Archived Data processing addendum
QueueRove Data Processing Addendum
This technical draft defines the narrow control-plane processing boundary proposed for a customer agreement. It is not an executed or counsel-approved DPA.
- Version 2026-07-17-draft.1
- Effective date: Pending Texas counsel approval
- SHA-256
50725806b16f0e484230b5c12d7dfd08979cacb2f95990a858040e83984b2b59
Archived draft status
Technical draft pending Texas counsel review; production collection and charging also require tax/accounting signoff and explicit launch approval.
This repository-local document is not provider, deployment, counsel, tax, or production evidence. It makes no approval or launch claim.
The content hash is derived from the versioned structured source rendered on this page. Material changes require a new version, archive entry, and the approved reacceptance process.
View the current stable route → · View all archived documents
1. Parties and effect
This proposed addendum is between ITECS Outsourcing, LLC and the MSP customer identified in an executed QueueRove agreement. It would apply only when incorporated into that agreement. Controller, processor, business, and service-provider terminology must be finalized for the applicable law and customer by counsel.
2. Processing scope
Explicit HaloPSA exclusion
This DPA covers only QueueRove-controlled account, technician identity, organization, membership, assignment, billing-administration, legal-acceptance, security/audit, support, and privacy-workflow data. It does not claim that the website controls or processes HaloPSA tickets, customer records, notes, photos, time entries, or mobile-held HaloPSA credentials on the customer's behalf.
| Element | Draft scope |
|---|---|
| Subject matter | Administration and security of the QueueRove business service |
| Duration | For the agreement term and approved retention periods, subject to holds |
| Purpose | Authentication, tenant administration, licensing, billing administration, support, privacy, security, and legal evidence |
| Data subjects | Customer users, invited users, technicians, administrators, Owners, support/privacy contacts, and business sales contacts |
| Personal data | Business identity/contact, account/provider identifiers, organization roles/grants, assignments, session/security metadata, legal acceptance, billing references, and request/correspondence data |
| Sensitive data | Not intentionally requested; secrets, customer ticket content, card data, MFA/recovery codes, and unredacted evidence must not be submitted |
3. Documented instructions and authority
QueueRove would process covered data only for the service, the executed agreement, lawful documented customer instructions, and applicable legal obligations. Instructions do not override tenant isolation, role authority, identity verification, recent-MFA requirements, retention duties, security controls, or another person's rights.
4. Confidentiality and security
Personnel with access would be bound by appropriate confidentiality duties. The approved design includes server-side authorization, explicit organization context, least privilege, session controls, immutable audit evidence, redaction, retention controls, incident procedures, backup/restore design, and provider-boundary validation. This draft does not claim deployed controls, certifications, audit reports, or provider configuration without evidence.
5. Subprocessors
The current Subprocessor List is incorporated only when an executed agreement says so. ITECS would remain responsible for appropriate written obligations and would provide the notice and objection process finalized in the executed DPA. Candidate provider names and activation status must not be treated as production evidence.
6. Assistance, requests, and incidents
Taking account of the processing and available information, ITECS would provide reasonable assistance for covered-data requests, security incidents, impact assessments, and regulator inquiries as required by the executed agreement and applicable law. Customer instructions must come through an authorized, verified channel; generic email alone is not action authority.
7. Return, deletion, and retention
At the end of services or on an authorized request, covered data would be returned, deleted, or anonymized according to the approved export/deletion workflow, retention schedule, provider capabilities, backup cycle, legal holds, and applicable law. QueueRove would not claim deletion of legally retained evidence, another controller's data, HaloPSA records, or device-local data.
8. Transfers, records, and audits
Production hosting regions, international-transfer mechanisms, audit materials, and customer audit procedures require provider evidence, contracting, security review, and counsel approval. They are intentionally not invented in this draft. Reasonable verification terms would be defined in the executed DPA without exposing other tenants or sensitive security information.
9. Conflicts and signatures
An executed DPA and service agreement would define order of precedence, governing terms, notices, signatures, and annexes. This public technical draft is not signed, does not itself appoint a processor, and must not be presented as an executed customer agreement.
Related resources
Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.