Plain-language summary
Device information is processed only for devices the customer owns or is expressly authorized to administer.
Administrative access is role-scoped, support sessions are consent-aware, and security-relevant actions are auditable.
Myserver MS does not sell personal information or share it for cross-context behavioral advertising.
We never ask for wallet seed phrases, private keys, passwords by email, or device credentials in support forms.
This summary is provided for convenience. The full policy below controls if a summary and a detailed provision differ.
Scope, controller, and service-provider roles
This policy applies to Myserver MS websites, account and demo forms, dashboards, APIs, authorized device agents, audit and reporting features, payment-status workflows, and support communications that link to this policy.
For website visitors, account applicants, and direct customers, Myserver MS generally determines why and how the information is processed. When an organization uses Myserver MS to manage its own users or authorized devices, that organization controls the relevant device and workforce information, and Myserver MS processes it on the organization’s instructions as a service provider or processor. Contact the organization first when your request concerns data it controls.
Information we collect
| Category | Examples | Source |
|---|---|---|
| Identity and account | Name, username, work email, organization, role, account status, authentication and session records. | You, your organization, and application security logs. |
| Commercial and request | Selected package, device count, requested services, demo details, discount and order identifiers, invoice status. | You, your organization, and the hosted payment provider. |
| Authorized device | Device name, operating system, version, IP/network information, hardware and health metrics, agent version, group, heartbeat, enrollment and revocation status. | The visible agent on an enrolled device and authorized administrators. |
| Support and activity | Support requests, operator actions, approvals, policy decisions, command status, session history, audit events, reports, and error records. | You, your organization, the application, and configured support providers. |
| Website and security | IP address, browser/user-agent, timestamps, essential cookie/session identifiers, login attempts, CSRF and abuse-prevention events. | Your browser, device, and application security systems. |
| Communications | Email, phone number if supplied, message content, preferred contact time, and support correspondence. | You or your organization. |
We do not intentionally collect precise geolocation, biometric templates, government identifiers, health records, consumer financial-account credentials, wallet seed phrases, private keys, or the contents of personal files as part of ordinary platform operation.
How and why information is used
- Provide accounts, selected packages, dashboards, device enrollment, heartbeat visibility, support coordination, reporting, and requested services.
- Authenticate users, apply role-based access, enforce policies, prevent abuse, investigate incidents, and protect the service.
- Review account, demo, trial, and support requests and communicate about requested services.
- Maintain billing records, discounts, hosted-invoice status, tax/accounting records, and transaction reconciliation.
- Maintain audit history, troubleshoot failures, improve reliability, measure service performance, and plan capacity.
- Meet legal obligations, enforce agreements, protect rights and safety, and respond to lawful requests.
Lawful bases where applicable
Depending on the context and jurisdiction, processing is based on performance of a contract or requested pre-contract steps, legitimate interests such as service security and reliable operations, compliance with legal obligations, and consent where the law requires it. You may withdraw consent for future processing, but withdrawal does not affect processing already completed lawfully.
Myserver MS does not use personal information to make decisions with legal or similarly significant effects based solely on automated processing.
Retention and deletion
We retain information only for as long as reasonably necessary for the purpose collected, the customer’s configured retention settings, security and audit needs, contractual requirements, dispute resolution, and applicable law. Account and device records may remain while the service relationship or authorized enrollment is active. Short-lived enrollment and reset tokens expire automatically. Security, billing, backup, and audit records may be retained longer where needed to protect the service, prove authorization, meet accounting duties, or establish legal claims.
When retention ends, information is deleted, de-identified, or securely isolated until backup rotation completes. A deletion request may be limited where retention is required for security, fraud prevention, legal compliance, billing, or the rights of others.
Security and authorized device operations
No system can guarantee absolute security. Customers are responsible for endpoint security, accurate permissions, lawful enrollment, administrator training, and promptly revoking access when it is no longer required. Report suspected privacy or security incidents immediately using the contact details below.
Your privacy rights
Subject to your location, our role, verification, and legal exceptions, you may request access, correction, deletion, restriction, portability, an explanation of processing, or objection to certain processing. You may withdraw consent and may complain to your local data-protection authority.
California and applicable U.S. state rights
Where applicable, you may request to know/access, correct, or delete personal information; receive a portable copy; opt out of sale, targeted-ad sharing, or certain profiling; limit certain sensitive-information uses; and receive equal service without unlawful discrimination. We do not sell personal information or use it for targeted-ad sharing. An authorized agent may submit a request, but we may verify the agent’s authority and your identity.
EEA, United Kingdom, and similar rights
Where applicable, you may have rights to be informed, access, rectification, erasure, restriction, portability, objection, and safeguards concerning solely automated decisions. You may also lodge a complaint with your competent supervisory authority.
These rights are not absolute. We will explain any denial and any available appeal process. We will not retaliate or unlawfully discriminate because you exercised a privacy right.
Privacy request roadmap
- 1SubmitEmail, call, or write through the website contact workflow. Describe the right and account or organization involved.
- 2AcknowledgeWe record the request and provide a case reference or follow-up instructions.
- 3VerifyWe use proportionate information to verify identity and authority. Never send your password or private keys.
- 4Locate and reviewWe identify relevant systems, customer-controller records, exceptions, and third-party dependencies.
- 5RespondWe complete the request or explain limitations within the period required by applicable law.
- 6Appeal or follow upIf applicable, you may appeal a denial or contact the relevant privacy regulator.
Children’s privacy
Myserver MS is a business administration service and is not directed to children. Users must be at least 18 or the age of legal majority required to enter the applicable agreement. We do not knowingly collect personal information directly from children under 13. If you believe a child submitted information, contact us so we can investigate and delete it where required. Customers may not use Myserver MS to collect children’s information without all legally required notices, authority, and verifiable parental consent.
International processing and transfers
Myserver MS and its configured providers may process information in countries other than where you live. Where required, transfers use recognized legal mechanisms and supplementary safeguards appropriate to the information and service. Contact us to ask about safeguards applicable to a specific transfer.
Third-party services and links
External sites, hosted payment pages, Microsoft resources, remote-support services, and customer-configured integrations have their own privacy practices. This policy does not control information you submit directly to those third parties. Review their policies before providing information.
Changes to this policy
We may update this policy to reflect service, legal, or operational changes. The “Last updated” date identifies the current version. If a change materially affects how previously collected information is used, we will provide additional notice or obtain consent where required.
Contact Myserver MS
For postal correspondence or a data-processing addendum, contact us by email or telephone for current instructions. We may ask for information needed to verify your identity, account, organization, or authorized-agent status.
This policy describes Myserver MS practices and is not legal advice. Rights and obligations vary by jurisdiction and customer deployment.