GDPR & Data Protection
Your data subject rights and how we process your data.
Last updated: July 25, 2026
1. Our Commitment to GDPR
Fesk e.U. is committed to compliance with the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). We process personal data lawfully, fairly, and transparently.
2. Controller and Allocation of Roles
The controller for account and billing data is:
Fesk e.U., owner Timo-Nicklas Goiss Mariahilfer Straße 136, 1150 Vienna, Austria Email: support@fesk.io · Legal Notice
For data within support tickets, Fesk acts as a processor on behalf of our customers (the respective controllers). For business customers we provide a Data Processing Agreement (DPA) under Art. 28 GDPR: view the full DPA here or accept it in your account settings.
3. Legal Basis for Processing
We process personal data under the following legal bases:
- Contract performance (Art. 6(1)(b)): to provide the services you have subscribed to
- Legitimate interest (Art. 6(1)(f)): to improve our services, prevent fraud, and ensure security
- Legal obligation (Art. 6(1)(c)): to comply with applicable laws and regulations
- Consent (Art. 6(1)(a)): where explicitly provided, such as for marketing communications
4. Your Data Subject Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15): request a copy of the personal data we hold about you
- Right to rectification (Art. 16): request correction of inaccurate personal data
- Right to erasure (Art. 17): request deletion of your personal data ("right to be forgotten")
- Right to restrict processing (Art. 18)
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)): withdraw consent at any time where processing is based on consent
To exercise your rights, an informal message to support@fesk.io is sufficient. If you are a user within a customer workspace, please first contact the relevant controller (your workspace operator).
5. Data Processing Details
We process the following categories of personal data:
- Identity data (name, email address, organization)
- Account data (login credentials, preferences, role assignments)
- Support ticket data (ticket content, attachments, comments)
- Billing data (subscription details, payment method identifiers via Stripe)
- Usage data (feature usage, access logs, IP addresses)
6. International Data Transfers
At registration you select the deployment region of your workspace. Your primary workspace data is processed in that region by Amazon Web Services; payment processing by Stripe may involve a transfer to the USA. The transfer instrument depends on the region you select:
| Group | Regions | Transfer instrument | |---|---|---| | European Economic Area | EU West (Ireland), EU Central (Frankfurt), EU North (Stockholm), EU South (Milan) | no third-country transfer | | Third country with adequacy decision | United Kingdom, Switzerland, Canada, Japan, South Korea | EU Commission adequacy decision | | Third country without adequacy decision | USA, Brazil, Mexico, Singapore, Australia, Indonesia, Malaysia, India, Hong Kong, Bahrain, UAE, South Africa | Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by technical and organizational measures; for the USA additionally the EU-US Data Privacy Framework where the recipient is certified |
If you are a controller, you need your own Transfer Impact Assessment for regions without an adequacy decision; we provide the information required for this on request. You can restrict your workspace to regions within the EEA. A copy of the safeguards is available on request at support@fesk.io.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Account data is processed during the active contractual relationship and is removed from or anonymized in production systems within 30 days after account deletion. Backup copies may remain for up to a further 30 days in the rolling backup cycle and are then automatically overwritten or deleted. Billing records are retained as required by tax and commercial-law regulations (in Austria, typically 7 years).
8. Recipients and Roles
We do not sell your data. Recipients and their data protection role are structured as follows:
A. Our sub-processors (process on our behalf)
- Amazon Web Services EMEA SARL, Luxembourg — hosting, storage, operation, email delivery, and authentication (including Cognito Hosted UI); processing takes place in the region you select
- Stripe Payments Europe, Ltd., Ireland — payment processing
B. Independent controllers (only with single sign-on)
- Google Ireland Ltd. or Microsoft Ireland Operations Ltd. — only if you sign in through their account; the processing there is governed by the respective provider's privacy policy
C. Integrations initiated by you (you remain the controller)
- your email provider (Gmail, Microsoft 365, or your own IMAP/SMTP server) and connector destinations (Slack, webhooks, REST endpoints) that you configure; the choice and legal basis are yours
D. Device platform services
- the push delivery services of the browser used by your users, where push notifications are enabled
Authorities and law-enforcement bodies receive data only where required by law; third parties in connection with a merger, acquisition, or sale of assets.
9. Automated Decisions in Individual Cases
Not every AI-assisted function constitutes an automated decision in an individual case within the meaning of Art. 22 GDPR. We distinguish:
- Assistance without legal effect: the AI only suggests (e.g. reply drafts, categorization) and a human decides. This is not a decision under Art. 22 GDPR.
- Semi-autonomous execution with review: the step executes itself, but the action is recorded in the audit queue and can be reviewed and reverted.
- Autonomous execution with significant effect: where a workflow, without human involvement, makes a decision producing legal effects or similarly significant effects, a decision under Art. 22 GDPR may exist. In that case we provide additional information on the logic involved, the significant criteria, and the significance.
AI processing takes place within the deployment region selected for your workspace. Your ticket and knowledge-base data is processed solely to answer the respective request, is not passed to an external AI provider or any other third party, and is not used to train models. Effective safeguards are in place: human approval for steps configured to only suggest, a review and revert mechanism (audit queue), and a kill switch. Where a decision under Art. 22 GDPR exists, you have the right to obtain human intervention, to express your point of view, and to contest the decision.
10. Data Protection Contact
For data protection inquiries or to exercise your rights, contact us at:
- Email: security@fesk.io
11. Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Austrian Data Protection Authority (Datenschutzbehörde) Barichgasse 40–42, 1030 Vienna, Austria Web: dsb.gv.at