GDPR Compliance

GDPR Compliance

Last Update: 02 Dec, 2025

GDPR Compliance at Desku

Desku.io is committed to maintaining GDPR Compliance for Customer Support Software and ensuring that all Processing of personal data within the platform conforms to the requirements of the General Data Protection Regulation (GDPR) and applicable UK and EEA data protection laws.

This page provides an overview of how Desku complies with GDPR, including; Desku.io’s role as a Data Processor, circumstances in which Desku.io acts as a Data Controller, the rights available to individuals under GDPR, and the technical and organizational measures implemented across the platform to support lawful, secure, and transparent data Processing activities.

What Is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law governing the collection, use, storage, and transfer of personal data relating to individuals located in the European Union (EU), the European Economic Area (EEA), and the United Kingdom (UK). It establishes specific obligations for organizations that process personal data and defines the rights of individuals whose data is subject to such Processing.

GDPR is particularly relevant for cloud-based services, including SaaS platforms and Customer Support Software, where personal data may appear within support tickets, communications, Customer profiles, or other operational records created or managed through the platform.

Key GDPR Definitions

Frame 1000009071

“Customer”

A business entity, organization, or authorized individual who accesses or uses the Service. The person creating the account represents that they have authority to bind the Customer.

Frame 1000009071

“Customer Data”

Any data submitted, transmitted, stored, or generated by Customers or their End-Users through use of the Service.

Frame 1000009071

“Data Controller”

The individual or organization that determines the purposes and means of Processing personal data.

Frame 1000009071

“Data Processor”

A service provider, such as Desku.io, that processes personal data on behalf of the Data Controller and in accordance with documented instructions.

Frame 1000009071

“Data Subject”

Data Subject has the meaning given in applicable data protection law (including the GDPR) and refers to an identified or identifiable natural person to whom Personal Data relates.

Frame 1000009071

“Processing”

Any operation performed on Personal Data, whether or not by automated means. Examples include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, transmission, dissemination, restriction, erasure, or destruction.

Frame 1000009071

“Personal Data”

Any information relating to an identified or identifiable natural person, as defined under GDPR.

Frame 1000009071

“Service”

The Desku.io platform and all associated tools, features, and interfaces, including HelpDesk services, Live Chat, OmniChannel messaging, AI functionality, automation tools, analytics, integrations, and administrative components.

Frame 1000009071

“Subprocessor”

A third-party entity engaged by the Data Processor to support the delivery of services and who may process personal data under the same obligations applied to the Processor.

Frame 1000009071

“User”

An individual or business entity that accesses or uses the Service, whether directly or through an authorized representative. This includes all agents, staff members, contractors, and administrators operating under a Customer’s account.

Desku as a Data Processor

Desku.io primarily acts as a Data Processor in relation to the personal data handled through the platform’s Customer Support functions. This includes personal data contained within messages, support tickets, contact records, automation workflows, and other information that Customers choose to store or process when using the Service.

In this capacity, Desku.io processes personal data solely on the documented instructions of the Data Controller and in accordance with applicable contractual, technical, and organizational requirements. Processing activities are limited to what is necessary to provide the platform’s functionality and to maintain the security and operational integrity of the Service.

The following sections provide clarification on the circumstances under which Desku.io acts as a Data Processor versus when it acts as a Data Controller, in order to outline how different categories of personal data are handled in accordance with GDPR.

When Desku Acts as Processor

Desku.io acts as a Data Processor with respect to personal data processed through the platform as part of Customer Support operations. This includes, but is not limited to:

Frame 1000009071
Personal data contained within support conversations and communications.
Frame 1000009071
Information processed as part of ticket management activities.
Frame 1000009071
Data used within automation workflows configured by the Customer.
Frame 1000009071
Personal data stored or managed through contact management features.
Frame 1000009071
Data processed through AI-powered support functionalities, subject to Customer-defined instructions.
Frame 1000009071
HelpDesk operations carried out within Desku.io’s GDPR-compliant support environment.

In all such cases, Desku.io processes personal data exclusively on behalf of, and according to the instructions of, the Data Controller.

