Published 11 September 2026. Version 1.0. Contractual terms take effect through the applicable agreement mechanism.
1. Parties and application
This Customer Data Processing Addendum (DPA) forms part of the agreement governing the Customer's use of Triage Helper (Agreement) where Will Perry trading as PezTech Software (Provider) processes Customer Personal Data for the Customer.
Provider contact: support@peztechsoftware.co.uk Correspondence and legal-notice address: [The Bristol Office, 2nd Floor, 5 High Street, Westbury-on-Trym, Bristol, BS9 3BY, England].
The Customer is the customer organisation identified by the applicable Marketplace, order or documented agreement mechanism. This DPA becomes effective when the Agreement becomes effective and continues while the Provider processes Customer Personal Data.
Where the Provider processes personal data on behalf of the Customer in providing Triage Helper, the Provider acts as the Customer's processor for the processing described here. If the Customer is itself a processor acting for another controller, the Customer confirms that its instructions and the Provider's appointment are authorised by that controller.
This DPA controls over the other Agreement documents only for Customer Personal Data and data-protection matters.
2. Definitions
Applicable Data Protection Law means data-protection law applicable to the processing, including the UK GDPR and Data Protection Act 2018 where relevant.
Customer Personal Data means personal data in Freshservice ticket, conversation, user, configuration or support information processed by the Provider on the Customer's behalf through the Product.
Freshworks Platform means the Freshservice, Marketplace, OAuth, request-proxy, SDK, installation-settings and hosted app-storage services used by the Product.
Controller, processor, data subject, personal data, processing and personal-data breach have the meanings in Applicable Data Protection Law.
3. Processing instructions
The Provider will process Customer Personal Data only:
- to provide, secure, maintain and troubleshoot the Product;
- on documented Customer instructions in the Agreement, Product configuration and authorised support requests;
- as required by applicable law, after informing the Customer unless legally prohibited; and
- for no independent advertising, profiling or sale purpose.
The Customer instructs the Provider to use the Freshworks Platform for the processing described in Schedule 1. The Customer is responsible for lawful instructions, notices, permissions and the accuracy and minimisation of data placed in Freshservice or deliberately supplied to support.
The Provider will notify the Customer if an instruction appears to infringe Applicable Data Protection Law, unless prohibited from doing so.
4. Confidentiality and personnel
The Provider will ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as necessary for their role.
5. Security
Taking account of the nature of processing, available platform controls, implementation cost and risk, the Provider will maintain appropriate technical and organisational measures. Current measures include the controls in Schedule 3 and the Triage Helper Security page.
No measure is represented as an absolute security guarantee. The Customer remains responsible for Freshservice access control, its users, lawful configuration, endpoint security and deciding what data to place in tickets or send to support.
6. Freshworks Platform and Provider-selected processors
Freshworks separately provides the Freshservice platform and processes data under the Customer's agreement with Freshworks. Freshworks is not a party to this DPA, and this DPA does not amend or replace the Customer's Freshworks agreement or the Freshworks DPA. The Provider does not describe itself as a Freshworks sub-processor unless Freshworks confirms that contractual relationship applies.
Where the Provider selects and controls another service provider to process Customer Personal Data on the Provider's behalf, the Customer gives general written authorisation for that appointment. The Provider will require legally appropriate data-protection obligations and remains responsible for its own compliance.
The current necessary service relationships are:
- Freshworks, separately, for Freshservice, Marketplace, OAuth, request proxy, SDK, installation settings and hosted app storage under the Customer's Freshworks agreement; and
- Microsoft 365 only where the Customer deliberately sends Customer Personal Data through the approved support mailbox.
The Provider will give reasonable notice of a material new or replacement processor that it selects and controls, and will consider a substantiated data-protection objection in good faith. Freshworks-managed processors and changes are governed by the Customer's applicable Freshworks terms and notices; the Provider does not promise control it does not possess.
7. Data-subject requests
Taking account of the nature of processing, the Provider will provide reasonable assistance for Customer responses to data-subject requests. The Provider will not respond to a request concerning Customer-controlled data except on Customer instruction, where required by law, or to direct the requester to the Customer.
8. Security incidents
The Provider will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide available information reasonably needed for the Customer's legal obligations.
Notification is not an admission of fault. The Customer remains responsible for deciding whether and how to notify individuals or authorities, with reasonable Provider assistance taking account of the processing and information available.
