Data Processing Addendum
This Data Processing Addendum applies when Aenze s.r.o. processes personal data as processor for a FoxDesk Cloud customer.
Roles
The customer is the controller of personal data entered into its workspace and remains responsible for the lawfulness, necessity, accuracy, retention, and use of that data. Aenze s.r.o. is the processor for that workspace data. If the customer processes data for another controller, the customer confirms that it has authority to instruct us and to appoint us as a sub-processor.
Subject matter and duration
We process workspace data to provide FoxDesk Cloud. Processing lasts while the workspace is active and for any limited period needed for export, deletion, backup expiry, legal compliance, accounting, security, or dispute handling.
Purpose of processing
We process workspace data so the customer can operate helpdesk tickets, client records, user access, time tracking, reports, notifications, files, and related administration.
Types of personal data
Workspace data may include names, emails, organisations, contact details, ticket content, comments, files, internal notes, time entries, reports, user roles, technical identifiers, logs, and communication metadata.
Data subjects
Data subjects may include the customer's employees, agents, client contacts, requesters, suppliers, contractors, and other people whose data is entered into a workspace.
Customer instructions
We process workspace data only on documented customer instructions, including these Terms, this DPA, product settings, support requests, and lawful written instructions. The customer warrants that its instructions and disclosure of personal data comply with applicable law. We may refuse or suspend instructions that appear unlawful, unsafe, technically unreasonable, or outside the service scope.
Confidentiality
People authorised to process workspace data for us must keep it confidential and may access it only as needed for the service, security, support, legal compliance, or claim defence.
Security
We use technical and organisational measures appropriate to a hosted business SaaS, the processing, and the risk. The customer is responsible for choosing what data to upload, assigning users correctly, and using available security controls.
Assistance
We will provide reasonable assistance with data subject requests, security incidents, deletion or export requests, and GDPR obligations where this is available through the service or reasonable support. Extraordinary assistance may require a separate agreement or fee.
Sub-processors
The customer gives general authorisation for sub-processors needed to operate FoxDesk Cloud. We may appoint, replace, or remove sub-processors. We remain responsible for imposing appropriate data protection obligations on them as required by GDPR. Provider information is supplied where required by law or customer agreement.
International transfers
Where processing involves transfers outside the European Economic Area, we will use a legally available transfer mechanism where required.
Personal data breach
If we become aware of a personal data breach affecting customer workspace data, we will investigate and notify affected customers without undue delay after we have enough information to make a meaningful notice.
Return and deletion
After termination, workspace data may be exported where technically available. We may delete or anonymise workspace data after the applicable retention period, subject to backups, legal duties, accounting, security, abuse prevention, and dispute handling.
Audit information
The customer may request reasonable information needed to verify compliance with this DPA. Any review must be proportionate, scheduled in advance, limited to relevant information, and must not compromise other customers, confidential information, security, or service availability.
If a mandatory law gives a customer or data subject rights that cannot be limited by contract, those mandatory rights remain unaffected.