Last Updated: July 1, 2026. For enterprise customers who require a signed DPA for GDPR and global data compliance. This document outlines Desk Simplified’s obligations as your Data Processor.
Request Signed DPAUnder GDPR, India’s Digital Personal Data Protection Act (DPDPA), and equivalent global data protection laws:
Data Controller — the Customer (the organization that subscribes to DS Workspace). You determine the purposes and means by which Personal Data is processed.
Data Processor — Desk Simplified. We process Personal Data strictly on your documented instructions and for no other purpose.
Personal Data — any information relating to an identified or identifiable natural person, including employee records, contact data, and behavioral data processed within the platform.
Desk Simplified processes Customer Data only to the extent necessary to deliver the contracted services. Specifically:
DS Workspace: We process HR records, employee attendance and leave data, project data, task assignments, documents, expense claims, and form submissions to power the DS Workspace operations platform.
We will never use your Customer Data to train AI models, for cross-customer analytics, or for any purpose outside of delivering your contracted services. We will process data in accordance with your instructions and will promptly notify you if, in our opinion, an instruction infringes applicable data protection law.
Desk Simplified maintains the following technical and organizational security measures:
Encryption: All data is encrypted at rest (AES-256 via Neon PostgreSQL) and in transit (TLS 1.2+ enforced by Cloudflare).
Access Control: Access to Customer Data is governed by a strict Role-Based Access Control (RBAC) system with the principle of least privilege. Internal Desk Simplified team access to production data is restricted and logged.
Edge Security: All web traffic is proxied through Cloudflare, providing DDoS protection, WAF rules, and bot mitigation before requests reach our infrastructure.
Backups: Automated daily database backups with point-in-time recovery. Backup data is encrypted and stored in geographically separate locations.
You authorize Desk Simplified to engage the following sub-processors to deliver the service. All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security standards.
Cloudflare — CDN, edge security, DDoS protection, WAF. Processes inbound web traffic at the network edge. Incorporated in the USA; edge nodes are globally distributed including Singapore. (Global / USA-incorporated)
Neon — Managed serverless PostgreSQL. Stores all primary Customer Data. Our Neon database is provisioned in the ap-southeast-1 (Singapore) region. Data does not leave this region. (Singapore)
Amazon Web Services (AWS) — Object storage (S3) for file uploads, documents, and form attachments. Our S3 bucket is provisioned in the ap-southeast-1 (Singapore) region. Data does not leave this region. (Singapore)
Stripe — Payment processing for international customers. Processes billing and subscription data only; no Customer workspace data. (USA)
Razorpay — Payment processing for Indian customers. Processes billing, UPI, and card data only; no Customer workspace data. (India)
We will notify you of any material changes to this sub-processor list with at least 30 days’ notice.
All primary Customer Data — database records and file attachments — is stored and processed exclusively in Singapore (ap-southeast-1).
Inbound web traffic passes through Cloudflare’s global edge network (a US-incorporated entity) as part of DDoS protection and WAF processing. Payment data is processed by Stripe (USA) and Razorpay (India) as applicable, but neither processor receives or stores your workspace data.
For transfers of Personal Data from the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) as the legal transfer mechanism with sub-processors established outside the EEA. All sub-processors maintain their own transfer mechanisms and data protection certifications appropriate to their jurisdictions.
In the event of a confirmed personal data breach affecting Customer Data, Desk Simplified will notify the Controller without undue delay, and no later than 72 hours after becoming aware of the incident, in compliance with GDPR Article 33.
The breach notification will include: (a) a description of the nature of the breach; (b) the categories and approximate volume of data subjects and records affected; (c) the likely consequences; and (d) the measures taken or proposed to address the breach.
Security incidents should be reported — report it here.
Upon termination of the service agreement or a verified deletion request, Desk Simplified will delete or anonymize all Customer Data within 30 days, except where retention is required by applicable law (e.g., billing records for tax compliance, retained for 7 years). Backup copies are purged within 90 days.
To request a signed DPA or to exercise your data deletion rights, contact us here.