Zendesk AI
Graded against 804 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.
“Generative AI functionality: All generative AI functionality is powered by third-party LLMs. These models are pre-trained and Zendesk customer data will never be used by the third-party LLM provider to train their model(s). See About Generative AI at Zendesk”
Partially verified: Privacy Policy assessed · Terms of Service pending. Everything below comes only from what was read in full.
Watch: audit rights dpa residency
Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.
Restricts HIPAA BAA coverage for Zendesk AI to customers who have access to the Advanced Compliance Add-on, establishing a tier-based eligibility condition for executing a Business Associate Agreement.
SOC 2 Type II reports are the primary mechanism by which customers can independently verify security controls. Requiring an NDA is standard industry practice but does restrict access and creates a procedural barrier for risk assessments.
Granular data lifecycle management is gated behind an advanced/paid tier. Organizations with complex regulatory requirements (e.g., GDPR, CCPA conditional deletion) may be unable to meet their obligations on standard plans without upgrading.
Scores derived from 43 enriched findings — same verbatim citations as below. AI-generated, not legal advice.
- Zendesk AI's terms explicitly protect your inputs from training use — the policy is affirmatively favorable on this point.
- Your outputs and prompts are explicitly yours — Zendesk AI's terms include affirmatively protective IP language.
Derived from AI-enriched analysis of the verified findings below — informational only, not legal advice.
How to read this page: Overall risk rates what Zendesk AI's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.
Policy benchmark
rubric v1.0 — how this is scoredIP/output assessment pending — terms of service not yet verified This lens receives a band only once its source document has been captured and read in full.
Know where this document lives? Point us to the URL or PDF and the pipeline will verify it.
Based on 203 verified, verbatim-cited findings below — read the citations.
Automated assessment against a published rubric — not legal advice.
Partially verified — Privacy Policy — Verified (read in full, 116 findings); Terms of Service — Capture under review. Findings below are from fully-read, verified documents only; remaining core documents are pending capture.
Needs review
A core policy document is captured but requires review before AIRIN can mark the corpus fully verified.
- Privacy PolicyVerified - read in full - 116 citationsstaticLast captured 2026-08-03
- Terms of ServiceCompleteness unconfirmedrendered
Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.
This clause establishes two procedural mechanisms—manual and automatic redaction—for removing sensitive data (including credit card numbers) from ticket comments and attachments via UI or API, describing how confidential information is protected and deleted from Zendesk storage.
" Zendesk has two types of redaction for removing sensitive data: Manual redaction provides the ability to redact or remove sensitive data in Support ticket comments, and securely delete attachments, so you can protect confidential informat..."
Establishes an obligation that Zendesk's globally distributed Security Team is on call 24/7 to respond to security alerts and events, representing a continuous security response commitment.
" Our globally distributed Security Team is on call 24/7 to respond to security alerts and events."
Describes Zendesk's obligation to operate a SIEM system that gathers logs from network devices and host systems and alerts the Security team based on correlated events for investigation and response.
" Our Security Incident Event Management (SIEM) system gathers extensive logs from important network devices and host systems. The SIEM alerts on triggers that notify the Security team based on correlated events for investigation and respon..."
Restricts access to the Zendesk Production Network on a need-to-know basis with least privilege principles, mandatory multi-factor authentication, and frequent auditing, establishing access control obligations binding on Zendesk employees.
" Access to the Zendesk Production Network is restricted on an explicit need-to-know basis, utilizes least privilege, is frequently audited and monitored, and is controlled by our Operations Team. Employees accessing the Zendesk Production ..."
This clause establishes Zendesk's obligation to provide Security Awareness Training upon hire and annually, Secure Code Training for engineers annually, and ongoing security awareness communications, imposing internal security training obligations on the company.
" All employees attend a Security Awareness Training, which is given upon hire and annually thereafter. All engineers receive annual Secure Code Training. The Security team provides additional security awareness updates via email, blog post..."
Details the operational steps and capabilities of both manual and automatic redaction tools, explaining how sensitive data is removed from tickets via UI or API and how credit card numbers are partially replaced, constituting a data minimization procedure.
" Zendesk has two types of redaction for removing sensitive data: Manual redaction provides the ability to redact or remove sensitive data in Support ticket comments, and securely delete attachments so that you can protect confidential inf..."
