What this means in plain language.
This addendum applies India's DPDP Act 2023 to your Wendesk workspace. You are the Data Fiduciary for your workspace data; we are your Data Processor. Grievances are acknowledged in 24 hours and resolved within 30 days.
TL;DR — The short version#
- You are the Data Fiduciary for everything you upload into your workspace; we are your Data Processor for that data.
- We are the Data Fiduciary for the account data you give us directly — billing, login, telemetry.
- Data Principal rights (access, correction, erasure, withdrawal of consent, grievance redressal) are routed through the in-app DSR workflow: 30 days standard; 7 days for India DPDP critical paths; statutory cap is 30 days under §13.
- Breach notification — 72 hours to the Data Protection Board; affected Data Principals notified without undue delay.
- Grievance Officer — [email protected]. Acknowledged within 24 hours, resolved within 30 days (per DPDP §8(9) and §13).
- Data residency — primary hosting in AWS Mumbai (ap-south-1); encryption is AES-256-GCM with AWS KMS-managed Customer Managed Keys; TLS 1.3 in transit.
1. Scope & definitions#
This Addendum forms part of the agreement between you (the "Customer") and FourteenCloud Pvt Ltd, a private limited company incorporated in India with its registered office at Jaipur, Rajasthan, India ("Wendesk", "we", "us"). It applies to personal data we process under the Digital Personal Data Protection Act, 2023 (the "Act") and the rules issued under it.
"Personal data" — any data about an individual who is identifiable by or in relation to such data, in line with §2(t) of the Act.
"Data Principal" — the individual to whom the personal data relates — in our context, your end-customer, your staff, or in the case of account data, you yourself.
"Data Fiduciary" — the entity that determines the purpose and means of processing personal data. The Customer is the Data Fiduciary for workspace data; Wendesk is the Data Fiduciary for the account data the Customer provides directly to us.
"Data Processor" — an entity that processes personal data on behalf of a Data Fiduciary. Wendesk acts as a Data Processor for all workspace data the Customer uploads.
"Significant Data Fiduciary" — a Data Fiduciary so notified under §10 of the Act, with additional obligations including DPIAs, audits, and a designated DPO.
Capitalised terms not defined here carry the meanings given in the Act or in our principal Terms.
2. Wendesk's role#
For personal data uploaded by the Customer into the Wendesk platform — CRM contacts, lead records, content drafts, message logs, voice-agent recordings, integration credentials, files — Wendesk acts as a Data Processor. We process this data only on the Customer's documented instructions, which are constituted by the configuration the Customer chooses in the platform, the actions the Customer's authorised users take, and any written direction the Customer issues to us.
For personal data the Customer provides directly to Wendesk to operate the account — the workspace owner's contact details, the billing contact, payment metadata, login credentials, security telemetry, and product-usage analytics — Wendesk acts as a Data Fiduciary.
3. The Customer's role#
The Customer is the Data Fiduciary for personal data of its end-customers, leads, employees, contractors, vendors, and any other third party whose personal data the Customer chooses to upload to its workspace. As Data Fiduciary, the Customer is responsible for: identifying a lawful basis for the processing; obtaining and recording any consents required under the Act; honouring Data Principal rights raised by its end-customers; publishing its own privacy notice; and configuring data retention to match its lawful purposes.
Wendesk does not determine the purpose or means of processing this data. We provide a configurable platform; the Customer determines what is collected, from whom, and why.
4. Categories of personal data processed#
Depending on which features the Customer enables, the platform may process the following categories of personal data on the Customer's behalf:
- CRM identifiers — names, mobile numbers, email addresses, postal addresses, GST numbers, custom-field values defined by the Customer.
- Conversational content — WhatsApp messages, SMS, email, in-app chat, and any media attached to these messages.
- Voice-agent data — if enabled, audio recordings, transcripts, sentiment classifications, and call metadata for inbound and outbound calls.
- Marketplace activity — storefront browsing, cart, order, and review data of end-customers transacting with the Customer.
