Privacy and data protection

GoMyid and GDPR responsibilities

GoMyid provides deployment and administration capabilities that can support a customer’s data protection program. Compliance depends on the customer’s purpose, configuration, agreements, lawful basis, notices, retention, security measures, and handling of individual rights.

Document scope

Effective August 15, 2026. This page explains general GoMyid product and service considerations. It is not legal advice, a certification, or an unconditional statement that every customer deployment is compliant.

Organizations should obtain independent legal advice for their processing activities and applicable jurisdictions.

Roles depend on context

Identify who determines the purpose and means of processing

The correct controller, joint-controller, or processor analysis depends on the service selected, the data involved, contractual terms, and how the customer uses GoMyid.

Customer responsibilities

Customers generally determine why their personnel, contractors, or support teams use remote desktop and which computers, users, records, and business systems are involved. Customers are responsible for confirming a lawful basis, providing required notices, limiting access, configuring retention, responding to rights requests, and evaluating monitoring or employment-law requirements.

DeskGate responsibilities

DeskGate LLC handles information according to the selected service and applicable agreement. Where DeskGate processes personal data for a customer, the contractual scope, documented instructions, security commitments, support responsibilities, and any applicable data-processing terms should define that relationship.

Data mapping

Know what the deployment processes

A GoMyid deployment may involve account and administrator information, device identifiers, connection information, network information, operational events, support communications, licensing information, and records generated by enabled administration or reporting capabilities.

The exact data set varies by product version, deployment model, enabled features, configuration, and customer use. Customers should document their actual data flow instead of relying on a generic list.

Purpose limitation

Define why each category is needed and avoid reusing remote access records for an incompatible, undisclosed purpose.

Data minimization

Enable and retain only information reasonably necessary for access, support, security, accountability, and documented obligations.

Accuracy

Maintain processes to correct relevant account, device, and administrative information when it is inaccurate.

Storage limitation

Set retention periods by category and purpose, then securely delete or anonymize information when retention is no longer justified.

GoMyid management view with sensitive information concealed

Cloud and On-Premise

Deployment changes the responsibility map

Cloud: Customers should review the hosted service terms, account administration, applicable processing locations, support workflow, retention choices, security controls, and contractual data-processing provisions.

On-Premise: Customers select and operate the hosting environment and generally control the database, network, backups, administrator access, retention, and deletion process. This additional control also creates direct responsibility for infrastructure security and governance.

Neither model removes the need for a lawful basis, appropriate notices, access discipline, documented retention, incident handling, and rights-request procedures.

Data-subject requests

Prepare a verified and documented response process

1

Receive and verify

Record the request, verify identity proportionately, and confirm the organization responsible for the relevant processing.

2

Locate and assess

Search relevant systems and backups, determine which rights apply, and identify information involving other people or legal restrictions.

3

Act securely

Provide, correct, restrict, delete, or otherwise handle information through an approved process where legally required.

4

Document the response

Record the decision, timing, communications, exceptions, and responsible reviewer without retaining unnecessary evidence.

Governance requirements

Lawful basis, notices, and workplace monitoring

Organizations should establish a lawful basis before processing personal data through remote desktop operations. Consent is not automatically appropriate, particularly where there is an imbalance of power such as an employment relationship. Privacy notices should clearly explain relevant purposes, categories, recipients, retention, rights, and contact routes. If activity review could amount to employee monitoring, the organization should assess necessity, proportionality, local employment requirements, and whether a data protection impact assessment is required.

Security and incident response

Appropriate measures may include access control, encryption in transit, endpoint security, infrastructure hardening, logging, backup protection, vulnerability management, staff training, vendor governance, and tested incident procedures. Customers should define how suspected personal-data incidents are identified, contained, assessed, documented, escalated, and notified. Notification duties and deadlines depend on the facts and applicable law.

International transfers and service providers

Customers should identify relevant processing locations and any service providers involved in their complete deployment. Where personal data is transferred across jurisdictions, organizations should evaluate the applicable transfer mechanism, contractual safeguards, risk assessment, and supplementary measures. On-Premise hosting can give a customer greater location control, but customer-selected hosting, support access, backups, and integrations must still be assessed.

Contractual documentation

Applicable agreements should describe service scope, confidentiality, security responsibilities, processing instructions, assistance, deletion or return, incident cooperation, and audit information where required. Contact GoMyid before deployment if your procurement or privacy review requires contractual data-processing documentation.

Map GoMyid to your data protection program

Tell us your deployment model, locations, user groups, enabled capabilities, and contractual review requirements.