MyRemotingMyRemoting
← All legal documents

I Own Software LLC — MyRemoting Data Processing Addendum

Version 2026.07

Last updated: July 10, 2026

This Data Processing Addendum governs I Own Software LLC's processing of personal data as a processor on behalf of its customers in connection with the MyRemoting Hosted Service, and is incorporated into and forms part of the MyRemoting Usage and License Agreement. It sets out the parties' respective data-protection obligations under the EU and UK GDPR, the California CCPA/CPRA, the Utah Consumer Privacy Act, and other applicable privacy laws.


1. Preamble and Incorporation

1.1 This Data Processing Addendum (this "DPA") forms part of, and is incorporated by reference into, the MyRemoting Usage and License Agreement, version 2026.07, between I Own Software LLC, a Utah limited liability company having its principal place of business at 321 N Mall Dr, Suite R259, Saint George, UT 84790, USA ("Vendor," "we," "us"), and the entity that licenses or subscribes to the Software ("Customer") (as amended from time to time, the "Agreement"). Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.

1.2 This DPA applies only where and to the extent Vendor processes Personal Data as a processor (or, under the CCPA/CPRA, as a service provider or contractor) on behalf of Customer in connection with the Hosted Service — that is, the SaaS deployment in which Vendor operates the Control Server (mr-control) for Customer. This DPA does not apply to Self-Hosted / On-Premises deployments, which are addressed in Section 4 (Deployment Models and Roles Summary) and in the Privacy Policy.

1.3 This DPA is published at myremoting.iownsoftware.com/legal/dpa. The Vendor Privacy Policy, published at myremoting.iownsoftware.com/legal/privacy, is incorporated into the Agreement by reference and governs the Personal Data for which Vendor acts as an independent controller (including Vendor's website, billing, license administration, and support data, and the Heartbeat Metadata received from all deployments).

1.4 To the extent this DPA conflicts with any other term of the Agreement with respect to the processing of Personal Data in the Hosted Service, this DPA controls. In all other respects the Agreement remains in full force and effect. Each party's liability under or in connection with this DPA is subject to, and counts toward, the exclusions and aggregate limitation of liability set out in Article 7 of the Agreement.

2. Definitions

2.1 For purposes of this DPA:

2.2 The defined terms "Software," "Control Server," "Agent," "Endpoint," "Operator," "End User," "Customer," "Hosted Service," "On-Premises"/"Self-Hosted," "Licensing Service," and "Heartbeat Metadata," to the extent used in this DPA, have the meanings given to them in the Agreement and are used consistently in this DPA.

3. Roles of the Parties (Hosted Service)

3.1 General allocation. With respect to the Processing of Personal Data in the Hosted Service:

3.2 Customer as processor; Vendor as sub-processor. Where Customer itself acts as a processor of Personal Data on behalf of its own customers or other third-party controllers (for example, where Customer is a managed-service provider using the Hosted Service to service its clients' Endpoints), then, as between the parties, Customer is the processor and Vendor is the sub-processor. In that case, Customer's instructions to Vendor are deemed to reflect the instructions of the relevant third-party controller, and Customer represents that it has the authority and any required authorization to engage Vendor as a sub-processor and to give the instructions contemplated by this DPA. References in this DPA to Customer's obligations as Controller apply, with necessary modifications, to Customer in its capacity as processor.

3.3 Vendor's own controller activities. Vendor also processes certain Personal Data as an independent Controller for its own purposes — including website/analytics data, Customer account and billing-contact data, limited payment metadata, License administration (Heartbeat Metadata) received from all deployments, and support communications. That Processing is not governed by this DPA and is instead described in the Privacy Policy. Nothing in this DPA makes Vendor a processor with respect to that data.

3.4 Instructions. Customer's complete and final instructions for the Processing of Personal Data in the Hosted Service are set out in the Agreement, this DPA (including Annex I), and Customer's configuration and use of the Software (for example, enabling or disabling session recording). Additional instructions must be agreed in writing and are subject to Vendor's applicable fees where they exceed the scope of the agreed Hosted Service.

4. Deployment Models and Roles Summary

4.1 The data-protection roles differ by deployment model, as summarized below. Where the summary and the operative text conflict, the operative text (Sections 3, 4.2, and 5 and the Privacy Policy) controls.

Deployment modelWho runs the Control ServerData held in / flowing through the Control ServerVendor's role for that dataGoverning document
Hosted Service (SaaS)VendorOperator, Endpoint, session, connection, and credential-blob Personal DataProcessor / service provider on Customer's instructions (Customer is Controller, or Customer is processor and Vendor sub-processor)This DPA
Self-Hosted / On-PremisesCustomerEndpoint inventory, audit logs, session recordings, agent-encrypted credential blobs — held solely by Customer; not hosted, accessed, or received by VendorIndependent Controller of the Heartbeat Metadata (deployment identity, Software version, counts) and any opt-in support telemetry it receives, used to validate licenses, enforce the Agreement, and provide support — not Customer's processorPrivacy Policy

4.2 Self-Hosted deployments. In a Self-Hosted / On-Premises deployment, Customer runs the Control Server on its own infrastructure and is the sole Controller of all data it holds. Vendor does not host, access, or receive that data. The only data that flows to Vendor is Heartbeat Metadata, plus any support telemetry Customer affirmatively enables, which Vendor processes as an independent Controller as described in the Privacy Policy. Accordingly, this DPA's processor obligations do not apply to Self-Hosted deployments, and each Section of this DPA is to be read as limited to the Hosted Service.

5. Scope of this DPA

5.1 This DPA governs the Hosted Service only. It sets out the parties' respective obligations with respect to Vendor's Processing of Personal Data as a Processor/service provider on Customer's documented instructions. It does not apply to Personal Data that Vendor processes as its own Controller (website, Customer account and billing contacts, payment metadata, license administration, and support communications), which is governed by the Privacy Policy.

5.2 This DPA takes effect on the effective date of the Agreement (or, if later, the date Customer accepts this DPA) and remains in effect for as long as Vendor processes Personal Data in the Hosted Service on Customer's behalf, subject to the survival of any provisions that by their nature should survive.

6. Subject Matter, Duration, Nature, and Purpose of Processing

6.1 Subject matter. The subject matter of the Processing is Vendor's provision of the Hosted Service to Customer under the Agreement — namely operating the Control Server to broker remote-access and remote-monitoring-and-management ("RMM") connections to Customer's Endpoints and to store the associated inventory, audit logs, session recordings (when enabled), and agent-encrypted credential blobs on Customer's behalf.

6.2 Duration. The Processing continues for the term of Customer's Hosted Service subscription and for any post-termination period during which Vendor retains Personal Data to permit Customer to retrieve it and pending its deletion or return in accordance with the Agreement and Section 16 (Return and Deletion) — a period of up to 30 days after termination or expiry — unless a longer retention is required by applicable law.

6.3 Nature of the Processing. The nature of the Processing consists of the operations necessary to provide the Hosted Service, which may include collecting, recording, organizing, structuring, storing, transmitting, brokering, displaying, retrieving, using, disclosing to authorized Operators and Sub-processors, restricting, erasing, and destroying Personal Data by automated means.

