Skip to content

NEW  Coming soon: ask your fleet a question and get an answer — an MCP server for AI.  Read more →

Legal

Data Processing Addendum

Effective July 17, 2026

1. Introduction

This Data Processing Addendum (“DPA”) supplements your Remote.It Terms of Use (the “Agreement”) and forms part of your contractual relationship with remot3.it, Inc. (“Remote.It”). Applicable Data Protection Law means all applicable laws relating to privacy, data protection, and information security, including but not limited to the EU General Data Protection Regulation (GDPR), the UK GDPR, the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and any successor legislation.

This DPA becomes binding upon your acceptance of the Terms of Use or execution of a separate agreement with Remote.It. You must be an authorized representative of a legal entity to enter into this DPA.

2. Definitions

The following definitions apply:

  • Applicable Law: As set forth in Section 1.
  • Controller: The entity that determines the purposes and means of the processing of Personal Data.
  • Processor: The entity that processes Personal Data on behalf of the Controller.
  • Data Subject: A natural person whose Personal Data is processed.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on Personal Data.
  • Sub-processor: A third-party processor engaged by Remote.It to process data on behalf of the Controller.

3. Artificial Intelligence

With respect to any optional AI-enabled features of the Services:

  • Remote.It does not use Customer Personal Data or Customer Content to train artificial intelligence or machine learning models.
  • Remote.It does not disclose Customer Personal Data to third-party AI providers unless expressly configured or authorized by the Customer.
  • Customers may elect to disable optional AI-enabled features.

4. Roles of the Parties

4.1 Controller and Processor

For Business customers, you act as the Data Controller, and Remote.It acts as the Data Processor with respect to the Personal Data processed to provide the Services. Remote.It processes Personal Data only on your documented instructions, except where processing is required by applicable law.

For Individual users, Remote.It acts as the Data Controller for Personal Data processed for account registration, account administration, billing, fraud prevention, security monitoring, legal compliance, and other purposes described in the Remote.It Privacy Policy.

4.2 Limited Controller Activities

In limited circumstances, Remote.It acts as an independent Data Controller with respect to Personal Data processed for its own legitimate business purposes, including account administration, billing, fraud prevention, platform security, legal compliance, service analytics, and improvement of the Services, as described in the Remote.It Privacy Policy.

Where Remote.It acts as an independent Data Controller, it determines the purposes and means of such processing and complies with its obligations under Applicable Data Protection Law.

4.3 Customer’s Obligations

You confirm that:

  • You have the legal right to provide Personal Data to Remote.It;
  • You provide documented instructions;
  • You have obtained all necessary consents under GDPR.

4.4 Processing by Remote.It

Remote.It agrees to:

  • Process Personal Data only on documented instructions;
  • Ensure personnel are subject to confidentiality obligations;
  • Assist the Controller in fulfilling obligations under Articles 32 to 36 GDPR;
  • Make available audit documentation annually upon request and under NDA;
  • Support responses to Data Subject Rights requests (see Section 5).

4.5 Confidentiality

Remote.It shall ensure that all personnel authorized to process Personal Data are bound by written confidentiality obligations and receive appropriate privacy and security training. Access to Personal Data is limited to personnel who require such access to perform their assigned responsibilities and is granted in accordance with the principle of least privilege.

Remote.It shall take reasonable steps to ensure that authorized personnel understand and comply with their obligations under this DPA and Applicable Data Protection Law.

4.6 Details of Processing

See Schedule A.

5. Data Subject Rights

Remote.It will assist you in responding to Data Subject requests (access, correction, deletion, restriction, portability, objection) in accordance with GDPR Articles 12–23. Remote.It will notify you of any requests received unless prohibited by law.

Remote.It does not intentionally inspect or retain Customer Content transmitted through the Services as part of normal platform operation except where expressly authorized by the Customer or required by law.

See the Privacy Policy for detailed procedures.

6. Sub-processors

6.1 Authorization. You authorize Remote.It to engage Sub-processors as necessary to provide the Services.

6.2 Obligations. All Sub-processors are bound by written agreements with data protection obligations equivalent to this DPA. Remote.It remains liable for their actions.

