Paradraw
Zendesk/Zendesk Partner Agreement is drafted as if it could incorporate DATA PROCESSING AGREEMENT
Zendesk Partner Agreement · Clause 11.3
perimeter

Zendesk Partner Agreement

5,127 words, 125 clausesno date on the pageread 08/10/2026source

·Agreements and Terms

·Policies and Guidelines

·Trademarks and Intellectual Property

·Procurement and Suppliers

·Data Protection and Privacy

·Tax Governance and Disclosures

·Customer Agreements and User Terms for Products and Services Zendesk Customer Agreement Region-Specific Terms Professional Services Terms

·Zendesk Partner Agreement

·This Agreement is governed by the terms set forth below, Zendesk's Partner Code of Conduct and Compliance Expectations, the Data Processing Agreement, the Zendesk Global GTM Partner Program Guide, and other binding documentation in Partner Connect.

·Table of Contents:

  • 1APPOINTMENT AND OBLIGATIONS
  • 2PARTNER'S MARKETING, SALE AND SUPPORT OF THE SERVICES
  • 3PARTNER'S USE OF THE SERVICES - DEMO PURPOSES
  • 4PAYMENT TERMS
  • 5CONFIDENTIALITY
  • 6INTELLECTUAL PROPERTY
  • 7TERM AND TERMINATION & SUSPENSION RIGHTS
  • 8REPRESENTATIONS, WARRANTIES, AND DISCLAIMERS
  • 9INDEMNIFICATION
  • 10LIMITATION OF LIABILITY
  • 11GENERAL TERMS
  • 12DEFINITIONS
1SECTION 1. APPOINTMENT AND OBLIGATIONS
  • 1.11.1 Appointment. Zendesk appoints Partner on a non-exclusive basis to market, sell, and support the Services, as authorized by Partner Type and Partner Tier. Zendesk has the right to appoint and transact with additional third parties or sell directly to Customers at any time. Additional third parties' sales and direct Zendesk sales does not constitute a termination or interference with this Agreement. Zendesk may change, update, or discontinue the availability of any of the Services in its sole discretion without incurring any obligation to Partner, its Additional Partners, or Customers. Partner is responsible for educating itself on all updates and communicating updates to its Customers and Additional Partners, as applicable, in compliance with the Program Guide.
  • 1.21.2 Additional Partners. Partners who are designated as Distributors have the right to appoint Additional Partners to perform sales, marketing and support services to Customers on Partner's behalf. As a condition to authorizing Additional Partners, Zendesk requires each Additional Partner to agree to the terms of this Agreement. Unless prohibited by applicable law, Zendesk is a third party beneficiary with respect to agreements between Partners, Additional Partners, and Customers. If Zendesk discovers that Partner has distributed any Services through unauthorized agents or other third parties, Zendesk has the right to either: (a) immediately suspend or terminate the third parties' access to the Services; or (b) enter into agreements directly with any of the third parties without compensation to Partner.
2SECTION 2. PARTNER'S MARKETING, SALE AND SUPPORT OF THE SERVICES
  • 2.12.1 Zendesk Customer Agreement. Partners engaged in resale activities will ensure that each Customer agrees to the Zendesk Customer Agreement, Order Form(s), and other terms Zendesk communicates from time to time. Partner will comply with Zendesk's ordering process.
  • 2.22.2 Partner Access Rights. Zendesk grants Partner and its authorized personnel a non-exclusive, non-transferable, revocable right solely for the purposes of demonstrating the Services to Customers and for internal training purposes as described in the Program Guide. Partner is responsible for its Affiliates' and personnel's use of the Services, all required training, and compliance with this Agreement. If Partner would like to use the Services for its internal business purposes unrelated to its activities as a Partner, Partner agrees to enter into a separate Zendesk Customer Agreement with Zendesk.
  • 2.32.3 Free Trials and Early Access Program. Zendesk may offer Partners and Customers a free trial of certain Services under the Zendesk Customer Agreement and the Free Trial Terms. Zendesk offers pre-release access to certain features under the Early Access Terms. Partner will ensure that each Customer agrees to the appropriate terms prior to access to these features. If Partner elects to access these features, it will agree to the Early Access Terms prior to access. Partner will ensure that its Customers and Additional Partners agree to the Early Access Terms prior to access.
  • 2.42.4 Support. Partner engaged in resale activities will indicate on an Order Form whether Partner or Zendesk will be responsible for providing support to the Customer. If Zendesk provides support, Zendesk will provide Customer standard support for the Services as detailed in the Documentation. If purchased by Customer, Zendesk will provide upgraded support or support that includes service level agreements.
3SECTION 3. PARTNER'S USE OF THE SERVICES - DEMO PURPOSES
  • 3.13.1 Use Obligations. In addition to the use obligations in this Agreement, Partner will: (i) comply with the User Content and Conduct Policy as applicable; (ii) ensure its use of the Services complies with applicable laws, regulations, and legal requirements; (iii) promptly notify Zendesk if Partner becomes aware of any unauthorized access to its account or the Services; (iv) monitor and be responsible for its users' compliance with all applicable terms and policies; and (v) promptly notify Zendesk of any known or suspected security issue or violation of any terms or policies.
  • 3.23.2 Prohibited Uses. Partner will not (and will not permit any other party to): (i) rent, lease, sell, distribute, transfer, or sublicense the Services, except as expressly authorized by this Agreement; (ii) provide any Partner with unauthorized access to the Services; (iii) develop a similar or competing product or service or derivative work or otherwise produce or disseminate benchmarking related to the Services without Zendesk's prior review and written approval; (iv) reverse engineer, decompile, disassemble, or seek to access the source code or non-public APIs to the Services; (v) circumvent any pricing or scope of use restrictions (including that no more than one individual may use each purchased Agent login); (vi) remove, obscure, or alter any proprietary or attribution notices in the Services; (vii) modify, adapt, or hack the Services or otherwise attempt to gain unauthorized access to the Services; (viii) attempt to bypass or break any security or rate limiting mechanism within the Services; or (ix) interfere with or disrupt the integrity, security, or performance of the Services.
  • 3.33.3 Development of APIs. If Partner or an Additional Partner wants to develop any functionality that interfaces with the Services, Partner or Additional Partner will enter into a separate agreement with Zendesk defining the development, license rights and ownership. It is not negotiable in the separate agreement that (i) Zendesk will have the right to test the development and to reject any developed functionality in its discretion; and (ii) notwithstanding any assistance in the development or subsequent testing or approvals by Zendesk, the party that developed the functionality agrees to indemnify and hold Zendesk harmless from all claims or damages arising from the development. Zendesk reserves the right to revoke any approvals under this Section if the functionality is not kept up to date and fully supported.
  • 3.43.4 Use of Service Data. For security and privacy purposes, Partner will only use synthetic data for demonstration, sales, and marketing purposes and not actual Service Data.
  • 3.53.5 Lead Sharing; Personal Data Processing. To the extent that the parties share personal data for lead sharing and account relationship purposes, the parties agree to comply with the Data Processing Agreement.
4SECTION 4. PAYMENT TERMS
  • 4.14.1 Pricing. Partner is responsible for establishing pricing of the Services to Additional Partners and Customers in its sole discretion.
  • 4.24.2 Financial Terms. As between Zendesk and Partner, the Program Guide defines all payment terms, financial incentives and discounts. Partners must pay all invoices regardless of when or whether an Additional Partner or Customer pays Partner.
  • 4.34.3 Payment Disputes. All good faith payment disputes must be submitted to Zendesk according to the Program Guide. If Zendesk determines that certain billing inaccuracies are attributable to Zendesk, Zendesk will issue a corrected invoice.
  • 4.44.4 Late Payment. Zendesk may charge Partner interest at the maximum rate permitted by law on any overdue amounts, plus all collection expenses.
