Privacy Policy
Effective as from 15 August 2026
At ISL Online, we respect the privacy of our website visitors and users who use our products and services. The purpose of this Privacy Policy is to make our activities related to the processing of your personal data as transparent as possible and to give you control over your own personal information. We will always strive to collect and process your personal data fairly and to keep it secure and confidential.
- Introduction
- Definitions
- Summary
- Controller, Processor, and Data Protection Officer
- Processing Overview
- Retention Periods
- Children
- Data Protection and Security
- Website Visitors
- Registration
- Notifications and Newsletter
- Additional Features
- Billing
- Customer Support
- Product Use
- Transfer of Personal Data to Third Countries
- Third Parties
- Managed Private Cloud
- Self-Hosted Solution
- Your Rights
- Contact Us
- Changes to this Privacy Policy
Introduction
ISL Online (“we”, “us”, “our”) has prepared this policy to provide information about the collection and processing of personal data when using the products and services offered on the official websites (islonline.com and islonline.net). The main purpose of the ISL Online software is to allow IT professionals and helpdesk technicians (“Operator”) to establish remote desktop sessions over the Internet for their business purposes, i.e., to provide technical support to their customers (“Client”) remotely or to access unattended remote computers.
This Privacy Policy describes which personal data we collect at various levels of your engagement with us, where your personal data is stored, and the security measures we use to protect it. We address personal data protection in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR). Where we rely on legitimate interest as our legal basis for processing, you have the right to object to that processing at any time in accordance with Article 21 GDPR. Your rights, including how to exercise them, are described in full in Chapter 20.Definitions
- Hosted Service: the cloud-delivered ISL Online service operated from ISL Online’s server network. The Hosted Service is distinct from the Managed Private Cloud (Chapter 18) and Self-Hosted Solution (Chapter 19) deployments.
- Authorized Partner: a distributor, reseller, or other third party that has signed an agreement with ISL Online and assists us in performing customer-care functions such as sales, marketing, and customer support in their respective regions.
- Website visitor: any individual visiting our official websites or social media sites for informative purposes only.
- Operator: any individual registered with an ISL Online account. Typically, this refers to an IT professional or helpdesk technician who offers support to a Client.
- Client: an end-user who joins remote desktop sessions, usually without any credentials, to receive technical support from Operators.
- Administrator: a privileged Operator who has permission to manage ISL Online licenses and accounts of other Operators within an organization.
Summary
We understand that this Privacy Policy is extensive. This section provides a brief, user-friendly overview of its main points. In the event of any discrepancy between this summary and the full Privacy Policy, the full Privacy Policy shall prevail.Who We Are
Controller: ISL Remote d.o.o., Pot za Brdom 100, 1000 Ljubljana, Slovenia, EU.
Email: dataprotection@islonline.com.
We may also act as a Processor when you use our software to support your own clients.What Data We Collect
Why We Use Your Data
How Long We Keep Your Data
For full retention periods, see Chapter 6. In brief: account data is retained for up to three years after subscription end; billing records are retained for ten years.Who We Share Data With
We do not sell your data. We only share it with: If we transfer personal data outside the EU, we rely on adequacy decisions, the EU-US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses with supplementary technical and organizational measures. Where required, we have also carried out Transfer Impact Assessments and Data Protection Impact Assessments. See Chapter 16 for details and recipient locations.- Account data: Email (required), username (required), name (optional), company details.
- Technical data: IP address, MAC address, device info, session metadata (see our Security Statement).
- Billing data: Name, company address, phone, payment details.
- Support requests: Data you provide when contacting us by chat, email, or phone.
- Cookies and analytics: Website usage info (with your consent for non-essential cookies).
- To provide our services and fulfill contracts (Article 6(1)(b) GDPR, performance of contract).
- To improve our products and user experience (Article 6(1)(f) GDPR, legitimate interest).
- To comply with tax and legal obligations (Article 6(1)(c) GDPR, legal obligation).
