Legal
Privacy Policy
Last updated September 27, 2026
This Privacy Policy explains how FirstDesk collects, uses, shares and protects personal information when you visit our website or use our Service. It covers both our customers (the businesses using FirstDesk) and the end customers who call or message those businesses.
1. Our role
For account and billing information about our customers, FirstDesk is the controller. For calls, messages, contacts and appointments that businesses process through FirstDesk, the business is the controller and FirstDesk acts as a processor on its behalf.
2. Information we collect
- Account data: name, email, business name, industry, address, phone numbers, team members and login details.
- Customer Data: caller phone numbers and names, SMS and WhatsApp messages, call recordings and transcripts, appointments, notes and review requests.
- Billing data: plan, billing period and transaction history. Card and payment details are collected and processed by Dodo Payments, our Merchant of Record; we do not store full card numbers.
- Usage data: device category, traffic source, pages visited and in-app activity, used for security and product improvement.
3. How we use information
- To provide the Service: answering calls, sending text-backs, reminders and review requests, and showing your inbox and dashboard.
- To operate the AI receptionist, which processes call audio and messages to generate responses and summaries.
- To bill, support and communicate with you.
- To secure the Service, prevent fraud and meet legal and carrier obligations.
We do not sell personal information and do not use Customer Data to train general-purpose AI models.
4. Sharing
We share information only with service providers who help us run FirstDesk, under contracts that protect it:
- Twilio and carriers (calls, SMS, WhatsApp delivery)
- Dodo Payments (payments, invoicing and tax, as Merchant of Record)
- Cloud hosting, database and AI model providers
- Calendar and CRM tools you choose to connect
We may also disclose information when required by law or to protect rights and safety.
5. Retention
We keep account data while your account is active. Customer Data is kept until you delete it or close your account, then deleted within 30 days (backups within 90 days), unless law requires longer.
6. Security
Data is encrypted in transit and at rest, access is restricted by role, and each business's data is isolated. No system is completely secure, and we will notify affected customers of any breach as required by law.
7. Your rights
Depending on where you live (for example under GDPR, UK GDPR or CCPA/CPRA), you may have the right to access, correct, delete, export or restrict use of your personal information, and to object to processing. End customers of a business should contact that business first; we will help them respond. Contact us to exercise your rights.
8. Health information
FirstDesk is designed with privacy in mind for clinics, but businesses must not send protected health information unless a separate written agreement covering it is in place.
9. International transfers
Information may be processed in the United States and other countries. Where required, we use safeguards such as Standard Contractual Clauses.
10. Cookies and analytics
We use essential cookies and local storage to keep you signed in and remember preferences. We also use limited, privacy-friendly analytics by default to count industry-page visits, calls to action and completed trial signups. These analytics use a random browser-session identifier for deduplication and short-lived attribution; they do not include names, email addresses, phone numbers or full IP addresses, and are not used for advertising or cross-site tracking.
11. Children
The Service is not directed to children under 16.
12. Changes and contact
We will post updates here and notify you of material changes. Privacy questions: support@firstdeskapp.com.