I Own Software LLC — MyRemoting Privacy Policy
Version 2026.07
Last updated: July 10, 2026
This Privacy Policy explains how I Own Software LLC ("Vendor," "we," "us") handles personal data in connection with MyRemoting, our self-hostable, white-label remote-access and remote-monitoring-and-management (RMM) platform, and our related websites and services. It focuses on the personal data for which we are a controller, and it explains where, instead, a Customer is the controller and we act only as a processor.
> Our role at a glance. MyRemoting is offered in two deployment models, and our data-protection role differs between them: > > - Self-Hosted / On-Premises — the Customer runs the Control Server on its own infrastructure and is the sole controller of all data that Control Server holds (Endpoint inventory, audit logs, session recordings, and agent-encrypted credential blobs). We do not host, access, or receive that data. The only data that reaches us is Heartbeat Metadata (plus any support telemetry the Customer opts into), for which we act as an independent controller to validate licenses, enforce the Agreement, and provide support. > - Hosted Service (SaaS) — we run the Control Server for the Customer. The Customer is the controller and we are the processor of the Operator, Endpoint, and session personal data processed through it, acting on the Customer's documented instructions. > > This Privacy Policy describes only the personal data we handle as a controller. Processing we perform as a processor in the Hosted Service is governed by the Data Processing Addendum ("DPA") at myremoting.iownsoftware.com/legal/dpa, which controls on any conflict about that data.
1. Introduction, Who We Are, and Scope
1.1 Introduction
This Privacy Policy explains how I Own Software LLC processes personal data for which it acts as a controller — meaning it determines the purposes and means of the processing. It applies to our websites, our Customer accounts and billing, our administration of the MyRemoting license (including Heartbeat Metadata we receive from all deployments), our support interactions, and our marketing relationship with you. Please read Section 1.4 (What This Policy Does Not Cover) carefully, because much of the personal data handled through the MyRemoting platform is not governed by this Policy.
Capitalized terms used but not defined here have the meanings given to them in the MyRemoting Usage and License Agreement, version 2026.07 (the "Agreement"), including "Software," "Control Server," "Agent," "Endpoint," "Operator," "End User," "Customer," "Hosted Service," "On-Premises/Self-Hosted," "Licensing Service," and "Heartbeat Metadata."
Effective date: July 10, 2026. We may update this Policy from time to time; how we do so, and how we notify you, is described in Section 11 (Changes to This Privacy Policy).
1.2 Who We Are (Controller Identity and Contact)
For the personal data described in Section 1.3, the controller is:
| Controller | I Own Software LLC, a Utah limited liability company ("Vendor," "we," "us," or "our") |
| Postal address | 321 N Mall Dr, Suite R259, Saint George, UT 84790, USA |
| Websites | iownsoftware.com and myremoting.iownsoftware.com |
| Privacy contact | privacy@iownsoftware.com (or the postal address above, marked to the attention of "Privacy") |
| EU/UK matters | None appointed (see Section 10) |
We are located in the United States (Utah). Where we transfer personal data across borders, we rely on the mechanisms described in Section 8 (International Data Transfers), including the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum (IDTA), and any recognized adequacy basis.
1.3 What This Policy Covers
This Policy covers personal data that we process as a controller in the course of operating our business, including:
1. Website visitors. Usage and analytics data, and cookies and similar technologies, on iownsoftware.com and myremoting.iownsoftware.com, as further described in Section 5 (Cookies and Similar Technologies). 2. Customer accounts and billing contacts. Names, email addresses, company details, billing addresses, and order history of the individuals who license, subscribe to, purchase, or administer the Software on behalf of a Customer. 3. Payment data. Limited billing metadata (for example, card last four digits and subscription status). Card payments are processed by our payment processor, Stripe, Inc.; we do not store full payment card numbers, and card-data security (PCI DSS) is handled by Stripe. 4. License administration. Heartbeat Metadata (deployment identity, Software version, and counts) that the Control Server sends to our Licensing Service from all deployments — including Self-Hosted / On-Premises deployments — to validate the license and enforce the Agreement, together with any optional support telemetry a Customer affirmatively enables. 5. Support communications. Emails, messages, and related information that a Customer or its personnel send to us for support, sales, or account purposes. 6. Marketing relationship. Contact and preference data used to send product, service, and other communications you have agreed to receive or that we are otherwise permitted to send.
For each category above, we describe the personal data we collect, why we process it, our legal bases, how we share it, how long we keep it, and your rights in the sections that follow.
1.4 What This Policy Does Not Cover
MyRemoting is deployed in two models, and the data roles differ by model. This Policy does not govern the following:
(a) Hosted Service — personal data we process as a processor. In the Hosted Service (SaaS), we run the Control Server for the Customer. The Customer is the controller of the Operator, Endpoint, and session personal data processed through the Control Server (for example, Operator account data, Endpoint inventory, live screen frames, session recordings, session audit logs, in-session chat, connection metadata, and agent-encrypted credential blobs), and we act as the Customer's processor, processing that data only on the Customer's documented instructions. Our handling of that data is governed by the Agreement and the Data Processing Addendum ("DPA") (published at myremoting.iownsoftware.com/legal/dpa), and by the Customer's own privacy notice to its Operators and End Users — not by this Policy. On any conflict about the processing of personal data in the Hosted Service, the DPA controls.
> Note: Even in the Hosted Service, saved Endpoint credentials are agent-encrypted per-Operator, and the Control Server stores only opaque ciphertext that we cannot decrypt or read.
(b) Self-Hosted / On-Premises deployments. Where the Customer runs the Control Server on its own infrastructure, the Customer is the sole controller of all data that Control Server holds — including Endpoint inventory, audit logs, session recordings, and agent-encrypted credential blobs — and we do not host, access, or receive that data. The only data that flows to us from a Self-Hosted deployment is Heartbeat Metadata (and any opt-in support telemetry the Customer enables), which we process as an independent controller to validate licenses, enforce the Agreement, and provide support, as described in Section 1.3(4) above. We are not the Customer's processor for Self-Hosted deployments.
