GDPR Compliance

GDPR Compliance

Last Update: 02 Dec, 2025

GDPR Compliance at Desku

Desku.io is committed to maintaining GDPR Compliance for Customer Support Software and ensuring that all Processing of personal data within the platform conforms to the requirements of the General Data Protection Regulation (GDPR) and applicable UK and EEA data protection laws.

This page provides an overview of how Desku complies with GDPR, including; Desku.io’s role as a Data Processor, circumstances in which Desku.io acts as a Data Controller, the rights available to individuals under GDPR, and the technical and organizational measures implemented across the platform to support lawful, secure, and transparent data Processing activities.

What Is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law governing the collection, use, storage, and transfer of personal data relating to individuals located in the European Union (EU), the European Economic Area (EEA), and the United Kingdom (UK). It establishes specific obligations for organizations that process personal data and defines the rights of individuals whose data is subject to such Processing.

GDPR is particularly relevant for cloud-based services, including SaaS platforms and Customer Support Software, where personal data may appear within support tickets, communications, Customer profiles, or other operational records created or managed through the platform.

Key GDPR Definitions

List dot icon

“Customer”

A business entity, organization, or authorized individual who accesses or uses the Service. The person creating the account represents that they have authority to bind the Customer.

List dot icon

“Customer Data”

Any data submitted, transmitted, stored, or generated by Customers or their End-Users through use of the Service.

List dot icon

“Data Controller”

The individual or organization that determines the purposes and means of Processing personal data.

List dot icon

“Data Processor”

A service provider, such as Desku.io, that processes personal data on behalf of the Data Controller and in accordance with documented instructions.

List dot icon

“Data Subject”

Data Subject has the meaning given in applicable data protection law (including the GDPR) and refers to an identified or identifiable natural person to whom Personal Data relates.

List dot icon

“Processing”

Any operation performed on Personal Data, whether or not by automated means. Examples include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, transmission, dissemination, restriction, erasure, or destruction.

List dot icon

“Personal Data”

Any information relating to an identified or identifiable natural person, as defined under GDPR.

List dot icon

“Service”

The Desku.io platform and all associated tools, features, and interfaces, including HelpDesk services, Live Chat, OmniChannel messaging, AI functionality, automation tools, analytics, integrations, and administrative components.

List dot icon

“Subprocessor”

A third-party entity engaged by the Data Processor to support the delivery of services and who may process personal data under the same obligations applied to the Processor.

List dot icon

“User”

An individual or business entity that accesses or uses the Service, whether directly or through an authorized representative. This includes all agents, staff members, contractors, and administrators operating under a Customer’s account.

Desku as a Data Processor

Desku.io primarily acts as a Data Processor in relation to the personal data handled through the platform’s Customer Support functions. This includes personal data contained within messages, support tickets, contact records, automation workflows, and other information that Customers choose to store or process when using the Service.

In this capacity, Desku.io processes personal data solely on the documented instructions of the Data Controller and in accordance with applicable contractual, technical, and organizational requirements. Processing activities are limited to what is necessary to provide the platform’s functionality and to maintain the security and operational integrity of the Service.

The following sections provide clarification on the circumstances under which Desku.io acts as a Data Processor versus when it acts as a Data Controller, in order to outline how different categories of personal data are handled in accordance with GDPR.

When Desku Acts as Processor

Desku.io acts as a Data Processor with respect to personal data processed through the platform as part of Customer Support operations. This includes, but is not limited to:

List dot icon
Personal data contained within support conversations and communications.
List dot icon
Information processed as part of ticket management activities.
List dot icon
Data used within automation workflows configured by the Customer.
List dot icon
Personal data stored or managed through contact management features.
List dot icon
Data processed through AI-powered support functionalities, subject to Customer-defined instructions.
List dot icon
HelpDesk operations carried out within Desku.io’s GDPR-compliant support environment.

In all such cases, Desku.io processes personal data exclusively on behalf of, and according to the instructions of, the Data Controller.

