Moorfox

Legal

Data Processing Addendum

Effective 19 August 2026. Devsmooth Ltd., Surrey, British Columbia, Canada.

Plain-English summary

When your organisation manages devices with Moorfox, data about the people who use those devices passes through our systems. This addendum is the contract for that: you are the controller, we are the processor, and we only act on your instructions.

It lists exactly what we process, how it is protected, which subprocessors we use, and what happens when you leave: your data is exportable for 30 days, then deleted.

The summary is here to help you read the document. The numbered sections below are the agreement.

1. What this is

This Data Processing Addendum ("DPA") forms part of the Terms of Service or, where one is signed, the Master Service Agreement (either, the "Agreement") between Devsmooth Ltd. ("Devsmooth") and the Customer. It applies whenever Customer Data includes personal data whose controller is the Customer or the Customer's clients. If this DPA conflicts with the Agreement on the handling of personal data, this DPA prevails.

2. Roles

The Customer is the controller (or, where the Customer is an IT provider acting for its own clients, a processor acting on their behalf), and Devsmooth is the Customer's processor. Each party complies with the data protection laws that apply to it, including PIPEDA and, where applicable, the EU and UK GDPR. The details of the processing are in Annex 1.

3. Instructions

Devsmooth processes personal data only on the Customer's documented instructions, which are: the Agreement, this DPA, and the Customer's use of the Service's controls (enrolling devices, running sessions, commands and flows, configuring alerts, and so on). Devsmooth will inform the Customer if it considers an instruction unlawful, unless the law forbids telling.

4. Confidentiality and personnel

Access to personal data is limited to people who need it to operate the Service, and everyone with access is bound by confidentiality obligations.

5. Security

Devsmooth implements and maintains the technical and organisational measures in Annex 2, and may improve them over time, but not in a way that lowers the overall protection.

6. Subprocessors

The Customer gives general authorisation for the subprocessors in Annex 3. Devsmooth will publish changes to the list on this page at least 30 days before a new subprocessor processes personal data, and will flag the change in the dashboard or by email. If the Customer reasonably objects on data protection grounds and no accommodation can be found, the Customer may terminate the affected services and receive a refund of any fees prepaid for the period after termination. Devsmooth remains responsible for its subprocessors' performance and binds each of them to obligations materially equivalent to this DPA.

7. Assistance

Taking into account the nature of the processing, Devsmooth will assist the Customer with data subject requests (access, correction, deletion, objection), with security and breach obligations, and with data protection impact assessments, in each case as far as the information is available to Devsmooth and the Customer cannot get it through the Service itself. If a data subject contacts Devsmooth directly about a device managed by the Customer, Devsmooth will refer them to the Customer.

8. Personal data breach

Devsmooth will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the Customer's personal data, with the information the Customer needs for its own notification duties: what happened, what data and how many data subjects are affected, what is being done, and a contact point. Devsmooth will not characterise the incident on the Customer's behalf.

9. Deletion and return

During the term, the Customer can export Customer Data through the Service and can delete devices, sessions and records with the Service's own controls, including permanent forget-and-purge of a device. After the Agreement ends, Devsmooth will make Customer Data available for export for 30 days, then delete it from live systems; backup copies age out automatically within about 35 days and are not restored except to recover the Service. Records Devsmooth must keep by law are retained only for that purpose and duration.

10. Audits

Devsmooth will make available the information reasonably necessary to demonstrate compliance with this DPA, starting with written answers and documentation. Where a law or authority requires more, the Customer (or an independent auditor that is not a competitor) may audit, at its own cost, at most once a year, on 30 days' notice, during business hours, without disrupting the Service, and under confidentiality.

11. International transfers

Personal data is processed in the locations listed in Annex 3. For personal data subject to the EU or UK GDPR transferred to countries without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (module 2, controller to processor; module 3 where the Customer is itself a processor), and the UK Addendum for UK data, with the annexes of this DPA supplying the required information.

12. Liability and law

Liability under this DPA is subject to the limitations in the Agreement. This DPA is governed by the same law and jurisdiction as the Agreement.

Annex 1: details of processing

ItemDescription
Subject matter and natureHosting and operating remote monitoring and management: collecting device inventory and health, relaying remote control and support sessions, executing commands, flows and patch policies, alerting, and record-keeping of the above.
DurationThe term of the Agreement, plus the export and deletion windows in section 9.
PurposeProviding the Service to the Customer; no other purpose.
Data subjectsThe Customer's staff who use the dashboard; people who use the Customer's managed devices; people who request or join attended support sessions.
Categories of personal dataNames and email addresses of dashboard users; device identifiers, hostnames, user account names, IP addresses; installed software and patch state; session metadata and chat messages; the content of what a technician sees or transfers during a live session (streamed, not stored); activity logs.
Special categoriesNone intended. The Service is not designed for them, and the Customer agrees not to target them at it.

Annex 2: technical and organisational measures

Annex 3: subprocessors

SubprocessorRoleLocation
Hetzner Online GmbHServers and network infrastructureGermany, Finland, United States
Amazon Web Services, Inc.Object storage: database backups and release artefactsUnited States
Microsoft CorporationTransactional email delivery (Microsoft 365)Canada, United States
Cloudflare, Inc.DNS, TLS and traffic protectionGlobal network

When the Bitdefender EDR add-on becomes available, Bitdefender (via the Pax8 marketplace) will be added to this list before any Customer personal data reaches it, with the notice period in section 6.