Last updated July 27, 2026
This page describes how BotDesk protects the data businesses and their visitors trust us with, and exactly what we do when something goes wrong. It applies to everyone who works on BotDesk.
Our commitment: if a personal data breach affects a business's data, we notify that business without undue delay and within 72 hours of becoming aware of it — including when we are still investigating, because a partial picture delivered on time is more useful than a complete one delivered late.
Anything suspected is reported immediately to security@botdesk.studio. Reports from outside — researchers, customers, providers — go to the same address and are treated with the same urgency. We do not take legal action against good-faith security researchers who report a finding privately and give us a reasonable chance to fix it.
Within 24 hours of a report we establish what happened, what data and whose data could be involved, whether it is still ongoing, and how severe it is. If we cannot rule out access to personal data, we proceed as though it occurred.
Stopping the bleeding comes before diagnosis. Depending on the incident that means revoking or rotating the affected credentials, disabling the affected endpoint or feature, or taking the service offline. Rotating a connected-store token is always safe: the merchant simply reconnects.
Affected businesses are told within 72 hours by email, covering what happened, which data was involved, what we have done, what we recommend they do, and who to contact. Where a business is the controller of the affected personal data, we support them in notifying their own customers and any regulator. Regulators are notified where the law requires it.
We restore service from a known-good state, using backups where required, and confirm the vulnerability is actually closed rather than merely quiet.
Within two weeks of resolution we write up the timeline, the root cause, and the specific changes that prevent a recurrence — and, wherever the failure is one a test could catch, we add that test. Fixes are tracked to completion rather than closed with the incident.
Email security@botdesk.studio with enough detail to reproduce the issue. We aim to acknowledge within one business day and to keep you updated until it is resolved. Please do not access, modify, or retain data belonging to anyone else while investigating.
BotDesk has not yet undergone a third-party security audit or certification. An independent review is planned before public app-store distribution. We would rather say so plainly than imply a certification we do not hold.
We update this page as our practices change and revise the date above.