What this means in plain language.
This DPA applies EU/UK GDPR to your use of Wendesk. You are the Controller; Wendesk is the Processor. EU SCCs Module 2 included. Breach notification to your lead supervisory authority within 72 hours.
TL;DR — The short version#
- You are the Controller, Wendesk is the Processor; we act only on your documented instructions.
- Sub-processors — published list (13 core entries), 30 days advance notice via in-app banner and email; tenant right to object and terminate.
- Transfers — EU SCCs Module 2 (Controller to Processor) incorporated by reference, plus the UK IDTA, plus the verbatim encryption block.
- Encryption — AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit.
- Breach — Without undue delay; within 72 hours to the lead supervisory authority.
- Audit — documentary evidence today (controls overview, sub-processor list, TOMs documentation); external attestations (SOC 2 Type II, ISO 27001) planned 2026 H2; on-site audit for Enterprise on reasonable notice.
- Return / delete — on contract end, 90-day frozen window after unsubscribe; immediate hard-delete on written request to [email protected]; deletion certificate on request.
1. Definitions#
This Data Processing Addendum (the "DPA") supplements the agreement between you (the "Customer") and FourteenCloud Pvt Ltd, a private limited company incorporated in India with its registered office at Jaipur, Rajasthan, India ("Wendesk"), under which Wendesk provides the Wendesk platform.
"GDPR" — Regulation (EU) 2016/679, the General Data Protection Regulation, together with the equivalent UK GDPR and the Data Protection Act 2018 where applicable.
"Personal Data" — any information relating to an identified or identifiable natural person processed under this DPA.
"Controller" — the entity that determines the purposes and means of processing — the Customer, in respect of personal data the Customer uploads to or generates on the Wendesk platform.
"Processor" — the entity that processes personal data on behalf of the Controller — Wendesk.
"Sub-processor" — any third party engaged by Wendesk to process personal data on behalf of the Controller, in addition to Wendesk.
"EU SCCs" — the Standard Contractual Clauses for the transfer of personal data to third countries under Regulation (EU) 2016/679, as adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"UK IDTA" — the United Kingdom International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner.
Other capitalised terms have the meanings given in the GDPR or in the principal Terms.
2. Roles#
The Customer is the Controller in respect of all personal data the Customer uploads, generates, or routes through the Wendesk platform (the "Customer Personal Data"). Wendesk is the Processor in respect of that Customer Personal Data, and processes it only on the Customer's documented instructions, including instructions concerning transfers of personal data to a third country.
For account-level personal data the Customer provides directly to Wendesk to operate the contract — for example, the workspace owner's contact details, billing contact, security telemetry, and product-usage analytics — Wendesk acts as an independent Controller, with the lawful purposes set out in our Privacy Policy.
3. Subject matter & duration of processing#
The subject matter is the provision of the Wendesk platform to the Customer in accordance with the principal Terms. The duration of the processing is the term of the principal Terms, plus any wind-down period defined therein (default 90-day post-termination grace) during which the Customer may export Customer Personal Data, after which the data is deleted in accordance with section 11 below.
EU data-residency option (Pro / Enterprise): EU Customers on Pro or Enterprise may pin primary storage of Customer Personal Data to AWS Frankfurt (eu-central-1) under a written contract, with EU-only sub-processor lanes for AI inference and ancillary services. Without this pin, the platform default is AWS Mumbai (ap-south-1) with the SCC + UK IDTA safeguards described in §9 applying to the Indian transfer.
4. Nature & purpose of processing#
The nature of the processing comprises the operations strictly necessary to provide the platform: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure to authorised users, alignment, restriction, erasure, and destruction of Customer Personal Data, by automated means, in pursuit of the Customer's instructions.
The purpose of the processing is to enable the Customer to operate its business activities using Wendesk. Wendesk does not use Customer Personal Data for any independent purpose — in particular, Wendesk does not use Customer Personal Data to train AI models for the benefit of any party other than the Customer, nor for advertising, nor for sale to third parties.
