Maxdesk — Data Processing Addendum (DPA)
Effective date: 10 July 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between MXG Infotech Private Limited ("MXG", "Processor", "we") and the Customer ("Customer", "Controller", "you") (each a "party") and applies to our processing of Customer Personal Data on your behalf in connection with the Maxdesk service (the "Service").
Where you act as a controller / data fiduciary of personal data you process through the Service, and we process that data on your behalf as a processor, this DPA governs that processing. In case of conflict with the Terms of Service on data-protection matters, this DPA prevails.
1. Definitions
- "Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the India Digital Personal Data Protection Act, 2023 and its Rules (DPDP), and applicable US state privacy laws.
- "Customer Personal Data" means personal data contained in Customer Data that we process on your behalf under the Terms.
- "Sub-processor" means a third party engaged by us to process Customer Personal Data.
- The terms "controller", "processor", "data subject", "personal data", "processing", and equivalents (including "data fiduciary" and "data principal" under DPDP) have the meanings given in the applicable Data Protection Laws.
2. Roles and scope
2.1 You are the controller (or, where you act on behalf of another controller, the processor) of Customer Personal Data, and we are your processor (or sub-processor). Each party will comply with its obligations under Data Protection Laws.
2.2 The subject matter, duration, nature, and purpose of processing, the types of personal data, and categories of data subjects are described in Annex A.
3. Processing instructions
3.1 We will process Customer Personal Data only (a) to provide the Service; (b) in accordance with your documented lawful instructions (including through your configuration and use of the Service and features such as AI Features); and (c) as required by law, in which case we will inform you unless legally prohibited.
3.2 You are responsible for ensuring your instructions and your use of the Service comply with Data Protection Laws, and that you have a lawful basis and all necessary consents and notices for the processing, including for AI Features and any advertising you enable.
3.3 You acknowledge that if you use AI Features, Customer Personal Data may be transmitted to third-party AI providers acting as our Sub-processors and processed solely to generate outputs for you. Such data is not used by those providers to train or improve their models. Your use of AI Features constitutes your instruction to us to enable such processing, and you represent you have the necessary lawful basis and consents.
4. Confidentiality
We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.
5. Security
We implement and maintain reasonable technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, appropriate to the risk, as further described in Annex B. You are responsible for your own security configuration and for how you use the Service (including access management for your Agents).
6. Sub-processors
6.1 You provide general authorisation for us to engage Sub-processors to process Customer Personal Data. A current list of Sub-processors is maintained at https://www.maxdesk.ai/subprocessors and currently includes categories such as cloud hosting (Amazon Web Services), payment processing (Razorpay and/or Stripe), analytics, advertising networks, and AI providers.
6.2 We will impose data-protection obligations on Sub-processors that are substantially similar to those in this DPA, and we remain responsible for their performance of those obligations.
6.3 We will provide a mechanism to notify you of changes to Sub-processors (for example, via the list page or email). You may object on reasonable data-protection grounds; if we cannot reasonably address your objection, your sole remedy is to stop using the affected feature or terminate as provided in the Terms.
7. Data-subject requests
Taking into account the nature of the processing, we will provide reasonable assistance, through appropriate technical and organisational measures and the self-service features of the Service, to help you respond to requests from data subjects / data principals to exercise their rights. If we receive such a request directly, we will, where lawful, direct the individual to you.
8. Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and will provide information reasonably available to us to assist you in meeting your obligations, including any obligation to notify authorities (such as the Data Protection Board of India) and affected individuals. You are responsible for making any required notifications where you are the controller.
9. Assistance
Taking into account the nature of processing and information available to us, we will provide reasonable assistance with your obligations regarding security, breach notification, and data-protection impact assessments and prior consultations, where applicable.
10. International transfers
Customer Personal Data may be transferred to and processed in India and other countries where we or our Sub-processors operate. Where such transfers are subject to Data Protection Laws requiring safeguards, the parties agree that appropriate transfer mechanisms apply, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum (or successor mechanisms), which are incorporated by reference and completed by reference to Annex A, with MXG as "data importer" and Customer as "data exporter", to the extent applicable.
11. Deletion and return
On expiry or termination of the Service, or otherwise on your written request, we will delete or return Customer Personal Data in accordance with the Terms and applicable Plan retention rules (including rolling-retention limits), except to the extent retention is required by law. You are responsible for exporting Customer Personal Data before termination or expiry.
12. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow for and contribute to audits, which may be satisfied by providing third-party certifications or reports where available. Audits are limited to once per year unless required by a supervisory authority, at your expense, and conducted so as not to disrupt our operations or compromise other customers' data.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service, including the aggregate liability cap.
14. General
This DPA is governed by the same law and dispute-resolution provisions as the Terms of Service, except where Data Protection Laws require otherwise (for example, the governing law of incorporated Standard Contractual Clauses). If any provision is invalid, the remainder remains in effect.
Annex A — Details of Processing
- Subject matter: provision of the Maxdesk helpdesk Service.
- Duration: the term of the Terms of Service, plus any retention period permitted or required.
- Nature and purpose: hosting, storing, transmitting, and processing Customer Personal Data to operate the Service and enabled features (including AI Features and, on ad-supported Plans, advertising as configured).
- Categories of data subjects: Customer's Agents, End Users, and other individuals whose personal data the Customer submits.
- Types of personal data: identity and contact details, support-ticket contents, communications, usage data, and any other personal data the Customer chooses to submit. The Customer is responsible for not submitting special-category / sensitive personal data except as appropriate and lawful.
- Controller: Customer. Processor: MXG.
Annex B — Security Measures (summary)
Access controls and authentication; encryption in transit and, where applicable, at rest; network and infrastructure security via our hosting provider; logical separation of customer environments; logging and monitoring; personnel confidentiality obligations; and vendor-management controls for Sub-processors. Specific measures may evolve; we will not materially reduce the overall level of security during the term.
Annex C — Sub-processors
A current list of Sub-processors is maintained at https://www.maxdesk.ai/subprocessors, including cloud hosting (Amazon Web Services), payment processors (Razorpay and/or Stripe), analytics providers, advertising networks, and AI providers.