6.4 Purpose of the Processing. The purpose of the Processing is limited to providing, maintaining, securing, and supporting the remote-access/RMM Hosted Service for Customer in accordance with Customer's documented instructions and the Agreement — including authenticating Operators, brokering live remote viewing and control sessions, capturing session recordings and audit logs where Customer enables them, storing Endpoint inventory and opaque credential blobs, and delivering transactional notifications. Vendor does not process Personal Data for its own independent purposes.

7. Categories of Data Subjects and Personal Data

7.1 The categories of data subjects and categories of Personal Data are summarized below and described in more detail in Annex I.

7.2 Categories of data subjects. (a) Customer's Operators; (b) Customer's personnel and other authorized users of the Control Server; and (c) End Users of the Endpoints managed through the Hosted Service.

7.3 Categories of Personal Data. (a) Operator account data — name, email, hashed password, TOTP two-factor secret, role/permission assignments, login/audit events, IP addresses; (b) Endpoint inventory — hostname, operating system, hardware/software/network/GPU details, logged-in usernames, security-posture signals; (c) session data — transient live screen frames, optional session recordings (when enabled by Customer), append-only session audit logs, and in-session chat; (d) agent-encrypted credential blobs; and (e) connection metadata — source IP addresses, timestamps, device identifiers.

7.4 Special-category and sensitive data. The Hosted Service is not designed or intended to process special categories of personal data (GDPR Article 9) or "sensitive personal information" (CCPA/CPRA), and Customer is responsible for its and its Operators' and End Users' use of the Software. Because the Software captures live screen content, session recordings, and file/console access at Customer's direction, such data may nonetheless be present in session data depending on Customer's configuration and use; any such Processing occurs on Customer's instructions, and Customer is responsible for determining the lawfulness of that use and for providing any required notices and obtaining any required consents. Any such Personal Data present in session data is subject to the technical and organizational measures described in Annex II.

8. Agent-Encrypted Credential Blobs

8.1 Endpoint credentials that an Operator elects to save are encrypted per-Operator by the Agent before storage. The Control Server stores only opaque ciphertext that Vendor cannot decrypt or read. Accordingly, Vendor processes these credential blobs solely as stored ciphertext and has no access to the underlying credentials. This limitation is technical, not merely contractual, and Customer acknowledges that Vendor therefore cannot retrieve, disclose, or act on the plaintext of such credentials (including in response to a data-subject request or lawful-access demand directed to Vendor).

9. Processing on Documented Instructions

9.1 Instructions. Vendor processes Personal Data only on Customer's documented instructions, including with respect to transfers of Personal Data to a third country, unless required to process by applicable law to which Vendor is subject; in that case, Vendor will inform Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.

9.2 Scope of documented instructions. Customer's documented instructions comprise (a) this DPA; (b) the Agreement; and (c) Customer's configuration and use of the Software (including its provisioning of Operators and their roles/permissions, its enablement of features such as session recording, its enabled Sub-processors and regions to the extent selectable, and the settings Customer applies), together with any additional written instructions Customer gives that the parties agree in writing. Processing necessary to provide, secure, and support the Hosted Service, to comply with Vendor's own legal obligations as processor, and to enforce the Agreement is deemed to be within Customer's instructions.

9.3 CCPA/CPRA and UCPA use limitation. Vendor will not (a) sell or share Personal Data (as "sale" and "sharing" are defined under the CCPA/CPRA); (b) retain, use, or disclose Personal Data for any purpose other than the specific purpose of performing the Hosted Service, or as otherwise permitted by Applicable Data Protection Laws; (c) retain, use, or disclose Personal Data outside the direct business relationship between the parties; or (d) combine Personal Data with personal data obtained from other sources, except as permitted by the CCPA/CPRA for a service provider/contractor. Vendor certifies that it understands and will comply with these restrictions. Vendor processes Personal Data as a "processor" for purposes of the UCPA and adheres to the processor obligations required by the UCPA and reflected in this DPA. These commitments are elaborated in Section 18 (US State Privacy Terms).

9.4 Notice of unlawful instructions. Vendor will inform Customer without undue delay if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws. In such a case, Vendor may, to the extent required by law, suspend performance of the affected instruction (without penalty and without being in breach of the Agreement) until Customer confirms, amends, or withdraws it. This Section does not obligate Vendor to undertake a general legal review of Customer's instructions or to provide legal advice.

9.5 Customer responsibilities. As between the parties, Customer is responsible for the accuracy, quality, and legality of Personal Data and of the means by which it acquired that data; for establishing a lawful basis for the Processing; for providing all notices and obtaining all consents and authorizations required for Vendor to process Personal Data as instructed (including from its Operators, personnel, and End Users); and for ensuring its instructions comply with applicable law.

10. Confidentiality

10.1 Personnel commitments. Vendor will ensure that any of its personnel, contractors, and Sub-processor personnel authorized to process Personal Data are bound by an appropriate obligation of confidentiality, whether a contractual duty or a statutory or professional duty, and that this obligation survives the termination of their engagement.

10.2 Need-to-know access. Vendor limits access to Personal Data to those personnel who need such access to provide, maintain, secure, or support the Hosted Service, or to comply with the Agreement or applicable law, and applies least-privilege access to its production environment.

10.3 Training and instruction. Vendor takes reasonable steps to ensure that personnel with access to Personal Data are made aware of their confidentiality and data-protection responsibilities and process such data only on Customer's documented instructions, except where applicable law requires otherwise (in which case Vendor informs Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest).

10.4 Duration. These confidentiality obligations continue for the term of the Agreement and remain in effect after its expiration or termination for so long as Vendor retains any Personal Data.

11. Security Measures

11.1 Appropriate technical and organizational measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, Vendor implements and maintains appropriate technical and organizational measures ("TOMs") designed to ensure a level of security appropriate to that risk. The current TOMs are described in Annex II.

11.2 Included measures. Vendor's security measures for the Hosted Service include, without limitation:

    (a) Encryption in transit using TLS, and WireGuard for the private overlay network between the Control Server and Agents/Endpoints; Operator connections to and from the Control Server are secured by TLS;

    (b) the agent-encrypted, per-Operator credential vault, under which saved Endpoint credentials are stored on the Control Server only as opaque ciphertext that Vendor cannot decrypt or read;

    (c) role-based access control (RBAC) governing Operator permissions;

    (d) mandatory TOTP two-factor authentication (2FA) for Operator accounts;

    (e) append-only session audit logging recording which Operator accessed which Endpoint, when, and what actions were taken; and

    (f) least-privilege access to the production environment hosting the Control Server.

11.3 No guarantee. Vendor does not warrant that its security measures will be error-free or that the Hosted Service or Personal Data will be immune from every unauthorized access, loss, or other security event. Vendor commits to reasonable and appropriate TOMs as described in this Section and Annex II, not to a guarantee of perfect security.

11.4 Changes to measures. Vendor may update or modify its TOMs from time to time, provided that any such change does not materially reduce the overall level of security of the Hosted Service during the term of the Agreement. Vendor may update Annex II to reflect current measures.

11.5 Testing and evaluation. Vendor maintains a process to regularly review, assess, and evaluate the effectiveness of the technical and organizational measures described in Annex II for ensuring the security of the Processing, and remediates identified deficiencies and updates those measures as appropriate.

