Zendesk App Data Privacy Policy
Scope
This policy explains how data is handled when you install and use apps published by L5.ai LLC ("L5," "we," "us") on the Zendesk Marketplace. It applies to every L5 app on the Marketplace, current and future, unless a specific app's listing states otherwise.
This policy covers the data our apps access inside your Zendesk account and the limited information L5 receives when you install an app or contact us for support. For how L5 handles other personal information, such as when you visit our website, see our general Privacy Notice at l5.ai/privacy-policy.
How our apps handle your data
Every L5 Marketplace app is built on the Zendesk Apps Framework (ZAF) and runs inside your own Zendesk account. Each app calls Zendesk's own APIs on your Zendesk subdomain to read and write the specific ticket, user, organization, or custom object data described in its Marketplace listing, only for the purpose of delivering the features that listing describes.
L5 does not operate servers that receive, process, or store your Zendesk data. Ticket content, customer information, and account data are not sent to L5 or to L5-operated infrastructure. Data an app reads or writes stays inside your Zendesk account, under your own data controls and retention settings. Our apps contain no analytics, tracking, or advertising code.
Where an app needs to exchange data with a system outside Zendesk to deliver a feature, that is stated in the app's Marketplace listing and in its in-app configuration before you enable it, together with the destination and the data involved. You control whether that feature is enabled.
Artificial intelligence and model training
L5 does not use your Zendesk data to train, fine-tune, or evaluate any machine learning model.
Where an app offers a feature that relies on a third-party AI service, that is stated in the app's Marketplace listing, the service is named, and the feature requires you to enable it and to supply your own credentials for that service. Data sent to such a service is governed by your agreement with that provider. No AI feature is enabled by default.
Optional components you run yourself
Some apps offer an optional companion script or scheduled job, for example to sync data between Zendesk and another system you already use. Where offered, this component runs in an environment you control, using credentials you generate and manage yourself. L5 does not host, operate, or have access to this component or any data it processes.
Installation and support information
Zendesk may share limited account and installation information with us as the app's developer, such as your subdomain or plan tier, to support Marketplace operations including billing and support. We also receive whatever you send us when you contact us directly for support.
This is the only customer information L5 holds. We use it to provide support, administer billing, and meet our legal obligations. We retain it for three years after your last interaction with us, or longer where the law requires.
Data retention and deletion
Your Zendesk data stays in your Zendesk account, so retention and deletion of that data are controlled entirely by you through Zendesk's own data management settings. Uninstalling an app removes its access to your account. Records an app created in your account, such as custom objects, remain there until you delete them.
For the installation and support information L5 holds, see the retention period above. You can request deletion using the contact details below.
Security
L5 maintains an ISO 27001 certified information security management system and undergoes annual SOC 2 Type II examination. Details of certification and report scope, and copies under non-disclosure agreement, are available on request at solutions@l5.ai.
Because our apps process data inside your Zendesk account rather than on L5 infrastructure, the controls governing that data are your own Zendesk account settings and Zendesk's platform security.
To report a suspected vulnerability in an L5 app, contact solutions@l5.ai. We acknowledge reports within three business days and will keep you informed while we investigate.
If we become aware of a security incident affecting the installation or support information we hold about you, we will notify affected customers without undue delay and no later than 72 hours after confirming the incident and will provide what we know about its scope and our response.
Sharing with third parties
Our apps do not send your Zendesk data to L5 or to any third party, so there is no app data for us to share. We do not sell personal information and do not share it for advertising or direct marketing.
The installation details and support correspondence we receive are shared only with service providers we use to run our business, such as email and collaboration tools, under contracts that limit how they may use it. A current list of these service providers is available on request at solutions@l5.ai.
This information may transfer to a successor if L5 is involved in a merger, acquisition, or sale of assets, and we may disclose it where the law requires.
Your rights and choices
You can review, restrict, or remove any app's access at any time from your Zendesk admin settings.
For the installation and support information L5 holds, you can ask us to provide a copy, correct it, delete it, or restrict how we use it. Contact us at solutions@l5.ai. Depending on where you live, you may also have the right to complain to your data protection authority.
For customers who need one, a data processing agreement is available on request at solutions@l5.ai.
Contact
Questions about this policy or about a specific app: solutions@l5.ai
Security reports: solutions@l5.ai
L5.ai LLC
8370 Seneca Pointe, Eden Prairie, MN 55347
Changes to this policy
We may update this policy as our apps evolve. The date at the top shows when it was last revised. For changes that materially affect how data is handled, we will post the updated policy at least 30 days before it takes effect.