This clause establishes Zendesk's obligation to provide free TLS encryption and automatically renew certificates for host-mapped Guide help centers, and grants the subscriber a permission to upload their own certificate, imposing a data security obligation on Zendesk.
" Zendesk provides free TLS encryption for host-mapped Guide help centers. Zendesk uses Let’s Encrypt to request certificates and automatically renews the certificate before it expires. You can also upload your own certificate, if you cho..."
This segment describes Zendesk's data replication practices using AWS for backup and archival, references the Regional Data Hosting Policy for further details, and outlines security audit and incident management procedures, establishing operational obligations relating to subprocessor use and data security.
" Access : Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving ..."
Evidence appendix
Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.
"For businesses that need a higher level of data privacy and security, Zendesk offers the Advanced Data Privacy and Protection add-on . The add-on includes capabilities for BYOK encryption, customizable data retention policies, data masking, PII redaction, and access logs"
Users on standard plans lack BYOK, customizable retention, and PII redaction capabilities by default. This creates risk for regulated industries where these controls may be required for compliance.
AI-generated interpretation, not legal advice.
"Zendesk offers ticket and end-user data deletion schedules right out of the box, regardless of plan. For Advanced Data Privacy and Protection customers with more nuanced data deletion requirements, Zendesk also offers advanced data retention policies, allowing customers to create conditional deletion schedules."
Granular data lifecycle management is gated behind an advanced/paid tier. Organizations with complex regulatory requirements (e.g., GDPR, CCPA conditional deletion) may be unable to meet their obligations on standard plans without upgrading.
AI-generated interpretation, not legal advice.
" Disclosure of Service Data : Zendesk only discloses Service Data to third parties where disclosure is necessary to provide or improve the services or as required to respond to lawful requests from public authorities. Please see our Government Data Request Policy as well as the Zendesk Transparency Report ."
This segment restricts Zendesk's disclosure of Service Data to third parties to only two circumstances: where disclosure is necessary to provide or improve services, or as required by lawful requests from public authorities, and incorporates by reference the Government Data Request Policy and Transparency Report as operative governing documents.
AI-generated interpretation, not legal advice.
" The Zendesk AI is eligible for coverage under Zendesk’s Business Associate Agreement (BAA) . Customers interested in executing a BAA with Zendesk must have access to the Advanced Compliance Add-on ."
Restricts HIPAA BAA coverage for Zendesk AI to customers who have access to the Advanced Compliance Add-on, establishing a tier-based eligibility condition for executing a Business Associate Agreement.
AI-generated interpretation, not legal advice.
"We undergo routine audits to receive updated SOC 2 Type II reports, available upon request and under NDA. Request the latest SOC 2 Type II report ."
SOC 2 Type II reports are the primary mechanism by which customers can independently verify security controls. Requiring an NDA is standard industry practice but does restrict access and creates a procedural barrier for risk assessments.
AI-generated interpretation, not legal advice.
" Data Subject Requests : An individual who seeks to exercise their data protection rights in respect of personal data stored or processed by us on behalf of a subscriber of ours within the subscriber’s Service Data (including to seek access to, or to correct, amend, delete, port, or restrict processing of such personal data) should direct such query to our subscriber (the data controller). Upon receipt of a request from one of our subscribers to remove personal data from Zendesk, we will respond to such request within thirty (30) days. We will retain personal data that we process and store on behalf of our subscribers for as long as needed to provide the Services to our subscribers. Zendesk's data subject request platform is available at this webform: https://www.zendesk.com/datasubjectrequest/ "
This segment establishes the procedure for data subjects to exercise privacy rights (access, correction, deletion, portability, restriction) by directing requests to the subscriber as data controller, and specifies Zendesk's obligation to respond to removal requests within thirty days and to retain personal data it processes on behalf of subscribers.
AI-generated interpretation, not legal advice.
