Processing purposes
EmailDesk processes workspace data to provide inbound mail, outbound delivery, mailbox access, contacts, campaigns, transactional history, DNS checks, protection, bounce and complaint evidence, quota accounting, reports, billing administration, and support.
Depending on the requested function, processing can include message content, headers, attachments, sender and recipient addresses, contact records, domains, provider responses, authentication evidence, audit events, and customer support records.
Mailbox and operational retention
Active workspace and message records remain available according to product behavior, authorized user actions, account status, storage limits, and applicable cleanup rules.
The current Spam/Junk policy permanently deletes messages after 30 days based on the visible EmailDesk message date. Inbox content is not deleted by that Spam/Junk age rule. Security, abuse, delivery, quota, billing, and audit evidence can follow different retention requirements.
Backups and recovery copies
EmailDesk maintains database, mail, deployed-source, and service-configuration backups for recovery. Backup archives are restricted operational data and can contain customer or service information.
The current production configuration retains daily operational backups for five days and weekly recovery bundles for 14 days. A record removed from active storage can remain in an existing backup until that backup leaves its rotation.
Customer and administrator controls
Customer administrators can manage users, permissions, mailboxes, domains, contacts, campaigns, templates, signatures, and related workspace records according to their product access.
Authorized platform administrators can suspend workspaces, enforce limits, transfer domains with authorization, review operational evidence, release held access or mail when appropriate, and support customer data operations.
Processors and transfer boundaries
Configured email gateways, recipient mail systems, mailbox and DNS infrastructure, analytics providers, AI providers, and other service processors receive only the information required for their part of an enabled workflow.
Recipient providers and external DNS services apply their own processing, retention, filtering, and delivery policies. EmailDesk cannot delete records held independently by those systems.
Export and deletion requests
An authorized customer administrator should submit export, correction, or deletion requests through the authenticated support desk. EmailDesk can verify account authority before acting.
Some records may be retained where needed for security, billing, legal obligations, backup recovery, abuse handling, or platform integrity. EmailDesk should explain the applicable boundary during request review.