- To send you product or service offers from ISL Online, which may include information about complementary products available within our corporate group (Article 6(1)(f) GDPR, legitimate interest). You can opt out of these communications at any time.
- To deliver newsletters and to activate analytics and website features where you have given your consent (Article 6(1)(a) GDPR, consent).
- Our subsidiaries (UK, Switzerland, Germany, only if applicable to you);
- Authorized Partners (for sales, support, or marketing, only if applicable to you);
- Service providers (e.g., data centers, Cloudflare, and other third parties engaged to support the delivery, security, and maintenance of our services);
- PDQ.com Corporation (our parent company), as our processor for market analytics and Security Operations Center services;
- Public authorities (only if legally required).
Controller, Processor, and Data Protection Officer
While using ISL Online products and services, the legal entity collecting and processing personal data is:
ISL Online Headquarters ISL Remote d.o.o.
Pot za Brdom 100
SI-1000 Ljubljana
Slovenia, European Union
VAT ID: SI 24379905
Reg. Number: 7300514
dataprotection@islonline.com
+386 1 2447760
ISL Online assumes both the role of data Controller and data Processor regarding different interactions with our customers and the corresponding personal data:Sub-processors and Affiliated Processors
In addition to ISL Online, the processor or sub-processor of personal data may be: A current list of Authorized Partners, including their location and the categories of data processed, is available at https://www.islonline.com/company/contact-us.htm.Data Protection Officer
We have appointed a Data Protection Officer (DPO) responsible for overseeing our data protection compliance. You may contact our DPO directly with any questions or concerns regarding the processing of your personal data:
Email: dataprotection@islonline.com
Phone: +386 1 2447760
Postal: ISL Remote d.o.o., Pot za Brdom 100, SI-1000 Ljubljana, Slovenia, EU.- ISL Online acts as the Controller for personal data described in Chapters 9-15 of this Policy (website visitors, registration, notifications, additional features, billing, customer support, and product use).
- ISL Online acts as the Processor for personal data of your Clients (the persons you support remotely) described in Chapter 15 (Product Use), where processing is carried out under your instructions. A Data Processing Agreement (DPA) is available to you once you log in at islonline.com under My Profile.
- Companies affiliated with us (our subsidiaries):
- ISL Online Ltd., 22 Basepoint Business Centre, Rivermead Drive, Westlea, Swindon, SN5 7EX, United Kingdom;
- ISL Online AG, Aargauerstrasse 250, 8048 Zurich, Switzerland;
- ISL Online GmbH, Noetherstrasse 1, D-69115 Heidelberg, Germany;
- PDQ.com Corporation, the parent company of ISL Online. PDQ.com Corporation acts as our processor for the market and usage analyses described in Chapter 17, Section E and for the Security Operations Center services described in Chapter 17, Section B. PDQ.com Corporation processes personal data exclusively on our documented instructions under a written processor agreement compliant with Article 28 GDPR.
- Third parties, including Authorized Partners and external contractual service providers (e.g., Google Analytics). These are described in Chapter 17 (Third Parties).