9. Compliance assistance
Taking account of the nature of processing and information available, the Provider will provide reasonable assistance with security obligations, breach notifications, data-protection impact assessments and prior consultation where required by Applicable Data Protection Law.
10. International transfers
Neither party will transfer Customer Personal Data in breach of Applicable Data Protection Law. Where a restricted transfer requires a safeguard, the parties will use an applicable lawful mechanism, including relevant standard contractual clauses or the UK Addendum where appropriate. Freshworks and Microsoft transfer arrangements are governed by their applicable contracts, data-protection terms and public subprocessor information. No UK-only processing promise is made.
11. Return, deletion and retention
During the Agreement, Product data remains available through the Product and Freshservice only to the extent supported by those services. The Product does not provide a separate Customer-data export.
On termination and at the Customer's documented choice where legally required, the Provider will delete or return Customer Personal Data that it controls, unless law requires retention. Ticket snapshots and author-role results are transient browser memory. Freshworks manages installation settings and OAuth; platform deletion and backup lifecycle depend on available Freshworks controls.
The Product does not establish automatic deletion, backup deletion timing, OAuth revocation or restored-state behaviour after uninstall. The Provider will not promise immediate platform deletion it cannot verify or perform. PezTech-controlled support and business records follow the retention periods in the Privacy Notice, with access restricted and processing limited during any required retention.
12. Information and audit
The Provider will make available information reasonably necessary to demonstrate compliance with this DPA, beginning with current documentation and relevant compliance evidence.
If that information is reasonably insufficient and Applicable Data Protection Law requires further verification, the Customer may request a proportionate audit by itself or an independent auditor subject to confidentiality. Audits require reasonable prior notice, occur during normal business hours, avoid disruption, and must not expose another customer's data, personal devices, a home, unrelated systems or Provider secrets.
The Customer bears its audit costs unless law requires otherwise or a material Provider breach is established.
13. Liability
The Agreement's General Cap and exclusions apply to contractual claims under this DPA to the extent legally permitted. Nothing limits statutory data-subject rights, direct statutory liability, regulator powers or liability that cannot lawfully be limited.
14. Duration and changes
This DPA continues until the Provider no longer processes Customer Personal Data. Changes required by law or a material Product/platform change will be documented and communicated through an appropriate agreement or Marketplace mechanism. No updated DPA automatically binds an existing Customer where further notice or acceptance is legally required.
Schedule 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Read-only review of Open and Pending tickets in configured, permitted Freshservice workspaces; unassigned, waiting and stale evidence, configuration, security and authorised support. |
| Duration | The Agreement term plus limited deletion/return and legally required retention. |
| Nature | Read, validate, compare, derive, display and troubleshoot using temporary browser-memory state. No automatic ticket mutation or reminder sending. |
| Purpose | Provide, secure, maintain and support Triage Helper. |
| Data subjects | Customer agents and administrators; requesters and other people represented in ticket or conversation data; support contacts. |
| Data categories | Ticket and workspace/assignment/status/priority identifiers, subjects and timestamps, resolution deadlines, conversation source/author/public-private state/timestamps, requester-role evidence, configuration and deliberately supplied support information. API responses may transiently contain additional bodies and personal profiles, which the app discards. |
| Sensitive data | Not intentionally sought. Customer-controlled ticket or conversation content may nevertheless contain sensitive data; the Customer should minimise it and avoid sending it to support. |
Schedule 2 — Platform and service providers
| Provider | Function | Data boundary |
|---|---|---|
| Freshworks | Separately provides Freshservice APIs and the system of record; Marketplace, OAuth, request proxy, SDK, settings and hosted app storage under the Customer's Freshworks agreement | Freshworks is not a party to this DPA. Exact platform countries, backups, processors and lifecycle depend on Freshworks terms and confirmed platform facts. |
| Microsoft 365 | Approved support mailbox | Only information the Customer deliberately sends; never credentials or unnecessary ticket/conversation content. |
Schedule 3 — Current technical and organisational measures
- three read-only Freshservice scopes and four fixed authenticated HTTPS GET templates;
- current-host binding and strict host and numeric identifier validation;
- bounded pagination, pacing, an 80-request and 120-second scan budget;
- identity checks, cancellation, access-loss clearing and safe error messages;
- HTML escaping of ticket strings;
- transient snapshots and scan-local author-role evidence, with no persistent ticket cache;
- no PezTech-operated application backend, ticket database, analytics or tracking service;
- dependency review, deterministic tests and Freshworks validation; and
- support data shared only when deliberately supplied by the Customer.