" Replication : Zendesk periodically replicates data for purposes of archival, backup, and audit logs. We use Amazon Web Services (AWS) to store some of the information that is backed up, such as database information and attachment files. Please see our Regional Data Hosting Policy for further details. Security : Zendesk prioritizes data security and combines enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure subscriber and business data is protected. See additional information here . Security Incidents : For more information about security incident management see our Security Incident Response . Sub-processors : Zendesk may use sub-processors, including affiliates of Zendesk, as well as third-party companies, to provide, secure, or improve the Services, and such sub-processors may have access to Service Data. Our Sub-processors policy provides an up-to-date list of the names and locations of all sub-processors. Termination : Zendesk maintains a Service Data Deletion Policy that describes Zendesk’s data deletion processes upon subscriber’s termination or expiration of the Zendesk subscription."
This segment describes Zendesk's data replication for archival, backup, and audit log purposes using AWS as a subprocessor, and references the Regional Data Hosting Policy, establishing procedures for data storage and security incident handling.
AI-generated interpretation, not legal advice.
" All Service Data is hosted in Zendesk’s existing AWS regions , except that certain features offered through acquisitions such as QA and AI Agents - Advanced may remain on Google Cloud Platform (GCP) hosting locations in the US and/or Europe for a period of time until fully integrated to Zendesk. For sub-processor hosting locations, please see the Zendesk Sub-processor Policy . Use of Zendesk AI does not impact any Customer data locality commitments, including those available in the Data Center Location Add-on . Service Data of eligible Customers will continue to be hosted in the selected region."
Specifies data hosting locations (AWS regions, with exceptions for GCP for certain acquired features), references the Sub-processor Policy for sub-processor hosting locations, and confirms that use of Zendesk AI does not affect customer data locality commitments including those in the Data Center Location Add-on, establishing binding data residency obligations and cross-referencing the sub-processor policy.
AI-generated interpretation, not legal advice.
" Zendesk offers Audit Logs to accounts with Enterprise/Enterprise Plus plans. These logs include account changes, user changes, app changes, business rules, ticket deletions, and settings. The Audit Log is available in both the Admin Center and Support API . To learn more about Audit Logs and see what information is available within the log please see Viewing the audit log for changes ."
This clause grants Enterprise/Enterprise Plus plan subscribers the right to access Audit Logs recording account, user, app, business rules, ticket deletion, and settings changes via Admin Center and Support API, establishing a tier-differentiated audit access right.
AI-generated interpretation, not legal advice.
" To achieve a HIPAA-Enabled Account, you will need to (1) purchase the Advanced Security Deployed Associated Service or Advanced Compliance Deployed Associated Service Add-On; (2) enable a set of security configurations as outlined by Zendesk; and (3) execute our Business Associate Agreement (“BAA”). For more details, including a list of which Services can be HIPAA-enabled, please see Advanced Compliance ."
This segment establishes the tiered procedure subscribers must follow to achieve HIPAA compliance, requiring purchase of specific add-on services, enabling security configurations, and executing a Business Associate Agreement, creating tier-specific access conditions for HIPAA-enabled functionality.
AI-generated interpretation, not legal advice.
" We do not “sell” our subscriber’s personal information as defined under the CCPA. We may share aggregated and/or anonymized information regarding use of the Service(s), which is not considered personal information under the CCPA, with third parties to help us develop and improve the Services and provide our subscribers with more relevant content and service offerings as detailed in our subscriber agreements. Zendesk’s CCPA Addendum has been incorporated into Zendesk’s Data Processing Agreement. If you would like to review and/or execute Zendesk’s Data Processing Agreement, please click here. If you would like to review and/or execute Zendesk’s US State Addendum to the Main Services Agreement, please click here ."
This clause restricts Zendesk from 'selling' subscriber personal information under the CCPA, and imposes a restriction permitting only the sharing of aggregated/anonymized information with third parties for service improvement, while incorporating the CCPA Addendum into the Data Processing Agreement and providing a procedure to execute it.
AI-generated interpretation, not legal advice.
"Zendesk offers Audit Logs to accounts with Enterprise/Enterprise Plus plans. These logs include account changes, user changes, app changes, business rules, ticket deletions, and settings."
"Zendesk offers Audit Logs to accounts with Enterprise/Enterprise Plus plans."
This span carries the plan-specific language - verbatim from the policy.
Audit logging is a key compliance and security control. Restricting it to Enterprise plans means Free and lower-tier Paid customers have diminished forensic and compliance capabilities.
