Remote Monitoring, Access and Control Privacy Notice
Introduction
Revell Research Systems Limited
(the Company, we, us, our)
is providing you with this information in order to comply with the Data Protection Act 2018
and the UK General Data Protection Regulation
(UK GDPR), which require us to
tell you what we do with your personal information.
This notice explains how we collect, use, store and protect personal data processed through
our remote monitoring, access and control systems.
Your personal data may be automatically captured by our remote monitoring, access
and control systems if you work for or on our behalf or that of a client or otherwise
use or interact with our or a client's systems where we have been authorised to
use these systems. We only use remote monitoring, access and control systems where we have
been authorised to do so by the system owner or another person with appropriate authority.
Our remote access and control systems may require the intervention of a user to
establish a session with their device or the owner may have authorised permanent
unattended access to it. The latter is always the case for remote monitoring operations.
Our systems monitor equipment belonging to us or our clients (where this has been
agreed) 24/7, continuously logging and reporting on various aspects of their use.
This includes how and when they are used and by whom based on user credentials.
The technical data logged may include IP addresses
involved, date and time as well as telemetric data such as processor utilisation, bandwidth
consumption, storage use, system access and session durations.
These systems log the access of technical staff to remote systems recording who
accessed what from where and when as well as for how long. The technical data logged
includes IP addresses involved, user credentials,
date and time. The record may include a detailed log of activity undertaken during the session,
including what systems, resources or information were accessed, and may capture text, video
or audio exchanged with the device's user or other personnel using the system, together with
screenshots or video recordings of the session.
Equipment users should be aware that our technical staff have access to the user's
screen, mic, camera and all storage on or accessible by the device. These tools can potentially
record traffic to and from a device and record device screens and activity. Consequently,
any accessible or visible personal data may be captured.
We will only use the personal data captured by our remote monitoring, access and
control systems for the purposes set out in this notice. We will treat all data
collected by our remote monitoring, access and control systems as confidential.
We may share personal data collected through these systems with the client whose equipment,
systems or services were being supported where necessary for service delivery, security, audit,
compliance or incident investigation purposes.
Who is collecting this personal data?
Revell Research Systems Limited
is collecting this data as the Data Controller.
Revell Research Systems Limited is a private limited company registered in
England and Wales as number 06939580.
Its registered office is at
5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom.
You should send regular correspondence to our principal office at
9-11 Coates Road,
Exeter,
Devon,
EX2 5RH, United Kingdom.
You can also contact us on (01392) 259797
or by email via
office@rrs.co.uk.
Revell Research Systems Limited
is registered with the Information Commissioner in the United Kingdom as a data controller
under
number Z186392X.
Who are we sharing your personal data with?
We may share personal data processed under this notice, where necessary and proportionate,
with the following categories of recipient:-
-
The courts and those involved in legal proceedings and non-contentious matters, including
solicitors and barristers
- Police and law enforcement agencies
- Our subsidiaries, our ultimate holding company and all its subsidiaries
- Clients
- Agents acting on our behalf
- Service providers (including associates)
- Professional advisers
We will not sell or rent your data to third parties. We will not share it with third
parties for marketing purposes.
Why are we collecting and what will we do with your personal data?
We are collecting this information to monitor, secure, protect, maintain, support
and improve our and our clients' computing and communication facilities.
We may also process this data for the purpose of the proper administration of our
business and in communicating with you as well as maintaining backups.
We may share data with the courts and associated professionals in establishing,
exercising or defending our legal rights or helping our clients do the same. We
may share data in reporting crime to or when co-operating with the police and law
enforcement agencies.
What is the legal basis for processing?
Our lawful bases for processing are Contract and Legitimate Interests.
-
contract - the Company may process your personal data in connection with a contract with
you or a client (typically to provide technical support or remote training) or as part
of pre-contractual negotiations.
-
legitimate interests - the Company has legitimate interests in monitoring, securing, protecting
and improving our computing and communication facilities; in protecting and asserting our
or another's legal rights; and in properly administering its business and backing up data.
These lawful bases are detailed in Article 6 of the UK General Data Protection Regulation
(UK GDPR):-
-
processing is necessary for the performance of a contract to which the data subject is
party or to take steps at the request of the data subject prior to entering into a contract
(Article 6(1)(b)).
-
processing is necessary for the purposes of the legitimate interests pursued by
the controller or by a third party, except where such interests are overridden by
the interests or fundamental rights and freedoms of the data subject which require
protection of personal data, in particular where the data subject is a child
(Article 6(1)(f)).
How are we collecting this information?
Our remote monitoring, access and control systems automatically collect personal data while
they are in operation.
What information are we collecting?
Our remote monitoring systems automatically collect telemetric data about the device
they are monitoring. Some of this recorded data is personal data such as usernames
and login sessions. These systems also may monitor network traffic, which could
reveal information about work patterns.
Our remote access and control systems log the IP
address of both the device being accessed or controlled and the device being used
to do that. The systems log the details of the technical agent initiating the access
or control session; the date, time and duration of the session; and other facts
about it. The systems may also record all the actions taken by the technical agent
for security and audit purposes.
Technical agents may also capture screenshots and record screen activity to document issues
they are working on. They may also have access to the mic and camera of the
device they are controlling.
Who can see your information within the Company?
Access to your personal data is restricted to authorised directors, staff and associates who
require it for legitimate business purposes.
How long is your information kept?
We will only keep your information for as long as necessary. The retention period
is either dictated by law or our legitimate requirements. Once your information
is no longer needed it will be securely and confidentially destroyed.
We typically retain personal data captured by our remote monitoring, control and access systems
for six years after the financial year in which it was recorded.
How secure is your information?
We take appropriate technical and organisational measures to protect your information against
unauthorised access, disclosure, alteration and destruction. You can read more about
our approach to security at www.rrs.co.uk/security.
Who keeps your information updated?
You are responsible for keeping your personal details up-to-date. Please advise
the Company of any changes.
Will your information be used for any automated decision-making?
No. We do not undertake solely automated decision-making, including profiling, that produces
legal effects concerning you or similarly significantly affects you.
Our Privacy Statement
You can access the Company's Privacy Statement at
www.rrs.co.uk/privacy.
This statement provides you with more information about how we address data protection
and privacy as well as informing you of your rights.
Other Privacy Notices
You are likely to interact with us in more than one way, so our other privacy notices
may apply to you in different scenarios. We are open and transparent about how we
use your personal data. You can find all of our Privacy Notices
at www.rrs.co.uk/privacy.
Changes to this Notice
Any changes to this privacy notice will take effect when the revised notice is published.
If these changes affect how your personal data is processed, the Company will take reasonable
steps to make sure you know.
Further Information
If you have any queries about this notice then please do not hesitate to contact
us by telephone on (01392) 259797
or via email to
office@rrs.co.uk.
You can write to us at
9-11 Coates Road,
Exeter,
Devon,
EX2 5RH, United Kingdom.
Version 0.0; 1st September 2020 (Reviewed: 13th September 2026).