What this means in plain language.
Wendesk's compliance posture across India (DPDP 2023), EU/UK (GDPR DPA), US healthcare (HIPAA BAA), and payments (PCI-DSS). Roles, data rights, breach notification, sub-processing, and Grievance Officer contact in one place.
TL;DR#
- India (DPDP 2023): You are the Data Fiduciary for workspace data; Wendesk is your Data Processor. Data Principal rights SLA: 30 days standard; 7 working days internal target. Breach notification: 72 hours to the Data Protection Board. Grievance Officer: [email protected] — acknowledged within 24 hours, resolved within 30 days.
- EU/EEA/UK (GDPR): You are the Controller; Wendesk is the Processor. Sub-processors: 30 days advance notice via in-app banner and email; tenant right to object and terminate. Encryption: AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit. Breach notification: without undue delay; within 72 hours to the lead supervisory authority. Audit: documentary evidence now; SOC 2 Type II and ISO 27001 planned 2026 H2.
- Primary hosting: AWS Mumbai (ap-south-1). Enterprise customers may pin to AWS Frankfurt (EU) or AWS Bahrain (GCC) under a written contract.
- DPO contact: [email protected] · Fourteen Cloud Pvt Ltd · Jaipur, Rajasthan, India.
Part 1 — India: DPDP Addendum#
Wendesk's posture under the Digital Personal Data Protection Act, 2023. This addendum auto-attaches to the principal Terms for all tenants with India data residency or Indian personal data in scope.
1. Scope & definitions
This Addendum forms part of the agreement between you (the "Customer") and Fourteen Cloud Pvt Ltd, a private limited company incorporated in India with its registered office at Jaipur, Rajasthan, India ("Wendesk", "we", "us"). It applies to personal data we process under the Digital Personal Data Protection Act, 2023 (the "Act") and the rules issued under it.
Definitions:
- "Personal data" — any data about an individual who is identifiable by or in relation to such data, in line with §2(t) of the Act.
- "Data Principal" — the individual to whom the personal data relates — in our context, your end-customer, your staff, or in the case of account data, you yourself.
- "Data Fiduciary" — the entity that determines the purpose and means of processing personal data. The Customer is the Data Fiduciary for workspace data; Wendesk is the Data Fiduciary for the account data the Customer provides directly to us.
- "Data Processor" — an entity that processes personal data on behalf of a Data Fiduciary. Wendesk acts as a Data Processor for all workspace data the Customer uploads.
- "Significant Data Fiduciary" — a Data Fiduciary so notified under §10 of the Act, with additional obligations including DPIAs, audits, and a designated DPO.
Capitalised terms not defined here carry the meanings given in the Act or in our principal Terms.
2. Wendesk's role
For personal data uploaded by the Customer into the Wendesk platform — CRM contacts, lead records, content drafts, message logs, voice-agent recordings, integration credentials, files — Wendesk acts as a Data Processor. We process this data only on the Customer's documented instructions, which are constituted by the configuration the Customer chooses in the platform, the actions the Customer's authorised users take, and any written direction the Customer issues to us.
For personal data the Customer provides directly to Wendesk to operate the account — the workspace owner's contact details, the billing contact, payment metadata, login credentials, security telemetry, and product-usage analytics — Wendesk acts as a Data Fiduciary. The lawful purposes are: providing the service the Customer signed up for, billing, fraud prevention, security, statutory compliance, and service improvement.
3. The Customer's role
The Customer is the Data Fiduciary for personal data of its end-customers, leads, employees, contractors, vendors, and any other third party whose personal data the Customer chooses to upload to its workspace. As Data Fiduciary, the Customer is responsible for: identifying a lawful basis for the processing; obtaining and recording any consents required under the Act; honouring Data Principal rights raised by its end-customers (with our assistance, see section 7); publishing its own privacy notice; and configuring data retention to match its lawful purposes.
Wendesk does not determine the purpose or means of processing this data. We provide a configurable platform; the Customer determines what is collected, from whom, and why.
4. Categories of personal data processed
Depending on which features the Customer enables, the platform may process the following categories of personal data on the Customer's behalf:
- CRM identifiers — names, mobile numbers, email addresses, postal addresses, GST numbers, custom-field values defined by the Customer.
