Data Processing Agreement

Last updated: September 3, 2026

This page is a standard-form template describing the terms we apply when processing personal data on your behalf. If your organisation requires a countersigned DPA (common for Business-tier and enterprise customers), email legal@remoteai.pro and we will issue an executable copy.

1. Scope & Roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between RemoteAI ("Processor") and the customer organisation ("Controller") and applies whenever RemoteAI processes personal data on the Controller's behalf in connection with the Service, in accordance with Article 28 of the General Data Protection Regulation (GDPR) and equivalent UK GDPR provisions.

2. Subject Matter & Duration

Processing is carried out for the duration of the Controller's subscription to the Service, for the purpose of providing remote device access, file transfer, and related functionality described in our Terms of Service.

3. Categories of Data Subjects & Personal Data

Data Subjects

The Controller's authorised users (employees, contractors, or team members).

Personal Data

Account identifiers (email address), device identifiers, connection and audit logs, and — where the Controller enables it — device telemetry (CPU/RAM/disk usage, online status). As described in our Privacy Policy, screen content, clipboard data, file contents, and keyboard/mouse input are end-to-end encrypted and are not accessible to RemoteAI as plaintext, so they do not constitute personal data we can process, view, or disclose.

4. Processor Obligations

RemoteAI, as Processor, shall:

  • Process personal data only on the Controller's documented instructions, including with regard to international transfers
  • Ensure personnel authorised to process personal data are bound by confidentiality
  • Implement appropriate technical and organisational security measures (see Section 5)
  • Assist the Controller in responding to data subject requests, to the extent the Service allows
  • Notify the Controller without undue delay after becoming aware of a personal data breach
  • Delete or return all personal data at the end of the engagement, at the Controller's choice, except where retention is required by law
  • Make available information necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice and confidentiality

5. Security Measures

Technical and organisational measures currently in place include:

  • End-to-end AES-256-GCM encryption with X25519 ECDH key exchange for all remote session data (screen, clipboard, files, input)
  • TLS 1.2+ for all data in transit to our servers
  • Password hashing (BCrypt), encrypted storage of sensitive fields (e.g. TOTP secrets)
  • Role-based access control, two-factor authentication, and audit logging
  • Rate limiting and abuse-prevention controls on all authentication and data-access endpoints

Full detail is in our Security & Responsible Disclosure Policy.

6. Sub-processors

The Controller authorises RemoteAI to engage the following categories of sub-processor:

  • Cloud infrastructure & database hosting — for application hosting and data storage
  • Payment processing (Razorpay for India, Stripe for global/EUR) — for billing account identifiers and subscription data only
  • Push notification delivery (Firebase Cloud Messaging) — device push tokens only
  • Transactional email delivery — for account and billing notifications

RemoteAI imposes data protection obligations on sub-processors substantially equivalent to those in this DPA, and remains liable to the Controller for a sub-processor's performance. We will notify Controllers of any intended change to sub-processors so they may object on reasonable grounds.

7. International Transfers

Where personal data is transferred outside the EEA or UK, RemoteAI relies on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or another lawful transfer mechanism, as applicable.

8. Liability

Liability under this DPA is subject to the limitation of liability set out in our Terms of Service.

9. Contact

For a countersigned DPA, sub-processor list updates, or any question about this Agreement, contact legal@remoteai.pro.