CONTROLLER–PROCESSOR TERMS

Data Processing Addendum

A Framework for Protecting Customer Personal Data

This Data Processing Addendum provides an online framework for processing performed by DeskGate on behalf of a customer. A signed agreement or negotiated DPA controls where applicable; contact DeskGate to complete the required contractual documentation.

DeskGateSelf-Hosted ControlClear scope · accountable access · documented review
Processing addendum · Last updated August 18, 2026Questions? Contact DeskGate

Scope and Precedence

This addendum applies only where DeskGate processes personal data on behalf of the customer in connection with contracted support or services and data-protection law requires processor terms. The customer is controller or processor acting for another controller; DeskGate is processor or subprocessor as applicable.

The underlying order or service agreement, signed DPA, documented instructions, and mandatory law determine the binding relationship. A signed customer-specific DPA prevails over this public summary. Customer-hosted product data that DeskGate cannot access is not processed by DeskGate merely because DeskGate developed or licensed the software.

Processing Details

Subject matterTechnical support, troubleshooting, implementation assistance, maintenance, security response, or other contracted service requiring customer-directed access.
DurationThe applicable service period and limited return, deletion, backup, legal-preservation, or dispute period stated in the agreement.
Nature and purposeAccessing, viewing, transmitting, organizing, diagnosing, protecting, restoring, or deleting information only as necessary to perform documented instructions.
Data subjectsCustomer representatives, employees, contractors, users, customers, or other individuals whose information the customer places within service scope.
Data categoriesContact, account, device, diagnostic, support, activity, security, and other data supplied or made accessible by the customer; sensitive data only where expressly agreed and necessary.

Customer instructions and obligations

DeskGate processes customer personal data only on documented instructions, including instructions in the agreement, support request, and authorized customer communication, unless law requires otherwise. The customer warrants that its instructions and disclosures are lawful; it has provided required notices and established legal bases; it limits data to what is necessary; and its representatives are authorized. DeskGate will inform the customer if an instruction appears to violate applicable data-protection law, where permitted.

Confidentiality and security

Personnel authorized to process customer personal data are bound by confidentiality. DeskGate applies appropriate technical and organizational measures proportionate to the service and risk, which may include access control, authentication, encryption in transit where supported, secure support procedures, logging, staff obligations, vulnerability management, backup safeguards, incident response, and deletion controls. Customer remains responsible for its self-hosted infrastructure, accounts, configuration, endpoints, database, network, backups, and access approvals.

Subprocessors and transfers

DeskGate may use subprocessors necessary for contracted communications, infrastructure, support, or business services, subject to written data-protection obligations appropriate to their processing. The governing DPA defines notice and objection procedures. Where personal data is transferred internationally, the parties will use an applicable adequacy decision, standard contractual clauses, or other lawful safeguard and supplementary measures where required.

Assistance and data-subject requests

Considering the nature of processing and information available, DeskGate will provide reasonable assistance with data-subject requests, DPIAs, consultations, security obligations, and compliance information as required by the agreement and law. If DeskGate receives a request concerning customer-controlled data, it will direct the requester to the customer unless legally prohibited. The customer remains responsible for identity, scope, exemptions, response, and deadlines.

Personal-data breach

DeskGate will notify the customer without undue delay after confirming a personal-data breach affecting customer data processed by DeskGate and will provide available information reasonably needed for the customer’s assessment and notifications. Notification is not an admission of fault. The customer controls authority and individual notifications unless law assigns responsibility otherwise.

Return, deletion, and audits

At the end of services, DeskGate will return or delete customer personal data according to the agreement, except where law requires retention or controlled backups expire through established cycles. DeskGate will make required compliance information available and support reasonable audits under agreed confidentiality, security, scope, timing, frequency, and cost conditions. Audits must avoid exposing other customers or compromising systems.

Request Contractual Documentation

Contact DeskGate to review the processing scope, security responsibilities, transfer needs, and appropriate customer-specific DPA.

Contact DeskGate

Allocation of Operational Responsibility

The customer decides which systems DeskGate support personnel may access, creates or approves accounts, confirms the authorized requester, and removes access when work is complete. Before sharing information, the customer should redact unrelated personal data, credentials, special-category data, private communications, and third-party confidential material. Where production data is unnecessary, a representative test case should be used.

DeskGate personnel process only the information reasonably required for the assigned support purpose and must not use customer personal data for advertising, unrelated analytics, or independent employment decisions. Diagnostic findings may be converted into non-identifying product knowledge where this can be done without retaining customer personal data or confidential business information. Any broader use requires a separate lawful basis and appropriate notice.

The parties will cooperate in good faith to clarify controller, processor, and subprocessor roles where the customer provides services to another organization. The customer is responsible for ensuring its instructions are consistent with obligations owed to that controller. Requests that materially expand processing scope, require exceptional security controls, involve sensitive or regulated categories, or create substantial assistance may require a written change, risk review, additional safeguards, and reasonable fees. Neither party’s contractual responsibility removes the other party’s independent duties under applicable law.