11.6 Customer responsibilities. Customer is responsible for the secure configuration and use of the Hosted Service within its control, including managing Operator accounts, roles, and permissions; enforcing and safeguarding Operator authentication and 2FA enrollment; determining whether to enable session recording; and controlling which Endpoints are enrolled and which credentials Operators save. Customer is responsible for assessing whether the Hosted Service, including the TOMs in Annex II, meets its own requirements and legal obligations.

12. Personal Data Breach

12.1 Notification to Customer. Vendor will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data. Notice will be given to the Customer contact designated in the Agreement or, if none, to Customer's administrative or account contact of record.

12.2 Contents of notice. To the extent known and reasonably available at the time, and supplemented as further information becomes available, Vendor's notice will describe:

    (a) the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects and records concerned;

    (b) the likely consequences of the Personal Data Breach;

    (c) the measures Vendor has taken or proposes to take to address the Personal Data Breach and to mitigate its possible adverse effects; and

    (d) a contact point at Vendor from whom more information may be obtained.

12.3 Investigation and mitigation. Vendor will take reasonable steps to investigate, contain, and mitigate the Personal Data Breach and to prevent its recurrence.

12.4 Assistance. Vendor will provide Customer with the information and reasonable cooperation Customer needs to meet its own breach-notification and communication obligations to supervisory authorities and data subjects under Applicable Data Protection Laws, taking into account the nature of the Processing and the information available to Vendor.

12.5 Controller's responsibility to notify. As between the parties, Customer, as Controller, is responsible for determining whether a Personal Data Breach requires notification to any supervisory authority, regulator, or data subject, and for making any such notification. Vendor does not act as Customer's notifier to regulators or data subjects and will not make such notifications on Customer's behalf unless separately and expressly instructed by Customer in writing (with Customer bearing responsibility for the content of any such notification). Nothing in this Section limits any independent legal obligation Vendor may have as a controller of its own data.

12.6 No admission of liability. Vendor's notification of, or response to, a Personal Data Breach is not and will not be construed as an acknowledgment or admission by Vendor of any fault, liability, or wrongdoing with respect to the Personal Data Breach.

13. Sub-processors

13.1 General authorization. Customer provides Vendor with a general written authorization to engage Sub-processors to process Personal Data in connection with the provision of the Hosted Service. Vendor may continue to use the Sub-processors identified in the maintained list referenced in Section 13.2 and, subject to the change-notice and objection mechanism in Section 13.3, may add or replace Sub-processors.

13.2 Current Sub-processors. Vendor maintains a current list of its Sub-processors for the Hosted Service at myremoting.iownsoftware.com/legal/subprocessors (the "Sub-processor List"). As of the effective date of this DPA, the categories of authorized Sub-processors are:

The Sub-processor List governs the current specifics (including entity names and processing locations) and controls over any snapshot reproduced in this DPA or in Annex III. Stripe's processing constitutes Vendor's own controller activity for billing and is governed by the Privacy Policy rather than this DPA; Stripe is included on the Sub-processor List and in Annex III for transparency and completeness only, and is not thereby characterized as a Hosted-Service processor engagement.

13.3 Notice of changes; right to object. Before authorizing any new Sub-processor, or replacing an existing one, that will process Personal Data in the Hosted Service, Vendor will update the Sub-processor List and give Customer prior written notice of the intended addition or replacement at least 30 days before the new Sub-processor begins processing Personal Data. Vendor will provide that notice to Customer's designated account or administrative contact of record; Customer may additionally subscribe to notifications of changes to the Sub-processor List via email to the Customer's designated administrative contact, but such subscription is a delivery channel only and is not a precondition to Customer's right to notice or to object. Within the notice period, Customer may object on reasonable data-protection grounds by written notice to privacy@iownsoftware.com stating the specific grounds, and the parties will work together in good faith to resolve the objection, including by Vendor describing available measures or, where reasonably practicable, offering an alternative that avoids the objected-to Sub-processor for Customer's Hosted Service.

13.4 Effect of unresolved objection. If the parties are unable to resolve an objection under Section 13.3 within a reasonable time, Customer may, as its sole and exclusive remedy, terminate the affected portion of the Hosted Service by written notice. Termination under this Section does not relieve Customer of fees accrued before the effective date of termination and is subject to the terms of the Agreement.

13.5 Sub-processor terms; flow-down. Vendor will engage each Sub-processor under a written contract that imposes data-protection obligations no less protective of Personal Data than those in this DPA, to the extent applicable to the services the Sub-processor performs. Where a Sub-processor processes Personal Data outside the EEA, the United Kingdom, or another jurisdiction for which a restricted-transfer mechanism is required, Vendor will ensure an appropriate transfer mechanism (as described in Section 15, including the SCCs and the UK IDTA, or a recognized adequacy basis) is in place.

13.6 Liability for Sub-processors. Vendor remains responsible for the acts and omissions of its Sub-processors in their Processing of Personal Data to the same extent Vendor would be liable if performing the services directly under this DPA.

14. Assistance: Data Subject Rights, DPIAs, and Consultations

14.1 Self-service tools; primary responsibility. Customer, as Controller, is responsible for receiving, validating, and responding to requests from data subjects (or, under the CCPA/CPRA, "consumers") to exercise their rights, including rights of access, rectification/correction, erasure/deletion, restriction of processing, data portability, and objection (collectively, "Data Subject Requests"). The Software provides self-service features — including data export, deletion, and append-only session audit logging — that Customer can use to locate, export, correct, and delete Personal Data in the Control Server and thereby respond to Data Subject Requests directly and without Vendor's involvement. Because Customer administers Operators, Endpoints, permissions, and retention settings, Customer is ordinarily best positioned to fulfill Data Subject Requests using these features, and Vendor's assistance under Section 14.2 is intended to supplement, not replace, Customer's use of them.

14.2 Vendor assistance with Data Subject Requests. Taking into account the nature of the Processing, and insofar as possible, Vendor will assist Customer by appropriate technical and organizational measures to fulfill Customer's obligation to respond to Data Subject Requests concerning Personal Data in the Hosted Service. Where the self-service features are insufficient for a particular request, Vendor will, on Customer's documented instruction, provide reasonable assistance to identify, retrieve, export, correct, restrict, or delete the relevant Personal Data within the Control Server, to the extent such Personal Data is within Vendor's control and reasonably accessible to it. Vendor is not obligated to provide assistance that is technically infeasible given the nature of the Processing, and specifically:

1. Agent-encrypted credential blobs. Vendor can delete or return such ciphertext in opaque form, but cannot access, export in intelligible form, or rectify the underlying credentials (see Section 8).

2. Transient session data. Live screen frames are processed transiently for remote viewing and control and are not retained as a stored record; assistance with respect to session data is limited to data actually retained, such as optional session recordings (where Customer has enabled recording), session audit logs, and in-session chat.

3. Records Customer controls directly. For Operator account data, Endpoint inventory, retention configuration, and other data Customer administers through the Control Server, Vendor's assistance is limited to that which Customer cannot accomplish through the self-service features.

