Parties and roles
The customer is controller of personal data submitted through enrolled devices and administrator accounts. Runtrace is processor and processes that data only on the customer's documented instructions, including configuration and use of the service, the applicable order form, and this addendum.
Processing details
- Subject matter: software inventory, vulnerability management, remediation workflow, reporting, account administration, support, and billing.
- Data subjects: customer administrators, billing contacts, support contacts, and people whose workstations are enrolled by the customer.
- Data types: account identifiers, device metadata, software inventory, vulnerability and finding metadata, remote scan and structured remediation records, reports, audit events, support records, and billing identifiers.
- Duration: the subscription term and the limited period required for return, deletion, backups, security, accounting, or legal obligations.
Runtrace obligations
- Process customer data only to provide, secure, support, and operate the service or as required by law.
- Ensure people authorized to process customer data are subject to confidentiality obligations.
- Maintain appropriate technical and organizational measures for the nature of the data and service.
- Assist the customer, taking into account the nature of processing, with data-subject requests, security obligations, and regulator inquiries.
- Notify the customer without undue delay after confirming a personal-data breach affecting customer data.
- Make information reasonably necessary to demonstrate compliance available for customer review.
Security measures
Runtrace uses organization-scoped authorization, role-based administrator access, server-side sessions, encrypted transport, per-device authentication, structured remote scans, allowlisted remediation actions, audit history, input validation, and backup procedures. The Security Overview and Data Inventory describe the current product boundary.
Subprocessors
The customer authorizes the subprocessors listed on the Subprocessors page. Runtrace remains responsible for their processing under applicable data-protection law and requires subprocessors to protect customer data under written terms. Runtrace will publish material changes to the list before the new provider processes customer data where reasonably practicable.
International transfers
Where customer data is transferred outside the European Economic Area, Runtrace will use a valid transfer mechanism and supplementary safeguards where required. Enterprise customers may agree deployment-region restrictions in an order form.
Return and deletion
During the subscription, authorized administrators can export organization data. At the end of the service, Runtrace will delete or return customer data according to the customer's instructions, the Retention Policy, backup lifecycle, and applicable law.
Customer obligations
The customer is responsible for lawful device enrollment, transparency notices, a valid legal basis, administrator role assignment, and instructions that comply with applicable law.