5. Categories of personal data and data subjects#
Categories of data subjects whose personal data may be processed under this DPA include the Customer's prospects, leads, customers, end-users, employees, contractors, partners, and any other natural persons whose personal data the Customer chooses to process via Wendesk.
Categories of personal data may include: identification and contact data (name, email, phone, postal address); professional information (role, employer); commercial data (orders, invoices, payment metadata); communication content (message bodies, attachments, transcripts of voice interactions); behavioural data (events, page views, in-app activity); technical data (IP address, device, browser); and any further category the Customer chooses to upload through custom fields and integrations.
The Customer is responsible for not uploading special categories of data (Article 9 GDPR) unless the Customer has confirmed a lawful basis for doing so and has notified Wendesk in writing.
6. Lawful basis (Controller responsibility)#
As Controller, the Customer is responsible for identifying and documenting a lawful basis under Article 6 GDPR (and, where relevant, Article 9) for each processing activity carried out via Wendesk. Wendesk does not determine the lawful basis on the Customer's behalf.
The Customer is also responsible for: providing the Article 13/14 transparency notices to data subjects; obtaining and recording consents where consent is the lawful basis; honouring objections under Article 21; and conducting any data protection impact assessments required by Article 35.
7. Processor obligations#
Wendesk, as Processor, undertakes the obligations set out in Article 28 GDPR. In particular:
- Documented instructions. Wendesk processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, except where required to do otherwise by EU or Member State law.
- Confidentiality. Persons authorised by Wendesk to process the personal data are bound by enforceable confidentiality obligations, whether by contract or by statute.
- Security. Wendesk takes the technical and organisational measures (TOMs) required by Article 32, including AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit, role-based access controls, multi-factor authentication for privileged access, audit logging, and business-continuity / disaster-recovery procedures.
- Sub-processors. Wendesk engages sub-processors only under the conditions set out in section 8.
- Data subject assistance. Wendesk assists the Customer in fulfilling Articles 12–22, 32–36 obligations (see section 10).
- Audits. Wendesk makes available the information necessary to demonstrate compliance with Article 28 and contributes to audits as set out in section 13.
- Notification. Wendesk notifies the Customer of a personal-data breach without undue delay and within 72 hours of confirming the breach, with the information required by Article 33(3).
8. Sub-processors#
The Customer grants a general written authorisation for Wendesk to engage sub-processors to provide the platform, on the conditions set out in Article 28(2) and (4) GDPR.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | Compute, RDS PostgreSQL, S3, KMS, Bedrock | AWS Mumbai (ap-south-1) |
| MongoDB Atlas | Database | Tenant business data (CRM, content, integrations) | AWS Mumbai (ap-south-1) |
| ClickHouse Cloud | Analytics database | High-volume activity logs (non-PII) | AWS Mumbai (ap-south-1) |
| Razorpay | Payments | Card tokenisation, UPI, net-banking, subscription billing | India |
| MSG91 | SMS gateway | OTP and transactional SMS | India |
| Twilio | Voice / messaging | WhatsApp Business API, voice fallback, programmable SMS | USA / Ireland (per region) |
| OpenAI | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Anthropic | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Google AI | AI inference | Gemini completions when routed via quota router | USA / Ireland |
| AWS Bedrock | AI inference | Default LLM provider for India tenants (Claude, Llama, Titan) | AWS Mumbai (ap-south-1) |
| Sarvam AI | AI inference | Indic-language LLM and TTS for vernacular features | India |
| Firebase | Authentication | Phone OTP delivery and Google OAuth for L7 marketplace customers | USA / multi-region |
| Cloudflare | CDN, DNS, WAF | DDoS mitigation, edge cache, custom-domain SSL for white-label tenants | Global edge |
| Typesense | Search | Full-text search index for marketplace and CRM (no PII indexed) | AWS Mumbai (ap-south-1) |
Wendesk gives the Customer at least 30 days advance notice via in-app banner and email; tenant right to object and terminate on reasonable grounds related to data protection. Wendesk imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains liable to the Customer for the sub-processor's performance.