When Desku Acts as Controller

Desku.io acts as a Data Controller only in relation to the limited categories of personal data required to operate and manage its own business functions. These activities include:
Frame 1000009071
Personal data processed for account creation, administration, and billing purposes.
Frame 1000009071
Personal data processed for fraud prevention, security monitoring, and risk management.
Frame 1000009071
Personal data processed for optional marketing communications, where such communications are sent in accordance with applicable consent and opt-out requirements.

In all other cases, Desku.io processes personal data strictly on behalf of the Customer in its capacity as a Data Processor.

Responsibilities Under GDPR (Article 28)

When acting as a Data Processor, Desku.io performs its obligations in accordance with Article 28 of the GDPR. These responsibilities include:

Frame 1000009071
Implementing appropriate technical and organizational measures to ensure the security, confidentiality, integrity, and availability of personal data.
Frame 1000009071
Processing personal data only on documented instructions provided by the Data Controller, including with respect to international transfers.
Frame 1000009071
Engaging Subprocessors only under GDPR-aligned contractual terms and conditions, and ensuring that all Subprocessors implement appropriate data protection and security safeguards.
Frame 1000009071
Supporting Data Controllers in meeting their own GDPR obligations, including assistance with Data Subject requests, security requirements, and regulatory compliance where applicable.
Frame 1000009071
Maintaining audit logs, access controls, monitoring systems, and related safeguards necessary to uphold a secure and compliant Processing environment.

Helping Customers Stay Compliant

Desku.io provides configuration options that enable Data Controllers to manage their own GDPR compliance obligations within the platform. Customers may configure:

Frame 1000009071
Data retention settings, including rules governing how long specific categories of personal data is stored.
Frame 1000009071
User permissions to control access to personal data based on defined roles and operational requirements.
Frame 1000009071
Access control settings to limit or govern user activity within the platform.
Frame 1000009071
Security features that support secure handling of personal data.
Frame 1000009071
Ticket-level data handling rules, which allow Customers to apply specific Processing, retention, or deletion criteria to individual support records.

These features assist Data Controllers in implementing their internal data protection policies and GDPR compliance frameworks.

How Desku Complies with GDPR

Desku.io implements technical and organizational measures designed to align the platform with the requirements of the General Data Protection Regulation. These measures apply across all components of the service, including the HelpDesk environment and AI-enabled support features.

The following sections provide a transparent, structured overview of the GDPR compliance framework applied within the platform.

Data Minimization

Desku.io processes only the personal data that is necessary to provide the services requested by the Data Controller. The platform does not collect or retain personal data that is unrelated, excessive, or unnecessary for the operation of its Customer Support and HelpDesk functions.

Purpose Limitation

Desku.io processes personal data only for purposes that are lawful, specified, and directly related to the operation of the platform. These purposes include:

Frame 1000009071

Delivering and maintaining the services requested by the Data Controller.

Frame 1000009071
Performing platform analytics necessary to support functionality, performance, and service improvement.
Frame 1000009071
Supporting security, fraud prevention, and operational integrity of the platform.
Frame 1000009071
Providing Customer Support and responding to service-related inquiries.
Desku.io does not sell personal data, use it for unrelated or incompatible purposes, or process it in any manner that falls outside the documented instructions of the Data Controller.

Lawful Basis for Processing

Desku.io processes personal data only where a lawful basis under the GDPR applies. Depending on the nature of the Processing activity, Desku.io relies on the following lawful bases:

Frame 1000009071
Contractual necessity, where the Processing of personal data is required to provide, maintain, or support the functionality of the platform in accordance with the Customer agreement.
Frame 1000009071
Legitimate interests, including activities necessary for security monitoring, fraud prevention, service integrity, and the protection of the platform and its Users, provided such interests are not overridden by the rights and freedoms of the Data Subject.
Frame 1000009071
Consent, where explicit consent is required for specific Processing activities and where such consent has been freely given by the Data Subject.

Storage Limitation

Desku.io applies defined data retention practices to ensure that personal data is stored only for as long as necessary to fulfil the purposes for which it was collected or to meet applicable legal, regulatory, or contractual requirements. These practices include:

Frame 1000009071

Retaining personal data only for the duration required to operate and support the services provided to the Data Controller.