14.3 Requests received directly by Vendor. If Vendor receives a Data Subject Request that relates to Personal Data processed on Customer's behalf in the Hosted Service, Vendor will:

1. not respond to the request substantively except on Customer's documented instruction or as otherwise required by applicable law (in which case Vendor will, to the extent legally permitted, inform Customer of that legal requirement before responding);

2. promptly, and in any event within 5 business days of identifying the Customer to whom the request relates, forward the request to Customer using Customer's designated contact, or, where reasonable, direct the data subject to submit the request to Customer; and

3. where Vendor cannot reasonably identify the Customer to which a request relates, use reasonable efforts to route the request appropriately or advise the data subject accordingly.

Vendor may confirm to a data subject that it has forwarded the request to the responsible Customer without disclosing Personal Data.

14.4 Assistance with DPIAs and prior consultations. Taking into account the nature of the Processing and the information available to Vendor, Vendor will provide Customer with reasonable assistance in connection with (a) data protection impact assessments (or comparable risk assessments) Customer is required to carry out under Article 35 of the EU GDPR, the corresponding provisions of the UK GDPR, or analogous obligations under the CCPA/CPRA or the UCPA, insofar as they concern Vendor's Processing of Personal Data in the Hosted Service; and (b) prior consultations with a competent supervisory authority under Article 36 of the EU GDPR or the corresponding provisions of the UK GDPR, insofar as required in relation to such Processing. Such assistance is limited to information within Vendor's possession and reasonably necessary for the assessment or consultation — including the descriptions of the nature and purposes of the Processing, the categories of Personal Data, the Sub-processors, and the TOMs set out in this DPA and its Annexes — and does not require Vendor to disclose confidential, security-sensitive, or third-party information, or information relating to other customers.

14.5 Cooperation, scope, and fees. Vendor will provide the assistance described in this Section within a reasonable period, consistent with any statutory deadline applicable to Customer of which Customer has given Vendor timely notice. Assistance under Sections 14.2 and 14.4 that is not readily addressable through the self-service features and that requires material Vendor effort may be provided on a reasonable and documented cost basis, except where Applicable Data Protection Laws require it to be provided at no charge. For the avoidance of doubt, the self-service framing in this Section supplements, and does not limit or relieve, Vendor's obligation to provide the assistance required under Articles 28(3)(e)–(f) of the EU GDPR (and equivalent provisions of Applicable Data Protection Laws) where Customer genuinely cannot fulfil a request through the self-service features.

15. International Data Transfers

15.1 Vendor location; scope. Vendor is established in the United States (Utah). This Section applies where Vendor's Processing of Personal Data under the Hosted Service, as a processor on Customer's documented instructions, involves a "restricted transfer" — that is, a transfer of personal data protected by EU GDPR or UK GDPR from the European Economic Area (EEA) or the United Kingdom to Vendor (or an onward transfer to a Sub-processor) in a country that has not been recognized as providing an adequate level of data protection.

15.2 Order of transfer mechanisms. For any restricted transfer, the parties will rely on a transfer mechanism in the following order of priority, to the extent one is valid and available for the transfer in question:

    (a) an adequacy decision or other recognized adequacy basis, where and to the extent one is validly available for the transfer in question;

    (b) failing (a), the EU SCCs as completed under this Section, together with the UK Addendum for UK transfers; or

    (c) any other transfer mechanism that is lawfully available and agreed by the parties (including any successor to the foregoing adopted by the European Commission or the UK ICO/Secretary of State).

15.3 EU Standard Contractual Clauses (incorporation by reference). Where the EU SCCs apply, they are hereby incorporated into this DPA by reference and form part of it, as if set out in full and executed by the parties, and are completed as follows:

    (a) Modules. Module Two (controller to processor) applies where Customer is a controller of the transferred personal data and Vendor is its processor. Module Three (processor to processor) applies where Customer acts as a processor on behalf of a third-party controller and Vendor acts as Customer's Sub-processor. Customer is the "data exporter" and Vendor is the "data importer." Clauses, options, and provisions that do not apply to the operative Module are disregarded.

    (b) Annexes. The Appendix to the EU SCCs (Annex I — Parties, description of transfer, and competent supervisory authority; and Annex II — technical and organizational measures) is completed by reference to Annex I and Annex II of this DPA, together with the Sub-processor List. The EU SCCs' Annex III (list of Sub-processors), where applicable to Module Three, is satisfied by that maintained list and Annex III of this DPA.

15.4 EU SCC option and clause selections. In each case, the corresponding clause of the EU SCCs is completed accordingly:

EU SCC clauseSelection
Clause 7 — Docking clauseApplies. Additional entities may accede to the EU SCCs as exporter or importer by agreement of the parties, subject to Section 15.7.
Clause 9 — Use of Sub-processorsOption 2 (general written authorization) applies. Vendor may engage Sub-processors in accordance with Section 13. Vendor will inform Customer of intended additions or replacements at least 30 days in advance, giving Customer the opportunity to object.
Clause 11 — RedressThe optional language permitting data subjects to lodge complaints with an independent dispute-resolution body does not apply. This is without prejudice to any other data-subject redress under the EU SCCs or applicable law.
Clause 13 / Annex I.C — Competent supervisory authorityAs identified in Annex I.C (the supervisory authority determined under Clause 13, e.g., the authority of the Member State of the exporter's establishment or of its EU Article 27 representative).
Clause 17 — Governing lawOption 1. The EU SCCs are governed by the law of Ireland.
Clause 18 — Choice of forum and jurisdictionDisputes arising from the EU SCCs will be resolved before the courts of Ireland.

15.5 UK transfers — International Data Transfer Addendum. For restricted transfers subject to the UK GDPR, the parties incorporate the International Data Transfer Addendum to the EU SCCs, version B.1.0, issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018 (the "UK Addendum"), which is hereby incorporated by reference and completed as follows:

UK Addendum tableCompletion
Table 1 — PartiesThe exporter and importer identified in Annex I.A.
Table 2 — Selected EU SCCs, Modules and clausesThe EU SCCs as incorporated and completed in Sections 15.3–15.4 (Module Two or Module Three, as applicable).
Table 3 — Appendix Information (Annexes I and II)Annex I and Annex II of this DPA (parties, transfer details, TOMs) and the Sub-processor List.
Table 4 — Ending the Addendum when the Approved Addendum changesNeither party may end the UK Addendum on this basis (i.e., only the parties by agreement), except that Vendor (as importer) may end it as permitted by Section 19 of the UK Addendum.

Where the UK Addendum applies, references in the EU SCCs are read as amended by the UK Addendum, the governing law and forum are those of England and Wales, and the competent supervisory authority is the UK Information Commissioner's Office.

15.6 Supplementary measures. In addition to the transfer mechanisms above, and taking into account the nature of the personal data and the Hosted Service, Vendor applies the supplementary technical and organizational measures described more fully in Annex II: encryption of personal data in transit (TLS, and WireGuard for the private overlay); the agent-encrypted, per-Operator credential vault, in which the Control Server stores only ciphertext Vendor cannot decrypt or read; role-based access control; mandatory TOTP two-factor authentication for Operators; append-only session audit logging; and least-privilege access to the production environment. As a further organizational measure relating to government access, Vendor will, to the extent legally permitted, notify Customer of any binding request by a public authority for Personal Data, will not disclose such data unless legally compelled, and will review and challenge requests it considers unlawful, disproportionate, or overbroad.

