← Cofferwell

Cofferwell for Zendesk: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Cofferwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or Microsoft's products, which are governed by their own privacy policies.

1. Summary

  • The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
  • It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your own Microsoft Dynamics 365 Business Central environment, signing in with the Microsoft Entra app registration you create.
  • Your client secret is stored by Zendesk as a secure setting. Zendesk adds it to the sign-in request on its way to Microsoft (login.microsoftonline.com); the secret is never sent to agents' browsers and Great Work never sees it.
  • Microsoft answers the sign-in with a short-lived access token (usually 60 to 90 minutes). The App keeps it in the sidebar's memory only, to read and write your Business Central environment, and it is limited to the permission sets you give the app in Business Central, which can never include SUPER.
  • The App keeps nothing outside Zendesk and Business Central: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.

2. What the App processes, and why

DataWhyWhere it lives
The ticket's id, subject, requester (name, email) and organization; on user profiles the user's id, name, email and organization; on organization profiles the organization's idTo find the matching Business Central customerRead from Zendesk into browser memory while the App is open
The requester's other email addresses (identities)To match every address they useRead from Zendesk into browser memory
The organization's name, domains and Cofferwell's customer-number fieldTo show the linked customer, or customers on the organization's domainRead from Zendesk
Business Central companies (name, id)To find the company you configuredRead from Business Central into browser memory
Business Central customers matching those emails, contacts or documents, and for the customer shown: name, number, city, state, country, phone, email, website, salesperson code, balance, overdue amount, total sales, credit limit, currency, payment terms, blocked state; open and recent invoices (number, dates, amounts, status, the customer's PO and order number); open sales orders with item lines (description, quantities ordered and shipped, planned dates); recent shipments with lines (number, date, order, shipping method, ship-to city and country); recent credit memos; customers on the requester's company domain when nothing matchedTo show the account picture to the agentRead from Business Central into browser memory while the App is open
A change the agent confirms (email a posted invoice or credit memo, change the customer's Blocked field)The purpose of the AppSent to your Business Central environment, which emails the document through your own document sending setup or saves the hold
An internal note and a tag describing each Business Central change, with the agent's name and, for holds, the reason the agent typedSo your team can see what was doneWritten to the ticket in your Zendesk account
A Business Central customer number, when an agent links an organizationSo every ticket from that organization shows the customerWritten to an organization field in your Zendesk account
Reply text the agent chooses to insert (order status, open invoices or the balance)To answer the customerPut into the agent's reply editor; the agent decides whether to send it
The installation's plan name and settings (not the secret), the number of agents and admins, the account subdomain, and the agent's id, name, email, role and groupsTo show the plan and check its band, apply who may take actions and name the agent in notesRead from Zendesk

When the sidebar closes, everything it held in memory, including the access token, is gone. What the App wrote stays in your Zendesk account and Business Central environment under your control and their retention settings.

3. What Great Work LLC receives

Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, passwords or secrets) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.

4. Sharing

We do not sell, rent or share personal information. The App sends data only to your Zendesk account, to Microsoft's sign-in service for your tenant and to the Business Central API for your own environment (api.businesscentral.dynamics.com). The requester's email addresses go to your own Business Central only, to find the customer. We have no subprocessors for the App itself.

5. AI and model training

The App uses no AI services, and no data processed by the App is used to train any model.

6. Security

The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Microsoft requests go through Zendesk's proxy. The client secret is a secure setting that can only be used in a request body and only for two fixed Microsoft hosts (login.microsoftonline.com and api.businesscentral.dynamics.com). The access token the sidebar receives is bounded by the permission sets you assign to the app in Business Central: the setup guide's D365 BASIC and D365 READ read data and changes nothing; sending documents and holds need permission sets you add on purpose. Admins also choose who may take actions and who may change holds in Zendesk (nobody, by default), and every change needs a confirmation. Deleting the client secret in Microsoft Entra ID stops new sign-ins at once; setting the app's State to Disabled in Business Central removes its access. Report a security issue to hello@greatwork.company; we treat it as urgent.

7. Your choices and rights

  • Admins choose who may take actions, who may change holds, which actions exist and whether shipments and credit memos are shown, and can uninstall at any time. Uninstalling deletes the stored secret and Zendesk removes Cofferwell's organization field; delete the client secret and the app entry in Microsoft as well. Notes and tags already on tickets stay until you delete them.
  • Requests about personal data in your Zendesk account or Business Central go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
  • If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.

8. Changes

We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.