Managing privacy and personal data – 247connect at a glance

Hi guys! We just wanted to give you a run-down on how NetSupport protects your users’ data and helps respect their privacy when you have, or are looking to get, a 247connect subscription.

This guide is about where and how NetSupport Group uses your data – and these are your instructions to us. This is generally based around the GDPR in UK/Europe but we also talk about other regions too.[i] We have tried not to use too much legal language, but sometimes we may need to point to particular things. For example, if we say ‘you’ or ‘your’, we will mean your organisation as the Data Controller. If we say ‘we’, ‘us’, ‘our’ or ‘NetSupport’, we mean NetSupport as the Data Processor.

Click here to read the full Data Processing Agreement/Product Privacy Policy.

Types of data we collect to use (Tell me why)

  • Contact details
  • Information we get from other systems
  • Information that identifies users
  • Information about devices and activities
  • Information on how your users use 247connect
  • Audit information about your 247connect.

How we use your data (How exactly?)

  • To provide you with remote access and remote management tools, through installed agents or requests
  • To provide you with information and tools to deliver technical support within your organisation
  • To maintain a consistent audit trail of activities and actions
  • To keep 247connect running and improve the existing service and tools
  • To give personalised customer support.

Sub-processors and partners who process your data (What do they do?)

NetSupport uses the following services to help us store and process your data on our behalf:

  • Infrastructure: Microsoft Azure
  • Integrations: Microsoft Entra, Google Cloud
  • Comms: Twilio Sendgrid.

We use cookies (How can I choose?)

  • We use only necessary cookies to run and improve the service.
  • We use only necessary cookies to run and improve how we manage our customer relationship with you.
  • Our partners/sub-processors use cookies too, which they control.
  • You can turn off cookies but this will mean, for example, that we can’t recognise you in in-app functions or we can’t resolve issues so efficiently.

When and how we collect data (Am I included?)

We collect data from people and devices connected to the 247connect platform, people browsing our website, NetSupport customers and people who view or obtain support through NetSupport, when…

Data you provide
Data you provide
Data users provide
Data users provide
Data we collect
Data we collect
 
Tick/check
 
 
You create staff accounts and roles 
Tick/check
 
 
When you connect to Microsoft, Google or other for integrations
Tick/check
Tick/check
Tick/check
You (and your users) use 247connect for remote support or remote management
 
 
Tick/check
You receive emails/notifications from us
Tick/check
Tick/check
Tick/check
When we monitor device information, activities and changes
Tick/check
 
Tick/check
When changes or updates are made to the configuration of 247connect
 
 
Tick/check
You chat with us for customer support

Helping you support user rights (What can users do?)

All users have to come through your organisation to make use of their rights [ii]. To support that, we make sure that:

  • You can access information we hold for you.
  • You can ensure information is held for you.
  • You can complain about us.

If you have any concerns about your data’s privacy at NetSupport, please get in touch via our contact form, email us at [email protected] or hit the Chat button on our website to talk to us.

The 247connect Data Processing Agreement

Our role in your privacy

If you are a NetSupport customer or subscriber, or just trialling our platform, this agreement applies to you. As part of the Terms of Service and Data Processing Agreement in our contract with you, you should check this agreement to make sure that this is understood to be the instructions that you (the Data Controller) give us (the Data Processor), as we are the provider of the 247connect platform. This agreement is based on the UK GDPR, but may talk about other regions where there is a difference[iii].

Our responsibilities

If you are a registered customer or using a trial, we act as the Data Processor of personal data. This means that we provide you with a service that allows you to process personal data based on the purpose and means that you have decided on. We are registered with the UK Information Commissioner’s Office under number Z9139408. We also provide you with all details of who we work withtechnical and security information and how you can make checks to ensure we are meeting our requirements against both this agreement and any relevant laws.

As you have entrusted us to provide a service to you which processes personal data, we want to help you with your need to show that you are looking after the personal data too. This agreement is designed to help with your risk assessments and our commitment to supporting you with any audits or inspections you are involved in.

As part of this agreement, we will provide clear information together with linked documents, be available to discuss and work through any questions you have, provide information about our partners who we use to process your data, and give guidance to help you take a privacy-first approach with our tools.