15.7 Onward transfers and Sub-processors. Any onward transfer of Personal Data by Vendor to a Sub-processor located in a country without an adequacy decision will be made only under an appropriate transfer mechanism consistent with this Section (including, where required, the EU SCCs and UK Addendum flowed down to, or independently entered into with, the Sub-processor via the docking clause or an equivalent commitment). Vendor's current Sub-processors and cloud infrastructure providers are described by category in Section 13 and Annex III and identified on the Sub-processor List.

15.8 Transfer impact assessment; cooperation. Vendor will provide Customer, on reasonable request, with information reasonably necessary to enable Customer to carry out a transfer impact assessment, and will cooperate with Customer to implement any additional measures a supervisory authority or applicable law reasonably requires for a lawful transfer. Where Customer has designated an EU or UK Article 27 representative or a data protection officer, its details are as recorded in Annex I.A.

15.9 Precedence and changes. To the extent of any conflict between this Section (or the body of this DPA) and the EU SCCs or UK Addendum as incorporated, the incorporated transfer clauses prevail with respect to the restricted transfer they govern. Nothing in this DPA, including the limitation of liability and cap in Article 7 of the Agreement, varies or waives any right of a data subject or obligation of the parties under those incorporated clauses that may not be varied by contract. If any incorporated mechanism is invalidated, superseded, or replaced, the parties will, without undue delay, adopt the successor or an alternative lawful mechanism under Section 15.2, and this Section will be read to give effect to it.

16. Return and Deletion of Personal Data

16.1 Trigger. This Section applies upon expiry or termination of the Hosted Service (or of the applicable Order or subscription), and otherwise upon Customer's written request with respect to Personal Data no longer needed for the Hosted Service.

16.2 Customer election. At Customer's choice, Vendor will (a) return the Personal Data it processes as processor to Customer, (b) delete that Personal Data, or (c) do both (return, then delete). If Customer does not communicate an election before the end of the retrieval window in Section 16.3, Vendor may proceed to delete under Section 16.4, except to the extent Section 16.6 (legally required retention) applies.

16.3 Retrieval window. For a period of 30 days after the effective date of expiry or termination (the "Retrieval Window"), Vendor will preserve the Personal Data it processes as processor and make it available for Customer's export and retrieval. During the Retrieval Window, Customer (through its authorized Operators, subject to RBAC and mandatory 2FA) may export data through the Control Server's available functions; where such functions are not sufficient for a category of data, Vendor will, on request, provide reasonable assistance to return that data in a commonly used, machine-readable format where reasonably feasible.

16.4 Deletion after the Retrieval Window. After the Retrieval Window closes (or earlier if Customer elects deletion and has completed any return it requested), Vendor will delete the Personal Data it processes as processor and delete existing copies, except as provided in Section 16.6. Deletion extends to routine system backups on Vendor's ordinary backup rotation and expiry cycle; Personal Data residing in backups will be rendered inaccessible for ordinary processing and deleted or overwritten in the ordinary course, and Vendor will not restore such data except as required by law.

16.5 Credential blobs and session data. Each agent-encrypted credential blob (opaque ciphertext Vendor cannot read; see Section 8) is deleted together with the Operator or Endpoint account with which it is associated, and in any event under Sections 16.3–16.4 upon termination. Live screen frames are transient and are not retained by the Control Server, so no return or deletion step is required for them beyond confirming they are not persisted. Session recordings exist only where Customer enabled recording and are returned and/or deleted under Sections 16.2–16.4 like other stored Personal Data, including copies in object storage where used.

16.6 Legally required retention. Vendor may retain Personal Data to the extent, and for so long as, retention is required by applicable law. In that case, Vendor will (a) retain only the data and for the period so required, (b) continue to protect it under this DPA and maintain the confidentiality obligations herein, and (c) process it solely for the purpose(s) that require its retention.

16.7 Sub-processors. Vendor will instruct its Sub-processors (including cloud infrastructure providers and any object storage used for session-recording retention) to return or delete Personal Data consistent with this Section, subject to the same legally-required-retention exception.

16.8 Certification and costs. Upon Customer's written request, Vendor will confirm in writing that it has completed the return and/or deletion required by this Section, subject to the exception in Section 16.6. Return and deletion consistent with this Section are provided at no additional charge; Vendor may charge a reasonable fee for extraordinary retrieval assistance requested beyond the standard export functions, on prior notice to Customer.

17. Audits and Demonstration of Compliance

17.1 Information on request. Vendor will make available to Customer the information reasonably necessary to demonstrate Vendor's compliance with its obligations under this DPA and Applicable Data Protection Laws with respect to the Hosted Service, including the TOMs described in Annex II.

17.2 Audit right. Vendor will allow for and contribute to audits and inspections of the Processing carried out under this DPA, conducted by Customer or by an independent auditor mandated by Customer, subject to the conditions in this Section.

17.3 Auditor confidentiality and independence. Any auditor must be bound by written obligations of confidentiality no less protective than those in the Agreement, and must not be a competitor of Vendor. Customer is responsible for its auditor's compliance with this Section.

17.4 Frequency and triggers. Audits and inspections under Section 17.2 may be conducted no more than once per calendar year, except where (a) required by a competent supervisory authority, (b) reasonably necessary following a Personal Data Breach affecting Customer's Personal Data, or (c) otherwise required by Applicable Data Protection Laws.

17.5 Notice and conduct. Audits and inspections will be conducted on reasonable prior written notice (at least 30 days, except where a shorter period is required by a supervisory authority or by law), during Vendor's normal business hours, for a reasonable duration, and in a manner that does not unreasonably disrupt Vendor's business operations or compromise the security, confidentiality, or availability of data belonging to Vendor or its other customers. On-site access, where genuinely necessary, is limited to facilities and systems relevant to the Processing under this DPA and is subject to Vendor's reasonable security and access policies.

17.6 Satisfaction through existing documentation. Vendor may satisfy an audit or information request under this Section, in whole or in part, by making available existing reports, questionnaires, policies, certifications, or other documentation that reasonably address the subject matter, where doing so is reasonable in the circumstances. Customer will accept such materials in lieu of a separate on-site audit to the extent they reasonably demonstrate compliance.

17.7 Findings, costs, and limitations. Customer will provide Vendor a copy of each audit report, which is Confidential Information of Vendor, and the parties will discuss and, acting reasonably and in good faith, agree on remediation of any material non-compliance identified. Each party bears its own costs of an audit, except that Vendor may charge its reasonable costs for time and materials incurred in supporting audits that (a) exceed the once-per-year frequency in Section 17.4, or (b) require support materially beyond making available the information and documentation contemplated by Sections 17.1 and 17.6, in each case on prior notice to Customer. Nothing in this Section requires Vendor to disclose or provide access to (a) data belonging to Vendor's other customers, (b) Vendor's internal pricing, financial, or personnel information, (c) any information subject to legal privilege or third-party confidentiality obligations, or (d) any information the disclosure of which would compromise the security of the Hosted Service. Vendor is not required to decrypt, and cannot decrypt, the agent-encrypted credential ciphertext described in Section 8.