  • 4.54.5 Taxes. Charges do not include Taxes or withholdings. Partner is solely responsible for paying any Taxes, except for those applicable to Zendesk's net income. If Zendesk has a legal obligation to collect or pay any Taxes, Zendesk will invoice Partner for such Taxes, unless Partner provides Zendesk with a valid tax exemption certification authorized by the appropriate taxing authority before Zendesk issues the invoice. Partner will pay applicable taxes in such amounts as are necessary to ensure that Zendesk receives the full amount of Zendesk's invoice.
  • 4.64.6 Withholding Tax. If Partner is required to withhold Taxes from payments to Zendesk, Partner will: (i) deduct authorized Taxes from payments to Zendesk; (ii) remit withheld Taxes directly to tax authorities; and (iii) provide Zendesk a valid tax receipt within 75 days. If Partner fails to submit a valid tax receipt within 75 days, Partner will pay the full amount of the invoice. Any withholding will only be valid and enforceable if it is established within an accepted Order Form.
5SECTION 5. CONFIDENTIALITY
  • 5.15.1 Obligations. Each party will protect the other's Confidential Information from unauthorized use, access, or disclosure in the same manner as each party protects its own Confidential Information, but with no less than reasonable care.
  • 5.25.2 Use. Each party may use the other party's Confidential Information solely to exercise its respective rights and perform its respective obligations under this Agreement and may disclose such Confidential Information only: (i) to its Affiliates, employees, and/or agents who have a need to know such Confidential Information and who are bound by terms of confidentiality at least as protective as this Agreement; (ii) as necessary to comply with an order or subpoena of any administrative agency or court of competent jurisdiction; or (iii) as reasonably necessary to comply with any applicable law or regulation.
  • 5.35.3 Remedies. The parties agree that any violation or threatened violation of this section may cause irreparable injury to the other party, entitling the other party to seek injunctive relief in addition to all other legal remedies.
6SECTION 6. INTELLECTUAL PROPERTY
  • 6.16.1 Intellectual Property Rights. Neither party grants the other any rights or interests to its intellectual property. Zendesk reserves and retains all right, title, and interest in the Services and the Documentation.
  • 6.26.2 Feedback. If Partner provides Zendesk with feedback or suggestions regarding the Services, Zendesk may use the feedback or suggestions without restriction or obligation.
  • 6.26.2 Use of Intellectual Property Rights; Publicity. Partner will comply with the policies and procedures in the Program Guide related to its use of Zendesk's intellectual property for marketing and publicity purposes.
7SECTION 7. TERM AND TERMINATION & SUSPENSION RIGHTS
  • 7.17.1 Term. The Term begins on the date that Partner signs this Agreement and will continue until terminated under Section 7.2
  • 7.27.2 Termination. Partner may terminate this Agreement upon 120 days' written notice in Partner Connect to allow for orderly transition of Customer accounts. Either party may terminate this Agreement for cause, if the other party: (i) is in material breach of this Agreement and fails to cure that breach within 30 days after receipt of written notice; or (ii) ceases its business operations or becomes subject to insolvency proceedings. Zendesk may immediately terminate this Agreement for cause without notice if Partner violates any use limitations or restrictions related to the Services or at any time upon 30 days' notice.
  • 7.37.3 Effect of Termination Termination of this Agreement does not release either party from the obligation to make payment of all undisputed amounts due and payable. Upon termination of this Agreement, Partner will follow all processes in the Program Guide and as directed by Zendesk.
  • 7.47.4 Effect of Licenses and Customer Relationships. If this Agreement is terminated for any reason, Zendesk and Partner will cooperate in transitioning Customer accounts so that there is no downtime or degradation of the Services. If Zendesk assumes first tier support for then-current Customer(s), Partner is responsible for refunding Customers the pro-rata share of all maintenance and support fees collected from applicable Customers, based on the time remaining in such Customers' then-current maintenance and support term. Partner will work with Zendesk or another Partner to complete a prompt and successful transition of Customers, including providing all Zendesk Customer Agreements, and documentation related to implementation, customizations and support.
  • 7.57.5 Suspension. Zendesk may limit or suspend Partner's access to the Services if: (i) Partner disrupts or creates a security risk to the Services; (ii) Zendesk reasonably believes Partner's use of the Services violates applicable law or suspension is requested by a government authority; (iii) Partner's fees owed to Zendesk are 30 days or more overdue; or (iv) Zendesk reasonably determines that suspension is necessary to avoid material harm to Zendesk, its Affiliates, or Customers. Suspension includes removing or disabling Agents, Service Data, or other content. Unless applicable law requires otherwise, Zendesk will use commercially reasonable efforts to notify Partner by email or through the Services before suspending access to the Services.
8SECTION 8. REPRESENTATIONS, WARRANTIES, AND DISCLAIMERS
  • 8.18.1 Mutual Warranties. Each party represents and warrants to the other that: (i) it has full authority to enter into this Agreement; (ii) executing and performing this Agreement does not violate any other agreements to which it is subject or any applicable laws or regulations; (iii) it will comply with all laws, rules and regulations applicable to its performance under this Agreement and (iv) it will comply with the applicable obligations in the Program Guide and Partner Connect.
  • 8.28.2 Zendesk Warranty. Zendesk warrants that the Services will operate materially as described in the Documentation. This warranty does not cover any misuse or unauthorized changes to the Services made by Partner, its Customers or others acting on its or their behalf. Partner is not authorized to offer any additional or different warranty than as set forth in the Zendesk Customer Agreement.
  • 8.38.3 Disclaimers. EXCEPT AS STATED IN SECTION 8.2, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE," AND ZENDESK EXPRESSLY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF PERFORMANCE, MERCHANTABILITY, TITLE, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. ZENDESK DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE, ERROR-FREE, OR FREE FROM VIRUSES OR OTHER MALICIOUS SOFTWARE, OR WILL MEET CUSTOMER'S BUSINESS, LEGAL, OR REGULATORY REQUIREMENTS, AND NO INFORMATION OR ADVICE OBTAINED BY CUSTOMER FROM ZENDESK OR THROUGH THE SERVICES WILL CREATE ANY WARRANTY NOT EXPRESSLY STATED IN THIS AGREEMENT. THESE DISCLAIMERS APPLY TO THE FULL EXTENT PERMITTED BY LAW.
  • 8.38.3 Partner Warranties. Partner warrants and covenants: (i) to ensure that each Customer enters into a binding Zendesk Customer Agreement without modification unless authorized in writing by Zendesk; and (ii) Partner will maintain a copy of the Zendesk Customer Agreement for each Customer and will promptly provide Zendesk with a copy upon request.
9SECTION 9. INDEMNIFICATION
  • 9.19.1 Zendesk IP Indemnity. Zendesk will defend and indemnify Partner against any IP Claim and damages or costs finally awarded by a court of competent jurisdiction or agreed in settlement by Zendesk (including reasonable attorneys' fees) resulting from the IP Claim. If Zendesk reasonably believes that the Services might result in an IP Claim, Zendesk may: (a) procure rights for Partner to continue using the Services; (b) replace or modify the alleged infringing portion of the Services without materially reducing functionality; or (c) terminate this Agreement. Zendesk will not be liable for any IP Claim resulting from: (i) following designs, data, instructions, or specifications provided by Partner or any of its Additional Partners or Customers; (ii) modifications of the Services made by anyone other than Zendesk; or (iii) Partner's, Additional Partners' or any of its Customers' combination or use of the Services in a manner inconsistent with this Agreement, the Zendesk Customer Agreement, or the Documentation. This Section states Partner's only remedy regarding any IP Claim.