- Conversational content — WhatsApp messages, SMS, email, in-app chat, and any media attached to these messages.
- Voice-agent data — if enabled, audio recordings, transcripts, sentiment classifications, and call metadata for inbound and outbound calls.
- Marketplace activity — storefront browsing, cart, order, and review data of end-customers transacting with the Customer.
- Payment metadata — transaction IDs, payment status, last-four card digits, UPI handle suffix; full card and bank account numbers never enter our systems and are tokenised at the payment gateway.
- Integration data — data synced from third-party apps the Customer connects (e.g. accounting, e-commerce, telephony).
- Industry-specific overlays — e.g. RERA project IDs (real estate), ICD-10 hints (healthcare, where the Customer enables this), HSN codes (e-commerce), FSSAI licence numbers (food & beverage), CDSCO drug-licence references (pharma).
- Aadhaar (UID). Where the Customer chooses to capture Aadhaar numbers in CRM custom fields, Wendesk applies field-level masking automatically — the platform stores only the last 4 digits in plaintext and the remainder is replaced before persistence. Storing full Aadhaar (in any field) is prohibited under the Customer's AUP and the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 §29. Customers requiring Aadhaar verification flows must integrate via DigiLocker; Wendesk never holds the full UID outside that ephemeral verification path.
5. Purpose limitation
Wendesk processes personal data only for the purposes specified in the principal Terms and this Addendum. We do not use Customer-uploaded personal data for advertising, for resale, or to train AI models for the benefit of any party other than the Customer itself. AI inference performed on Customer data is scoped to the Customer's workspace and the model's response is returned to that workspace alone.
Where we use Customer-uploaded data to improve the platform — for example, aggregated, de-identified usage patterns to size infrastructure or to detect novel abuse — the data is anonymised before any analyst sees it, and the result cannot be used to single out any individual or any Customer.
6. Consent management
The Act treats consent as a primary lawful basis for processing personal data. Where the Customer relies on consent, the Customer is responsible for obtaining, recording, and being able to demonstrate that consent — in clear plain language, for specific stated purposes, and freely withdrawable.
To assist the Customer, Wendesk provides: configurable consent banners and consent forms inside the platform; a consent-record store that links each consent grant to the Data Principal record, the purpose, and the timestamp; tools to honour withdrawal of consent (suppress further processing for that purpose); and an audit log that captures every consent-related event.
Consent withdrawal: When a Data Principal withdraws consent through the in-app workflow, Wendesk immediately suppresses further processing for the affected purpose and notifies the Customer. Past lawful processing is not invalidated — the Act, like the GDPR, treats withdrawal as forward-looking.
Notice in plain English and an Indian language — DPDP §5: DPDP §5 requires that the notice given to a Data Principal be available in clear and plain language and in any one of the languages listed in the 8th Schedule of the Constitution. Wendesk delivers consent notices, withdrawal notices, and Data Principal Request acknowledgements in English by default and in the Customer's chosen Indian-language pair (live: Hindi; upcoming: Tamil, Telugu, Marathi, Bengali, Gujarati). The Customer selects the language pair at workspace setup; Wendesk translates only system-generated notices — Customer-authored copy must be supplied in the chosen languages by the Customer.
DPDP Consent Manager interoperability: DPDP §6(1)(b) introduces the Consent Manager — a registered intermediary through which Data Principals manage consents across Data Fiduciaries. Once the Data Protection Board notifies the registration framework and certifies Consent Managers, Wendesk will accept consent attestations issued by registered Consent Managers and route Data Principal Requests through them where the Data Principal has elected to use one. Pending notification, the in-app consent and DPR workflows are the sole route.
7. Data Principal rights
Sections 11 to 14 of the Act grant Data Principals the right to: confirm whether their personal data is being processed and obtain a summary; correct, complete, update, and erase their data; nominate another individual to exercise these rights upon their death or incapacity; and obtain readily available means of grievance redressal.
Wendesk surfaces these rights through an in-app Data Principal Request (DPR) workflow. Our internal SLA is 7 working days; the statutory cap is 30. Wendesk surfaces a parallel workflow for the Customer's own Data Principal rights against Wendesk-as-Fiduciary; route those requests to [email protected].
