1. Parties and application
This Customer Data Processing Addendum (DPA) forms part of the agreement governing the Customer's use of Freshservice Work Next (Agreement) where Will Perry trading as PezTech Software (Provider) processes Customer Personal Data for the Customer.
Provider contact: support@peztechsoftware.co.uk Correspondence and legal-notice address: [The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, England].
The Customer is the customer organisation identified by the applicable Marketplace, order or documented agreement mechanism. This DPA becomes effective when the Agreement becomes effective and continues while the Provider processes Customer Personal Data.
Where the Provider processes personal data on behalf of the Customer in providing Work Next, the Provider acts as the Customer's processor for the processing described here. If the Customer is itself a processor acting for another controller, the Customer confirms that its instructions and the Provider's appointment are authorised by that controller.
This DPA controls over the other Agreement documents only for Customer Personal Data and data-protection matters.
2. Definitions
Applicable Data Protection Law means data-protection law applicable to the processing, including the UK GDPR and Data Protection Act 2018 where relevant.
Customer Personal Data means personal data in Freshservice ticket, conversation, user, configuration or support information processed by the Provider on the Customer's behalf through the Product.
Freshworks Platform means the Freshservice, Marketplace, OAuth, request-proxy, SDK, installation-settings and hosted app-storage services used by the Product.
Controller, processor, data subject, personal data, processing and personal-data breach have the meanings in Applicable Data Protection Law.
3. Processing instructions
The Provider will process Customer Personal Data only:
- to provide, secure, maintain and troubleshoot the Product;
- on documented Customer instructions in the Agreement, Product configuration and authorised support requests;
- as required by applicable law, after informing the Customer unless legally prohibited; and
- for no independent advertising, profiling or sale purpose.
The Customer instructs the Provider to use the Freshworks Platform for the processing described in Schedule 1. The Customer is responsible for lawful instructions, notices, permissions and the accuracy and minimisation of data placed in Freshservice or deliberately supplied to support.
The Provider will notify the Customer if an instruction appears to infringe Applicable Data Protection Law, unless prohibited from doing so.
4. Confidentiality and personnel
The Provider will ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as necessary for their role.
5. Security
Taking account of the nature of processing, available platform controls, implementation cost and risk, the Provider will maintain appropriate technical and organisational measures. Current measures include the controls in Schedule 3 and the Work Next Security page.
No measure is represented as an absolute security guarantee. The Customer remains responsible for Freshservice access control, its users, lawful configuration, endpoint security and deciding what data to place in tickets or send to support.
6. Freshworks Platform and Provider-selected processors
Freshworks separately provides the Freshservice platform and processes data under the Customer's agreement with Freshworks. Freshworks is not a party to this DPA, and this DPA does not amend or replace the Customer's Freshworks agreement or the Freshworks DPA. The Provider does not describe itself as a Freshworks sub-processor unless Freshworks confirms that contractual relationship applies.
Where the Provider selects and controls another service provider to process Customer Personal Data on the Provider's behalf, the Customer gives general written authorisation for that appointment. The Provider will require legally appropriate data-protection obligations and remains responsible for its own compliance.
The current necessary service relationships are:
- Freshworks, separately, for Freshservice, Marketplace, OAuth, request proxy, SDK, installation settings and hosted app storage under the Customer's Freshworks agreement; and
- Microsoft 365 only where the Customer deliberately sends Customer Personal Data through the approved support mailbox.
The Provider will give reasonable notice of a material new or replacement processor that it selects and controls, and will consider a substantiated data-protection objection in good faith. Freshworks-managed processors and changes are governed by the Customer's applicable Freshworks terms and notices; the Provider does not promise control it does not possess.
7. Data-subject requests
Taking account of the nature of processing, the Provider will provide reasonable assistance for Customer responses to data-subject requests. The Provider will not respond to a request concerning Customer-controlled data except on Customer instruction, where required by law, or to direct the requester to the Customer.
8. Security incidents
The Provider will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide available information reasonably needed for the Customer's legal obligations.
Notification is not an admission of fault. The Customer remains responsible for deciding whether and how to notify individuals or authorities, with reasonable Provider assistance taking account of the processing and information available.
9. Compliance assistance
Taking account of the nature of processing and information available, the Provider will provide reasonable assistance with security obligations, breach notifications, data-protection impact assessments and prior consultation where required by Applicable Data Protection Law.