  • 9.29.2 Partner Indemnity. Partner will defend and indemnify Zendesk from and against any claims made against Zendesk or its Affiliates and damages and costs (including reasonable attorneys' fees and expenses) arising from or relating to (i) any acts or omissions of Partner; (ii) violations of this Agreement by Partner, its Affiliates, or its or their personnel; or (iii) the acts or omissions of its Customers or Additional Partners. At Zendesk's request, Partner will cooperate fully with Zendesk in all actions taken by Zendesk to protect its rights in the Services and Confidential Information.
  • 9.39.3 Indemnity Process. The indemnities given by each party under this section are subject to: (i) the indemnified party giving the indemnifying party prompt written notice of the claim; (ii) the indemnifying party having sole control over the defense and settlement of the claim (but the indemnifying party cannot settle any claim that admits liability for the indemnified party without the indemnified party's prior written consent, which will not be unreasonably withheld or delayed); and (iii) the indemnified party providing information as may be reasonably requested by the indemnifying party in connection with the claim. Failure by the indemnified party to notify the indemnifying party of the claim will not relieve the indemnifying party of its obligations under this Section; however, the indemnifying party will not be liable for any litigation expenses that the indemnified party incurred prior to the time when notice is given or for any damages and/or costs resulting from any material prejudice caused by the delay or failure to provide notice to the indemnifying party.
10SECTION 10. LIMITATION OF LIABILITY
  • 10.110.1 EXCLUSION OF DAMAGES. EXCEPT FOR EXCLUDED CLAIMS, TO THE FULLEST EXTENT PERMITTED BY LAW, UNDER NO CIRCUMSTANCES AND UNDER NO LEGAL THEORY (WHETHER IN CONTRACT, TORT, NEGLIGENCE, OR OTHERWISE) WILL EITHER PARTY OR THEIR RESPECTIVE AFFILIATES, OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, SERVICE PROVIDERS, SUPPLIERS, OR LICENSORS, BE LIABLE TO THE OTHER PARTY, ADDITIONAL PARTNERS, CUSTOMERS OR ANY OF THEIR RESPECTIVE AFFILIATES OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, SERVICE PROVIDERS, SUPPLIERS, OR LICENSORS FOR ANY LOST PROFITS, LOST SALES OR BUSINESS, LOST DATA, BUSINESS INTERRUPTION, LOSS OF GOODWILL, COSTS OF COVER OR REPLACEMENT, OR FOR ANY OTHER TYPE OF INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE LOSS OR DAMAGES, OR FOR ANY OTHER INDIRECT LOSS OR DAMAGES IN CONNECTION WITH THIS AGREEMENT OR THE SERVICES, REGARDLESS OF WHETHER SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF OR COULD HAVE FORESEEN SUCH DAMAGES.
  • 10.210.2 MAXIMUM LIABILITY. EXCEPT FOR EXCLUDED CLAIMS, TO THE FULLEST EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF EACH PARTY AND ITS AFFILIATES ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE SERVICES WILL IN NO EVENT EXCEED THE AMOUNTS PAID UNDER THIS AGREEMENT IN THE 12-MONTH PERIOD PRECEDING THE INITIAL CLAIM GIVING RISE TO LIABILITY.
11SECTION 11. GENERAL TERMS
  • 11.111.1 Audit. Partner will allow Zendesk to audit Partner's records related to this Agreement to determine compliance or noncompliance with this Agreement. Partner will enforce this Section against its Additional Partners and assist Zendesk in conducting audits of its Additional Partners.
  • 11.211.2 Assignment. Partner will not assign this Agreement without Zendesk's prior written consent, including connection with a merger, acquisition, change in control, or sale of substantially all of its assets. This Agreement will bind and inure to the benefit of each party's permitted successors and assigns.
  • 11.311.3 Entire Agreement. Unless a separate agreement has been signed between Partner and Zendesk that expressly supersedes the terms of this Agreement, this Agreement sets out all terms agreed between the parties and supersedes all other agreements relating to its subject matter. This Agreement will apply in lieu of the terms or conditions in any purchase order, request for information, request for proposal, or other order documentation Partner, Additional Partner(s) or Customer(s) provide(s) and all such terms are null and void. Except as expressly stated or incorporated into this Agreement, there are no other agreements, representations, warranties, or commitments which may be relied upon by either party with respect to the subject matter of this Agreement. This Agreement is drafted in English, which controls over any translation. Failure to exercise any right under this Agreement will not constitute a waiver. If there is a conflict between the documents that make up this Agreement, the documents will control in the following order: (i) these terms; (ii) the Partner Code of Conduct and Compliance Expectations; (iii) the Data Processing Agreement; (iv) the Program Guide; and (v) the applicable Order Form.
  • 11.411.4 Severability. If any part of this Agreement is invalid, illegal, or unenforceable, that term will be limited to the minimum extent necessary so that the rest of this Agreement will remain in effect.
  • 11.511.5 Amendment. Zendesk may amend this Agreement from time to time, in which case the new Agreement will supersede prior versions. Zendesk will notify Partner of amendments in Partner Connect. Partner's continued performance of this Agreement following the effective date of any amendment will serve as Partner's consent to the amendment(s). Zendesk may make updates to online or URL terms and policies that are incorporated into this Agreement.
  • 11.611.6 Compliance. The parties will cooperate with each other and their respective Customers and Additional Partners to ensure compliance with the Program Guide, including training, monitoring, auditing, and reporting any suspected violations to the other party. Partner agrees to comply with the Partner Code of Conduct and Compliance Expectations.
  • 11.711.7 Relationship. This Agreement does not create any agency, partnership, or joint venture between the parties. Neither party is granted any right or authority to assume or to create any obligation or responsibility, express or implied, on behalf of or in the name of the other party. In fulfilling its obligations pursuant to this Agreement each party is an independent contractor.
  • 11.811.8 Survival. Upon termination or expiration of this Agreement, all provisions that by their nature are intended to survive such termination or expiration will continue in full force and effect.
  • 11.911.9 Force Majeure. Except for payment obligations, neither party will be liable to the other party for any delay or failure to perform any obligation under this Agreement resulting from any cause beyond such party's reasonable control, including, but not limited to, acts of God, acts of government, labor disputes, earthquake, storms, or other elements of nature, embargoes, riots, utility or telecommunication failures, public health emergencies (including pandemics and epidemics), acts of terrorism, or war.
  • 11.1011.10 Notices. All notices under this Agreement will be in writing and deemed given: (i) on personal delivery; (ii) the first business day after sending by email; (iii) the first business day after being mailed by a recognized overnight delivery service; or (iv) on receipt after being sent by certified or registered mail, return receipt requested. Unless otherwise provided in this Agreement, notice to Zendesk will be sent: (a) by email, to legalnotice@zendesk.com; or (b) by mail, to Zendesk, Inc., 181 Fremont Street, 17th Floor, San Francisco, California 94105 U.S.A. Attn: Legal Department with a copy sent to Partner Connect. Zendesk will provide notices to Partner in Partner Connect.
  • 11.1111.11 Governing Law. This Agreement is governed by the laws of the State of California, without reference to conflict of laws principles. Partner agrees to submit to the exclusive personal jurisdiction and venue in a court of general jurisdiction in San Francisco County, California.
  • 11.1211.12 Export. The Services are subject to global sanctions and export laws and regulations. Partner represents and warrants that it, its Affiliates, and its authorized personnel: (i) are not on any U.S. or applicable non-U.S.-restricted or denied persons list; and (ii) are not located in any countries or territories subject to U.S. government embargo or trade sanctions. Partner will not (and will not permit any other party to) export, re-export, transfer, or disclose the Services to any party subject to the restrictions in (i) and (ii) or to any party that Partner has reason to know may use the Services in violation of applicable sanctions and export laws and regulations.
12SECTION 12. DEFINITIONS

