This agreement forms part of the subscription between flyhelpdesk (the processor) and the customer that runs a workspace on the service (the controller). It sets out the terms required by Article 28 of the GDPR, the UK GDPR and similar laws for the personal data the service processes on the customer’s behalf.
Processor: flyhelpdesk · Privacy contact: [email protected]
1. Roles
The customer decides why and how personal data in its workspace is processed and is the controller. flyhelpdesk processes that data only to provide the service and is the processor. Where the customer is itself a processor for its own clients, flyhelpdesk is its sub-processor and these terms apply in the same way.
2. Instructions
flyhelpdesk processes personal data only on the customer’s documented instructions: this agreement, the terms of service, and what the customer’s administrators configure in the workspace. If an instruction appears to break data protection law, flyhelpdesk will say so before acting on it, unless the law forbids that.
3. Confidentiality
Everyone at flyhelpdesk who can reach customer data is bound by confidentiality, and access is limited to those who need it to run, secure or support the service. Support staff reach a workspace only when the customer asks for help or to keep the service secure, and that access is logged.
4. Security
flyhelpdesk keeps the technical and organisational measures in Annex II in place, and may improve them, but will not lower the overall level of protection.
5. Sub-processors
The customer authorises the sub-processors listed on the sub-processors page. flyhelpdesk gives at least 30 days’ notice of a new one there; the customer may object on reasonable data protection grounds, and if no solution is found may end the affected service. Each sub-processor is bound by terms that protect the data at least as well as these. Sub-processors
6. Where data is kept
A workspace’s data is stored in the data region chosen for it. Where personal data is transferred outside the UK or the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses (and the UK Addendum), or by an adequacy decision.
7. Requests from people
The service lets the customer answer data subjects itself: export a person’s data, correct it, and erase them from the workspace (Compliance → Data requests). If a request reaches flyhelpdesk directly, it is passed to the customer without answering it.
8. Breaches
flyhelpdesk tells the customer of a personal data breach affecting its workspace without undue delay, and within 48 hours of becoming aware of it, with what is known of its nature, the data and people involved, the likely consequences and the steps taken, and keeps the customer informed as more is learned.
9. Help and audits
flyhelpdesk helps the customer with impact assessments and consultations with authorities as far as they concern the service, and makes available the information needed to show these terms are met. The customer may audit that, on 30 days’ notice and at most once a year unless a breach or an authority requires otherwise, relying first on the security documentation and reports flyhelpdesk provides.
10. At the end
Before the subscription ends the customer can export its data. flyhelpdesk deletes the workspace within 30 days of the end, and its backups as they expire, within 14 days after that, unless the law requires a copy to be kept.
11. Precedence and liability
Where this agreement and the terms of service differ on personal data, this agreement prevails; where the Standard Contractual Clauses apply, they prevail over both. Liability under this agreement follows the limits in the terms of service, except where the law does not allow them to be limited.
12. Security incidents (NIS2)
Where the customer is an essential or important entity under the NIS2 Directive (EU 2022/2555) and the laws implementing it, flyhelpdesk tells it of any significant incident affecting the service within 24 hours of becoming aware of it, with what it needs for its own early warning; gives an update within 72 hours with an assessment of severity and impact and the indicators known; and a final report within one month. flyhelpdesk manages the security of its own supply chain and answers the customer's reasonable supplier-security questions.
13. India (DPDP Act)
Where the customer is a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 and its Rules, flyhelpdesk is its Data Processor: it processes personal data only under this agreement; helps the customer give data principals their rights (access, correction, erasure, grievance redress and nomination) through the tools in clause 7; tells it of a personal data breach within 48 hours so it can inform the Data Protection Board and the people affected; keeps the measures in Annex II as reasonable security safeguards; and erases the data when the customer instructs or at the end, under clause 10.
14. Switching and exit (EU Data Act)
The customer may switch to another provider or to its own systems at any time, on at most 30 days' notice. flyhelpdesk makes all the workspace's exportable data available in open, machine-readable formats free of charge (Compliance → Data requests → Export everything), supports the move during a transition of up to 30 days, keeps the data retrievable for at least 30 days after it, and charges no switching or data-egress fees. The switching annex on the switching page describes the data, formats and steps.
15. Accepting it
An administrator of the workspace can accept this agreement on the customer’s behalf in Compliance → Data requests, and download a copy recording who accepted it, for which organisation, which version and when. Nothing needs to be signed on paper.
Annex I: the processing
- People
- The customer’s own customers and their contacts, people who write to the customer’s support addresses or portal, and the customer’s staff who use the service.
- Data
- Names, email addresses, phone numbers and company details; the content of tickets, emails, chats, calls and their attachments; portal activity; staff accounts and sign-in records; technical data such as IP addresses. The customer should not send special-category data through the service unless it has a lawful basis to.
- Purpose and duration
- Providing the help desk: receiving, organising and answering support requests, the features the customer turns on (such as AI assistance, telephony and campaigns), keeping it secure and backed up. For as long as the subscription lasts, then until deletion under clause 10.
Annex II: security measures
- Encryption in transit (TLS, HSTS) and of secrets at rest with a separate key per workspace, rotatable.
- Each workspace’s data kept apart from every other’s, enforced on every query and covered by tests.
- Roles with least privilege; multi-factor sign-in (authenticator apps, passkeys) that the customer can require; single sign-on and SCIM; session timeouts; network allow-lists; a recent sign-in required for sensitive settings.
- A tamper-evident audit log of access and changes, and monitoring that alerts on suspicious activity.
- Daily encrypted backups, verified, kept off-site and restored into a scratch copy every week to prove they work.
- Attachments scanned for malware; outbound connections to customer-set addresses checked so they cannot reach internal networks.
- A recorded incident and breach process, and dependencies checked for known vulnerabilities on every change.
Administrators can accept this agreement in the app: Compliance → Data requests.
This document is a template provided with the platform and should be reviewed by your own legal counsel before you rely on it for a production service.