Your responsibilities

  • Read this Data Processing Agreement.
  • Check any contract or Terms of Service between us or any other document we have asked you to look at, as these may also have specific information that you want.
  • Where you have provided us with personal information as part of our service, or where your end-users have provided us with personal data, it will only be used for the reasons it was provided to us. By submitting the information to us, you confirm that you have the right to authorise us to process it on your behalf in accordance with this Data Processing Agreement.
  • You have reviewed the most appropriate use of 247connect in your organisation and considered its impact on privacy.

What if I am just using 247connect as an end-user

If you are reviewing 247connect because it is provided to you through your organisation (that is to say, the organisation is the Data Controller and we are the Data Processor), then this document will help you better understand how NetSupport handles your information on behalf of your organisation. In addition, your organisation will be able to explain more through things such as their Privacy Notice. You should be able to find this on your organisation’s website, handbook or guides.

 When and how we collect data

From the first moment your users and devices interact with 247connect, we are collecting data. Sometimes users provide us with data, sometimes your organisation provides us with data and sometimes data about users and devices is collected automatically.

Here’s when and how this is done:

Data you provide
Data you provide
Data users provide
Data users provide
Data we collect
Data we collect
 
Tick/check
 
 
You create user accounts and roles 
Tick/check
 
 
 When you connect to Microsoft, Google or other for integrations
Tick/check
Tick/check
Tick/check
You (and your users/customers) use 247connect
 
 
Tick/check
You receive emails/notifications from us
Tick/check
Tick/check
Tick/check
When we monitor device information, activities and changes
Tick/check
Tick/check
When changes or updates are made to the configuration of 247connect
 
Tick/check
You chat with us for customer support

What types of data we collect

Contact details

Your name, email address, role in the organisation, groups such as organisation/department, contact numbers, other organisation details.

Technical data that identifies you

Your IP address, login information, browser type, time zone setting, browser plug-in types, geolocation information about where you might be, the device you are using, operating system and version.

Data on how you use 247connect during remote management sessions

Images of desktops whilst you are working, requests for help/chats with your operator, applications used and websites accessed.

Data on how 247connect is accessed or changes made

Information on access to the 247connect web portal, changes to groups/devices/users, an audit trail for any configuration changes and who made them.

What about really sensitive data?

We know that you will be using247connect in remote support and other general activities as part of life in your organisation. When your end-users are using their devices during daily use, talk with others via their devices and share how they are feeling or their particular experiences, then you may be sharing sensitive information. You may also include end-users in particular groups based on ‘sensitive data’ (like racial or ethnic origin, political opinions, religious/philosophical beliefs, genetic data, biometric data, health data, or data about your sexual life). Where you share sensitive information or we use it, then it will be allowed based on how you, as an organisation, have agreed to it. We will process this information on the understanding that you have a lawful basis for processing it. This may include explicit consent or substantial public interest, but this will need to be shared by the organisation through the organisation’s Privacy Notice.

What about children’s data?

247connect is designed to provide organisations with resources and tools to aid in remote management, remote support and remote access. This means that both staff and end-user personal data will be used. It is not intended that these tools are to be used specifically with children, and are not designed as such.

How and why we collect your data

Data protection law means that we can only use your data for certain reasons, where instructed by the organisation and where they have a lawful basis to do so, or where we are required to use it with relevant authorities. As part of the building of 247connect, we have taken this into account and these are the areas we have identified and may be used by your organisation. Where there are differences to our normal list, it is because your organisation has identified something differently, which you can do as Data Controller.

Giving you 247connect and all relevant resources

This means making sure that 247connect gives you all the available tools. This includes access to resources, interactions between users and end-users and helping you get assistance.

Lawful basis for this data usage: Legitimate Interest/Public Task/Substantial Public Interest.

Improving 247connect

This means making sure that 247connect is the right tool for you and works as you need it to, including any improvements needed to make sure it continues to be the right tool. This will include technical support and analytical information.

This may also mean taking personal data and anonymising it so that when different people within NetSupport use it, we have protected it as much as we can.

Lawful basis for this data usage: Legitimate interest/Contractual Obligations.

Here is what each of the lawful bases means:

Legitimate interest

This states:

“Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

Use of legitimate interest would involve a three-part test, looking at the purpose, the necessity and where the balance is between your use of the data and the individual’s interest.

