Status: draft. Not legal advice. Do not publish before a lawyer has read it.
See README.md in this folder for what to have them check.
Last updated: [DATE] Who this is from: [LEGAL ENTITY NAME] ("TicketModules", "we", "us"), [REGISTERED ADDRESS], company number [COMPANY NUMBER]. Questions or requests: [PRIVACY CONTACT EMAIL]
1. The two different roles we play
This is the part worth reading even if you skip the rest, because it decides who you should be talking to.
If you signed up for TicketModules — you run a support desk here — we are the controller of your data. We decide what to collect about you and why. This policy covers that, and you can exercise your rights against us directly.
If you contacted a company that uses TicketModules — you opened a support ticket about a theme, plugin or product you bought — we are a processor. We are the software their support desk runs on. They decide what is collected and why; we hold it for them and act on their instructions.
That means we are not the right people to ask about your data. If you want a copy of it, or want it deleted, ask the company you contacted — they are the ones who can act on it. If you ask us, we will tell you the same thing and, if you can identify them, point you at them. This is not us passing the buck; it is that we are not permitted to act on their data without their instruction.
The rest of this policy is written from the controller side unless a section says otherwise.
2. What we collect about account holders
When you sign up: your name, email address, a hashed password (we never store the password itself), and your workspace name.
When you subscribe: your billing details. Card numbers never reach our servers — payment is handled by Stripe and we store only their reference to your customer record, the plan you are on, and your invoice history.
When you use the product: the IP address and browser of your sessions, an audit trail of significant actions (who changed a setting, who deleted a ticket, who downloaded an export), and two-factor authentication settings if you enable them.
When you contact us: whatever you write to us, and your address.
3. What we hold on behalf of our customers
This section is descriptive. For everything in it, the company running the desk is the controller and we are the processor — see §1.
Support desks running on TicketModules typically hold: the names and email addresses of people who contact them; the content of tickets, replies and live chats; file attachments; the raw source of inbound emails; a log of outbound emails and whether they were delivered; and, where the desk uses purchase verification, a record of which product a person bought and when their support period ends.
We do not decide any of that, and we do not use it for our own purposes. We do not sell it, we do not advertise against it, and we do not use it to train AI models — see §6.
4. Why we use it, and on what legal basis
| What for | Basis |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Taking payment, invoicing, chasing failed payments | Performance of a contract |
| Security: rate limits, IP bans, audit logs, 2FA | Legitimate interests — running a service that is not trivially abusable |
| Telling you about outages, breaking changes, and things you must act on | Legitimate interests |
| Marketing emails about new features | Consent, and every one has an unsubscribe link |
| Meeting our legal and tax obligations | Legal obligation |
ASSUMPTION: that this is the right basis-by-purpose split for your jurisdiction. Worth confirming — it is the table a regulator reads first.
5. Who else touches it
These are every external service the application actually sends data to. The list is derived from the code rather than written from memory, and it is reviewed when a new integration ships.
| Who | What they get | When |
|---|---|---|
| [HOSTING PROVIDER] | Everything — they host the servers and the database | Always |
| Stripe | Your billing details and email | When you subscribe |
| Mailgun | The content and recipients of outbound email | Whenever the desk sends mail |
| Anthropic | Ticket content, to draft a suggested reply | Only when a desk uses AI drafting |
| Voyage AI | Ticket and knowledge-base text, converted to search vectors | Only when a desk uses AI search |
| Envato | A purchase code, to check it is genuine | Only when a desk verifies Envato purchases |
| Ticksy | Nothing — we only read from them, during an import you start | Only during a migration you run |
| Slack, or your own systems | Ticket events you choose to send | Only if you set up a webhook |
Several of these are optional and off by default. A desk that does not use AI drafting never sends anything to Anthropic or Voyage AI.
We do not sell personal data. We have never sold personal data. There is no version of this business where we sell personal data.
6. AI, specifically
Worth its own section, because it is the question people actually have.
When a desk uses the AI drafting feature, the ticket's text is sent to Anthropic to generate a suggested reply, and to Voyage AI to build the search index that finds relevant help articles. A human on the desk reads and edits the draft before anything is sent to a customer — the AI never replies to anybody on its own.
ASSUMPTION — have your lawyer verify this against your actual contracts, not against a marketing page. The intent is that our agreements with these providers prohibit using your data to train their models and require prompt deletion. If the contract you sign does not say that, this paragraph is false and must be rewritten. It is also the paragraph your customers will quote back at you.
Prompts and responses are kept for 30 days so that a bad draft can be investigated, then deleted automatically.
Any desk can turn AI features off entirely, in which case none of this applies to it.
7. How long we keep things
| What | Kept for |
|---|---|
| Your account and its tickets | As long as your workspace exists |
| AI prompts and responses | 30 days |
| Inbound email that matched no ticket | 30 days |
| Application logs | 14 days |
| Webhook delivery records | 14 days |
| Backups | 14 days, then deleted (see §8) |
| Invoices and payment records | As long as tax law requires — typically 6–7 years |
| Audit logs | As long as the workspace exists — they exist to answer "who did that" long after the fact |
8. Deleting your account — and the honest part about backups
Ask us to delete your workspace and we mark it for deletion, then wait seven days. During those seven days you can cancel, and nothing is lost. This is deliberate: irreversible deletion with no pause is how one bad afternoon becomes an unrecoverable mistake.
After seven days it is irreversible. The workspace, its tickets, its customers and its file attachments are deleted, and any subscription is cancelled so you are not billed again.
Backups are the exception, and we would rather say so than have you find out. We keep encrypted backups for 14 days. A workspace deleted today still exists inside backups taken before today, until those age out. We do not restore a backup to recover deleted data, and the same applies to individual erasure requests under §9. If a backup ever has to be restored for a disaster, we re-apply outstanding deletions afterwards.
Most privacy policies do not mention this. It is true of essentially every service that takes backups at all, and quietly omitting it does not make it less true.
9. Erasing one person
When a desk erases a customer at that person's request, this is exactly what happens — it is worth being precise, because "deleted" is used loosely:
- Their name and email are replaced with an anonymous placeholder.
- The text of everything they wrote is replaced with "erased at the customer's request".
- Their address and the content of emails sent to them are removed from the mail log.
- The record that an email was sent, and when, survives. The desk keeps the fact of the delivery without its contents, because that is what answers a later dispute about whether somebody was told something.
- The erasure itself is recorded in the audit log.
Backups: see §8.
10. Your rights
If we are the controller of your data (§1), you can ask us to give you a copy, correct it, delete it, restrict what we do with it, or object to processing based on legitimate interests. You can withdraw consent for marketing at any time, and every marketing email has a one-click unsubscribe.
Write to [PRIVACY CONTACT EMAIL]. We will respond within one month.
If you are unhappy with how we handled it you can complain to your data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.
ASSUMPTION: no UK or EU representative is appointed. If you have no establishment in the UK/EU but offer the service to people who do, Article 27 may require one. Ask your lawyer directly about this — it is easy to miss and it is a standalone obligation.
11. Security
Passwords are hashed and never stored in a readable form. Traffic is encrypted in transit. Stored credentials for third-party services are encrypted at rest. Backups are encrypted. Access to production systems is limited to people who need it, and significant actions are logged.
We will tell affected customers about a personal data breach without undue delay, and notify the relevant authority within 72 hours where the law requires it.
No system is perfectly secure, and anybody who tells you otherwise is selling something.
12. Children
The service is for businesses. It is not directed at children and we do not knowingly collect data from anyone under 16. If you believe we have, write to [PRIVACY CONTACT EMAIL] and we will delete it.
13. Changes
We will post changes here and update the date at the top. If a change materially affects your rights we will email you before it takes effect rather than relying on you noticing.
14. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS] — [PRIVACY CONTACT EMAIL]