Processing Overview
The table below summarizes the personal data for which ISL Online acts as a Controller as described in Chapters 9 to 15. Where ISL Online acts as a Processor (see Chapter 15), the relevant data processing details are set out in the Data Processing Agreement (DPA).Purpose of processing Enabling the use of ISL Online products and services in accordance with the Terms of Service and License Agreement; operating our websites; providing customer support; and meeting our legal obligations. Categories of data subjects Website visitors, registered users (Operators, Administrators), prospective customers, billing contacts. Categories of personal data Identification and contact data (name, username, email, phone); company and billing data (company name, address, VAT, payment details); technical and device data (IP address, MAC address, operating system, browser); usage and session metadata; support and communication content (including chat transcripts and free-form session inputs); consent and preference records. Duration of processing Specific retention periods are set out in Chapter 6. For registered users, processing generally extends for the duration of the contractual relationship plus the retention periods in Chapter 6. For website visitors, processing is limited to the visit and the retention periods set out for analytics and security data. Retention Periods
Account Data
Usage Data
Billing Records
Retained for ten (10) years in accordance with applicable legal and tax requirements.Support Requests
Retained for three (3) years from closure of the support ticket, after which records are deleted or anonymized.Chat Transcripts and Session Inputs (Chapter 12)
If created, they are retained alongside session metadata for the period applicable to the relevant Operator account (see Account Data, above).Newsletter and Marketing Consent Records (Chapter 11)
Consent records are retained for as long as the corresponding Account Data is held (see Account Data, above).Cookie Consent Records (Chapter 17, Section D)
Retained for the validity period of the consent record (typically up to twelve (12) months) and renewed on each new consent action.Security Event Data (Chapter 17, Section B)
Retained for up to 180 days, after which non-incident data is deleted. Data tied to a security incident is retained for the duration of the investigation and any required post-incident review.Web Analytics Data (Google Analytics, Leadfeeder)
Retained according to each provider’s default retention window, currently fourteen (14) months for Google Analytics and twelve (12) months for Leadfeeder, unless a shorter period applies based on your cookie preferences.- Customers: retained for three (3) years and one (1) month after the end of your subscription.
- Trial users: retained for one (1) year and one (1) month after the trial expiration date.
- Reports: data available to users through the Reports feature is retained for three (3) years and one (1) month from the date of creation.
- Service and system logs: data accessible to ISL Online administrators is retained for up to one (1) year, and may be deleted earlier when no longer needed for security, troubleshooting, or service maintenance purposes.
Children
ISL Online products and services are designed for use by professionals and organizations and are not directed at children. We do not knowingly process personal data of individuals below the digital age of consent applicable in their country of residence. If we become aware that personal data of such an individual has been collected inadvertently, we will take appropriate steps to delete it without undue delay.Data Protection and Security
ISL Online Headquarters (ISL Remote d.o.o.) holds the ISO/IEC 27001:2022 certificate, which demonstrates our commitment to information security. We use the globally recognized ISO 27001 standard as a framework for implementing our information security management system (ISMS), which helps us keep information assets secure.
All our servers have disk encryption and are exclusively managed by the controller’s operations team. Data is encrypted both at rest and in transit. We have physical and logical access procedures and controls in place, and we conduct training for our employees and contractors to ensure compliance with our data protection and privacy policies.
We employ the latest technologies and administrative procedures to safeguard your personal data. ISL Online servers are hosted by professional, industry-proven data centers with modern facilities and equipment, including redundant or backup power supplies, redundant data communication connections, environmental controls, and security devices.
ISL Online master servers, which hold the data for which ISL Online acts as a Controller, are located within the European Union in ISO 27001-certified data centers. Session metadata for which ISL Online acts as a Processor is replicated across our worldwide network of servers and gets processed in a location selected by our load-balancing system, which includes locations outside the EU. Server locations are shown at: islonline.com/company/about-us.htm.Website Visitors
Legal basis: legitimate interest (Article 6(1)(f) GDPR).
When you visit our website, we collect a limited scope of personal data transmitted to us by your browser. This helps us provide the service and improve the user experience. Data collected consists of your IP address and metadata (such as timestamp), technology used (operating system, browser), referrals (website from which the request comes), language, and the country of origin.
Your IP address is also collected by our systems for security reasons to detect anomalous activity (including DNS attacks, scam detection, and other activities that could compromise the security or availability of our systems). Browser metadata, language, and country of origin are used to serve the correct version of our website. Referral addresses, if obtained, are used by ISL Online to understand where our traffic is coming from.Registration
Legal basis: performance of a contract (Article 6(1)(b) GDPR).
If you decide to sign up for a free trial of ISL Online software, we will ask you to provide the following personal information: We process this information to fulfill the contractual obligation. The username can be used as an alternative to an email address when logging into ISL Online products and services. The full name is optional and can be specified to personalize the user experience.
