Privacy Policy
This Privacy Policy explains what information AetherDesk ("AetherDesk," "we," "us," or "our") collects, how we use and protect it, and the choices you have. It applies to our marketing website and to the AetherDesk IT service-desk platform (together, the "Service").
1. Information we collect
We collect only the information we need to operate the Service and respond to you.
Contact-form data
When you submit our contact or early-access form, we collect the information you provide — your name, work email, organization, organization type, approximate number of seats, timeline, and any message you include — along with basic technical metadata such as the IP address of the submission. We use this to respond to your inquiry.
Customer account data
When your organization uses AetherDesk, we process account and directory information needed to provide the Service — for example, user names and email addresses, roles and permissions, and the support requests, tickets, comments, and related records created within your organization's workspace. This information is submitted by you or your organization and is handled on your organization's behalf.
Service telemetry
We collect operational and security telemetry generated as the Service runs — such as request logs, performance and latency metrics, error and audit events, and authentication events. We use this to keep the Service reliable, secure, and performant. We do not use telemetry to build advertising profiles.
2. How we use information
- Responding to inquiries — to reply to contact-form submissions and communicate with you about early access, pilots, and support.
- Providing the Service — to operate, maintain, and improve AetherDesk's features, including triaging, routing, and resolving IT requests for our customers.
- Security and integrity — to authenticate users, enforce access controls, detect and prevent abuse or fraud, monitor for security events, and maintain an audit trail.
- Legal and compliance — to meet legal obligations and enforce our agreements.
We process personal information only for these purposes, or with your consent.
3. AI and your data
AetherDesk's AI features run on Amazon Bedrock within US-based AWS regions. We do not use customer data — including prompts, conversations, tickets, or other content — to train or improve any AI model, and your data is not shared with model providers for their own training. This is consistent with the commitments described on our Trust & Security page. Sensitive values such as credit-card numbers, Social Security numbers, and passwords are automatically detected and redacted before content is stored or sent to the AI.
4. How we store and protect information
The Service is hosted on Amazon Web Services (AWS) in the United States. Data is encrypted in transit and at rest, access is restricted through role-based controls, and administrative activity is logged. While no system can be guaranteed perfectly secure, we design AetherDesk to limit what any single failure or manipulated input could affect.
5. How we share information
We do not sell your personal data, and we do not share it for third-party advertising. We share information only in these limited circumstances:
- Service providers — infrastructure and subprocessors such as AWS that host and operate the Service on our behalf, under obligations to protect the data.
- Within your organization — customer account data is accessible to authorized users of your organization's workspace according to their roles.
- Legal requirements — when required by law, or to protect the rights, safety, and security of AetherDesk, our customers, or the public.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
6. Data retention
We keep personal information only as long as needed for the purposes described here. Contact-form submissions are retained while we evaluate and follow up on your inquiry and for a reasonable period thereafter for our records. Customer account data is retained for the life of your organization's account and deleted or returned within a reasonable period after the account ends, except where we must keep it to meet legal obligations. Operational and security logs are retained on a rolling basis (for example, audit and security events are kept for a limited retention window and then expire automatically).
7. Your choices and privacy requests
You may request to access, correct, or delete personal information we hold about you, or ask questions about this Policy, by emailing contact@aetherdesk.net. For customer account data processed on behalf of an organization, we will direct requests to that organization, which controls the data. We will respond to verified requests within a reasonable time and in accordance with applicable law.
8. Children's privacy
The Service is intended for organizations and their workforce, not for children. We do not knowingly collect personal information from children under 13.
9. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide additional notice where appropriate. Your continued use of the Service after an update means you accept the revised Policy.
10. Contact us
Questions or privacy requests: contact@aetherdesk.net.