Privacy Policy
This policy explains what personal information ITSupport RMM collects, why, how long we keep it, and the rights you can exercise. It is written to be read, not to be impenetrable.
1. Short summary
- This website runs no analytics scripts, no advertising pixels and no third-party trackers, and sets no advertising cookies.
- We do not sell or share personal information as those terms are defined under California law, and we do not transfer personal information to advertising networks.
- The contact form on this site opens your own email client. It does not submit data to a server we operate.
- For platform customers, we act as a service provider / processor for the operational data you place in the platform, and we process it to deliver the service you purchased.
- For US accounts, platform data is processed and stored in United States data center regions.
2. Information we collect
2.1 Information you send us directly
When you contact us by email, phone or through the form on our Contact page, we receive the information you choose to provide: your name, work email address, telephone number, company name, approximate endpoint count, state or time zone, and the content of your message. We ask you not to include passwords, payment card numbers, health information or other sensitive data in an initial inquiry, and the form states this.
2.2 Website server logs
Our web hosting infrastructure records standard technical information when a page is requested: IP address, timestamp, requested URL, HTTP status, referring URL where sent by your browser, and user-agent string. These logs exist for security, abuse prevention and troubleshooting. They are not used to build advertising or behavioral profiles.
2.3 Account and billing information
If you become a customer, we process business contact details for authorized users, billing contact information, billing address, purchase order references where applicable, and transaction records. Card payments are processed by a payment provider; we receive confirmation and limited identifiers, not your full card number.
2.4 Platform data (where we act as processor)
When you use the ITSupport RMM platform, the agent and console generate and store operational data about the devices you manage, which may include device names, hardware and software inventory, performance telemetry, patch state, selected event log entries, logged-on user names, script output you configure to be captured, remote session metadata, and audit records of actions taken by your users. You determine what is collected through your policy configuration. We process this data on your behalf to provide the service, to support you, to maintain security, and to meet legal obligations.
2.5 What we do not collect
We do not operate keystroke logging, continuous screen capture outside a technician-initiated session, browsing history collection, or content scanning of documents and email. We do not purchase personal information from data brokers, and we do not collect information for advertising purposes.
3. How we use information
- To respond to inquiries and provide quotes, demos, trials and technical answers.
- To provide and operate the service you purchased, including support, incident response and platform maintenance.
- To bill you and maintain accounting and tax records required by US law.
- To secure the platform: detect abuse, investigate suspected unauthorized access, and maintain audit trails.
- To communicate service information: maintenance notices, security advisories, material changes to policies, and release notes. These are operational messages, not marketing.
- To send optional product updates only where you have asked for them; every such message includes an unsubscribe mechanism and unsubscribing never affects your service.
- To comply with law and to establish, exercise or defend legal claims.
We do not use your platform data to train generalized machine learning models, and we do not use it for advertising, profiling or resale.
4. Legal bases (for visitors in the EU, EEA and UK)
Our services are directed at the United States market, but this website is reachable internationally. Where the GDPR or UK GDPR applies to our processing, we rely on: contract (Art. 6(1)(b)) to provide services you have requested; legitimate interests (Art. 6(1)(f)) for security, abuse prevention, and responding to business inquiries; consent (Art. 6(1)(a)) for optional communications you opt into; and legal obligation (Art. 6(1)(c)) for accounting, tax and lawful requests. You may object to processing based on legitimate interests as described in section 8.
5. When we disclose information
We disclose personal information only in these circumstances:
- Service providers (sub-processors) who help us operate: cloud infrastructure and data center hosting, email delivery, payment processing, and accounting. Each is bound by contract to process data only on our instructions, with confidentiality and security obligations. A current list of sub-processors, including their function and processing location, is available on request at Info@itsupport-rmm.com, and material additions are notified to customers in advance.
- Professional advisors (legal, audit, insurance) where necessary and under confidentiality.
- Legal compliance: where required by valid legal process. We review requests for validity and scope, and where we are legally permitted to do so we notify the affected customer before disclosing.
- Business transfer: if the business or part of it is sold or reorganized, information may transfer as part of that transaction, subject to this policy. Customers would be notified.
We never sell personal information, never rent contact lists, and never provide personal information to advertising networks, data brokers or lead-generation resellers.
