FoxDesk Cloud
Privacy Terms DPA Refunds Security

Data Processing Addendum

This Data Processing Addendum applies when Aenze s.r.o. processes personal data as processor for a FoxDesk Cloud customer.

Last updated: July 17, 2026

Roles

The customer is the controller of personal data entered into its workspace and remains responsible for the lawfulness, necessity, accuracy, retention, and use of that data. Aenze s.r.o. is the processor for that workspace data. If the customer processes data for another controller, the customer confirms that it has authority to instruct us and to appoint us as a sub-processor.

Subject matter and duration

We process workspace data to provide FoxDesk Cloud. Processing lasts while the workspace is active and for any limited period needed for export, deletion, backup expiry, legal compliance, accounting, security, or dispute handling.

Purpose of processing

We process workspace data so the customer can operate helpdesk tickets, client records, user access, time tracking, reports, notifications, files, and related administration.

Types of personal data

Workspace data may include names, emails, organisations, contact details, ticket content, comments, files, internal notes, time entries, reports, user roles, technical identifiers, logs, and communication metadata.

Data subjects

Data subjects may include the customer's employees, agents, client contacts, requesters, suppliers, contractors, and other people whose data is entered into a workspace.

Customer instructions

We process workspace data only on documented customer instructions, including these Terms, this DPA, product settings, support requests, and lawful written instructions. The customer warrants that its instructions and disclosure of personal data comply with applicable law. We may refuse or suspend instructions that appear unlawful, unsafe, technically unreasonable, or outside the service scope.

Confidentiality

People authorised to process workspace data for us must keep it confidential and may access it only as needed for the service, security, support, legal compliance, or claim defence.

Security

We use technical and organisational measures appropriate to a hosted business SaaS, the processing, and the risk. The customer is responsible for choosing what data to upload, assigning users correctly, and using available security controls.

Assistance

We will provide reasonable assistance with data subject requests, security incidents, deletion or export requests, and GDPR obligations where this is available through the service or reasonable support. Extraordinary assistance may require a separate agreement or fee.

Sub-processors

The customer gives general authorisation for sub-processors needed to operate FoxDesk Cloud. We may appoint, replace, or remove sub-processors. We remain responsible for imposing appropriate data protection obligations on them as required by GDPR. Provider information is supplied where required by law or customer agreement.

International transfers

Where processing involves transfers outside the European Economic Area, we will use a legally available transfer mechanism where required.

Personal data breach

If we become aware of a personal data breach affecting customer workspace data, we will investigate and notify affected customers without undue delay after we have enough information to make a meaningful notice.

Return and deletion

After termination, workspace data may be exported where technically available. We may delete or anonymise workspace data after the applicable retention period, subject to backups, legal duties, accounting, security, abuse prevention, and dispute handling.

Audit information

The customer may request reasonable information needed to verify compliance with this DPA. Any review must be proportionate, scheduled in advance, limited to relevant information, and must not compromise other customers, confidential information, security, or service availability.

Operator: Aenze s.r.o., Company ID 28534395, registered office Moskevska 1842, 272 04 Kladno, Czech Republic. Support: [email protected]. Billing: [email protected].

If a mandatory law gives a customer or data subject rights that cannot be limited by contract, those mandatory rights remain unaffected.