AttachmentFlow

Privacy Policy

Last updated: July 31, 2026

This policy applies to the current public beta of AttachmentFlow and its supporting Cloudflare Worker service.

1. About AttachmentFlow

AttachmentFlow is an independent Zendesk application developed under the SteelLace27 product brand. SteelLace27 is not affiliated with, endorsed by, or operated by Zendesk.

Privacy and security questions can be sent to [email protected].

2. Scope and roles

This policy explains how AttachmentFlow processes information when a Zendesk administrator installs the application or an authorised Zendesk agent uses it to copy attachments between a main ticket and a side conversation.

The organisation operating the relevant Zendesk account determines how its ticket data is collected and used and remains responsible for its Zendesk configuration, users, retention settings, and legal obligations. AttachmentFlow processes ticket and attachment data only to provide the functionality requested by that organisation and its authorised agents.

Depending on the context and applicable law, SteelLace27 may act as a service provider or processor for customer-controlled Zendesk data, and as a controller for limited installation, security, and support information.

3. Information processed

Installation and authentication data

AttachmentFlow may process and store:

  • The customer’s Zendesk subdomain.
  • Zendesk OAuth access and refresh credentials, scopes, status, and expiry timestamps.
  • Cryptographic hashes of AttachmentFlow installation access and refresh tokens.
  • Temporary OAuth states, authorisation flows, authorisation-code hashes, and related timestamps.

AttachmentFlow does not ask customers to provide their Zendesk password or a Zendesk API token.

Ticket, side-conversation, and attachment data

To display available files and complete an agent-requested transfer, AttachmentFlow may temporarily process ticket identifiers, comment or event identifiers, side-conversation identifiers, attachment identifiers, filenames, file types, file sizes, recipient details, and Zendesk-provided file URLs.

Attachment content

When an authorised agent starts a copy operation, the selected attachment is transmitted through AttachmentFlow’s Cloudflare Worker so it can be downloaded from Zendesk and uploaded to the selected destination in Zendesk.

AttachmentFlow does not intentionally store attachment content in its D1 database, object storage, or a separate external archive. The content is processed for the duration of the transfer request. Copies created in Zendesk remain subject to the customer’s Zendesk settings and retention rules.

Internal Zendesk transfer notes

AttachmentFlow may add an internal note to the relevant Zendesk ticket. The note can include visible filenames and technical transfer identifiers, such as source attachment identifiers or a side-conversation identifier. This supports agent visibility and helps the app avoid offering already transferred files again.

These notes are stored inside the customer’s Zendesk account, not in a separate AttachmentFlow transfer-history database.

Operational telemetry

AttachmentFlow maintains limited operational telemetry to operate the service, detect failures, evaluate reliability, and understand public-beta usage. Detailed events may include a technical request identifier, a pseudonymous tenant identifier created from the customer’s Zendesk subdomain using a keyed cryptographic hash, transfer direction, copy outcome, selected and successfully copied file counts, operation duration, a generalised error or warning category where applicable, Worker version, beta cohort, and timestamp.

AttachmentFlow also creates tenant-level daily activity records and monthly usage summaries. These summaries may include first and last use, active days, operation and successful-file totals, direction totals, success, failure, unknown and warning counts, and counts of per-operation safety-limit events.

Operational telemetry and tenant-level summaries do not include attachment content, filenames, ticket or side-conversation content, ticket, comment, side-conversation or attachment identifiers, recipient details, raw Zendesk subdomains, agent email addresses or IDs, persistent agent hashes, OAuth credentials, or Authorization headers. Cloudflare and Zendesk may also process request metadata, security events, and platform logs as part of operating their services.

Support information

If you contact support, we may process your name, email address, organisation, Zendesk subdomain, and any information you voluntarily include in the request. Please do not send passwords, OAuth credentials, or unnecessary ticket content.

4. Purposes and legal bases

AttachmentFlow processes information to:

  • Authenticate authorised installations and maintain OAuth connections.
  • Display available attachments and complete agent-initiated transfers.
  • Create transfer records inside the customer’s Zendesk account.
  • Help reduce incorrect or duplicate actions.
  • Protect, troubleshoot, and maintain the service.
  • Respond to support, privacy, and security requests.
  • Meet applicable legal obligations.
  • Measure public-beta adoption and usage patterns to evaluate reliability, product demand, and appropriate future usage limits.

