Access and data minimization
- Authenticate every protected workspace request and enforce authorization on the server.
- Limit customer, payment, recording, and business data by role and location.
- Store only the operational data required for the configured purpose and retention policy.
- Keep secrets, raw card data, bank credentials, KYC documents, and provider credentials out of ordinary application fields and logs.
Provider-hosted sensitive information
Stripe-hosted or embedded Stripe surfaces collect payment and connected-account identity information. Authentication providers handle credentials and OAuth. Telephony and messaging providers deliver calls and messages. NevoDesk stores the identifiers, permissions, status, and evidence needed to coordinate the business workflow.
AI and customer data
Service data is used to operate the requested NevoDesk functions and follows the published Privacy Policy. NevoDesk does not use service data to train shared foundation models unless the customer expressly opts in under the applicable terms.
Business responsibilities
The business is responsible for lawful notices, recording consent, marketing consent, content, employment and routing policies, services, prices, taxes, customer commitments, dispute evidence, and the actions of authorized users. NevoDesk provides controls and records but does not replace legal, tax, medical, financial, or emergency advice.
This article is part of the same maintained knowledge corpus used by NevoGuide. Live provider evidence and saved workspace configuration remain authoritative for your account’s current operational state.