We have updated this policy. If you are a new Subscriber, then this policy will be effective as of September 13, 2023. If you are an existing Subscriber, we are providing you with prior notice of these changes which will be effective as of October 13, 2023. For the previous version of this policy, please expand the section below.
Zendesk, Inc. (“Zendesk”) uses certain Sub-processors (including members of the Zendesk Group and third parties, as listed below) and content delivery networks to assist it in providing the Zendesk Services as described in the Main Services Agreement (“MSA”). Defined terms used herein shall have the same meaning as defined in the MSA.
What is a Sub-processor
A Sub-processor is a third-party data processor engaged by Zendesk, including entities from the Zendesk Group, who receives Service Data (which may contain Personal Data) from Zendesk for Processing on behalf of our Subscribers and in accordance with our Subscribers' instructions (as communicated by Zendesk) and the terms of its written subcontract. Zendesk engages different types of Sub-processors to perform various functions as explained in the tables below.
Due Diligence
Zendesk undertakes to use a commercially reasonable selection process by which it evaluates the security, privacy and confidentiality practices of proposed Sub-processors.
Contractual Safeguards
Zendesk generally requires its Sub-processors to satisfy equivalent obligations as those required from Zendesk (as a Data Processor) as set forth in Zendesk’s Data Processing Agreement (“DPA”), including but not limited to the requirements to:
- Process Personal Data in accordance with data controller’s (i.e., Subscriber’s) documented instructions (as communicated in writing to the relevant Sub-processor by Zendesk);
- In connection with their sub-processing activities, use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable, pursuant to applicable data protection laws;
- Provide regular training in security and data protection to personnel to whom they grant access to Personal Data;
- Implement and maintain appropriate technical and organizational measures (including measures consistent with those to which Zendesk is contractually committed to adhere to insofar as they are equally relevant to the Sub-processor’s Processing of Personal Data on Zendesk’s behalf) and provide an annual certification that evidences compliance with this obligation. In the absence of such certification Zendesk reserves the right to audit the Sub-processor;
- Promptly inform Zendesk about any actual or potential security breach; and
- Cooperate with Zendesk in order to deal with requests from data controllers, data subjects or data protection authorities, as applicable.
Sub-processors which incidentally have access to Your Service Data in Innovation Services and are used to provide specific features or components of the product outside of the core hosting of Service Data (“Innovation Service Specific Sub-processors”) are regularly reviewed by Zendesk to ensure they work towards implementing each of the standards described in this Section. However, Innovation Service Specific Sub-processors may not currently meet all of the measures identified above.
This policy does not give Subscribers any additional rights or remedies and should not be construed as a binding agreement. The information herein is only provided to illustrate Zendesk’s engagement process for Sub-processors as well as to provide the actual list of third party Sub-processors and content delivery networks used by Zendesk as of the date of this policy (which Zendesk may use in the delivery and support of its Services).
If you are a Zendesk Subscriber and wish to enter into our DPA, please see our Trust Center at https://www.zendesk.com/trust-center/.
Process to Engage New Sub-processors:
For all Subscribers who have executed Zendesk’s standard DPA, Zendesk will provide notice via this policy of updates to the list of Sub-processors that are utilized or which Zendesk proposes to utilize to deliver its Services. Zendesk undertakes to keep this list updated regularly to enable its Subscribers to stay informed of the scope of sub-processing associated with the Zendesk Services. Zendesk Subscribers may subscribe to receive notifications of updates to this policy by clicking “Follow” at the top of this policy.
Pursuant to the DPA, a Subscriber may object in writing to the Processing of its Personal Data by a newly appointed Sub-processor within thirty (30) days following the update of this policy and such objection shall describe Subscriber's legitimate reason(s) for objection. If Subscriber does not object during such time period, the new Sub-processor(s) shall be deemed accepted.
If a Subscriber objects to the use of a newly appointed Sub-processor pursuant to the process provided under the DPA, Zendesk shall have the right to cure the objection through one of the following options (to be selected at Zendesk’s sole discretion) by either:
(a) instructing the Sub-processor to cease the Processing of Subscriber's Personal Data, in which event the DPA shall continue unaffected; or (b) allowing Subscriber to terminate their DPA and any related services agreement with Zendesk immediately and provide it with a pro rata reimbursement of any sums paid in advance for Services to be provided, but not yet received by Subscriber as of the effective date of termination.
