Effective as from 1 February 2023
- Verantwortliche und Verarbeiter
- Processing Details
- Benachrichtigungen und Newsletter
- Additional Features
- Verwendung unserer Produkte
- Transfer of personal data to third countries
- Inhalte Dritter
- Managed Private Cloud
- Selbst-gehostete Lösung
- Anonymisierung und Pseudonymisierung
- Frühere Produktversionen
- Ihre Rechte
- Änderung der Datenschutzerklärung
ISL Online ("we", "us", "our") has prepared this policy to provide information about the collection and processing of personal data when using the products and services offered on the official websites (islonline.com and islonline.net). The main purpose of the ISL Online software is to allow IT professionals and helpdesk technicians ("Operator") to establish remote desktop sessions over the Internet for their business purposes, i.e. to provide technical support to their customers ("Client") remotely or to access unattended remote computers.
We address personal data protection in accordance with the General Data Protection Regulation (EU) 2016/679, which is a European regulation on data protection and privacy (GDPR).
- Controller: means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data pursuant to Article 4 paragraph 7 of GDPR.
- Processor: means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller pursuant to Article 4 paragraph 8 of GDPR.
- Personal Data: refers to any information that relates to an identified or identifiable natural person pursuant to Article 4 paragraph 1 of GDPR, or any information which can be used to uniquely identify a Website visitor, Operator, Client, or Administrator.
- Website visitor: refers to any individual visiting our official websites or social media sites for informative purposes only.
- Operator: refers to any individual registered with an ISL Online account. Typically, this refers to an IT professional or helpdesk technician who offers support to a Client.
- Client: refers to an End-User who joins remote desktop sessions, usually without any credentials, to receive technical support from Operators.
- Administrator: refers to a privileged Operator who has permission to manage ISL Online licenses and accounts of other Operators within an organization.
Verantwortliche und Verarbeiterlink
While using ISL Online products and services the legal person collecting, and processing personal data is:
- ISL Online Headquarters
- XLAB d.o.o.
- Pot za Brdom 100
- SI-1000 Ljubljana
- Slovenia, European Union
- USt ID: SI15779092
- Reg. Nummer: 1639714
- +386 1 2447760
While providing its services ISL Online assumes both the role of data Controller as well as data Processor regarding different interactions with our customers and the corresponding personal data.
ISL Online assumes the role of the Controller regarding personal data described in chapters 8-13, with processing details being described in chapter 4.
ISL Online assumes the role of the Controller regarding personal data described in chapter 14 which pertains to you (Operator).
ISL Online assumes the role of the Processor regarding personal data described in chapter 14 which pertains to your clients (Client / Person you offer remote support to). Data Processing Agreement (DPA) for our hosted service users is made available, once they log into their account, under My Profile > Other > Data Processing Agreement.
In addition to ISL Online the processor or sub-processor of personal data may be:
- dem Verantwortlichen,
- mit uns verbundenen Unternehmen (Tochtergesellschaften, deren Hauptanteilseigner wir sind, und die als solches nicht als Dritte erachtet werden sollen):
- ISL Online Limited, 22 Basepoint Business Centre, Rivermead Drive, Westlea, Swindon, Wiltshire, SN5 7EX, United Kingdom
- ISL Online DACH GmbH, Aargauerstrasse 250, 8048 Zürich, Switzerland
- ISL Online GmbH, Noetherstrasse 1, D-69115 Heidelberg, Germany
- Dritte Parteien (Dritte):
- Autorisierte Partner (unsere Distributoren und Wiederverkäufer, die uns bei der Durchführung bestimmter Kundendienstfunktionen wie Marketingaktivitäten, Verkauf, Kundensupport und ähnlichen Geschäftsaktivitäten in unserem Namen unterstützen)
- external contractual service providers which we use in connection with the specific functions of our business process, e.g. Google Analytics
Processing details in the table below cover the personal data for which ISL Online acts as a controller as described in chapters 8-13.
Beschreibung Details Zweck der Verarbeitung Dient der Nutzung von ISL Online-Produkten und -Diensten in Übereinstimmung mit den Nutzungsbedingungen und dem Lizenzvertrag. Dauer der Verarbeitung Dauer der Vertragsbeziehung, die zustande kommt, wenn ein Benutzerkonto erstellt wird. Beschaffenheit der Verarbeitung
Arten der verarbeiteten personenbezogenen Daten
- Namen (optional)
- E-Mailadresse (optional)
Most personal data is collected for as long as is necessary to fulfil the purpose of processing under which it was collected.
Certain personal information is kept for a longer period in order to comply with European and local legislation.