Frame 1000009071

Applying distinct retention periods to specific categories of data where necessary or appropriate.

Frame 1000009071
Deleting or anonymising personal data following the termination of an account or at the end of the applicable retention period, in accordance with a documented retention schedule.

Security Measures

Desku.io implements layered technical and organizational measures designed to protect personal data and maintain a secure Processing environment. These measures include:

Frame 1000009071
TLS encryption in transit to safeguard data exchanged between clients, servers, and integrated systems.
Frame 1000009071
AES-256 encryption at rest to protect stored personal data.
Frame 1000009071
Strict access control and permission frameworks to limit access to authorized Users only.
Frame 1000009071
Audit logs to record and monitor system activity relevant to security and compliance.
Frame 1000009071
Real-time monitoring and alerting mechanisms to identify anomalous or unauthorized activity.
Frame 1000009071
A secure development lifecycle, incorporating secure coding practices and regular security assessments.

Additional details regarding platform security controls are available on our Security Page. 

Hosting Location

Desku.io operates on a secure, cloud-based infrastructure designed to support reliable and compliant data Processing. The platform incorporates:

Frame 1000009071
Enterprise-grade cloud hosting to ensure stability, security, and performance.
Frame 1000009071
EU data residency options, where applicable, to support Customers with specific geographic or regulatory requirements.
Frame 1000009071

Global redundancy measures to maintain service continuity and availability in the event of localized disruptions.

These hosting arrangements are designed to provide a secure and resilient environment for the Processing of personal data.

AI & Automated Processing

Desku.io incorporates AI-driven features that are designed and operated in accordance with GDPR principles and applicable data protection requirements. All automated Processing within the platform is implemented with safeguards that ensure personal data is handled with the same level of protection applied to human-driven support activities.

To maintain alignment with GDPR obligations:

Frame 1000009071
AI features use anonymized or pseudonymized data, where feasible, to reduce the identifiability of individuals during automated Processing.
Frame 1000009071
Customer Data is not used to train public or shared AI models, and is not retained for model improvement outside the Customer’s own environment.
Frame 1000009071
Automated responses and actions operate strictly according to parameters and rules defined by the Data Controller.
Frame 1000009071
Automated decision-making is not used to produce legal or similarly significant effects on individuals without human involvement, consistent with GDPR Article 22.
Frame 1000009071
Processing carried out by AI components follows the same technical and organizational safeguards applied across the broader Desku.io platform.

These measures ensure that AI-supported workflows function in a secure, transparent, and responsible manner, supporting GDPR-compliant data Processing throughout the automation lifecycle.

Data Processing Agreement (DPA)

Desku.io makes a GDPR-aligned Data Processing Agreement (DPA) available to all Customers that require a contractual framework governing the Processing of personal data. The DPA sets out the terms and conditions under which Desku.io processes personal data on behalf of the Data Controller and describes the technical and organizational measures implemented to ensure its security and confidentiality.

The DPA outlines:

Frame 1000009071
The respective roles and responsibilities of the Data Controller and Desku.io in its capacity as Data Processor.
Frame 1000009071
The security, confidentiality, and data protection safeguards applied across the Desku.io platform.
Frame 1000009071
Requirements and obligations applicable to Subprocessors, including contractual terms and conditions designed to ensure GDPR-aligned protections.
Frame 1000009071
Mechanisms for international data transfers, including the use of Standard Contractual Clauses (SCCs) where relevant.
Frame 1000009071
How documented Processing instructions from the Data Controller are applied and adhered to within Desku.io.

All Subprocessors engaged by Desku.io are required to enter into a GDPR-aligned Data Processing Agreement to ensure consistency of obligations and protections across the entire processing chain.

Customers may request or download the DPA using the link provided on this page.

Your Rights Under GDPR Law

Individuals located in the European Union (EU), the European Economic Area (EEA), or the United Kingdom (UK) have specific rights under the GDPR in relation to the Processing of their personal data. When Desku.io processes personal data as a Data Processor, requests relating to these rights must generally be directed to the Data Controller. However, Desku.io will assist the Data Controller in responding to such requests where required by the regulation or by contract.