The following is an up-to-date list (as of the date of this policy) of the names, entity type, and locations of Zendesk Sub-processors and content delivery networks (including members of the Zendesk Group and third parties):
Infrastructure Sub-processors – Service Data Storage and Processing
Zendesk owns or controls access to the infrastructure that Zendesk uses to host and Process Service Data submitted to the Services, other than as set forth herein. Currently, the Zendesk production systems used for hosting Service Data for the Services are located in the infrastructure Sub-processor listed below. Subscriber accounts are typically established in one of these regions based on where the Subscriber is located, but may be shifted among locations to ensure performance and availability of the Services. The following table describes the legal entity engaged by Zendesk in the storage of Service Data. Zendesk also uses additional services provided by this Sub-processor to Process Service Data as needed to provide the Services.
Entity Name | Entity Type | Data Hosting Location |
Amazon Web Services, Inc. | Cloud Service Provider | United States, Ireland, Germany, Japan, Australia |
Service Specific Sub-processors
Zendesk works with certain third parties to provide specific functionality within the Services. These providers are the Sub-processors set forth below. In order to provide the relevant functionality, these Sub-processors access and Process Service Data. Their use is limited to the indicated Services. If Subscriber has purchased the Zendesk Suite or Sales Suite, the Sub-processors used for the Suites will be in accordance with the Sub-processors listed for the underlying Services that make up the Zendesk Suite or Sales Suite as detailed in this policy. Definitions for the terms used to refer to the Applicable Services included below can be found in the Service-Specific Supplemental Terms found here: https://support.zendesk.com/hc/en-us/articles/4408831944730. For reference, such definitions are as follows:
- Ticketing System Functionality: means Zendesk Support and help desk functionality, email support functionality and Agent Workspace functionality available within Zendesk Suite.
- Voice Functionality: means Zendesk Talk and call center software available within Zendesk Suite.
- Analytics Functionality: means Zendesk Explore and reporting and analytics functionality available within Zendesk Suite.
Entity Name | Purpose and Data Processed | Applicable Services | Data Hosting Location |
Twilio, Inc. | Zendesk Talk’s cloud center software is built on Twilio, Inc.’s (“Twilio”) development platform. Twilio’s development platform provides the APIs from which Zendesk Talk accesses the telecommunications infrastructure, including phone numbers, voice minutes, web client, and phone call recording and transcription. Twilio has access to Subscribers’ and End-Users’ information as needed to deliver the Talk and Text messages between Subscribers and End-Users. This includes Service Data contained in the messages and the Personal Data of Subscribers’ Agents and End-Users as needed to send and deliver the messages. Zendesk Support also uses Twilio for two-factor authentication of Agents and Admins. The only information Twilio has access to for this purpose is the Agent/Admin's phone number. | Voice Functionality, Ticketing System Functionality, Zendesk Sell | United States |
GoodData Corporation | GoodData Corporation (“GoodData”) is the analytics provider that Zendesk uses in Insights reporting, our legacy analytics feature. Insights is a legacy Service that is not available to new Subscribers and GoodData is only an applicable Sub-processor for a limited number of existing Subscribers using Insights. Where Insights is used, GoodData may Process Service Data from all of the Services used by the relevant Subscriber. | Insights (Legacy Service) | United States |
SendGrid, Inc. | SendGrid, Inc. (“SendGrid”) is an email campaign service provider used to send notification emails and dashboards to Agents and End-Users. The primary information SendGrid has access to is the email addresses of recipients of the emails and the content of the emails themselves. The content of the emails may include the dashboards Subscriber has chosen to include in the email campaign, chat analytics reports, and chat transcripts that have been exported via email. | Analytics Functionality, Zendesk Sell, Live Chat Functionality | United States |
Cloudflare, Inc. |
Cloudflare, Inc. (“Cloudflare”) provides content distribution, security, abuse prevention and DNS services for web traffic transmitted to and from the Services. This allows Zendesk to efficiently manage traffic and secure the Services. The primary information Cloudflare has access to is information in and associated with the Zendesk website URL with which the End-User or Agent is interacting (including End-User or Agent IP address). All information (including Service Data) contained in web traffic transmitted to and from the Services is transmitted through Cloudflare’s systems. Cloudflare also Processes a limited amount of Personal Data (specifically Agent and End-User IP addresses, browser and operating system related information) for logging, security, and abuse prevention purposes. |