The only personal data we process based on your consent are email subscriptions for "Account expiry notifications" and "ISL Online Updates". Processing consent can be revoked at any time in the "My Profile" section of your account. Such revocation of consent is valid for future data processing and does not influence the validity of our data processing prior to your revocation.
It is our belief that children have no requirements for our software and therefore, we do not verify age or obtain parental or guardian consent for any data processing activity. ISL Online software has no age sensitive material, nor should it pose any risk to children.
ISL Online Headquarters (XLAB d.o.o.) holds the ISO/IEC 27001:2013 certificate, which proves our commitment to information security. We use the globally recognized ISO 27001 standard as a framework for implementing the information security management systems (ISMS) which helps us keep information assets secure.
All our servers have disk encryption and are solely managed by the controller's OPS team (system administrators and other privileged access users). Data is encrypted in rest as well as in flight. We have physical and logical access procedures and controls in place, and we conduct training for our employees and contractors in order to enforce conformity with our data protection and privacy policies.
Wir verwenden die neuesten Technologien und Verwaltungsverfahren, um Ihre persönlichen Daten zu schützen. ISL Online-Server werden von professionellen, industrieerprobten Rechenzentren mit modernen Einrichtungen und Geräten, wie z. B. Not- oder redundante Stromversorgungen, redundante Datenkommunikationsverbindungen, Raumklimaüberwachungen (z. B. Klimaanlage, Brandschutz) und Sicherheitseinrichtungen gehostet.
ISL Online's master servers, which hold the data upon which ISL Online acts as a Controller, are located within the European Union in ISO 27001-certified data centers. Session meta-data upon which ISL Online acts as a Processor is replicated across our worldwide network of servers and gets processed in a location selected by our load balancing system, which includes locations outside the EU. Server locations are shown here: About Us.
Wenn Sie die volle Kontrolle über die Serverstandorte und den Datentransfer wünschen, richten Sie eine Serverlizenz (der ISL Online-Service wird auf Ihrem/Ihren Server(n) gehostet und von Ihnen verwaltet) ein, oder verwenden Sie eine Managed Private Cloud-Lösung (der ISL Online-Service wird auf Servern gehostet, die in Übereinstimmung mit Ihren Präferenzen ausgewählt und von ISL Online Fachleuten verwaltet werden).
When you visit our website, we collect a limited scope of personal data transmitted to us by your browser. This helps us provide the service as well as improve the user experience. Data collected consists of your IP address and metadata (such as timestamp), technology used (operating system, browser etc.), referrals (website from which the request comes), language and the country of origin.
Um anomale Aktivitäten zu erkennen, wird aus Sicherheitsgründen zusätzlich Ihre IP-Adresse von unseren Systemen erfasst. Anomale Aktivitäten beinhalten, sind jedoch nicht darauf beschränkt, DNS-Attacken, Scam-Erkennung und andere Aktivitäten, die Ihre Sicherheit oder die Verfügbarkeit unserer Systeme kompromittieren könnten. Die Metadaten Ihres Webbrowsers, Sprache und Herkunftsland dienen der korrekten Version unserer Webseite in Bezug auf Ihren Standort und die Sprache Ihrer Wahl. Die Referral-Adresse, falls verfügbar, wird von ISL Online verwendet, um den Ursprung des Datenverkehrs festzustellen.
If you decide to sign up for a free trial of the ISL Online software, we will ask you to provide the following personal information:
- Vollständiger Name
You are only required to provide your email address during the registration process. We process this information to complete the contractual obligation. The username is chosen by you and can be used as an alternative to an Email address when logging into ISL Online products and services. Full name is optional and can be specified to personalize the user experience when using ISL Online products and services.
For billing purposes, we also ask you to provide the name of the company, address, phone number and similar information which will be needed if you decide to buy a license. You are able to review and change this information at any time (log in to My Account > License > Change Information).
According to your country of origin and the cookie information, your account information may only be processed by the ISL Online Headquarters, our subsidiaries or Authorized Partners which have signed information sharing agreements with us. These processors have access to the personal data needed only to perform their customer care functions related to ISL Online's products and services and may not use it for any other purpose. You have the power to choose your preferred point of contact at any time (log in to My Account > License > Change Local Partner).
Some organizations may decide to enable additional features provided by ISL Online to enhance their remote desktop sessions, for example:
- ISL Pronto, which is a text-chat solution that can be published on their allows Clients to join a remote support session directly from the respective websites.
- End-of-Session dialogs, which pop up to Operators or Clients once the remote desktop session is finished for the purpose of collecting the users' feedback.
- Integration into third-party solutions, such as service desk or ticketing products, CRMs, ERPs and other enterprise systems.
