Trust is built on controls you can verify
YundaDesk brings workspace isolation, member permissions, AI execution boundaries, and human approval into daily operations. AI can handle repetitive questions first, while customer data, critical configuration, and high-risk decisions remain subject to permissions and human control.
Workspace and member access
Isolation starts with the workspace
YundaDesk organizes customers, conversations, knowledge, skills, memory, and channel configuration by workspace. Data and configuration are managed separately between workspaces, and members can access only the workspace resources for which they have permission.
Each member receives only the access needed for their role
Team members use individual accounts and receive permissions according to roles such as administrator or agent. Channel, AI, team, and other management capabilities should be reserved for members who need them. Access should be revoked promptly when responsibilities change or a member leaves.
Credentials belong in secure configuration fields
Channel tokens, API keys, mailbox passwords, and store secrets should be submitted only through the configuration fields provided by the product. They should not be placed in knowledge content, Yuna conversations, customer messages, screenshots, or shared documents.
AI cannot bypass real authorization
Permission is checked when an action runs
AI can use only capabilities that are registered, ready, and authorized in the current workspace. Understanding an instruction does not grant execution permission, and a capability description does not replace real authorization.
Humans keep control of high-risk actions
Actions with external effects, including refunds, price changes, and outbound messages, require confirmation or approval. When permission is missing, a tool fails, or information is uncertain, the system should stop, degrade, or hand off rather than invent a successful result.
Learning does not silently change live rules
Agent replies, corrections, and instructions may create learning suggestions. Suggestions remain traceable to their source, are checked or tested, and require confirmation from an authorized member before activation. Active changes can still be reviewed and rolled back.
- Source
- Suggestion
- Review and test
- Human confirmation
- Activation
- Monitoring and rollback
Data and privacy
YundaDesk processes relevant data as needed to provide account management, customer communication, AI assistance, automation, integrations, security, and support. The formal Privacy Policy describes data categories, purposes, sharing, cross-border transfers, retention, and privacy rights in detail.
| Topic | Current rule |
|---|---|
| Purpose | Data is used to provide, maintain, protect, and improve the services described to customers |
| Sale of personal information | YundaDesk does not sell personal information |
| Third-party connections | Data required for a function is exchanged according to customer authorization and configuration |
| Business customer data | Business customers are generally the controllers or business decision-makers for their business data; YundaDesk processes it within the service scope |
| Public model training | Unless separately agreed or authorized, raw enterprise customer data is not used to train public models for other customers |
| Retention | Data is retained for service, contractual, legal, security-audit, and dispute-handling needs, then deleted, anonymized, or otherwise processed as permitted by law |
| Privacy rights | Requests may include access, correction, copying, deletion, restriction, withdrawal of consent, or account closure, subject to applicable law |
Third-party channels and integrations
YundaDesk can connect messaging channels, storefronts, AI services, and other business systems. Each third-party service is independently operated under its own terms and privacy practices.
When a customer authorizes a connection, YundaDesk receives, displays, synchronizes, or returns the data needed for the configured function. Customers can manage or revoke authorizations where supported and remain responsible for applicable account, messaging, marketing, and data-use rules.
Security practices for your team
- Give each member an individual account and avoid sharing administrator accounts.
- Assign roles and permissions according to least privilege.
- Review login records, member status, and external channel authorizations.
- Revoke access and rotate affected credentials when a member leaves.
- Keep passwords and secrets out of knowledge content, chats, screenshots, and shared documents.
- Verify identity and authority before processing customer data export, correction, or deletion requests.
- Preserve timestamps, account details, page URLs, and activity records when reporting suspicious access, permission errors, or exposed credentials.
Related documents
Privacy Policy
Collection, use, sharing, retention, cross-border processing, and privacy rights.
Read the Privacy PolicyTerms of Service
Accounts, services, third-party channels, data responsibilities, and acceptable use.
Read the Terms of ServiceSecurity, permissions, and data boundaries
Security guidance for administrators and agents.
View the security guideFAQ
Does YundaDesk sell personal information?
No. YundaDesk may use cloud infrastructure, messaging channels, AI services, and other technical providers to deliver the service, but data is processed only within the scope required by the relevant functions and rules. See the Privacy Policy for details.
Are customer conversations and knowledge used to train public models for other customers?
Unless separately agreed or authorized, raw enterprise customer data is not used to train public models for other customers. De-identified, anonymized, or aggregated data may be used to evaluate safety, quality, and reliability.
Can AI issue refunds, change prices, or send outbound messages on its own?
These actions have external effects or higher risk. They require the appropriate permission and confirmation or human approval under the product rules. Understanding an instruction does not allow AI to bypass real authorization.
Can every team member see all customer data?
Access is limited by workspace and role permissions. Teams should give each member only the resources needed for their responsibilities.
Can we request data deletion or close an account?
Requests may include access, correction, copying, deletion, withdrawal of consent, or account closure. YundaDesk verifies the requester's identity and authority and handles requests subject to applicable law, contracts, and necessary retention.
How can we request security-review or data-processing information?
Contact YundaDesk with your operating regions, connected channels, product version, and review questions. The team will respond based on the current product and available documentation.
Running a security or data-processing review?
Tell us your operating regions, connected channels, and review questions. We will verify the relevant information against the current product version.