Data processing agreement
Agreement under Art. 28 GDPR · version 1.0, 27 July 2026 · Deutsche Fassung
When you need this: only if you use BrowserDesk through our relay — then we process data on your behalf. If you run the relay yourself there is no processing on your behalf; the data stays with you and you do not need this agreement (see section 2).
1Parties and conclusion
The controller (“you”) is you as the customer. The processor (“we”) is TriLine, Martin Stemplinger & Tobias Aufschläger, Ilztalstraße 5, 94116 Hutthurm, Germany, info@browserdesk.de.
This agreement supplements the terms of use and applies as soon as you request it in text form and we confirm it — an e-mail is enough. On request we will also sign it. In case of conflict this agreement prevails over the terms of use as far as the processing of personal data is concerned.
2Subject matter and duration
The subject matter is the processing of personal data arising when BrowserDesk is operated through our relay: brokering remote connections, providing the administration console, the web client and the update feed.
Not covered is self-hosting. If you run the relay via Docker, as a Windows service or as a Linux package, we process none of this data; it stays solely on your systems. What remains reachable from us is the update feed, whose retrieval creates the usual server logs on our side — we process those as a controller, not on your behalf.
The agreement runs for as long as we process on your behalf and ends with the usage relationship.
3Nature, purpose, categories of data and data subjects
Nature and purpose: collecting, storing, transmitting and deleting the data listed below, solely to provide the agreed service and to secure its operation. We do not process the data for our own purposes — no advertising, no profiling, no sale of data.
| Category | Content |
|---|---|
| Device data | Name, platform, version, tags, first and last check-in, device certificate, inventory data from collector scripts |
| Session data | Target device ID, IP addresses of both sides, start and end. Picture, input and files of the session are not stored and are encrypted between the endpoints. |
| Log data | Hash-chained audit log: time, acting person, device, action; device logs; script runs with masked parameters |
| Consent | Consent granted per capability, person and validity period |
| Accounts | User name, role, password only as a salted hash (PBKDF2) |
| Recordings | Screen previews and session recordings — only if you switch them on; off by default |
Categories of data subjects: your staff and agents who use BrowserDesk or whose devices are supported; persons present at a supported device on your behalf. Special categories under Art. 9 GDPR are not covered; if your use nevertheless places them in a recording, that is your responsibility.
4Instructions
We process the data only on your documented instructions. Instructions comprise this agreement, the terms of use and your settings in the console — such as retention periods, consent, and switching preview and recording on or off. Further instructions are to be given in text form to info@browserdesk.de.
If we consider an instruction unlawful, we will say so and may suspend its execution until you confirm or change it.
5Our obligations
- Processing exclusively within the European Union; no transfer to third countries.
- Confidentiality: access only for persons bound to confidentiality and familiar with the requirements of the GDPR.
- Implementing and maintaining the measures in Annex 1 (Art. 32 GDPR).
- Assisting you with your obligations under Art. 32 to 36 GDPR as far as possible and reasonable.
- Keeping a record of the processing carried out for you (Art. 30(2) GDPR).
- A data protection officer is not required by law; the contact is Martin Stemplinger at the address above.
6Your obligations
- You remain responsible for the lawfulness of the processing, in particular for the legal basis of the remote access.
- You inform the data subjects and involve — where required — the works council and the data protection function, especially before switching preview or recording on.
- You choose retention periods and consent settings as your purposes require.
- You notify us without delay of misuse or lost credentials.
7Technical and organisational measures
The measures in Annex 1 apply. We may develop them further as long as the level of protection does not fall. We will notify material reductions in advance.
8Sub-processors
You consent to the use of the sub-processors listed in Annex 2. We bind them contractually to at least the level of protection of this agreement.
We will notify a change or an addition of sub-processors at least four weeks in advance in text form. You may object within two weeks on important data protection grounds; if no agreement is reached, you may terminate the usage relationship as at the date the change takes effect.
9Data subject rights
If a data subject approaches us with a request for access, rectification or erasure, we refer them to you and inform you without delay. We assist you in fulfilling such requests — access, rectification, erasure, restriction and portability — and provide the data in a common format on request. Simple requests are handled at no extra cost; where the effort is substantial we agree remuneration in advance.
10Personal data breaches
If we become aware of a breach of the protection of personal data, we will inform you without delay, at the latest within 24 hours of becoming aware — describing the incident, the categories of data affected, the likely consequences and the measures taken. Notifying the supervisory authority and the data subjects is your task; we supply the information needed for it.
11Evidence and audits
We demonstrate compliance with this agreement by information in text form and by presenting the measures in Annex 1. On request we will complete a questionnaire.
If that is not a sufficient basis for you, you may request an on-site audit — announced with reasonable notice, during business hours, without disrupting operations and without access to other customers’ data. Audits by third parties require their commitment to confidentiality. No ISO 27001 certification and no SOC 2 report exist.
12Deletion and return
After the usage relationship ends we delete the data processed for you within 30 days, unless a statutory retention duty applies. On request we will provide it beforehand in a common format. Backups expire within the retention cycle (at most 14 backups). We confirm deletion in text form on request.
13Liability and final provisions
Art. 82 GDPR applies. Otherwise the liability rules of the terms of use apply. Changes to this agreement require text form. German law applies; the place of jurisdiction is Passau as far as legally permissible. If a provision is invalid, the remainder stays in force.
A1Annex 1: technical and organisational measures
State of the measures described here: 27 July 2026.
| Area | Measure |
|---|---|
| Confidentiality in transit | TLS 1.3 and 1.2 to the relay (older versions are disabled), certificate from a public certification authority; picture and input are encrypted between the endpoints, the relay at most forwards encrypted packets. |
| Device authentication | Mutual proof by device certificate (mTLS); certificates revocable; can be enforced per tenant. |
| Passwords | Stored only as a salted hash (PBKDF2); never in clear text — device access passwords included. |
| Access control | Roles for viewing, controlling and administering; separation by tenant; four-eyes approval for critical devices. |
| Accountability | Hash-chained audit log, so later changes become detectable; session and script logs. |
| Consent by default | Preview, recording and pre-login access are off by default and are enabled per device or tenant. |
| Availability | Nightly database backup retaining the last 14; backup also available by e-mail; service restart after a crash. |
| Separation | Tenant separation in the database; separate accounts for administration and use. |
| Storage limitation | Session data and device logs are deleted automatically after 30 days; server logs are overwritten after 14 days. |
| Organisation | Server access via SSH with a key pair; access to customer data only where required for operation or fault finding, and only by the two partners. |
| Data minimisation | Session content is not stored; script parameters are stored masked. |
A2Annex 2: sub-processors
| Company | Service | Location |
|---|---|---|
| IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany | Server (virtual server running relay and database) | Germany |
| IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany | E-mail delivery (notifications, replies to enquiries) | Germany |
We currently use no further sub-processors. In particular no analytics, advertising or content delivery services are used.
This English text is provided for convenience. In case of doubt, the German version prevails.