AI-generated interpretation, not legal advice.
" Does Zendesk use customer Service Data to train machine learning models? Zendesk offers three types of machine learning functionality:"
Introduces the three categories of machine learning functionality offered by Zendesk, establishing definitional framework for how customer Service Data may be used in training contexts.
AI-generated interpretation, not legal advice.
" 1. Account-specific machine learning: Zendesk creates classification or clustering machine learning models tailored to a customer’s account using only data existing in the account. Account-specific models will not be used by any other customer."
Restricts account-specific machine learning models to use only data from the individual customer's account and prohibits those models from being used by any other customer, establishing a data isolation obligation for account-specific ML.
AI-generated interpretation, not legal advice.
" 3. Generative AI functionality: All generative AI functionality is powered by third-party LLMs. These models are pre-trained and Zendesk customer data will never be used by the third-party LLM provider to train their model(s). See About Generative AI at Zendesk ."
Restricts third-party LLM providers from using Zendesk customer data to train their models, establishing a contractual prohibition on downstream training use by generative AI subprocessors.
AI-generated interpretation, not legal advice.
" Access to the Zendesk Production Network is restricted on an explicit need-to-know basis, utilizes least privilege, is frequently audited and monitored, and is controlled by our Operations Team. Employees accessing the Zendesk Production Network are required to use multiple factors of authentication."
Restricts access to the Zendesk Production Network on a need-to-know basis with least privilege principles, mandatory multi-factor authentication, and frequent auditing, establishing access control obligations binding on Zendesk employees.
AI-generated interpretation, not legal advice.
" Zendesk provides an advanced set of access and encryption features to help subscribers effectively protect their information. We do not access or use subscriber data for any purpose other than providing, maintaining, and improving the Zendesk Services and as otherwise required by applicable law. Additional information is available here ."
This segment restricts Zendesk's access to and use of subscriber data to only the purposes of providing, maintaining, and improving its services and as required by applicable law, establishing a binding limitation on permissible data use.
AI-generated interpretation, not legal advice.
" Zendesk’s spam filtering service can be used to prevent end-user spam posts from being published in your Guide help center. Learn about filtering spam in Guide ."
This clause describes Zendesk's spam filtering service as a tool subscribers can use to prevent end-user spam posts from being published in the Guide help center, constituting a content moderation enforcement mechanism.
AI-generated interpretation, not legal advice.
Common questions about Zendesk AI's policies
- Does Zendesk AI train its AI models on your data?
- No training on your content by default — based on 6 verified findings from Zendesk AI's published policy. Informational only, not legal advice.
Clause detail — protections, your obligations, and coverage
Every clause below is a verbatim quote from Zendesk AI's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.
✅ Protections found
34 verified clausesClauses in Zendesk AI's policies that work in your favour — commitments the platform made to you.
- Audit rights, DPA & residency
“Since our inception, Zendesk’s approach has been anchored by a strong commitment to privacy, security, compliance, and transparency. This approach includes supporting our subscribers’ compliance with EU data protection requirements, such as those set out in th…”
This segment identifies Zendesk's obligation to support subscriber compliance with GDPR requirements, including the requirement that third-party data processors guarantee implementation of technical and organizational me…
📍 Privacy Policy › “Europe General Data Protection Regulation (GDPR)”Jump to exact text → - Privacy & data useproduct telemetry/usage tracking
“Access : Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services…”
This segment describes Zendesk's data replication practices using AWS for backup and archival, references the Regional Data Hosting Policy for further details, and outlines security audit and incident management procedur…
📍 Privacy Policy › “Additional information”Jump to exact text → - Audit rights, DPA & residency
“The Brazilian General Data Protection Law or Lei Geral de Proteção de Dados Pessoais (“LGPD”), was entered into effect on September 18, 2020. LGPD is a comprehensive data protection law which covers the activities of data controllers and processors and provide…”