Grievance Officer.
Wendesk's designated grievance contact is reachable at [email protected]. Every grievance is acknowledged within 24 hours and resolved within 30 days (per DPDP Section 8(9) and Section 13). The full grievance form lives at /grievance.
Where a request is manifestly unfounded or excessive, the Customer may, in consultation with us, charge a reasonable fee or refuse to act, with reasons recorded.
Article 26-equivalent — support staff impersonation logging: When platform Admin Support staff (role L3) act on a Customer workspace at the Customer's request, the session is wrapped in an ImpersonationSession record holding: actor, target tenant, target user, written reason, session start, session end, and every action taken inside the session. The record is immutable, retained 7 years, and surfaced to the Customer in a monthly compliance digest. Customers may request a real-time export of impersonation events at any time via /dsr-request.
8. Personal data breach notification
Section 8(6) of the Act requires Data Fiduciaries to notify the Data Protection Board of India and each affected Data Principal of a personal-data breach. The cross-regime timing matrix is below.
Breach notification.
| Regime | To regulator | To affected person |
|---|---|---|
| DPDP (India) | 72 hours to the Data Protection Board | Without undue delay; via in-app banner + email |
| GDPR (EU/EEA) | Without undue delay; within 72 hours to the lead supervisory authority | Without undue delay where high risk to rights and freedoms |
| HIPAA (US healthcare) | As Business Associate, Wendesk notifies the Covered Entity without unreasonable delay and within 60 days of discovery (45 CFR §164.410); the Covered Entity then notifies HHS, individuals, and (≥500 records in a state) media per §164.404 | Customer-facing notice runs from the Covered Entity; Wendesk supplies forensic detail under the BAA |
Where Wendesk experiences a breach affecting Customer data, we notify the Customer's designated security contact within 72 hours of confirming the breach, in writing, with: the nature of the breach, the categories and approximate number of Data Principals affected, the categories and approximate number of records affected, the likely consequences, the measures taken or proposed to address the breach, and the contact for follow-up. We support the Customer in the Customer's own statutory notification to the Board and to affected Data Principals.
Where the Customer experiences a breach affecting personal data hosted on Wendesk, the Customer must notify us promptly so we can preserve forensic artefacts, scope the impact, and assist with the Customer's notifications.
9. Sub-processing
The Customer authorises Wendesk to engage sub-processors for the purposes of providing the platform — cloud infrastructure, payment processing, transactional email and SMS, AI model inference, telephony, analytics, customer support tooling, and security monitoring. Each sub-processor is bound by a written agreement with confidentiality, security, breach-notification, and data-handling obligations no less protective than those in this Addendum.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | Compute, RDS PostgreSQL, S3, KMS, Bedrock | AWS Mumbai (ap-south-1) |
| MongoDB Atlas | Database | Tenant business data (CRM, content, integrations) | AWS Mumbai (ap-south-1) |
| ClickHouse Cloud | Analytics database | High-volume activity logs (non-PII) | AWS Mumbai (ap-south-1) |
| Razorpay | Payments | Card tokenisation, UPI, net-banking, subscription billing | India |
| MSG91 | SMS gateway | OTP and transactional SMS | India |
| Twilio | Voice / messaging | WhatsApp Business API, voice fallback, programmable SMS | USA / Ireland (per region) |
| OpenAI | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Anthropic | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Google AI | AI inference | Gemini completions when routed via quota router | USA / Ireland |
| AWS Bedrock | AI inference | Default LLM provider for India tenants (Claude, Llama, Titan) | AWS Mumbai (ap-south-1) |
| Sarvam AI | AI inference | Indic-language LLM and TTS for vernacular features | India |
| Firebase | Authentication | Phone OTP delivery and Google OAuth for L7 marketplace customers | USA / multi-region |
| Cloudflare | CDN, DNS, WAF | DDoS mitigation, edge cache, custom-domain SSL for white-label tenants | Global edge |
| Typesense | Search | Full-text search index for marketplace and CRM (no PII indexed) | AWS Mumbai (ap-south-1) |
The full sub-processor list is also published at /sub-processors. Wendesk provides 30 days advance notice via in-app banner and email before engaging any new sub-processor for tenant data. The Customer may object to any new sub-processor on reasonable grounds during the 30-day notice window, and if Wendesk cannot accommodate the objection, the Customer may terminate the affected service.