9. International data transfers#
Where Wendesk transfers Customer Personal Data from the EEA, the United Kingdom, or Switzerland to a third country that is not the subject of an adequacy decision, the transfer is governed by the EU SCCs (Module 2: Controller to Processor), incorporated by reference into this DPA. Where the transfer is from the United Kingdom, the SCCs are supplemented by the UK IDTA. Where the transfer is from Switzerland, the SCCs are read with the modifications set out by the Swiss Federal Data Protection and Information Commissioner.
Encryption
All tenant data is protected with AES-256-GCM with AWS KMS-managed Customer Managed Keys; per-tenant DEK; TLS 1.3 in transit. Each tenant is issued a dedicated data encryption key (DEK) wrapped by a Customer Managed Key (CMK) in AWS KMS; integration credentials and AI BYOK keys are encrypted with the same envelope and never logged.
Wendesk applies supplementary technical and organisational measures to protect transferred personal data: the encryption block above; strict role-based access; mandatory MFA; comprehensive audit logging; and a documented procedure for handling third-party government access requests.
EU/EEA hosting: Wendesk's primary region is AWS Mumbai (ap-south-1). Enterprise customers may pin all primary storage of Customer Personal Data to the AWS Frankfurt (eu-central-1) region under a written contract. This is the recommended posture for tightly-regulated EU verticals.
Where you are determines what applies.
Wendesk is built India-first and ships compliance for additional jurisdictions on request or by roadmap. The matrix below is authoritative.
| Region | Regime | Status | How to invoke |
|---|---|---|---|
| India | DPDP Act 2023 | Enforced — default for all Indian tenants | Automatic |
| EU / EEA | GDPR | Available now via Data Processing Addendum | Email [email protected] |
| United Kingdom | UK GDPR + DPA 2018 | Available now via DPA + UK IDTA addendum | Email [email protected] |
| US healthcare | HIPAA | Available now via signed Business Associate Addendum | Email [email protected] |
| UAE | Federal PDPL | Coming 2027 — on roadmap | Register interest at [email protected] |
| Singapore | PDPA | Coming 2027 — on roadmap | Register interest at [email protected] |
10. Data subject rights assistance#
Wendesk assists the Customer, taking into account the nature of the processing, in responding to requests by data subjects exercising their rights under Articles 15–22 GDPR (access, rectification, erasure, restriction, portability, objection, and decisions based solely on automated processing).
Assistance is provided through the in-app Data Subject Request workflow at no additional charge for paid plans — the Customer routes the request, Wendesk performs the technical execution (export, correction, suppression, deletion across primary stores and within 35 days across encrypted backups).
11. Return and deletion#
On termination or expiry of the principal Terms, and at the Customer's choice, Wendesk either (a) returns Customer Personal Data to the Customer in a structured, commonly-used, machine-readable format, or (b) deletes it. The default is a 90-day post-termination grace, after which deletion proceeds automatically across primary stores; encrypted backups rotate out within a further 35 days. A deletion certificate is available on written request.
12. Liability and indemnification#
The liability of each party under this DPA is governed by the limitation-of-liability clauses of the principal Terms, including the aggregate liability cap. Where Article 82 GDPR allocates liability between Controller and Processor, each party indemnifies the other to the extent of its respective responsibility for the harm, in line with Article 82(5).
13. Audit rights#
To enable the Customer to demonstrate compliance with Article 28 GDPR, Wendesk makes available, on written request and under non-disclosure, the documentary evidence currently in place: a controls overview; the current sub-processor list with category, purpose and location; the most recent independent penetration-test summary; and the TOMs documentation. External attestations (SOC 2 Type II and ISO 27001) are planned 2026 H2; until they are issued, we will not cite them in this DPA.
Where the standard documents do not satisfy a specific audit requirement, the Customer may request an on-site or remote audit, conducted by a mutually-agreed independent third-party auditor, on at least 30 days' written notice and during business hours.