18. US State Privacy Terms (CCPA/CPRA and UCPA)

This Section supplements this DPA and applies to the extent Vendor processes personal information or personal data subject to the CCPA/CPRA, the UCPA, or any other United States state privacy law (collectively, "US State Privacy Laws"), in each case only in connection with the Hosted Service and only where Vendor acts on Customer's behalf. Capitalized terms used but not defined in this Section have the meanings given in the applicable US State Privacy Law. To the extent this Section conflicts with the general terms of this DPA with respect to US State Privacy Laws, this Section controls.

18.1 Scope of Covered Personal Information. The personal information covered by this Section is the personal information within the Personal Data that Vendor processes as part of the Hosted Service on Customer's documented instructions, including Operator account data, Endpoint inventory, session data and audit logs, connection metadata, and the opaque, agent-encrypted credential blobs the Control Server stores but cannot decrypt or read (collectively, "Covered Personal Information").

18.2 CCPA/CPRA — Vendor as service provider / contractor. Where Customer is a business (or acts on behalf of a business) under the CCPA/CPRA, the parties intend and agree that Vendor is a service provider and, where applicable, a contractor with respect to Covered Personal Information. Vendor:

1. Limited purpose. Processes Covered Personal Information only for the business purpose(s) of providing, operating, securing, and supporting the Hosted Service as specified in the Agreement and this DPA, and for no other purpose; will not process it for any commercial purpose other than performing the Hosted Service; and will not process it outside the direct business relationship between the parties, except as otherwise permitted by the CCPA/CPRA.

2. No sale; no share. Will not sell and will not share (as those terms are defined in the CCPA/CPRA, including sharing for cross-context behavioral advertising) any Covered Personal Information, and will not accept, and has not received, any monetary or other valuable consideration in exchange for Covered Personal Information.

3. No unauthorized retention, use, or disclosure. Will not retain, use, or disclose Covered Personal Information for any purpose other than the business purposes specified in this DPA, unless expressly permitted by the CCPA/CPRA.

4. No combining. Will not combine Covered Personal Information with personal information received from or on behalf of another person, or collected from its own interaction with a consumer, except as necessary to perform a business purpose permitted by the CCPA/CPRA and its implementing regulations.

5. Certification. Vendor certifies that it understands the restrictions set out in this Section 18.2 and will comply with them.

6. Downstream flow-down. Will engage another person to assist it in processing Covered Personal Information for a business purpose only pursuant to a written contract that binds that person to the same or equivalent CCPA/CPRA obligations, consistent with Section 18.5 and Section 13.

7. Customer oversight and remediation. Customer may take reasonable and appropriate steps to ensure Vendor uses Covered Personal Information consistently with Customer's CCPA/CPRA obligations. On Customer's reasonable written notice that Vendor is processing Covered Personal Information in an unauthorized manner, Vendor will take reasonable and appropriate steps to stop and remediate the unauthorized processing.

8. Assistance with consumer rights. Taking into account the nature of Vendor's processing, Vendor will provide reasonable assistance to enable Customer to respond to verifiable consumer requests to know, access, correct, delete, opt out, or limit the use of sensitive personal information, to the extent Customer cannot fulfill such requests through the functionality of the Hosted Service. Because certain Covered Personal Information (such as the agent-encrypted credential blobs) is opaque to Vendor, assistance with respect to that information is limited to the actions technically available to Vendor.

9. Notice of inability to comply. Vendor will notify Customer without undue delay if it determines that it can no longer meet its obligations under the CCPA/CPRA with respect to Covered Personal Information.

18.3 UCPA and other US State Privacy Laws — Vendor as processor. Where Customer is a controller under the UCPA (Utah Code § 13-61-301 et seq.) or another US State Privacy Law, Vendor acts as a processor with respect to Covered Personal Information and will process it only in accordance with Customer's documented instructions. In that capacity, Vendor will: (a) process Covered Personal Information only on Customer's behalf and in adherence with Customer's instructions; (b) ensure that each person processing Covered Personal Information is subject to a duty of confidentiality; (c) at Customer's direction, delete or return all Covered Personal Information at the end of the provision of the Hosted Service, unless retention is required by law, subject to Section 16; (d) make available, on reasonable request, information reasonably necessary to demonstrate compliance and allow for and cooperate with assessments or audits as provided in Section 17; (e) engage a Sub-processor only after providing Customer an opportunity to object under Section 13 and only pursuant to a written contract requiring the Sub-processor to meet Vendor's obligations under this Section and the applicable US State Privacy Law; and (f) taking into account the nature of the processing and the information available, provide reasonable assistance to help Customer meet its own obligations, including as to consumer rights requests, the security of processing, and breach notification, consistent with Sections 11, 12, and 14.

18.4 Deidentified data. If either party discloses or provides deidentified data to the other in connection with the Hosted Service, or if Vendor derives deidentified data from Covered Personal Information as permitted by this DPA, the receiving party will, consistent with US State Privacy Laws: (a) take reasonable measures to ensure the information cannot be associated with, or reasonably linked to, an identified or identifiable natural person, household, or device; (b) publicly commit to maintain and use the information only in deidentified form and not to attempt to reidentify it, except solely to test that its deidentification process is effective; and (c) contractually obligate any recipient of the deidentified data to comply with clauses (a) and (b). Deidentified data meeting the requirements of the applicable US State Privacy Law is not Covered Personal Information for purposes of this Section.

18.5 Sub-processor obligations under US State Privacy Laws. Vendor's current Sub-processors and service providers are identified by category in Section 13 and Annex III and on the Sub-processor List. Each Sub-processor that processes Covered Personal Information is engaged under a written contract imposing obligations no less protective than those in this Section, consistent with the CCPA/CPRA service-provider/contractor requirements and the UCPA processor-contract requirements.

18.6 Role mapping.

FrameworkCustomer's roleVendor's roleScope of Vendor processing
CCPA/CPRA (California)BusinessService provider / contractorCovered Personal Information in the Hosted Service, on Customer's behalf
UCPA (Utah)ControllerProcessorCovered Personal Information in the Hosted Service, per Customer instructions
Other US State Privacy Laws (as enacted/effective)Controller / businessProcessor / service provider (as that law defines)Covered Personal Information in the Hosted Service, per Customer instructions
Vendor's own processing (all deployments)N/A (Vendor is controller/business)Controller / business — governed by the Privacy Policy, not this DPAWebsite/analytics, account and billing contacts, payment metadata, Heartbeat Metadata, opt-in telemetry, support communications

19. Liability

19.1 Each party's liability arising out of or related to this DPA, whether in contract, tort (including negligence), or otherwise, is subject to, and counts toward, the exclusions of liability and the aggregate limitation-of-liability cap set out in Article 7 of the Agreement. Any reference in this DPA to a party's liability is to be read as so limited.

19.2 The exclusions and cap in Article 7 apply to the combined, aggregate liability of the parties (and their affiliates) under the Agreement and this DPA taken together, and not separately or cumulatively. This DPA does not create any separate or additional liability cap.

