Privacy policy
Last updated 2026-09-16
Please have this reviewed
1. Who we are
DeadlineDesk (“we”, “us”) provides a deadline and renewal tracking service for businesses. This policy explains what personal data we handle, why, and what you can do about it. Contact us at hello@getdeadlinedesk.com.
2. What we collect
Account data
- Your name, email address and, if you provide one, phone number.
- Your chosen language and timezone.
- Which organizations you belong to and your role in each.
Organization data you enter
- Obligations: titles, categories, reference numbers, issuing authorities and dates.
- Who is responsible for each obligation.
- Notes and costs you record.
- Documents you upload, such as licences, certificates and contracts.
Operational data
- An append-only audit log of significant actions inside your organization.
- Records of reminder emails we attempted to send, and whether they succeeded.
- Product analytics events: coarse counters such as “an obligation was created”. These carry no page URLs, no IP addresses and no free text.
- Rate limiting counters keyed by a one-way hash of your IP address. We do not store the address itself.
3. What we do not do
- We do not sell your data, or share it with advertisers.
- We do not read your uploaded documents, and we do not use them to train models.
- We do not use third-party advertising or tracking cookies.
4. Why we process it
To provide the service you asked for: storing your deadlines, sending reminders, controlling who in your organization can see what, taking payment, and keeping the service secure and available. Where a legal basis is required, ours is performance of a contract with you and our legitimate interest in operating a secure service.
5. Cookies
We use only cookies the service cannot work without:
- A session cookie that keeps you signed in.
- A cookie recording which organization you are currently viewing.
There are no analytics or advertising cookies, so there is no consent banner to click through.
6. Who processes data on our behalf
We use a small number of subprocessors. Each is used for one clearly defined purpose:
- Supabase — database, authentication and file storage. Stores your account and organization data, and your uploaded documents in a private bucket.
- Cloudflare — application hosting, and Workers AI for the in-app assistant when Google is unavailable.
- Google (Gemini API) — the in-app assistant. When someone asks it a question, the question and a list of that workspace’s deadlines (titles, categories, dates, status and the name of the person responsible) are sent to answer it. No documents or files are sent. On Google’s free tier, Google may use this content to improve its products and it may be read by human reviewers. The assistant is used only when someone opens it and asks.
- Brevo — transactional email. Receives recipient addresses and the contents of reminder and account emails.
- Lemon Squeezy — international payments, acting as merchant of record. Receives billing details, which we never see or store.
We never send payment card details to our own servers.
7. Where data is stored
Data is stored on infrastructure operated by the providers above, which may be located outside your country. If your organization has data residency requirements, contact us before uploading anything.
8. How long we keep it
- Organization data: for as long as your organization exists.
- Deleted organizations: content is removed from active systems, and uploaded documents are deleted from object storage, when an owner requests deletion.
- Audit logs: retained for the life of the organization; they cannot be edited.
- Reminder delivery logs: retained to let you prove a reminder was sent.
- Rate limiting counters: purged after a few days.
9. Your rights
- Access and portability. Export your full organization at any time from Settings, as a single machine-readable file.
- Correction. Edit your profile and your organization data directly.
- Deletion. An owner can delete an organization and its documents from Settings. To delete your personal account, email us.
- Objection and complaint. Contact us, and you may also complain to your local data protection authority.
10. Data ownership
The data and documents you put into DeadlineDesk remain yours. We claim no ownership of them and use them only to run the service for you.
11. Security
Our security measures are described on the security page. No system is perfectly secure; if we become aware of a breach affecting your data we will tell you without undue delay.
12. Children
DeadlineDesk is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.
13. Changes
If we change this policy materially we will notify account owners by email before the change takes effect.