← Staffwell

Staffwell for Zendesk: Privacy Policy

Effective date: October 1, 2026 Publisher: Great Work LLC, 651 N Broad St Suite 206, Middletown, DE 19709, USA Contact: hello@greatwork.company

This policy explains what information the Staffwell app for Zendesk Support (the "App") processes, where it is kept, and your choices. It covers only the App, not the products of Zendesk, HiBob (Bob), Deel or BambooHR, which are governed by their own privacy policies.

1. Summary

  • The App runs in your browser inside Zendesk Support, through the Zendesk Apps framework. Great Work LLC operates no server for it and receives no data from it.
  • It reads from your Zendesk account (as the signed-in agent, with that agent's permissions) and, read-only, from the HR systems you connect (HiBob, Deel, BambooHR) with credentials you create. It never writes to an HR system.
  • Your HR credentials are stored by Zendesk as secure settings. Zendesk adds each one to requests on their way to that HR system's own API host; credentials are never sent to agents' browsers and Great Work never sees them.
  • The App asks the HR systems only for the fields your admin allows the signed-in agent to see, and never for pay or compensation, bank details, national ID, tax, SSN or passport numbers, birth dates, gender, ethnicity, marital status, home addresses, dependents, benefits, or health, medical or leave reasons.
  • The App keeps nothing outside Zendesk and the HR systems: no copies, archives, caches or indexes, no browser storage, no background collection, no analytics or usage statistics, no cookies of its own, no export, and no AI services.

2. What the App processes, and why

DataWhyWhere it lives
The ticket's id and requester (name, email); on user profiles the user's id, name, emailTo find the matching employee recordRead from Zendesk into browser memory while the App is open
The requester's other email addresses (identities)To match every address they useRead from Zendesk into browser memory
From HiBob, Deel or BambooHR, for employees whose work email matches: name, email, and only the fields your admin allows for the agent's role among employment status (with start, termination and leave status), job title, department, manager (name, email), location, start date, employment type, work phone, time zoneTo show the agent who the requester is and whether they are still employed, on leave or not startedRead from the HR system into browser memory while the App is open
Time off for that employee overlapping the next two weeks: dates and, only if your admin allows it, the type for ordinary leave (sick, medical, parental and other personal leave always read "Time off"). HiBob answers this for everyone the service user can see in one list; the App keeps only the requester's entries and discards the rest immediatelyTo say when someone is awayBrowser memory while the App is open
Equipment the HR system records for that employee (Deel IT devices, BambooHR Assets): name, category, serial number, loan date, location; never cost or purchase valueFor IT agents handling device requestsBrowser memory while the App is open
An internal note with the fields an agent picks and confirms, with the agent's name, and the staffwell_note tagSo your team does not have to look the person up againWritten to the ticket in your Zendesk account
The installation's plan name and settings (never the credentials) and the agent's id, name, email, role and groupsTo show the plan, apply who sees the panel and which fields, and name the agent in notesRead from Zendesk

When the sidebar closes, everything it held in memory is gone. Notes the App wrote stay in your Zendesk account under your control and retention settings.

3. What Great Work LLC receives

Nothing from the App. If you email us for support, we receive what you send (we ask you not to send employee data, passwords, tokens or keys) and keep it in our email system for as long as needed to help you, at most 24 months. Billing for the App is handled by Zendesk through Stripe; we receive the subscription records Stripe provides to sellers (your Zendesk domain, the plan, payment status and billing contact), which we keep as long as tax and accounting law requires.

4. Sharing

We do not sell, rent or share personal information. The App sends data only to your Zendesk account, and only requests (never employee data) to the HR systems you connect. We have no subprocessors for the App itself.

5. AI and model training

The App uses no AI services, and no data processed by the App is used to train any model.

6. Security

The App has no server or database to breach. It loads the Zendesk Apps framework from Zendesk's CDN. HR requests go through Zendesk's proxy with each credential in a secure setting scoped to the part of the request it belongs in and sent only to that HR system's API host. Hidden fields are never requested, so they never reach the agent's browser. Because an agent's browser can make requests through the app framework, the HR credential's own permissions are the outer limit: create a read-only service user, token or API key that can see only the fields you show, and restrict the App to the roles or groups that need it. Report a security issue to hello@greatwork.company; we treat it as urgent.

7. Your choices and rights

  • Admins choose which HR systems are connected, who sees the panel, which fields every agent and which fields HR roles see, whether leave types are named, and whether agents may add notes, and can uninstall at any time. Uninstalling deletes the stored credentials; delete the service user, token or API key in the HR system as well. Notes and tags already on tickets stay until you delete them.
  • Requests about personal data in your Zendesk or HR accounts go to your administrator, who controls that data. Questions about this policy: hello@greatwork.company.
  • If you are in the EEA, UK or California, you have rights to access, correct and delete personal information we hold about you (in practice, support emails and billing records). Write to us.

8. Changes

We will post changes here with a new effective date and, for material changes, email the billing contact of each paying account at least 14 days before they apply.