Support and CRM
GDPR Zendesk
In an indie stack, Zendesk is used for Customer support and help center. Entity cited: Zendesk, Inc.. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 5, 2026. Verified on October 5, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Zendesk
Yes. Public Data Processing Agreement, concluded with Zendesk, Inc.
Stated role
Annex I of the DPA states that the customer is controller and that Zendesk is processor. Zendesk processes personal data according to the customer's documented instructions.
Personal data
Annex I cites, at the customer's discretion, first name and last name, email, title, position, employer, contact details, date of birth, gender, communications (recordings, messaging, metadata), and customer-service information. Special categories may be included if the customer submits them. Persons cited: employees, customers, prospects, providers, partners, and end users.
Sub-processors of Zendesk
Public sub-processor policy, cited by the DPA. The named table is not copied here.
Transfers outside the EU
Hosting / location
The DPA indicates worldwide processing of Service Data. Encryption at rest is attributed to Amazon Web Services Inc. A Data Center Location Add-On lets you choose where Service Data is hosted. Default region without that option: not disclosed. Transfers to a country without an adequacy decision: a valid certification mechanism, then binding corporate rules, then standard contractual clauses.
EU–United States Data Privacy Framework
The Privacy Notice of 6 May 2026 states that Zendesk, Inc., FutureSimple Inc., and Smooch Technologies US Inc. have certified to the EU-U.S. Data Privacy Framework, the United Kingdom extension, and the Swiss-U.S. DPF. The exact status displayed on the participant entry was not read on 5 October 2026 (page requiring JavaScript). Status: not disclosed.
Cookies
Names of cookies set on a customer's site: not disclosed.
Typical use, written by StackLégal and not by the vendor: Customer support and help center.
History
Last update: October 5, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 5, 2026.
Frequently asked questions
Is Zendesk a processor within the meaning of the GDPR?
Annex I of the DPA states that the customer is controller and that Zendesk is processor. Zendesk processes personal data according to the customer's documented instructions.
What DPA does Zendesk publish?
Yes. Public Data Processing Agreement, concluded with Zendesk, Inc. https://www.zendesk.com/se/company/data-processing-agreement/
Which further sub-processors does Zendesk publish?
Public sub-processor policy, cited by the DPA. The named table is not copied here. https://support.zendesk.com/hc/en-us/articles/4408883061530-Sub-processor-Policy
Where does Zendesk state that it processes data, including outside the EU?
The DPA indicates worldwide processing of Service Data. Encryption at rest is attributed to Amazon Web Services Inc. A Data Center Location Add-On lets you choose where Service Data is hosted. Default region without that option: not disclosed. Transfers to a country without an adequacy decision: a valid certification mechanism, then binding corporate rules, then standard contractual clauses.
Is Zendesk registered under the EU–United States Data Privacy Framework?
The Privacy Notice of 6 May 2026 states that Zendesk, Inc., FutureSimple Inc., and Smooch Technologies US Inc. have certified to the EU-U.S. Data Privacy Framework, the United Kingdom extension, and the Swiss-U.S. DPF. The exact status displayed on the participant entry was not read on 5 October 2026 (page requiring JavaScript). Status: not disclosed.
Which personal data does Zendesk mention?
Annex I cites, at the customer's discretion, first name and last name, email, title, position, employer, contact details, date of birth, gender, communications (recordings, messaging, metadata), and customer-service information. Special categories may be included if the customer submits them. Persons cited: employees, customers, prospects, providers, partners, and end users.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.