Zendesk AI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk maintains a publicly available system-status webpage , which includes system availability details, scheduled maintenance, service incident history, and relevant security events.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ CSA STAR AI Levels 1 & 2 certify advanced cloud security and AI governance practices, with Zendesk proudly being the first in the industry to achieve this recognition.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk has achieved a number of internationally recognized certifications and accreditations demonstrating compliance with third-party assurance frameworks. Security certifications are described here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ All Service Data is hosted in Zendesk’s existing AWS regions , except that certain features offered through acquisitions such as QA and AI Agents - Advanced may remain on Google Cloud Platform (GCP) hosting locations in the US and/or Europe for a period of time until fully integrated to Zendesk. For sub-processor hosting locations, please see the Zendesk Sub-processor Policy . Use of Zendesk AI does not impact any Customer data locality commitments, including those available in the Data Center Location Add-on . Service Data of eligible Customers will continue to be hosted in the selected region.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Access to data within Zendesk applications is governed by role-based access control (RBAC) and can be configured to define granular access privileges. Zendesk supports various permission levels for users (owner, admin, agent, end-user, etc.). Learn about user roles:” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ To achieve a HIPAA-Enabled Account, you will need to (1) purchase the Advanced Security Deployed Associated Service or Advanced Compliance Deployed Associated Service Add-On; (2) enable a set of security configurations as outlined by Zendesk; and (3) execute our Business Associate Agreement (“BAA”). For more details, including a list of which Services can be HIPAA-enabled, please see Advanced Compliance .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Testing and staging environments are logically separated from the Production environment. No Service Data is used in our development or test environments.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Binding Corporate Rules (BCRs) : Binding Corporate Rules (“BCRs”) are company-wide data protection policies approved by European data protection authorities to facilitate intra-group transfers of personal data from the European Economic Area (“EEA”) to countries outside the EEA. BCRs are based on strict privacy principles established by European Union data protection authorities and require intensive consultation with those authorities. Subscribers can find the full list of approved entities on the Binding Corporate Rules Approved List here . In 2017 Zendesk completed the EU approval process with the Irish Data Protection Commissioner (“DPC”) (peer reviewed by both the UK Information Commissioner’s Office and the Dutch Data Protection Authority) BCRs as processor and as a controller” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk is ISO 27017:2015 certified. The certificate is available for download here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Annual secure code training for all engineers, based on OWASP Top 10 security risks. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk's Data Processor and Data Controller Binding Corporate Rules ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk is ISO 27018:2019 certified. The certificate is available for download here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Cyber Essentials Plus is a UK government-backed certification that demonstrates an organization’s commitment to strong cybersecurity through independent verification of key controls.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk offers several data processing agreements and other addenda to support subscribers’ compliance with data privacy laws, available for execution here . These include:” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Our Enhanced Disaster Recovery package adds contractual objectives for Recovery Time Objective (RTO) and Recovery Point Objective (RPO). These are supported through our capability to prioritize operations of Enhanced Disaster Recovery subscribers during any declared disaster event. Get more information on Disaster Recovery Guarantees. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Regional Data Hosting Policy Where Zendesk Service Data can be hosted if a Subscriber purchases or enables the Data Center Location Add-On.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Zendesk subscribers that collect and store personal data in Zendesk Services may be considered “controllers” under the LGPD. Controllers bear the primary responsibility for ensuring that their processing of personal data is compliant with relevant data protection law, including the LGPD. Zendesk acts as a “processor,” as such term is defined in the LGPD, with respect to the processing of personal data through our Services.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The Australian Privacy Act of 1988 (as amended) provides several data subject rights and added mandatory notification of eligible data breaches. Unlike the GDPR, there are no concepts of data controller and data processor. https://www.zendesk.com/company/anz-privacy/ ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk has a robust global privacy and data protection program, which takes a unified approach to privacy and information governance to give customers flexibility to manage personal data that lives within Zendesk’s systems. For details, see our product guides: Complying with Privacy and Data Protection in Zendesk Products .