Skip to main content
Zendesk logo

Zendesk

GDPR evidence

zendesk.comCustomer supportLast verified 17 Sep 2026
GDPR mark, CertReports state No public evidenceNo public evidence

Zendesk and GDPR

CertReports found no public GDPR evidence for Zendesk as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.

Evidence

VerifiedActive: UK Extension Certification, SW-US Certification, EU-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
17 Apr 2019
Expires or valid through
11 Dec 2026
Scope
Life360 is a mobile application that families use to communicate and collaborate with each other. We also have built-in mapping functionality. Hence, we hold user personal data related to family messaging & communication plus their location(s). We share some of this data with our partners, including Arity (particularly related to user behaviors when driving). Further details are included in our Privacy Policy.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Life360: Active: UK Extension Certification, SW-US Certification, EU-US Certification
Live pagesha256 d7789e83ad
VerifiedActive: UK Extension Certification, EU-US Certification, SW-US Certification
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
6 Dec 2016
Expires or valid through
23 Dec 2026
Scope
Personal data is collected online and offline in connection with business activities of Zendesk, Inc. and its Affiliates (collectively, "Zendesk"), including information related to prospective, current, and former customers, employees, and candidates, vendors, and suppliers. Zendesk collects this data for the following purposes: (1) to provide, operate, maintain, improve, and promote our Digital Properties and Services; (2) for our own business purposes; (3) for marketing our products and Services or those of third parties, such as our business partners; (4) internal processes to support legitimate business interests (such as day-to-day operations, such as accounting, financial reporting, audits, and business planning); (5) to fulfill a referral request when individuals use our referral service to tell a friend about our Services; (6) diversity, equity and inclusion analysis, programs, reporting, and initiatives, where legally permitted, including through aggregated data; (7) to evaluate or conduct a corporate transaction, such as a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of all or a portion of our business or assets; (8) when an individual has voluntarily agreed; (9) administering benefits and processing employee work-related claims; (10) business operations, including internal audits; (11) administering salary, payroll, equity incentive plans, and reimbursing expenses; (12) for investigative, disciplinary, or termination actions; (13) responding to emergencies or to protect the health or safety of an individual; (14) detecting fraud or other types of wrongdoing; (15) managing and protecting the security (both technical and physical) of our premises, operations, networks, software, systems, confidential information and similar assets and resources; (16) carrying out work performance appraisals, career planning, and skills monitoring; (17) where permitted or required to do so by law or by the order of a competent regulatory authority or court; and (18) where necessary to exercise, establish, or defend legal claims.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Zendesk, Inc.: Active: UK Extension Certification, EU-US Certification, SW-US Certification
Live pagesha256 3937964c21
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
We collect HR data to compensate employees based upon employment contract and also to remain complaint with local taxing authorities. Data is used to facilitate the employees personal health, wellness, and retirement goals. We collect non-HR data from prospects and donors to enable gift acknowledgement, provide periodic program results and reporting, marketing and engagement invitations.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026World Bicycle Relief: Inactive
Live pagesha256 8f2315ac68
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
6 Dec 2016
Scope
Our organization conducts e-commerce transactions online and collects personal data in the following ways: 1. We require user email addresses to facilitate our e-commerce transactions as a method of identifying the rightful purchaser. In addition, we collect the following non-personal information, as a necessary step of facilitating e-commerce transactions for our users. This includes the details of their order (search preferences), such as flight itinerary details. For all completed purchases and partially completed sessions in users' interactions with our services, we may retain such non-personal data on an aggregated and/or anonymized basis. Financial data is not collected, retained, or stored directly by FLYR INC., as we work with fully licensed and secured service providers to facilitate payment for our e-commerce transactions. As of December 2018, these service providers consist of Stripe and Paypal Inc. We have taken steps to ensure that any service providers interacting with our users are PCI compliant. We provide a gateway for these services via a 256-bit secure socket layer (SSL) connection directly to the service providers. As such, we do not retain (nor are we ever in custody of) personal financial details of our users.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026FLYR INC.: Inactive
Live pagesha256 8ceaa0bf3d
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
22 Nov 2019
Scope
