Data processing agreement
Last updated August 31, 2026
This agreement governs how fikadesk processes personal data on behalf of a customer. It is incorporated into the terms of service, so accepting the terms accepts this agreement.
Scope and parties
This Data Processing Agreement (DPA) is between the customer, as controller of personal data, and [COMPANY ENTITY] (fikadesk), as processor. It applies where fikadesk processes personal data on the customer's behalf to provide the Service. Terms used here have the meaning in Article 4 of the GDPR unless stated otherwise.
The customer is the controller of its end users' personal data. fikadesk processes that data only on the customer's documented instructions, which are to provide, secure, and improve the Service as described in Annex 1.
Definitions
Controller, processor, data subject, personal data, and processing have the meaning in Article 4 of the GDPR. Subprocessor means a third party fikadesk engages to process personal data under this DPA. SCCs means the European Commission's standard contractual clauses for controllers to processors, and the UK equivalent where the transfer is from the United Kingdom.
Processing details
The subject matter, nature, purpose, and duration of processing, and the categories of data subjects and personal data, are set out in Annex 1.
Processor obligations
fikadesk will:
- Process personal data only on the customer's documented instructions, including where the law requires us to process it.
- Ensure people authorized to process the data are bound by confidentiality.
- Take the technical and organizational measures in Annex 3.
- Engage subprocessors only under Section 5.
- Assist the customer in answering data subject requests using the controls in Section 6.
- Assist the customer with its obligations on security, breach notification, and data protection impact assessments where the information we hold can help.
- Delete or return personal data when the processing ends, as described in Section 9.
- Make information available to demonstrate compliance and allow audits under Section 10.
Controller obligations
The customer will:
- Have a lawful basis for the personal data it submits, and for instructing fikadesk to process it.
- Not submit special categories of personal data or data about children unless it has a lawful basis that supports that processing through the Service.
- Provide its own privacy notice to its end users, since the customer is the controller.
- Use the Service's controls, not email to fikadesk, to carry out day-to-day deletions and exports.
- Keep its account credentials secure.
Subprocessors
The customer authorizes fikadesk to engage the subprocessors in Annex 2, which lists the current set with the data they hold, the region they store it in, and why. Each subprocessor is bound by a written contract that imposes data protection terms no less protective than this DPA.
fikadesk remains liable to the customer for a subprocessor's acts and omissions as if they were its own. Before adding a new subprocessor, fikadesk will update the subprocessors page. That update is the notice, and the customer may object by terminating the Service if the addition is not acceptable.
Data subject rights
The Service gives the customer the controls to answer data subject requests. A contact can be exported as a JSON archive that includes the conversations, messages, and attachments tied to that person. A contact can be erased, which blanks their identifying fields and redacts the messages they wrote. Individual messages can be redacted on their own, and a whole workspace can be deleted.
Where a data subject contacts fikadesk directly, we refer them to the customer where we can identify it, because the customer is the controller. We will pass a request to the customer and assist where the law requires us to.
Security
fikadesk implements the technical and organizational measures in Annex 3. We test, assess, and adjust those measures as the Service changes.
Breach notification
If fikadesk becomes aware of a personal data breach, we will notify the customer without undue delay and no later than 72 hours after becoming aware. The notice describes the nature of the breach, the categories of data and data subjects affected, the likely consequences, and the measures taken or proposed to address it, where those facts are known at the time.
We will give the customer further details as they become available and help the customer meet its own notification obligations to authorities and data subjects.
Deletion and return
When this DPA ends, fikadesk deletes the customer's personal data from its systems, including backups, unless the law requires us to keep it. The customer can also delete its workspace itself, which removes the data and files the workspace holds.
Data that falls inside the workspace's retention window is deleted by the retention job once it passes the window. Contact export archives are deleted 7 days after they are created.
International transfers
Personal data is stored and processed in the regions listed on the subprocessors page. Where a subprocessor is located outside the European Economic Area or the United Kingdom, fikadesk relies on the SCCs, and the UK addendum where the transfer is from the United Kingdom, to keep the transfer lawful. The SCCs are incorporated into this DPA by reference.
Liability
Each party is liable for damage it causes by violating the GDPR in connection with its own processing. fikadesk's liability under this DPA is subject to the limitation of liability in the terms of service, except that nothing in this DPA limits a party's liability where the law forbids it.
Term and termination
This DPA runs for as long as the terms of service are in effect and continues until fikadesk has deleted the customer's personal data as described in Section 9.
Annex 1: processing details
Subject matter. The operation of the fikadesk Service: a shared inbox, website messenger, help center, AI agent, and outbound email.
Nature of processing. Collection, storage, retrieval, transmission, indexing and search, redaction, deletion, and, where the customer enables the AI agent, model inference over message content.
Purpose. Providing the Service to the customer, securing it, and answering support requests.
Duration. For the term of the agreement, then for the time needed to complete deletion under Section 9.
Data subjects. The customer's end users: contacts, website visitors, and the senders and recipients of email the customer handles.
Data categories. Contact details such as name, email address, phone number, and custom attributes. Message content and attachments. Email metadata such as sender, recipient, and subject. Usage timestamps tied to those records.
Special categories. The Service is not designed for special category data. The customer agrees not to submit it unless it has a lawful basis that covers processing through the Service.
Annex 2: subprocessors
The current subprocessors are:
- Cloudflare R2, for object storage of attachments, archived email, and contact exports.
- Leaseweb, for hosting the servers that run the Service.
- OVHcloud, for hosting the servers that run the Service.
- Paddle, as merchant of record for payments.
- Postmark and AWS SES, for sending transactional and support email.
The full list, with the data each subprocessor holds, the region it stores it in, and the purpose, is maintained at /legal/subprocessors and is part of this Annex.
Annex 3: technical and organizational measures
fikadesk maintains the following measures:
- Access control. Role-based permissions and scoped database sessions. Each request resolves to one workspace, and row-level security keeps one workspace from reading another's rows.
- Encryption in transit. All traffic is served over TLS.
- Encryption at rest. Storage and hosting providers encrypt stored data, including object storage and database volumes.
- Pseudonymization and erasure. Message redaction removes content and attachment metadata while preserving thread structure. Contact erasure blanks identifying fields and redacts authored messages.
- Deletion processes. A scheduled retention job deletes data past its window, and workspace deletion removes all rows and files for an account.
- Logging and monitoring. Request and error logs support incident investigation and abuse detection.
- Vendor management. Subprocessors are selected, contracted, and reviewed under this DPA's terms.
- Incident response. A documented process for detecting, containing, and notifying breaches under Section 7.