(c) Third-party sites and services. Websites, products, and services operated by third parties (including a Customer's own systems and the third-party services listed on our sub-processor page at myremoting.iownsoftware.com/legal/subprocessors) are governed by those third parties' own privacy notices, not this Policy.
(d) Relationship to other documents. The Agreement is the master agreement; the DPA and this Policy are each incorporated into it by reference. This Policy is the Vendor-as-controller document; the DPA is the Vendor-as-processor document for the Hosted Service only. Nothing in this Policy limits or varies the rights, obligations, or the limitation of liability and cap set out in the Agreement (including Article 7).
2. Personal Data We Collect and How
This section describes the personal data that we collect and process as a controller in connection with our websites, our sales and billing relationship with Customers, our administration of MyRemoting licenses, and our support activities. It does not cover personal data that we process as a processor on a Customer's instructions within the Hosted Service (for example, Operator accounts, Endpoint inventory, session data, and credential blobs handled through a Control Server we host). That processing is governed by the DPA at myremoting.iownsoftware.com/legal/dpa, and on any conflict about Hosted Service personal data, the DPA controls.
2.1 Categories of Personal Data We Collect
We collect the following categories of personal data in our capacity as a controller.
2.1.1 Website and Usage Data (Cookies and Similar Technologies)
When you visit iownsoftware.com or myremoting.iownsoftware.com, our web servers automatically record standard log data such as IP address, approximate location derived from it, pages viewed, referring pages, browser and device characteristics, and timestamps. We use only strictly-necessary cookies required for the Websites to function and remain secure, and we do not use third-party analytics or advertising cookies. We use this log data to operate, secure, and maintain our sites. Where required by applicable law, we obtain consent for non-essential cookies and honor recognized opt-out preference signals. For details on the specific cookies used and how to manage them, see Section 5.
2.1.2 Account and Billing Contact Data
When a Customer registers, subscribes, or transacts with us, we collect account and billing contact details, including name, business email address, company name, billing address, and order history (including the products or subscriptions licensed and transaction records). Where a Customer administers an account with us that is protected by two-factor authentication, this may include an account log-in credential and a TOTP secret, which we treat as described in Section 2.4.
2.1.3 Payment Data
Card payments are processed by our payment processor, Stripe, Inc. We do not receive or store full payment card numbers; card data is handled by Stripe under its own PCI DSS obligations. We store only limited billing metadata returned to us, such as the last four digits of the card and subscription status. Your use of card payments is subject to Stripe's terms and privacy notice.
2.1.4 License-Administration Data
The Control Server in each Customer deployment periodically contacts our Licensing Service to validate the license and enforce the Agreement. From all deployments — including Self-Hosted / On-Premises deployments that we do not otherwise host or access — we receive Heartbeat Metadata, consisting of deployment identity, Software version, and counts (such as Endpoint or Operator counts). For Self-Hosted deployments this Heartbeat Metadata is the only data that flows to us, and we act as an independent controller of it to validate licenses, enforce the Agreement, secure the Software, and provide support. If a Customer affirmatively enables optional support telemetry, we also receive the diagnostic data that feature is designed to transmit; support telemetry is off unless the Customer turns it on.
2.1.5 Support Communications
When a Customer or its personnel contact us for support, sales, or other inquiries, we collect the contents of those communications (for example, emails and messages), the contact details you provide, and any information you choose to include, such as configuration details, logs, or screenshots you send us.
2.2 Summary of Categories, Sources, and Collection Method
| Category | Examples | Source | How Collected |
|---|---|---|---|
| Website / usage data | Pages viewed, IP-derived location, device/browser data, interaction events | The visitor / the websites | Automatically, via cookies and similar technologies |
| Account & billing contact data | Name, business email, company, billing address, order history; account log-in credential and TOTP secret (where 2FA is used) | The Customer / its personnel | Directly, when you register, subscribe, or transact |
| Payment data | Last four digits, subscription status (no full card numbers) | Stripe; the Customer | From Stripe (payment status) and directly at checkout |
| License-administration data | Heartbeat Metadata (deployment identity, Software version, counts); opt-in support telemetry | Customer deployments (incl. Self-Hosted), via the Licensing Service | Automatically, via license heartbeats; telemetry only if enabled |
| Support communications | Emails/messages, contact details, information you include | The Customer / its personnel | Directly, when you contact us |
2.3 Sources of Personal Data
We obtain personal data from three sources:
- Directly from you or the Customer — for example, when you create an account, subscribe, complete a purchase, configure a deployment, or contact support.
- Automatically — through our websites (via cookies and similar technologies) and through the Licensing Service (Heartbeat Metadata, and opt-in support telemetry where enabled).
- From our payment processor, Stripe — limited billing metadata and payment/subscription status, so that we can administer your subscription and account.
2.4 Sensitive and Special-Category Data
We do not intentionally collect special-category data as defined under the EU/UK GDPR (such as data concerning health, biometrics, or racial or ethnic origin) through the controller activities described in this section. The only "sensitive personal information" (as defined under the California CCPA/CPRA) that we process as a controller is the account log-in credential and any TOTP two-factor-authentication secret used to secure a Customer's account with us. We use that information solely for the permitted business purposes of authenticating the account and securing access to it (consistent with California Civil Code § 1798.121), and not to infer characteristics about you; for that reason we are not required to, and do not, offer a separate "Limit the Use of My Sensitive Personal Information" mechanism. Please do not include other sensitive or special-category data in support communications or other submissions to us unless it is strictly necessary and you are lawfully permitted to share it. Personal data processed within the Hosted Service is addressed by the DPA, not this section.
