Customer instructions and obligations
DeskGate processes customer personal data only on documented instructions, including instructions in the agreement, support request, and authorized customer communication, unless law requires otherwise. The customer warrants that its instructions and disclosures are lawful; it has provided required notices and established legal bases; it limits data to what is necessary; and its representatives are authorized. DeskGate will inform the customer if an instruction appears to violate applicable data-protection law, where permitted.
Confidentiality and security
Personnel authorized to process customer personal data are bound by confidentiality. DeskGate applies appropriate technical and organizational measures proportionate to the service and risk, which may include access control, authentication, encryption in transit where supported, secure support procedures, logging, staff obligations, vulnerability management, backup safeguards, incident response, and deletion controls. Customer remains responsible for its self-hosted infrastructure, accounts, configuration, endpoints, database, network, backups, and access approvals.
Subprocessors and transfers
DeskGate may use subprocessors necessary for contracted communications, infrastructure, support, or business services, subject to written data-protection obligations appropriate to their processing. The governing DPA defines notice and objection procedures. Where personal data is transferred internationally, the parties will use an applicable adequacy decision, standard contractual clauses, or other lawful safeguard and supplementary measures where required.
Assistance and data-subject requests
Considering the nature of processing and information available, DeskGate will provide reasonable assistance with data-subject requests, DPIAs, consultations, security obligations, and compliance information as required by the agreement and law. If DeskGate receives a request concerning customer-controlled data, it will direct the requester to the customer unless legally prohibited. The customer remains responsible for identity, scope, exemptions, response, and deadlines.
Personal-data breach
DeskGate will notify the customer without undue delay after confirming a personal-data breach affecting customer data processed by DeskGate and will provide available information reasonably needed for the customer’s assessment and notifications. Notification is not an admission of fault. The customer controls authority and individual notifications unless law assigns responsibility otherwise.
Return, deletion, and audits
At the end of services, DeskGate will return or delete customer personal data according to the agreement, except where law requires retention or controlled backups expire through established cycles. DeskGate will make required compliance information available and support reasonable audits under agreed confidentiality, security, scope, timing, frequency, and cost conditions. Audits must avoid exposing other customers or compromising systems.