For billing purposes, we also ask you to provide the name of the company, address, phone number, and similar information, which will be needed if you decide to buy a license. You can review and change this information at any time (log in to My Account > License > Change Information).
Based on your country of origin, your account information may be processed by the ISL Online Headquarters, our subsidiaries, or Authorized Partners. These processors have access to the personal data needed only to perform their customer-care functions and may not use it for any other purpose. You have the option to choose your preferred point of contact at any time (log in to My Account > License > Change Local Partner).- Email address (required)
- Username (required)
- Full name (optional)
Additional Features
Legal basis: performance of a contract or legitimate interest, depending on the feature (Article 6(1)(b) and (f) GDPR).
Some organizations may enable additional features provided by ISL Online, such as: Enabling such features may result in collecting text messages (chat transcripts) and different free-form inputs related to a remote desktop session, stored on ISL Online servers alongside metadata. Chat transcripts are available to Operators and Administrators of the respective organizations.
ISL Online encourages users to exercise caution when entering personal or confidential information into session chats, end-of-session dialogs, or other features that allow free-form user input. Any information entered in this manner becomes subject to data processing.
Due to the nature of such free-form content, the exercise of certain data subject rights such as access, rectification, or portability may be technically limited. Where technically feasible, ISL Online can support the deletion of such data upon request.
In the case of integration of ISL Online software into third-party solutions, the chat transcript may be transferred to those systems. We do not control the personal data collected and managed by these enterprise systems. We recommend contacting the enterprise system providers directly for their privacy policies.- ISL Pronto: a text-chat solution that can be published on a website, allowing Clients to join a support session directly.
- End-of-Session dialogs: pop-ups for Operators or Clients after a session, used for collecting feedback.
- Integration into third-party solutions: such as service desk or ticketing products, CRMs, ERPs, and other enterprise systems.
Billing
Legal basis: performance of a contract (Article 6(1)(b) GDPR) for order and invoice processing; compliance with a legal obligation (Article 6(1)(c) GDPR) for retention of financial records.
When an organization decides to purchase ISL Online licenses, we will collect the information needed for billing and order processing purposes, which may include your name, company name, company address, email address, and telephone number. We will keep purchase orders and invoice records for ten years in accordance with applicable legal and tax requirements (see Chapter 6).Customer Support
Legal basis: performance of a contract (Article 6(1)(b) GDPR) for support requests from existing customers; legitimate interest (Article 6(1)(f) GDPR) for support requests from prospective customers.
When you contact our service desk via live chat, email, or phone, we may collect your email address, your name, and your telephone number to respond to your inquiry. Your message will also be stored and might be shared with our Authorized Partners to provide prompt and localized customer service to you.
ISL Online uses Zendesk to manage support requests. Personal data collected in the context of customer support is processed through Zendesk’s platform. Further details are available in Chapter 17, Section C.
Where we rely on legitimate interest (support requests from prospective customers), you have the right to object to this processing at any time in accordance with Article 21 GDPR (see Chapter 20).Product Use
Legal basis: performance of a contract (Article 6(1)(b) GDPR) for service delivery; legitimate interest (Article 6(1)(f) GDPR) for security and licensing monitoring.
Upon account activation, we collect your IP address and MAC address on each successful login for auditing, licensing, and misuse prevention purposes. To safeguard the integrity of our software, ISL Online monitors account usage to identify and prevent licensing violations, excessive usage, fraudulent behavior, and other activities that do not align with our Fair Usage Policy. Where ISL Online uses automated monitoring to detect licensing violations or fraudulent behavior, any material account action resulting from such monitoring, including suspension or termination, is subject to human review prior to implementation.
All remote desktop sessions are encrypted using symmetrical AES 256-bit keys. A secure SSL end-to-end tunnel is established between a local and a remote computer or device.
Depending on the connection type (Standard or Direct) the remote desktop session is either routed via one of ISL Online’s servers (Standard connection), routed via a TURN server (Direct connection, relayed), or established directly between a local and remote computer (Direct connection, no relay). Since end-to-end encryption is used, no relay point, not even ISL Online servers, can decrypt the content of the sessions. Neither we nor any third party collects any personal data transmitted via the remote desktop data stream.
