Data Processing Addendum

The GDPR data processing terms between you as controller and File Master LLC as processor, including subprocessors, security measures and transfer mechanisms.

Last updated 2026-08-26

This Addendum forms part of the Terms of Service and applies whenever we process personal data on your behalf under Regulation (EU) 2016/679 (GDPR). You are the controller; File Master LLC is the processor. Where the two documents conflict on data protection, this one wins.

Scope of processing

ItemDetail
Subject matterProvision of the Servers Sentinel monitoring service
DurationFor as long as your workspace exists, plus the retention windows in the Privacy Policy
Nature and purposeCollection, storage, aggregation, rule evaluation, alerting and display of server telemetry and security events
Categories of data subjectYour administrators and engineers; any person whose IP address or username appears in an authentication event on a monitored host
Categories of personal dataAccount identifiers, IP addresses, usernames present in authentication logs, hostnames, and any personal data you choose to put into server names, tags or custom metrics
Special categoriesNone. Do not send special-category data through custom metrics or tags.

Our obligations

  1. We process personal data only on your documented instructions, which the Terms and your configuration of the Service constitute. If we are legally required to process it otherwise, we will tell you unless the law forbids it.
  2. Everyone we allow to access the data is bound by confidentiality.
  3. We implement the technical and organisational measures listed below, and keep them under review.
  4. We assist you, taking into account the nature of processing, with data-subject requests, breach notification, and data-protection impact assessments.
  5. We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data.
  6. On termination we delete your data, subject to the backup ageing window and any retention the law requires of us.
  7. We make available the information needed to demonstrate compliance and allow audits, once per year on reasonable notice, or immediately after a breach.

Security measures

  • Mutual TLS between every agent and the ingest endpoint, with certificates issued by an internal CA.
  • Single-use enrollment tokens with an expiry, stored only as SHA-256 hashes, bound to a device identifier on redemption.
  • TLS 1.2+ for all browser and API traffic; HSTS enforced.
  • Passwords stored using a memory-hard hash. Optional TOTP two-factor authentication and OAuth sign-in.
  • Role-based access within a workspace, and an append-only audit log of administrative actions.
  • Encryption at rest for database volumes and backups.
  • Least-privilege access to production for operations staff, reviewed periodically.

Subprocessors

You give general authorisation for the subprocessors below. We will give you at least 30 days' notice by e-mail before adding or replacing one, and you may object on reasonable data-protection grounds - in which case you may terminate the affected part of the Service and receive a pro-rata refund.

SubprocessorPurposeLocation
PayPro GlobalInternational payment processing, merchant of recordCanada / EU
YooKassaPayment processing for customers in RussiaRussia
CryptomusCryptocurrency payment processingEU
Google Ireland LtdWebsite analytics (marketing pages only)EU / US
Hosting provider for the panel and databaseInfrastructureEU
Transactional e-mail relayVerification, password reset and alert e-mailEU

International transfers

Personal data for the hosted service is stored in the European Union. Where a subprocessor processes data outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914), with the supplementary measures described in the security section above.

Self-hosted deployments

To execute this Addendum, or to raise a data-protection question, write to tech.support@recoverytoolbox.com.