Skip to main content

Archived Data processing addendum

QueueRove Data Processing Addendum

This addendum defines the narrow control-plane processing boundary offered for customer agreements. The executed copy incorporated into a customer agreement controls.

  • Version 2026-08-02.1
  • Effective date: August 2, 2026
  • SHA-256 7bf467178f7f2396f380fb990ccaaf79e007d85468da621c900d2ab8bf4cda6c

Archived version

This is the current published version of this document. Material changes receive a new immutable version, a new content hash, and an archive entry.

The content hash is derived from the versioned structured source rendered on this page. Material changes receive a new version, an archive entry, and, where required, reacceptance.

View the current stable route → · View all archived documents

1. Parties and effect

This addendum is between ITECS Outsourcing, LLC and the MSP customer identified in an executed QueueRove agreement, and applies when incorporated into that agreement. Controller, processor, business, and service-provider terminology is applied as the applicable law defines it for the executed agreement.

2. Processing scope

Explicit HaloPSA exclusion

This DPA covers only QueueRove-controlled account, technician identity, organization, membership, assignment, billing-administration, legal-acceptance, security/audit, support, and privacy-workflow data. It does not claim that the website controls or processes HaloPSA tickets, customer records, notes, photos, time entries, or mobile-held HaloPSA credentials on the customer's behalf.

Processing details
ElementScope
Subject matterAdministration and security of the QueueRove business service
DurationFor the agreement term and approved retention periods, subject to holds
PurposeAuthentication, tenant administration, licensing, billing administration, support, privacy, security, and legal evidence
Data subjectsCustomer users, invited users, technicians, administrators, Owners, support/privacy contacts, and business sales contacts
Personal dataBusiness identity/contact, account/provider identifiers, organization roles/grants, assignments, session/security metadata, legal acceptance, billing references, and request/correspondence data
Sensitive dataNot intentionally requested; secrets, customer ticket content, card data, MFA/recovery codes, and unredacted evidence must not be submitted

3. Documented instructions and authority

QueueRove processes covered data only for the service, the executed agreement, lawful documented customer instructions, and applicable legal obligations. Instructions do not override tenant isolation, role authority, identity verification, recent-MFA requirements, retention duties, security controls, or another person's rights.

4. Confidentiality and security

Personnel with access are bound by appropriate confidentiality duties. QueueRove uses server-side authorization, explicit organization context, least privilege, session controls, immutable audit evidence, redaction, retention controls, incident procedures, backup and restore controls, and provider-boundary validation appropriate to the covered data.

5. Subprocessors

The current Subprocessor List is incorporated when an executed agreement says so. ITECS remains responsible for appropriate written obligations with each subprocessor and provides the notice and objection process defined in the executed DPA.

6. Assistance, requests, and incidents

Taking account of the processing and available information, ITECS provides reasonable assistance for covered-data requests, security incidents, impact assessments, and regulator inquiries as required by the executed agreement and applicable law. Customer instructions must come through an authorized, verified channel; generic email alone is not action authority.

7. Return, deletion, and retention

At the end of services or on an authorized request, covered data is returned, deleted, or anonymized according to the export/deletion workflow, retention schedule, provider capabilities, backup cycle, legal holds, and applicable law. QueueRove does not claim deletion of legally retained evidence, another controller's data, HaloPSA records, or device-local data.

8. Transfers, records, and audits

Covered data is processed in the United States. Where applicable law requires an international-transfer mechanism or audit rights, the executed DPA defines them, with reasonable verification terms that do not expose other tenants or sensitive security information.

9. Conflicts and signatures

The executed DPA and service agreement define order of precedence, governing terms, notices, signatures, and annexes. This public page is a reference copy for review; it is not itself a signed customer agreement.

Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.