Data Retention Policy for Zendesk
Data retention
A retention policy will define how long a ticket is allowed to remain in Zendesk. After the retention time has passed, the ticket will be permanently deleted. By implementing a retention policy in Zendesk we make sure to follow the rules of GDPR by not keeping information longer than necessary. There must be retention times set for all data in Zendesk as personal data cannot be kept indefinitely according to GDPR guidelines. The retention times should reflect our legitimate and concrete need to keep the data. Retention based on nice-to-have is not acceptable.
What is being deleted?
Tickets are the objects being deleted in Zendesk. The Data Retention Policy will cover all patient, potential patient, clinician and business employee data held in Zendesk.
Information in a ticket can include the following information.
- Personal information (address, name, location) mentioned in the ticket’s subject, description
- Tickets events which are actions/updates done to the ticket and includes the requester´s browser, location, ip address and updates of the tickets.
- Attachments
- Name
- Phone number
- Location
- IP address
- Tags (information about the ticket)
- Native ticket fields
- Custom ticket fields
- Assignee/Agent handling the ticket
- CC
- Event (all updates/actions done to the ticket)
- Followers (Anyone tagged in a ticket in Zendesk)
- Side Conversations (Anyone tagged outside of Zendesk)
How is it deleted?
Tickets are deleted via an automation platform called Make. There are no ways to recover deleted tickets once deleted via these automation workflows. The only exception is before these deleted tickets reach the 30 day period after initial deletion in which it may be possible to recover if we reach out to Zendesk. After 90 days, these tickets cannot be retrieved by even Zendesk. The time period before a ticket will be deleted will depend on the brand in which the ticket was created. Brand is the end user-facing Zendesk landing page. Depending on the topic you can create different brands (landing pages) and steer the end-user to a specific brand.
Some markets like the UK have multiple brands while others such as Norway have one brand.
Retention times
| Brand | Support Groups | Retention Time |
| Sweden Operation Support |
|
3 years |
| Kry Support Norge |
|
3 years |
|
Livi UK UK Clinician Support UK Support Diagnostics UK Vitality |
|
6 years |
Centre d'aide aux médecinsLivi France |
|
5 years |
| Kry [Sweden] |
|
3 years |
| IT Support |
|
5 years |
| Ask Finance |
|
3 years |
| People and Culture |
|
3 years |
Reasoning for retention time
The differences in retention time between our Zendesk brands depend on the support services offered and legal requirements for each specific market. Support services may involve providing guidance, answering questions, offering technical assistance, resolving problems, improving service offerings, referencing historical tickets to aid in resolving current inquiries, and addressing inquiries related to products or services.
| Brand | Reasoning | Retention time |
| Sweden Operation Support | Necessary to fulfill the purpose of support services and improvements. | 3 years |
| Kry Support Norge | Necessary to fulfill the purpose of support services. | 3 years |
|
Livi UK UK Clinician Support UK Support Diagnostics UK Vitality |
Necessary to fulfill the purpose of providing support services and maintaining evidence according to the NHS guidelines. | 6 years |
Centre d'aide aux médecinsLivi France |
Necessary to fulfill the purpose of support services and maintaining evidence according to the common law limitation period. |
5 years |
| Kry [Sweden] | Necessary to fulfill the purpose of support services. | 3 years |
| IT Support | Necessary to fulfill support services that can crossover to other markets/brands. | 5 years |
| Ask Finance | Necessary to fulfill the purpose of support services. | 3 years |
| People and Culture | Necessary to fulfill the purpose of support services. | 3 years |
Legal team contact details
If you have questions, identify an issue or struggle to comply with these guidelines for a use case, please reach out to Ask Legal channel in Teams.
Comments
0 comments
Please sign in to leave a comment.