10. Cross-border transfers
Section 16 of the Act permits transfers of personal data outside India to any country other than those notified by the Central Government as restricted. Wendesk's primary hosting region is AWS Mumbai (ap-south-1) with disaster-recovery in a second Indian region. Some sub-processors operate from outside India.
For every cross-border flow, Wendesk applies one or more of: (i) contractual safeguards in the sub-processor agreement, including India-equivalent data protection clauses; (ii) the encryption posture stated below; (iii) access controls and audit logging that ensure the data cannot be accessed except for the contracted purpose. Enterprise customers may pin all primary storage to India under a written contract.
Encryption
All tenant data is protected with AES-256-GCM with AWS KMS-managed Customer Managed Keys; per-tenant DEK; TLS 1.3 in transit. Each tenant is issued a dedicated data encryption key (DEK) wrapped by a Customer Managed Key (CMK) in AWS KMS; integration credentials and AI BYOK keys are encrypted with the same envelope and never logged.
11. Retention & erasure
Wendesk retains Customer personal data only as long as necessary for the purpose of providing the platform. The default for closed workspaces is a 90-day frozen window after unsubscribe. After the grace period, primary stores are wiped automatically; encrypted backups rotate out within 35 days; a deletion certificate is available on request.
Erasure requests under section 12(3) of the Act are honoured regardless of the default grace period, save for data we must retain to comply with a statutory obligation (for example, billing records held for tax purposes) or to defend a legal claim.
12. Grievance Officer / Data Protection Officer
Under section 8(9) of the Act, every Data Fiduciary must publish the contact details of an individual responsible for answering questions on its behalf. Wendesk has appointed a Grievance Officer who also serves as the Data Protection Officer for India operations.
Fourteen Cloud Pvt Ltd — Grievance Officer. Registered office: Jaipur, Rajasthan, India. Email [email protected] for privacy and data rights; [email protected] for escalations. The full grievance form lives at /grievance; the DSR portal at /dsr-request.
SLA: Acknowledged within 24 hours, resolved within 30 days (per DPDP §8(9) and §13).
If a Data Principal is not satisfied with the response, they may approach the Data Protection Board of India. The Customer (as Data Fiduciary for its end-customers) must publish its own grievance contact — Wendesk surfaces the field in the workspace's privacy-notice template.
13. Significant Data Fiduciary status
Section 10 of the Act empowers the Central Government to notify any Data Fiduciary as a Significant Data Fiduciary based on volume and sensitivity of personal data, risk to electoral democracy, security of the State, public order, and other factors. SDFs carry additional duties: appointing a DPO based in India, periodic Data Protection Impact Assessments, periodic audits by an independent data auditor, and other measures the Government may prescribe.
If the Customer is notified as a Significant Data Fiduciary, our Enterprise plan includes the controls needed to support compliance: a designated DPO contact on our side, evidence packs for independent data audits, DPIA support for high-risk processing flows, in-region data pinning, and elevated audit-log retention. Speak to your account manager or write to [email protected] to engage these.
14. Children's data
Section 9 of the Act defines a child as anyone under the age of 18 and prohibits the processing of children's personal data without verifiable parental consent. The Act also prohibits tracking, behavioural monitoring, and targeted advertising directed at children.
Wendesk does not knowingly process the personal data of children. Where a Customer's service may involve children — for example, an education tenant or a paediatric healthcare clinic — the Customer must enable the in-platform "verifiable parental consent" workflow before sending any communications, and must not configure behavioural-monitoring features on minor records.
15. Effective date & amendments
This Addendum is effective from 2026-05-06. We update it as the Act, the rules under it, and our practices evolve. Material changes are emailed to workspace admins at least 30 days before they take effect, accompanied by a redline diff. Past versions are archived at /policies.
Where this Addendum conflicts with the principal Terms or with the Privacy Policy, this Addendum controls for matters within the scope of the Act. Where it conflicts with a written CustomPlan agreement, the CustomPlan controls.