This clause incorporates Brazil's LGPD as an applicable data protection framework, defines Zendesk subscribers as potential 'controllers' and Zendesk as a 'processor,' and assigns primary compliance responsibility to con…
📍 Privacy Policy › “Brazil Lei Geral de Proteção de Dados Pessoais (LGPD)”Jump to exact text → - Subprocessors & data sharingdata shared with other AI providers
“Service Data processed by Zendesk AI is subject to all security standards and commitments, including compliance with Zendesk’s robust Enterprise Security Measures , and storage within Zendesk’s SOC 2-compliant environment . Service Data will not be shared wi…”
Specifies that Service Data processed by Zendesk AI is subject to all security standards, will not be shared with other customers, and identifies third-party LLM subprocessors (OpenAI, Microsoft Azure, Amazon Bedrock, Go…
📍 Privacy Policy › “Data Security”Jump to exact text → - Privacy & data usesensitive data (biometric/location/health)
“Zendesk has two types of redaction for removing sensitive data: Manual redaction provides the ability to redact or remove sensitive data in Support ticket comments, and securely delete attachments, so you can protect confidential information. The data is redac…”
This clause establishes two procedural mechanisms—manual and automatic redaction—for removing sensitive data (including credit card numbers) from ticket comments and attachments via UI or API, describing how confidential…
📍 Privacy Policy › “Redaction”Jump to exact text → - Audit rights, DPA & residency
“Binding Corporate Rules (BCRs) : Binding Corporate Rules (“BCRs”) are company-wide data protection policies approved by European data protection authorities to facilitate intra-group transfers of personal data from the European Economic Area (“EEA”) to countri…”
Approved BCRs provide a legally recognized mechanism for cross-border data transfers within the Zendesk group under GDPR. This is a favorable compliance posture for subscribers whose data may be processed across jurisdic…
📍 Privacy Policy › “Europe General Data Protection Regulation (GDPR)”Jump to exact text →
+ 28 more verified clauses of this kind on this platform, cited in full in the report.
📋 Rules you must follow
0 verified clausesWhat Zendesk AI requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.
No user-conduct rule has been verified in Zendesk AI's published policies yet.
What the policies actually cover
9 topics- Product telemetry & usage tracking1 protective8 clauses
- Advertising & tracking3 clauses
- Sale or sharing of personal data1 protective1 clause
- Sensitive data (biometric, location, health)1 protective1 clause
- Government & law-enforcement disclosure2 clauses
- Data shared with other AI providers1 protective1 clause
- Does not train on your content5 protective5 clauses
- Deletion rights & post-termination survival2 protective6 clauses
- Breach-notification promises2 clauses
87 further verified clauses are cited on this page but not yet assigned a topic.
Cross-clause notes
Two verified clauses intersect on the same subject matter: the Privacy Policy, Privacy Policy › “Data Minimization Features” addresses how long content is retained, and the Privacy Policy, Privacy Policy › “Model Training” addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.
Verified retention clauses point in different directions: the Privacy Policy, Privacy Policy › “Europe General Data Protection Regulation (GDPR)” describes broad or open-ended retention, while the Privacy Policy, Privacy Policy › “Data Minimization Features” describes deletion or erasure. Which clause controls in a given situation is not resolved by the documents' text alone — this is surfaced as an ambiguity, treated as Caution.
Automated cross-reference against the published rubric — not legal advice.
Clause intelligence
Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.
The clause affirms user ownership or retention of rights.
“Ownership : From a privacy perspective, the subscriber is the controller of Service Data and Zendesk is a processor. This means that throughout the time that you subscribe to services with Zendesk, you retain ownership of and control over Service Data in your Zendesk instance.”Open source citation
The clause affirms user ownership or retention of rights.
“Access : Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information. Data Hosting : Zendesk uses Amazon Web Services to host Service Data as described here...”Open source citation
The clause affirms user ownership or retention of rights.
“Access : Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information. Data Hosting : Zendesk uses Amazon Web Services to host Service Data as described here...”Open source citation
The clause affirms user ownership or retention of rights.
“Access : Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information. Data Hosting : Zendesk uses Amazon Web Services to host Service Data as described here...”Open source citation
The clause affirms user ownership or retention of rights.