2.5 Whether You Must Provide Personal Data
Certain account and billing-contact data (such as name, business email, company, and billing details) must be provided to enter into or perform the subscription and to complete a transaction; if you do not provide it, we may be unable to provide the Software or complete the purchase. Other personal data — for example, optional support telemetry and consent-based marketing — is voluntary, and declining to provide it will not affect your ability to use the licensed Software.
3. How We Use Personal Data and Our Legal Bases
3.1 Scope of This Section
This Section explains the purposes for which we use personal data as a controller — that is, personal data we determine the purposes and means of processing for our own account. This includes personal data relating to website visitors, Customer account and billing contacts, payment and license administration, support communications, and the Heartbeat Metadata and any opt-in support telemetry we receive from all deployments (including Self-Hosted).
For the Hosted Service, personal data that we process on the Customer's documented instructions through the Control Server — including Operator account data, Endpoint inventory, session data, credential blobs, and connection metadata — is processed by us as a processor, not a controller. We do not determine the legal basis for that processing; the Customer, as controller, is responsible for identifying its lawful basis. Our processing of that data is governed by the DPA at myremoting.iownsoftware.com/legal/dpa, and this Section does not restate legal bases for it.
For Self-Hosted / On-Premises deployments, the Customer is the sole controller of the data held on its own Control Server; we do not host, access, or receive that data. The only personal data we receive from a Self-Hosted deployment is Heartbeat Metadata and any opt-in support telemetry the Customer affirmatively enables, for which we act as an independent controller and to which the legal bases below apply.
3.2 The Legal Bases We Rely On
Where the EU General Data Protection Regulation (GDPR) or the UK GDPR applies, we rely on the following legal bases (Article 6(1)):
- Contract — Article 6(1)(b): processing necessary to perform a contract with you, or to take steps at your request before entering into one.
- Legitimate interests — Article 6(1)(f): processing necessary for our (or a third party's) legitimate interests, except where overridden by your interests or fundamental rights and freedoms. We identify the specific interest for each such purpose in the table below, and we carry out a balancing assessment before relying on this basis.
- Legal obligation — Article 6(1)(c): processing necessary to comply with a legal obligation to which we are subject.
- Consent — Article 6(1)(a): processing you have specifically agreed to, such as optional analytics/marketing cookies, opt-in support telemetry, and certain marketing communications. You may withdraw consent at any time (see Section 3.5).
The concept of a "legal basis" is specific to the GDPR and UK GDPR. If you are a resident of California, Utah, or another U.S. state with its own privacy law, your rights and our obligations are described in Section 7 (Your Privacy Rights) rather than by the Article 6 bases below.
3.3 Purposes and Legal Bases
The table maps each purpose for which we act as controller to the personal data involved and the legal basis (or bases) we rely on. Where more than one basis is listed, we rely on the basis appropriate to the specific processing activity and category of individual.
| # | Purpose | Personal data involved | EU / UK GDPR legal basis |
|---|---|---|---|
| a | Provide and administer licenses and the Hosted Service subscription — create and manage Customer accounts, provision and configure the Hosted Service, and administer the Agreement | Customer account and billing-contact data (name, email, company, billing address, order history) | Contract (Art. 6(1)(b)) with the Customer; Legitimate interests (Art. 6(1)(f)) — administering our relationship with, and communications to, personnel of a Customer who are not themselves the contracting party |
| b | Validate licenses via the heartbeat — verify entitlement, enforce license terms and Software version, and detect unlicensed or out-of-scope use across all deployments | Heartbeat Metadata (deployment identity, Software version, counts) received from Hosted and Self-Hosted deployments | Contract (Art. 6(1)(b)) where tied to a subscription; Legitimate interests (Art. 6(1)(f)) — validating licenses, enforcing the Agreement, and preventing unlicensed use of the Software |
| c | Process payments and prevent payment fraud — take subscription and license payments and detect fraudulent transactions | Limited billing metadata (e.g., card last4, subscription status); our own payment/checkout logs (e.g., the IP address and timestamp of a transaction on our sites). Full card data is processed by Stripe and not stored by us | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) — tax, accounting, and record-keeping; Legitimate interests (Art. 6(1)(f)) — preventing and detecting payment fraud and securing payments |
| d | Provide support — respond to and resolve support requests and, where enabled, diagnose issues using support telemetry | Support communications (emails/messages from the Customer or its personnel); opt-in support telemetry | Contract (Art. 6(1)(b)) where support is part of the subscription; Legitimate interests (Art. 6(1)(f)) — responding to and resolving support requests; Consent (Art. 6(1)(a)) — for optional support telemetry the Customer affirmatively enables |
| e | Secure our services — protect our own websites and Licensing Service against abuse, unauthorized access, and other security threats; maintain audit and event logs for our own infrastructure | Sign-in and audit events for our own websites and Licensing Service, IP addresses, and device identifiers from our own systems (not Hosted Service session or connection data, which is governed by the DPA) | Legitimate interests (Art. 6(1)(f)) — ensuring the security, integrity, and availability of our services and detecting and preventing abuse; Legal obligation (Art. 6(1)(c)) where a specific security or breach obligation applies |
| f | Communicate with you — send service, transactional, security, and administrative messages (e.g., account recovery, alerts, notifications, billing and license notices); and, where permitted, send marketing messages | Customer account and billing-contact data; email address | Service/transactional messages: Contract (Art. 6(1)(b)) and/or Legitimate interests (Art. 6(1)(f)) — keeping you informed about the service you use. Marketing: Consent (Art. 6(1)(a)) where required, or Legitimate interests (Art. 6(1)(f)) — promoting our products to existing business customers where permitted by applicable law (see Section 3.5) |
| g | Comply with law — meet legal, regulatory, tax, and accounting obligations, respond to lawful requests, and establish, exercise, or defend legal claims | Any of the above categories, as relevant to the obligation or claim | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) — establishing, exercising, or defending legal claims where no specific legal obligation applies |
| h | Improve our products and services — understand how our websites and Software are used and develop and improve features, performance, and reliability | Website usage/analytics data; opt-in support telemetry; Heartbeat Metadata (aggregated counts) | Legitimate interests (Art. 6(1)(f)) — maintaining and improving our products and services; Consent (Art. 6(1)(a)) — for optional analytics cookies and any optional telemetry |
| i | Operate our websites — deliver iownsoftware.com and myremoting.iownsoftware.com and remember preferences | Cookie and device data (see Section 5) | Strictly necessary cookies: Legitimate interests (Art. 6(1)(f)) — providing a functioning website. Non-essential (analytics/marketing) cookies: Consent (Art. 6(1)(a)) |
Where a legitimate-interests basis is listed, the identified interest is the one shown in italics, and we have determined that it is not overridden by your interests or fundamental rights and freedoms. You may ask us for more information about a specific balancing assessment using the contact details in this Policy.
