Data Processing Agreement
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Controller", "you") and IncredibleIT ("Processor", "we") governing use of RedeskPro. It applies whenever, in the course of using the Service, personal data of your own end users or customers is processed by RedeskPro on your behalf — for example, when you connect to a client's computer for remote support and that session incidentally involves personal data visible on their screen.
This DPA does not apply to IncredibleIT's processing of your own account data as a RedeskPro customer, which is governed by our Privacy Policy.
2. Subject matter and duration
The subject matter is the provision of remote desktop connectivity that may incidentally transmit personal data between devices at your direction. This DPA remains in effect for as long as we process personal data on your behalf under the Service, and terminates automatically when your account is closed and all such data has been deleted in accordance with Section 11.
3. Nature and purpose of processing
Processing consists of the real-time transmission of screen, audio, clipboard, and file data between devices you control, strictly for the purpose of enabling the remote session you initiate. RedeskPro's infrastructure does not inspect, analyze, or store the content of these transmissions — see Section 4 of our Privacy Policy for the technical detail of what is (and isn't) retained.
4. Categories of data and data subjects
| Category of data | Data subjects |
|---|---|
| Any personal data visible on a controlled screen during a session (e.g. documents, emails, application data) | Your customers, employees, or other individuals whose devices you access |
| Files transferred during a session | Same as above |
| Connection metadata (timestamps, IP address, device identifiers) | The individual operating the connected device |
You are responsible for having a valid legal basis to access each device and for informing the relevant individuals as required under your own obligations as controller.
5. Processor obligations
As processor, IncredibleIT will:
- Process personal data only on your documented instructions (i.e., the connections and actions you initiate through the Service)
- Ensure personnel authorized to process personal data are bound by confidentiality
- Implement appropriate technical and organizational security measures (Section 7)
- Not engage a new sub-processor without informing you in advance where required (Section 6)
- Assist you in responding to data subject requests and regulatory obligations (Section 8)
- Delete or return personal data at the end of the provision of services (Section 11)
- Make available information necessary to demonstrate compliance with this DPA (Section 10)
6. Sub-processors
You authorize IncredibleIT to engage the following categories of sub-processors: infrastructure/hosting providers and TURN relay operators necessary to operate the Service. [List actual named sub-processors here, e.g. your VPS/hosting provider, once finalized.] We'll provide reasonable advance notice of any new sub-processor with material access to personal data, giving you the opportunity to object.
7. Security measures
IncredibleIT maintains technical and organizational measures appropriate to the risk, including: encryption of session data in transit (WebRTC DTLS/SRTP), password hashing (never stored in plain text), access controls limiting who can view account data, and the architectural design that keeps session content (video, audio, files, clipboard, chat) off our servers entirely wherever a peer-to-peer connection is possible.
8. Assistance with data subject rights
Given the nature of the Service — RedeskPro has no visibility into session content — most data subject requests concerning what happened during a session will need to be answered by you directly, since you control the access. We will assist, to the extent reasonably possible, with requests concerning data we do hold (see our Privacy Policy, Section 2).
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, providing the information reasonably available to us to help you meet your own notification obligations under GDPR Article 33/34.
10. Audits
On reasonable written request, no more than once per year (except following a breach), IncredibleIT will make available information necessary to demonstrate compliance with this DPA. [Specify audit mechanics — e.g. questionnaire-based review vs. on-site audit — once finalized; on-site audits at a shared-infrastructure provider are often impractical and can be replaced with independent certifications if/when obtained.]
11. Deletion or return of data
Since session content generally isn't stored by IncredibleIT (Section 3), this primarily concerns account and connection-log data. Upon termination of your account, this data is deleted or anonymized per the retention terms in our Privacy Policy.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms & Conditions, except where such limitation is not permitted under applicable data protection law.
13. Contact
For a signed copy of this DPA for your records, or questions about it: privacy@redeskpro.com.