A wide range of interests may be legitimate interests. They can be your own interests or the interests of third parties, and commercial interests as well as wider societal benefits. They may be compelling or trivial, but trivial interests may be more easily overridden in the balancing test.

Public Task

This states:

“…processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller”

This means that the organisation, as a public authority, has many things it does with personal data. It has to do these things as it has been told that it needs to do it (by laws, regulations or statutory guidance) or it does the task as it is in the best interest of the relevant individuals..

Substantial Public Interest

This states:

“…processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject…”

This means that the organisation has taken extra measures to ensure that any information is safe (including having the appropriate policy documents). It also means that the organisation has taken the approach that the use of any ‘sensitive data’ is part of its work such as management of devices which may be used by those at risk or supporting those at risk.

Other lawful bases

It may be that your organisation provides support for other organisations or agencies, or where you have a direct contract or other relationship with a consumer. In these circumstances, you may be reliant upon a contract, or individuals have given you their consent to use their personal data.

If this involves sensitive/special category personal data, then you will also need to consider the exemption you are using under article 9 of GDPR, such as explicit consent.

We would suggest you discuss this and review guidance from the supervisory authority in your country (e.g. the Information Commissioner’s Office for the UK) so you chose the most appropriate lawful bases.

For all countries, we try to make sure that it is understood that your organisation makes the decision and ensures they have the right basis for using any personal data.

Your privacy choices and rights (information for end-users)

We also want to help you be transparent with your data subjects. It is possible to use the initial summary with your data subjects to help them understand how we process data on your behalf. It may be that you also need to provide additional information on rights and choices. We include the additional information that may support this. This is not specifically a part of the Agreement, but additional helpful information.

You have various rights about your personal data. These are all managed directly by your organisation and any questions about the rights would normally be dealt with by the organisation. These may vary, depending on the lawful bases mentioned in the previous section and the country you are in.

Your choices

We will only use the personal data you and your organisation give us. Where we have been given personal data by your organisation and instructions on what to do with it, giving us more personal data will depend on what your organisation says is needed. We will only use what has been provided.

Turning off cookies in your browser by changing its settings. There are various settings in your web browser that you can use to block or refuse cookies. You can also delete cookies through your browser settings as well. However, if you do delete cookies, some of 247connect may not work. We have already mentioned that we collect some information about your computer and how you use 247connect, and any cookies we use really are needed.

No need to ask us not to use your data for marketing. Any information you provide to us or that you create when you use 247connect is only ever used as part of giving you 247connect. We do not use it for any marketing or anything else.

Your rights

Please have a look at your organisation’s Privacy Notice or equivalent for how you can exercise your rights.

How secure is the data we collect?

We have organisational and technical measures in place to safeguard and secure the information we hold, based on standard industry practices. Further information is in our general Request for Information document as part of this DPA, but we prefer not to publicly publish too much security information as a measure to protect our services.

And please remember:

  • Only share personal data where you need to.
  • You are responsible for your username and password, so keep them secret and safe!
  • If you believe that your privacy has been breached, then contact your Data Protection Officer or follow the guidance your organisation provides.

Where do we store your data?

The personal data we collect is processed at our offices in Peterborough or regional offices, or our platform, which is hosted by Microsoft Azure Services in the

By submitting your personal data, you agree to this transfer, storing or processing by us. Limited personal data is transferred or stored outside of the UK or EEA and is detailed below. If we make changes to any transfer of data outside of the UK or EEA, we will notify you, including explaining any steps being taken to ensure that your privacy rights continue to be protected as outlined in this Data Processing Agreement.

For how long do we store your data?

We continue to hold all ‘active’ data (data that has been provided and is linked to active accounts on a verified licence) until the following:

  • If your subscription licence has run out and accounts are no longer active, personal data is kept for 30 days, as per this agreement, and then securely deleted.
  • We also operate a rolling retention program that retains audit log data for 13 months.
  • We can extend the length of the rolling backup, but additional agreements and costs may be needed.

Partners (sub-processors) who process your data

Technology businesses often use contractors and outside companies to help them host their applications, power their support tools, etc. Any company or individual that we use when processing information under this agreement is a “sub-processor”. This means that any agreement or contract we have with them is, at least, as strict as this agreement. We make sure that we are happy that they will also take the same level of care of the personal data you are trusting us with, including checking if they hold any certificates for their work. Any partners mentioned below will be considered to have general authorisation for us to tell them what they need to do.