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The United Kingdom withdrew from the European Union on 31 January 2020. On 28 June 2021, the European Commission adopted adequacy decisions for transfers of personal data to the United Kingdom under GDPR.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “We undergo routine audits to receive updated SOC 2 Type II reports, available upon request and under NDA. Request the latest SOC 2 Type II report .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ ISO 42001 is the world’s first international standard for managing artificial intelligence. Achieving certification means that Zendesk’s AI practices — spanning design and development through deployment and ongoing monitoring — have been independently audited for conformance with a formal Artificial Intelligence Management System (AIMS) and demonstrate transparency, security, and responsible governance.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The Brazilian General Data Protection Law or Lei Geral de Proteção de Dados Pessoais (“LGPD”), was entered into effect on September 18, 2020. LGPD is a comprehensive data protection law which covers the activities of data controllers and processors and provides individual rights. Zendesk subscribers that collect and store personal data in Zendesk Services may be considered “controllers” under the LGPD. Controllers bear the primary responsibility for ensuring that their processing of personal data is compliant with relevant data protection law, including the LGPD. Zendesk acts as a “processor,” as such term is defined in the LGPD, with respect to the processing of personal data through our Services. Subscribers can view our Product Guides and Service Data Deletion Policy for more detailed information on how to use Zendesk’s products to align with compliance initiatives.The National Authority for Protection Data (“ANPD”) may issue additional guidance for the LGPD in the future. Zendesk will continue to actively track the law and we will continue to keep our subscribers updated on features and functionality they can use to support their compliance efforts. Zendesk’s LGPD Addendum has been incorporated into Zendesk’s Data Processing Agreement. If you would like to review and/or execute Zendesk’s Data Processing Agreement, please click here. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ Zendesk offers Audit Logs to accounts with Enterprise/Enterprise Plus plans. These logs include account changes, user changes, app changes, business rules, ticket deletions, and settings. The Audit Log is available in both the Admin Center and Support API . To learn more about Audit Logs and see what information is available within the log please see Viewing the audit log for changes .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ HDS enables healthcare providers in France to use Zendesk’s customer service and engagement platform with confidence that our platform has appropriate technical and governance measures in place to secure and protect personal health information (PHI). Additional information is available here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk hosts Service Data primarily in AWS data centers that have been certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC 2 compliant. Learn about Compliance at AWS . AWS infrastructure services include backup power, HVAC systems, and fire suppression equipment to help protect servers and ultimately your data. Learn about Data Center Controls at AWS .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk has a formal global privacy and data protection program, which includes cross-functional key stakeholders including Legal, Security, Product, and Executive sectors of the company. As privacy advocates, we work diligently to ensure our Services and team members are dedicated to compliance with applicable regulatory and industry frameworks.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk uses best practices and industry standards to achieve compliance with industry-accepted general security and privacy frameworks, which in turn helps our subscribers meet their own compliance standards.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ You can review and/or execute Zendesk’s DPA here . The Zendesk DPA covers the specific processing activities and security measures applicable to our Services and incorporates the new EU Standard Contractual Clauses (“EU SCCs”). Subscribers can read our Product Guides and Service Data Deletion Policy for detailed information on how to use Zendesk’s products to assist in compliance with data protection and privacy laws.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk leverages AWS data centers in the United States, Europe, and Asia Pacific. Learn about Data Hosting Locations for your Zendesk Service Data . Zendesk offers multiple data locality choices including the United States (US), Australia (AU), Japan (JP), or European Economic Area (EEA). For more information on product, plan, and regional offerings please see our Regional Data Hosting Policy .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “This significant regulatory approval validated Zendesk’s implementation of the highest possible standards for protecting personal data globally, covering both the personal data of its customers and its employees. Zendesk is one of the first software companies in the world to have received approval for its BCRs; and was the second company ever to receive approval from the Irish DPC. To access Zendesk's EU BCRs and UK addenda please visit:” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The New Zealand Privacy Act in 2020 commenced on December 1, 2020, applies to agencies and maintains the principle-based framework of the 1993 Act. The 2020 Act states that organisations are responsible for ensuring that personal information sent outside of New Zealand is adequately protected and added mandatory breach notification requirements. https://www.zendesk.com/company/anz-privacy/ ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Subscribers who purchase the Data Center Location Deployed Associated Service (“Data Center Location Add-on”), or have the Data Center Location functionality in their Service Plan, have the ability to select the region that will host their Service Data from a list of Zendesk available regions.