Nebula processes data to provide its core services in genetic trait, ancestral and other forms of reporting. Additionally, Nebula will further process personal data to give users access to the possibility of sharing data with researchers working in the life sciences.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Nebula Genomics: Inactive
Live pagesha256 a8db1361ba
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
15 Nov 2016
Scope
Cloud4Wi is a B2B company that provides clients with an open WI-FI engagement platform that enhances Guest Wi-Fi access at venues. In some instances, Cloud4Wi may operate its Platform and collect personal data on behalf of its clients. Cloud4Wi limits disclosure of such collected data to client-approved service providers and third parties. For more details regarding the data collected by Cloud4Wi please visit our privacy policy.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Cloud4wi Inc.: Inactive
Live pagesha256 171311a794
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
FutureSimple Inc. develops a CRM software that allows customers to store their customer and prospect information along business information. It also processes personal data about its staff, including its employees, temporary staff, interns, and applicants for employment.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026FutureSimple, Inc.: Inactive
Live pagesha256 820f27e796
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
21 Nov 2016
Scope
We collect personal data for the purpose of helping people achieve their personal and professional goals. The data is collected to allow them to track their progress, share that with friends and family for support, and attach incentives to ensure success.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026stickK.com, LLC: Inactive
Live pagesha256 94edcad842
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Scope
Zendesk, with Smooch as an affiliate entity, stores and processes personal information about website visitors and Subscribers (through customer sign-up to the Zendesk Service) within the EEA, the United States and in other countries and territories. Zendesk also processes the personal information of Zendesk employees. To facilitate our global operations and to provide the Services for which our Subscribers purchase, we may transfer and access such personal information from around the world, including from other countries in which the Zendesk Group has operations. Zendesk may disclose personal information to its wholly-owned affiliate entities or third party service providers. Zendesk processes personal information about its Subscribers and their users in order to provide them the Zendesk Services to which they subscribe. For example, to enable our Subscribers and their users to login to the Services and send communications using these Services. Zendesk processes information that Subscribers submit to, and store in, the Service (“Service Data”) as instructed by our Subscribers, and has no ownership rights in and to our Subscribers’ Service Data. The use of Service Data is limited to the purpose of providing the Service for which our Subscribers have engaged a member of the Zendesk Group. Disclosure of Service Data to third party service providers is limited to Sub-Processors: https://support.zendesk.com/hc/en-us/articles/360022185294-Sub-processors. Zendesk processes personal information of website visitors for communications and business operations, for instance, participation in community forums or webinars, or event registration. Zendesk also processes personal information about its EEA and Swiss employees to manage all aspects of the employment relationship, such as onboarding, payroll, performance, and administration of benefits.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Smooch Technologies US Inc.: Inactive
Live pagesha256 78d4dcba23
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
12 Mar 2025
Scope
We collect user's personal information needed to complete applications for various government services on user's behalf. Data can include but is not limited to the name, email, phone number, and passport numbers. All sensitive user data such as passport numbers are hardware encrypted using AWS KMS service and is automatically deleted 30 days after we have completed the user's application. We also allow users to request to have their sensitive information deleted before that time if they choose to do so.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026Gov Apply Support: Inactive
Live pagesha256 36d8c3b432
ExpiredInactive
as of 17 Sep 2026 · confidence 100%
Kind
listing
Issued or listed
20 Nov 2018
Scope
There are three areas that StreamText servers will store user information. User data is collected to allow users to login and access their accounts. This includes email address and a password. Address data is collected for the account holder for invoicing purposes. StreamText is used to stream text communications by our customers. Those sessions can be stored to our servers and the contents of the comminations. This is not the default setting and users must explicitly select the option to save these communications.
SourceCapturedQuoteLinks
Data Privacy Framework list
Official registry · HTTP 200
17 Sep 2026StreamText.Net Inc.: Inactive
Live pagesha256 430aa5af7e
What GDPR means, and what it does not

"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.

Read the GDPR guide and browse all vendors with evidence

Questions buyers ask

Is Zendesk GDPR compliant?

There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.

How does CertReports verify this?

Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.

Alternatives with GDPR evidence

Similar vendors (shared product tags or the Customer support category) whose GDPR row is verified or vendor-stated, ranked by similarity.