Updated: 7 October 2026
Privacy policy
ALX Desk is an organisation task-management service. Its website, installable web app and Chrome extension connect to the same secured ALX Desk account and database.
Information processed
ALX Desk processes the account information and work content that authorised users provide. This can include names, email addresses, authentication information, task details, progress updates, customer or case references, attachments, photographs and voice notes. Insurance case content may include personal, financial or health information entered by an authorised user.
How the Chrome extension works
- The extension communicates only with https://alx.my to sign in and operate ALX Desk.
- A revocable authentication token and the selected organisation information are stored locally in Chrome so the user can remain signed in.
- Microphone access is requested by the browser only when the user deliberately records a voice note.
- The extension does not read browsing history, page contents or information from unrelated websites.
- The extension does not download or execute remotely hosted program code.
Purpose and disclosure
Information is used only to provide task assignment, reminders, progress tracking, file sharing and related office workflow features. It is not sold, rented, used for advertising or disclosed to unrelated third parties. Data may be processed by infrastructure providers that host or secure the ALX Desk service.
Organisation presence and deliberate sharing
When Desk is open, it records brief connection and recent-activity timestamps to show approximate Active, Away and Last active indicators within the organisation's access rules. Activity events are used locally only to update that indicator; keystrokes, scroll positions, click details and activity on unrelated websites are not collected. Presence records expire after seven days without a connection.
If a user chooses Share or Download, Desk prepares only the selected attachments in their original quality. The user chooses the receiving app and recipient through their device, or attaches downloaded files manually. That deliberate action may send the selected files to a third-party service such as WhatsApp, whose own privacy policy applies. Desk does not confirm delivery or include internal task notes and history in those files.
Storage and retention
Task information remains in the organisation's ALX Desk workspace until an authorised user removes it or the organisation's retention process deletes it. Uploaded files are stored outside the public website directory. The extension's local authentication information is removed when the user signs out or clears the extension's storage.
Access and security
Access is controlled by authenticated accounts, organisation membership and task visibility rules. Restricted users can access only tasks created by or assigned directly to them, while the organisation's manager and authorised Superuser can administer those tasks. Personal tasks remain visible only to their creator. Attachment downloads pass through permission checks instead of being exposed as public file links. Users should report unintended access to their organisation administrator.
Requests and contact
Users may ask their organisation's manager or administrator to correct or remove information that the organisation controls. For service enquiries, use the contact details published at alx.my.
← Back to ALX Desk