3.4 Payment Processing
Card payments are processed by Stripe, Inc. as our payment processor. We do not store full card numbers; card data is handled by Stripe under its PCI-DSS obligations. We retain only limited billing metadata (such as the last four digits of a card and subscription status) to administer your subscription and support and to prevent fraud, on the bases described at rows (c) and (g) of Section 3.3.
3.5 Withdrawing Consent and Objecting to Processing
3.5.1 Withdrawing consent. Where we rely on your consent — for example, optional analytics or marketing cookies, opt-in support telemetry, or consent-based marketing — you may withdraw it at any time. Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out before withdrawal. You can:
- control or block cookies at any time through your browser settings (blocking strictly-necessary cookies may affect how the Websites function);
- turn off optional support telemetry in your deployment or Hosted Service settings; and
- unsubscribe from consent-based marketing using the link in any such message or by contacting us at privacy@iownsoftware.com.
3.5.2 Objecting to legitimate-interests processing. Where we process your personal data on the basis of our legitimate interests (Article 6(1)(f)), you have the right to object at any time on grounds relating to your particular situation. If you object, we will stop processing your personal data for that purpose unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is needed to establish, exercise, or defend legal claims. To object, contact us at privacy@iownsoftware.com.
3.5.3 Objecting to direct marketing. You have an absolute right to object to the processing of your personal data for direct marketing at any time, including any profiling related to that marketing. If you object, we will stop processing your personal data for direct marketing. You can exercise this right using the unsubscribe link in any marketing message, through the unsubscribe link in our marketing emails or by contacting privacy@iownsoftware.com, or by contacting us at privacy@iownsoftware.com.
3.5.4 How to reach us. Requests under this Section can be sent to privacy@iownsoftware.com or to I Own Software LLC, 321 N Mall Dr, Suite R259, Saint George, UT 84790, USA. Where the request concerns personal data processed through the Hosted Service on a Customer's instructions (for which we act as processor), we will refer or forward the request to the relevant Customer as controller and assist as required under the DPA.
4. How We Share Personal Data
We do not sell your personal data. We share personal data only in the limited circumstances described in this section, and only as needed for the purposes described in this Privacy Policy or as permitted or required by law. This section addresses the personal data for which we act as a controller (our websites, Customer account and billing data, license administration, and support communications). Personal data we process on a Customer's behalf as a processor in the Hosted Service — including Operator account data, Endpoint inventory, session data, and connection metadata processed through the Control Server — is governed by the DPA and disclosed to the categories of sub-processors described there and in our maintained sub-processor list (see Section 4.2).
4.1 Categories of Recipients
We share personal data with the following categories of recipients:
| Recipient category | Who they are | Why we share |
|---|---|---|
| Service providers / sub-processors | Vendors that process personal data on our behalf under written contract, currently: Stripe, Inc. (payment processing); our cloud infrastructure providers hosting the Hosted Service, currently Hetzner, DigitalOcean, and Vultr (multi-provider, with failover across U.S. and EU regions), including object storage used for session-recording retention; and SendGrid / Twilio (transactional email — account recovery, alerts, and notifications). | To operate, provide, secure, and support the Software and the Hosted Service, take payment, and send transactional communications. |
| Professional advisers | Our lawyers, accountants, auditors, insurers, and similar advisers. | To obtain professional advice, manage risk, and establish, exercise, or defend legal claims. |
| Authorities and other parties where legally required | Courts, regulators, law-enforcement, and other government or third parties. | To comply with applicable law, a valid legal process (such as a subpoena or court order), or a lawful request; to enforce the Agreement; and to protect the rights, property, or safety of the Vendor, our Customers, or others. |
| Acquirers in a business transfer | A counterparty (and its advisers) to a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, or a successor entity. | To evaluate or complete the transaction; any successor will remain bound by this Privacy Policy or provide notice of any material change. |
By way of illustration, the categories of personal information we disclose to each category of recipient for a business purpose are: account and billing-contact data and limited payment metadata to Stripe for payment processing; contact and email details to SendGrid / Twilio for transactional email; and, in the Hosted Service, account, license, and session data (including any session recordings) to our cloud infrastructure and object-storage providers. The cloud infrastructure and object-storage providers that host the Hosted Service are engaged as sub-processors under the DPA (see Section 4.2) and are listed above for transparency; in our controller capacity, our principal service providers are Stripe and SendGrid / Twilio.
We require our service providers and sub-processors to process personal data only on our instructions and for the purposes for which we engaged them, and to protect it under contractual terms consistent with this Privacy Policy and applicable law.
4.2 Sub-Processors for the Hosted Service
For personal data processed in the Hosted Service, we maintain a current list of sub-processors, together with their categories of processing, at myremoting.iownsoftware.com/legal/subprocessors. That list governs the specific sub-processors then in use and is updated from time to time. Customer rights to notice of, and objection to, new sub-processors are set out in the DPA.