“Access : Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information. Data Hosting : Zendesk uses Amazon Web Services to host Service Data as described here...”Open source citation
Tier matrix
Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.
| Tier | Surface | Verdict | Risk | Citations |
|---|---|---|---|---|
| All applicable tiers | commercial use | conditional | MEDIUM | 3 |
| All applicable tiers | output ownership | improves | LOW | 1 |
| All applicable tiers | privacy data use | worsens | HIGH | 8 |
| All applicable tiers | subprocessors data sharing | conditional | MEDIUM | 2 |
| All applicable tiers | training use | worsens | HIGH | 24 |
| Enterprise | tier differences | conditional | MEDIUM | 1 |
| Government | data retention | improves | LOW | 3 |
| Government | subprocessors data sharing | improves | LOW | 5 |
| Team / Business | tier differences | conditional | MEDIUM | 3 |
Policy evolution
Open full timelineBefore/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.
data sharing worsened from medium/third party or vendor sharing to high/sale or sell.
“Disclosure of Service Data : Zendesk only discloses Service Data to third parties where disclosure is necessary to provide or improve the services or as required to respond to lawful requests from public authorities.”Before citation
“We do not “sell” our subscriber’s personal information as defined under the CCPA. We may share aggregated and/or anonymized information regarding use of the Service(s), which is not considered personal information under the CCPA, with third parties to help us develop and improve the Services and provide our subscribers with more relevant content and service offerings as detailed in our subscriber agreements. Zendesk’s CCPA Addendum has been incorporated into Zendesk’s Data Processing Agreement. If you would like to review and/or execute Zendesk’s Data Processing Agreement, please click here. If you would like to review and/or execute Zendesk’s US State Addendum to the Main Services Agreement, please click here .”After citation
Latest stance: training permitted on training use
“How does Zendesk protect Service Data when used for model training? Before Service Data is used to train generic ML functionality, Zendesk applies aggregation and sanitation processes, as necessary. No fields designed to intake personal data or ticket attachments are used for model training. Zendesk is committed to ensuring that no Service Data will be reproduced by the model. There is no risk that one customer’s data will be exposed to another customer through the model’s output. See AI Data Use Information .”Open timeline citation
Latest stance: training permitted on training use
“3. Generative AI functionality: All generative AI functionality is powered by third-party LLMs. These models are pre-trained and Zendesk customer data will never be used by the third-party LLM provider to train their model(s). See About Generative AI at Zendesk .”Open timeline citation
Latest stance: third party or vendor sharing on commercial use
“The California Consumer Privacy Act , Cal. Civ. Code §§ 1798.100 et seq. (“CCPA”) is a U.S. law enacted in the State of California, which went into force on January 1, 2020. It expands upon the privacy rights available to certain California consumers, and requires certain companies to comply with various data protection requirements. Please also visit the final CCPA Regulations and the California Privacy Rights Act (“CPRA”). A few CPRA provisions went into effect on December 16, 2020, with the remaining provisions of the CPRA becoming operative on January 1, 2023. Zendesk subscribers that collect and store personal information in Zendesk Services may be considered “Businesses” under the CCPA. Businesses bear the primary responsibility for ensuring that their processing of personal data is compliant with relevant data protection law, including the CCPA. Zendesk acts as a “Service Provider,” as such term is defined in the current version of the CCPA, with respect to the processing of personal information through our Services. Therefore, Zendesk collects, accesses, maintains, uses, processes, and transfers the personal information of our subscribers and our subscriber’s end-users processed through the Services solely for the purpose of performing our obligations under our existing contract(s) with our subscribers; and for no commercial purpose other than the performance of such obligations and improvement of the Services we provide.”Open timeline citation
Latest stance: training permitted on training use
“2. Generic machine learning: Zendesk uses Service Data to train its generic, cross-account machine learning models to be predictive and useful to multiple Zendesk customers. These include global and industry models. These models will never disclose one customer’s Service Data to another customer, because they are not “generative” (i.e., they do not create text - See Model Security section).”Open timeline citation
Capture recency
- Privacy Policy:Last captured 2026-08-03· verified 2026-08-03
- Terms of Service:Last captured 2026-08-24· verified 2026-06-09not re-verified in 93 days
Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.
↓ 21 fewer findings this quarter vs last (160 vs 181). First scan: June 2026.
Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Zendesk AI's policies — no human edits the data.
Need this for procurement or legal diligence?
Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.
Know where the missing document lives?
We haven't yet verified Zendesk AI's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.
Every finding above is a verbatim quote from Zendesk AI's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.