Privacy & GDPR
How Mojo Helpdesk protects customer data and supports your privacy and compliance obligations.
Security & Privacy
Protecting customer data is a core part of how Mojo Helpdesk is designed and operated. We implement administrative, technical, and organizational safeguards to protect Personal Data and help customers meet their compliance obligations.
Data Processing
When providing the Services, Metadot processes Personal Data solely on behalf of its customers and only as necessary to provide, support, secure, and maintain Mojo Helpdesk.
Customers remain the Controller of their data. Metadot acts as the Processor.
Our processing practices are governed by our Data Processing Agreement (DPA), which is incorporated into our Terms of Service.
Security Controls
Mojo Helpdesk maintains security measures appropriate to the nature of the Services and the risks associated with processing Personal Data, including:
- Access controls and authentication
- Encryption of data in transit and, where appropriate, at rest
- Logging and monitoring
- Vulnerability management and security patching
- Backup and disaster recovery procedures
- Regular evaluation of security controls
Mojo Helpdesk is hosted on Amazon Web Services (AWS).
Compliance
Mojo Helpdesk supports customer compliance with applicable privacy laws, including, where applicable:
- GDPR
- UK GDPR
- Swiss Federal Act on Data Protection
- Applicable U.S. federal and state privacy laws
Metadot also maintains an independent SOC 2 Type II examination covering the security of the Mojo Helpdesk platform. A current attestation letter is available upon reasonable request.
HIPAA
Customers requiring HIPAA support may request a Business Associate Agreement (BAA) as part of an Enterprise subscription.
International Data Transfers
Where Personal Data is transferred internationally, Metadot uses appropriate transfer mechanisms required by applicable data protection laws, including the European Commission's Standard Contractual Clauses (where applicable).
Subprocessors
Metadot uses carefully selected subprocessors to deliver and support the Services. Each subprocessor is contractually required to protect Personal Data at a level substantially equivalent to our obligations under our DPA.
A current list of subprocessors is available upon reasonable request.
Data Retention
After termination of the Services, Customer Data remains available for 30 days to allow export. After that period, Customer Data is securely deleted unless retention is required by law. Customers may also request earlier deletion in writing.
AI Privacy
Felix AI is designed with customer privacy in mind.
- Customer data remains within your helpdesk environment.
- Data is not shared across customer instances.
- Customer content is not used to train external AI models.
Resources
- Data Processing Agreement
- Privacy Policy
- Terms of Service
- SOC 2 Attestation (available upon request)
- Business Associate Agreement (Enterprise customers)
If you have any questions about our privacy and security practices, please contact us.