Paradraw
Zendesk/
notice

Security, Privacy and Legal | Zendesk Trust Center

1,716 words, 64 clausesno date on the pageread 08/10/2026source

·Secure Customer Service

·Cover your bases

·Zendesk takes security very seriously-just ask the number of Fortune 100 and Fortune 500 companies that trust us with their data. We use a combination of enterprise-class security features and comprehensive audits of our applications, systems, and networks to ensure that your data is protected, which means every customer can rest easy-our own included.

·Global Standards, Independently Verified

·Zendesk aligns with the world's most rigorous security and privacy frameworks. We don't just follow best practices; we undergo continuous independent auditing to ensure our controls meet the highest standards. This rigorous validation simplifies your own vendor risk assessments and helps you meet your compliance obligations with confidence. Learn more

SOC 2 Type IIWe undergo routine audits to receive updated SOC 2 Type II reports, available upon request and under NDA. Request the latest SOC 2 Type II report.
ISO 27001:2022Zendesk is ISO 27001:2022 certified. Download the certificate.
ISO 27018:2019Zendesk is ISO 27018:2019 certified. The certificate is available for download here.
ISO 27701:2019Zendesk is ISO 27701:2019 certified. The certificate is available for download here.
ISO 27017:2015Zendesk is ISO 27017:2015 certified. The certificate is available for download here.
ISO 42001ISO 42001 is the world's first international standard for managing artificial intelligence. Achieving certification means that Zendesk's AI practices - spanning design and development through deployment and ongoing monitoring - have been independently audited for conformance with a formal Artificial Intelligence Management System (AIMS) and demonstrate transparency, security, and responsible governance.
FedRAMP LI-SaaSZendesk is FedRAMP authorized with Low Impact Software-as-a-Service (LI-SaaS) and is listed in the FedRAMP Marketplace. US Government agency subscribers can request access to the Zendesk FedRAMP Security Package by completing a Package Access Request Form or submitting a request to fedramp@zendesk.com.
Cyber Essentials PlusCyber Essentials Plus is a UK government-backed certification that demonstrates an organization's commitment to strong cybersecurity through independent verification of key controls.
CSA STAR AI Levels 1 & 2CSA STAR AI Levels 1 & 2 certify advanced cloud security and AI governance practices, with Zendesk proudly being the first in the industry to achieve this recognition.

·Security Artifacts & Due Diligence

·Accelerate your vendor review. Gain instant, self-serve access to our comprehensive library of security documentation. Log in to the Trust Portal to download current certifications, audit reports, policy documents, and standardized security questionnaires.

SOC 2 Type IIOur security controls are audited annually against the AICPA Trust Services Criteria. Our Type II report covers Security, Availability, and Confidentiality, demonstrating the operating effectiveness of our controls over time.
ISO Certification SuiteZendesk maintains a comprehensive Integrated Management System (IMS) audited against key ISO standards. ISO 27001:2022: Information Security Management ISO 27017:2015: Cloud Security ISO 27018:2019: Privacy & PII Protection in the Cloud ISO 27701:2019: Privacy Information Management ISO 42001:2023: AI Management System

·Cloud Security

·We host Service Data primarily in Amazon Web Services (AWS) data centers that are certified as ISO 27001, PCI DSS Service Provider Level 1, and SOC 2 compliant.

Global ReachWe leverage data centers in the United States, Europe (EEA), and Asia Pacific.
Data LocalityYou can choose where your data resides based on your region.
Physical SecurityAWS data centers employ 24/7 surveillance, biometric access, and strict personnel controls.
Vendor Risk ManagementWe continuously safeguard our supply chain. Any third-party vendor with potential access to our systems or Service Data must undergo a rigorous security and privacy risk assessment prior to onboarding, followed by regular lifecycle reviews to ensure ongoing adherence to our strict standards.
Incident Response ReadinessOur 24/7 globally distributed Security, Network Engineering, and Operations teams adhere to a mature, continuously tested Incident Response Plan. In the event of an anomaly, established escalation protocols ensure rapid containment, remediation, and transparent communication.

·Product & People Security

·Security is integrated into every stage of our development process.

TrainingAll engineers receive annual secure code training based on OWASP Top 10 risks.
Automated ScanningWe use Static (SAST) and Dynamic (DAST) analysis tools to identify vulnerabilities in code and dependencies (SCA) before deployment.
Separate EnvironmentsDevelopment, testing, and staging environments are logically separated from production data.

·Welcome to the Zendesk Global Privacy Program

·Zendesk has a formal global privacy and data protection program, which includes cross-functional key stakeholders including Legal, Security, Product, and Executive sectors of the company. As privacy advocates, we work diligently to ensure our Services and team members are dedicated to compliance with applicable regulatory and industry frameworks.