6. Retention
| Category | Retention |
|---|---|
| Website server logs | 90 days |
| Inquiry correspondence (email records) | 24 months from last contact, unless you ask for earlier deletion |
| Trial account data | Deleted within 30 days after trial expiry if you do not purchase |
| Platform telemetry (raw / aggregated) | 30 days / 13 months |
| Inventory, alert history | 13 months of history |
| Script output | 90 days |
| Session metadata and audit logs | 12 months (Core), 24 months (Professional), custom (Enterprise) |
| Account, billing and tax records | As required by US federal and state law, generally 7 years |
| Customer data after termination | Available for export for 30 days, then deleted within 60 days unless law requires retention |
7. How we protect information
Security measures include TLS 1.2 or higher for data in transit, encryption at rest for stored data, application-level encryption for credential vault entries, mandatory multi-factor authentication for platform console users, role-based access control with least-privilege defaults, tenant isolation enforced at the data layer, append-only audit logging, restricted and logged administrative access to production systems, change review before release, and documented backup and incident response procedures. Details are on our Security & Compliance page. No system can be guaranteed absolutely secure; if an incident affects your data we will notify the account's designated contacts without undue delay and in accordance with applicable US state breach notification laws.
8. Your rights and how to exercise them
To make any request, email Info@itsupport-rmm.com with the subject line "Privacy request", or call +1 717 823 6666, or write to ITSupport RMM, 401 W Lemon St, Lancaster, PA 17603, United States. We respond within 45 days for California requests (extendable once by a further 45 days with notice) and within 30 days for GDPR requests. We verify requests by confirming control of the email address on file or, for platform accounts, through the account's authorized contact. We do not charge a fee, and we do not discriminate against anyone for exercising a privacy right.
8.1 Your California privacy rights (CCPA / CPRA)
If you are a California resident you have the right to: know what personal information we have collected, the categories of sources, the purposes, and the categories of third parties to whom it was disclosed; access a copy of that information in a portable format; delete personal information, subject to legal exceptions; correct inaccurate personal information; opt out of sale or sharing for cross-context behavioral advertising; and limit the use of sensitive personal information.
Do Not Sell or Share My Personal Information. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. Because we run no advertising or analytics trackers on this website, we also do not process opt-out preference signals such as Global Privacy Control for advertising purposes — there is no such processing to disable. If that ever changes, this policy will be updated before the change takes effect and customers will be notified.
Categories of personal information collected in the last 12 months, using CCPA categories: identifiers (name, email, phone, IP address); commercial information (subscription and transaction records); internet or network activity (server logs, platform audit records); professional or employment-related information (company, job context you provide); and geolocation only at the coarse level implied by IP address. We collect no sensitive personal information for the purpose of inferring characteristics, and we do not knowingly collect personal information from anyone under 16.
You may use an authorized agent to submit a request; we will require written authorization and verification of your identity.
8.2 Rights under the GDPR and UK GDPR
Where the GDPR or UK GDPR applies, you have rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent where consent is the basis. You may lodge a complaint with your supervisory authority. Because we are established in the United States, transfers of personal data to us from the EEA or UK are made on the basis of the European Commission's Standard Contractual Clauses, or the UK Addendum where applicable, together with the supplementary measures described in section 7. We will provide the relevant clauses on request.
8.3 Other US states
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others as they take effect, may exercise the access, correction, deletion, portability and opt-out rights those laws provide, and may appeal a refused request by replying to our response with the subject line "Privacy appeal".
9. Controller and processor roles
For our own website visitors, prospects and billing contacts, we act as the controller (or "business" under California law). For the operational data our customers place in the platform about their own devices and end users, the customer is the controller and we act as the processor / service provider. If you are an end user whose employer or IT provider manages your device with ITSupport RMM and you want to exercise rights over that data, contact your employer or provider; we will assist them in responding. A data processing agreement is available for customers who require one, and is incorporated into Enterprise agreements on request.
10. Cookies and browser storage
This website uses only strictly necessary browser storage: a single localStorage entry recording that you dismissed our storage notice, and, on the Pricing page, in-page values for the cost estimator that never leave your browser. No advertising, analytics or cross-site tracking technology is present. Details are in the Cookie Policy. The authenticated platform console uses a session cookie strictly necessary for keeping you logged in.
11. Children
Our services are business-to-business tools sold to organizations. They are not directed at children, and we do not knowingly collect personal information from children under 13, nor from anyone under 16 for the purposes of sale or sharing. If you believe a child has provided us information, contact us and we will delete it.
12. Links to other sites
Where this site links to an external resource, that site's own privacy practices apply. We do not embed third-party content that tracks you across sites, and we do not include social media widgets or advertising frames on any page.
13. Changes to this policy
If we change this policy we will update the "Last updated" date above, and for material changes affecting customers we will provide notice by email at least 30 days before the change takes effect. Previous versions are available on request.
14. How to contact us about privacy
ITSupport RMM — Privacy
401 W Lemon St
Lancaster, PA 17603
United States
Phone: +1 717 823 6666
Email: Info@itsupport-rmm.com (subject line: "Privacy request")
We aim to resolve every concern directly. If you are not satisfied with our response, you may contact your state attorney general, or your data protection supervisory authority if you are in the EEA or UK.