emploidai Marketplace

Zendesk Advanced Ticket Tools privacy policy

Policy content supplied in the product package by its publisher.

← Back to Zendesk Advanced Ticket Tools

Privacy Policy

Data processed

The plugin sends the configured Zendesk subdomain, agent email, and API token only to the configured Zendesk tenant for authentication. During tool use, it may process ticket metadata, requester details, comments, Messaging events, tags, Help Center articles, views, and ticket attachments that the configured Zendesk account is permitted to access.

Purpose and destination

Data is processed only to perform the selected Zendesk Support API operation. Requests start at https://{subdomain}.zendesk.com. Attachment retrieval may follow a Zendesk tenant-issued HTTPS redirect to signed storage; those redirected requests omit Zendesk Basic Auth. The plugin does not send ticket data or credentials to a separate analytics, telemetry, MCP, or browser-relay service. Zendesk processes data under its Privacy Notice.

Storage and access

Credential storage, workspace authorization, and audit controls are provided by Dify. The plugin source does not persist credentials, ticket content, or attachments. Access is limited by the Zendesk permissions of the configured agent and by Dify credential authorization.

Retention

The plugin retains no data after an invocation completes. Zendesk and Dify may retain data according to their own configuration and policies.

Security notes

Attachment downloads start only from an HTTPS URL on the configured Zendesk subdomain. A tenant-issued redirect may continue to an HTTPS host only when every resolved address is globally routable; redirected requests omit Zendesk Basic Auth and are capped at three redirects and 20 MiB. All ticket-changing operations require an explicit confirm=true parameter.