← Back to home

Privacy Policy

Effective date: August 12, 2026

This Privacy Policy describes, in general terms, how Desktop Ark ("Desktop Ark," "we," "us," or "our") may handle information in connection with our websites, applications, platforms, and other services (collectively, the "Service"). By accessing or using the Service, you acknowledge the practices described here. This Policy forms part of our Terms of Service. It describes general practices rather than any guaranteed outcome, and it is not a warranty that any particular practice will be followed in any particular instance.

1. Scope and Roles

This Policy applies to information handled by us through the Service. It does not apply to any third party, including any provider, integration, intermediary, or any customer or organization that administers accounts, environments, or access on your behalf, each of which maintains its own practices for which we are not responsible.

Where an organization makes the Service available to you, that organization — not us — decides what information is provided, how the Service is configured and used, who may access it, and how long it is kept. In that arrangement we generally act on that organization's instructions with respect to information submitted through its account, and that organization is responsible for its own handling of that information and for its relationship with you. Where we determine the purposes and means of handling information ourselves — for example, for our own website, billing, security, and business operations — we act on our own behalf.

2. Information We May Collect

Depending on how the Service is accessed and used, the categories of information we may collect include:

  • information you provide directly, such as account, profile, organizational, contact, support, and billing details, and anything you choose to include in a form, message, or request;
  • information generated through use of the Service, such as records of access and activity, session and connection records, settings and configuration, entitlement and licensing records, and support and correspondence history;
  • technical information about the devices, applications, and connections used to access the Service, such as identifiers, characteristics, approximate location derived from connection information, and preference settings;
  • operational, diagnostic, performance, error, and security information used to run, protect, and improve the Service;
  • information received from third parties, such as authentication, payment, fraud-prevention, and business-information providers, and from your organization; and
  • information you submit in connection with an inquiry, application, event, or other interaction with us.

The specific categories, volume, and sources of information collected may vary by user, configuration, and context, and may change over time as the Service changes. We do not seek to collect information beyond what is relevant to operating and supporting the Service and our business.

3. Content You Process Through the Service

The Service may be used to create, store, transmit, or process content that you or your organization control. We generally do not monitor, review, or access such content except as necessary to provide, secure, or support the Service; to investigate a suspected violation of our terms or of law; to respond to a request from you or your organization; or where required by law or legal process. You and your organization are responsible for what is placed into the Service and for the lawfulness of doing so.

4. How We May Use Information

We may use information to: provide, operate, maintain, and administer the Service; authenticate users and manage entitlements; secure the Service and detect, investigate, and prevent fraud, abuse, and security incidents; provide support and respond to inquiries; process transactions and billing; analyze usage and improve, develop, and test the Service and new offerings; communicate with you about the Service, including service, security, and administrative messages; comply with legal and regulatory obligations; establish, exercise, or defend legal claims and enforce our terms; and for any other purpose disclosed to you at the time of collection or otherwise permitted by applicable law.

We may create and use aggregated, anonymized, or de-identified information — which does not identify any individual and is not re-identified by us — for any lawful purpose, including analytics, benchmarking, research, and publication.

5. Legal Bases

Where required by applicable law, we handle information on one or more of the following bases: performance of a contract with you or steps taken at your request; our legitimate interests in operating, securing, supporting, analyzing, and improving the Service and our business, where those interests are not overridden by your interests and rights; compliance with a legal obligation; protection of the vital interests of any person; and, where applicable, your consent, which you may withdraw at any time without affecting the lawfulness of handling before withdrawal.

6. Cookies and Similar Technologies

We and our providers may use cookies, local and session storage, tags, pixels, software development kits, and similar technologies to operate, secure, remember preferences for, measure, and analyze the Service and our communications. Some of these are strictly necessary for the Service to function; others support analytics or measurement.

You may be able to control these technologies through your device, application, or browser settings, or through any preference mechanism we make available. Disabling them may degrade or break parts of the Service. We may not respond to browser "do not track" signals, as no common standard for them has been adopted; where applicable law requires us to honor a specific opt-out preference signal, we will do so.

7. How We May Share Information

We may share information:

  • with service providers, vendors, contractors, and processors that perform functions on our behalf, under obligations to use it only for those functions;
  • with your organization and its administrators, where the Service is made available to you through an organization;
  • with our affiliates, and with professional advisors such as auditors, accountants, insurers, and lawyers;
  • where required or permitted by law, regulation, legal process, or governmental or regulatory request, and to respond to lawful requests from public authorities;
  • where we believe in good faith it is necessary to investigate, prevent, or take action regarding suspected fraud, abuse, security incidents, or illegal activity, or to protect the rights, property, or safety of any person;
  • to establish, exercise, or defend legal claims, and to enforce our terms;
  • in connection with a merger, acquisition, financing, reorganization, insolvency, or sale of all or part of our business or assets, including during diligence, subject to appropriate confidentiality protections;
  • with your consent or at your direction; and
  • in aggregated, anonymized, or de-identified form, without restriction.