·Capitalized terms in this Agreement are defined below. If not defined below, the other capitalized terms are defined in the Program Guide.

·"Additional Partner(s)" means Partner(s) that is (or are) appointed by a Distribution Partner.

·"Affiliate(s)" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means control of greater than 50% of the voting rights or equity interests of a party.

·"Agent(s)" means an individual (including those of Partner's Affiliates) authorized to use the Services through Partner's account.

·"Agreement" means, collectively, these terms, Order Form(s), and the other terms incorporated by reference in this Agreement and on Partner Connect.

·"Charges" means the charges on an Order Form, Statement of Work, or charges accepted by Customer when functionality is enabled in-product, including usage-based or pay-as-you-go charges.

·"Confidential Information" means non-public, business, or technical information, including Customer information and opportunity related details regardless of whether such information is marked "confidential" or "proprietary", but not information that: (i) was known to the receiving party without restriction prior to receipt from the disclosing party; (ii) is publicly available through no fault of the receiving party; (iii) is rightfully received by the receiving party from a Partner without a duty of confidentiality; or (iv) is independently developed by the receiving party.

·"Customer" means the contracting party using the Services under the Zendesk Customer Agreement, as identified in the applicable account, Order Form, or Statement of Work. Customer may also be referred to as "Subscriber," "You," or "Your" in the Zendesk Customer Agreement and Documentation.

·"Data Processing Agreement" means the data processing agreement governing personal data sharing and processing between Partner and Zendesk located in Partner Connect.

·"Distributor" means a Partner that is authorized by Zendesk to market, sell, and support the Services, appoint Additional Partners to act on its behalf, manage Additional Partner activities, and refer sales and other opportunities to Zendesk in accordance with the Program Guide.

·"Documentation" means any specifications or technical guidelines for the Services and Service Plan that Zendesk makes available to the Partner and Customer, including through Zendesk help center(s) or https://www.zendesk.com/, which Zendesk may update from time to time. Documentation excludes any community-moderated forums provided or accessible through such resources.

·"Early Access Terms" means features and functionality not yet available for general commercial release. The terms are located at: https://support.zendesk.com/hc/en-us/articles/9282911922586.

·"End User(s)" means any person or entity, other than Customer or Agents, with whom Customer or its agents interact using the Services.

·"Excluded Claims" means obligations and claims related to: (i) Partner's payment obligations; (ii) Partner's or its Customers' or Additional Partners' breach of Section 3.1(ii) or 3.1(v) and equivalent sections in the Zendesk Customer Agreement; (iii) a party's breach of its confidentiality obligations (but excluding breaches relating to Service Data or security incidents); (iv) a party's indemnification obligations; (v) either party's misappropriation or infringement of the other party's intellectual property rights; or (vi) liability that cannot be limited or excluded by applicable law.

·"Free Trial Terms" means the terms at: https://www.zendesk.com/company/agreements-and-terms/free-trial-terms.

·"IP Claim" means any third-party claim made against Partner alleging that Partner's use of the Services directly infringes a third party's intellectual property rights.

·"Order Form" means a generated or online ordering document or process completed between Zendesk and Partner or Zendesk, Partner, and Customer for the onward sale of the Services to Customer.

·"Partner" means the third party entering into this Agreement with Zendesk. The term "Partner" used to collectively and generally refer to a third party engaged to refer, resell, distribute, implement and support Zendesk's Services. Partners are engaged as Distributors, Referral Partners, Managed Service Providers, Systems Integrators, and Resellers, depending on the qualifications and activities designated in Partner Connect and the Program Guide.