The rights available to Data Subjects include:

Frame 1000009071

Right of Access

The right to obtain confirmation as to whether personal data is being processed and, where applicable, to receive a copy of that data.

Frame 1000009071

Right to Rectification

The right to request the correction of inaccurate or incomplete personal data.

Frame 1000009071

Right to Erasure

The right to request the deletion of personal data in circumstances permitted under Article 17 of the GDPR.

Frame 1000009071

Right to Restrict Processing

The right to request the limitation of Processing in certain situations, such as when the accuracy of the data is contested.

Frame 1000009071

Right to Data Portability

The right to receive personal data in a structured, commonly used, and machine-readable format, and to request its transmission to another controller where technically feasible.

Frame 1000009071

Right to Object

The right to object to Processing carried out on the basis of legitimate interests or for direct marketing purposes.

Frame 1000009071

Right to Withdraw Consent

Where Processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of prior Processing.

Frame 1000009071

Right to Lodge a Complaint

The right to submit a complaint to a competent supervisory authority in the EU, EEA, or UK.

How to Submit a Request

Data Subjects may submit requests to exercise their GDPR rights through Desku.io’s designated request channels. Requests may be submitted:

Frame 1000009071
Through the Support Portal (link to be provided on this page), or
Frame 1000009071

By contacting the Desku.io Privacy Team at: support@desku.io

All requests will be handled in coordination with the applicable Data Controller, and Desku.io will provide reasonable assistance as required under the GDPR and relevant contractual obligations.

Subprocessors

Desku.io engages certain third-party service providers (“Subprocessors”) to support the delivery and operation of the platform. Where Subprocessors process personal data on behalf of the Data Controller, Desku.io ensures that:

Frame 1000009071
Each Subprocessor implements appropriate technical and organizational measures consistent with GDPR requirements.
Frame 1000009071
Subprocessors are bound by GDPR-aligned Data Processing Agreements, including confidentiality, security, and data protection obligations equivalent to those imposed on Desku.io.
Frame 1000009071
Subprocessors are independently vetted for their technical, organizational, and security safeguards prior to engagement.
Frame 1000009071
A transparent and regularly updated list of Subprocessors is made available to Customers.

Customers may view the current list of approved Subprocessors using the link provided on this page.

Data Transfers Outside the EU

When personal data is transferred outside the European Union (EU) or the European Economic Area (EEA), Desku.io implements lawful transfer mechanisms and safeguards in accordance with Chapter V of the GDPR. These safeguards include:

Frame 1000009071
EU Standard Contractual Clauses (SCCs) for international data transfers, where applicable.
Frame 1000009071
Supplementary technical and organizational protections to mitigate risks associated with cross-border transfers.
Frame 1000009071
Transfer impact assessments, performed to evaluate the legal and operational context of the destination country.
Frame 1000009071
Data residency options, where available, for Customers with specific regulatory or geographic requirements.

These measures are designed to ensure that international transfers of personal data are conducted in a secure and compliant manner.

Data Breach Policies

Desku.io maintains internal procedures for identifying, assessing, and responding to personal data breaches and other security incidents that may affect the confidentiality, integrity, or availability of personal data. These procedures are designed to support compliance with Articles 33 and 34 of the GDPR.

Desku.io’s commitments include:

Frame 1000009071

Immediate internal escalation of suspected or confirmed security incidents.

Frame 1000009071
Prompt investigation and containment actions to mitigate potential impact.
Frame 1000009071
Notification to affected Customers without undue delay, where a personal data breach has occurred and notification is required under applicable law or contract.
Frame 1000009071
Notification to regulatory authorities, where legally mandated, in accordance with GDPR requirements.
Frame 1000009071
Transparent communication, delivered through email or platform dashboard alerts, where appropriate and consistent with legal obligations.

These policies support a structured and compliant approach to breach management across the Desku.io platform.

Data Protection Officer & Contact Information

For questions regarding GDPR Compliance for Customer Support Software, the Processing of personal data, or Desku.io’s privacy practices, organizations and individuals may contact the Desku.io Data Protection Officer (DPO), where a DPO has been appointed.

Additional information regarding Desku.io’s privacy practices can be found in the Privacy Policy.