Patronwell for Zendesk: Privacy Policy
Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company
This policy explains what information the Patronwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not Zendesk's or Microsoft's products, which are governed by their own privacy policies.
1. Summary
- The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
- It reads from and writes to two places only: your Zendesk account (as the signed-in agent, with that agent's permissions) and your own Dynamics 365 (Dataverse) environment, signing in with the Microsoft Entra app registration you create.
- Your client secret is stored by Zendesk as a secure setting. Zendesk adds it to the sign-in request on its way to Microsoft (login.microsoftonline.com); the secret is never sent to agents' browsers and Great Work never sees it.
- Microsoft answers the sign-in with a short-lived access token (usually 60 to 90 minutes). The App keeps it in the sidebar's memory only, to read and write your environment, and it is limited to the security role you give the application user. The App refuses to run with an administrator role.
- The App keeps nothing outside Zendesk and Dynamics 365: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.
2. What the App processes, and why
| Data | Why | Where it lives |
|---|---|---|
| The ticket's id, subject and requester (name, email); on user profiles the user's id, name, email; on organization profiles the organization's id, name and domains | To find the matching Dynamics 365 contact or account and to link records back to the ticket | Read from Zendesk into browser memory while the App is open |
| The requester's other email addresses (identities) | To match every address they use | Read from Zendesk into browser memory |
| Dynamics 365 contacts matching those emails, and for the record shown: contact columns (name, emails, phones, job title, owner, dates, extra columns your admin lists), the account (name, number, website, email, phone, city, country, industry, size, revenue, relationship type, owner, extra columns), opportunities (name, value, dates, sales stage, probability, status, owner), recent activities (type, subject, description, status, dates, owner), notes (title, text, author, date), cases (title, number, status, priority, owner, date); accounts matching an email or organization domain | To show the CRM picture to the agent | Read from Dynamics 365 into browser memory while the App is open |
| The application user's id, its security roles and whether it holds the privileges Patronwell uses | To refuse administrator roles, turn off actions the role does not allow and run the setup check | Read from Dynamics 365 into browser memory |
| An action the agent confirms (create a contact, add a note, log a phone call or task) | The purpose of the App | Sent to your Dynamics 365 environment. Notes and activities carry the ticket number and link (unless the agent turns the link off), the ticket subject, the agent's name and what the agent typed; never the ticket conversation |
| An internal note and a tag describing each action, with the agent's name | So your team can see what was done | Written to the ticket in your Zendesk account |
| The installation's plan name and settings (not the secret), the account subdomain, and the agent's id, name, email, role and groups | To show the plan, apply who may take actions and name the agent in notes | Read from Zendesk |
When the sidebar closes, everything it held in memory, including the access token, is gone. What the App wrote stays in your Zendesk account and Dynamics 365 environment under your control and their retention settings.
3. What Great Work LLC receives
Nothing from the App. If you email us for support, we receive what you send (we ask you not to send customer data, passwords or secrets) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.
4. Sharing
We do not sell, rent or share personal information. The App sends data only to your Zendesk account, to Microsoft's sign-in service for your tenant and to the Dataverse Web API of your own environment. We have no subprocessors for the App itself.
5. AI and model training
The App uses no AI services, and no data processed by the App is used to train any model.
6. Security
The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. Microsoft requests go through Zendesk's proxy. The client secret is a secure setting that can only be used in a request body and only for Microsoft hosts (login.microsoftonline.com and your environment's dynamics.com host). The access token the sidebar receives is bounded by the security role of the application user: the setup guide's role reads customer records and creates contacts, notes and activities, and cannot edit or delete accounts, contacts or opportunities or change security. The App checks the role every time it opens and refuses System Administrator, System Customizer and any role that can change security. Admins also choose who may take actions in Zendesk, and every action needs a confirmation. Deleting the client secret in Microsoft Entra ID stops new sign-ins at once; disabling the application user removes its access to the environment. Report a security issue to hello@greatwork.company; we treat it as urgent.
7. Your choices and rights
- Admins choose who may take actions, which actions exist, which extra columns are shown and whether domain matching and cases are on, and can uninstall at any time. Uninstalling deletes the stored secret; delete the client secret and the application user in Microsoft as well. Notes and tags already on tickets, and records created in Dynamics 365, stay until you delete them.
- Requests about personal data in your Zendesk account or Dynamics 365 environment go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
- If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.
8. Changes
We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.