Part 2 — EU/EEA/UK: GDPR Data Processing Addendum#
For customers based in the EU/EEA or the UK, or any party processing personal data of EU residents on Wendesk. This DPA supplements the principal Terms.
1. Definitions
This Data Processing Addendum (the "DPA") supplements the agreement between you (the "Customer") and Fourteen Cloud Pvt Ltd, a private limited company incorporated in India with its registered office at Jaipur, Rajasthan, India ("Wendesk").
Definitions:
- "GDPR" — Regulation (EU) 2016/679, the General Data Protection Regulation, together with the equivalent UK GDPR and the Data Protection Act 2018 where applicable.
- "Personal Data" — any information relating to an identified or identifiable natural person processed under this DPA.
- "Controller" — the entity that determines the purposes and means of processing — the Customer, in respect of personal data the Customer uploads to or generates on the Wendesk platform.
- "Processor" — the entity that processes personal data on behalf of the Controller — Wendesk.
- "Sub-processor" — any third party engaged by Wendesk to process personal data on behalf of the Controller, in addition to Wendesk.
- "EU SCCs" — the Standard Contractual Clauses for the transfer of personal data to third countries under Regulation (EU) 2016/679, as adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK IDTA" — the United Kingdom International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner.
Other capitalised terms have the meanings given in the GDPR or in the principal Terms.
2. Roles
The Customer is the Controller in respect of all personal data the Customer uploads, generates, or routes through the Wendesk platform (the "Customer Personal Data"). Wendesk is the Processor in respect of that Customer Personal Data, and processes it only on the Customer's documented instructions, including instructions concerning transfers of personal data to a third country.
For account-level personal data the Customer provides directly to Wendesk to operate the contract — for example, the workspace owner's contact details, billing contact, security telemetry, and product-usage analytics — Wendesk acts as an independent Controller, with the lawful purposes set out in our Privacy Policy.
3. Subject matter & duration of processing
The subject matter is the provision of the Wendesk platform to the Customer in accordance with the principal Terms. The duration of the processing is the term of the principal Terms, plus any wind-down period defined therein (default 90-day post-termination grace) during which the Customer may export Customer Personal Data, after which the data is deleted in accordance with section 11 below.
EU data-residency option (Pro / Enterprise): EU Customers on Pro or Enterprise may pin primary storage of Customer Personal Data to AWS Frankfurt (eu-central-1) under a written contract, with EU-only sub-processor lanes for AI inference and ancillary services. Without this pin, the platform default is AWS Mumbai (ap-south-1) with the SCC + UK IDTA safeguards described in §9 applying to the Indian transfer.
4. Nature & purpose of processing
The nature of the processing comprises the operations strictly necessary to provide the platform: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure to authorised users, alignment, restriction, erasure, and destruction of Customer Personal Data, by automated means, in pursuit of the Customer's instructions.
The purpose of the processing is to enable the Customer to operate its business activities using Wendesk. Wendesk does not use Customer Personal Data for any independent purpose — in particular, Wendesk does not use Customer Personal Data to train AI models for the benefit of any party other than the Customer, nor for advertising, nor for sale to third parties.
5. Categories of personal data and data subjects
Categories of data subjects whose personal data may be processed under this DPA include the Customer's prospects, leads, customers, end-users, employees, contractors, partners, and any other natural persons whose personal data the Customer chooses to process via Wendesk.
Categories of personal data may include: identification and contact data (name, email, phone, postal address); professional information (role, employer); commercial data (orders, invoices, payment metadata); communication content (message bodies, attachments, transcripts of voice interactions where the Customer enables the voice agent); behavioural data (events, page views, in-app activity); technical data (IP address, device, browser); and any further category the Customer chooses to upload through custom fields and integrations. The Customer is responsible for not uploading special categories of data (Article 9 GDPR) unless the Customer has confirmed a lawful basis for doing so and has notified Wendesk in writing.
6. Lawful basis (Controller responsibility)
As Controller, the Customer is responsible for identifying and documenting a lawful basis under Article 6 GDPR (and, where relevant, Article 9) for each processing activity carried out via Wendesk. Wendesk does not determine the lawful basis on the Customer's behalf.