ISL Online processes the personal data of the people you are supporting upon your request and according to your instructions, assuming the role of data processor. A data processing agreement (DPA) is available to you once you log in at islonline.com under My Profile. A detailed list of basic session parameters (metadata) is available in our Security Statement.Metadata Collected
Source Data Collected Operator device Username, email address, IP address, MAC address. Client device IP address, MAC address. Third parties engaged by ISL Online IP address (as further described in Chapter 17). Transfer of Personal Data to Third Countries
ISL Online operates a worldwide network of servers to provide the Hosted Service. This means that personal data may be transferred to and processed in countries outside the European Economic Area. Where such transfers occur, ISL Online ensures an adequate level of protection through the following: A current list of sub-processors, their locations, and the applicable transfer safeguard for each is available in the Data Processing Agreement, accessible upon login at islonline.com under My Profile. The third parties ISL Online engages in connection with its products and services are described in Chapter 17.- Where a transfer is to a country covered by a European Commission adequacy decision, we rely on that decision as the transfer basis.
- Where a recipient is certified under the EU-US Data Privacy Framework, we rely on that certification as the transfer basis.
- All data is encrypted in flight and at rest. ISL Online is the only entity that holds the encryption keys for server disk storage and for TLS connections used to deliver the service. Session content transmitted between Operator and Client devices is end-to-end encrypted; ISL Online does not hold the keys for session content and cannot access it. For Managed Private Cloud and Self-Hosted Solution deployments, the customer organization controls the server infrastructure (see Chapters 18 and 19).
- In cases where data transfer to a third country is not covered by an Adequacy Decision or the EU-US Data Privacy Framework, ISL Online relies on Standard Contractual Clauses (SCCs) signed with the relevant providers, supplemented where necessary by technical and organizational measures appropriate to the risks identified in our Transfer Impact Assessments.
- ISL Online also maintains ISO/IEC 27001:2022 certification as a general organizational safeguard applicable across all processing and transfer activities.
Third Parties
Within the context of the services provided by ISL Online, including our websites and online presence, we may share your personal data with the third parties listed in this chapter. The legal basis for sharing with each category of third party is indicated below.- Service Provisioning
Legal basis: performance of a contract (Article 6(1)(b) GDPR). Engagement of the parties listed in this section is necessary for the delivery of ISL Online services.
ISL Online engages certain third parties while providing the Hosted Service. Those parties are essential and are engaged solely in the context of service provision. They are described in more detail in the DPA (My Account > My Profile > DPA) and fall into the following main categories:- Data Centers: (physically) hosting the nodes of ISL Online’s network providing the Hosted Service. They store and manage encrypted data. Since they provide network connectivity to the servers, they will process the IP address of the Operator and the Client connected to a remote desktop session.
- STUN/TURN/ICE providers: providers that support the “Direct Connection” feature of ISL Online. Third-party (TURN/STUN) servers allow the Operator and the Client to discover each other and establish a direct connection between them. Since they provide IP discovery capabilities, they will process the IP address of the Operator and the Client trying to establish a remote desktop session.
- IP Quality and Reputation services: services used by ISL Online in the session establishment process to obtain additional information about a potentially suspicious IP address. Sessions deemed “high risk” according to our internal security algorithms are dropped to protect our customers. They will process the IP address of the Operator and the Client provided to them by ISL Online for further verification.
- Security and Protection
Legal basis: performance of a contract (Article 6(1)(b) GDPR). Engagement of the parties listed in this section is necessary for the delivery of ISL Online services.- Cloudflare
Cloudflare is used by ISL Online to protect its website from abuse and malicious actors. ISL Online uses Cloudflare for website protection, load balancing, and rate limiting. More information is available at Cloudflare’s website.