4.3 What We Do Not Do
We do not sell personal data, and we do not "share" personal data for cross-context behavioral advertising, as the terms "sell" and "share" are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA). We likewise do not sell personal data as "sale" is defined under the Utah Consumer Privacy Act (UCPA) or other applicable U.S. state privacy laws. We have not sold or shared personal data for those purposes in the preceding twelve (12) months. Our disclosures to service providers and sub-processors under Section 4.1 are made under contract for the business purposes described above and are not sales or shares.
4.4 Deidentified and Aggregated Information
We may create and use deidentified or aggregated information (for example, aggregate license and usage statistics derived from Heartbeat Metadata, or website analytics) that does not identify any individual. We will maintain and use such information in deidentified form and will not attempt to reidentify it except as permitted by law.
4.5 International Transfers
Because we are based in the United States (Utah), sharing personal data with us and with the recipients described above may involve cross-border transfers. The mechanisms we rely on for those transfers are described in Section 8 (International Data Transfers), and, for the Hosted Service, in the DPA.
5. Cookies and Similar Technologies
5.1 Scope of this Section. This Section explains how we use cookies and similar technologies (such as pixels, local storage, and device identifiers, collectively "Cookies") on our public websites at iownsoftware.com and myremoting.iownsoftware.com and on the account, billing, and login pages we operate (together, the "Websites"). In this context we act as an independent controller of the personal data described here. Cookies and similar technologies set within the Control Server web interface for the Hosted Service — for example, to authenticate an Operator session — are processed on the Customer's behalf and are addressed by the DPA and the Customer's own privacy notices, not by this Section.
5.2 What Cookies Are. A cookie is a small text file placed on your device when you visit a website; similar technologies (local/session storage, pixels, and device or browser identifiers) perform comparable functions. Cookies may be "session" (deleted when you close your browser) or "persistent" (retained until they expire or you delete them), and may be set by us ("first-party") or, where applicable, by a service provider acting on our behalf ("third-party").
5.3 Categories of Cookies We Use.
| Category | Purpose | Consent |
|---|---|---|
| Strictly Necessary | Enable core Website functions that you request, such as page navigation, load balancing, session continuity, maintaining a signed-in state on our account/login pages, and protecting the security and integrity of the Websites. The Websites cannot function properly without these. | Set on the basis of our legitimate interest / necessity to provide the service; not subject to opt-in consent. |
| Functional | Remember choices and preferences you make (for example, language, region, or interface settings) to provide enhanced, personalized features. | Non-essential; set only with your consent where consent is legally required. |
| Analytics (only to the extent used) | Help us understand how visitors use the Websites in aggregate — for example, which pages are visited and how our sites perform — so we can measure and improve them. We do not currently use third-party analytics; if this changes, we will update this Policy and, where required, obtain your consent. | Non-essential; set only with your consent where consent is legally required. |
We do not use Cookies to sell or "share" (as those terms are defined under U.S. state privacy laws) your personal information for cross-context behavioral advertising, and we do not serve targeted advertising through the Websites.
5.4 Consent for Non-Essential Cookies. Where required by applicable law (including the EU GDPR, UK GDPR, and the ePrivacy rules), we set functional and analytics Cookies only after you give consent, which you may provide, decline, or withdraw through our Cookie consent mechanism (for example, a Cookie banner or preference control) presented on the Websites. Strictly necessary Cookies do not require consent and cannot be switched off through that mechanism. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
5.5 How You Can Control Cookies. You can manage Cookies in several ways:
- Our consent mechanism. Where offered, use the Cookie banner or preference control on the Websites to accept or reject non-essential categories and to change your choices at any time.
- Browser settings. Most browsers let you block or delete Cookies, or alert you before one is set. Instructions are found in your browser's help or settings menu. Blocking strictly necessary Cookies may cause parts of the Websites to malfunction.
- Device controls. You may be able to reset or limit device or advertising identifiers through your device settings.
5.6 Global Privacy Control and Opt-Out Preference Signals. Where required by applicable law (including the California CCPA/CPRA and other U.S. state privacy laws that recognize such signals), we honor opt-out preference signals — such as the Global Privacy Control (GPC) — that your browser or a browser extension transmits, and we treat a valid signal as a request to opt out of any sale/share and of non-essential Cookies for that browser or device to the extent legally required. Because such signals are tied to a specific browser or device, you must enable them on each browser and device you use.
6. Data Retention and Security
6.1 Data Retention
6.1.1 General principle. We keep personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including to provide and administer the accounts, licenses, and services you use; to maintain business, billing, and support records; to comply with our legal, tax, accounting, and regulatory obligations; and to establish, exercise, or defend legal claims. When personal data is no longer needed for these purposes, we delete it or de-identify it so that it can no longer be associated with you.
6.1.2 How we determine retention periods. The period for which we retain a given category of personal data depends on the nature of the data, the purpose for which we process it, and any minimum retention required or permitted by applicable law. Where different retention periods apply to the same record, we retain the record for the longest applicable period and then delete or de-identify it.
6.1.3 Retention schedule. The following describes our retention practices for the personal data we process as controller under this Privacy Policy. (This schedule does not govern personal data we process as processor within the Hosted Service on a Customer's behalf; that data is retained and returned or deleted as described in Section 6.2.5 and the DPA.)
