Moorfox

Legal

Privacy Policy

Effective 19 August 2026. Devsmooth Ltd., Surrey, British Columbia, Canada.

Plain-English summary

We collect what the product needs and nothing more: your account details, and the device and session data your organisation's use of Moorfox produces. The marketing site has no analytics or advertising trackers, and we never sell personal information.

For data about the people whose devices you manage, your organisation is in charge and we process it on your instructions under the Data Processing Addendum. If Moorfox is on your work computer, your IT provider or employer decides what is collected there: start with them.

The summary is here to help you read the document. The numbered sections below are the agreement.

1. Who this covers

This policy explains how Devsmooth Ltd. (Surrey, British Columbia, Canada) handles personal information across www.moorfox.com, the dashboard at app.moorfox.com, and the Moorfox agents. It is written to satisfy PIPEDA, British Columbia's PIPA, and, where it applies, the EU and UK GDPR.

2. Two roles, two kinds of data

For account holders, the people who sign up, sign in and use the dashboard, we decide how the data is handled and are the controller.

For managed devices and the people who use them, the organisation that enrolled the device decides why and how data is processed; we act on its instructions as a processor under the Data Processing Addendum. If Moorfox manages your work computer, questions about what is collected there go first to whoever runs your IT.

3. What we collect

Account data. Email address, organisation name, and a salted hash of your password (never the password itself). If you request an invitation, the email address you submit.

Device data, collected by the agent. Hostname, hardware and operating system details, installed software and patch status, security posture (for example disk encryption and update settings), logged-in user account names, and the device's network addresses. The agent collects what the dashboard shows; it does not log keystrokes and it does not scan the contents of personal files.

Session data. Remote desktop and quick support screens are streamed to the connected technician, not recorded or stored by us. What we do keep: session metadata (who connected to what, when, for how long), chat messages exchanged during sessions, file transfer records (names and sizes, not a copy of the file beyond the transfer itself), and the results of commands and flows your organisation runs.

Activity and server logs. Sign-ins, administrative actions and API calls, with IP addresses and timestamps, kept for security and audit.

Support. Tickets and feature requests you send through the Support tab, and emails we exchange with you.

Payment data. When paid billing is in effect, card details are handled by a dedicated payment processor and do not touch our servers; we keep the invoice records.

4. What we do not do

No advertising trackers and no third-party analytics, on the marketing site or in the product. No sale or rental of personal information, ever. No use of Customer Data to train machine-learning models. The only cookies and browser storage we use are the ones that keep you signed in and remember preferences like your theme.

5. Why we process it

To provide and secure the Service (performance of the contract), to stop abuse and defend the systems (legitimate interests), to send operational messages like alert emails and invoices (performance of the contract), to answer you when you write to us, and to meet legal obligations such as tax record-keeping. We send marketing only with consent, and every such email has an unsubscribe link.

6. Who we share it with

The subprocessors that host and run the Service, listed with their roles and locations in Annex 3 of the DPA: at present Hetzner (infrastructure), Amazon Web Services (storage and backups), Microsoft (email delivery) and Cloudflare (DNS and traffic protection). Beyond that, only professional advisers under confidentiality, authorities when the law genuinely requires it, and a successor if the business is sold, under this same policy. We do not have third-party "partners" who receive your data.

7. Where it lives

The Service runs on infrastructure in the European Union and the United States, with backups in the United States. Wherever the data is, it is protected by this policy, the DPA, and contracts with each subprocessor; for data subject to the GDPR we rely on Standard Contractual Clauses for transfers.

8. How long we keep it

Account and device data: for the life of the account, then deleted within 30 days of closure, after the export window described in the Terms. Activity logs: up to 24 months, for security and audit. Backups: age out automatically on the backup schedule, within about 35 days. Support correspondence: up to 24 months after the ticket closes. Invoices and tax records: 7 years, as Canadian law requires.

9. How we protect it

All traffic is encrypted in transit with TLS, including agent-to-server and remote-session traffic. Access to production systems is restricted, key-based and logged. Passwords are stored only as salted hashes, agents authenticate with per-device credentials, and releases are code-signed. Databases are backed up hourly to separate storage. No system is perfectly secure, but if a breach affects your personal information we will notify you and the authorities as the law requires.

10. Your rights

You can ask us for a copy of your personal information, ask us to correct or delete it, object to a use of it, or withdraw consent where consent is the basis. Write to support@moorfox.com and we will answer within 30 days. If you are unsatisfied you can complain to the Office of the Privacy Commissioner of Canada or your provincial or national authority. If your request concerns a device managed by another organisation, we will refer it to that organisation, as the DPA requires.

11. Children

The Service is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16 as a controller.

12. Changes

If we change this policy materially we will announce it by email or in the dashboard before the change takes effect, and this page always carries its effective date.

13. Contact

Privacy questions and requests: support@moorfox.com. Devsmooth Ltd., Surrey, British Columbia, Canada.