Enabling such additional features may result in collecting text messages (the transcript of the chat between the Operator and the Client) and different free-form inputs related to a remote desktop session and storing this data on ISL Online servers alongside metadata. Chat transcripts are available to Operators and Administrators of the respective organizations.
ISL Online implores the users to be careful when entering personal or confidential data into session chats, end-of-session dialogs and other places which allow unmoderated user input. This information becomes a subject of data processing; however, it is technically infeasible to exercise your data subject rights upon such data.
In the case of the integration of ISL Online software into third-party solutions, the chat transcript may be transferred to service desk or ticketing products, CRMs, ERPs or other enterprise systems. We do not control the personal data collected and managed by these enterprise systems. We recommend that you contact the enterprise system providers directly for their privacy and data sharing policies.
When the organization decides to purchase the ISL Online licenses, those licenses are assigned to a specific ISL Online account. These accounts are normally managed by Administrators (license owners). During the purchasing process, we will collect the information needed for billing and order processing purposes, which may include your name, company name, company address, email address, and telephone number. We will keep purchase orders and invoice records as long as requested by tax authorities. Please refer to the Terms of Service for details.
When you contact our service desk via live chat, email or phone, we may collect your email address, your name, and your telephone number in order to respond to your inquiry. Your message will also be stored and might be shared with our Authorized Partners in order to provide a prompt and localized customer service to you. Any personal data and other information intentionally or unintentionally provided by you whilst communicating with our support staff will be processed by us based on our legitimate interest to fulfill your support request.
Verwendung unserer Produktelink
When you register for a free trial, your account will be activated for product use. Upon the registration, and all subsequent successful log in attempts, we will collect your IP and MAC addresses for auditing and licensing purposes.
Once logged into your account, ISL Online allows you to establish a remote desktop session with a remote computer or mobile device. The session may include different services such as text-chat, screen sharing, video call and file transfer.
All remote desktop sessions are encrypted using symmetrical AES 256-bit keys. A secure SSL end-to-end tunnel is established between a local and a remote computer or device. This means that even the ISL Online servers cannot decrypt the content of the sessions, but only transfer packets from one side to another. This means that we do not collect any personal data transmitted during remote desktop sessions.
We use proprietary geoDNS algorithms to distribute sessions to the nearest servers available. This means that users from a particular country are most likely to be connected through one of our servers hosted in that country (if any of our servers are located in that country). For example, the UK users will be almost certain to connect through our UK servers, the German users will be almost certain to connect through our German servers etc.
However, we do collect, store, and process metadata of the remote desktop sessions. This is needed for the legitimate purpose of enabling access to the ISL Online products and services explicitly requested by you. The list of metadata stored on ISL Online's servers may include the following personal data collected from your device as well as the device to which you are connecting.
From your device / pertaining to you, we may collect the following:
From the device you are connecting / pertaining to the person you are supporting, we may collect the following:
ISL Online processes the personal data of the people you are supporting upon your request and according to your instructions, thus ISL Online assumes the role of data processor. A data processing agreement (DPA) is available to you once you log in at islonline.com under "My Profile" section.
A detailed list of basic session parameters (metadata) is available in our Security Statement.
Transfer of personal data to third countrieslink
ISL Online utilizes a grid of servers worldwide to provide our hosted service. A distributed data allocation allows us to guarantee 24/7 availability and reliability of the remote desktop software as a service around the globe.
While (personal) data outside of the European Union, ISL Online uses the following safeguards and measures to ensure adequate protection of data:
- All data is encrypted in flight and at rest, with ISL Online being the only entity to possess the encryption/decryption keys;
- ISL Online has obtained and maintains the ISO 27001 certification;
- In cases where data export to a third country is not covered by Adequacy Decision, ISL Online relies on Standard Contractual Clauses signed with selected providers.
You can request information about the data stored about you via the contact details provided in Chapter 3.
Google Tag Manager
- Google Analytics
reCAPTCHA is used by ISL Online to protect our websites from abuse. It uses advanced risk analysis techniques to tell bots and humans apart. More information regarding reCAPTCHA can be found here: https://developers.google.com/recaptcha/. reCAPTCHA system additionally utilizes and sets the NID cookie. Please refer to our Cookies Policy for details.
To provide the services and improve our official websites, we may engage the services of third-party vendors, such as Vimeo, YouTube and Google Maps. In the process of supplying such website services through our official website, these third-party vendors may collect your IP or other information provided by your browser.
Ausser der Deaktivierung der Drittanbieter-Cookies kann ISL Online Drittanbietern die Art und Weise der Speicherung und Verwaltung von personenbezogenen Daten nicht vorschreiben. Bitte richten Sie sämtliche Anträge auf Geltendmachung Ihrer Rechte in Hinsicht auf die Verarbeitung Ihrer personenbezogenen Daten direkt an die entsprechenden Drittanbieter.