| Category of Data | Purpose | Retention Period |
|---|---|---|
| Customer account and billing-contact data (name, email, company, billing address, order history) | Manage the customer relationship, provide the Software, and support the account | Duration of the account/subscription plus for the duration of the customer relationship and then as required for tax and accounting purposes for tax, accounting, and legal-claim purposes |
| Payment/billing metadata (e.g., card last4, subscription status) | Billing, renewals, and fraud prevention (full card data is held by Stripe, not us) | Duration of the account plus generally seven (7) years, to meet tax and accounting requirements as required for financial recordkeeping |
| Account log-in credential and TOTP secret (sensitive PI, where 2FA is used) | Authenticate the account and secure access | For the life of the account; deleted or invalidated on account closure or credential reset |
| License administration / Heartbeat Metadata (deployment identity, Software version, counts) received from all deployments, including Self-Hosted | Validate licenses, enforce the Agreement, and administer entitlements | For the term of the license, plus for as long as the deployment is licensed, plus up to 24 months after expiry or termination for renewal, audit, and enforcement, after which it is deleted or de-identified |
| Optional support telemetry (only where the Customer affirmatively enables it) | Diagnose issues and provide support | up to 24 months, or until the Customer disables it and requests deletion, whichever is earlier |
| Support communications (emails/messages to support) | Respond to and track support requests and maintain a service history | up to 24 months after the request is resolved from the last interaction |
| Website analytics data and cookies (iownsoftware.com / myremoting.iownsoftware.com) | Operate, secure, and improve the websites | up to 24 months, or the shorter lifetime stated in our cookie notice; cookie lifetimes are described in Section 5 and our Cookie Notice |
6.1.4 Backups and legal holds. Residual copies of personal data may persist in encrypted backups for a limited period after deletion from active systems, consistent with our backup rotation cycle, after which they are overwritten or destroyed. Where we are subject to a legal hold, subpoena, or other legal obligation to preserve data, we retain the affected data for as long as required and then delete or de-identify it.
6.2 Security
6.2.1 Reasonable technical and organizational measures. We maintain reasonable administrative, technical, and organizational measures designed to protect personal data against unauthorized access, use, disclosure, alteration, loss, or destruction, appropriate to the nature of the data and the risks involved. These measures include:
- Encryption in transit. We use TLS to protect data in transit, and WireGuard to secure the private overlay network used to broker connections.
- Access controls and least privilege. We use role-based access control, restrict access to production systems to authorized personnel on a least-privilege basis, and require mandatory time-based one-time-password (TOTP) two-factor authentication for Operators.
- Audit logging. The Control Server maintains append-only session audit logging of Operator access to Endpoints.
- Agent-encrypted credential vault (Hosted Service). Endpoint credentials that an Operator saves are agent-encrypted on a per-Operator basis; the Control Server stores only opaque ciphertext that we cannot decrypt or read. As a result, we cannot access stored Endpoint credentials.
- Infrastructure. The Hosted Service runs on established cloud infrastructure providers (see our sub-processor list at myremoting.iownsoftware.com/legal/subprocessors).
6.2.2 No guarantee of perfect security. No method of transmission over the Internet, method of electronic storage, or security measure is perfectly secure. While we work to protect personal data using reasonable measures, we cannot and do not guarantee the absolute security of any information, and you provide it at your own risk.
6.2.3 Your responsibilities. Security is a shared responsibility. You are responsible for safeguarding your account credentials and TOTP secrets, managing Operator roles and permissions appropriately, and configuring the Software (including session recording, credential saving, and access policies) in a manner suited to your environment. For Self-Hosted / On-Premises deployments, the Customer runs and secures its own Control Server and is responsible for the security of the Endpoint inventory, audit logs, session recordings, and credential blobs it holds; we do not host, access, or receive that data (other than Heartbeat Metadata and any opt-in support telemetry).
6.2.4 Breach notification. If we become aware of a security incident affecting personal data for which we are the controller, we will notify affected parties and applicable authorities as required by law, without undue delay and within 72 hours. For personal data we process as processor within the Hosted Service, our incident-notification obligations to the Customer are governed by the DPA.
6.2.5 Hosted Service security detail and processing terms. For the Hosted Service, we process Customer, Endpoint, and Operator personal data as a processor acting on the Customer's documented instructions. The specific technical and organizational security measures, sub-processor terms, breach-notification obligations, and return-or-deletion of data upon termination (within a 30 days retrieval period, after which data is deleted or de-identified) are set out in the DPA at myremoting.iownsoftware.com/legal/dpa, including its security-measures Annex. In the event of a conflict between this Section and the DPA regarding the processing of personal data in the Hosted Service, the DPA controls.
7. Your Privacy Rights
This Section explains the privacy rights that may be available to you and how to exercise them. The rights you have depend on where you live and on the law that applies to a particular processing activity. This Section addresses personal data for which we act as a controller — for example, website usage data, Customer account and billing contacts, payment metadata, License administration data (including Heartbeat Metadata received from all deployments and any opt-in support telemetry), and support communications. For personal data we process as a processor on a Customer's behalf, see Section 7.1.
7.1 Data Where We Act as a Processor (Hosted Service)
For the Hosted Service, the Customer is the controller of the personal data processed through the Control Server (including Operator account data, Endpoint inventory, session data and recordings, session audit logs, connection metadata, and the agent-encrypted credential blobs, which we cannot decrypt or read). We process that data as a processor on the Customer's documented instructions under the DPA, published at myremoting.iownsoftware.com/legal/dpa.
If you are an Operator, End User, or other individual and you wish to exercise rights in personal data held in a Customer's Hosted Service environment, please direct your request to the relevant Customer (the controller). If you send such a request to us directly, we will, where permitted, refer you to the applicable Customer or forward your request to it, and we will assist the Customer in responding as required by the DPA and applicable law. For Self-Hosted / On-Premises deployments, the Customer runs the Control Server and is the sole controller of the data it holds; we do not host, access, or receive that data (other than Heartbeat Metadata and any opt-in telemetry described elsewhere in this Policy).
7.2 How to Exercise Your Rights
To exercise any right described in this Section with respect to personal data for which we are the controller, contact us at:
- Email: privacy@iownsoftware.com
- Mail: I Own Software LLC, Attn: Privacy, 321 N Mall Dr, Suite R259, Saint George, UT 84790, USA
Please tell us which right you want to exercise and provide enough detail for us to locate the relevant personal data.
Identity verification. To protect your data, we will take reasonable steps to verify your identity before acting on a request. Verification may involve confirming information we already hold about you (for example, matching the email address associated with your account or billing contact). If we cannot verify your identity to the degree of certainty required by applicable law, we may be unable to fulfill the request, and we will explain why. We will not use information you provide for verification for any purpose other than verification and responding to your request.
