Privacy Policy
How we collect, use, and protect your personal data.
Last updated: July 25, 2026
1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Fesk e.U.
Owner: Timo-Nicklas Goiss
Mariahilfer Straße 136, 1150 Vienna, Austria
Email: support@fesk.io
Full company details are available in our Legal Notice. Please direct privacy inquiries to support@fesk.io.
2. Information We Collect
We collect information you provide directly to us, including:
- Account registration details (name, email address, organization name)
- Support ticket content and attachments
- Billing and payment information (processed securely via Stripe)
- Communications with our support team
We also automatically collect usage data such as IP addresses, browser type, pages visited, and feature usage patterns.
3. Purposes and Legal Bases for Processing
We process personal data only on a valid legal basis under Art. 6 GDPR:
- Providing and operating the Service and performing contracts, contract performance (Art. 6(1)(b))
- Billing and payment notifications: contract performance and legal obligation (Art. 6(1)(b) and (c))
- Improving the Service, security, fraud and abuse prevention: legitimate interest (Art. 6(1)(f))
- Service-related communications and updates: contract performance or legitimate interest
- Marketing communications: where applicable, only based on your consent (Art. 6(1)(a))
- Meeting statutory retention and disclosure duties: legal obligation (Art. 6(1)(c))
4. Data Sharing and Recipients
We do not sell your personal data. A full recipient overview structured by data protection role (our sub-processors, independent controllers for single sign-on, integrations initiated by you, and device platform services) is set out in section 8 of our GDPR page. In summary:
- Sub-processors who assist in operating our platform: Amazon Web Services (hosting, operation, authentication) and Stripe (payment processing)
- External identity providers (Google, Microsoft) where you use single sign-on; these act as independent controllers
- Integrations you configure (connected email mailboxes, connectors such as Slack, webhooks, REST endpoints), for which you remain the controller
- Authorities and law enforcement when required by applicable law
- Third parties in connection with a merger, acquisition, or sale of assets
5. International Data Transfers
Your primary workspace data is processed in the region you select at registration. Depending on the region, this may involve a transfer outside the European Economic Area; payment processing by Stripe may involve a transfer to the USA. We rely on appropriate safeguards under Chapter V GDPR for such transfers: for regions with an adequacy decision, on that decision (such as the EU-US Data Privacy Framework); for regions without an adequacy decision, on the EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by technical and organizational measures. Which region is subject to which instrument is set out in section 6 of our GDPR page, where you can also restrict your workspace to the EEA. A copy of the safeguards is available on request at support@fesk.io.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. After account deletion, personal data is removed from or anonymized in production systems within 30 days, unless retention is required by law. Backup copies are retained on a rolling basis for up to a further 30 days and are then automatically overwritten or deleted. They are used only for recovery and security purposes; if a backup is restored, previously requested deletions are applied again. In particular, billing records and invoices are retained for seven years in accordance with Austrian tax and commercial law (§ 132 BAO, § 212 UGB). Aggregated, non-personal usage data may be retained indefinitely for analytical purposes.
7. Security
We use security measures such as encryption in transit (TLS 1.2+), encryption at rest, access controls, and regular security reviews based on recognized web application standards. For more details, see our Security page.
8. Obligation to Provide Data
Providing certain data (such as your name, email address, and billing details) is necessary to conclude and perform the usage contract. Without this data we cannot provide the Service. Providing any further data is voluntary.
9. Automated Decisions and AI Features
If an account administrator configures AI workflow steps to act autonomously, our platform may take certain actions automatically (e.g. closing tickets or sending replies). Whether this constitutes an automated decision in an individual case within the meaning of Art. 22 GDPR depends on the degree of autonomy; the tiers (mere assistance, semi-autonomous execution with review, autonomous execution with significant effect) are described in section 9 of our GDPR page. Human safeguards are in place: actions can be reviewed, reverted, and stopped immediately via a kill switch; AI acts autonomously only where explicitly configured, and steps can be set so that every action requires human approval. AI processing takes place within the deployment region selected for your workspace. Your ticket and knowledge-base data is not passed to an external AI provider or any other third party and is not used to train models. Where a solely automated decision within the meaning of Art. 22 GDPR exists, you have the right to contest it, to express your point of view, and to obtain human intervention.
10. Storage of Information on Your Device
We access your device only insofar as strictly necessary for the service you have expressly requested (§ 165(3) Austrian Telecommunications Act 2021). No consent is required for this, and we do not use a cookie banner. On our public pages, no cookies are set before you sign in.
After you sign in, we use:
- a session cookie for authentication and a token for CSRF protection (each lasting the session or until you sign out)
- local storage entries for your interface preferences (theme, language, time zone, view and filter settings, most recently used workspace); these remain on your device and are not transmitted to us
- when you use the installable app (PWA), a local cache for offline operation
- when you enable push notifications, a push subscription of your browser
In the billing area, our payment provider Stripe includes its own identifiers required for fraud prevention; details are in Stripe's privacy policy. We do not use tracking, analytics, or marketing technologies and do not embed external fonts, scripts, or content delivery networks. Should we use non-strictly-necessary technologies in the future, we will obtain your consent beforehand. On shared devices we recommend signing out and, if the app is installed, clearing local storage.
11. Your Rights
Depending on applicable law, you have the right to access, rectify, erase, restrict, and port your personal data, as well as to object and to withdraw consent. For details on your data subject rights under the GDPR, see our GDPR/Data Protection page.
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Austrian Data Protection Authority (Datenschutzbehörde)
Barichgasse 40–42, 1030 Vienna, Austria
Web: dsb.gv.at
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date above.
14. Contact Us
If you have questions about this Privacy Policy, please contact our support team or email support@fesk.io.
For data protection and security matters, you can also reach us at security@fesk.io.