Heartwell for Zendesk: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Heartwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's, Vitally's or Planhat's products, which are governed by their own privacy policies.
1. Summary
- The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
- It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your own Vitally or Planhat account (with the API key or access token you create).
- The key or token is stored by Zendesk as a secure setting. Zendesk adds it to requests on their
way to your tool's API host (
<subdomain>.rest.vitally.io,rest.vitally-eu.ioorapi.planhat.com); it is never sent to agents' browsers and Great Work never sees it. - The App keeps nothing outside Zendesk and your customer success tool: no copies, archives, caches or indexes, no browser storage, no export, no background work, no usage statistics.
2. What the App processes, why, and where it stays
| Data | Why | Where it stays |
|---|---|---|
| The ticket's id, subject, requester (name, email) and organization; on user profiles the user's id, name, email and organization; on organization profiles the organization id | To find the matching account and to link notes back to the ticket | Read from Zendesk into browser memory while the App is open |
| The requester's email addresses (identities) and the organization's name, external id, domains and tags | To match the account by external id, email and company domain, and to show the at-risk flag | Read from Zendesk into browser memory |
| Users or end users with those emails (Vitally: also users at the company domain), the matched account (name, health score, segments or phase, MRR and ARR, renewal, trial and churn dates, CSM and owner, NPS, last activity, the traits or custom fields your admin names), the CSM's and owner's names and emails, the account's latest notes and conversations, open tasks and projects, NPS answers (Planhat) | To show the account's health to the agent | Read from your Vitally or Planhat account into browser memory while the App is open |
| A note the agent confirms (subject, the agent's text, the ticket number and link, the agent's name) | The purpose of the App | Sent to your Vitally or Planhat account; never the ticket conversation |
| The at-risk flag the agent confirms | To let your triggers and views route the account's tickets | The heartwell_at_risk tag on the Zendesk organization |
An internal note and a heartwell_* tag for each action | Audit trail for your team | On the Zendesk ticket |
| The installation's plan name and settings (not the key or token), the count of agents and admins, the account subdomain, and the agent's id, name, email, role and groups | To check the plan, apply who may take actions, name the agent in notes and credit the note to the agent's Vitally user | Read from Zendesk |
When the sidebar closes, everything it held in memory is gone. What the App wrote stays in your Zendesk and customer success accounts under your control and their retention settings.
3. What Great Work LLC receives
Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, passwords, keys or tokens) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.
4. Sharing
We do not sell, rent or share personal information. The App sends data only to your Zendesk account and to the API of your own Vitally or Planhat account. We have no subprocessors for the App itself.
5. AI and model training
The App uses no AI services, and no data processed by the App is used to train any model.
6. Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Requests to your customer success tool go through Zendesk's proxy with the key or token in a secure setting that can only be used for authentication and only for the tool's API host. The App never changes health scores or other fields in your tool; its only write there is a note an agent confirms. Admins choose who may take actions and which actions exist. Report a security issue to hello@greatwork.company; we treat it as urgent.
7. Your choices and rights
- Admins choose who may take actions, which actions exist, which traits are shown and whether the domain match is on, and can uninstall at any time. Uninstalling deletes the stored key or token; revoke it in Vitally or Planhat as well. Notes and tags already written stay until you delete them.
- Requests about personal data in your Zendesk, Vitally or Planhat account go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
- If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.
8. Changes
We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.