The Customer is also responsible for: providing the Article 13/14 transparency notices to data subjects; obtaining and recording consents where consent is the lawful basis (we provide tooling, the Customer makes the choice); honouring objections under Article 21; and conducting any data protection impact assessments required by Article 35. Wendesk supports each of these obligations; we do not perform them in place of the Customer.
7. Processor obligations
Wendesk, as Processor, undertakes the obligations set out in Article 28 GDPR. In particular:
- Documented instructions. Wendesk processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, except where required to do otherwise by EU or Member State law.
- Confidentiality. Persons authorised by Wendesk to process the personal data are bound by enforceable confidentiality obligations, whether by contract or by statute.
- Security. Wendesk takes the technical and organisational measures (TOMs) required by Article 32, including AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit, role-based access controls, SSO and SCIM provisioning, multi-factor authentication for privileged access, audit logging, change management, secure software development lifecycle, vulnerability management, and business-continuity / disaster-recovery procedures.
- Sub-processors. Wendesk engages sub-processors only under the conditions set out in section 8.
- Data subject assistance. Wendesk assists the Customer in fulfilling Articles 12–22, 32–36 obligations (see section 10).
- Audits. Wendesk makes available the information necessary to demonstrate compliance with Article 28 and contributes to audits as set out in section 13.
- Notification. Wendesk notifies the Customer of a personal-data breach without undue delay and within 72 hours of confirming the breach, with the information required by Article 33(3).
8. Sub-processors
The Customer grants a general written authorisation for Wendesk to engage sub-processors to provide the platform, on the conditions set out in Article 28(2) and (4) GDPR.
Wendesk gives the Customer at least 30 days advance notice via in-app banner and email; tenant right to object and terminate on reasonable grounds related to data protection. If Wendesk cannot accommodate the objection — for example, by reassigning the function to a different sub-processor — the Customer may terminate the affected service with a pro-rated refund of fees paid in advance. Wendesk imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains liable to the Customer for the sub-processor's performance.
The full sub-processor list is published at /sub-processors.
9. International data transfers
Where Wendesk transfers Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a third country that is not the subject of an adequacy decision, the transfer is governed by the EU SCCs (Module 2: Controller to Processor), incorporated by reference into this DPA. Where the transfer is from the United Kingdom, the SCCs are supplemented by the UK IDTA. Where the transfer is from Switzerland, the SCCs are read with the modifications set out by the Swiss Federal Data Protection and Information Commissioner.
Wendesk applies supplementary technical and organisational measures to protect transferred personal data: AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit; strict role-based access; mandatory MFA; comprehensive audit logging; and a documented procedure for handling third-party government access requests (challenge through every available legal channel; notify the Customer except where law prohibits).
EU/EEA hosting: Wendesk's primary region is AWS Mumbai (ap-south-1). Enterprise customers may pin all primary storage of Customer Personal Data to the AWS Frankfurt (eu-central-1) region under a written contract, with EU-only sub-processor lanes for inference and ancillary services. This is the recommended posture for tightly-regulated EU verticals.
10. Data subject rights assistance
Wendesk assists the Customer, taking into account the nature of the processing, in responding to requests by data subjects exercising their rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection, and decisions based solely on automated processing).
Assistance is provided through the in-app Data Subject Request workflow at no additional charge for paid plans — the Customer routes the request, Wendesk performs the technical execution (export, correction, suppression, deletion across primary stores and within 35 days across encrypted backups). Where a request is made directly to Wendesk by a data subject of the Customer, Wendesk forwards the request to the Customer without responding, and the response timer runs from receipt by the Customer.
11. Return and deletion
On termination or expiry of the principal Terms, and at the Customer's choice, Wendesk either (a) returns Customer Personal Data to the Customer in a structured, commonly-used, machine-readable format, or (b) deletes it. The default is a 90-day post-termination grace, after which deletion proceeds automatically across primary stores; encrypted backups rotate out within a further 35 days. A deletion certificate is available on written request.
Wendesk may retain Customer Personal Data only to the extent and for the duration required by EU or Member State law — for example, billing records held for tax purposes — and only for the lawful basis identified, subject to appropriate confidentiality and security.
