RemoteGymp Data Processing Agreement
Version: 2026-07-27
Effective date: 27 July 2026
This Data Processing Agreement ("DPA") forms part of the RemoteGymp Terms of Service, an order form or another agreement for the Services (the "Agreement") between the customer ("Customer") and RemoteGymp Ltd, company number NI742463, of B1 Portview Trade Centre, BT4 1HE, United Kingdom ("RemoteGymp").
1. Scope and roles
1.1 This DPA applies where RemoteGymp processes Personal Data on Customer's behalf in providing the Services. Customer is the Controller and RemoteGymp is the Processor, except where applicable law assigns different roles. Capitalised data-protection terms have the meanings in applicable UK data-protection law.
1.2 Customer instructs RemoteGymp to process Personal Data as necessary to provide, secure and support the Services, comply with the Agreement and Customer's documented lawful instructions, and as described in Schedule 1.
1.3 Customer is responsible for the lawfulness, fairness and transparency of the processing; the accuracy and minimisation of Personal Data; all required notices, consents and other legal bases; and the lawfulness of its instructions and remote access.
2. Processor obligations
RemoteGymp will:
- process Personal Data only on documented instructions, including for international transfers,
- promptly tell Customer if, in RemoteGymp's opinion, an instruction infringes applicable
- ensure that authorised personnel are bound by confidentiality;
- implement and maintain measures appropriate to the risk as described in Schedule 2;
- taking account of the nature of processing, reasonably assist Customer with data-subject
- notify Customer without undue delay after becoming aware of a Personal Data Breach affecting
- make available information reasonably necessary to demonstrate compliance with this DPA.
unless required by law, in which case it will notify Customer before processing unless legally prohibited;
data-protection law;
requests, security, breach notifications, data-protection impact assessments and prior consultation duties;
Customer Personal Data and provide available information reasonably needed for Customer's obligations; and
RemoteGymp's assistance may be charged at reasonable rates where the request is unusually burdensome or arises from Customer's acts or instructions, unless the assistance is required because of RemoteGymp's breach.
3. Subprocessors
3.1 Customer gives RemoteGymp general written authorisation to use subprocessors to provide the Services. RemoteGymp will remain responsible for each subprocessor's data-protection obligations to the extent required by law and will impose materially equivalent protections by written contract.
3.2 A current list of subprocessors is available on request from support@remotegymp.com. RemoteGymp will give the account contact reasonable advance notice of an intended new subprocessor that will materially process Customer Personal Data.
3.3 Customer may object on reasonable data-protection grounds within 14 days of notice. The parties will work in good faith on a reasonable solution. If none is available, Customer may terminate the affected Service before the new subprocessor begins processing; this is Customer's sole remedy for the objection, without affecting mandatory rights.
4. International transfers
RemoteGymp will not make a restricted transfer of Customer Personal Data unless it uses a lawful transfer mechanism, such as applicable adequacy regulations, the UK International Data Transfer Agreement or Addendum, or another mechanism recognised by applicable law. The parties will reasonably cooperate on necessary transfer documentation and supplementary measures.
5. Data-subject requests
If RemoteGymp receives a request relating to Customer Personal Data, it will not respond on Customer's behalf unless authorised or legally required. Where practicable, RemoteGymp will forward the request to Customer. Customer is responsible for responding, and RemoteGymp will provide reasonable assistance appropriate to the nature of processing.
6. Security and breaches
6.1 RemoteGymp will assess processing risks and maintain appropriate technical and organisational measures. Customer acknowledges that security changes over time and that Schedule 2 describes categories of controls rather than a guarantee against every incident.
6.2 A breach notification is not an admission of fault or liability. Customer is responsible for notifications to individuals and regulators unless law expressly requires RemoteGymp to notify them directly.
7. Return and deletion
At the end of the affected Services, and at Customer's choice where reasonably technically available, RemoteGymp will return or delete Customer Personal Data and existing copies, unless law requires retention. Data in protected backups may remain until overwritten through the normal backup cycle and will remain protected and unavailable for ordinary use. Customer must export required data before account access ends.
8. Audit
8.1 RemoteGymp will first satisfy audit requests using current independent reports, certifications, policies, questionnaires or other relevant evidence where available.
8.2 If that evidence is insufficient, Customer may conduct one audit in any 12-month period, and additional audits following a relevant Personal Data Breach or regulator request. Audits require reasonable advance notice, must occur during business hours, must minimise disruption and risk, must protect other customers and confidential information, and may not include vulnerability or penetration testing without written agreement.
8.3 Customer bears reasonable audit costs unless the audit identifies a material breach by RemoteGymp.
9. Liability and priority
The exclusions and limitations of liability in the Agreement apply to this DPA to the fullest extent permitted by law. If this DPA conflicts with the Agreement on processing Personal Data, this DPA controls for that conflict.
10. Term
This DPA starts when Customer accepts the Agreement or the parties otherwise enter it and continues while RemoteGymp processes Customer Personal Data. Governing law and jurisdiction are those in the Agreement.
Schedule 1 — Processing details
Subject matter and duration: Provision, security, maintenance and support of the Services for the term of the Agreement and the limited deletion, backup and legal-retention period afterwards.
Nature and purpose: Collection, recording, organisation, transmission, hosting, retrieval, consultation, troubleshooting, protection, deletion and other processing needed for remote support, account administration and Customer's documented instructions.
Data subjects: Customer's users, administrators, technicians, staff, contractors, clients, end users, device users, support contacts and other people whose data Customer makes available.
Personal Data: Names, usernames, business contact details, identifiers, IP and device details, authentication and permission data, audit and session metadata, support information, screen content, filenames, files, commands, terminal output and other content selected by Customer.
Special-category and high-risk data: The Services are not designed to require special-category or criminal-offence data, but such data may incidentally appear on a remotely accessed device or in content selected by Customer. Customer must minimise it and have all additional legal conditions and safeguards required for its processing.
Frequency: As initiated by Customer and its authorised users, with continuous supporting security and operational processing where needed.
Schedule 2 — Security measures
RemoteGymp's measures, appropriate to the relevant deployment and risk, include:
- logical access controls, unique accounts, role-based permissions and least privilege;
- authentication protections and multi-factor authentication where supported;
- encryption of supported communications in transit and appropriate protection of secrets;
- segregation between customers and controlled administrative access;
- security, operational and acceptance logging with access restrictions;
- secure development, change control, dependency review, patching and vulnerability handling;
- availability monitoring, backup and recovery arrangements appropriate to hosted components;
- malware, abuse, network and infrastructure protections;
- incident detection, escalation, response and post-incident review;
- personnel confidentiality, access review and security awareness;
- due diligence and contracts for subprocessors; and
- periodic review and improvement of controls in light of risk and technology.
Customer remains responsible for security of its endpoints, networks, self-hosted environment, credentials, user permissions, backups and configuration.