In the rare circumstance that there is a change to who we work with that significantly affects any existing service you have with us, we will work to give you advance notice. Where a new element of functionality is available from 247connect, this is turned off by default and does not process any of your data. If you want to turn it on, then you will need to check that you are happy with any partners we are using. In these cases, we include information in our release notes and updates to this agreement, plus associated guidance such as our By Default and By Design articles.

Here are the details of the main sub-processors and service providers; what they collect, process and store, and a general explanation of why.

Infrastructure

   
Service providerData collected or processedPurposePlace of processing

Azure hosting

https://docs.microsoft.com/en-us/compliance/assurance/assurance-datacenter-security

·         Contact details

·         Use of the platform

·         Safeguarding information

This is a web hosting provider. We use it to store the application.UK, US, DE (location dependent on location of customer)
Service Cloud (from Salesforce)

·         Contact details

·         Technical information

To provide support and training.Ireland

Analytics

   
Service providerData collected or processedPurposePlace of processing
N/A – no external partner used for analyticsN/AN/AN/A

Integrations (optional)

   
Service providerData collected or processedPurposePlace of processing
Microsoft Entra

·         Authentication ID

·         Groups

To enable access to the platform and access to relevant groups.

Regionally specific
Google Cloud

·         Authentication ID

·         Groups

To enable access to the platform and access to relevant groups.

Regionally specific

Comms

   
Service providerData collected or processedPurposePlace of processing

Twilio Sendgrid

https://www.twilio.com/legal/privacy)

(SCCs in place)

·         User informationEmail/notification of alertsUS/Ireland

Tawk.to

(SCCs in place)

·         Contact information

·         Support information

To provide support and training.US/Ireland

 External parties

As part of our sales process, access is also provided to an online purchasing tool (via Paddle.com). This is part of our relationship with you on a business-to-business basis and does not form part of this Data Processing Agreement. For more details, please review the NetSupport Privacy Policy.

How we use cookies

We use cookies. Unless you adjust your browser settings to refuse them, we (and our sub-processors) will issue cookies when you interact with 247connect. These may be session cookies, meaning they delete themselves when you leave 247connect or ‘persistent’ cookies which do not delete themselves and help us to recognise you when you return so we can provide you with a tailored service.

How can I block cookies?

You can block cookies by activating a setting in your browser allowing you to refuse the setting of cookies. You can also delete cookies through your browser settings. If you use your browser to disable, reject, or block cookies (including essential cookies), certain parts of our platform will not function fully. In some cases, our platform may not be available at all. Please note that where sub-processors use cookies, it is also to enable the service to work correctly. This also includes blocking cookies from other systems you want us to integrate with. We do not allow third parties to set cookies.

Which specific cookies do we use?

Service provider

Key cookies

Purpose

NetSupport

ASLBSA

Identity and authentication

 

.AspNetCore.Antiforgery.SBNXHGqQ3AM

Identity and authentication

 

ASLBSACORS

Identity and authentication

 

idsrv

Identity and authentication

Making this DPA great

Well done for getting through this Data Processing Agreement and reviewing everything in it! It is designed to help you best understand what we do, under your instructions. Where you have instructions outside of this agreement, then they will be treated as support or account requests, as long as they do not fundamentally change anything mentioned in this agreement.

N.B. This DPA was built based on an open-source design for Privacy Notices from https://juro.com and https://stefaniapassera.com/. Get these patterns free at github.com/juro-privacy. This DPA pattern is open source and reuse is permitted when using the attributions above. Specific content relating to the service itself may not be reused without the permission of NetSupport.

Further technical information

If you need further technical or operational information, please request our (based on a popular) standardised template. We hope you find this useful as well.

Publication date: 11th June 2025
Version: 1.1

What's New

Agreement updated to include the optional use of Google for authentication and account management.

Clarification that this Data Process Agreement also operates as the Product Privacy Policy.

 

[i] Terms of Service 1.1.2 Data Processing Agreement
[ii] Terms of Service 1.1.2.1 Data Subject Rights
[iii] Terms of Service 1.1.2 Data Processing Agreement