Contact: privacyquestions@cloudflare.com - Microsoft (Defender for Servers)
ISL Online has deployed Microsoft Defender for Servers across our server infrastructure to enhance our overall security posture, strengthen threat detection and response, reduce exposure to risk, and provide a centralized view of system security. ISL Online operates a Security Operations Center for monitoring and responding to security events detected on our infrastructure. PDQ.com Corporation personnel are engaged to support the SOC under our processor agreement and act exclusively on ISL Online’s instructions; PDQ.com Corporation does not use security event data for its own purposes. See also Chapter 4 (Sub-processors and Affiliated Processors).
Where Microsoft Defender for Servers generates alerts or threat intelligence derived from Microsoft’s global threat detection network rather than solely from ISL Online’s own infrastructure, such information is received from Microsoft rather than from you directly. We use it solely for the security purposes described in this section.
Contact: via Microsoft Privacy Requests. - reCAPTCHA
ISL Online uses reCAPTCHA, operated by Google LLC, to protect our websites from automated abuse. reCAPTCHA uses advanced risk analysis techniques to distinguish human users from bots. Google processes reCAPTCHA data as a data processor on ISL Online’s behalf, under the Google Cloud Data Processing Addendum. Data processed includes IP address and browser metadata. This transfer is covered by the EU-US Data Privacy Framework. ISL Online uses reCAPTCHA with the recaptcha.net domain. Further technical information is available at docs.cloud.google.com/recaptcha/docs.
- Cloudflare
- Operational Tools
Legal basis: legitimate interest (Article 6(1)(f) GDPR) for requests relating to prospective customers; performance of a contract (Article 6(1)(b) GDPR) for requests relating to existing customers.- Zendesk
ISL Online uses Zendesk to manage customer support requests submitted via email, live chat, or web form. When you contact our support team, your name, email address, and the content of your support inquiry are processed through Zendesk’s platform. For information on Zendesk’s data handling practices, see Zendesk’s Privacy Policy.
Contact: privacy@zendesk.com - Anthropic
ISL Online uses Claude, an AI assistant operated by Anthropic PBC, to support employees in handling customer support requests and daily operational workflows. While using Claude, employees may process limited customer-related personal data, such as name, email address, and support request content. ISL Online applies data minimization measures to limit the personal data submitted through Claude to what is necessary for the task at hand, including the use of custom integration layers that strip personally identifiable information prior to submission and pseudonymization of personal data before it is passed to Claude. No special category personal data is submitted to Claude. ISL Online accesses Claude through a paid subscription, so all use is contractually covered under Anthropic’s commercial terms, and Claude does not use this data to train its models. - OpenAI
ISL Online uses ChatGPT, an AI assistant operated by OpenAI, to support employees in handling customer support requests and daily operational workflows. While using ChatGPT, employees may process limited customer-related personal data, such as name, email address, and support request content. ISL Online applies data minimization measures to limit the personal data submitted through ChatGPT to what is necessary for the task at hand, including the use of custom integration layers that strip personally identifiable information prior to submission and pseudonymization of personal data before it is passed to ChatGPT. No special category personal data is submitted to ChatGPT. ISL Online accesses ChatGPT through a paid subscription, so all use is contractually covered under OpenAI’s commercial terms, and ChatGPT does not use this data to train its models. - Pipedrive
ISL Online uses Pipedrive as a customer relationship management platform to manage sales pipelines and customer data. Personal data processed through Pipedrive may include name, email address, company details, and account-related information. ISL Online’s contractual relationship is with Pipedrive OÜ, an entity established in Estonia, and data is hosted within the European Economic Area. Pipedrive processes personal data as a data processor on ISL Online’s behalf. For information on Pipedrive’s data handling practices, see Pipedrive’s Privacy Policy.
Contact: privacy@pipedrive.com - Salesforce
ISL Online uses Salesforce as a customer relationship management platform to manage sales and customer data. Personal data processed through Salesforce may include name, email address, company details, and account-related information. Salesforce processes personal data as a data processor on ISL Online’s behalf. The transfer of personal data to Salesforce, Inc. in the United States is covered by Standard Contractual Clauses (Module Two, controller to processor) under Commission Implementing Decision (EU) 2021/914. For information on Salesforce’s data handling practices, see Salesforce’s Privacy Policy.
