RemoteGymp Data Processing Agreement
Version: 2026-08-28
Effective date: 28 August 2026
This Data Processing Agreement ("DPA") forms part of the RemoteGymp Terms of Service, an order form or another agreement for the Services (the "Agreement") between the customer ("Customer") and RemoteGymp Ltd, company number NI742463, of B1 Portview Trade Centre, BT4 1HE, United Kingdom ("RemoteGymp").
1. Scope and roles
1.1 This DPA applies where RemoteGymp processes Personal Data on Customer's behalf in providing the Services. Customer is the Controller and RemoteGymp is the Processor, except where applicable law assigns different roles.
1.2 Customer instructs RemoteGymp to process Personal Data as necessary to provide, secure and support the Services, comply with the Agreement and Customer's documented lawful instructions, and as described in Schedule 1.
1.3 Customer is responsible for the lawfulness, fairness and transparency of the processing; the accuracy and minimisation of Personal Data; all required notices, consents and other legal bases; and the lawfulness of its instructions and remote access.
1.4 Where Customer deploys the Services in its own environment, Customer alone determines the means and purposes of processing within that environment and RemoteGymp is not a Processor of Personal Data held there. RemoteGymp acts as Processor only in respect of licensing and entitlement data transmitted to RemoteGymp. Sections 6, 7 and 8 apply only to data RemoteGymp processes.
1.5 Applicable Data Protection Law means all laws relating to data protection, privacy and the processing of Personal Data applicable to a party's processing under this DPA, including (a) the UK GDPR and the Data Protection Act 2018; (b) Regulation (EU) 2016/679 and Member State implementing legislation; (c) the Swiss Federal Act on Data Protection; and (d) the US State Privacy Laws identified in Schedule 3.
Controller, Processor, Data Subject, Personal Data, Personal Data Breach and processing have the meanings given in Regulation (EU) 2016/679, and equivalent terms under any other Applicable Data Protection Law shall be construed accordingly.
2. Processor obligations
RemoteGymp will:
- process Personal Data only on documented instructions, including for international transfers,
- promptly tell Customer if, in RemoteGymp's opinion, an instruction infringes applicable
- ensure that authorised personnel are bound by confidentiality;
- implement and maintain measures appropriate to the risk as described in Schedule 2;
- taking account of the nature of processing, reasonably assist Customer with data-subject
- notify Customer without undue delay after becoming aware of a Personal Data Breach affecting
- make available information reasonably necessary to demonstrate compliance with this DPA.
unless required by law, in which case it will notify Customer before processing unless legally prohibited;
data-protection law;
requests, security, breach notifications, data-protection impact assessments and prior consultation duties;
Customer Personal Data and provide available information reasonably needed for Customer's obligations; and
RemoteGymp's assistance may be charged at reasonable rates where the request is unusually burdensome or arises from Customer's acts or instructions, unless the assistance is required because of RemoteGymp's breach.
3. Subprocessors
3.1 Customer gives RemoteGymp general written authorisation to use subprocessors to provide the Services. RemoteGymp will impose data protection obligations on each subprocessor by written contract that are no less protective than those in this DPA, and shall remain fully liable to Customer for the performance of each subprocessor's data protection obligations.
3.2 RemoteGymp will give the account contact at least 30 days' advance notice by email of an intended new subprocessor that will process Customer Personal Data.
3.3 Customer may object on reasonable data-protection grounds within 30 days of notice. The parties will work in good faith on a reasonable solution. If none is available, Customer may terminate the affected Service before the new subprocessor begins processing; this is Customer's sole remedy for the objection, without affecting mandatory rights.
4. International transfers
RemoteGymp will not make a restricted transfer of Customer Personal Data unless it uses a lawful transfer mechanism recognised by Applicable Data Protection Law. The parties will reasonably cooperate on necessary transfer documentation and supplementary measures.
5. Data-subject requests
If RemoteGymp receives a request relating to Customer Personal Data, it will not respond on Customer's behalf unless authorised or legally required. Where practicable, RemoteGymp will forward the request to Customer. Customer is responsible for responding, and RemoteGymp will provide reasonable assistance appropriate to the nature of processing.
6. Security and breaches
6.1 RemoteGymp will assess processing risks and maintain appropriate technical and organisational measures. Customer acknowledges that security changes over time and that Schedule 2 describes categories of controls rather than a guarantee against every incident.
