Legal

Data processing addendum

The standard controller-to-processor terms for customer support content processed through a ReTicketDesk workspace.

Last updated July 9, 2026

Scope and roles

This addendum forms part of the ReTicketDesk terms or other agreement covering the service. The customer is controller of personal data placed in its workspace. ReTicketDesk is the processor and will process that data only to provide, secure, maintain, and support the service or as required by law. Each party remains responsible for its own compliance.

A countersigned copy identifying both contracting entities is available through the DPA contact route. These public terms remain the operational baseline while a signature copy is prepared.

Documented instructions

Customer instructions are expressed through workspace configuration, connected Resend accounts, authorized user actions, support requests, and this addendum. ReTicketDesk will notify the customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.

People and confidentiality

Access to workspace data is limited to authorized personnel and providers who need it to operate, secure, or support the service. Those people are subject to confidentiality duties. ReTicketDesk does not use workspace content for advertising or model training.

Security measures

  • TLS for public application and API traffic.
  • Provider-managed encryption for Azure storage and additional application encryption for Resend API keys and webhook secrets.
  • Workspace-scoped authorization checks and explicit role permissions.
  • Signature validation for Resend webhooks, provider-message deduplication, and inbound HTML sanitization.
  • Managed secret storage, production health checks, audit events, and restricted operational logging.
  • Backups and recovery controls supplied by the managed hosting providers.

More detail, current provider roles, and candid limitations are published on the security page.

Subprocessors

ReTicketDesk may use subprocessors where needed to provide the service. The current list is maintained on the security page. Material additions that affect workspace-content processing will be published before or promptly after the change, and customers may raise a reasonable data-protection objection through the contact page.

Data-subject and compliance assistance

Taking account of the nature of processing and information available, ReTicketDesk will provide reasonable assistance with data-subject requests, security assessments, breach obligations, and data-protection impact assessments. The customer remains responsible for verifying requests and deciding how to respond as controller.

Personal-data incidents

ReTicketDesk will notify the customer without undue delay after confirming a personal-data breach affecting customer workspace content. The notice will include available information about the nature, likely consequences, affected data, and mitigation. Notification is not an admission of fault or liability.

Return and deletion

On a verified request or when service processing ends, ReTicketDesk will return available workspace data or delete it, unless retention is required by law. Data may remain in restricted backups until normal rotation, during which it remains protected and is not used for ordinary product operations.

International transfers

Primary application and database services run in Azure North Europe. Some subprocessors may process limited data in other regions. Where a restricted transfer requires safeguards, ReTicketDesk relies on the provider's applicable transfer mechanism, including standard contractual clauses where offered and required.

Processing details

  • Subject: operating a shared customer-support inbox connected to Resend.
  • Duration: the service term plus the limited deletion and legal-retention period.
  • Data subjects: customer users, customer contacts, correspondents, and people mentioned in support conversations.
  • Data: identity and contact data, message content and metadata, notes, assignments, tags, audit events, and integration identifiers.
  • Operations: collection, receipt, organization, storage, search, display, transmission, support, security, export, and deletion.
Questions about these terms can be sent through the contact page. Do not email passwords, API keys, payment-card details, or customer message exports.