Response timelines. We will respond within the timeframes required by applicable law. For US state privacy laws, we generally respond within 45 days of receiving a verifiable request, with an extension of up to an additional 45 days where reasonably necessary, and we will notify you of any extension. For the EU/UK GDPR, we will respond within one month, extendable by up to two further months for complex or numerous requests, with notice to you. We may charge a reasonable fee or refuse to act only where permitted by law (for example, where a request is manifestly unfounded, excessive, or repetitive), and we will tell you why.
Authorized agents. Where the law allows, you may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof that you gave them signed permission to act, and we may still require you to verify your own identity directly with us or to confirm that you authorized the agent.
No discrimination / no retaliation. We will not discriminate or retaliate against you for exercising any of your privacy rights. We will not deny you goods or services, charge you different prices, or provide a different level or quality of service because you exercised your rights, except as permitted by applicable law.
7.3 EU and UK GDPR Rights
If the EU General Data Protection Regulation ("EU GDPR") or the UK GDPR applies to our processing of your personal data as a controller, you have the following rights, subject to the conditions and exceptions in those laws:
1. Access — to obtain confirmation of whether we process your personal data and, if so, a copy of it and information about the processing. 2. Rectification — to have inaccurate personal data corrected and incomplete data completed. 3. Erasure — to have your personal data deleted in certain circumstances (the "right to be forgotten"). 4. Restriction — to have our processing of your personal data restricted in certain circumstances. 5. Portability — to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible, for processing based on consent or a contract and carried out by automated means. 6. Objection — to object to processing based on our legitimate interests, and to object at any time to processing of your personal data for direct marketing. 7. Withdraw consent — where we rely on your consent, to withdraw it at any time; withdrawal does not affect the lawfulness of processing before withdrawal. 8. Rights related to automated decision-making — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except as permitted by law. We do not use your personal data for such decision-making.
Legal bases and transfers. Where relevant, we will identify the legal basis for our processing and the safeguards we apply to cross-border transfers of personal data out of the EEA or the UK. Because we are based in the United States (Utah), transfers to us and our sub-processors are made under an appropriate transfer mechanism, which may include the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum / IDTA, or a recognized adequacy basis. You may request more information about these safeguards using the contact details above.
Complaints. You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) (ico.org.uk). In the EU, you may complain to the supervisory authority in your country of habitual residence, place of work, or the place of the alleged infringement. Because we are established in the United States and do not maintain an establishment in the EU, there is no single "lead" supervisory authority for our processing; where we have appointed an EU representative under Article 27, the supervisory authority of that representative's Member State may also be contacted (see Section 10.1). We ask that you contact us first so we can try to resolve your concern.
EU/UK representative and DPO. Our EU/UK representative and/or Data Protection Officer, where one is required, is identified in Section 10.
7.4 California Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA/CPRA"), gives you the following rights with respect to personal information we hold about you as a business:
1. Right to know / access — to request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, and the categories of third parties and service providers with whom we share it. 2. Right to delete — to request deletion of personal information we collected from you, subject to legal exceptions. 3. Right to correct — to request correction of inaccurate personal information we maintain about you. 4. Right to opt out of sale or sharing — to opt out of the "sale" or "sharing" (for cross-context behavioral advertising) of your personal information. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. 5. Right to limit use of sensitive personal information — to direct us to limit the use and disclosure of sensitive personal information to that permitted under the CCPA/CPRA. The only sensitive personal information we process as a controller is account log-in credentials (and any TOTP secret), which we use solely to authenticate and secure the account and not to infer characteristics about you; because our use is limited to those permitted business purposes, no separate right-to-limit mechanism is required (see Section 2.4). 6. Right to non-discrimination — to not receive discriminatory treatment for exercising your rights, as described in Section 7.2. 7. Authorized agents — you may use an authorized agent to submit requests, as described in Section 7.2.
Because we do not sell or share personal information, we do not offer a separate "Do Not Sell or Share My Personal Information" mechanism; however, we honor recognized opt-out preference signals (such as the Global Privacy Control) as required by law. You may exercise your California rights using the contact methods in Section 7.2.
7.5 Utah UCPA and Other US State Rights
If you are a Utah resident, the Utah Consumer Privacy Act ("UCPA") gives you the following rights with respect to personal data we control:
1. Access — to confirm whether we process your personal data and to access that data. 2. Delete — to delete personal data you provided to us. 3. Portability — to obtain a copy of your personal data in a portable and, to the extent technically feasible, readily usable format. 4. Opt out — to opt out of the processing of your personal data for purposes of targeted advertising or the sale of personal data.
Please note two UCPA-specific points, which we state to be accurate: the UCPA does not provide a right to correct your personal data, and the UCPA does not require us to offer a formal appeals process of the kind required by some other state laws. We do not sell your personal data and do not process it for targeted advertising; if that changes, we will provide a clear method to opt out.
Other US state laws. Residents of certain other US states may have comparable rights, which may include the rights to access, correct, delete, and obtain a portable copy of personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling in furtherance of decisions that produce legal or similarly significant effects. The specific rights, exceptions, and definitions vary by state and are provided to the extent the applicable state law grants them.
7.6 Appeals (US State Laws)
Where an applicable US state privacy law grants a right to appeal, if we decline to act on your request you may appeal our decision by emailing privacy@iownsoftware.com with the subject line "Privacy Rights Appeal" within the time permitted by that law. We will respond in writing to your appeal within the period required by the applicable law (generally 45–60 days), explaining the action we have taken or declined to take and our reasons. If your appeal is denied, you may contact the attorney general of your state to submit a complaint. As noted in Section 7.5, the Utah UCPA does not require this appeals process; where it does not apply, you may still raise concerns with us using the contact details above.
