DeskNova
Omnichannel inboxNovaCopilotKnowledge basePricing
Sign in Start 14-day trial
Omnichannel inboxNovaCopilotKnowledge basePricing
Sign in Start 14-day trial
On this page
  1. Purpose & how this fits together
  2. Roles of the parties
  3. Subject matter & details of processing
  4. Subprocessors
  5. Security measures
  6. International transfers
  7. Assistance & audits
  8. Breach notification
  9. Data return & deletion
  10. Liability
  11. How to execute a signed DPA
  12. Contact

Data Processing Agreement

Effective 11 August 2026 · Last updated 24 September 2026

Purpose & how this fits together

This Data Processing Agreement ("DPA") describes how Techlyft Pty Ltd processes personal data contained in workspace content — conversations, contact records, and help-center data — on behalf of a customer ("Customer") that operates a DeskNova workspace, where data protection law requires a written processing agreement between a controller and its processor. It supplements the Terms of Service and is read alongside the Privacy Policy and AI Policy.

Where a signed DPA exists between Customer and Techlyft Pty Ltd, that signed agreement prevails for processor activities over this web page.

Roles of the parties

For personal data Customer's contacts submit through a workspace (for example, chat and email conversation content), Customer is the controller (or processor on behalf of a third-party controller) and Techlyft Pty Ltd is the processor (or service provider) acting on Customer's documented instructions, as described in this DPA and the Terms. This DPA does not apply to Techlyft Pty Ltd's own controller activities — account, billing, and marketing data — which are covered by the Privacy Policy.

Subject matter & details of processing

  • Subject matter: providing the DeskNova shared inbox, help center, automation, Nova, and Copilot features Customer configures for its workspace.
  • Duration: for the term of Customer's subscription plus the post-termination retention periods described in Data return & deletion.
  • Nature and purpose: receiving, storing, routing, and displaying conversations and related workspace content so Customer's agents can respond to Customer's contacts; and, where enabled, operating Nova and generating Copilot drafts grounded in Customer's connected knowledge sources.
  • Categories of data subjects: Customer's contacts/end users who message the workspace, and Customer's agents and admins who use the workspace.
  • Categories of personal data: contact identifiers (for example name, email address, or phone number depending on the channel), message and attachment content, and account identifiers for agents/admins. Customer should not submit special-category data unless the Service explicitly supports it and Customer has obtained Techlyft Pty Ltd's prior written approval.

Subprocessors

Techlyft Pty Ltd uses subprocessors to provide the Service — including Hetzner (hosting), Cloudflare (DNS, tunnel, R2, email relay), Stripe (payments), OpenAI, Anthropic, and AWS Bedrock (eu-central-1) for DeskNova-funded AI generations, and PostHog EU for analytics. The current list is published at Subprocessors.

We will notify Customer of new subprocessors at least 30 days before they begin processing Customer Personal Data. Customer may object on reasonable grounds relating to data protection by notifying us within 14 days of the notice. If we cannot reasonably accommodate the objection, Customer may terminate the affected Service as its sole remedy.

Security measures

Technical controls are described on the Security page and Security FAQ, which this DPA incorporates by reference. Techlyft Pty Ltd maintains technical and organizational measures appropriate to the risk, including tenant isolation, access controls, encryption in transit, and field-level encryption for sensitive configuration values.

International transfers

Personal data may be processed in Australia (Techlyft Pty Ltd), Germany (hosting), the European Union (Cloudflare R2, Backblaze B2, PostHog EU, AWS Bedrock eu-central-1), and the United States (Stripe, OpenAI, Anthropic), among locations listed on Subprocessors.

Where transfers require safeguards under GDPR or UK GDPR, Techlyft Pty Ltd relies on the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or other mechanisms recognized under applicable law.

Assistance & audits

Taking into account the nature of processing, Techlyft Pty Ltd will assist Customer with data subject requests and regulatory inquiries by appropriate technical and organizational measures. We will forward any data subject request we receive directly to Customer without responding to the requester unless required by law.

Upon written request no more than once per 12-month period, we will provide responses to a reasonable security questionnaire or our latest security documentation. On-site audits are not available; audit obligations are satisfied through these materials and the information on our Security pages.

Breach notification

Techlyft Pty Ltd will notify Customer without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known: the nature of the incident, categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, and a point of contact. Notification is not an admission of fault or liability.

Data return & deletion

During the term. Customer may export Customer Personal Data during the subscription using product capabilities or by written request to [email protected].

After termination. Customer may request export for up to 30 days after termination. Customer Personal Data is deleted from active systems within 90 days after termination unless Customer instructs earlier deletion or law requires retention. Backup copies are deleted within 365 days on a rolling basis, subject to legal holds.

Techlyft Pty Ltd may retain Customer Personal Data as required by law or to establish, exercise, or defend legal claims; processing will be limited to those purposes.

Liability

Liability under this DPA follows the limitation of liability in the Terms of Service, unless applicable law requires otherwise. Each party remains liable for damages caused by processing that violates this DPA or applicable data protection law.

How to execute a signed DPA

This web page summarizes our processor commitments. Workspaces that need a countersigned DPA for procurement should contact [email protected] or [email protected]. Accepting the Terms of Service constitutes acceptance of this DPA for processor activities unless a separate signed agreement is executed.

Contact

Questions about this DPA, or requests for a signed copy, can be sent to [email protected].

Related documents

This document should be read together with our other legal documents, including:

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Subprocessors
  • Security
  • Security FAQ

Company details

DeskNova is operated by Techlyft Pty Ltd, a company incorporated in Australia (ABN 32 635 864 970), with its registered office at Sydney, NSW, Australia.

Legal and privacy notices: [email protected]

DeskNova

The support desk with Nova for customers and Copilot for your team — both grounded in your docs.

Product

Omnichannel inboxNovaCopilotKnowledge basePricing

Solutions

StartupsE-commerceSaaSEnterprise

Resources

DocsChangelogStatusCommunity

Company

AboutCareersBlogContact
© 2026 Techlyft Pty Ltd. All rights reserved. Legal Privacy Terms Security DPA