Legal

Privacy Policy

Effective 21 September 2026 · Version 1.0
Houston IT Developers LLC, Houston, Texas, United States

The short version

Remote Login is a business tool. Most of what it handles is not our data — it belongs to the IT provider or company using it, and we hold it on their behalf. We do not sell personal information, we do not use session content for advertising, and we do not train models on it. A remote support session is announced to the person at the device and recorded in an audit trail by design; that is a privacy feature, not a side effect.

Contents
  1. Who we are
  2. Controller and processor
  3. What we collect
  4. What a remote session captures
  5. Why we use it
  6. Legal bases (EEA/UK)
  7. Who we share it with
  8. What we never do
  9. How long we keep it
  10. Security
  11. International transfers
  12. Your rights
  13. US state privacy rights
  14. Cookies and this website
  15. Children
  16. Changes
  17. Contact

1Who we are

Remote Login is operated by Houston IT Developers LLC, a Texas limited liability company based in Houston, Texas, United States ("we", "us"). This policy explains how we handle personal information in connection with the Remote Login platform — the web application, technician console, device agents and installers, mobile applications, session relay and APIs (the "Service") — and this website.

This policy sits alongside our Terms of Service and Acceptable Use Policy.

2Controller and processor — which one we are matters

Remote Login is sold to businesses. There are two different relationships in play, and your rights run differently in each:

SituationOur roleWho to ask about your data
You are a customer — an MSP or IT team with an accountController of your account and billing dataUs, directly
Your device is supported by a provider using Remote LoginProcessor acting for that providerThat provider, in the first instance
You visit this marketing websiteControllerUs, directly

Where we act as a processor, we handle Customer Data only on the customer's documented instructions, and we will forward any request we receive to them rather than acting on it unilaterally. We will always help; we will not go around the account owner.

3What we collect

Account and contact data

Name, business email, phone number where given, company name, role, password hashes and multi-factor enrolment data, and the support correspondence you send us.

Billing data

Plan, seat counts, invoices and payment status. Card numbers are handled by our payment processor and never reach our servers; we store only the last four digits, card brand and expiry returned to us.

Device and session metadata

Data the agent reports about administered devices: hostname, operating system and version, hardware inventory, network addresses, agent version, connection state, and the start time, end time, participants and outcome of each session.

Technician activity and audit logs

Who signed in, from where, what they did, which device they connected to, what consent was given, and which files were transferred. This log exists so that access is accountable, and it is deliberately hard to alter.

Technical logs

IP address, user agent, request paths, timestamps and error traces from the web application and relay, retained for security, abuse prevention and debugging.

Website data

Standard server logs and, if we enable analytics, aggregate page-view data. This site does not carry advertising trackers.

4What a remote session captures — and what it does not

This is the part people actually want answered, so we will be specific.

During a remote session, screen contents, keyboard and mouse input and any transferred files pass through our relay so the technician can see and work on the device. Whatever is on that screen — a medical record, a bank statement, a private message — travels with it. Session traffic is encrypted in transit and is relayed rather than stored. We do not retain a video recording of the session unless session recording is switched on for that account, in which case the recording is Customer Data belonging to the account owner, stored under their retention setting, and available to them.

Consent

Attended sessions require the person at the device to accept a connection prompt, and the platform displays a visible session indicator while a technician is connected. Unattended access — used for servers and for maintenance outside business hours — is configured in advance by the account owner and is recorded in the same audit trail. Remote Login is not, and must not be used as, covert monitoring software. Section 5 of the Acceptable Use Policy is not decorative: accounts used for stalkerware are terminated.

5Why we use it

6Legal bases (EEA and UK)

Where the GDPR or UK GDPR applies and we act as controller, we rely on: contract (providing the Service you signed up for); legitimate interests (security, abuse prevention, product measurement, direct B2B communication about the Service) balanced against your rights; legal obligation (tax, accounting, lawful requests); and consent where we ask for it, which you may withdraw at any time without affecting prior processing.

7Who we share it with

We share personal information only with the following, and only as needed:

CategoryPurpose
Hosting and infrastructureRunning the application, database and session relay in our hosting provider's European and US data centres
Network and securityDNS, TLS, DDoS protection and WAF in front of our services
Payment processingTaking payment and issuing invoices
Email and support toolingTransactional mail, sign-in codes and support correspondence
Error and uptime monitoringDiagnosing failures and detecting outages
Professional advisersAccountants and lawyers, under duty of confidence

Each is bound by a written agreement limiting them to our instructions. We will also disclose information where legally compelled — and where we are permitted to tell you, we will. If we are ever party to a merger, acquisition or asset sale, information may transfer to the successor under this policy; we will give notice before it becomes subject to a materially different one. A current list of subprocessors is available from [email protected] on request.

8What we never do

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under US state privacy law. We do not use Customer Data or session content to train machine-learning models. We do not read customer sessions except where an account owner asks us to investigate a specific incident, or where we are legally compelled — and such access is itself logged.

9How long we keep it

DataRetention
Account and profileFor the life of the account, then deleted or anonymised within 90 days of closure
Session and audit logsPer the account's configured retention; 12 months by default
Session recordings, where enabledPer the account's configured retention; deleted with the account
Technical and security logsUp to 12 months
Billing and tax recordsAs required by law, generally 7 years
Support correspondenceUp to 3 years after the ticket closes

Backups roll off on their own schedule, so deleted data may persist in encrypted backups for a short period after deletion from the live systems.

10Security

We encrypt data in transit with TLS and encrypt data at rest. Access to production is restricted to named personnel, requires multi-factor authentication, and is logged. Technician access to devices requires account-level authorisation and is recorded. We review dependencies for known vulnerabilities and patch on a regular cadence.

No system is perfectly secure, and we will not claim otherwise. If we become aware of a breach affecting your personal information, we will notify the affected account owner without undue delay and, where required, the relevant supervisory authority.

11International transfers

We are based in the United States and operate infrastructure in the United States and the European Union. Using the Service may involve transferring personal information across borders. Where we transfer personal data out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary technical measures, including encryption in transit and at rest.

12Your rights

Subject to local law, you may request access to your personal information, correction of it, deletion of it, a portable copy, restriction of or objection to processing, and withdrawal of consent. You may also lodge a complaint with your supervisory authority — in the UK, the Information Commissioner's Office.

Email [email protected]. We respond within 30 days, and we may need to verify your identity first. If your data sits inside a customer's account, see section 2 — we will route your request to that customer and support them in answering it.

13US state privacy rights

Residents of Texas, California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have rights to know, access, correct, delete and obtain a portable copy of their personal data, and to appeal a refused request. We do not sell personal data or use it for targeted advertising, so there is nothing to opt out of on that front, but you may still exercise the other rights above at the same address. We will not discriminate against you for exercising them. If we deny a request, you may appeal by replying to our decision; we will respond to the appeal within 45 days.

14Cookies and this website

The application uses strictly necessary cookies for sign-in, session security and CSRF protection. You can block them, but you will not be able to sign in. This marketing website sets no advertising or cross-site tracking cookies. Fonts on this site are served by Google Fonts, which receives the request as a normal web request. We honour Global Privacy Control signals where the law requires it.

15Children

The Service is a business product and is not directed to children under 16. We do not knowingly collect their personal information. If you believe a child's information has reached us, write to us and we will delete it.

16Changes

We may update this policy. Material changes take effect 30 days after we post the revised version or notify account owners, whichever is earlier. The effective date at the top of this page always reflects the current version.

17Contact

Houston IT Developers LLC
Houston, Texas, United States
[email protected]