All | Local
Cloudflare routes traffic to worldwide data centers closest to the user's location. Logging by Cloudflare is performed in the United States. |
Pendo.io, Inc. | Pendo.io, Inc. (“Pendo”) is a third-party analytics provider that Zendesk uses to capture how users interact with the Service. Zendesk uses this information to analyze and improve the Services. The primary information Pendo has access to is information in and associated with the Zendesk website URL that the Agent and End-User are interacting with, such as time spent on page, items clicked (including Service Data contained in those items), Agent email addresses, End-User email addresses, etc. |
All | United States |
Datadog, Inc. | Datadog, Inc. (“Datadog”) is a third-party logging platform that Zendesk uses for ingesting, parsing, querying and performing analytics on Service application and infrastructure logs (“Logs”). These Logs are then used for debugging, troubleshooting, auditing, reporting, and detecting and alerting on unexpected application behavior. Incidental to the purpose of the Log Processing, Service Data and Personal Data may be Processed by Datadog. Examples of the data that may be in the Logs includes: timestamp, token ID, email address, user agent, username, Account ID, User ID, name, IP address, application paths and parameters, Session IDs, provisioned infrastructure, Ticket and Help Center data, Agent data and other types of Service Data. | All | United States, Germany |
MongoDB, Inc. | MongoDB, Inc. (“MongoDB”) provides scalable database services used to host select Service Data related to messaging integrations. The primary data MongoDB has access to includes messages exchanged through Sunshine Conversations and other messaging integrations, profile metadata supplied by messaging channels, metadata supplied by SDK integrator/APIs, messaging channel identities and credentials, push notification certificates and API keys, and webhook information. | Sunshine Conversations, Zendesk messaging, WhatsApp Integration and Social Messaging Add-Ons | United States, Ireland, Germany, Japan, Australia |
Functional Software, Inc. | Functional Software, Inc. ("Sentry") is a cross-platform error monitoring tool with a focus on error reporting. Zendesk uses Sentry to capture errors thrown within the Service to better understand and resolve issues in real-time. Incidental to the purpose of the error monitoring, Service Data and Personal Data may be Processed by Sentry. Examples of the data that may be in the logs include: timestamp, token ID, email address, user agent, username, Account ID, User ID, name, IP address, application paths and parameters, Session IDs, provisioned infrastructure, Ticket and Help Center data, Agent data and other types of Service Data. | All | United States, Germany |
Google LLC | Google LLC ("Google") supports the translation functionality that is available to Agents within Agent Workspace. If the translation functionality is used by Agents, Google will Process all Service Data that is translated within Agent Workspace. | Translation Functionality within Agent Workspace, Live Chat Functionality | No hosting of Service Data |
NetApp, Inc. | NetApp, Inc. ("NetApp") provides services used to cache Subscribers' tickets for export within the Services. NetApp Processes the Service Data (including any Personal Data) contained within Subscribers' tickets and all associated metadata, which may include without limitation Agent data, Account IDs, User IDs, email addresses, and IP addresses. | Ticketing Functionality | United States, Germany, Japan, Australia |
OpenAI, L.L.C. | OpenAI, L.L.C. ("OpenAI") provides services to support generative artificial intelligence functionality within (a) the Advanced AI Add-On to the Zendesk Services, including, without limitation, automated summarization of correspondence, text revision, and text completion, and (b) Zendesk Services with features powered by OpenAI, where Subscriber enables such features. OpenAI Processes the Service Data contained within the content of Subscribers' tickets and the Services to which the Advanced AI Add-On applies. The Advanced AI Add-On, and use of OpenAI as a Sub-processor, is optional and may be enabled by Subscribers. | OpenAI functionality within Advanced AI Add-On and All Zendesk Services where OpenAI functionality is enabled | No hosting of Service Data |
Snowflake Inc. | Snowflake Inc. ("Snowflake") provides data warehouse services underlying the Zendesk platform, allowing for efficient provision and trend analysis of the Services and day to day business operations, as well as supporting advanced Analytics Functionality available to Subscribers. Snowflake may access a copy of all Service Data for the above-referenced purposes. | All | United States, Germany |
Innovation Services Sub-processors
Zendesk Sell and Tymeshift Functionality are supported by additional Innovation Services Sub-processors, which can be viewed by expanding below.
Zendesk Group Sub-processors
The following entities are members of the Zendesk Group. Accordingly, they may function as Sub-processors to provide the Services.
