Remote Monitoring, Access and Control Privacy Notice

Introduction

Revell Research Systems Limited (the Company, we, us, our) is providing you with this information in order to comply with the Data Protection Act 2018 and the General Data Protection Regulation 2016 (GDPR), which require us to tell you what we do with your personal information.

This notice relates to the personal data that we automatically collect and process as we utilise our remote monitoring, access and control systems.

Your personal data may be automatically captured by our remote monitoring, access and control systems if you work for or on our behalf or that of a client or otherwise use or interact with our or a client's systems where we have been authorised to use these systems.

Our remote access and control systems may require the intervention of a user to establish a session with their device or the owner may have authorised permanent unattended access to it. The latter is always the case for remote monitoring operations.

Our systems monitor equipment belonging to us or our clients (where this has been agreed) 24/7, continuously logging and reporting on various aspects of their use. This includes how and when they are used and by whom based on user credentials. The technical data logged includes IP addresses involved, date and time as well as telemetric data such as processor utilisation, bandwidth consumption, storage use, system access and session durations.

These systems log the access of technical staff to remote systems recording who accessed what from where and when as well as for how long. The technical data logged includes IP addresses involved, user credentials, date and time. The record may include a detailed log of exactly what was accessed on the remote device and may capture any text, video or audio exchanged with the device's user or other personnel using the system as well as screenshots and video recordings of the entire access session.

Equipment users should be aware that our technical staff have access to the user's screen, mic, camera and all storage on or accessible by the device. The tools potentially can record all traffic to and from a device and can record device screens and use. Consequently, any accessible or visible personal data may be captured.

We will only use the personal data captured by our remote monitoring, access and control systems for the purposes set out in this notice. We will treat all data collected by our remote monitoring, access and control systems as confidential.

We may share your personal data with the client whose equipment you were using when it was collected.

Who is collecting this personal data?

Revell Research Systems Limited is collecting this data as the Data Controller.

Revell Research Systems Limited is a private limited company registered in England and Wales as number 06939580. Its registered office is at 5 Providence Court, Pynes Hill, Exeter, Devon, EX2 5JL, United Kingdom. You should send regular correspondence to our principal office at 9-11 Coates Road, Exeter, Devon, EX2 5RH, United Kingdom.

You can also contact us on (01392) 259797 or by email via office@rrs.co.uk.

Revell Research Systems Limited is registered with the Information Commissioner in the United Kingdom as a data controller under number Z186392X.

Who are we sharing your Personal Data with?

We may share your personal data processed under this notice with the following third parties:-

  • The courts and those involved in legal proceedings and non-contentious matters, including solicitors and barristers
  • Police and law enforcement agencies
  • Our subsidiaries, our ultimate holding company and all its subsidiaries
  • Clients
  • Agents acting on our behalf
  • Service providers (including associates)
  • Professional advisors

We will not sell or rent your data to third parties. We will not share it with third parties for marketing purposes.

Why are we collecting and what will we do with Your Personal Data?

We are collecting this information to monitor, secure, protect, maintain, support and improve our and our clients' computing and communication facilities.

We may also process this data for the purpose of the proper administration of our business and in communicating with you as well as maintaining backups.

We may share data with the courts and associated professionals in establishing, exercising or defending our legal rights or helping our clients do the same. We may share data in reporting crime to or when co-operating with the police and law enforcement agencies.

What is the legal basis for processing?

Our lawful purposes are Contract and Legitimate Interest.

  • contract - the Company may process your personal data in connection with a contract with you or a client (typically to provide technical support or remote training) or as part of pre-contractual negotiations.
  • legitimate interests - the Company has a legitimate interest in monitoring, securing, protecting and improving our computing and communication facilities; in protecting and asserting our or another's legal rights; and in properly administering its business and backing up data.

These lawful purposes area detailed in Article 6 of the General Data Protection Regulation (GDPR):-

  • processing is necessary for the performance of a contract to which the data subject is party or to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b)).
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child (Article 6(1)(f)).

How are we collecting this information?

The remote monitoring, access and control systems automatically collect personal data while they are in use.

What information are we collecting?

Our remote monitoring systems automatically collect telemetric data about the device they are monitoring. Some of this recorded data is personal data such as usernames and login sessions. These systems also may monitor network traffic, which could reveal information about work patterns.

Our remote access and control systems log the IP address of both the device being accessed or controlled and the device being used to do that. The systems log the details of the technical agent initiating the access or control session; the date, time and duration of the session; and other facts about it. The systems may also record all the actions taken by the technical agent for security and audit purposes.

Technical agents may also take screenshots and video the screen interaction to document issues they are working on. They may also have access to the mic and camera of the device they are controlling.

Who can see your information within the Company?

Only authorised directors, staff and associates may access your data.

How long is your information kept?

We will only keep your information for as long as necessary. The retention period is either dictated by law or our legitimate requirements. Once your information is no longer needed it will be securely and confidentially destroyed.

We typically retain personal data that is captured by our remote monitoring, control and access systems logs for six years after the financial year in which they were recorded.

How secure is your information?

We take stringent steps to keep your information secure. You can read more about our approach to security at www.rrs.co.uk/security.

Who keeps your information updated?

You are responsible for keeping your personal details up-to-date. Please advise the Company of any changes.

Will your information be used for any automated decision making?

No.

Our Privacy Statement

You can access the Company's Privacy Statement at www.rrs.co.uk/privacy. This statement provides you with more information about how we address data protection and privacy as well as informing you of your rights.

Other Privacy Notices

You are likely to interact with us in more than one way, so our other privacy notices may apply to you in different scenarios. We are open and transparent about how we use your personal data. You can find all of our Privacy Notices at www.rrs.co.uk/privacy.

Changes to this Notice

We may change this privacy notice at any time. Any changes to this privacy notice will apply to you and your data immediately. If these changes affect how your personal data is processed, the Company will take reasonable steps to make sure you know.

Further Information

If you have any queries about this notice then please do not hesitate to contact us by telephone on (01392) 259797 or via email to office@rrs.co.uk. You can write to us at 9-11 Coates Road, Exeter, Devon, EX2 5RH, United Kingdom.

Version 0.0; 1st September 2020