8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This is Zendesk's privacy policy, explaining what personal information the company collects about people who visit its website, sign up for its products, or interact with Zendesk marketing, and how that information is used and shared. The most important thing to know is that if you are an end user contacting a business through Zendesk's support software, your data is controlled by that business, not Zendesk, meaning you must go to the business to exercise rights like deletion or access rather than contacting Zendesk. If you are a direct Zendesk customer or website visitor, you can submit privacy rights requests including data deletion or access at https://www.zendesk.com/company/agreements-and-terms/privacy-notice/ or through Zendesk's designated privacy contact.

Technical / Legal Breakdown

This document is Zendesk's Privacy Notice, governing how Zendesk collects, uses, discloses, and retains personal data about visitors to its websites, prospective and current customers, and end users of its services, with stated legal bases including consent, legitimate interests, and contractual necessity. The notice states that Zendesk collects a broad range of data categories including contact information, usage data, device and log data, payment information, and inferred data, and the terms authorize sharing this data with service providers, business partners, advertising networks, analytics providers, and in the context of corporate transactions such as mergers or acquisitions. Notably, the notice draws a clear operational distinction between data Zendesk processes as a controller (its own marketing and website interactions) and data it processes as a processor on behalf of its business customers (service data submitted through Zendesk products), with the latter governed by separate data processing agreements rather than this notice; this distinction is operationally significant because end users whose data appears in a customer's Zendesk instance must direct privacy requests to that business customer, not to Zendesk directly. The notice engages GDPR and UK GDPR for EU and UK residents, CCPA and CPRA for California residents, and references adequacy mechanisms including Standard Contractual Clauses for international data transfers; Zendesk also references its participation in the EU-U.S. Data Privacy Framework. Material compliance considerations include the adequacy of cross-border transfer mechanisms post-Schrems II, the sufficiency of consent mechanisms for cookie-based advertising, and the clarity of the controller-processor boundary for enterprise customers subject to their own regulatory obligations.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

1 important change detected

3 versions captured · Last updated: May 2026

What changed Zendesk's Privacy Policy was updated on May 5, 2026 to add references to two new documents in its governance framework: the Zendesk Partner Agreement and the AI Services Addendum. These documents now appear in the policy's table of contents alongside existing agreements. The change itself is organizational—no substantive modifications to privacy rights or data handling practices are stated in the detected change.
Why this matters The updated Privacy Policy now references two additional governing documents: the Zendesk Partner Agreement and the AI Services Addendum. These documents may contain terms that apply to specific user groups, particularly those using partner services or AI-powered features. To understand how these new documents affect you, review the full text of both agreements, especially if you are a partner or use any AI-enabled Zendesk services.
View full change record →
Medium — 6 provisions
Low — 2 provisions

Monitoring

Zendesk has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Dual Controller-Processor Role Structure and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 11, 2026 19:45 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000639
Version ID CA-V-002459
SHA-256 42a6755963d1b2ed7eb292347911bd19392e96692773489fa96c5af1ed86fae1
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans