Legal
Data processing addendum
Last updated October 6, 2026
This addendum is part of the terms of service between Aiden Wu (“we”, the processor) and the business using Flatdesk (“you”, the controller). It applies whenever we process personal data for you, and it applies automatically: there's nothing to sign. If your company needs a signed copy, email flatdeskmain@gmail.com and we'll countersign this text.
1. What we process
Subject matter and purpose: running your help desk: receiving, storing, showing and sending your customers' emails and chats, their attachments, your team's replies and notes, imported history, and AI features your team uses.
People: your customers and website visitors who contact you, and the members of your team. Data: names, email addresses, message content, files, and anything else they choose to send you. You agree not to send special categories of data (such as health data) or card numbers through Flatdesk.
Duration: as long as your account exists, then until deletion under section 8.
2. Your instructions
We process the data only to provide the service, as these terms and your settings describe, and on your other documented instructions. If we believe an instruction breaks data protection law, we'll tell you. We don't sell the data or use it to train AI models.
3. Confidentiality
Anyone we allow to access the data is bound to keep it confidential, and has access only as far as their work needs it.
4. Security
We keep the technical and organizational measures described on the security page, including encryption in transit and at rest, separation of each team's data, required two-step verification when you turn it on, an audit log, and an off switch for AI processing. We may improve these measures but won't make them materially weaker.
5. Subprocessors
You authorize the subprocessors listed in the privacy policy. We have written terms with each that protect the data at least as well as this addendum, and we remain responsible for them. Before adding or replacing a subprocessor we'll email your admins at least 30 days ahead. If you object on reasonable data protection grounds and we can't address it, you can cancel and we'll refund any prepaid time you haven't used.
6. Helping you
We'll help you answer requests from people exercising their rights (access, correction, deletion, export), mostly through the export and delete tools in the app. We'll pass on any such request we receive directly. We'll also give reasonable help with impact assessments and with questions from a data protection authority.
7. Breaches
If we become aware of a breach of security leading to accidental or unlawful loss, change, disclosure of or access to your data, we'll notify your team's admins without undue delay and within 72 hours, with what we know, the likely effects and what we're doing about it, and keep you updated as we learn more.
8. Return and deletion
You can export everything, attachments included, from Settings at any time. When your account is deleted at your request, we delete the data within 30 days, except where the law requires us to keep it.
9. Audits
We'll answer reasonable written security questionnaires and give you the information needed to show we meet this addendum, once a year or after a breach. We don't have a third-party audit report yet (see the security page).
10. Transfers
The data is processed mainly in the United States. Where data from the EU, UK or Switzerland is transferred, the European Commission's Standard Contractual Clauses (module 2, controller to processor) and the UK addendum apply between us, and are incorporated by reference.
11. Order of precedence
If this addendum and the terms disagree about personal data, this addendum wins.