10. International transfers
Neither party will transfer Customer Personal Data in breach of Applicable Data Protection Law. Where a restricted transfer requires a safeguard, the parties will use an applicable lawful mechanism, including relevant standard contractual clauses or the UK Addendum where appropriate. Freshworks and Microsoft transfer arrangements are governed by their applicable contracts, data-protection terms and public subprocessor information. No UK-only processing promise is made.
11. Return, deletion and retention
During the Agreement, Product data remains available through the Product and Freshservice only to the extent supported by those services. The Product does not provide a separate Customer-data export.
On termination and at the Customer's documented choice where legally required, the Provider will delete or return Customer Personal Data that it controls, unless law requires retention. Product configuration, cache and waiting observations are held in Freshworks-hosted app storage; deletion and backup lifecycle depend on available Freshworks controls.
The Product does not establish automatic deletion, backup deletion timing, OAuth revocation or restored-state behaviour after uninstall. The Provider will not promise immediate platform deletion it cannot verify or perform. PezTech-controlled support and business records follow the retention periods in the Privacy Notice, with access restricted and processing limited during any required retention.
12. Information and audit
The Provider will make available information reasonably necessary to demonstrate compliance with this DPA, beginning with current documentation and relevant compliance evidence.
If that information is reasonably insufficient and Applicable Data Protection Law requires further verification, the Customer may request a proportionate audit by itself or an independent auditor subject to confidentiality. Audits require reasonable prior notice, occur during normal business hours, avoid disruption, and must not expose another customer's data, personal devices, a home, unrelated systems or Provider secrets.
The Customer bears its audit costs unless law requires otherwise or a material Provider breach is established.
13. Liability
The Agreement's General Cap and exclusions apply to contractual claims under this DPA to the extent legally permitted. Nothing limits statutory data-subject rights, direct statutory liability, regulator powers or liability that cannot lawfully be limited.
14. Duration and changes
This DPA continues until the Provider no longer processes Customer Personal Data. Changes required by law or a material Product/platform change will be documented and communicated through an appropriate agreement or Marketplace mechanism. No updated DPA automatically binds an existing Customer where further notice or acceptance is legally required.
Schedule 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Read-only evaluation of tickets assigned to the signed-in Freshservice agent; ranked recommendations, Smart Views, waiting observations, configuration, security and authorised support. |
| Duration | The Agreement term plus limited deletion/return and legally required retention. |
| Nature | Read, validate, organise, compare, derive, cache, display, retrieve, delete and troubleshoot. No automatic ticket mutation or reminder sending. |
| Purpose | Provide, secure, maintain and support Freshservice Work Next. |
| Data subjects | Customer agents and administrators; requesters and other people represented in ticket or conversation data; support contacts. |
| Data categories | Identifiers, workspace/assignment/status/priority, ticket subject and timestamps, SLA data, conversation direction/public-private state/timestamps, configuration, derived cache/waiting observations and deliberately supplied support information. |
| Sensitive data | Not intentionally sought. Customer-controlled ticket or conversation content may nevertheless contain sensitive data; the Customer should minimise it and avoid sending it to support. |
Schedule 2 — Platform and service providers
| Provider | Function | Data boundary |
|---|---|---|
| Freshworks | Separately provides Freshservice APIs and the system of record; Marketplace, OAuth, request proxy, SDK, settings and hosted app storage under the Customer's Freshworks agreement | Freshworks is not a party to this DPA. Exact platform countries, backups, processors and lifecycle depend on Freshworks terms and confirmed platform facts. |
| Microsoft 365 | Approved support mailbox | Only information the Customer deliberately sends; never credentials or unnecessary ticket/conversation content. |
Schedule 3 — Current technical and organisational measures
- two read-only Freshservice scopes and authenticated HTTPS GET requests;
- strict Freshservice host, ticket and agent identifier validation;
- bounded pagination, duplicate-page rejection and a 45-request refresh ceiling;
- validated configuration, response and cache schemas with conservative failure handling;
- tenant-host markers and agent-specific derived-cache keys;
- text rendering of ticket/configuration values and curated errors rather than raw API bodies;
- no PezTech-operated Work Next backend, external ticket database, analytics or tracking service;
- no intentional derived-cache storage of ticket subjects, conversation bodies, private-note text, participant details, credentials or tokens;
- dependency review and release validation; and
- local support diagnostics that are not automatically transmitted.