Skip to content
Auditrak.ai
ProductQuestionsHow it worksPlansFAQ
Get updates
ProductQuestionsHow it worksPlansFAQ
Get updates
Data Processing Addendum

Customer data processing terms for Auditrak.

This addendum describes the processing terms that apply when Auditrak acts as processor for a customer's Zendesk data.

Last updated: September 30, 2026.

Application and acceptanceRolesCustomer instructionsCustomer responsibilitiesAuditrak commitmentsPII-aware and AI processingSecurity measuresSubprocessorsData subject requestsDeletion and returnPersonal data breachAudits and informationInternational transfersPrecedence Annex 1 Annex 2
01

Application and acceptance

This DPA is entered into between the customer identified in the applicable order, Marketplace subscription or Auditrak account record (the Customer) and Henri Mercier EI, an individual entrepreneur registered in France under SIREN 524 978 087 and trading as Auditrak.ai, with its registered establishment at 9 Avenue Maryse Bastié, 44230 Saint-Sébastien-sur-Loire, France (Auditrak).

This Data Processing Addendum forms part of and is incorporated into the applicable Auditrak agreement. Customers accept it when they accept the Terms of Use, install or authorize the Zendesk app, connect Zendesk, authorize an audit, or sign an order form, subscription terms or other agreement that incorporates this DPA by reference. It applies when Auditrak processes Personal Data on behalf of a customer in connection with Zendesk Marketplace app installation, Zendesk connection, audit execution, product results, report generation, support, security and service operations.

02

Roles

For Zendesk data processed as part of an Auditrak audit or report flow, the customer is generally the Controller and Auditrak is the Processor. For website inquiries, support conversations, account administration, billing and Auditrak business operations, Auditrak may act as an independent Controller.

03

Customer instructions

Auditrak processes customer Personal Data only to provide and secure the service, according to the customer's documented instructions in the agreement, app configuration, audit settings, support requests or written communications, or as required by law.

04

Customer responsibilities

Customers are responsible for Zendesk permissions, app installation approval, selecting the tickets and settings included in each audit, maintaining a valid legal basis, and avoiding unnecessary secrets, credentials, payment data, protected health information or other data that is not needed for the support audit.

05

Auditrak commitments

Auditrak will process customer Personal Data only for the agreed purposes, keep authorized personnel under confidentiality obligations, use appropriate technical and organizational measures, engage subprocessors under written data protection terms, and assist with privacy requests, security incidents and deletion processes as required by applicable law.

06

PII-aware and AI processing

Auditrak is designed to preserve useful business evidence while reducing unnecessary sensitive detail in analyzed material and customer-facing reports. Certain product features may use AI providers for analysis and report generation. Auditrak aims to send only the material reasonably needed for the audit and report flow, subject to PII-aware preparation and redaction controls.

07

Security measures

Auditrak uses approved Zendesk authorization, HTTPS/TLS for data in transit, managed-provider encryption at rest where supported, internal access controls, sanitized logs and monitoring.

08

Subprocessors

The customer gives Auditrak general authorization to use the subprocessors listed on the Subprocessors page. Auditrak remains responsible for subprocessor performance to the extent required by applicable data protection law. Auditrak will provide reasonable advance notice of a material new subprocessor through the public list and, where customer contact information and the applicable agreement permit, by direct notice. The customer may raise a reasonable data-protection objection before the change takes effect; the parties will work in good faith on an appropriate resolution.

09

Data subject requests

Auditrak will reasonably assist customers with data subject requests relating to customer Personal Data. Requests relating to underlying Zendesk ticket data may need to be handled through the customer because the customer controls the Zendesk account and support relationship.

10

Deletion and return

After termination, offboarding or written request, Auditrak will delete or return customer Personal Data according to the agreement and applicable law, unless retention is required or permitted for legal, security, backup, dispute-resolution, accounting or compliance purposes.

11

Personal data breach

Auditrak will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting customer Personal Data and will provide available information reasonably needed for the customer to meet its own obligations.

12

Audits and information

Auditrak will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security and service constraints. The parties will first use available documentation, security summaries, provider attestations and written responses before any deeper audit.

13

International transfers

Auditrak and subprocessors may process data in countries where they operate. Where required for EEA Personal Data transferred outside the EEA, the applicable European Commission Standard Contractual Clauses are incorporated by reference: Module 2 where the Customer is a controller and Auditrak is a processor, and Module 3 where the Customer and Auditrak act as processors. The UK Addendum, Swiss adaptations, transfer impact assessments or equivalent lawful mechanisms apply where relevant.

14

Precedence

If there is a conflict between this DPA and the Terms regarding processing of customer Personal Data, this DPA controls to the extent of the conflict. Mandatory transfer clauses control for the relevant international transfer.

Annex 1

Processing details

Subject matter

Processing Zendesk data and related service data to provide Auditrak audits, product results, privacy-conscious report generation, support, security and service administration.

Nature

Access, retrieval, preparation, redaction, analysis, classification, summarization, report generation, storage, transmission, display, download, logging, deletion and support.

Purposes

Zendesk connection, support-demand analysis, repeated request detection, self-service and automation recommendations, report generation, reliability, security and support.

Data subjects

Zendesk ticket requesters, end users, support agents, administrators, customer contacts and individuals mentioned inside support conversations.

Data categories

Names, email addresses, Zendesk identifiers, organization information, ticket content, ticket details, tags, custom fields, timestamps, CSAT-related content where selected, generated findings, reports, support communications and service logs.

Sensitive data

Auditrak is not designed for secrets, payment card data, health data, government identifiers or special-category data. Customers should avoid including such data unless expressly agreed in writing.

Annex 2

Authorized subprocessors

The current public list of authorized subprocessors is maintained on the Subprocessors page. Auditrak may update that list as described in this DPA and the applicable customer agreement.

Auditrak.ai

The Zendesk app that helps support teams decide what to automate, document, route or fix first from real support conversations.

Product

Product Questions Reports Trust

Resources

Plans FAQ Launch updates Marketplace updates

Legal

Data Processing Addendum Trust Subprocessors Contact Legal Notice
AUDITRAK.
© 2026 Auditrak.ai
Terms of Use Privacy Policy
Zendesk® is a trademark of Zendesk, Inc.