·"Partner Code of Conduct and Compliance Expectations" means the document on Partner Connect containing the set of ethical and compliance responsibilities for all Partners.

·"Partner Connect" means the technology tool utilized by Zendesk to onboard and manage Partners. Definitive and binding terms and documentation are located in a Partner's account within Partner Connect.

·"Partner Program" means the collective set of rights, obligations and other relationship terms between Zendesk and Partner.

·"Partner Tier" means the specific authorisation of the level of Partner activities and responsibilities designated in Partner Connect. Changes to a designated Partner Tier are notified in Partner Connect along with any additional terms that will become part of this Agreement.

·"Partner Type" means the specific authorisation of Partner activities set out in Partner Connect and this Agreement, Partners are authorised to provide under the Partner Program. Changes to a designated Partner Type are notified in Partner Connect along with any additional terms that will become part of this Agreement.

·"Privacy Notice" means the notice at: https://www.zendesk.com/company/agreements-and-terms/privacy-notice

·"Professional Services" means consulting or professional services (including training, success, and implementation services) that Zendesk provides, as specified on an Order Form or Statement of Work.

·"Program Guide" means the Zendesk Global GTM Partner Program Guide, available in Partner Connect.

·"Referral Partner(s)" means Partners that refer potential Customers to a Partner or to Zendesk. Referral Partners are not authorised to sell or support the Services.

·"Reseller(s)" means an Additional Partner that is either appointed by Zendesk directly or appointed and managed by Distributor and approved by Zendesk to refer, sell, and support the Services and perform Professional Services.

·"Services" means the products and services developed or provided by Zendesk that Customer purchases under an Order Form or Statement of Work, or that Zendesk otherwise makes available to Customer, as described in the Documentation and Supplemental Terms. Services performed by Zendesk exclude Third-Party Products.

·"Service Data" means all data, text, messages, communications, or other information submitted to and stored within the Services by Partner, Agents, and End Users relating to Partner's use of the Services. Service Data excludes Partner, Customer and Agent account information, which is subject to the Privacy Notice and the Data Processing Agreement.

·"Service Plan(s)" means the packaged service plan(s) Customer purchased as set out in the Order Form, or detailed in the Documentation.

·"Statement of Work" means a document describing Professional Services.

·"Supplemental Terms" means: (i) additional terms on an Order Form or Statement of Work; (ii) the Service-Specific Terms available at https://support.zendesk.com/hc/en-us/articles/4408831944730; (iii) the Region-Specific Terms available at: https://support.zendesk.com/hc/en-us/articles/4980549029018; (iv) the Professional Services Terms and Conditions at: https://support.zendesk.com/hc/en-us/articles/4784220538650; and (v) additional terms that otherwise supplement features or functionality used in connection with the Services.

·"Systems Integrator(s)" means a Partner that is engaged in Professional Services related to the implementation, maintenance and customization of the Services.

·"Taxes" means taxes, levies, duties, or similar governmental assessments, including value-added, sales, use, or withholding taxes assessed by any local, state, provincial, or foreign jurisdiction.

·"Term" means the duration of this Agreement.

·"Third-Party Product(s)" means all products and services provided by third parties that interoperate with the Services. Third-Party Products may also be referred to as "Non-Zendesk Services."

·"User Content and Conduct Policy" means the policy at: https://support.zendesk.com/hc/en-us/articles/360022367333.

·"Zendesk" means Zendesk, Inc., a Delaware corporation, or applicable Zendesk Affiliates, or any successors or assignees.

·"Zendesk Customer Agreement" means the terms and conditions at: https://www.zendesk.com/company/agreements-and-terms/main-services-agreement/.

DATA PROCESSING AGREEMENT · agreements and terms
Part of the agreement

DATA PROCESSING AGREEMENT

4,019 words, 134 clausesno date on the pageread 08/10/2026source

·Agreements and Terms

·Policies and Guidelines

·Trademarks and Intellectual Property

·Procurement and Suppliers

·Data Protection and Privacy

·Tax Governance and Disclosures

·DATA PROCESSING AGREEMENT

·This Data Processing Agreement ("DPA") is entered into by Customer and Zendesk, Inc. ("Zendesk"), each a "Party" and together the "Parties".

·Customer and Zendesk have entered into the Agreement under which Customer is provided access to and use of the Services during the Subscription Term. This DPA is incorporated into and made a part of the Agreement. If you wish to electronically sign the DPA, please click here.

