Data Processing Agreement
Effective 11 August 2026 · Last updated 24 September 2026
Purpose & how this fits together
This Data Processing Agreement ("DPA") describes how Techlyft Pty Ltd processes personal data contained in workspace content — conversations, contact records, and help-center data — on behalf of a customer ("Customer") that operates a DeskNova workspace, where data protection law requires a written processing agreement between a controller and its processor. It supplements the Terms of Service and is read alongside the Privacy Policy and AI Policy.
Where a signed DPA exists between Customer and Techlyft Pty Ltd, that signed agreement prevails for processor activities over this web page.
Roles of the parties
For personal data Customer's contacts submit through a workspace (for example, chat and email conversation content), Customer is the controller (or processor on behalf of a third-party controller) and Techlyft Pty Ltd is the processor (or service provider) acting on Customer's documented instructions, as described in this DPA and the Terms. This DPA does not apply to Techlyft Pty Ltd's own controller activities — account, billing, and marketing data — which are covered by the Privacy Policy.
Subject matter & details of processing
- Subject matter: providing the DeskNova shared inbox, help center, automation, Nova, and Copilot features Customer configures for its workspace.
- Duration: for the term of Customer's subscription plus the post-termination retention periods described in Data return & deletion.
- Nature and purpose: receiving, storing, routing, and displaying conversations and related workspace content so Customer's agents can respond to Customer's contacts; and, where enabled, operating Nova and generating Copilot drafts grounded in Customer's connected knowledge sources.
- Categories of data subjects: Customer's contacts/end users who message the workspace, and Customer's agents and admins who use the workspace.
- Categories of personal data: contact identifiers (for example name, email address, or phone number depending on the channel), message and attachment content, and account identifiers for agents/admins. Customer should not submit special-category data unless the Service explicitly supports it and Customer has obtained Techlyft Pty Ltd's prior written approval.
Subprocessors
Techlyft Pty Ltd uses subprocessors to provide the Service — including Hetzner (hosting),
Cloudflare (DNS, tunnel, R2, email relay), Stripe (payments), OpenAI, Anthropic, and AWS
Bedrock (eu-central-1) for DeskNova-funded AI generations, and PostHog EU for
analytics. The current list is published at
Subprocessors.
We will notify Customer of new subprocessors at least 30 days before they begin processing Customer Personal Data. Customer may object on reasonable grounds relating to data protection by notifying us within 14 days of the notice. If we cannot reasonably accommodate the objection, Customer may terminate the affected Service as its sole remedy.
Security measures
Technical controls are described on the Security page and Security FAQ, which this DPA incorporates by reference. Techlyft Pty Ltd maintains technical and organizational measures appropriate to the risk, including tenant isolation, access controls, encryption in transit, and field-level encryption for sensitive configuration values.
International transfers
Personal data may be processed in Australia (Techlyft Pty Ltd), Germany (hosting), the
European Union (Cloudflare R2, Backblaze B2, PostHog EU, AWS Bedrock
eu-central-1), and the United States (Stripe, OpenAI, Anthropic), among locations
listed on Subprocessors.
Where transfers require safeguards under GDPR or UK GDPR, Techlyft Pty Ltd relies on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other mechanisms recognized under applicable law.
Assistance & audits
Taking into account the nature of processing, Techlyft Pty Ltd will assist Customer with data subject requests and regulatory inquiries by appropriate technical and organizational measures. We will forward any data subject request we receive directly to Customer without responding to the requester unless required by law.
Upon written request no more than once per 12-month period, we will provide responses to a reasonable security questionnaire or our latest security documentation. On-site audits are not available; audit obligations are satisfied through these materials and the information on our Security pages.
Breach notification
Techlyft Pty Ltd will notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known: the nature of the incident, categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, and a point of contact. Notification is not an admission of fault or liability.
Data return & deletion
During the term. Customer may export Customer Personal Data during the subscription using product capabilities or by written request to [email protected].
After termination. Customer may request export for up to 30 days after termination. Customer Personal Data is deleted from active systems within 90 days after termination unless Customer instructs earlier deletion or law requires retention. Backup copies are deleted within 365 days on a rolling basis, subject to legal holds.
Techlyft Pty Ltd may retain Customer Personal Data as required by law or to establish, exercise, or defend legal claims; processing will be limited to those purposes.
Liability
Liability under this DPA follows the limitation of liability in the Terms of Service, unless applicable law requires otherwise. Each party remains liable for damages caused by processing that violates this DPA or applicable data protection law.
How to execute a signed DPA
This web page summarizes our processor commitments. Workspaces that need a countersigned DPA for procurement should contact [email protected] or [email protected]. Accepting the Terms of Service constitutes acceptance of this DPA for processor activities unless a separate signed agreement is executed.
Contact
Questions about this DPA, or requests for a signed copy, can be sent to [email protected].