FoxDesk Cloud
Privacy Terms DPA Refunds Security Subprocessors

Data Processing Addendum

This DPA forms part of the FoxDesk Cloud customer contract whenever Aenze s.r.o. processes customer personal data as processor or sub-processor under GDPR.

Effective and last updated: August 6, 2026 · Version 2026-08-06

Parties and roles

The customer is controller of personal data entered into its workspace, or a processor authorised by another controller. Aenze s.r.o. is the customer’s processor for that data. Each party remains independently responsible for personal data it controls, including account, billing and business-contact records described in the Privacy Policy.

Subject matter, duration and purpose

Processing covers hosting and operating the customer’s FoxDesk Cloud workspace for the contract term and the limited return, deletion, backup, security and legal-retention period afterwards. The purpose is to let the customer receive and manage requests, users, clients, tickets, messages, files, time entries, reports, notifications, integrations and related administration.

Data and people

Personal data may include names, email addresses, organisations, contact details, roles, credentials metadata, ticket and message content, internal notes, files, time entries, reports, communication metadata, technical identifiers and logs. Data subjects may include the customer’s staff, agents, contractors, client contacts, requesters, suppliers and other people whose data the customer chooses to process. The frequency is continuous or as initiated by authorised users, email senders, integrations and configured automation.

Documented instructions

We process customer personal data only on documented instructions contained in the contract, product settings, authorised support requests, API actions and lawful written directions. If EU or Member State law requires other processing, we will inform the customer before processing unless law prohibits that notice. We will immediately inform the customer if, in our opinion, an instruction infringes applicable data-protection law and may suspend only the affected instruction while the parties resolve it.

Customer duties

The customer must ensure lawful collection, instructions, notices, legal bases, accuracy, minimisation, retention, access and responses to data-subject requests. It must configure users and permissions appropriately, protect credentials, and avoid unnecessary sensitive data. If the customer acts for another controller, it warrants that it is authorised to appoint us and give instructions.

Confidentiality and personnel

People authorised by us to process customer personal data are bound by confidentiality or an appropriate statutory duty, receive security and privacy guidance, and access data only as needed for their role. Access is reviewed and removed when no longer required.

Security measures

Taking account of the state of the art, implementation costs, processing and risk, we maintain measures including encrypted network transport; password hashing and protected secret storage; role-based access and least privilege; optional multi-factor authentication; tenant-bound access checks; logging and security monitoring; patch, dependency and vulnerability management; controlled deployment; availability and recovery procedures; verified database backups with a current 14-day rotation; incident handling; and procedures to test and improve relevant safeguards. Exact implementation details may change without reducing the overall level of protection.

Data-subject requests

Considering the nature of processing, we assist the customer through product controls and reasonable support with access, correction, deletion, restriction, portability and objection requests. If a request is sent directly to us about customer workspace data, we will redirect it to the customer where practicable and will not respond substantively unless authorised or legally required.

Articles 32 to 36 assistance

We provide reasonable information and assistance needed for the customer’s security obligations, breach notifications, data-protection impact assessments and prior consultation, taking account of the service and information available to us. Assistance beyond standard product and compliance information may be charged at an agreed rate when it requires substantial bespoke work, unless it is needed because of our breach.

Personal data breach

After becoming aware of a personal data breach affecting customer workspace data, we will notify the affected customer without undue delay and will not wait for every fact to be known. Available information will cover the nature of the breach, likely consequences, affected data and people, contact point, and measures taken or proposed. We may provide information in phases and will cooperate with reasonable investigation and notification needs. Customer notification is not an admission of fault.

Sub-processors and changes

The customer gives general written authorisation for the sub-processors listed on the public Subprocessors page. We require them by contract to protect personal data to the standard required by Article 28 and remain responsible for our processor obligations. We will normally give workspace administrators at least 15 days’ advance notice of a material new sub-processor by updating that page and by email or in-service notice. The customer may object during that period on reasonable data-protection grounds. If no practical alternative resolves a valid objection, either party may end the affected service before the change. Urgent replacement needed for security or service continuity may occur sooner with notice as soon as practicable.

International transfers

We and our sub-processors will not transfer customer personal data from the EEA to a country without an adequate level of protection unless a valid transfer mechanism applies, such as an adequacy decision or EU Standard Contractual Clauses, with supplementary measures where appropriate. The customer authorises us to enter relevant transfer terms for the limited purpose of providing the service. Safeguard information is available from [email protected].

Return and deletion

At the customer’s choice after the service ends, we will make available the standard export or delete the workspace following a verified request and reasonable export window, normally 30 days, unless law requires storage. Production deletion is completed without undue delay after that window. Data may remain inaccessible in routine backups until the current 14-day cycle expires and will not be restored except for disaster recovery, in which case the deletion obligation continues.

Information and audits

We make available information reasonably necessary to demonstrate Article 28 compliance, including this DPA, security information and relevant independent evidence when available. Once per year, or after a substantiated incident or regulator request, the customer may request a proportionate audit on reasonable notice. Remote document review is used first. Any inspection must protect other customers, confidentiality and security, occur during business hours, and avoid disruption. The customer bears reasonable external audit costs unless the audit identifies our material breach.

Deletion instructions and legal retention

Deletion obligations do not apply to data we must retain under Union or Member State law. Such retained data is isolated from ordinary use, protected, used only for the legal purpose and deleted when the duty ends. Billing and controller records are not customer workspace data and follow the Privacy Policy.

Liability and duration

The liability provisions in the Terms apply to this DPA unless mandatory data-protection law requires otherwise. This DPA remains effective for as long as we process customer personal data. If a conflict concerns protection of that data, this DPA prevails over the Terms.

Operator: Aenze s.r.o., Company ID 28534395, VAT ID CZ28534395, Commercial Register maintained by the Municipal Court in Prague, file C 148584, registered office Moskevská 1842, 272 04 Kladno, Czech Republic. Support: [email protected]. Billing: [email protected]. Privacy: [email protected].

Nothing in these documents excludes a statutory duty, remedy, or right that applicable mandatory law does not permit the parties to exclude or limit.