Skip to main content

Data processing addendum

QueueRove Data Processing Addendum

This technical draft defines the narrow control-plane processing boundary proposed for a customer agreement. It is not an executed or counsel-approved DPA.

  • Version 2026-07-17-draft.1
  • Effective date: Pending Texas counsel approval
  • SHA-256 50725806b16f0e484230b5c12d7dfd08979cacb2f95990a858040e83984b2b59

Review and release status

Technical draft pending Texas counsel review; production collection and charging also require tax/accounting signoff and explicit launch approval.

This repository-local document is not provider, deployment, counsel, tax, or production evidence. It makes no approval or launch claim.

The content hash is derived from the versioned structured source rendered on this page. Material changes require a new version, archive entry, and the approved reacceptance process.

Open the immutable archive route for this version → · View all archived documents

1. Parties and effect

This proposed addendum is between ITECS Outsourcing, LLC and the MSP customer identified in an executed QueueRove agreement. It would apply only when incorporated into that agreement. Controller, processor, business, and service-provider terminology must be finalized for the applicable law and customer by counsel.

2. Processing scope

Explicit HaloPSA exclusion

This DPA covers only QueueRove-controlled account, technician identity, organization, membership, assignment, billing-administration, legal-acceptance, security/audit, support, and privacy-workflow data. It does not claim that the website controls or processes HaloPSA tickets, customer records, notes, photos, time entries, or mobile-held HaloPSA credentials on the customer's behalf.

Proposed processing details
ElementDraft scope
Subject matterAdministration and security of the QueueRove business service
DurationFor the agreement term and approved retention periods, subject to holds
PurposeAuthentication, tenant administration, licensing, billing administration, support, privacy, security, and legal evidence
Data subjectsCustomer users, invited users, technicians, administrators, Owners, support/privacy contacts, and business sales contacts
Personal dataBusiness identity/contact, account/provider identifiers, organization roles/grants, assignments, session/security metadata, legal acceptance, billing references, and request/correspondence data
Sensitive dataNot intentionally requested; secrets, customer ticket content, card data, MFA/recovery codes, and unredacted evidence must not be submitted

3. Documented instructions and authority

QueueRove would process covered data only for the service, the executed agreement, lawful documented customer instructions, and applicable legal obligations. Instructions do not override tenant isolation, role authority, identity verification, recent-MFA requirements, retention duties, security controls, or another person's rights.

4. Confidentiality and security

Personnel with access would be bound by appropriate confidentiality duties. The approved design includes server-side authorization, explicit organization context, least privilege, session controls, immutable audit evidence, redaction, retention controls, incident procedures, backup/restore design, and provider-boundary validation. This draft does not claim deployed controls, certifications, audit reports, or provider configuration without evidence.

5. Subprocessors

The current Subprocessor List is incorporated only when an executed agreement says so. ITECS would remain responsible for appropriate written obligations and would provide the notice and objection process finalized in the executed DPA. Candidate provider names and activation status must not be treated as production evidence.

6. Assistance, requests, and incidents

Taking account of the processing and available information, ITECS would provide reasonable assistance for covered-data requests, security incidents, impact assessments, and regulator inquiries as required by the executed agreement and applicable law. Customer instructions must come through an authorized, verified channel; generic email alone is not action authority.

7. Return, deletion, and retention

At the end of services or on an authorized request, covered data would be returned, deleted, or anonymized according to the approved export/deletion workflow, retention schedule, provider capabilities, backup cycle, legal holds, and applicable law. QueueRove would not claim deletion of legally retained evidence, another controller's data, HaloPSA records, or device-local data.

8. Transfers, records, and audits

Production hosting regions, international-transfer mechanisms, audit materials, and customer audit procedures require provider evidence, contracting, security review, and counsel approval. They are intentionally not invented in this draft. Reasonable verification terms would be defined in the executed DPA without exposing other tenants or sensitive security information.

9. Conflicts and signatures

An executed DPA and service agreement would define order of precedence, governing terms, notices, signatures, and annexes. This public technical draft is not signed, does not itself appoint a processor, and must not be presented as an executed customer agreement.

Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.