1How DeskDox accounts are created
DeskDox is published by Zbix Technologies Pvt. Ltd. (“Zbix Technologies”). The mobile app carries the application id com.zbixtechnologies.deskdox.
The app does not create accounts
The released DeskDox mobile app has no sign-up screen or self-service registration. A customer administrator provisions the account in the customer’s DeskDox deployment. Mobile users can then sign in with issued credentials, including a two-factor code when required, or use a pairing QR code created in the DeskDox web application’s Profile → Mobile Access area.
A customer may operate its own server, or may contract Zbix Technologies to host, operate or support it. The customer normally controls account and record decisions. Where Zbix operates the deployment, it may process that customer data as the customer’s contracted processor and act only within the customer’s instructions and the available DeskDox controls.
2What the current product can do
DeskDox distinguishes local app cleanup, access revocation, account deactivation, and account archiving. The currently released server does not provide an administrator action that permanently deletes a user row and all associated personal data.
| Action | Current behavior | Permanent deletion? |
|---|---|---|
| Sign out of the released app | Attempts to revoke the current mobile session and clears the refresh token and device id locally. The saved server address remains so it can be reused. | No |
| Uninstall the app | Removes the app and its local app data from that device; server records remain. | No server-side deletion |
| Revoke a mobile device | Marks its session revoked. The current backend exposes this to the signed-in device owner; it does not expose a separate administrator endpoint for deleting device rows or push tokens. | No — the device row and push token remain stored |
| Deactivate an account | Disables sign-in and can later be reversed. | No |
| Archive an account | Hides the account from normal lists, prevents sign-in and assignment, and preserves the user row so historical references continue to resolve. A system administrator can restore it as deactivated. | No — this is a reversible soft-delete |
| Delete documents | A separate records decision governed by the customer’s retention rules. | Only where an authorized record action permits it |
A request starts an assessment
Submitting this form does not promise permanent erasure. We identify the deployment, verify the requester, involve the customer controller, and report which supported action was approved and performed. If only deactivation or archiving is available, we say so.
3How to make a request
You can use the public request form, email info@zbixtech.com with the subject DeskDox Account Deletion Request, or contact your organization’s DeskDox administrator, IT service desk or privacy contact directly.
Include:
- your full name and organization;
- the DeskDox server address configured in the app;
- your DeskDox username; and
- whether you want mobile access stopped, the account archived, or erasure assessed.
Do not send credentials
Never include a password, one-time passcode, signing key, recovery code or confidential document. Those items are not needed to assess a request.
4Verification and assessment
- We aim to acknowledge the request by email. An acknowledgement is not confirmation that deletion is possible or authorized.
- We verify the deployment and account.We may ask the requester to confirm control of the supplied address and ask the customer’s designated contact to validate the account and the requester’s authority.
- The customer decides what may be changed.For self-managed deployments, the customer performs approved actions. For a Zbix-managed deployment, Zbix may perform a supported action under the customer’s documented instruction.
- We communicate the actual outcome. This may be device-session revocation, deactivation, reversible archiving, correction, or a refusal/limitation where a technical, legal, audit or retention constraint applies.
5Timing
We aim to acknowledge requests and begin routing them to the responsible customer contact promptly. Verification, customer authorization, deployment access and applicable law all affect completion time, so this page does not promise a fixed number of days.
We will aim to keep the requester informed about material delays and to describe the action actually taken. Backup copies follow the retention and recovery arrangements for the specific deployment; no single backup-retention period applies to every DeskDox customer.
6Data outcomes under the current backend
User record and credentials
Archiving keeps the user row, including profile fields, password credential fields and two-factor/TOTP fields. It disables the account and invalidates unused invitation tokens, but it is not a credential purge or anonymization process. The backend has no supported administrator operation that permanently deletes this complete record.
Registered devices and push tokens
A mobile device session can be marked revoked by its signed-in owner. Revocation prevents that session from refreshing, but the device record, refresh-token hash and any stored push token are not deleted by that action. Account archiving also does not currently revoke or delete those mobile-device rows automatically. A request involving a lost device therefore requires deployment-specific assessment and must not be represented as a guaranteed purge.
Audit, workflow and electronic-signature history
The user row is deliberately retained so audit, workflow, approval and e-sign references continue to resolve. The archive action does not anonymize those histories. The customer must assess correction, restriction, retention or any separate data operation under its legal and records-management duties.
Backups
DeskDox backups contain database and file snapshots. The current product can expire whole backup artifacts under settings chosen for a deployment, but it does not remove one person’s records from existing backup artifacts. Customer-managed copies, exports or disaster-recovery systems may have separate controls. Any backup answer must therefore be confirmed for the named deployment.
7Documents are separate from an account request
Stopping access does not delete documents
Signing out, revoking a device, deactivating or archiving an account, and uninstalling the app do not delete documents in the customer’s DeskDox repository.
Ask the customer’s document owner, records manager or privacy contact to assess a specific document. They must consider ownership, other people’s rights, legal holds and applicable retention rules. Zbix Technologies does not make that decision unilaterally when acting as a processor.
8If you only want to stop using the released mobile app
- Use Sign Outin the account card near the bottom of the released app’s dashboard. If the server can be reached, the app asks it to revoke that device session; locally it clears the refresh token and device id. It keeps the server address.
- Use the app’s server reset/change flow if you also want the saved server address cleared.
- Uninstall the app to remove its local app data from that device. This does not change the account or records on the server.
- If the device is unavailable, contact the customer administrator or Zbix support for an assessment. The current backend does not provide a separate administrator device-deletion endpoint, so do not rely on a promise that the device row or push token will be erased.
9Questions about a request
Reply in the same email thread or write to info@zbixtech.com using the subject line DeskDox Account Deletion Request. For related information, see Support and Privacy Policy.