Introduction
We are committed to protecting your personal data and ensuring transparency in how your information is handled when you interact with our support team.
Our helpdesk runs on Zendesk, and some conversations may be assisted by Zendesk AI Agents – Essential, which use generative AI to provide helpful replies based on our Help Center content.
This article explains how your data is collected, processed, stored, and protected under GDPR.
Data Roles and Responsibilities
We Are the Data Controller
As the organisation offering support, we determine what data is collected and why. GDPR places the responsibility for compliance with us as the data controller.
Zendesk Is the Data Processor
Zendesk processes personal data strictly on our behalf and according to our instructions. They do not decide how your data is used.
What Personal Data Is Collected
Information You Provide
When you contact us, Zendesk may process:
- Your name
- Your email address
- The content of your message
- Attachments you upload
- Technical details (browser, operating system, etc.)
Under GDPR, all of these are considered personal data.
Data Sanitisation and Protection
Zendesk AI automatically excludes fields such as usernames and email addresses from training datasets. Additional natural‑language sanitisation removes identifiable data from any messages used for model improvement. Identifiers such as email addresses or IBANs are replaced with placeholders (e.g., <EMAIL>, <IBAN>).
How Your Data Is Used
Providing Support Services
Your data is used only to:
- Respond to your support request
- Offer self‑service solutions
- Escalate a request to a human agent when necessary
- Improve support workflows internally
AI Agent Essential Usage
Zendesk AI Agents – Essential use generative AI to craft responses based solely on our Help Center content and conversation context. They do not train generative models on customer data.
The model generates a reply in your language but does not store or learn from full conversation transcripts.
No Customer Data Used for Generative Model Training
Zendesk confirms:
- Proprietary machine‑learning models are not generative
- Generative features powered by third‑party LLMs are not trained on Zendesk customer data
- No training datasets are stored in Zendesk’s models
Where Data Is Stored and Processed
Regional Hosting
Zendesk hosts data according to its Regional Data Hosting Policy, based on our account’s configuration. Your personal data remains subject to their Trust Center–level security and privacy commitments.
AI Processing and Cross‑Border Considerations
Some AI features use third‑party LLMs to generate responses. While these models may operate outside the EU:
- They do not retain your information
- They are never trained on your data
- Data is sanitized before processing wherever possible
Data Retention and Deletion
Retention Practices
We retain your data only as long as needed to provide support and fulfill legal obligations. Zendesk enforces standard retention and deletion aligned with their Service Data Deletion Policy.
Right to Erasure (“Right to Be Forgotten”)
Deleting your data is fully supported. Zendesk provides mechanisms for:
- Full deletion (hard delete)
- Data export
- User anonymization
To request deletion, simply contact us.
Who Can Access Your Data
Restricted Access
Only authorised personnel may access your data:
- Our support team
- Zendesk support engineers under strict processor restrictions for troubleshooting
Data Masking
Sensitive customer information may be automatically masked to reduce internal exposure, further minimizing risk.
AI and Third‑Party Data Sharing
AI Agents – Essential
AI Agents rely on our knowledge base and conversation context. They:
- Do not share your data externally for training
- Use sanitized data where applicable
- Do not store raw conversations in models
Third‑Party Services
Some Zendesk features may rely on external partners (e.g., cloud providers). Any processing is covered under Zendesk’s GDPR‑compliant sub‑processor agreements.
Your GDPR Rights
Your Rights Under GDPR
You have the right to:
- Access your personal data
- Request correction
- Request deletion
- Export your data
- Object to certain processing activities
- Restrict processing
We will support your request promptly through Zendesk’s data‑management tools.
Security and Compliance
Robust Security Framework
Zendesk maintains industry‑standard privacy and security practices including:
- Encryption
- Pseudonymization
- Access control
- Data masking
- Regular audits
These measures help ensure your data remains protected throughout your support experience.
Contact Us
If you have questions about how your data is processed or wish to exercise your GDPR rights, you may contact us via our ticket form.
We are committed to ensuring your privacy and protecting your personal information.
Comments
0 comments
Please sign in to leave a comment.