Entity Name | Country |
Zendesk, Inc. FutureSimple Inc. ZD Sub Holdings Smooch Technologies US Inc. |
United States |
Zendesk International Limited | Ireland |
Zendesk ApS | Denmark |
Zendesk GmbH | Germany |
Zendesk Pty., Ltd | Australia |
Zendesk UK Limited | United Kingdom |
Zendesk Incorporated | Philippines |
Zendesk Singapore Pte. Ltd. | Singapore |
Zendesk Brasil Software Corporativo LTDA | Brazil |
Kabushiki Kaisha Zendesk | Japan |
We Are Cloud SAS | France |
Base sp. z o. o. (Base spółka z ograniczoną odpowiedzialnością) | Poland |
Smooch Technologies ULC | Canada |
Zendesk Technologies Private Limited | India |
Zendesk Korea LLC | South Korea |
Cleverly, Unipessoal, LDA | Portugal |
Zendesk Technologies Spain S.L. | Spain |
Zendesk, S. de R.L. de C.V. | Mexico |
Zendesk Sweden AB | Sweden |
Zendesk Netherlands B.V. | Netherlands |
Zendesk Italy S.r.l. | Italy |
Content Delivery Networks
As explained above, Zendesk’s Services may use content delivery networks (“CDNs”) to provide the Services, for security purposes, and to optimize content delivery. CDNs do not have access to Service Data but are commonly used systems of distributed services that deliver content based on the geographic location of the individual accessing the content and the origin of the content provider. Website content served to website visitors and domain name information may be stored with a CDN to expedite transmission, and information transmitted across a CDN may be accessed by that CDN to enable its functions. The following describes the use of CDNs by Zendesk’s Services.
CDN Provider | Services Using CDN | CDN Location | Description of CDN Services |
Amazon Web Services, Inc. | All Zendesk Services | Global | Public website content served to website visitors may be stored with Amazon Web Services, Inc., and transmitted by Amazon Web Services, Inc., to website visitors, to expedite transmission. |
9 Comments
February 1, 2021 - Sub-processor Policy updated to revise select "Applicable Services" terminology. No sub-processors were added or removed as part of this update.
June 1, 2021 - Sub-processor Policy updated to revise the "Ticketing System Functionality" definition. No sub-processors were added or removed as part of this update.
October 1, 2021 - Sub-processor Policy updated to modify MongoDB and 84Codes applicability and purpose descriptions. No new sub-processors were added or removed as part of this update.
March 18, 2022 - Sub-processor Policy updated to add a new sub-processor, Functional Software, Inc. (“Sentry”). Sentry will be enabled in the Services in thirty (30) days.
June 1, 2022 - This Sub-processor Policy has been updated. For reference, the previous version can be found above.
January 12, 2023 - This Sub-processor Policy has been updated for clarity to update the Zendesk Group Sub-processors to include new corporate Zendesk entities, remove Accenture International Limited as a Sub-processor, and add a new Sub-processor, NetApp, Inc. ("NetApp"). NetApp will be enabled in the Services in thirty (30) days.
March 21, 2023 - This Sub-processor Policy has been updated to remove 84codes AB as a Sub-processor, which will no longer be used, and to modify the SendGrid, Inc. ("SendGrid") applicability and purpose description to include Live Chat Functionality. SendGrid will be enabled as a Sub-processor for Zendesk Chat in thirty (30) days. For clarity, SendGrid is not a Sub-processor for Zendesk messaging.
May 15, 2023 - This Sub-processor Policy has been updated to include new European Zendesk Group Sub-processors and add a new Sub-processor, OpenAI, L.L.C. ("OpenAI"). For clarity, OpenAI will be disabled by default as a Sub-processor except for Subscribers that use the OpenAI functionality within the optional Advanced AI Add-On to the Zendesk Services, as of the date that the OpenAI functionality within the Advanced AI Add-On is enabled by the Subscriber.
September 14, 2023 - This Sub-processor Policy has been updated to list Tymeshift, Inc. (“Tymeshift”) Sub-processors, and to add a new Zendesk Sub-processor, Snowflake Inc. ("Snowflake"). All Tymeshift Sub-processors are existing Sub-processors, as previously disclosed here. Additionally, the applicability and purpose descriptions of the existing Sub-processors Cloudflare, Inc., Good Data Corporation, and OpenAI, L.L.C. have been updated. For clarity, as before, OpenAI will be disabled by default until proactively enabled by the Subscriber.
Article is closed for comments.