12. Liability and indemnification
The liability of each party under this DPA is governed by the limitation-of-liability clauses of the principal Terms, including the aggregate liability cap. Where Article 82 GDPR allocates liability between Controller and Processor, each party indemnifies the other to the extent of its respective responsibility for the harm, in line with Article 82(5).
Nothing in this DPA limits or excludes a party's liability for matters that cannot, by applicable law, be limited or excluded — including liability for fraud, gross negligence, or wilful misconduct, and including any rights of data subjects under the GDPR that cannot be contractually waived.
13. Audit rights
To enable the Customer to demonstrate compliance with Article 28 GDPR, Wendesk makes available, on written request and under non-disclosure, the documentary evidence currently in place: a controls overview; the current sub-processor list; the most recent independent penetration-test summary; and the TOMs documentation. External attestations (SOC 2 Type II and ISO 27001) are planned 2026 H2; until they are issued, we will not cite them in this DPA.
The Customer may exercise this right once per 12-month period in the ordinary course. Where the standard documents do not satisfy a specific audit requirement, the Customer may request an on-site or remote audit, conducted by a mutually-agreed independent third-party auditor, on at least 30 days' written notice and during business hours, scoped to data-protection compliance and subject to confidentiality.
14. Standard Contractual Clauses — module selection
Where the EU SCCs apply under section 9, the parties agree on the following module and option selections:
| Item | Selection |
|---|---|
| Module | Module 2 (Controller to Processor) |
| Clause 7 (docking) | Applicable; further controllers may accede |
| Clause 9(a) (sub-processor authorisation) | Option 2 — general written authorisation, 30 days' prior notice |
| Clause 11 (redress) | Independent dispute resolution body not selected |
| Clause 17 (governing law) | The law of the Republic of Ireland |
| Clause 18 (forum & jurisdiction) | The courts of the Republic of Ireland |
| Annex I.A (parties) | Customer (Controller); Wendesk (Processor) |
| Annex I.B (description) | As set out in sections 3–5 of this DPA |
| Annex I.C (supervisory authority) | The lead supervisory authority of the Customer's establishment in the EU/EEA |
| Annex II (TOMs) | As set out in section 7 and the Security Overview, available on request |
| Annex III (sub-processors) | As published at /sub-processors |
For UK transfers, the UK IDTA is incorporated with the parties, key contacts, dates, and the SCC version mirrored from the EU SCCs above.
15. Effective date & governing law of this DPA
This DPA is effective from 2026-05-06. It applies for so long as Wendesk processes Customer Personal Data on behalf of the Customer.
This DPA is governed by the law of the Republic of Ireland, save that the SCCs (and the UK IDTA) are governed by their own choice-of-law as set out in section 14. The principal Terms continue to govern all other matters between the parties. Where this DPA conflicts with the principal Terms in respect of personal data processing, this DPA controls. Any updates to this DPA are emailed to workspace admins at least 30 days before they take effect, and the prior version is archived at /policies.
Wendesk's designated grievance contact is [email protected]. Every grievance is acknowledged within 24 hours, resolved within 30 days (per DPDP §8(9) and §13); we apply the same SLA to GDPR enquiries even though the regulation does not mandate this floor.
Wendesk DPO & Article 27 representative posture:
Fourteen Cloud Pvt Ltd, registered in Jaipur, Rajasthan, India. Data Protection Officer: [email protected] Legal escalations: [email protected] Customer support: [email protected]
Article 27 (non-EU controller representative) — current posture: Wendesk acts as Processor for EU-established Customer Controllers; this DPA is the Processor commitment under Article 28 GDPR and is unaffected by Article 27. For Wendesk's own marketing site, where Wendesk acts as Controller for EU-resident visitor data, an Article 27 EU representative is not yet appointed. While appointment is in progress, Wendesk does not actively solicit new EU-resident signups for direct services on the marketing site; existing GDPR DPA support for EU-established Customer organisations continues. Once the representative is appointed, the contact is published on the sub-processors page and announced via the policy-update channel.
DPDP Addendum v2.0 · GDPR DPA v2.0 · Reviewed 2026-05-06 · Effective 2026-05-06 · See all policies at /policies