19.3 Nothing in this Section limits or excludes either party's liability to the extent such limitation or exclusion is not permitted by Applicable Data Protection Laws, or to the extent required to be uncapped under the SCCs (including as to the rights of data subjects as third-party beneficiaries thereunder). As between the parties, any allocation of liability in this DPA or the Agreement does not affect a data subject's rights under Applicable Data Protection Laws or under the SCCs.

20. Order of Precedence

20.1 This DPA is incorporated into and forms part of the Agreement. Except as stated in this Section, the terms of the Agreement continue in full force.

20.2 In the event of a conflict or inconsistency concerning the Processing of Personal Data in the Hosted Service, the following order of precedence governs, from highest to lowest:

RankDocumentPrevails as to
1The SCCs and the UK IDTA, as applicableRestricted transfers of Personal Data — to the extent of any conflict, the SCCs/IDTA prevail over this DPA and the Agreement
2This DPAProcessing of Personal Data in the Hosted Service — prevails over the body of the Agreement and the Privacy Policy
3The body of the Agreement (including any Privacy Policy incorporated by reference)All other matters

20.3 Outside the subject matter of Personal-Data Processing in the Hosted Service, the Agreement continues to govern, and this Section does not alter the precedence of documents for any other purpose.

21. Term and Termination

21.1 This DPA takes effect when the Agreement takes effect for a Hosted Service deployment (or, if later, when Customer first uses the Hosted Service) and remains in effect for so long as Vendor processes Personal Data on Customer's behalf in the Hosted Service under the Agreement.

21.2 This DPA terminates automatically upon expiration or termination of the Agreement as it applies to the Hosted Service. Termination of this DPA does not relieve either party of obligations that by their nature survive, including obligations relating to confidentiality, deletion or return of Personal Data (including any 30 days and applicable retention obligations), cooperation on Data Subject Requests and regulatory inquiries, the SCCs where required, and Sections 19–24.

22. Governing Law and Jurisdiction

22.1 This DPA is governed by, and construed in accordance with, the governing law of the Agreement — the laws of the State of Utah, USA — and the parties submit to the forum and dispute-resolution provisions of the Agreement, in each case except where Applicable Data Protection Laws or the SCCs require a different governing law or forum.

22.2 To the extent the SCCs apply, the governing law and forum specified in the SCCs (or otherwise required by applicable EU or UK data protection law) govern the SCCs and prevail over Section 22.1 for that purpose. Nothing in this Section deprives a data subject of the protection of the mandatory law of the data subject's habitual residence where such protection cannot be excluded.

23. Acceptance; Published Version

23.1 For Hosted Service deployments, this DPA is accepted together with, and by acceptance of, the Agreement; no separate signature is required for it to be binding. Where the parties execute a separately negotiated data processing addendum for the Hosted Service, that executed addendum governs in place of this published DPA to the extent of any difference.

23.2 Absent a separately executed data processing addendum, the version of this DPA published at myremoting.iownsoftware.com/legal/dpa as of the effective date of the Agreement (or of the applicable Hosted Service order) applies. Vendor may update the published DPA from time to time; material changes that adversely affect Customer's rights or Vendor's obligations as processor apply to an existing Hosted Service subscription only upon renewal or as otherwise agreed by the parties in writing, except where a change is required to comply with Applicable Data Protection Laws or the SCCs, in which case it applies upon posting.

23.3 A party may request execution of a countersigned copy of this DPA. Upon such request, the parties will execute this DPA (which may be signed electronically and in counterparts) without altering its substantive terms, and the executed copy will evidence, but not expand, the parties' obligations.

24. General

24.1 Severability. If any provision of this DPA is held invalid or unenforceable, that provision is modified to the minimum extent necessary to make it enforceable, or if it cannot be so modified, severed; the remaining provisions remain in full force.

24.2 No waiver. A party's failure or delay in enforcing any provision of this DPA is not a waiver of that or any other provision.

24.3 Entire agreement on processing. This DPA, together with its Annexes, the SCCs where applicable, and the Agreement, constitutes the entire agreement of the parties regarding Vendor's Processing of Personal Data in the Hosted Service and supersedes any prior or contemporaneous understanding on that subject.

24.4 Counterparts and electronic acceptance. This DPA may be accepted or executed electronically and in counterparts, each of which is deemed an original and all of which together constitute one instrument.

24.5 Contact. Notices and requests under this DPA concerning Personal Data may be directed to Vendor at privacy@iownsoftware.com or I Own Software LLC, 321 N Mall Dr, Suite R259, Saint George, UT 84790, USA, and to Customer at the contact designated in the Agreement or Customer's Control Server account.


Annexes

These Annexes form part of, and are governed by, this DPA and apply solely to the Hosted Service, in which Vendor (I Own Software LLC) acts as processor on behalf of Customer. They do not apply to Self-Hosted / On-Premises deployments (in which Customer is the sole controller of the data its Control Server holds and Vendor receives only Heartbeat Metadata and any opt-in support telemetry as an independent controller under the Privacy Policy). Where these Annexes populate the EU SCCs (Commission Implementing Decision (EU) 2021/914) and/or the UK IDTA, they serve as the corresponding appendices to those instruments.

Annex I — List of Parties, Description of Processing, and Competent Supervisory Authority

A. List of Parties

Data Exporter / Controller

FieldDetail
NameThe Customer identified in the Usage and License Agreement (v2026.07) into which this DPA is incorporated
AddressThe Customer address stated in the Agreement or Customer's account record
Contact name, position, contact detailsTo be completed by Customer (data exporter) at signing: name, position, contact details
RoleController (and, under Module Three, processor); for the EU/UK SCCs, data exporter
Activities relevant to the transferLicensing and use of the Hosted Service to remotely access, monitor, and manage Endpoints
Signature and dateAs per the Agreement / DPA execution block

Data Importer / Processor

FieldDetail
NameI Own Software LLC, a Utah limited liability company
Address321 N Mall Dr, Suite R259, Saint George, UT 84790, USA
Contactprivacy@iownsoftware.com (privacy/data matters); postal address above
RoleProcessor (and, under Module Three, sub-processor); for the EU/UK SCCs, data importer
Activities relevant to the transferOperating the Hosted Service (Control Server) to broker remote-access/RMM connections and to store inventory, audit logs, and session recordings on Customer's documented instructions
EU/UK Representative (Art. 27)None appointed
Data Protection OfficerNone appointed
Signature and dateAs per the Agreement / DPA execution block

B. Description of the Processing

Categories of data subjects. (1) Operators — Customer's authenticated Control Server users who remotely access Endpoints; (2) Customer personnel — Customer's administrators, technicians, and other authorized users of the Hosted Service; (3) End Users — persons at the managed Endpoints whose device, session, and connection data may be processed during remote access, monitoring, and management.

Categories of personal data.

