Personal data · GDPR

Privacy policy

For the RDN Remote app and the remote support service. Last updated: .

This policy explains what personal data we process when you use the RDN Remote app or this website, why we process it, how long we keep it and what your rights are under Regulation (EU) 2016/679 (GDPR).

1. Who we are

Controller
Company details
The full company name, tax ID (CUI), trade register number and registered office are published in our shop: shop.rdndata.ro.
Email
Phone

RDN Remote subscriptions are bought from shop.rdndata.ro. The terms and conditions, the purchase agreement and the processing of billing data are those published there; this page complements the shop's policy for the data processed by the RDN Remote app.

2. What data we process

a) When you use the RDN Remote app

For the service to work and stay secure, the app sends our server the following technical data:

b) When you use the organization portal

For accounts in the management portal (remote.rdndata.ro/portal) we keep the email address, the name (if filled in), the role (administrator or view-only), the date of creation and of the last sign-in. The password is only stored as an irreversible hash. Settings made in the portal (device display names and their rights) are kept for as long as the license exists. The portal uses a single strictly necessary cookie, for the sign-in session, valid for 12 hours. Administrators of an organization only see the devices, sessions and accounts of their own license.

c) What we do not process

d) When you visit this website

The website uses no cookies, analytics or advertising and loads no third-party resources. The web server keeps no visitor logs. The IP address is used only technically, to deliver the page and the downloaded files.

3. Why and on what legal basis

PurposeLegal basis (GDPR)
Running the app and providing the remote support service you asked forPerformance of a contract or of steps taken at your request (Art. 6(1)(b))
Service security: detecting and blocking unauthorized access and password-guessing attempts, investigating incidentsOur legitimate interest, and that of our customers, in protecting their computers (Art. 6(1)(f))
Keeping a record of support work for customers and handling complaintsPerformance of a contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f))
Complying with legal obligations, for example at the request of the authoritiesLegal obligation (Art. 6(1)(c))

4. How long we keep the data

The session log, security events and device data are deleted automatically 180 days after they were recorded or, for devices, after their last connection. We may keep them longer only when they are needed for an ongoing security incident or complaint, and only for as long as it lasts.

5. Who has access to the data

6. When we provide support to a company

If we support you as an employee or contractor of a company that has a contract with us, that company is the controller of the data on your computer, and we act as its processor (Art. 28 GDPR), under the contract signed with the company.

7. Your rights

You have the right of access to your data, to rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interest. To exercise any of them, write to us at . We answer within one month.

You can lodge a complaint with the Romanian data protection authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest, www.dataprotection.ro, or with the data protection authority of the EU country where you live.

8. How we protect the data

9. Changes

We may update this policy when the service or the law changes. The version in force is always the one on this page, with the date of the last update shown above. The Romanian version of this policy prevails if the two differ.