Scope, company and roles
This notice covers the FogiDesk web portal and mobile app, operated by Fogito, CVR 34170339, Inge Lehmanns Gade 10, 6., 8000 Aarhus C, Denmark.
For cases, messages, attachments and other operational workspace data, the controller is the party named for that purpose in the signed onboarding agreement or data processing agreement. This will ordinarily be your organisation, buyer or service provider. Fogito processes that data on the controller's documented instructions and does not decide the controller role from the workspace name, logo or web address.
Fogito is a separate controller for the limited personal data it needs for its own subscription billing, account security, fraud prevention, legal compliance and defence of legal claims.
Data we store
FogiDesk stores the information needed to provide the service and preserve an accountable case history:
- your name, email address and role;
- cases you create, messages and comments you add, and actions recorded under your name;
- photos, documents or other attachments you choose to add to a case;
- technical log data such as sign-in times and device information; and
- device registration and notification preferences when mobile notifications are enabled.
Purposes and legal bases
Operational data is used to run the portal and app, route and follow service cases, document the service delivered and meet the agreement with your organisation. The workspace controller determines the legal basis for that processing and explains any organisation-specific purpose to you.
Where Fogito acts as controller, it relies on:
- performance of a contract for account administration, support and subscription delivery;
- legal obligations for accounting records and other mandatory compliance;
- legitimate interests in account and service security, fraud prevention and the establishment or defence of legal claims; and
- consent for optional SMS communication where consent is required. You may withdraw that consent at any time.
FogiDesk does not sell personal data and does not make decisions about you solely by automated processing. Any optional AI function is suggest-only and requires a human decision.
Recipients, subprocessors and international transfers
Workspace data may be seen by authorised users in the customer, provider or supplier organisations configured for the case. Fogito personnel receive access only where needed to operate, secure or support the service and subject to the support-access controls described below.
Fogito uses service providers to deliver the platform. The supported categories and routes are:
- Hetzner Online GmbH for compute, database and object storage in Germany or Finland;
- Stripe Payments Europe in Ireland where card subscription billing is used; card details are handled by Stripe rather than FogiDesk;
- transactional email and SMS providers operating in the EU for recipient addresses, telephone numbers and message delivery; and
- Anthropic PBC, and Amazon Web Services EMEA SARL where selected, only for an optional AI function enabled by a workspace administrator.
Core operational hosting is in the EU. A direct Anthropic route can involve United States workspace storage and is permitted only after the required data processing agreement and transfer mechanism are recorded. A workspace requiring EU-only AI processing can use only an approved EU Amazon Bedrock route; it does not fall back to a US or global route. AI is off by default, receives redacted case text only and does not receive attachments by default.
The binding, current subprocessor schedule and the exact route for your workspace are supplied with the data processing agreement. Controllers receive notice of a schedule change with the recorded objection period.
Access and security
Access follows your workspace role and the scope assigned by your administrator. Actions are recorded in the case history or audit trail where the service requires accountability.
How long data is kept
Cases, messages and service records are kept for 3 years after a case is closed, unless your company has documented another necessary purpose. Security and sign-in logs are kept for 13 months.
A legal obligation or an active legal hold may require specific records to be retained longer. A deletion request is assessed against those obligations before it is carried out.
When a workspace ends
The workspace becomes read-only and there are normally 90 days to export its data. Active operational data is deleted no later than 30 days after that export window.
Invoices and payments that must be retained under accounting law are isolated and kept for 5 years from the end of the relevant financial year. Backups roll off after at most 35 days.
Your rights
Depending on the processing and applicable law, you may request access, rectification, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing.
For operational workspace data, make the request through your workspace administrator or the controller identified in your organisation's privacy information. The administrator can verify your identity, identify the correct workspace and register the request. For processing where Fogito is controller, or if you cannot identify the correct controller, contact Fogito using the details above. Data-subject requests are generally tracked against a 30-day deadline; restriction and withdrawal of consent are applied promptly where they apply.
See the account and privacy choices page for the practical steps and the difference between removing access and deleting data. If you believe personal data is being processed unlawfully, you may also file a complaint with the Danish Data Protection Agency. The authority recommends contacting the relevant controller first.