Contact: privacy@salesforce.com
- Zendesk
- Web Analytics
Legal basis: consent (Article 6(1)(a) GDPR). Analytics tools listed in this section are activated only where you have provided consent via our cookie consent mechanism. You may withdraw your consent at any time by adjusting your cookie preferences.- Cookies
Our websites use cookies, which are small text files stored on your device. Some cookies are essential or functional and are required for the website to operate properly or improve user experience. We also use certain third-party cookies, which you can opt out of. For more information, please refer to our Cookies Policy. - Google Analytics
Google Analytics is used by ISL Online to understand how visitors use our website and to inform improvements to layout and workflow. We apply IP anonymization, which truncates the last octet of the IP address as a pseudonymisation measure. Google Analytics involves a transfer of personal data to Google LLC in the United States; this transfer is covered by the EU-US Data Privacy Framework. More information is available in Google’s Privacy Policy. - Google Tag Manager
Google Tag Manager is used by ISL Online to support the usage of Google Analytics. The Google Tag Manager system itself does not collect any user information. More information is available in Google’s Privacy Policy.
Contact: Google Privacy Inquiry form.
- Cookies
- Market Analytics and Strategy
Legal basis: legitimate interest of ISL Online (Article 6(1)(f) GDPR) in understanding market trends, customer segments, and usage patterns to inform our product, service, and business development activities. Processing is limited to what is necessary for these purposes and takes into account the rights and interests of data subjects.- PDQ.com Corporation
ISL Online engages PDQ.com Corporation, our parent company, as a data processor to perform market analytics on our behalf. For this purpose, PDQ.com may process limited customer-related data, such as name, email address, company name, account information, and usage data, under our documented instructions.
Outputs from these analyses may also help ISL Online provide information about ISL Online products and services, including related or complementary products available within our corporate group. You can opt out of marketing communications at any time using the subscription management options described in Chapter 11, or by contacting dataprotection@islonline.com.
- PDQ.com Corporation
- Third-Party Services (Website Features)
Legal basis: consent (Article 6(1)(a) GDPR) where third-party features are loaded via cookies or activated through your interaction with embedded content. You may withdraw your consent at any time by adjusting your cookie preferences.
To provide services and improve our official websites, we may engage the services of third-party vendors such as Vimeo, YouTube, and Google Maps. In supplying such website services, these third-party vendors may collect your IP address or other information provided by your browser.
Where these features load on our website, ISL Online is responsible for the collection and transmission of your personal data to the relevant third party. Once received by the third party, that party processes your personal data under its own privacy policy and as an independent controller. You may exercise your rights against ISL Online in relation to the collection and transmission, and against the third party in relation to subsequent processing. - Blog
Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Besides the official websites, we use a blog hosted by WordPress.com to publish content. WordPress.com offers features such as “Subscribe to blog” and “Reply to a blog post”. We do not control the personal data collected and managed by these blog features. If you wish to use these features and have any concerns, we recommend that you contact WordPress.com directly for their privacy and data-sharing policies. - Public Authorities
Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
Under certain circumstances it may be necessary for us to disclose your personal information to relevant public authorities to comply with a legal obligation, court order, or in response to a valid request by public authorities. Our legal team reviews all requests for data access to ensure they comply with applicable legal requirements. - Authorized Partners
Legal basis: legitimate interest (Article 6(1)(f) GDPR). ISL Online has a legitimate interest in working with regional partners to provide localized sales, marketing, and customer-care support to prospective and existing customers.
ISL Online works with a network of Authorized Partners, including distributors and resellers, who may assist us in performing customer-care functions such as sales, marketing, and customer support in their respective regions. Where your account is managed through an Authorized Partner, that partner may have access to your account data, including your name, email address, company details, and relevant account status information, to the extent necessary to perform those functions.
