Privacy Policy
1. Who is responsible for your data
The data controller for RedeskPro is IncredibleIT, [legal form, e.g. PFA/SRL], registered in Romania, [registration number / CUI], registered office at [full address]. For anything related to this policy: privacy@redeskpro.com.
2. What we collect
We collect only what the Service needs to function:
| Data | Why we have it |
|---|---|
| Email address, password (hashed) | Account creation and login |
| Device name, code, OS version | So you can identify and connect to your own devices |
| MAC address of a device | Only if you use Wake-on-LAN — used to send the wake signal |
| Unattended-access password | Stored as a one-way hash, never in plain text — lets a device accept connections without manual approval |
| Small screen preview ("thumbnail") | Shown in your own device list so you can recognize a device at a glance — visible only to you and anyone you've explicitly granted access to |
| Connection history (who connected, when, for how long, IP address) | Shown to you as session history, and used to secure the Service against abuse |
| Permission settings | Enforces exactly what each person you share a device with is allowed to do |
3. Why we process it (legal basis)
- Performance of a contract — account data, device data, and permissions exist because they're required for the Service you signed up for to work at all.
- Legitimate interest — connection logs and IP addresses are kept to detect abuse, debug connection issues, and secure accounts.
- Consent — where required, e.g. optional analytics cookies (see our Cookie Policy) or marketing communications, which are opt-in only.
4. Screen, audio, and file data during a session
This is the part that matters most for a remote-desktop tool, so we're explicit about it:
- Live screen and audio streaming travels directly between the two devices (peer-to-peer) whenever a direct connection is possible. When it isn't, it's relayed through our TURN server in real time and is never written to disk or stored by us.
- Files transferred during a session go directly between the two devices and are never copied to our servers.
- Clipboard content syncs directly between devices, the same way.
- Chat messages sent during a session travel directly between devices and are not stored on our servers or persisted after the window closes.
- Session recordings, if you turn that feature on, are saved only to your own device — we never receive a copy.
The one exception is the small device thumbnail described above, uploaded periodically so device lists show a recognizable preview — this is a low-resolution still image, not a recording, and only applies to your own registered devices.
5. How long we keep it
- Account and device data: kept while your account is active, deleted within 30 days of account deletion
- Connection/session history: kept for [confirm retention period, e.g. 12 months] for security and support purposes, then deleted automatically
- Device thumbnails: overwritten on every update, deleted when the device is removed from your account
6. Who we share it with
We don't sell personal data. We share it only with:
- Infrastructure providers hosting our servers and database [name your VPS/hosting provider if you want to disclose it, or state "based in the EU/Romania"]
- People you explicitly grant access to — a device owner controls exactly who can connect and what they can do, via the permissions system
- Authorities, only where required by law
If you use RedeskPro to access devices belonging to your own customers (e.g. IT support), a separate Data Processing Agreement applies between you and us.
7. International transfers
Our infrastructure is hosted in [confirm country — e.g. Romania / EU]. If any data is ever processed outside the European Economic Area, we ensure an appropriate safeguard is in place (such as Standard Contractual Clauses) before that happens.
8. Security
Passwords and unattended-access passwords are stored as one-way hashes, never in plain text. Sessions are encrypted end-to-end via WebRTC (DTLS/SRTP). Access to account data on our servers is limited to what's needed to operate the Service. No system is 100% secure, and we'll notify affected users and the relevant authority without undue delay in the event of a breach affecting personal data, as required by law.
9. Your rights
If you're in the EU/EEA (or covered by similar law elsewhere), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion ("right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local data protection authority — in Romania, the National Supervisory Authority (ANSPDCP)
To exercise any of these, email privacy@redeskpro.com. Most account and device data can also be edited or deleted directly from the dashboard.
10. Children
RedeskPro isn't directed at children under 16. We don't knowingly collect personal data from children. If you believe a child has created an account, contact us and we'll remove it.
11. Changes to this policy
If we make material changes, we'll update the date at the top of this page and, where the change is significant, notify account holders by email.