Webseiten sozialer Medien
Our official websites feature social media plugins like Facebook, Twitter, and LinkedIn, to enable you to share information with others. If you are logged into a social media site while visiting our website, the social plugins may allow that social media website to receive information that you have visited our website and to share information about your activities on our website with other users of their social media website. We do not control any of the content from the social media plugins. We recommend that you contact those sites directly for their privacy and data sharing policies.
Beside the official websites, we use a blog to publish the content created by us. The blog is hosted by WordPress.com, which offers features like "Subscribe to blog" and "Reply to a blog post". We do not control the personal data collected and managed by these blog features. If you wish to use these features and have any concerns, we recommend that you contact WordPress.com directly for their privacy and data sharing policies.
Links zu anderen Webseiten
Our official websites contain links to other websites. The fact that we link to a website is not an endorsement, authorization or representation of our affiliation to that third party. We do not exercise control over third party websites. We recommend that you contact those sites directly for their privacy and data sharing policies.
Managed Private Cloudlink
To organizations which wish to use the cloud solution but want to have total control over the locations of the ISL Online servers hosting their data and remote desktop connections, we offer a special plan called Managed Private Cloud (MPC). This allows users to enjoy all the benefits of cloud computing in a PRIVATE cloud, without investing in hardware or human resources (sysops) for setting up, configuring, monitoring and maintaining the system. Please Contact Us for details.
To most security delicate organizations such as banks, national agencies or corporate environments, we offer the self-hosted models (Server License, Private Cloud). With these models, the ISL Online system is installed onto the server(s) hosted by those organizations. In this case, all remote desktop connections are established through the server(s) controlled by those organizations. As the self-hosted installation is a stand-alone system, where all data (including metadata) remains in a closed corporate environment, the organization is responsible for the administration of the server(s) and for protecting personal data of their users (Operators and Clients). If you are using a self-hosted system and have concerns, inquiries or requests related to your personal data, you need to contact Administrators of those respective organizations. ISL Online helps the organizations using our self-hosted system to meet personal data protection requirements by tailoring the ISL Online products to their needs. Please Contact Us for details.
Anonymisierung und Pseudonymisierunglink
We strive to minimize the collection of your personal data. A vast majority of data collected by ISL Online is anonymized, stripped of any identifiable information, which makes it impossible to derive insights into a discrete individual. On the other hand, the personal data we do collect and store may be pseudonymized:
- auf Ihre ausdrückliche Anfrage hin, oder
- nach festgelegten Aufbewahrungsfristen.
You have the right to be forgotten. Pseudonymization means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately. Your personal data will be rendered in such a way that it would be nearly impossible to reidentify you.
We use reasonable efforts and deidentification techniques to pseudonymize your personal data. We provide pseudonymization support tools to Administrators of self-hosted systems.
Die Informationen in dieser Datenschutzerklärung basieren auf den Produktversionen von ISL Online, die am Wirksamkeitsdatum dieser Datenschutzrichtlinie oder später per Menüpunkt "Downloads" auf unserer offiziellen Website verfügbar sind. Sie gelten unter Umständen nicht für frühere Versionen oder Betaversionen.
Jedes Datensubjekt, dessen persönliche Daten wir verarbeiten, kann jederzeit:
- Einsicht darüber erhalten, welche personenbezogenen Daten sich in unserem Besitz befinden, wie wir diese Informationen erlangt haben und wie wir sie schützen und verarbeiten.
- eine Kopie seiner in unserem Besitz befindlichen personenbezogenen Daten anfordern.
- falsche/unvollständige Teile seiner in unserem Besitz befindlichen personenbezogenen Daten berichtigen/vervollständigen.
- die Löschung seiner in unserem Besitz befindlichen personenbezogenen Daten beantragen.
- die Verarbeitung seiner in unserem Besitz befindlichen personenbezogenen Daten einschränken oder untersagen.
- die Übermittlung seiner personenbezogenen Daten an eine Drittpartei beantragen.
You can lodge a complaint directly with us via the contact details provided in Chapter 3 or with a relevant data protection supervisory authority:
- Information Commissioner of the Republic of Slovenia
- Dunajska cesta 22
- SI-1000 Ljubljana
Sollten Sie weitere Fragen hinsichtlich der Erfassung und Verarbeitung Ihrer personenbezogenen Daten haben, kontaktieren Sie bitte unseren Datenschutzbeauftragten unter email@example.com.
Änderung der Datenschutzerklärunglink