·The Australian Privacy Act of 1988 (as amended) provides several data subject rights and added mandatory notification of eligible data breaches. Unlike the GDPR, there are no concepts of data controller and data processor. https://www.zendesk.com/company/anz-privacy/

·Subscriber Service Data Details

·Service Data is any information, including personal data, which is stored in or transmitted via the Zendesk Services by, or on behalf of, our subscribers and their end-users. We use Service Data to operate and improve our Services, help customers access and use the Services, respond to subscriber inquiries, and send communications related to the Services.

·Access: Zendesk provides an advanced set of access and encryption features to help customers effectively protect their information. We do not access or use customer content for any purpose other than providing, maintaining, and improving the Zendesk services and as otherwise required by law. See here for additional information.

·Data Hosting: Zendesk uses Amazon Web Services to host Service Data as described here and in the Regional Data Hosting Policy. For additional information, please also see the Security section.

·Default Data Types Collected by the Service: Zendesk has created a list of data points, categorized by product. For the full picture of data types, subscribers can use this list in conjunction with their specific intended use case and resultant data types.

·Legal or Government Requests: Privacy, data security, and subscriber trust are our top priorities. Zendesk does not disclose Service Data, except as necessary to provide our Services and to comply with applicable laws, as detailed in our Privacy Notice. To assist our subscribers in performing compliance reviews, we have additional resources: Transparency Report and Government Request Policy.

·Ownership: From a privacy perspective, the subscriber is the controller of Service Data and Zendesk is a processor. This means that throughout the time that you subscribe to services with Zendesk, you retain ownership of and control over Service Data in your Zendesk instance.

·Replication: Zendesk periodically replicates data for purposes of archival, backup, and audit logs. We use Amazon Web Services (AWS) to store some of the information that is backed up, such as database information and attachment files. Please see our Regional Data Hosting Policy for further details.

·Security: Zendesk prioritizes data security and combines enterprise-class security features with comprehensive audits of our applications, systems, and networks to ensure subscriber and business data is protected. See additional information here.

·Security Incidents: For more information about security incident management see our Security Incident Response.

·Sub-processors: Zendesk may use sub-processors, including affiliates of Zendesk, as well as third-party companies, to provide, secure, or improve the Services, and such sub-processors may have access to Service Data. Our Sub-processors policy provides an up-to-date list of the names and locations of all sub-processors.

·Termination: Zendesk maintains a Service Data Deletion Policy that describes Zendesk's data deletion processes upon subscriber's termination or expiration of the Zendesk subscription.

Cookie PolicyDetailed information about how and when we use cookies on Zendesk websites.
In-Product Cookie PolicyProvides information about how and when Zendesk uses cookies within the Zendesk Services.
Service Data Deletion PolicyHow our Subscribers' Service Data is deleted in connection with the cancellation, termination, or migration of an Account within the Zendesk Services.
Shared Responsibility ModelThis framework clarifies which party is responsible for which controls related to the security and privacy of your data.

·Zendesk has tools for each of its products to assist with user requests and other obligations under applicable privacy and data protection laws and regulations, such as data access, correction, portability, deletion, and objection. To learn about the features and functionality in each Zendesk product, please see Complying with Privacy and Data Protection in Zendesk products.

·Zendesk AI

·Zendesk AI is built based on the core principles of privacy, security, and compliance, by design. Our commitment to providing businesses with secure, trusted products and solutions is embedded in our DNA. As part of this, Zendesk leverages a set of design principles that not only set the standard for how we design, develop, and build everything we do, but set a clear foundation for our use of AI for customer experiences (CX and employee experience (EX)). For more information, see AI Trust at Zendesk.

·Service Data processed by Zendesk AI is subject to all security standards and commitments, including compliance with Zendesk's robust Enterprise Security Measures, and storage within Zendesk's SOC 2-compliant environment. Service Data will not be shared with any other customer.

·Generative AI features are currently powered by OpenAI (using zero data retention endpoints) or models hosted on Microsoft Azure, Amazon Bedrock, or Google Cloud Platform (where the model provider never has access to prompts or outputs). We also offer AI transcription services powered by Twilio and DeepGram.

·OpenAI data security practices are available here. Amazon Bedrock data security practices are available here. Microsoft Azure data security practices are available here. Google Cloud Platform data security practices are available here.

·Our agreements and policies provide our subscribers transparency and detailed information about Zendesk's Services, which in turn support our subscribers in meeting their own legal and compliance standards.

·Zendesk offers several data processing agreements and other addenda to support subscribers' compliance with data privacy laws, available for execution here. These include: Data Processing Agreement (DPA)

·United States HIPAA Business Associate Agreement (BAA) Zendesk Customer Agreement (ZCA) US State Addendum

·Transparency Report

·Disclosure of Service Data: Zendesk only discloses Service Data to third parties where disclosure is necessary to provide or improve the services or as required to respond to lawful requests from public authorities. Please see our Government Data Request Policy as well as the Zendesk Transparency Report.

·This could be the beginning of a beautiful relationship