- Payment metadata — transaction IDs, payment status, last-four card digits, UPI handle suffix; full card and bank account numbers never enter our systems and are tokenised at the payment gateway.
- Integration data — data synced from third-party apps the Customer connects (e.g. accounting, e-commerce, telephony).
- Industry-specific overlays — e.g. RERA project IDs (real estate), ICD-10 hints (healthcare), HSN codes (e-commerce), FSSAI licence numbers (food & beverage), CDSCO drug-licence references (pharma).
- Aadhaar (UID). Where the Customer chooses to capture Aadhaar numbers in CRM custom fields, Wendesk applies field-level masking automatically — the platform stores only the last 4 digits in plaintext. Storing full Aadhaar is prohibited. Customers requiring Aadhaar verification flows must integrate via DigiLocker.
5. Purpose limitation#
Wendesk processes personal data only for the purposes specified in the principal Terms and this Addendum. We do not use Customer-uploaded personal data for advertising, for resale, or to train AI models for the benefit of any party other than the Customer itself. AI inference performed on Customer data is scoped to the Customer's workspace and the model's response is returned to that workspace alone.
6. Consent management#
The Act treats consent as a primary lawful basis for processing personal data. Where the Customer relies on consent, the Customer is responsible for obtaining, recording, and being able to demonstrate that consent — in clear plain language, for specific stated purposes, and freely withdrawable.
To assist the Customer, Wendesk provides: configurable consent banners and consent forms inside the platform; a consent-record store that links each consent grant to the Data Principal record, the purpose, and the timestamp; tools to honour withdrawal of consent; and an audit log that captures every consent-related event.
Consent withdrawal: When a Data Principal withdraws consent through the in-app workflow, Wendesk immediately suppresses further processing for the affected purpose and notifies the Customer. Past lawful processing is not invalidated — the Act, like the GDPR, treats withdrawal as forward-looking.
Notice in plain English and an Indian language — DPDP §5: DPDP §5 requires that the notice given to a Data Principal be available in clear and plain language and in any one of the languages listed in the 8th Schedule of the Constitution. Wendesk delivers consent notices in English by default and in the Customer's chosen Indian-language pair (live: Hindi; upcoming: Tamil, Telugu, Marathi, Bengali, Gujarati).
DPDP Consent Manager interoperability: DPDP §6(1)(b) introduces the Consent Manager — a registered intermediary through which Data Principals manage consents across Data Fiduciaries. Once the Data Protection Board notifies the registration framework and certifies Consent Managers, Wendesk will accept consent attestations issued by registered Consent Managers.
7. Data Principal rights#
Sections 11 to 14 of the Act grant Data Principals the right to: confirm whether their personal data is being processed and obtain a summary; correct, complete, update, and erase their data; nominate another individual to exercise these rights upon their death or incapacity; and obtain readily available means of grievance redressal.
Wendesk surfaces these rights through an in-app Data Principal Request (DPR) workflow. Our internal SLA is 7 working days; the statutory cap is 30. Wendesk surfaces a parallel workflow for the Customer's own Data Principal rights against Wendesk-as-Fiduciary; route those requests to [email protected].
Where a request is manifestly unfounded or excessive, the Customer may, in consultation with us, charge a reasonable fee or refuse to act, with reasons recorded.
Article 26-equivalent — support staff impersonation logging: When platform Admin Support staff (role L3) act on a Customer workspace at the Customer's request, the session is wrapped in an ImpersonationSession record holding: actor, target tenant, target user, written reason, session start, session end, and every action taken inside the session. The record is immutable, retained 7 years, and surfaced to the Customer in a monthly compliance digest.
8. Personal data breach notification#
Section 8(6) of the Act requires Data Fiduciaries to notify the Data Protection Board of India and each affected Data Principal of a personal-data breach. The matrix below summarises the timelines we operate under across the regimes we serve.
