Archived Data processing addendum
QueueRove Data Processing Addendum
This addendum defines the narrow control-plane processing boundary offered for customer agreements. The executed copy incorporated into a customer agreement controls.
- Version 2026-08-02.1
- Effective date: August 2, 2026
- SHA-256
7bf467178f7f2396f380fb990ccaaf79e007d85468da621c900d2ab8bf4cda6c
Archived version
This is the current published version of this document. Material changes receive a new immutable version, a new content hash, and an archive entry.
The content hash is derived from the versioned structured source rendered on this page. Material changes receive a new version, an archive entry, and, where required, reacceptance.
View the current stable route → · View all archived documents
1. Parties and effect
This addendum is between ITECS Outsourcing, LLC and the MSP customer identified in an executed QueueRove agreement, and applies when incorporated into that agreement. Controller, processor, business, and service-provider terminology is applied as the applicable law defines it for the executed agreement.
2. Processing scope
Explicit HaloPSA exclusion
This DPA covers only QueueRove-controlled account, technician identity, organization, membership, assignment, billing-administration, legal-acceptance, security/audit, support, and privacy-workflow data. It does not claim that the website controls or processes HaloPSA tickets, customer records, notes, photos, time entries, or mobile-held HaloPSA credentials on the customer's behalf.
| Element | Scope |
|---|---|
| Subject matter | Administration and security of the QueueRove business service |
| Duration | For the agreement term and approved retention periods, subject to holds |
| Purpose | Authentication, tenant administration, licensing, billing administration, support, privacy, security, and legal evidence |
| Data subjects | Customer users, invited users, technicians, administrators, Owners, support/privacy contacts, and business sales contacts |
| Personal data | Business identity/contact, account/provider identifiers, organization roles/grants, assignments, session/security metadata, legal acceptance, billing references, and request/correspondence data |
| Sensitive data | Not intentionally requested; secrets, customer ticket content, card data, MFA/recovery codes, and unredacted evidence must not be submitted |
3. Documented instructions and authority
QueueRove processes covered data only for the service, the executed agreement, lawful documented customer instructions, and applicable legal obligations. Instructions do not override tenant isolation, role authority, identity verification, recent-MFA requirements, retention duties, security controls, or another person's rights.
4. Confidentiality and security
Personnel with access are bound by appropriate confidentiality duties. QueueRove uses server-side authorization, explicit organization context, least privilege, session controls, immutable audit evidence, redaction, retention controls, incident procedures, backup and restore controls, and provider-boundary validation appropriate to the covered data.
5. Subprocessors
The current Subprocessor List is incorporated when an executed agreement says so. ITECS remains responsible for appropriate written obligations with each subprocessor and provides the notice and objection process defined in the executed DPA.
6. Assistance, requests, and incidents
Taking account of the processing and available information, ITECS provides reasonable assistance for covered-data requests, security incidents, impact assessments, and regulator inquiries as required by the executed agreement and applicable law. Customer instructions must come through an authorized, verified channel; generic email alone is not action authority.
7. Return, deletion, and retention
At the end of services or on an authorized request, covered data is returned, deleted, or anonymized according to the export/deletion workflow, retention schedule, provider capabilities, backup cycle, legal holds, and applicable law. QueueRove does not claim deletion of legally retained evidence, another controller's data, HaloPSA records, or device-local data.
8. Transfers, records, and audits
Covered data is processed in the United States. Where applicable law requires an international-transfer mechanism or audit rights, the executed DPA defines them, with reasonable verification terms that do not expose other tenants or sensitive security information.
9. Conflicts and signatures
The executed DPA and service agreement define order of precedence, governing terms, notices, signatures, and annexes. This public page is a reference copy for review; it is not itself a signed customer agreement.
Related resources
Questions may be sent to support@itecsonline.com with the subject “QueueRove privacy request”.