11. GLOBAL PRIVACY OBLIGATIONS OF THE PARTIES
  • 1Ownership of Service Data. Zendesk asserts no ownership right or interest to Service Data processed under this DPA and, between the Parties, Service Data owned by Customer remains the property of Customer.
  • 2Personal Data. The Parties agree that the nature, purposes, subject matter, duration of processing, categories of Personal Data or data subjects, and applicable retention periods are as described in Annex I.
  • 3Applicable Data Protection Law. Zendesk and Customer agree to comply with their respective obligations of Applicable Data Protection Law.
  • 4Zendesk's Obligations. Zendesk agrees to:
  • 4.1process Personal Data according to Customer's documented instructions, unless otherwise permitted or required by applicable law. Zendesk will inform Customer immediately if its processing instructions infringe Applicable Data Protection Law;
  • 4.2not sell or share Personal Data;
  • 4.3ensure that all employees and contractors are fully aware of their responsibilities to protect Personal Data under this DPA and have committed to an appropriate contractual or statutory obligation of confidentiality;
  • 4.4notify Customer if it can no longer meet its obligations under Applicable Data Protection Law and allow Customer to take reasonable and appropriate steps to remediate unauthorized processing of Personal Data;
  • 4.5implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, taking into account the likelihood and severity of risks to the privacy rights of data subjects, including the measures in Annex II;
  • 4.6notify Customer of a confirmed personal data breach without undue delay and within 48 hours, unless prohibited by law or government agency; take appropriate measures designed to mitigate the cause(s) of the personal data breach; and provide Customer all necessary information as required under Applicable Data Protection Law;
  • 4.7reasonably assist Customer with its obligation to respond to data subject requests and, if Zendesk receives a request directly from Customer's data subject, direct the data subject to Customer unless prohibited by law; and
  • 4.8make available commercially reasonable information and assistance to enable Customer to conduct any data protection impact assessment or supervisory authority consultation, as required by Applicable Data Protection Law.
  • 5Customer Obligations. Customer, as data controller, determines what Personal Data is processed by the Services. Customer is responsible for assessing Zendesk's technical and organization measures as appropriate for the types of Personal Data Customer wishes to process by its use of the Services.
22. USE OF SUB-PROCESSORS
  • 1Sub-Processors. Customer provides its general written authorization for Zendesk to use Sub-processors provided that:
  • 1.1Zendesk remains liable to Customer for the acts or omissions of its Sub-processors with respect to their processing of Personal Data; and
  • 1.2each Sub-processor agrees to protect the Personal Data to standards consistent with the requirements of this DPA.
  • 2Sub-Processor Policy Updates. Zendesk will update the Sub-processor Policy with any newly appointed Sub-processors at least 30 days before such change. Customer may sign-up to receive email notifications of such changes.
  • 3Sub-Processor Policy Objections. Customer may object to any newly appointed Sub-processor on reasonable grounds relating to data protection. If Customer objects, it will inform Zendesk in writing by emailing privacy@zendesk.com within 30 days following the update to the Sub-processor Policy. In such event, the Parties will negotiate, in good faith, a solution to Customer's objection. If the Parties cannot reach resolution within 60 days of Zendesk's receipt of Customer's objection, Zendesk, in its sole discretion, will either:
  • 3.1instruct the Sub-processor not to process Customer's Personal Data, and the DPA will continue unaffected, or
  • 3.2allow Customer to terminate any affected portion of the Services and provide Customer with a pro rata refund of Subscription Charges paid in advance for the affected portion of the Services not yet received as of the effective date of termination.
33. AUDIT
  • 1External Auditors. Zendesk uses independent and qualified external auditors to verify the adequacy of its data protection measures and compliance with its obligations in this DPA (e.g. SOC 2 Type II or ISO 27001).
  • 2Audit Report. At Customer's written request, Zendesk will provide Customer with an Audit Report, subject to the confidentiality provisions of the Agreement.
  • 3Assistance. To the extent Customer's audit requirements under Applicable Data Protection Law are not reasonably satisfied through the Audit Report or other documentation that Zendesk makes generally available to its customers, and Customer does not otherwise have access to the relevant information, Zendesk will reasonably assist Customer.
  • 4Audit. If Customer cannot satisfy its audit obligations under Applicable Data Protection Law through Zendesk's assistance provided in Section 3.3 and Customer has the right to conduct an audit under Applicable Data Protection Law, Customer may request such an audit by providing at least 30 days' advance written notice to privacy@zendesk.com. Such audit may be conducted no more than once annually, must be conducted during normal business hours with reasonable duration, must not interfere with Zendesk's operations, and must only be conducted at Zendesk headquarters or an agreed business office. Such audit will not involve access to any data relating to other Zendesk customers, or to secured facilities or systems in any way that would violate Zendesk's security controls or cause Zendesk to violate its confidentiality obligations to any third party. Any information generated in connection with such audit is Zendesk's Confidential Information and will be promptly provided to Zendesk. Customer is responsible for costs and expenses relating to any audit it requests beyond the Audit Report.
44. INTERNATIONAL DATA TRANSFERS
  • 1International Data Transfers. Customer acknowledges that it is necessary for the performance of the Services that Zendesk may process Service Data on a global basis in compliance with Applicable Data Protection Law. If Zendesk transfers Personal Data from an origin country to a country that has not received an adequacy decision from the origin country, the transfers will adhere to one or more of the following Transfer Mechanisms, made applicable to all Personal Data, and in the following order:
  • 1.1a valid certification mechanism;
  • 1.2Binding Corporate Rules;
  • 1.3SCCs.
  • 2Transfer Mechanisms. Transfer Mechanisms, clause selections, and specific country requirements, if applicable, are detailed and incorporated by reference in Annex III.
  • 3Data Transfer Assessment. Customer acknowledges that it may be obligated to conduct a data transfer assessment in addition to relying on Transfer Mechanisms. Zendesk will provide reasonable assistance with this assessment upon request.
  • 4Binding Signature. Customer acknowledges that signature of the Agreement constitutes binding signature of the SCCs and other signature requirements stated in the Region-Specific Terms.
55. RETURN AND DESTRUCTION OF PERSONAL DATA

·Upon Customer's written request, Zendesk will make Service Data available to Customer for export or download as provided in the Agreement. Zendesk will delete Service Data in accordance with Zendesk's Service Data Deletion Policy.

66. INNOVATION SERVICES

·All Sections of this DPA apply to Innovation Services except for Section 3 (Audit), Annex II (Zendesk Technical and Organizational Security Measures - Enterprise Services), and Annex III, Sections 1 and 2 (Binding Corporate Rules and Data Privacy Framework).

77. CONFLICTS

·Unless otherwise agreed, the terms of this DPA will take precedence over any conflicting terms in the Agreement.

88. DEFINITIONS

·All terms used in this DPA will have the meanings given to them below. Where not defined in this DPA, the terms "sell", "share", "processing", "process", "processor", "controller", "data exporter", "data importer", "data subject", "personal data breach" (and similar terms), and "supervisory authority" will have the same meaning as in Applicable Data Protection Law. Any capitalized terms not otherwise defined in this DPA are as defined in the Agreement.

·"Applicable Data Protection Law" means all data protection laws and regulations applicable to each party in connection with its respective processing of Personal Data under this Agreement.

·"Audit Report" means a confidential summary of any such certification or audit report for Enterprise Services.

·"Binding Corporate Rules" mean (a) EU Binding Corporate Rules - Processor for transfers of Personal Data subject to the GDPR, or (b) UK Binding Corporate Rules - Processor for transfers of UK Personal Data.

·"Bug Bounty Program" means the terms at: https://support.zendesk.com/hc/en-us/articles/115002853607-Zendesk-Bug-Bounty-Program.

·Business Resilience Webpage https://support.zendesk.com/hc/en-us/articles/360022191434-Business-Continuity-and-Disaster-recovery.

·"Personal Data" means any personal data relating, directly or indirectly, to an identified or identifiable natural person that is contained in Service Data.

·"Status Webpage" https://status.zendesk.com/.

·"SCCs" mean standard contractual clauses approved by a supervisory authority as a Transfer Mechanism.

·"Sub-processor" means any third-party data processor engaged by Zendesk who receives and processes Service Data in accordance with Customer's instructions (as communicated by Zendesk) and the terms of its written subcontract with Zendesk, as listed in the Sub-processor Policy.

·"Sub-processor Policy" means the policy at: https://support.zendesk.com/hc/en-us/articles/4408883061530-Sub-processor-Policy.

·"Transfer Mechanism" means the framework(s) governing the international processing of Personal Data described in Annex III.

Annex IANNEX I
·Details of Processing

·Data Exporter: Customer

·Contact Details: Provided in the DPA signature block.

·Data Exporter Role: Customer is a controller (with respect to Zendesk)

·Data Importer: Zendesk, Inc.