Where GDPR or similar law applies and SteelLace27 acts as a controller, processing may be based on steps requested before entering into an agreement, performance of an agreement, legitimate interests in operating, securing, evaluating, and improving the beta service, compliance with legal obligations, or consent where consent is specifically requested.

5. What we do not do

  • Sell Zendesk data or personal information.
  • Use ticket or attachment content for advertising or profiling.
  • Share one customer’s Zendesk data with another customer.
  • Use attachment or ticket content to train general AI models.
  • Automatically send files without an authorised agent action.
  • Create a permanent external archive of transferred attachments.

6. Storage and retention

The current automated retention rules are:

  • Attachment content: processed only for the transfer request and not intentionally retained by AttachmentFlow after the request completes.
  • Detailed operational events: retained for up to 90 days and deleted automatically by scheduled cleanup, including events whose tenant-level rollup was not completed.
  • Tenant-level daily activity records and monthly usage summaries: retained for the current UTC month and the preceding 11 UTC months, then deleted automatically.
  • Temporary OAuth states: deleted after use or when older than one day.
  • Temporary OAuth flows and authorisation codes: deleted after use or expiry.
  • Pending tenant records without credentials: deleted when older than one day.
  • Revoked installation-token records: deleted after 30 days.
  • Expired, non-revoked installation-token records: deleted 30 days after the refresh-token expiry date.
  • Revoked tenant records: deleted after 30 days.
  • Active tenant records and Zendesk OAuth credentials: retained while needed to operate an active OAuth connection, unless authorisation is revoked or deletion is requested.

Cleanup runs automatically once per day. Backups, security investigations, legal obligations, or provider-level recovery systems may cause limited residual retention beyond the periods above.

Support correspondence is retained for as long as reasonably necessary to resolve the request, provide follow-up support, protect the service, or meet legal obligations.

7. Service providers and recipients

AttachmentFlow relies on Zendesk for the ticketing platform and APIs, and Cloudflare for serverless hosting, network services, and D1 database infrastructure. These providers process data under their own contracts, security measures, and privacy terms.

Information may also be disclosed where required by law, necessary to protect rights or security, or involved in a lawful reorganisation or transfer of the product. It is not disclosed to independent advertisers or data brokers.

8. International processing

Zendesk and Cloudflare operate internationally. Depending on the customer’s Zendesk environment, provider configuration, and network routing, information may be processed outside the user’s country or outside the European Economic Area.

AttachmentFlow does not currently represent that all processing is confined to the European Union. Where legally required, international transfers are subject to the safeguards and transfer mechanisms made available under the relevant provider arrangements and applicable law.

9. Security

Measures used by AttachmentFlow include OAuth-based authorisation, one-time authorisation-code redemption, request rate limiting for installation OAuth endpoints, HTTPS, cryptographic hashing of installation tokens and operational tenant identifiers, access controls, limited-purpose credentials, privacy-safe structured logs, protected operational monitoring, data minimisation, and scheduled deletion of expired authentication and operational telemetry records.

Cloudflare D1 provides encryption for stored data at rest and for data transferred between Workers, D1, and supported APIs. No online service can guarantee absolute security. Suspected incidents should be reported promptly to [email protected].

10. Uninstalling, revocation, and deletion

A Zendesk administrator can stop agent use by uninstalling AttachmentFlow and can revoke the related authorisation through the available Zendesk administration controls.

Uninstalling the app does not currently guarantee that AttachmentFlow receives an immediate backend uninstall notification. To request deletion of active tenant, authentication, and linked telemetry records, an authorised customer representative should email [email protected] and identify the relevant Zendesk subdomain. We may ask for reasonable proof of authority before acting.

Requests concerning personal data contained in underlying Zendesk tickets should normally be directed to the organisation that controls the relevant Zendesk account.

11. Individual rights

Depending on applicable law, individuals may have rights to request access, correction, deletion, restriction, portability, or objection, and may have the right to complain to a competent data-protection authority. We may need to verify identity, authority, and the relevant customer relationship before responding.

12. Changes

This policy may be updated when AttachmentFlow’s functionality, infrastructure, provider arrangements, or legal obligations change. The current version and update date will be published on this page.

13. Contact

SteelLace27
Email: [email protected]
Website: https://steellace27.com