When Desku Acts as Controller

Desku.io acts as a Data Controller only in relation to the limited categories of personal data required to operate and manage its own business functions. These activities include:
List dot icon
Personal data processed for account creation, administration, and billing purposes.
List dot icon
Personal data processed for fraud prevention, security monitoring, and risk management.
List dot icon
Personal data processed for optional marketing communications, where such communications are sent in accordance with applicable consent and opt-out requirements.

In all other cases, Desku.io processes personal data strictly on behalf of the Customer in its capacity as a Data Processor.

Responsibilities Under GDPR (Article 28)

When acting as a Data Processor, Desku.io performs its obligations in accordance with Article 28 of the GDPR. These responsibilities include:

List dot icon
Implementing appropriate technical and organizational measures to ensure the security, confidentiality, integrity, and availability of personal data.
List dot icon
Processing personal data only on documented instructions provided by the Data Controller, including with respect to international transfers.
List dot icon
Engaging Subprocessors only under GDPR-aligned contractual terms and conditions, and ensuring that all Subprocessors implement appropriate data protection and security safeguards.
List dot icon
Supporting Data Controllers in meeting their own GDPR obligations, including assistance with Data Subject requests, security requirements, and regulatory compliance where applicable.
List dot icon
Maintaining audit logs, access controls, monitoring systems, and related safeguards necessary to uphold a secure and compliant Processing environment.

Helping Customers Stay Compliant

Desku.io provides configuration options that enable Data Controllers to manage their own GDPR compliance obligations within the platform. Customers may configure:

List dot icon
Data retention settings, including rules governing how long specific categories of personal data is stored.
List dot icon
User permissions to control access to personal data based on defined roles and operational requirements.
List dot icon
Access control settings to limit or govern user activity within the platform.
List dot icon
Security features that support secure handling of personal data.
List dot icon
Ticket-level data handling rules, which allow Customers to apply specific Processing, retention, or deletion criteria to individual support records.

These features assist Data Controllers in implementing their internal data protection policies and GDPR compliance frameworks.

How Desku Complies with GDPR

Desku.io implements technical and organizational measures designed to align the platform with the requirements of the General Data Protection Regulation. These measures apply across all components of the service, including the HelpDesk environment and AI-enabled support features.

The following sections provide a transparent, structured overview of the GDPR compliance framework applied within the platform.

Data Minimization

Desku.io processes only the personal data that is necessary to provide the services requested by the Data Controller. The platform does not collect or retain personal data that is unrelated, excessive, or unnecessary for the operation of its Customer Support and HelpDesk functions.

Purpose Limitation

Desku.io processes personal data only for purposes that are lawful, specified, and directly related to the operation of the platform. These purposes include:

List dot icon

Delivering and maintaining the services requested by the Data Controller.

List dot icon
Performing platform analytics necessary to support functionality, performance, and service improvement.
List dot icon
Supporting security, fraud prevention, and operational integrity of the platform.
List dot icon
Providing Customer Support and responding to service-related inquiries.
Desku.io does not sell personal data, use it for unrelated or incompatible purposes, or process it in any manner that falls outside the documented instructions of the Data Controller.

Lawful Basis for Processing

Desku.io processes personal data only where a lawful basis under the GDPR applies. Depending on the nature of the Processing activity, Desku.io relies on the following lawful bases:

List dot icon
Contractual necessity, where the Processing of personal data is required to provide, maintain, or support the functionality of the platform in accordance with the Customer agreement.
List dot icon
Legitimate interests, including activities necessary for security monitoring, fraud prevention, service integrity, and the protection of the platform and its Users, provided such interests are not overridden by the rights and freedoms of the Data Subject.
List dot icon
Consent, where explicit consent is required for specific Processing activities and where such consent has been freely given by the Data Subject.

Storage Limitation

Desku.io applies defined data retention practices to ensure that personal data is stored only for as long as necessary to fulfil the purposes for which it was collected or to meet applicable legal, regulatory, or contractual requirements. These practices include:

List dot icon

Retaining personal data only for the duration required to operate and support the services provided to the Data Controller.