·Contact Details: Provided in the DPA signature block

·Data Importer Role: Zendesk is a processor

  • 1Nature and Purpose of the Processing: Zendesk will process Personal Data as specified in the Agreement and for the purposes determined by Customer.
  • 2Processing Activities: Processing activities will include hosting and processing of Personal Data as specifically instructed by the Customer programmatically or in the Agreement.
  • 3Duration of Processing and Retention: Zendesk will process and retain Personal Data on a continuous basis for the Subscription Term. Zendesk deletes Personal Data according to the Zendesk Service Data Deletion Policy.
  • 4Data Subjects: Customer may, at its sole discretion, submit Personal Data to the Services, which may include, but is not limited to: employees (including contractors and temporary employees), relatives of employees, customers, prospective customers, service providers, business partners, vendors, End Users, advisors (all of whom are natural persons) of Customer and any natural person(s) authorized by Customer to use the Services.
  • 5Categories of Personal Data: Customer may process any category of Personal Data at its sole discretion using the Services, which may include, but is not limited to, the following categories of Personal Data: first and last name, email address, title, position, employer, contact information (company, email, phone numbers, physical address), date of birth, gender, communications (telephone recordings, voicemail, metadata), and customer service information.
  • 6Special Categories of Data (if applicable): Sensitive categories of data requiring special treatment under Applicable Data Protection Law may be included Personal Data at the discretion of Customer.
Annex IIANNEX II
·Zendesk Technical and Organizational Security Measures - Enterprise Services

·The technical and organizational measures to protect Service Data for Enterprise Services are contained in Zendesk's Enterprise Security Measures.

·Zendesk reserves the right to update its security program from time to time; provided, however, any update will not materially reduce the overall protections in this Annex II.

  • 1Information Security Program and Team: The Zendesk security program includes documented policies and standards of administrative, technical, physical and organizational safeguards, which govern the handling of Service Data in compliance with applicable law. The security program is designed to protect the confidentiality and integrity of Service Data, appropriate to the nature, scope, context and purposes of processing and the risks involved in the processing for the data subjects. Zendesk maintains a globally distributed security team on call 24/7 to respond to security alerts and events.
  • 2Security Certifications: Zendesk holds the following security-related certifications from independent third-party auditors: SOC 2 Type II, ISO 27001:2013, or ISO 27018:2014.
  • 3Physical Access Controls: Zendesk takes reasonable measures, such as security personnel and secured buildings, to prevent unauthorized persons from gaining physical access to Service Data and validates third parties operating data centers on Zendesk's behalf are adhering to such controls.
  • 4System Access Controls: Zendesk takes reasonable measures to prevent Service Data from being used without authorization. These controls vary based on the nature of the processing undertaken and may include, among other controls, authentication via passwords and/or two-factor authentication, documented authorization processes, documented change management processes and/or, logging of access on several levels.
  • 5Data Access Controls: Zendesk takes reasonable measures to ensure Service Data is accessible and manageable only by properly authorized staff, direct database query access is restricted and application access rights are established and enforced to ensure that persons entitled to use a data processing system only have access to the Service Data to which they have privilege of access; and, that Service Data cannot be read, copied, modified or removed without authorization in the course of processing.
  • 6Transmission Controls: Zendesk takes reasonable measures to ensure the ability to check and establish which entities are transferred Service Data by means of data transmission facilities so Service Data cannot be read, copied, modified or removed without authorization during electronic transmission or transport. Service Data is encrypted in transit over public networks when communicating with Zendesk user interfaces (UIs) and application programming interface (APIs) via industry standard HTTPS/TLS (TLS 1.2 or higher). Exceptions to encryption in transit may include any Third-Party Product that does not support encryption, which data controller may link to through the Enterprise Services at its election. Service Data is encrypted at rest by Zendesk's Sub-processor and managed services provider, Amazon Web Services Inc., via AES-256.
  • 7Input Controls: Zendesk takes reasonable measures to provide the ability to check and establish whether and by whom Service Data has been entered into data processing systems, modified or removed, and that any transfer of Service Data to a third-party service provider is made via a secure transmission.
  • 8Logical Separation: Data from different Zendesk's Customer environments is logically segregated on systems managed by Zendesk to ensure that Service Data that is collected by different controllers is segregated from one another.
  • 9No Backdoors: Zendesk has not built any backdoors or other methods into the Services to allow government authorities to circumvent its security measures to gain access to Service Data.
  • 10Data Center Architecture and Security: Zendesk hosts Service Data primarily in AWS data centers that have been certified as ISO 27001, PCI DSS Service Provider Level 1, and/or SOC2 compliant. AWS infrastructure services include backup power, HVAC systems, and fire suppression equipment to help protect servers and ultimately Customer's data. AWS on-site security includes a number of features, such as, security guards, fencing, securing feeds, intrusion detection technology, and other security measures. More details on AWS controls can be found at: https://aws.amazon.com/security.
  • 11Network Architecture and Security: Zendesk systems are housed in zones to commensurate with their security, depending on function, information classification, and risk. Zendesk's network security architecture consists of multiple zones with more sensitive systems, like database servers, in Zendesk's most trusted zones. Depending on the zone, additional security monitoring and access controls will apply. DMZs are utilized between the internet and internally between the different zones of trust. Zendesk's network is protected through the use of key AWS security services, regular audits, and network intelligence technologies, which monitor and/or block known malicious traffic and network attacks. Zendesk utilizes network security scanning to provide quick identification of potentially vulnerable systems, in addition to Zendesk's extensive internal scanning and testing program. Zendesk also participates in several threat intelligence sharing programs to monitor threats posted to these threat intelligence networks and take action based on risk. Zendesk has a multi-layer approach to DDoS mitigation, utilizing network edge defenses, along with scaling and protection tools.
  • 12Testing, Monitoring, and Logging: Each year, Zendesk employs third-party security experts to perform a broad penetration test across the Zendesk production and corporate networks. Zendesk utilizes a Security Incident Event Management (SIEM) system, which gathers logs from important network devices and host systems. The SIEM alerts on triggers that notify the Security team based on correlated events for investigation and response. Service ingress and egress points are instrumented and monitored to detect anomalous behavior, including 24/7 system monitoring.
  • 13Data Hosting Location: Zendesk offers Customers an option to elect where Service Data is hosted if a Customer purchases the Data Center Location Add-On. A full description of this offering is provided at: https://support.zendesk.com/hc/en-us/articles/360053579674.
  • 14Availability and Continuity: Zendesk maintains a publicly available Status Webpage, which includes system availability details, scheduled maintenance, service incident history, and relevant security events. Zendesk employs service clustering and network redundancies to eliminate single points of failure. Our strict backup regime and/or Zendesk's Enhanced Disaster Recovery service offering allows us to deliver a high level of service availability, as Service Data is replicated across available zones. Zendesk's Disaster Recovery program ensures that the Zendesk Services remain available and are easily recoverable in the case of a disaster, through building a robust technical environment. Additional details are available on Zendesk's Business Resilience Webpage.
  • 15People Security: Zendesk performs pre-employment background checks of all employees, including education and employment verification, in accordance with applicable local laws. Employees receive security training upon hire and annually thereafter. Employees are bound by written confidentiality agreements to maintain the confidentiality of data.
  • 16Vendor Management: Zendesk uses third party vendors to provide certain aspects of the Services. Zendesk completes a security risk assessment of prospective vendors.
  • 17Bug Bounty: Zendesk maintains a Bug Bounty Program to allow independent security researchers to report security vulnerabilities on an ongoing basis.
·Zendesk Technical and Organizational Security Measures - Innovation Services

·The technical and organizational measures to protect Service Data for Innovation Services are contained in Zendesk's Innovation Security Measures.