7.7 Summary of Rights by Framework
The following table is a convenience summary only; the operative rights and their conditions are set out in Sections 7.3–7.6 and in the applicable law.
| Right | EU / UK GDPR | California (CCPA/CPRA) | Utah (UCPA) | Certain other US states |
|---|---|---|---|---|
| Access / know | Yes | Yes | Yes | Yes |
| Correct / rectify | Yes | Yes | No | Varies |
| Delete / erase | Yes | Yes | Yes | Yes |
| Portability | Yes | Yes (via access) | Yes | Yes |
| Restriction | Yes | No | No | No |
| Object to processing | Yes | N/A | N/A | N/A |
| Opt out of sale / share | N/A | Yes (we do neither) | Yes (sale) (we do not sell) | Varies |
| Opt out of targeted advertising | N/A | Yes (as "sharing") | Yes | Varies |
| Opt out of / limit profiling | Yes (automated decisions) | Limited | No | Varies |
| Limit use of sensitive data | N/A | Yes (login credentials only) | N/A | Varies |
| Withdraw consent | Yes | N/A | N/A | Varies |
| Appeal a denial | N/A | N/A | No | Varies (often yes) |
| Complain to a regulator | Yes (ICO / EU authority) | Yes (CA AG / CPPA) | Yes (Utah AG) | Yes (state AG) |
Nothing in this Section limits any additional rights you may have under applicable law, and we will honor those rights to the extent they apply.
8. International Data Transfers
8.1 We are US-based. I Own Software LLC operates from the United States (Utah), and the personal data we process as a controller under this Privacy Policy — including website and analytics data, Customer account and billing data, Heartbeat Metadata received from all deployments (including Self-Hosted), opt-in support telemetry, and support communications — is generally stored and processed in the United States. Where we run the Hosted Service, the Control Server and associated data may be hosted with our cloud infrastructure providers across US and EU regions (see our sub-processor list at myremoting.iownsoftware.com/legal/subprocessors).
8.2 Transfers from the EEA, the United Kingdom, and Switzerland. When we receive personal data that is subject to the EU GDPR, UK GDPR, or Swiss data protection law and transfer it to a country that has not received an adequacy decision, we implement appropriate safeguards for that transfer. Depending on the data flow and the parties, we rely on one or more of the mechanisms below:
| Transfer mechanism | When we rely on it |
|---|---|
| EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), including the applicable modules | Transfers of personal data subject to the EU GDPR to us or to our sub-processors in third countries |
| UK International Data Transfer Addendum to the EU SCCs (IDTA / Addendum) | Transfers of personal data subject to the UK GDPR |
| Swiss addendum / adaptations to the EU SCCs | Transfers of personal data subject to Swiss data protection law |
| A recognized adequacy decision or other lawful transfer basis | Where the destination country benefits from an adequacy determination, or another valid basis under applicable law applies |
Where required, we also carry out and document a transfer risk assessment and adopt supplementary measures. Our technical and organizational safeguards for data in transit and at rest are described in Section 6 (Data Retention and Security) and, for the Hosted Service, in the DPA Annex of technical and organizational measures.
8.3 Hosted Service (processor) data. For personal data we process as a processor on behalf of a Customer through the Hosted Service (Operator account data, Endpoint inventory, session data and recordings, connection metadata, and agent-encrypted credential blobs), the cross-border transfer terms in the DPA govern, and the DPA incorporates the EU SCCs and the UK IDTA / Addendum as applicable. The DPA is published at myremoting.iownsoftware.com/legal/dpa. On any conflict about the processing of personal data in the Hosted Service, the DPA controls, and liability under the DPA remains subject to the limitation of liability and cap in the Agreement (Article 7).
8.4 Self-Hosted / On-Premises deployments. For Self-Hosted deployments, the Customer runs the Control Server and is the sole controller of all data it holds; we do not host, access, or receive that data. The only personal data flowing to us is Heartbeat Metadata (deployment identity, Software version, and counts) and any support telemetry the Customer affirmatively enables, which we process as an independent controller as described in this Privacy Policy. The Customer remains responsible for the lawfulness of any transfers within its own deployment.
9. Children's Privacy
The Software, the Hosted Service, and our websites are intended for business use by Operators and Customer personnel. They are not directed to children, and we do not knowingly collect personal data from children under the age of 16 (or such higher age as may apply under local law). If we learn that we have collected personal data from a child in circumstances that require consent we did not obtain, we will take reasonable steps to delete that data. If you believe a child has provided us with personal data, please contact us using the details in Section 12 so we can address it.
10. EU/UK Representative and Data Protection Officer
10.1 Article 27 Representative. We have not appointed a representative in the EU or the UK under Article 27 of the EU GDPR or the UK GDPR, having assessed that the obligation is not currently engaged (or that an exemption applies). You may contact us directly using the details in Section 12.
10.2 Data Protection Officer. We have not appointed a Data Protection Officer, having determined that we are not required to appoint one. You may direct data protection inquiries to the contact in Section 12.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Software, or applicable law. When we make changes, we will revise the "Last updated" / effective date at the top of this Privacy Policy and post the updated version at myremoting.iownsoftware.com/legal/privacy. If we make material changes, we will provide additional notice as appropriate — for example, by email to the Customer's account or billing contact or through a notice in the Software or on our websites — before the changes take effect, except where immediate application is required by law. Your continued use of the Software or services after the effective date of an updated Privacy Policy constitutes acceptance of the update to the extent permitted by applicable law. This Privacy Policy is incorporated by reference into the Usage and License Agreement (v2026.07).
12. How to Contact Us
For questions about this Privacy Policy or our handling of personal data, or to exercise your privacy rights, contact us at:
I Own Software LLC 321 N Mall Dr, Suite R259 Saint George, UT 84790, USA Email: privacy@iownsoftware.com
If you are located in the EEA, the United Kingdom, or Switzerland, you may also contact our Article 27 representative (where appointed) as set out in Section 10.1. You have the right to lodge a complaint with your local supervisory authority or data protection regulator, though we encourage you to contact us first so we can try to resolve your concern.