6.3 Current Sub-processors. See Schedule C.

6.4 Changes & Objection Rights. Remote.It will provide at least 30 days’ notice before adding new Sub-processors. You may object on reasonable grounds. If an objection is unresolved, either party may terminate the affected Services.

7. Security Measures

7.1 Remote.It implements appropriate technical, organizational and administrative safeguard measures (see Schedule B) in accordance with Article 32 GDPR.

7.2 Remote.It will notify the Customer without undue delay after becoming aware of a Personal Data Breach and, where feasible, within seventy-two (72) hours.

8. Return or Deletion of Data

Upon termination of the Services, Remote.It will delete all Personal Data within 30 days unless retention is required by law or authorized by the customer.

9. International Transfers

Remote.It may transfer Personal Data outside the European Economic Area (“EEA”) where necessary to provide the Services. Where Personal Data is transferred to a country that has not been recognized as providing an adequate level of protection under Applicable Data Protection Law, Remote.It will implement appropriate safeguards in accordance with Article 46 of the GDPR, including the European Commission’s Standard Contractual Clauses (including any successor or replacement versions) or other legally approved transfer mechanisms.

10. Audit Rights

You may audit Remote.It’s compliance with this DPA provided such audit does not unreasonably interfere with Remote.It’s operations or compromise the security of other customers:

  • Once annually with at least 30 days’ notice;
  • Or in the event of a security incident or regulatory request;
  • At your own expense, using an independent auditor under confidentiality.

11. Term and Termination

This Data Processing Addendum remains in effect for the duration of the Agreement under which Remote.It processes Personal Data on your behalf.

Upon termination or expiration of the Agreement, Remote.It will cease processing Personal Data except as necessary to comply with applicable law, fulfill outstanding legal obligations, or as otherwise authorized by this DPA.

The obligations relating to confidentiality, security, data deletion or return, liability, audit rights, and any other provisions that by their nature are intended to survive termination shall remain in effect following termination of this DPA.

12. Liability

Each party’s liability arising under or in connection with this Data Processing Addendum shall be governed by the limitations of liability and exclusions set forth in the underlying Agreement.

Nothing in this Data Processing Addendum shall be interpreted to expand, increase, or otherwise modify either party’s liability beyond that provided in the Agreement, except to the extent such limitation or exclusion is prohibited by Applicable Data Protection Law, including Article 82 of the General Data Protection Regulation (GDPR), the UK GDPR, or any equivalent mandatory provision of applicable law.

Nothing in this Data Processing Addendum shall limit, restrict, or waive any rights or remedies available to Data Subjects or Supervisory Authorities where such rights cannot be limited or excluded by Applicable Data Protection Law.

13. Governing Law and Jurisdiction

This DPA is governed by the laws of California, USA. However, EEA-based Controllers and Data Subjects retain the right to seek remedies in their home jurisdictions as required by GDPR.

14. Exercising Your Rights

To exercise your GDPR rights, contact:

  • Email: legal@remote.it
  • Address: remot3.it, Inc., 1309 Ross Street, Suite A, Petaluma, CA 94954, United States

You may be asked to verify your identity and provide details to support your request.

15. Updates to This DPA

Remote.It may update this DPA to reflect legal or service changes. We will provide notice of material updates. Continued use of the Service after updates constitutes acceptance.

Schedule A: Details of Processing

  • Subject Matter: Providing connectivity and network access Services
  • Duration: Duration of Agreement + 30-day retention
  • Categories of Data: Email address, unique user and device identifiers, transaction IDs
  • Data Subjects: End users of paid and unpaid Remote.It accounts
  • Purpose: Managing device connectivity and account identity verification

Schedule B: Security Measures

Technical and organizational security measures include:

  • Physical and logical access controls
  • Encrypted data at rest and in transit
  • Role-based access management
  • Logging and monitoring
  • Intrusion detection
  • Business continuity and disaster recovery procedures
  • Regular vulnerability assessments

Schedule C: Sub-Processors

Remote.It uses the following Sub-processors:

Sub-processorService providedLocation of sub-processor
Amazon Web ServicesCloud servicesUnited States of America
GoogleCloud services and analyticsUnited States of America
StripePayment TransactionsUnited States of America
HubSpotMarketing & Sales CommunicationsUnited States of America
MicrosoftCloud services and analyticsUnited States of America
ZendeskSupportUnited States of America
Search articles