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Shared Responsibility Model This framework clarifies which party is responsible for which controls related to the security and privacy of your data.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Since our inception, Zendesk’s approach has been anchored by a strong commitment to privacy, security, compliance, and transparency. This approach includes supporting our subscribers’ compliance with EU data protection requirements, such as those set out in the General Data Protection Regulation (“GDPR”). If a subscriber collects, transmits, hosts, or analyzes personal data of EU citizens, GDPR requires the subscriber to use third-party data processors who guarantee their ability to implement the technical and organizational requirements of the GDPR. To further earn our subscribers’ trust, our Data Processing Agreement (“DPA”) has been updated to provide our customers with contractual commitments regarding our compliance with applicable EU data protection law and to implement additional contractual provisions required by the GDPR. Binding Corporate Rules (BCRs) : Binding Corporate Rules (“BCRs”) are company-wide data protection policies approved by European data protection authorities to facilitate intra-group transfers of personal data from the European Economic Area (“EEA”) to countries outside the EEA. BCRs are based on strict privacy principles established by European Union data protection authorities and require intensive consultation with those authorities. Subscribers can find the full list of approved entities on the Binding Corporate Rules Approved List here . In 2017 Zendesk completed the EU approval process with the Irish Data Protection Commissioner (“DPC”) (peer reviewed by both the UK Information Commissioner’s Office and the Dutch Data Protection Authority) BCRs as processor and as a controller. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk has satisfied all requirements (Stage 1 and Stage 2) to become fully registered on the FSQS (Financial Services Qualification System) supplier qualification system, as set out by participating buying organisations. Request the latest FSQS Certificate here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk is ISO 27001:2022 certified. Download the certificate .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In addition to our extensive internal scanning and testing program, Zendesk employs third-party security experts to perform detailed penetration tests on different applications within our family of products.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk is FedRAMP authorized with Low Impact Software-as-a-Service (LI-SaaS) and is listed in the FedRAMP Marketplace . US Government agency subscribers can request access to the Zendesk FedRAMP Security Package by completing a Package Access Request Form or submitting a request to fedramp@zendesk.com .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ In addition to our extensive internal scanning and testing program, each year Zendesk employs third-party security experts to perform a broad penetration test across the Zendesk Production and Corporate Networks.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ The Zendesk AI is eligible for coverage under Zendesk’s Business Associate Agreement (BAA) . Customers interested in executing a BAA with Zendesk must have access to the Advanced Compliance Add-on .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ For businesses that need a higher level of data privacy and security, Zendesk offers the Advanced Data Privacy and Protection add-on . The add-on includes capabilities for BYOK encryption, customizable data retention policies, data masking, PII redaction, and access logs.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “The Zendesk DPA covers the specific processing activities and security measures applicable to our Services and incorporates the new EU Standard Contractual Clauses (“EU SCCs”).” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Explore our Conveyor Trust Portal for on-demand, self-serve access to up-to-date security artifacts — certifications, audit reports, policies, and questionnaire answers.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Zendesk is a member of the Cloud Security Alliance (CSA), a not-for-profit organization with a mission to promote the use of best practices for providing security assurance within Cloud Computing. CSA has launched the Security, Trust & Assurance Registry (STAR), a publicly accessible registry that documents the security controls provided by various cloud computing offerings. Zendesk completed a publicly available Consensus Assessment Initiative (CAI) Questionnaire, based on the results of our due diligence self-assessment. The CSA CAIQ is available here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | Enterprise | low | “Zendesk offers Audit Logs to accounts with Enterprise/Enterprise Plus plans. These logs include account changes, user changes, app changes, business rules, ticket deletions, and settings.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Zendesk offers ticket and end-user data deletion schedules right out of the box, regardless of plan. For Advanced Data Privacy and Protection customers with more nuanced data deletion requirements, Zendesk also offers advanced data retention policies, allowing customers to create conditional deletion schedules. Additionally, all Zendesk customers have access to standard redaction capabilities , so that sensitive ticket content can be permanently redacted. Advanced Data Privacy and Protection customers also have access to our AI-powered redaction suggestions feature, which automatically highlights certain types of data within tickets for agents to quickly redact.