WrapDesk privacy
Government Requests Policy
Effective July 21, 2026
This policy explains how WrapDesk handles requests from public authorities for personal information, including information received through connected Facebook, Instagram, WhatsApp Business, and other Meta services.
Scope
This policy applies to requests, demands, orders, notices, warrants, subpoenas, and other compulsory or voluntary requests from government agencies, regulators, law-enforcement bodies, courts, national-security authorities, and other public authorities.
It covers personal information controlled by WrapDesk and information WrapDesk processes for a shop. Where a shop controls the relevant record, WrapDesk will involve that shop when legally permitted and appropriate.
Our commitments
WrapDesk follows these requirements for every public-authority request:
- Require a review of the legality, validity, jurisdiction, authority, and scope of each request before disclosing personal information.
- Challenge or seek clarification of requests that appear unlawful, invalid, unauthorised, vague, or unnecessarily broad where WrapDesk is legally permitted to do so.
- Disclose only the minimum information that WrapDesk reasonably determines is legally required and within the verified scope of the request.
- Document each request, the response, the legal basis and reasoning, the information considered or disclosed, and the people involved in the review and decision.
No employee, contractor, service provider, or workspace user may voluntarily disclose personal information on WrapDesk's behalf outside this process.
Legality review
Every request must be escalated to the WrapDesk data controller. Before any disclosure, WrapDesk verifies the requester's identity and authority, the legal basis relied on, the issuing jurisdiction, the request's authenticity, and whether it is binding on WrapDesk.
WrapDesk reviews the request against applicable law, contractual duties, platform requirements, and the rights of affected people. Independent legal advice will be obtained where the request is uncertain, sensitive, unusually broad, or could create a material risk to users or customers.
Challenging requests
Where legally permitted, WrapDesk will challenge, reject, narrow, or seek clarification of a request that appears unlawful, invalid, improperly authorised, outside the issuing authority's jurisdiction, vague, or broader than reasonably necessary. WrapDesk will not disclose information merely because a requester asks informally or asserts authority without verification.
Data minimisation
If disclosure is legally required, WrapDesk identifies the smallest responsive dataset and limits the disclosure to the verified person, account, time period, data fields, and purpose covered by the request. Unrelated records, credentials, message content, integration tokens, and information about other people or workspaces are excluded unless specifically and lawfully required.
Where practical, WrapDesk uses redaction, aggregation, de-identification, restricted access, and secure transfer methods to reduce the personal information disclosed and the risk created by the disclosure.
Documentation and approval
WrapDesk maintains a restricted register for public-authority requests. The register records the request and requester, dates, jurisdiction, legal authority, scope, affected systems and people, review steps, challenges or clarifications, decision, legal reasoning, approver, response, information disclosed, transfer method, and closure date.
A disclosure requires documented approval from the WrapDesk data controller or an authorised legal adviser. Records are kept securely with access limited to people who need them for legal, security, audit, or response purposes.
User notice and transparency
Where legally permitted, WrapDesk will notify the affected shop or person before disclosure so they can seek advice or exercise available rights. If notice is legally prohibited, WrapDesk will record that restriction and reassess whether notice can be provided when the restriction expires.
WrapDesk may publish aggregated information about government requests where it is lawful and practical to do so, without revealing personal information or compromising security.
Emergency requests
An emergency assertion does not remove the verification, minimisation, approval, or documentation requirements. WrapDesk will assess the claimed emergency, urgency, authority, and risk of harm and will disclose only information reasonably necessary and legally permitted for that emergency. Any expedited response receives a documented follow-up review.
Contact
Public authorities and people with questions about this policy can contact support@wrapdesk.app. Requests sent through another channel must still be escalated through the process described above.
You can also review the WrapDesk Privacy Policy, Terms of Service, and User Data Deletion instructions.