DeskDox Logo
Account & Data Deletion

DeskDox Account & Data Requests

How to request an assessment of a DeskDox account, mobile access and associated data, including the limits of the deletion controls currently available.

Effective date
1 September 2026
Applies to
DeskDox mobile app (Android & iOS)
Request mailbox
info@zbixtech.com

A request and assessment route

Customer administrators provision DeskDox accounts; the mobile app does not create them. This page gives any user a public way to ask for access to be stopped or data erasure to be assessed. The action depends on the named deployment, customer approval, applicable retention duties and the controls the current product actually supports.

Account and mobile access

We verify the deployment and assess which supported access controls can be applied. The current administrator action archives the account; it is not permanent erasure.

Organization documents

Account changes remove or restrict access. They do not automatically delete documents or other organizational records.

History and backups

Audit, workflow and e-sign history remain linked to the archived user record. Backup handling depends on the customer deployment and cannot be promised on a universal timetable.

1How DeskDox accounts are created

DeskDox is published by Zbix Technologies Pvt. Ltd. (“Zbix Technologies”). The mobile app carries the application id com.zbixtechnologies.deskdox.

The app does not create accounts

The released DeskDox mobile app has no sign-up screen or self-service registration. A customer administrator provisions the account in the customer’s DeskDox deployment. Mobile users can then sign in with issued credentials, including a two-factor code when required, or use a pairing QR code created in the DeskDox web application’s Profile → Mobile Access area.

A customer may operate its own server, or may contract Zbix Technologies to host, operate or support it. The customer normally controls account and record decisions. Where Zbix operates the deployment, it may process that customer data as the customer’s contracted processor and act only within the customer’s instructions and the available DeskDox controls.

2What the current product can do

DeskDox distinguishes local app cleanup, access revocation, account deactivation, and account archiving. The currently released server does not provide an administrator action that permanently deletes a user row and all associated personal data.

ActionCurrent behaviorPermanent deletion?
Sign out of the released appAttempts to revoke the current mobile session and clears the refresh token and device id locally. The saved server address remains so it can be reused.No
Uninstall the appRemoves the app and its local app data from that device; server records remain.No server-side deletion
Revoke a mobile deviceMarks its session revoked. The current backend exposes this to the signed-in device owner; it does not expose a separate administrator endpoint for deleting device rows or push tokens.No — the device row and push token remain stored
Deactivate an accountDisables sign-in and can later be reversed.No
Archive an accountHides the account from normal lists, prevents sign-in and assignment, and preserves the user row so historical references continue to resolve. A system administrator can restore it as deactivated.No — this is a reversible soft-delete
Delete documentsA separate records decision governed by the customer’s retention rules.Only where an authorized record action permits it

A request starts an assessment

Submitting this form does not promise permanent erasure. We identify the deployment, verify the requester, involve the customer controller, and report which supported action was approved and performed. If only deactivation or archiving is available, we say so.

3How to make a request

You can use the public request form, email info@zbixtech.com with the subject DeskDox Account Deletion Request, or contact your organization’s DeskDox administrator, IT service desk or privacy contact directly.

Include:

  • your full name and organization;
  • the DeskDox server address configured in the app;
  • your DeskDox username; and
  • whether you want mobile access stopped, the account archived, or erasure assessed.

Do not send credentials

Never include a password, one-time passcode, signing key, recovery code or confidential document. Those items are not needed to assess a request.

4Verification and assessment

  1. We aim to acknowledge the request by email. An acknowledgement is not confirmation that deletion is possible or authorized.
  2. We verify the deployment and account.We may ask the requester to confirm control of the supplied address and ask the customer’s designated contact to validate the account and the requester’s authority.
  3. The customer decides what may be changed.For self-managed deployments, the customer performs approved actions. For a Zbix-managed deployment, Zbix may perform a supported action under the customer’s documented instruction.
  4. We communicate the actual outcome. This may be device-session revocation, deactivation, reversible archiving, correction, or a refusal/limitation where a technical, legal, audit or retention constraint applies.

5Timing

We aim to acknowledge requests and begin routing them to the responsible customer contact promptly. Verification, customer authorization, deployment access and applicable law all affect completion time, so this page does not promise a fixed number of days.

We will aim to keep the requester informed about material delays and to describe the action actually taken. Backup copies follow the retention and recovery arrangements for the specific deployment; no single backup-retention period applies to every DeskDox customer.

6Data outcomes under the current backend

User record and credentials

Archiving keeps the user row, including profile fields, password credential fields and two-factor/TOTP fields. It disables the account and invalidates unused invitation tokens, but it is not a credential purge or anonymization process. The backend has no supported administrator operation that permanently deletes this complete record.

Registered devices and push tokens

A mobile device session can be marked revoked by its signed-in owner. Revocation prevents that session from refreshing, but the device record, refresh-token hash and any stored push token are not deleted by that action. Account archiving also does not currently revoke or delete those mobile-device rows automatically. A request involving a lost device therefore requires deployment-specific assessment and must not be represented as a guaranteed purge.

Audit, workflow and electronic-signature history

The user row is deliberately retained so audit, workflow, approval and e-sign references continue to resolve. The archive action does not anonymize those histories. The customer must assess correction, restriction, retention or any separate data operation under its legal and records-management duties.

Backups

DeskDox backups contain database and file snapshots. The current product can expire whole backup artifacts under settings chosen for a deployment, but it does not remove one person’s records from existing backup artifacts. Customer-managed copies, exports or disaster-recovery systems may have separate controls. Any backup answer must therefore be confirmed for the named deployment.

7Documents are separate from an account request

Stopping access does not delete documents

Signing out, revoking a device, deactivating or archiving an account, and uninstalling the app do not delete documents in the customer’s DeskDox repository.

Ask the customer’s document owner, records manager or privacy contact to assess a specific document. They must consider ownership, other people’s rights, legal holds and applicable retention rules. Zbix Technologies does not make that decision unilaterally when acting as a processor.

8If you only want to stop using the released mobile app

  • Use Sign Outin the account card near the bottom of the released app’s dashboard. If the server can be reached, the app asks it to revoke that device session; locally it clears the refresh token and device id. It keeps the server address.
  • Use the app’s server reset/change flow if you also want the saved server address cleared.
  • Uninstall the app to remove its local app data from that device. This does not change the account or records on the server.
  • If the device is unavailable, contact the customer administrator or Zbix support for an assessment. The current backend does not provide a separate administrator device-deletion endpoint, so do not rely on a promise that the device row or push token will be erased.

9Questions about a request

Reply in the same email thread or write to info@zbixtech.com using the subject line DeskDox Account Deletion Request. For related information, see Support and Privacy Policy.

Submit a request

This public form sends the supplied details to the published address info@zbixtech.com. We aim to acknowledge the request and explain the assessment route; submission does not guarantee permanent deletion.

Use your work email address. We reply to this address only.

Include your DeskDox server address and username, and say what you want deleted.

Never include passwords, one-time passcodes or confidential documents in this form. We use what you submit only to verify and process your deletion request.