CategoryExamples
Operator account dataName, email, hashed password, TOTP two-factor authentication secret, role/permission assignments, login and audit events, IP addresses
Endpoint inventoryHostname, operating system, hardware/software/network/GPU details, logged-in usernames, security-posture signals
Session dataLive screen frames (transient, for remote viewing/control); optional session recordings (only when Customer enables recording); append-only session audit logs (which Operator accessed which Endpoint, when, and what actions); in-session chat
Agent-encrypted credential blobsEndpoint credentials saved by an Operator, stored by the Control Server only as opaque, per-Operator agent-encrypted ciphertext that Vendor cannot decrypt or read
Connection metadataSource IP addresses, timestamps, device identifiers

Special categories of personal data. None are intended or requested. The Hosted Service is not designed to process special-category data (Article 9 GDPR) or other sensitive data. Customer, as Controller, is responsible for determining what data is exposed through remote-access sessions, inventory collection, and recordings, and must not submit special-category data except as it deliberately configures the Software; any such data is processed only incidentally as part of screen frames, recordings, or session activity initiated by Customer's Operators, subject to the safeguards in Annex II. Not applicable. The Hosted Service is not intended for special-category or otherwise sensitive Personal Data, and the Customer must not submit such data through it except to the extent expressly configured and lawfully permitted.

Nature and purpose of the processing. Provision of a hosted, white-label remote-access and RMM platform: brokering and relaying remote-access connections between Operators and Endpoints; collecting and storing Endpoint inventory; capturing and transmitting live screen frames for remote viewing and control; storing optional session recordings and append-only session audit logs; transmitting transactional email (account recovery, alerts, notifications); and related storage, hosting, and support activities, in each case on Customer's documented instructions.

Frequency of the processing. Continuous, for the duration of Customer's subscription to the Hosted Service.

Duration and retention. For the term of Customer's subscription, followed by deletion or return of Personal Data in accordance with Section 16, subject to a post-termination retrieval period of 30 days and any residual retention required by applicable law. Session recordings and audit logs are retained per Customer's configured settings within the Software (the retention period configured by the Customer); backups are retained per the rotation described in Annex II and overwritten in the ordinary course.

Sub-processor transfers. For processing by (sub-)processors, the subject matter, nature, and duration are as described in Annex III; retention is as above.

C. Competent Supervisory Authority

The competent supervisory authority is determined in accordance with EU SCC Clause 13 and applicable law, by reference to the data exporter's place of establishment (or its EU Article 27 representative, where the exporter is not established in the EU): The supervisory authority of the EEA Member State in which the Customer (data exporter) is established or has designated a representative; where the Customer is not established in the EEA, the Irish Data Protection Commission acts as the competent supervisory authority for purposes of the SCCs.. For processing subject to the UK GDPR, the competent authority is the UK Information Commissioner's Office (ICO).

Annex II — Technical and Organizational Security Measures

Vendor implements and maintains the reasonable technical and organizational measures below, appropriate to the risk, to protect Personal Data processed in the Hosted Service against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures are described at a general level and may be updated over time (Section 11.4), provided the level of protection is not materially reduced. No security measure guarantees absolute security, and Vendor does not warrant that the Hosted Service is impenetrable.

AreaMeasures
Encryption in transitTLS for connections to and from the Control Server; WireGuard-based encrypted private overlay network between the Control Server and Agents/Endpoints. Operator connections to and from the Control Server are secured by TLS.
Credential protectionAgent-encrypted, per-Operator credential vault: saved Endpoint credentials are stored on the Control Server only as opaque ciphertext Vendor cannot decrypt or read. Operator passwords are stored hashed (never in clear text); TOTP 2FA secrets are stored to support authentication.
Access control — authenticationMandatory TOTP two-factor authentication for Operator accounts, in addition to account credentials.
Access control — authorizationRole-based access control (RBAC) governing Operator permissions and the actions available within the Control Server.
Accountability and auditabilityAppend-only session audit logging recording which Operator accessed which Endpoint, when, and what actions were taken; login and audit event logging for Operator accounts.
Production accessLeast-privilege, need-to-know access to the production environment, limited to authorized Vendor personnel bound by confidentiality obligations (Section 10).
Session data handlingLive screen frames processed transiently for remote viewing/control; session recording performed only when Customer enables it; recordings retained and rotated, with object storage used for retention as applicable.
Security review and testingRegular review and evaluation of the effectiveness of the technical and organizational measures, and remediation of identified deficiencies (Section 11.5).
Hosting and resilienceHosted Service operated on multi-provider cloud infrastructure (currently Hetzner, DigitalOcean, and Vultr) with failover across US and EU regions; backups maintained to support recovery, with rotation and overwriting in the ordinary course.
Sub-processor governanceUse of Sub-processors under written terms and a maintained, updatable list at myremoting.iownsoftware.com/legal/subprocessors (Section 13).
PersonnelConfidentiality obligations binding personnel and contractors with access; awareness of data-protection and security responsibilities.
Government-access handlingNotice (where legally permitted), non-disclosure absent legal compulsion, and review/challenge of unlawful or overbroad requests (Section 15.6).
Incident responseProcesses to detect, investigate, and respond to Personal Data Breaches and to notify Customer in accordance with Section 12.

Planned / aspirational measures (not present representations): Vendor may in the future pursue a formal third-party security certification or attestation, a documented penetration-testing cadence, and a formal, documented incident-response runbook. These are forward-looking roadmap items only and are not present representations or commitments. Vendor makes no claim to hold SOC 2, ISO 27001, or any other certification or attestation, and makes no representation that any such measure is currently in place, unless and until separately stated in writing.

Annex III — List of Sub-processors

Customer authorizes Vendor to engage the categories of Sub-processors below to support the Hosted Service. Vendor maintains a current, updatable list of specific Sub-processors at myremoting.iownsoftware.com/legal/subprocessors, which governs the specific entities in use from time to time and controls in the event of any discrepancy with the table below. Changes to Sub-processors are handled in accordance with Section 13.

Sub-processor (category)PurposeCategories of personal dataLocation(s)
Cloud infrastructure providers — Hetzner, DigitalOcean, and Vultr (multi-provider, with failover)Hosting the Control Server and storing Hosted Service data (Endpoint inventory, session audit logs, and — where Customer enables recording — session recordings)All categories of Personal Data processed in the Hosted Service (per Annex I.B)United States and European Union regions
Object storage provider (may be one of the cloud providers above)Retention/storage of session recordings where Customer enables recordingSession recordings and associated session metadatathe United States and/or the European Union, as identified in the Sub-processor List
SendGrid / TwilioTransactional email and messaging (account recovery, alerts, notifications)Operator name and email address; message content and delivery metadatathe United States, as identified in the Sub-processor List
Stripe, Inc. (listed for transparency only — supports Vendor's own controller-side billing under the Privacy Policy, not Hosted-Service processing under this DPA)Payment processing for Customer billing (card data handled by Stripe under its PCI compliance; Vendor does not store full card numbers)Billing-contact details and limited payment metadata (not "Personal Data" as defined in this DPA; governed by the Privacy Policy)the United States, as identified in the Sub-processor List

Where a Sub-processor processes Personal Data outside the data exporter's jurisdiction, Vendor relies on the applicable cross-border transfer mechanism (EU SCCs, the UK IDTA, and/or a recognized adequacy basis) as described in Section 15.


Acceptance. By accepting the Agreement or by using the Hosted Service, Customer and Vendor agree to be bound by this DPA, which is incorporated into and forms part of the Agreement and applies to the Hosted Service only. No separate signature is required; the parties may nonetheless execute a countersigned copy under Section 23.3.