6.2 A breach notification is not an admission of fault or liability. Customer is responsible for notifications to individuals and regulators unless law expressly requires RemoteGymp to notify them directly.
7. Return and deletion
At the end of the affected Services, and at Customer's choice where reasonably technically available, RemoteGymp will return or delete Customer Personal Data and existing copies, unless law requires retention. Data in protected backups may remain until overwritten through the normal backup cycle and will remain protected and unavailable for ordinary use. Customer must export required data before account access ends.
8. Audit
8.1 RemoteGymp will first satisfy audit requests using current independent reports, certifications, policies, questionnaires or other relevant evidence where available.
8.2 If that evidence is insufficient, Customer may conduct one audit in any 12-month period, and additional audits following a relevant Personal Data Breach or regulator request. Audits require reasonable advance notice, must occur during business hours, must minimise disruption and risk, must protect other customers and confidential information, and may not include vulnerability or penetration testing without written agreement.
8.3 Customer bears reasonable audit costs unless the audit identifies a material breach by RemoteGymp.
9. Liability and priority
The exclusions and limitations of liability in the Agreement apply to this DPA to the fullest extent permitted by law. If this DPA conflicts with the Agreement on processing Personal Data, this DPA controls for that conflict.
10. Term
This DPA starts when Customer accepts the Agreement or the parties otherwise enter it and continues while RemoteGymp processes Customer Personal Data. Governing law and jurisdiction are those in the Agreement.
Schedule 1 — Processing details
Subject matter and duration: Provision, security, maintenance and support of the Services for the term of the Agreement and the limited deletion, backup and legal-retention period afterwards.
Nature and purpose: Collection, recording, organisation, transmission, hosting, retrieval, consultation, troubleshooting, protection, deletion and other processing needed for remote support, account administration and Customer's documented instructions.
Data subjects: Customer's users, administrators, technicians, staff, contractors, clients, end users, device users, support contacts and other people whose data Customer makes available.
Personal Data: Names, usernames, business contact details, identifiers, IP and device details, authentication and permission data, audit and session metadata, support information, screen content, filenames, files, commands, terminal output and other content selected by Customer.
Special-category and high-risk data: The Services are not designed to require special-category or criminal-offence data, but such data may incidentally appear on a remotely accessed device, in content selected by Customer, or in free-text descriptions entered by a person requesting support. Customer must minimise it and have all additional legal conditions and safeguards required for its processing.
Frequency: As initiated by Customer and its authorised users, with continuous supporting security and operational processing where needed.
Schedule 2 — Security measures
RemoteGymp's measures, appropriate to the relevant deployment and risk, include:
- logical access controls, unique accounts, role-based permissions and least privilege;
- authentication protections and multi-factor authentication where supported;
- encryption of supported communications in transit and appropriate protection of secrets;
- segregation between customers and controlled administrative access;
- security, operational and acceptance logging with access restrictions;
- secure development, change control, dependency review, patching and vulnerability handling;
- availability monitoring, backup and recovery arrangements appropriate to hosted components;
- malware, abuse, network and infrastructure protections;
- incident detection, escalation, response and post-incident review;
- personnel confidentiality, access review and security awareness;
- due diligence and contracts for subprocessors; and
- periodic review and improvement of controls in light of risk and technology.
Customer remains responsible for security of its endpoints, networks, self-hosted environment, credentials, user permissions, backups and configuration.
Schedule 3 — US State Privacy Laws
1. Scope. This Schedule applies where RemoteGymp processes Personal Information subject to US State Privacy Laws, and prevails over the body of this DPA for that processing.
2. Roles. Customer is a Business or Controller; RemoteGymp is a Service Provider or Processor.
3. Restrictions. RemoteGymp shall not: (a) sell or share Personal Information; (b) retain, use or disclose Personal Information for any purpose other than performing the Services specified in the Agreement, or as otherwise permitted by the CCPA; (c) retain, use or disclose Personal Information outside the direct business relationship between the parties; or (d) combine Personal Information with information received from another source, except as permitted by the CCPA.
4. Certification. RemoteGymp certifies that it understands the restrictions in paragraph 3 and will comply with them.
5. Assistance. RemoteGymp shall assist Customer in responding to consumer rights requests and, where required, honour opt-out preference signals including Global Privacy Control.
6. Notice. RemoteGymp shall notify Customer if it determines it can no longer meet its obligations under US State Privacy Laws.