FoxDesk Cloud
Privacy Terms DPA Refunds Security

Privacy Policy

Aenze s.r.o. processes personal data for FoxDesk Cloud as described below.

Last updated: July 17, 2026

Controller and processor roles

Aenze s.r.o., Company ID 28534395, VAT ID CZ28534395, registered office at Moskevska 1842, 272 04 Kladno, Czech Republic, operates FoxDesk Cloud. We are the controller for website visits, accounts, billing, security, support, and our own service operations. For ticket, client, file, report, and workspace content entered by a customer, we normally act as processor and process that content for the customer.

Business service only

FoxDesk Cloud is intended for business helpdesk and time tracking data. Customers must not intentionally upload payment card numbers, special categories of personal data, criminal offence data, national identifiers, medical data, or other sensitive regulated data unless we have expressly agreed to that in writing.

Personal data processed

We may process names, email addresses, login and role details, company details, workspace settings, client and contact records, tickets, comments, internal notes, attachments, time entries, reports, notification records, billing and invoice details, IP addresses, device and browser data, security logs, and messages sent to support or billing contacts.

Purposes

We process personal data to provide, secure, maintain, bill, support, improve, and protect FoxDesk Cloud; to create and manage accounts and workspaces; to send necessary service communications; to prevent abuse; to keep accounting and legal records; and to establish, exercise, or defend legal claims.

Legal bases

Where GDPR applies, our legal bases are contract performance, legal obligation, legitimate interests in operating and protecting a paid business service, and consent where consent is legally required. Workspace content is processed on the customer's documented instructions.

Customer responsibility

The customer determines the purposes and means of processing workspace content and controls what its users enter into the service. The customer is responsible for having a valid legal basis, giving required notices, handling data subject requests, configuring permissions, keeping account access secure, and deleting data that should no longer be stored. The customer must not instruct us to process data unlawfully. We do not sell workspace content and do not use it for advertising.

Customer instructions and content

We process workspace content only to provide, secure, support, and administer the service, comply with documented customer instructions, or meet a legal obligation. We do not determine whether customer content is necessary, accurate, lawful, or suitable for the customer's business. We may reject, restrict, preserve, or remove content or instructions where reasonably necessary for security, legal compliance, abuse prevention, or protection of the service and third parties.

Service providers

We may use professional service providers for hosting, storage, email delivery, payment processing, monitoring, security, support, accounting, and other operations needed to run FoxDesk Cloud. They may process personal data only for those services and under appropriate obligations. Provider details are supplied where required by law or customer agreement.

Transfers outside the EEA

If personal data is transferred outside the European Economic Area, we rely on a lawful transfer mechanism where required, such as an adequacy decision, Standard Contractual Clauses, or another mechanism permitted by data protection law.

Retention

Workspace data is kept while the workspace is active. After cancellation, expiry, suspension, or termination, we may retain data for export, recovery, security, backup expiry, billing, accounting, tax, legal compliance, dispute handling, and claim defence. We may delete or anonymise inactive or unpaid workspace data after a reasonable period.

Data subject rights

Where GDPR applies, individuals may request access, correction, deletion, restriction, portability, or objection. Requests concerning customer workspace content may need to be handled by the customer as controller. Contact us at [email protected]. Complaints may be made to the Czech data protection authority: Office for Personal Data Protection of the Czech Republic (UOOU), https://www.uoou.cz.

Security

We use reasonable technical and organisational measures for a hosted business service. No online service is risk-free. Customers remain responsible for their own users, devices, passwords, permissions, and the data they choose to store.

Operator: Aenze s.r.o., Company ID 28534395, registered office Moskevska 1842, 272 04 Kladno, Czech Republic. Support: [email protected]. Billing: [email protected].

If a mandatory law gives a customer or data subject rights that cannot be limited by contract, those mandatory rights remain unaffected.