·The Zendesk information security program includes documented policies or standards governing the handling of Service Data in compliance with applicable law, and administrative, technical and physical safeguards designed to protect the confidentiality and integrity of Service Data. Zendesk reserves the right to update its security program from time to time; provided, however, any update will not materially reduce the overall protections in this Annex II.

  • 1Physical Access Controls: Zendesk takes reasonable measures to prevent unauthorized persons from gaining physical access to Service Data.
  • 2System Access Controls: Zendesk takes reasonable measures to prevent Service Data from being used without authorization.
  • 3Data Access Controls: Zendesk takes reasonable measures to provide that Service Data is accessible and manageable only by properly authorized staff.
  • 4Transmission Controls: Zendesk takes reasonable measures to ensure the ability to check and establish to which entities are transferred Service Data by means of data transmission facilities so Service Data cannot be read, copied, modified or removed without authorization during electronic transmission or transport.
  • 5Input Controls: Zendesk takes reasonable measures to provide that it is possible to check and establish whether and by whom Service Data has been entered into data processing systems, modified or removed, and that any transfer of Service Data to a third-party service provider is made via a secure transmission.
  • 6Logical Separation: Data from different Zendesk's Customer environments is logically segregated on systems managed by Zendesk to ensure that Service Data that is collected by different controllers is segregated from one another.
  • 7Security Policies and Personnel: Zendesk has and will maintain a managed security program to identify risks and implement preventative technology, as well as technology and processes for common attack mitigation. Zendesk has, and will maintain, a full-time information security team responsible for safeguarding Zendesk's networks, systems and services, and developing and delivering training to Zendesk's employees in compliance with Zendesk's security policies.
Annex IIIANNEX III
·Transfer Mechanisms and Region-Specific Terms

·Zendesk utilizes several transfer mechanisms governing the international transfer of Personal Data, depending upon the jurisdiction of the Personal Data that is Processed. Additional privacy-specific terms in the Region-Specific Terms are incorporated as applicable.

11. Binding Corporate Rules

·Zendesk, its affiliates, and Sub-processors comply with the requirements of Zendesk's Binding Corporate Rules, which have been approved by the Irish Data Protection Commission and the UK Information Commission Office and available on Zendesk's Trust Center at: https://www.zendesk.com/trust-center/.

22. Data Privacy Framework

·Zendesk has certified to participate in and comply with the EU-U.S. Data Privacy Framework ("EU-U.S. DPF"), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework ("Swiss-U.S. DPF") (see: https://www.dataprivacyframework.gov/s/). Zendesk commits to maintain the self-certification of compliance with the EU-U.S. DPF, the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF, or any replacement framework, for the Services provided under the Agreement and this DPA.

33. SCCs
  • 1Zendesk also utilizes the standard contractual clauses adopted by the European Commission that are stated in the Annex to the European Commission's Implementing Decision 2021/914 of 4 June 2021, available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32021D0914 ("EU SCCs"), and the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses', available at: https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf ("UK Addendum"). The parties acknowledge that the SCCs are incorporated into this DPA as if fully stated below. These links may be updated from time to time based on updates by regulatory authorities and will be updated by amendment to this DPA.
  • 2To the extent that SCCs are published and required by a supervisory authority that are not EU SCCs, the parties interpret them as completed consistent with the selections in subsection (e).
  • 3In the event of conflict or ambiguity, the terms of SCCs will take precedence over the DPA and all other terms between Zendesk and Customer.
  • 4Where the EU SCCs are recognized by a local supervisory authority as a Transfer Mechanism, they apply to all Personal Data subject to that authority and will be considered completed in the manner specified in subsection (e).
  • 5EU SCCs. Where the EU SCCs are used as a Transfer Mechanism, they are considered completed as follows:
  • 5.1Module 2 (Controller to Processor) will apply where Customer is a controller of Service Data and Zendesk is a processor of Service Data; Module 3 (Processor to Processor) will apply where Customer is a processor of Service Data and Zendesk is a processor of Service Data;
  • 5.2in Clause 7, the optional docking clause will not apply;
  • 5.3in Clause 9(a), Option 2 "General Written Authorisation" will apply, and the time period for prior notice of Sub- processor changes as stated in the "Use of Sub-processors" section of this DPA;
  • 5.4in Clause 11, the optional language will not apply;
  • 5.5in Clause 17, Option 1 will apply and will be governed by the laws provided in the Agreement, or by the laws of Ireland if no EEA member state law applies, or by the laws of the importer where neither apply;
  • 5.6in Clause 18(b), disputes will be resolved before the courts in the following order of precedence: (1) as provided in the Agreement, (2) Dublin, Ireland, if no EEA member state applies, (3) Customer's country with jurisdiction over the Customer's headquarters, (4) Zendesk's registered office address;
  • 5.7in Annex I.A and I.B and Annex II of the EU SCCs are considered completed with the information listed in Annexes I and II to this DPA; and
  • 5.8in Annex I.C of SCCs, the supervisory authority will be the authority competent with respect to the data exporter. Where the data exporter is not established in the local country but is still within the territorial scope of Applicable Data Protection Law, the competent supervisory authority will be located where the data exporter has appointed a representative, but if it has not appointed a representative, then supervisory authority of Ireland will be the competent authority.
  • 6UK Addendum. Where the UK Addendum applies, it will be deemed completed as follows:
  • 6.1Table 1, is considered completed with the information stated in Annex I of this DPA, the contents of which are hereby agreed to by the Parties;
  • 6.2Table 2, the Parties select the checkbox that reads: "Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of this Addendum", and the accompanying table are considered completed according to the Parties' preferences outlined in this Annex;
  • 6.3Table 3, is considered completed with the information stated in Annex I, Annex II and as stated in the "Use of Sub-processors" section of this DPA; and
  • 6.4Table 4, the Parties agree that neither Party may terminate the UK Addendum as stated in Section 19.