Breach notification.
| Regime | To regulator | To affected person |
|---|---|---|
| DPDP (India) | 72 hours to the Data Protection Board | Without undue delay; via in-app banner + email |
| GDPR (EU/EEA) | Without undue delay; within 72 hours to the lead supervisory authority | Without undue delay where high risk to rights and freedoms |
| HIPAA (US healthcare) | As Business Associate, Wendesk notifies the Covered Entity without unreasonable delay and within 60 days of discovery (45 CFR §164.410); the Covered Entity then notifies HHS, individuals, and (≥500 records in a state) media per §164.404 | Customer-facing notice runs from the Covered Entity; Wendesk supplies forensic detail under the BAA |
Where Wendesk experiences a breach affecting Customer data, we notify the Customer's designated security contact within the regime-relevant window above, in writing, with: the nature of the breach, the categories and approximate number of Data Principals affected, the categories and approximate number of records affected, the likely consequences, the measures taken or proposed to address the breach, and the contact for follow-up.
9. Sub-processing#
The Customer authorises Wendesk to engage sub-processors for the purposes of providing the platform — cloud infrastructure, payment processing, transactional email and SMS, AI model inference, telephony, analytics, customer support tooling, and security monitoring. Each sub-processor is bound by a written agreement with confidentiality, security, breach-notification, and data-handling obligations no less protective than those in this Addendum.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure | Compute, RDS PostgreSQL, S3, KMS, Bedrock | AWS Mumbai (ap-south-1) |
| MongoDB Atlas | Database | Tenant business data (CRM, content, integrations) | AWS Mumbai (ap-south-1) |
| ClickHouse Cloud | Analytics database | High-volume activity logs (non-PII) | AWS Mumbai (ap-south-1) |
| Razorpay | Payments | Card tokenisation, UPI, net-banking, subscription billing | India |
| MSG91 | SMS gateway | OTP and transactional SMS | India |
| Twilio | Voice / messaging | WhatsApp Business API, voice fallback, programmable SMS | USA / Ireland (per region) |
| OpenAI | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Anthropic | AI inference | LLM completions when routed via quota router (zero-retention API) | USA |
| Google AI | AI inference | Gemini completions when routed via quota router | USA / Ireland |
| AWS Bedrock | AI inference | Default LLM provider for India tenants (Claude, Llama, Titan) | AWS Mumbai (ap-south-1) |
| Sarvam AI | AI inference | Indic-language LLM and TTS for vernacular features | India |
| Firebase | Authentication | Phone OTP delivery and Google OAuth for L7 marketplace customers | USA / multi-region |
| Cloudflare | CDN, DNS, WAF | DDoS mitigation, edge cache, custom-domain SSL for white-label tenants | Global edge |
| Typesense | Search | Full-text search index for marketplace and CRM (no PII indexed) | AWS Mumbai (ap-south-1) |
The Customer may object to any new sub-processor on reasonable grounds during the 30-day notice window, and if Wendesk cannot accommodate the objection, the Customer may terminate the affected service.
10. Cross-border transfers#
Section 16 of the Act permits transfers of personal data outside India to any country other than those notified by the Central Government as restricted. Wendesk's primary hosting region is AWS Mumbai (ap-south-1) with disaster-recovery in a second Indian region. Some sub-processors operate from outside India — for example, model inference may take place in Singapore or the United States.
Encryption
All tenant data is protected with AES-256-GCM with AWS KMS-managed Customer Managed Keys; per-tenant DEK; TLS 1.3 in transit. Each tenant is issued a dedicated data encryption key (DEK) wrapped by a Customer Managed Key (CMK) in AWS KMS; integration credentials and AI BYOK keys are encrypted with the same envelope and never logged.
Where you are determines what applies.
