Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement establishes that while Customer retains ownership of Service Data, the Customer simultaneously instructs Zendesk to use that data not only to deliver and secure the Services but also to improve Zendesk's products and services broadly.
This analysis describes what Zendesk's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision authorizes Zendesk to use Service Data for product improvement purposes, which may extend beyond the scope of processing strictly necessary to deliver contracted services. Depending on the nature of personal data within Service Data and applicable law, this authorization may require evaluation against GDPR purpose limitation requirements and CCPA service provider restrictions.
Interpretive note: The scope of permissible product improvement processing relative to GDPR purpose limitation and CCPA service provider restrictions depends on the content of the incorporated Data Processing Agreement, which is referenced by URL and not reproduced in this document.
The agreement authorizes Zendesk to use Service Data, which includes all data, text, messages, communications, or other information submitted by customers, agents, and end users, for the purpose of improving Zendesk's products and services. This authorization is framed as a customer instruction within the agreement rather than a separate opt-in mechanism.
Cross-platform context
See how other platforms handle Service Data Use for Product Improvement and similar clauses.
Compare across platforms →Monitoring
Zendesk has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"As between the parties, Customer retains ownership of all Service Data. Customer instructs Zendesk to use Service Data to provide, secure, and improve Zendesk's products and services.Excerpt from Zendesk's Terms of Service
(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles on purpose limitation and lawful basis for processing, as well as CCPA service provider restrictions that prohibit use of personal information outside the scope of the service relationship. The Data Protection Agreement incorporated by reference may further define or restrict permissible processing purposes. Enforcement authorities include EU/EEA national data protection authorities and the California Privacy Protection Agency. (2) GOVERNANCE EXPOSURE: High. The framing of product improvement as a Customer instruction rather than a Zendesk-initiated processing purpose may influence how this is characterized under GDPR and CCPA, but the operational effect is that Service Data, which may include personal data of end users and agents, is processed for purposes beyond service delivery. Whether the incorporated Data Processing Agreement adequately constrains this use requires specific review. (3) JURISDICTION FLAGS: EU/EEA customers face heightened exposure under GDPR, where processing personal data for product improvement by a data processor may require a separate lawful basis or may be permissible only under specific conditions. California-based customers should evaluate whether this authorization is consistent with CCPA service provider limitations. UK customers face similar considerations under UK GDPR. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should assess whether the Data Processing Agreement restricts the product improvement use of personal data within Service Data or whether it permits it, as the ZCA and DPA may need to be read together to determine the full scope of authorized processing. This clause may create liability exposure for customer organizations whose own privacy notices do not disclose that their service providers may use customer-submitted data for product improvement. (5) COMPLIANCE CONSIDERATIONS: Legal and compliance teams should review the incorporated Data Processing Agreement to determine whether it limits the product improvement processing authorization and whether customer privacy notices and consent mechanisms adequately disclose this downstream use. Data mapping exercises should flag Service Data flows to Zendesk's product improvement processes as a processing activity requiring documentation under GDPR Article 30.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision authorizes Zendesk to use Service Data for product improvement purposes, which may extend beyond the scope of processing strictly necessary to deliver contracted services. Depending on the nature of personal data within Service Data and applicable law, this authorization may require evaluation against GDPR purpose limitation requirements and CCPA service provider restrictions.
The agreement authorizes Zendesk to use Service Data, which includes all data, text, messages, communications, or other information submitted by customers, agents, and end users, for the purpose of improving Zendesk's products and services. This authorization is framed as a customer instruction within the agreement rather than a separate opt-in mechanism.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Zendesk.