We do not sell information in exchange for money. Where any sharing described above constitutes a "sale" or "sharing" under an applicable law, we will honor any opt-out that law provides.

8. Third-Party Services

The Service may link to, interoperate with, or rely on services, content, and infrastructure that we do not control. We are not responsible for the privacy or security practices of any third party, and this Policy does not govern them. Your interactions with any third party are solely between you and that third party and are subject to its terms and policies, which you should review.

9. Retention

We retain information for as long as we consider necessary for the purposes described in this Policy, taking into account the nature and sensitivity of the information, the purposes for which it is handled, the duration of our relationship with you or your organization, applicable legal, tax, accounting, and regulatory requirements, the need to resolve disputes and enforce our agreements, and our legitimate business needs. After that period we may delete, anonymize, or de-identify it. Backups, archives, and logs may persist for a period after deletion from active systems.

Except where applicable law requires otherwise, we are under no obligation to retain, back up, export, or return any information, and you should not rely on the Service as a system of record or as a backup.

10. Security

We use measures we consider commercially reasonable and appropriate to the risk, which may include access controls, encryption in transit, segregation, logging, and personnel confidentiality obligations, intended to protect information against unauthorized access, alteration, disclosure, and destruction. Our measures change over time as the Service and the threat landscape change.

No method of transmission or storage is completely secure, and no system can be guaranteed against every attack, defect, or failure. We cannot and do not guarantee the security of any information. To the maximum extent permitted by applicable law, we are not responsible or liable for any unauthorized access to, or loss, alteration, or disclosure of, information. You are responsible for safeguarding your credentials, devices, and environment, and you provide information at your own risk.

Where an incident affecting information occurs and applicable law requires notification, we will provide notice as and when required by that law.

11. International Handling and Transfers

Information may be handled, transferred to, and stored in one or more jurisdictions other than the one in which you are located, including jurisdictions whose data-protection laws differ from those where you reside and which may permit access by public authorities under their own laws.

Where required by applicable law, we rely on an appropriate legal mechanism for such transfers, which may include an adequacy determination, standard contractual clauses, or another lawful basis. Details of the mechanism applicable to a particular transfer are available on request through the contact details on our website.

12. Your Choices and Rights

(a) Rights that may apply. Depending on your jurisdiction, you may have rights to request access to, correction of, deletion of, or a copy of information about you; to object to or request restriction of certain handling; to withdraw consent where handling is based on consent; to opt out of certain sharing or targeted advertising; and not to be discriminated against for exercising a right.

(b) How to exercise them. Requests may be made through the contact details on our website. We may need to verify your identity and, where applicable, your authority to act for another person, before responding, and we may decline a request that is unfounded, excessive, or that we are legally required or permitted to refuse. We will respond within the time required by applicable law.

(c) Organization-administered accounts. Where the Service is made available to you by an organization, that organization controls the information in its account. Direct your request to that organization; we will refer such requests to it and will assist it as required by applicable law and our agreement with it.

(d) Marketing. Where we send promotional communications, you may opt out at any time using the mechanism provided in the message or by contacting us. You cannot opt out of service, security, billing, and other administrative communications while you use the Service.

(e) Complaints. You may have the right to lodge a complaint with a supervisory or regulatory authority in your jurisdiction. We ask that you contact us first so that we have an opportunity to address your concern.

13. Automated Decision-Making

We may use automated processes for purposes such as security screening, abuse and fraud detection, rate limiting, and prioritization. We do not use automated processing to make decisions producing legal or similarly significant effects concerning you without a lawful basis and, where applicable law requires, appropriate safeguards including the ability to request human review.

14. Children

The Service is intended for organizations and adults and is not directed to children, and we do not knowingly collect information from children. If you believe a child has provided information to us, please contact us and we will take reasonable steps to delete it.

15. Region-Specific Information

Where applicable law in your jurisdiction grants rights or requires disclosures beyond those described above, this Policy is supplemented as required by that law, and that law prevails to the extent of any conflict with this Policy. Additional region-specific information is available on request through the contact details on our website.

16. Changes to This Policy

We may update this Policy at any time in our sole discretion. Changes take effect on posting or as otherwise indicated, and the effective date above will be updated. Where a change materially affects how we handle information and applicable law requires notice, we will provide it. Your continued use of the Service after a change takes effect constitutes acknowledgment of the updated Policy.

17. Contact

Questions, requests, or complaints regarding this Policy may be directed to us through the contact details provided on our website.

This document forms part of the agreement between Desktop Ark and the customer. Where the parties have entered into a separate written agreement executed by authorized representatives of both parties, that agreement controls to the extent of any conflict. Nothing on any other page of this website — including any description, target, figure, or overview — creates a service-level commitment, warranty, representation, or other binding obligation.