SV_REMOTE / PRIVACY
sv_remote product privacy notice
Product-specific GDPR transparency for the controlled B2B pilot. This notice supplements the general Service IT privacy notice.
Version 2026-08-23-pilot · 23.08.2026
1. Controller and roles
For Service IT's own pilot onboarding, contract administration, security operation and direct support relationship, the controller is Service IT, Einzelunternehmen, proprietor Serhii Yanov, Paul-Gossen-Str. 89, 91052 Erlangen, Germany; s@st-in.eu; +49 9131 9185513.
When a business customer determines why remote support is carried out for its employees, contractors, customers or managed devices, that customer normally acts as controller and Service IT processes control-plane metadata on documented instructions as processor. A project-specific Data Processing Addendum is required before production personal-data processing. Actual roles depend on the facts.
2. Data processed
The service can process business contact data; random public device ID; device public key, display name and platform; pairing relationships, folders and aliases; heartbeat, presence and last-seen time; source IP, protocol timestamps, rate-limit and relay metadata; session request/decision/end state; consent decision; audit, support and incident records.
A device ID is an address, not a password or proof of authority. Device private keys remain in Windows DPAPI or Android Keystore-backed storage and are not sent to the control plane.
3. Screen content
After explicit local approval and the operating-system capture prompt, the target encrypts screen frames between the participating endpoints before direct or relay transport. The control plane, STUN and TURN/relay are not given the content key and are not designed to decrypt the screen.
Endpoints necessarily handle the clear image in memory. No server-side recording is enabled. The pilot has no remote input, clipboard, file transfer, audio capture or unattended access.
4. Purposes and legal bases
Processing supports device authentication, pairing, presence, short-lived sessions, encrypted relay fallback, abuse prevention, support, audit, legal duties and pilot administration. Service IT relies as applicable on Article 6(1)(b), (c) and (f) GDPR, and on Article 6(1)(a) only for genuinely optional consent-based processing.
For customer-controlled support, the customer selects and documents the legal basis and provides transparency. The local Continue action is a technical authorization for one session, not blanket GDPR consent or permission for employee surveillance.
5. Recipients and transfers
Authorized Service IT personnel access only necessary metadata. The isolated pilot VPS in Germany is provided by Contabo GmbH. Internet carriers and customer network providers transport encrypted packets and related IP metadata. The clients contain no advertising network, behavioral analytics SDK or data broker.
No transfer outside the EEA is intended. A future transfer requires a documented mechanism and assessment before activation.
6. Retention
Pairing codes expire after five minutes; only a hash is stored and expired rows are purged within about 24 hours. Undecided session requests expire after 120 seconds. Session tickets and relay credentials expire within the configured maximum of 15 minutes; Redis presence and signalling state is short-lived.
Session metadata, source IP and audit events are kept for up to 180 days. Device/link/tree metadata remains until deletion, revocation or relationship end; residual encrypted backup data is targeted for overwrite within 30 additional days. Statutory business records follow German retention law.
7. Rights, security and contact
Depending on the GDPR, data subjects may request access, rectification, erasure, restriction, portability and objection and may complain to a supervisory authority. Requests go to s@st-in.eu. If Service IT acts only as processor, it forwards the request to the customer controller and assists under the DPA.
Security includes signed devices, protected keys, one-time pairing, short-lived tickets, rate limits, encrypted transport, E2E screen frames, explicit target approval, a permanent indicator/Stop, isolation and audit. No automated Article 22 decision or AI profiling is used.