14. Standard Contractual Clauses — module selection#
Where the EU SCCs apply under section 9, the parties agree on the following module and option selections:
| Item | Selection |
|---|---|
| Module | Module 2 (Controller to Processor) |
| Clause 7 (docking) | Applicable; further controllers may accede |
| Clause 9(a) (sub-processor authorisation) | Option 2 — general written authorisation, 30 days' prior notice |
| Clause 11 (redress) | Independent dispute resolution body not selected |
| Clause 17 (governing law) | The law of the Republic of Ireland |
| Clause 18 (forum & jurisdiction) | The courts of the Republic of Ireland |
| Annex I.A (parties) | Customer (Controller); Wendesk (Processor) |
| Annex I.B (description) | As set out in sections 3–5 of this DPA |
| Annex I.C (supervisory authority) | The lead supervisory authority of the Customer's establishment in the EU/EEA |
| Annex II (TOMs) | As set out in section 7 and the Security Overview, available on request |
| Annex III (sub-processors) | As published at /sub-processors |
For UK transfers, the UK IDTA is incorporated with the parties, key contacts, dates, and the SCC version mirrored from the EU SCCs above.
15. Effective date & governing law of this DPA#
This DPA is effective from 2026-05-06. It applies for so long as Wendesk processes Customer Personal Data on behalf of the Customer.
This DPA is governed by the law of the Republic of Ireland, save that the SCCs (and the UK IDTA) are governed by their own choice-of-law as set out in section 14. Any updates to this DPA are emailed to workspace admins at least 30 days before they take effect, and the prior version is archived at /policies.
Grievance Officer.
Wendesk's designated grievance contact is reachable at [email protected]. Every grievance is acknowledged within 24 hours and resolved within 30 days (per DPDP Section 8(9) and Section 13). The full grievance form lives at /grievance.
Breach notification.
| Regime | To regulator | To affected person |
|---|---|---|
| DPDP (India) | 72 hours to the Data Protection Board | Without undue delay; via in-app banner + email |
| GDPR (EU/EEA) | Without undue delay; within 72 hours to the lead supervisory authority | Without undue delay where high risk to rights and freedoms |
| HIPAA (US healthcare) | As Business Associate, Wendesk notifies the Covered Entity without unreasonable delay and within 60 days of discovery (45 CFR §164.410); the Covered Entity then notifies HHS, individuals, and (≥500 records in a state) media per §164.404 | Customer-facing notice runs from the Covered Entity; Wendesk supplies forensic detail under the BAA |
Wendesk DPO & Article 27 representative posture: FourteenCloud Pvt Ltd, registered in Jaipur, Rajasthan, India. Data Protection Officer: [email protected]. Legal escalations: [email protected]. Customer support: [email protected]. Article 27 (non-EU controller representative) — current posture: While appointment is in progress, Wendesk does not actively solicit new EU-resident signups for direct services on the marketing site; existing GDPR DPA support for EU-established Customer organisations continues.
Industry-specific obligations.
Wendesk serves 38 industries. The five regimes below trigger specific shared duties between us and the tenant. The rest of the catalog imposes no industry-specific data obligations beyond DPDP / GDPR baseline.
| Industry | Regime | What Wendesk does | What you must do |
|---|---|---|---|
| Real Estate | RERA | RERA project-ID storage, audit log, disclosure templates | Register your project; we don't list on your behalf |
| Food & Beverage | FSSAI | Allergen schema, expiry tracking, label fields | Display your FSSAI licence number on storefront |
| Pharma | CDSCO | Schedule H / H1 / X gating in marketplace; auto-block Schedule X self-fulfilment | Verify retailer licence; upload prescription proof when required |
| Healthcare | HIPAA | BAA on request; PHI auto-redaction before AI inference; 6-year audit retention | Sign BAA; mark PHI fields; obtain patient consent |
| E-commerce / Financial / Insurance | PCI-DSS | No card storage in our systems; card data tokenised by Razorpay; we hold token reference only | Don't paste card data into chat; train staff on PCI scope |