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Service Data Deletion Policy How our Subscribers’ Service Data is deleted in connection with the cancellation, termination, or migration of an Account within the Zendesk Services.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “Data is deleted in connection with the cancellation, termination, or migration of an Account within the Zendesk Services.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “ Data Subject Requests : An individual who seeks to exercise their data protection rights in respect of personal data stored or processed by us on behalf of a subscriber of ours within the subscriber’s Service Data (including to seek access to, or to correct, amend, delete, port, or restrict processing of such personal data) should direct such query to our subscriber (the data controller). Upon receipt of a request from one of our subscribers to remove personal data from Zendesk, we will respond to such request within thirty (30) days. We will retain personal data that we process and store on behalf of our subscribers for as long as needed to provide the Services to our subscribers. Zendesk's data subject request platform is available at this webform: https://www.zendesk.com/datasubjectrequest/ ” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ Data Deletion Policy How our Subscribers’ Service Data is deleted in connection with the cancellation, termination, or migration of an Account within the Zendesk Services.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | Paid | medium | “Zendesk offers ticket and end-user data deletion schedules right out of the box, regardless of plan. For Advanced Data Privacy and Protection customers with more nuanced data deletion requirements, Zendesk also offers advanced data retention policies, allowing customers to create conditional deletion schedules.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Legal or Government Request Policy Addresses Zendesk’s procedure for responding to a request received from a law enforcement or other government authority.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Disclosure of Service Data : Zendesk only discloses Service Data to third parties where disclosure is necessary to provide or improve the services or as required to respond to lawful requests from public authorities. Please see our Government Data Request Policy as well as the Zendesk Transparency Report .” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Service Data processed by Zendesk AI is subject to all security standards and commitments, including compliance with Zendesk’s robust Enterprise Security Measures , and storage within Zendesk’s SOC 2-compliant environment . Service Data will not be shared with any other customer. Generative AI features are currently powered by OpenAI (using zero data retention endpoints) or models hosted on Microsoft Azure, Amazon Bedrock, or Google Cloud Platform (where the model provider never has access to prompts or outputs). We also offer AI transcription services powered by Twilio and DeepGram. OpenAI data security practices are available here . Amazon Bedrock data security practices are available here . Microsoft Azure data security practices are available here . Google Cloud Platform data security practices are available here .” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ Replication : Zendesk periodically replicates data for purposes of archival, backup, and audit logs. We use Amazon Web Services (AWS) to store some of the information that is backed up, such as database information and attachment files. Please see our Regional Data Hosting Policy for further details. Security : Zendesk prioritizes data security and combines enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure subscriber and business data is protected. See additional information here . Security Incidents : For more information about security incident management see our Security Incident Response . Sub-processors : Zendesk may use sub-processors, including affiliates of Zendesk, as well as third-party companies, to provide, secure, or improve the Services, and such sub-processors may have access to Service Data. Our Sub-processors policy provides an up-to-date list of the names and locations of all sub-processors. Termination : Zendesk maintains a Service Data Deletion Policy that describes Zendesk’s data deletion processes upon subscriber’s termination or expiration of the Zendesk subscription.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ Zendesk minimizes risks associated with third-party vendors by performing security reviews on all vendors with any level of access to our systems or Service Data.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ We do not “sell” our subscriber’s personal information as defined under the CCPA. We may share aggregated and/or anonymized information regarding use of the Service(s), which is not considered personal information under the CCPA, with third parties to help us develop and improve the Services and provide our subscribers with more relevant content and service offerings as detailed in our subscriber agreements. Zendesk’s CCPA Addendum has been incorporated into Zendesk’s Data Processing Agreement. If you would like to review and/or execute Zendesk’s Data Processing Agreement, please click here. If you would like to review and/or execute Zendesk’s US State Addendum to the Main Services Agreement, please click here .” | Captured 2026-06-07Open source →Finding permalink → |
| Tier differences | Paid | medium | “For businesses that need a higher level of data privacy and security, Zendesk offers the Advanced Data Privacy and Protection add-on . The add-on includes capabilities for BYOK encryption, customizable data retention policies, data masking, PII redaction, and access logs” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.