Privacy at OTISA

Privacy Policy

This Privacy Policy explains how OTISA collects, uses, stores, and shares information when you use our website, products, and integrations, including OTISA FollowUp for Zendesk.

Last updated: 27 September 2026

1. Who we are

OTISA develops software and automation tools for customer support teams.

Website: https://otisa.io
Contact: hello@otisa.io

2. Information OTISA FollowUp processes

When OTISA FollowUp is connected to Zendesk, it processes only the information required to provide the service.

This may include:

  • Zendesk account/subdomain information
  • Ticket IDs
  • Ticket status
  • Public ticket comments
  • Ticket subject
  • Requester/customer name and relevant user information
  • Agent identifiers
  • Scheduled follow-up dates and times
  • Follow-up message text
  • Follow-up status, such as scheduled, sent, cancelled, failed, or replied
  • Technical authentication information required to securely connect OTISA to Zendesk

OTISA does not intentionally use private/internal Zendesk notes for AI generation.

3. How we use this information

OTISA uses this information to:

  • Schedule customer follow-ups
  • Automatically send approved follow-up messages through Zendesk
  • Determine whether a customer has replied
  • Cancel remaining unsent follow-ups when appropriate
  • Display follow-up status and activity
  • Generate optional AI-assisted follow-up drafts
  • Maintain and secure the Zendesk integration
  • Troubleshoot and operate the service

OTISA does not sell customer or Zendesk data.

4. AI-assisted follow-up drafts

OTISA FollowUp includes an optional AI drafting feature.

AI generation only occurs when an agent explicitly selects “Generate with AI”. When that happens:

  • OTISA retrieves the relevant public Zendesk ticket conversation
  • Private/internal Zendesk notes are excluded
  • Selected public conversation content is sent to OpenAI through its API
  • The AI produces a suggested follow-up draft
  • The generated draft remains editable by the agent
  • The AI draft is not automatically sent
  • A follow-up is only scheduled after the agent explicitly approves and schedules it

OTISA currently configures these OpenAI requests with:

store: false

OTISA does not use OpenAI during the later automatic-send step. The automatic worker sends only the exact message that the agent previously approved and scheduled.

5. Information OTISA stores

To operate scheduled follow-ups, OTISA stores information such as:

  • Zendesk account identifier
  • Zendesk ticket identifier
  • Scheduled follow-up time
  • Approved follow-up message
  • Agent identifier
  • Follow-up status
  • Timestamps related to sending and customer replies

OTISA also stores authentication credentials required to connect securely to Zendesk. OAuth access and refresh tokens are stored server-side and protected using encryption.

We retain information only for as long as reasonably necessary to provide, maintain, secure, and improve the service, meet legal obligations, and resolve disputes. Retention may vary depending on the type of information and the context in which it is processed.

6. Service providers

OTISA relies on third-party infrastructure and service providers to operate the service. Relevant providers currently include:

  • Zendesk — customer support platform and integration source
  • OpenAI — optional AI follow-up generation
  • Supabase — backend database and infrastructure
  • Railway — backend application hosting

These providers process information only as required to provide their respective services and are subject to their own privacy and data-protection terms.

7. Security

OTISA uses reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. These measures include secure HTTPS connections, server-side credentials, encrypted Zendesk OAuth credentials, and secure Zendesk app settings. Secrets are not exposed in the Zendesk frontend.

No method of transmission or storage can be guaranteed to be completely secure.

8. International processing

OTISA and its service providers may process information in countries other than the country where you live or work. Where required by applicable law, appropriate safeguards are used for international transfers of personal data.

9. Your privacy rights

Depending on applicable law, you may have rights to:

  • Access your personal data
  • Correct inaccurate information
  • Request deletion
  • Restrict or object to certain processing
  • Request portability
  • Withdraw consent where processing relies on consent

Requests can be sent to hello@otisa.io. These rights may be subject to legal limitations, and OTISA may need to verify your identity before responding to a request.

10. Zendesk customers

If you are a customer or end user of an organization that uses OTISA FollowUp, that organization is generally responsible for deciding how your personal information is used within Zendesk. Requests relating to your support ticket data may therefore need to be directed to that organization.

11. Website data

The OTISA website does not currently use analytics, advertising trackers, or non-essential cookies.

If you submit a concept or call request through the website, OTISA collects the information you choose to provide, such as your name, email address, company, message, selected call preferences, and answers entered in the concept form. OTISA uses this information to respond to your request and communicate with you about it. The website sends submitted form details to OTISA through an automated webhook service.

12. Children’s privacy

OTISA’s business software is not intended for use by children, and OTISA does not knowingly target children through this service.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the date shown at the top of this page.

14. Contact

Questions about this Privacy Policy or OTISA’s privacy practices can be sent to:

hello@otisa.io

Website:
https://otisa.io