Authorized Partners process personal data on ISL Online’s behalf under written agreements that restrict their use of personal data to the purposes described above. They may not use it for their own independent purposes.
You may identify your current Authorized Partner and update your partner preference at any time by logging in to My Account > License > Change Local Partner. A list of ISL Online’s Authorized Partners and their locations is available at https://www.islonline.com/company/contact-us.htm.
Where you have questions about how your Authorized Partner handles personal data in connection with ISL Online services, you may contact us at dataprotection@islonline.com.
- Service Provisioning
Managed Private Cloud
Under the Managed Private Cloud (MPC) plan, ISL Online deploys and operates dedicated server infrastructure in locations selected by the customer organization. In this context, the customer organization acts as the data Controller and ISL Online acts as the data Processor, operating solely under the customer’s instructions. Data processing obligations are governed by the MPC Agreement signed between the parties.
For more information please refer to islonline.com/si/en/enterprise/managed-private-cloud.htm or contact us directly at islonline.com/company/contact-us.htm.Self-Hosted Solution
Under the self-hosted solution, the ISL Online system is installed on servers owned and operated by the customer organization. All data, including session metadata, remains within the customer’s infrastructure. The customer organization acts as the data Controller and is solely responsible for the administration of the servers and the protection of personal data of their users.
If you are using a self-hosted system and have concerns or requests related to your personal data, contact the Administrators of the relevant organization directly. ISL Online does not have access to data held in self-hosted environments.
For more information, contact us at islonline.com/company/contact-us.htm.Your Rights
The rights described in this chapter apply to personal data for which ISL Online acts as a Controller. Where ISL Online acts as a Processor, for example when processing session data on behalf of an Operator’s organization, the data subject rights in relation to that data must be exercised directly with the relevant Controller, which is the Operator’s organization. ISL Online will redirect any requests it receives in this context to the appropriate Controller without undue delay.
As a data subject whose personal data we process, you have the following rights: To exercise any of these rights, please contact us via the contact details provided in Chapter 21.
We will respond to your request within one month of receipt. Where the request is complex or numerous, we may extend this period by up to two further months and will inform you of any such extension within the first month, together with the reasons. To protect your personal data, we may ask you to provide additional information to verify your identity before acting on a request.Right to Lodge a Complaint
If you have any concerns, you can lodge a complaint directly with us or with a relevant data protection supervisory authority:- Information Commissioner of the Republic of Slovenia
- Dunajska cesta 22
- SI-1000 Ljubljana
- www.ip-rs.si
- Right of access and to a copy: you have the right to know which types of personal data we hold, how we obtained it, how we process it, and to receive a copy of that data in our possession (Article 15 GDPR).
- Right to rectification: you have the right to rectify or complete any incorrect or incomplete parts of your personal data in our possession (Article 16 GDPR).
- Right to erasure: you have the right to request the erasure of your personal data in our possession, subject to applicable legal obligations (Article 17 GDPR).
- Right to restriction: you have the right to restrict the processing of your personal data in our possession (Article 18 GDPR).
- Right to object: you have the right to object at any time to processing of your personal data where we rely on legitimate interest as our legal basis. Where you object, we will stop processing your personal data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims (Article 21 GDPR).
- Right to data portability: you have the right to request the transmission of your personal data to a third party in a structured, commonly used, machine-readable format (Article 20 GDPR).
- Right to withdraw consent: where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal (Article 7(3) GDPR).
Contact Us
If you have any additional questions or concerns about the collection and processing of your personal data, please do not hesitate to contact our Data Protection Officer:
Email: dataprotection@islonline.com
Phone: +386 1 2447760
Post: ISL Remote d.o.o., Pot za Brdom 100, SI-1000 Ljubljana, Slovenia, EUChanges to this Privacy Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify registered users by email and/or by an in-product notice prior to the changes taking effect. Where changes are not material, the updated version will be published on this page with a revised effective date and version number. Previous versions of this Privacy Policy are available on request.