Privacy

Requester information is part of the workflow, not an afterthought.

Kantan Desk includes privacy and governance workflows around support content, email addresses, portal access, comments, files, and audit records.

Separation

Public and internal comments stay distinct.

Staff can keep internal notes separate from requester-visible replies, which is essential when support discussion includes operational context.

Access

Secure ticket access for public-form users.

People who submit through the public form can follow an email-based ticket access flow without creating an account first.

Governance workflows

Verified export and erasure workflows are built in.

The product handles data subject requests end-to-end — from intake ticket to confirmation email — without requiring manual database intervention or out-of-band tooling. All personal data held in the support system is in scope.

  • Export support-related records by email address.
  • Anonymize matching users, tickets, comments, files, client records, customer contacts, sessions, and audit metadata where supported by the workflow.
  • Send privacy confirmation emails through the system relay.
  • Review related audit logs and administrative activity.
  • Clear client tags, next actions, and linked relationship fields where the workflow identifies a matching customer record.

What the export covers

Every table that holds personal data is in scope.

The export and anonymization workflows cover the full reach of support-related personal data held in the system. Operators do not need to supplement with manual database queries or out-of-band scripts to satisfy a complete data subject request.

Privacy request · data scope
Data typeExportAnonymization
Tickets and commentsIncludedAuthor anonymized
Uploaded filesIncludedRemoved
Active sessionsIncludedCleared
Client and contact recordsIncludedFields cleared
Audit log referencesIncludedMetadata anonymized

Plain boundary

Private does not mean unreadable to the application.

Kantan Desk is built for private support operations, but ticket content must be readable by the server for ticketing, email, portal, search, automation, and administrative workflows to function.

Third-party processing

One optional feature transmits ticket content externally.

All other processing happens within the operator's own infrastructure. The exception is AI ticket review, which is disabled by default and requires explicit configuration by an admin.

  • When AI review is enabled, the text content of a ticket is sent to the AI provider the admin has configured — DeepSeek, OpenAI, Anthropic, or OpenRouter. The operator holds the API key and chooses the provider.
  • A custom server option is available for operators who need processing to stay within their own infrastructure.
  • Tickets submitted through the inbound API may contain personal data originating from the submitting system. The operator is responsible for ensuring integrations that send data to Kantan Desk comply with applicable obligations.
  • Kantan Desk itself does not operate a cloud service or send data to Sector Processing. The operator runs and controls the instance.
Kantan Desk · PrivacySector Processing LTD