Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Zendesk states that it may retain personal data after a business relationship ends for purposes including fulfilling surviving contract provisions, evidencing business practices, marketing its products and services, and meeting legal or tax requirements; data stored in backup archives may be retained until deletion is technically feasible.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes post-relationship retention for a range of purposes, including continued marketing communications, which may require evaluation under GDPR storage limitation principles and applicable national laws. The backup archive exception permits retention beyond standard deletion timelines in cases where technical deletion is not immediately feasible.
Interpretive note: Whether retention for marketing purposes after relationship termination satisfies GDPR's legitimate interests standard depends on the specific circumstances and the outcome of a legitimate interests assessment, which the notice does not provide in detail.
Under this clause, personal data may remain in Zendesk's systems after a contractual relationship ends, and may be used to send information about Zendesk products and services until a legitimate business need no longer exists. The agreement states that data in backup archives will be isolated from further processing but retained until deletion is technically possible.
Cross-platform context
See how other platforms handle Post-Relationship Data Retention and similar clauses.
Compare across platforms →Monitoring
Zendesk has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Once you and/or your company have terminated the contractual relationship with us or otherwise ended your relationship with us, we may retain your personal data in our systems and records to ensure adequate fulfillment of surviving provisions in terminated contracts or for other legitimate business purposes, such as to evidence our business practices and contractual obligations, to provide you with information about our products and services, or to comply with applicable legal, tax, or accounting requirements. When we have no ongoing legitimate business need nor lawful legal ground to process your personal data, we will delete, anonymize, or aggregate it or, if this is not possible (for example, because your personal data has been stored in backup archives), then we will securely store your personal data and isolate it from any further processing until deletion is possible.Excerpt from Zendesk's Privacy Policy
1. REGULATORY LANDSCAPE: Post-relationship retention for purposes including marketing implicates GDPR Articles 5(1)(e) (storage limitation) and 6 (lawful basis), as well as UK GDPR equivalents. The CCPA and CPRA impose obligations on retention periods and require disclosure of retention periods or the criteria used to determine them. Supervisory authorities including EU data protection authorities and the UK ICO have examined post-contractual retention practices. 2. GOVERNANCE EXPOSURE: Medium. The inclusion of 'to provide you with information about our products and services' as a post-relationship retention purpose may require evaluation under GDPR's legitimate interests assessment, given that marketing following relationship termination may not meet the legitimate interests threshold without additional justification or consent. The backup archive exception is operationally common but should be documented in the organization's data retention schedule. 3. JURISDICTION FLAGS: EU and EEA jurisdictions create heightened exposure given GDPR storage limitation requirements. California residents may request deletion under CCPA, and the document's exceptions for backup archives and legitimate business purposes may be evaluated against CCPA's defined deletion exceptions. 4. CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm whether Zendesk's DPA specifies retention periods applicable to Subscriber data, and whether post-relationship retention for marketing purposes applies to data processed in the Processor capacity or only to Controller-capacity data. The notice's scope exclusion of Processor data may limit applicability, but this should be verified through contractual review. 5. COMPLIANCE CONSIDERATIONS: Legal teams should map post-relationship retention periods against GDPR storage limitation requirements and confirm that retention for marketing purposes is supported by a valid lawful basis following contract termination. Data subject deletion requests submitted after relationship termination should be assessed against the exceptions described in this provision. Retention schedules should document the backup archive exception and specify when archived data will be deleted.
This provision authorizes post-relationship retention for a range of purposes, including continued marketing communications, which may require evaluation under GDPR storage limitation principles and applicable national laws. The backup archive exception permits retention beyond standard deletion timelines in cases where technical deletion is not immediately feasible.
Under this clause, personal data may remain in Zendesk's systems after a contractual relationship ends, and may be used to send information about Zendesk products and services until a legitimate business need no longer exists. The agreement states that data in backup archives will be isolated from further processing but retained until deletion is technically possible.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.