List dot icon

Applying distinct retention periods to specific categories of data where necessary or appropriate.

List dot icon
Deleting or anonymising personal data following the termination of an account or at the end of the applicable retention period, in accordance with a documented retention schedule.

Security Measures

Desku.io implements layered technical and organizational measures designed to protect personal data and maintain a secure Processing environment. These measures include:

List dot icon
TLS encryption in transit to safeguard data exchanged between clients, servers, and integrated systems.
List dot icon
AES-256 encryption at rest to protect stored personal data.
List dot icon
Strict access control and permission frameworks to limit access to authorized Users only.
List dot icon
Audit logs to record and monitor system activity relevant to security and compliance.
List dot icon
Real-time monitoring and alerting mechanisms to identify anomalous or unauthorized activity.
List dot icon
A secure development lifecycle, incorporating secure coding practices and regular security assessments.

Additional details regarding platform security controls are available on our Security Page. 

Hosting Location

Desku.io operates on a secure, cloud-based infrastructure designed to support reliable and compliant data Processing. The platform incorporates:

List dot icon
Enterprise-grade cloud hosting to ensure stability, security, and performance.
List dot icon
EU data residency options, where applicable, to support Customers with specific geographic or regulatory requirements.
List dot icon

Global redundancy measures to maintain service continuity and availability in the event of localized disruptions.

These hosting arrangements are designed to provide a secure and resilient environment for the Processing of personal data.

AI & Automated Processing

Desku.io incorporates AI-driven features that are designed and operated in accordance with GDPR principles and applicable data protection requirements. All automated Processing within the platform is implemented with safeguards that ensure personal data is handled with the same level of protection applied to human-driven support activities.

To maintain alignment with GDPR obligations:

List dot icon
AI features use anonymized or pseudonymized data, where feasible, to reduce the identifiability of individuals during automated Processing.
List dot icon
Customer Data is not used to train public or shared AI models, and is not retained for model improvement outside the Customer’s own environment.
List dot icon
Automated responses and actions operate strictly according to parameters and rules defined by the Data Controller.
List dot icon
Automated decision-making is not used to produce legal or similarly significant effects on individuals without human involvement, consistent with GDPR Article 22.
List dot icon
Processing carried out by AI components follows the same technical and organizational safeguards applied across the broader Desku.io platform.

These measures ensure that AI-supported workflows function in a secure, transparent, and responsible manner, supporting GDPR-compliant data Processing throughout the automation lifecycle.

Data Processing Agreement (DPA)

Desku.io makes a GDPR-aligned Data Processing Agreement (DPA) available to all Customers that require a contractual framework governing the Processing of personal data. The DPA sets out the terms and conditions under which Desku.io processes personal data on behalf of the Data Controller and describes the technical and organizational measures implemented to ensure its security and confidentiality.

The DPA outlines:

List dot icon
The respective roles and responsibilities of the Data Controller and Desku.io in its capacity as Data Processor.
List dot icon
The security, confidentiality, and data protection safeguards applied across the Desku.io platform.
List dot icon
Requirements and obligations applicable to Subprocessors, including contractual terms and conditions designed to ensure GDPR-aligned protections.
List dot icon
Mechanisms for international data transfers, including the use of Standard Contractual Clauses (SCCs) where relevant.
List dot icon
How documented Processing instructions from the Data Controller are applied and adhered to within Desku.io.

All Subprocessors engaged by Desku.io are required to enter into a GDPR-aligned Data Processing Agreement to ensure consistency of obligations and protections across the entire processing chain.

Customers may request or download the DPA using the link provided on this page.

Your Rights Under GDPR Law

Individuals located in the European Union (EU), the European Economic Area (EEA), or the United Kingdom (UK) have specific rights under the GDPR in relation to the Processing of their personal data. When Desku.io processes personal data as a Data Processor, requests relating to these rights must generally be directed to the Data Controller. However, Desku.io will assist the Data Controller in responding to such requests where required by the regulation or by contract.

The rights available to Data Subjects include:

List dot icon

Right of Access

The right to obtain confirmation as to whether personal data is being processed and, where applicable, to receive a copy of that data.

List dot icon

Right to Rectification

The right to request the correction of inaccurate or incomplete personal data.

List dot icon

Right to Erasure

The right to request the deletion of personal data in circumstances permitted under Article 17 of the GDPR.

List dot icon

Right to Restrict Processing

The right to request the limitation of Processing in certain situations, such as when the accuracy of the data is contested.

List dot icon

Right to Data Portability

The right to receive personal data in a structured, commonly used, and machine-readable format, and to request its transmission to another controller where technically feasible.

List dot icon

Right to Object

The right to object to Processing carried out on the basis of legitimate interests or for direct marketing purposes.

List dot icon

Right to Withdraw Consent

Where Processing is based on consent, the right to withdraw that consent at any time without affecting the lawfulness of prior Processing.

List dot icon

Right to Lodge a Complaint

The right to submit a complaint to a competent supervisory authority in the EU, EEA, or UK.

How to Submit a Request

Data Subjects may submit requests to exercise their GDPR rights through Desku.io’s designated request channels. Requests may be submitted:

List dot icon
Through the Support Portal (link to be provided on this page), or
List dot icon

By contacting the Desku.io Privacy Team at: support@desku.io

All requests will be handled in coordination with the applicable Data Controller, and Desku.io will provide reasonable assistance as required under the GDPR and relevant contractual obligations.

Subprocessors

Desku.io engages certain third-party service providers (“Subprocessors”) to support the delivery and operation of the platform. Where Subprocessors process personal data on behalf of the Data Controller, Desku.io ensures that:

List dot icon
Each Subprocessor implements appropriate technical and organizational measures consistent with GDPR requirements.
List dot icon
Subprocessors are bound by GDPR-aligned Data Processing Agreements, including confidentiality, security, and data protection obligations equivalent to those imposed on Desku.io.
List dot icon
Subprocessors are independently vetted for their technical, organizational, and security safeguards prior to engagement.
List dot icon
A transparent and regularly updated list of Subprocessors is made available to Customers.

Customers may view the current list of approved Subprocessors using the link provided on this page.

Data Transfers Outside the EU

When personal data is transferred outside the European Union (EU) or the European Economic Area (EEA), Desku.io implements lawful transfer mechanisms and safeguards in accordance with Chapter V of the GDPR. These safeguards include:

List dot icon
EU Standard Contractual Clauses (SCCs) for international data transfers, where applicable.
List dot icon
Supplementary technical and organizational protections to mitigate risks associated with cross-border transfers.
List dot icon
Transfer impact assessments, performed to evaluate the legal and operational context of the destination country.
List dot icon
Data residency options, where available, for Customers with specific regulatory or geographic requirements.

These measures are designed to ensure that international transfers of personal data are conducted in a secure and compliant manner.

Data Breach Policies

Desku.io maintains internal procedures for identifying, assessing, and responding to personal data breaches and other security incidents that may affect the confidentiality, integrity, or availability of personal data. These procedures are designed to support compliance with Articles 33 and 34 of the GDPR.

Desku.io’s commitments include:

List dot icon

Immediate internal escalation of suspected or confirmed security incidents.

List dot icon
Prompt investigation and containment actions to mitigate potential impact.
List dot icon
Notification to affected Customers without undue delay, where a personal data breach has occurred and notification is required under applicable law or contract.
List dot icon
Notification to regulatory authorities, where legally mandated, in accordance with GDPR requirements.
List dot icon
Transparent communication, delivered through email or platform dashboard alerts, where appropriate and consistent with legal obligations.

These policies support a structured and compliant approach to breach management across the Desku.io platform.

Data Protection Officer & Contact Information

For questions regarding GDPR Compliance for Customer Support Software, the Processing of personal data, or Desku.io’s privacy practices, organizations and individuals may contact the Desku.io Data Protection Officer (DPO), where a DPO has been appointed.

Additional information regarding Desku.io’s privacy practices can be found in the Privacy Policy.