Your projects, tasks and client details are yours. Here's how Ctrldesk keeps them safe, who can see them, and the controls you have. The full detail lives in our Privacy Policy.
Encrypted in transit (TLS/HTTPS) and at rest by our hosting providers — on the wire and on disk.
Row-level security scopes every record to your account and organisation. One user cannot read another's projects or clients — enforced at the database, not just the screen.
One click in Settings → Your data & privacy gives you a complete, portable JSON copy of everything, any time.
Delete your account and all its data yourself, whenever you want — no email, no waiting.
Ctrldesk runs on managed, industry-standard infrastructure: a Supabase (PostgreSQL) database for your data and sign-in, and Vercel for hosting the app. Both encrypt data in transit and at rest. Secrets that could read across accounts (the database's privileged key) are never shipped to your browser or stored in our code.
Our website analytics are cookieless and store no personal data and no IP addresses — just coarse, anonymous visit counts. They respect your browser's Do-Not-Track setting. There is no advertising or cross-site tracking.
Ctrldesk is built to follow the principles of the EU/Dutch GDPR (AVG) — data minimisation, encryption, least-privilege access, and giving you real control (export & erase). These practices also map to the core controls of security frameworks like ISO/IEC 27001.
Found something that doesn't look right? Contact us via the contact form or at info@ctrldesk.co. To exercise a data right, use privacy@ctrldesk.co. You can also read the full Privacy Policy and Terms.
Read the full Privacy Policy →