: no one at Nomad Inno reads your emails or documents, except with your explicit agreement for a specific support request, when necessary for security (for example investigating abuse), to comply with the law, or in aggregated and anonymised form for internal operations.

Storage and protection: Google access tokens are stored encrypted in a secrets vault and are never exposed to the apps. Data is encrypted in transit and at rest, and access rules isolate each company's data.

Retention: the text of processed emails is deleted after 30 days. The sender, subject and processing status stay in the business's history until it deletes them or closes its account. Copies of Drive files are kept as long as the folder is synced. When the business disconnects its Google account, we revoke our access immediately and stop reading its data. The business chooses whether the documents already imported into its knowledge base are kept or deleted; deleted documents are removed within 30 days.

Revoking access: the business can disconnect its Google account at any time in HelloDesk, or from https://myaccount.google.com/permissions.

HelloDesk's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

5. WhatsApp, Messenger and Instagram

A business can connect its WhatsApp Business account, its Facebook Page or its Instagram professional account. When you write to that business, Meta sends us your message, any photos, your WhatsApp ID and phone number or your Messenger or Instagram user ID, and your profile name. We use this data only to reply on behalf of the business and to let its staff follow and take over the conversation.

To connect an account, we receive the identifiers of the business's Page, WhatsApp account and phone numbers, and an access token that is stored encrypted. We do not use data received from Meta for advertising, we do not sell it and we do not share it with data brokers.

Deleting your data: to have your data deleted, write to hello-bongu@nomadinno.com with the subject "Data deletion request", stating the channel used and your phone number or profile name. We confirm receipt within 5 working days and delete the data, or have it deleted by the business that is its controller, within 30 days. When a business disconnects a channel in HelloDesk, we immediately stop receiving data from it.

6. Phone calls and SMS

A business can connect phone numbers provided by Vonage or Twilio. For SMS, we receive and send the phone number and the text of the message.

For calls, what the caller says is converted to text in real time by Gradium or by the telephony provider, and the assistant's reply is converted to speech in the same way. Only the text of the conversation is kept; no recording is made.

7. Artificial intelligence and automated replies

Replies are written by AI models from Mistral AI, based on the information provided by the business. The business decides how much the assistant may do on its own, and its staff can take over any conversation at any time.

The assistant takes no decision that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR. Bookings and requests that it collects are handled by the business.

We do not use the content of conversations to train AI models, and our AI provider is not allowed to use it to train its own models.

Each night, conversations that have been inactive for 24 hours are summarised (language, tone, topics and one summary sentence) to give the business statistics about its customers' requests.

8. Purposes and legal bases

Providing HelloDesk to our customers and managing their accounts: performance of our contract (Article 6(1)(b) GDPR).

Processing conversations on behalf of businesses: on their instructions, under the legal basis that each business determines as controller.

Securing the service, preventing abuse and improving its reliability: our legitimate interest (Article 6(1)(f) GDPR).

Invoicing and meeting our legal obligations: legal obligation (Article 6(1)(c) GDPR).

Sending notifications to staff: performance of our contract, subject to the permission given on your device, which you can withdraw at any time.

9. Our service providers

We use the following providers, which process data only on our instructions and under contract:

Supabase Inc.: database, authentication, file storage and server functions, hosted in the United Kingdom (London).

Mistral AI (France): writing replies, search in the knowledge base, text extraction from documents and conversation summaries.

Scaleway (France): our voice server for phone calls, in Paris.

Gradium (France): speech recognition and speech synthesis for phone calls.

Vercel Inc. (United States): hosting of the HelloDesk web app.

Hostinger (Lithuania): hosting of the website hello-desk.eu.

Expo (650 Industries Inc., United States): sending notifications to the staff's phones through Apple and Google notification services, and app updates. A notification can contain the customer's name and the first 140 characters of their message.

Resend (United States): sending account invitation and password reset emails.

When a business connects them, the platforms of its channels also receive the messages they carry: Meta Platforms Ireland (WhatsApp, Messenger, Instagram), Vonage and Twilio (SMS and calls), Google (Gmail, Drive and Sheets). We also use the Google Places API to import a business's opening hours; no personal data is sent to it.

The list of providers may change. Our customers are informed of any new provider that processes their customers' data and may object.

10. Transfers outside the European Union

Our database is hosted in the United Kingdom, which benefits from an adequacy decision of the European Commission. When a provider is located in the United States, the transfer relies on the EU-U.S. Data Privacy Framework where the provider is certified, or otherwise on the standard contractual clauses of the European Commission.

11. How long we keep data

Account data: as long as the account is active, then deleted within 90 days after the account is closed, except invoicing data, kept for the period required by law.

Conversations and the photos they contain: the business decides. By default they are kept for as long as the business uses HelloDesk, so that it can consult its history. The business can ask us at any time to set an automatic deletion period or to delete all or part of its history.

Text of emails processed by the assistant: deleted after 30 days. The sender, subject and processing status stay in the business's history.

Technical records of messages received from and sent to the channels: deleted after 30 days.

When a customer stops using HelloDesk: its account is archived. Its data is kept, without access, for 90 days so that it can be exported or the account reactivated, then it is permanently deleted, except data we must keep by law.

12. Security

Data is encrypted in transit and at rest. Access tokens and credentials for connected channels are stored in an encrypted secrets vault and are never sent to the apps. Access rules isolate each company's data, messages received from channels are verified by signature, and two-factor authentication is available for accounts. Access by our team is limited to what is necessary.

13. Your rights

You have the right to access your data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format and to withdraw your consent at any time when processing relies on it.

To exercise these rights, write to hello-bongu@nomadinno.com. We answer within one month. If your request concerns a conversation with a business, we pass it on to that business, which is the controller.

You can lodge a complaint with the Information and Data Protection Commissioner in Malta (idpc.org.mt) or with the data protection authority of your country, for example the CNIL in France.

14. Deleting an account

A staff member can ask the administrator of their company to delete their account, or write to hello-bongu@nomadinno.com with the subject "Account deletion" from the email address of the account. The account and its personal data are deleted within 30 days, except data we must keep by law.

15. Cookies and local storage

Website: we only use a cookie that remembers the language you chose. There are no advertising or tracking cookies.

Apps: the login session is kept on your device so that you stay signed in.

Chat window on businesses' websites: a random conversation identifier is kept in your browser so that you find your conversation again. No cookie is used and no tracking takes place.

16. Children

HelloDesk is a service for businesses and is not intended for children under 16. We do not knowingly collect data about them.

17. Changes to this policy

We may update this policy. The date at the top shows the latest version. If a change is significant, we inform our customers by email or in the app before it applies.

18. Contact

Nomad Inno Ltd, Northlink Business Centre, Level 2, Burmarrad Road, Naxxar NXR 6345, Malta. Email: hello-bongu@nomadinno.com.