This policy explains what personal data we process when you use the RDN Remote app or this website, why we process it, how long we keep it and what your rights are under Regulation (EU) 2016/679 (GDPR).
1. Who we are
- Controller
- Company details
- The full company name, tax ID (CUI), trade register number and registered office are published in our shop: shop.rdndata.ro.
- Phone
RDN Remote subscriptions are bought from shop.rdndata.ro. The terms and conditions, the purchase agreement and the processing of billing data are those published there; this page complements the shop's policy for the data processed by the RDN Remote app.
2. What data we process
a) When you use the RDN Remote app
For the service to work and stay secure, the app sends our server the following technical data:
- about the device: the RDN Remote ID, the computer name, the name of the user signed in to the system, the operating system, the processor type and amount of memory, the app version;
- about the connection: the public IP address, the date and time when the app is started or online;
- remote support session log: the IP address the connection came from, the ID and name of the device that connected, the session type (control, file transfer, terminal), the authentication method, the start and end time, the number of files transferred;
- security events: failed connection attempts, automatic lockouts after repeated wrong passwords and the IP addresses involved;
- the license: the license code, the name of the customer it was issued to, the devices it is activated on (ID and computer name), the date of activation and of the last check, and the connection and bandwidth limits of the subscription. For licenses bought from the shop we also keep the order number, the email address and the billing name or company, so we can extend the same license on renewal.
b) When you use the organization portal
For accounts in the management portal (remote.rdndata.ro/portal) we keep the email address, the name (if filled in), the role (administrator or view-only), the date of creation and of the last sign-in. The password is only stored as an irreversible hash. Settings made in the portal (device display names and their rights) are kept for as long as the license exists. The portal uses a single strictly necessary cookie, for the sign-in session, valid for 12 hours. Administrators of an organization only see the devices, sessions and accounts of their own license.
c) What we do not process
- The session content (the screen image, keystrokes, files and clipboard) is end-to-end encrypted between your computer and the technician's. Our server only relays the encrypted data and has no access to it. The technician sees your screen only during the session, with your consent.
- Our server does not record sessions. Video recording of a session can only be started by the person in control, in their own app, and is saved on their computer; whoever uses this feature is responsible for informing the person whose screen they record.
- We do not store access passwords. The one-time password shown by the app expires after use.
d) When you visit this website
The website uses no cookies, analytics or advertising and loads no third-party resources. The web server keeps no visitor logs. The IP address is used only technically, to deliver the page and the downloaded files.
3. Why and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Running the app and providing the remote support service you asked for | Performance of a contract or of steps taken at your request (Art. 6(1)(b)) |
| Service security: detecting and blocking unauthorized access and password-guessing attempts, investigating incidents | Our legitimate interest, and that of our customers, in protecting their computers (Art. 6(1)(f)) |
| Keeping a record of support work for customers and handling complaints | Performance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations, for example at the request of the authorities | Legal obligation (Art. 6(1)(c)) |
4. How long we keep the data
The session log, security events and device data are deleted automatically 180 days after they were recorded or, for devices, after their last connection. We may keep them longer only when they are needed for an ongoing security incident or complaint, and only for as long as it lasts.
5. Who has access to the data
- Only authorized staff of , for the purposes above.
- Administrators appointed by the company that holds the license, in the organization portal, and only for that license's devices and sessions.
- The server is run by us, on our own infrastructure, and we do not transfer the data outside the European Economic Area.
- We do not sell or rent the data. We may disclose it to the authorities only when the law requires us to.
6. When we provide support to a company
If we support you as an employee or contractor of a company that has a contract with us, that company is the controller of the data on your computer, and we act as its processor (Art. 28 GDPR), under the contract signed with the company.
7. Your rights
You have the right of access to your data, to rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest. To exercise any of them, write to us at . We answer within one month.
You can lodge a complaint with the Romanian data protection authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest, www.dataprotection.ro, or with the data protection authority of the EU country where you live.
8. How we protect the data
- end-to-end encryption of sessions and a server that only accepts our own apps;
- automatic blocking of IP addresses after repeated wrong passwords and monitoring of access attempts;
- an administration panel available only to authorized staff, protected by a password and a two-step verification code;
- organization portal accounts have passwords stored only as hashes and are locked temporarily after repeated failed attempts;
- automatic deletion of logs after the retention period.
9. Changes
We may update this policy when the service or the law changes. The version in force is always the one on this page, with the date of the last update shown above. The Romanian version of this policy prevails if the two differ.
RDN REMOTE