Wendesk is built India-first and ships compliance for additional jurisdictions on request or by roadmap. The matrix below is authoritative.
| Region | Regime | Status | How to invoke |
|---|---|---|---|
| India | DPDP Act 2023 | Enforced — default for all Indian tenants | Automatic |
| EU / EEA | GDPR | Available now via Data Processing Addendum | Email [email protected] |
| United Kingdom | UK GDPR + DPA 2018 | Available now via DPA + UK IDTA addendum | Email [email protected] |
| US healthcare | HIPAA | Available now via signed Business Associate Addendum | Email [email protected] |
| UAE | Federal PDPL | Coming 2027 — on roadmap | Register interest at [email protected] |
| Singapore | PDPA | Coming 2027 — on roadmap | Register interest at [email protected] |
For every cross-border flow, Wendesk applies one or more of: (i) contractual safeguards in the sub-processor agreement, including India-equivalent data protection clauses; (ii) the encryption block above; (iii) access controls and audit logging; and (iv) where the destination is on the restricted list, we will not transfer personal data unless and until a lawful basis exists.
11. Retention & erasure#
Wendesk retains Customer personal data only as long as necessary for the purpose of providing the platform. The default for closed workspaces is a 90-day frozen window after unsubscribe. After the grace period, primary stores are wiped automatically; encrypted backups rotate out within 35 days; a deletion certificate is available on request.
Erasure requests under section 12(3) of the Act are honoured regardless of the default grace period, save for data we must retain to comply with a statutory obligation (for example, billing records held for tax purposes) or to defend a legal claim.
12. Grievance Officer / Data Protection Officer#
Under section 8(9) of the Act, every Data Fiduciary must publish the contact details of an individual responsible for answering questions on its behalf. Wendesk has appointed a Grievance Officer who also serves as the Data Protection Officer for India operations.
Grievance Officer.
Wendesk's designated grievance contact is reachable at [email protected]. Every grievance is acknowledged within 24 hours and resolved within 30 days (per DPDP Section 8(9) and Section 13). The full grievance form lives at /grievance.
Postal & escalation: FourteenCloud Pvt Ltd — Grievance Officer. Registered office: Jaipur, Rajasthan, India. Email [email protected] for privacy and data rights; [email protected] for escalations. The full grievance form lives at /grievance; the DSR portal at /dsr-request.
If a Data Principal is not satisfied with the response, they may approach the Data Protection Board of India. The Customer (as Data Fiduciary for its end-customers) must publish its own grievance contact — Wendesk surfaces the field in the workspace's privacy-notice template.
13. Significant Data Fiduciary status#
Section 10 of the Act empowers the Central Government to notify any Data Fiduciary as a Significant Data Fiduciary based on volume and sensitivity of personal data, risk to electoral democracy, security of the State, public order, and other factors. SDFs carry additional duties: appointing a DPO based in India, periodic Data Protection Impact Assessments, periodic audits by an independent data auditor, and other measures the Government may prescribe.
If the Customer is notified as a Significant Data Fiduciary, our Enterprise plan includes the controls needed to support compliance: a designated DPO contact on our side, evidence packs for independent data audits, DPIA support for high-risk processing flows, in-region data pinning, and elevated audit-log retention. Speak to your account manager or write to [email protected] to engage these.
14. Children's data#
Section 9 of the Act defines a child as anyone under the age of 18 and prohibits the processing of children's personal data without verifiable parental consent. The Act also prohibits tracking, behavioural monitoring, and targeted advertising directed at children.
Wendesk does not knowingly process the personal data of children. Where a Customer's service may involve children — for example, an education tenant or a paediatric healthcare clinic — the Customer must enable the in-platform "verifiable parental consent" workflow before sending any communications, and must not configure behavioural-monitoring features on minor records.
15. Effective date & amendments#
This Addendum is effective from 2026-05-06. We update it as the Act, the rules under it, and our practices evolve. Material changes are emailed to workspace admins at least 30 days before they take effect, accompanied by a redline diff. Past versions are archived at /policies.
Where this Addendum conflicts with the principal Terms or with the Privacy Policy, this Addendum controls for matters within the scope of the Act. Where it conflicts with a written CustomPlan agreement, the CustomPlan controls.