Data Controller Information
For the purposes of GDPR, the data controller is:
Effective Date: April 28, 2026
This page explains how Pro Nova Technologies Inc. ("we," "us," or "our") complies with the General Data Protection Regulation (GDPR) and outlines your rights regarding your personal data when you use our website at https://rmms.pronovatech.com and our PNT Remote Monitoring & Management Services ("PNT-RMMS") desktop client.
For the purposes of GDPR, the data controller is:
We process personal data under the following legal bases as defined by GDPR Article 6:
When you explicitly agree to the processing (e.g., marketing emails, cookies)
When processing is necessary to fulfill a contract with you (e.g., software purchase, RMMS subscription, device licensing)
When processing is required to comply with legal requirements (e.g., tax records)
When processing serves our legitimate business interests (e.g., fraud prevention, analytics, security monitoring, remote device management)
Under GDPR, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten").
Request limitation on how we use your data.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or direct marketing.
Right not to be subject to decisions based solely on automated processing.
Withdraw consent at any time for processing based on consent.
To exercise any of your GDPR rights, you can:
We will respond to your request within 30 days. In complex cases, this may be extended by an additional 60 days, and we will notify you of the extension.
We collect the following categories of personal data:
Email address, first and last name, hashed password (PBKDF2-SHA512), TOTP secret if 2FA is enabled, company memberships and per-company role.
Stripe customer ID, subscription ID, current plan and seat count. Card numbers and full billing details are held by Stripe — we never see or store them.
HTTP server access logs (IP, user-agent, request path, timestamp) generated by the portal for security and abuse prevention.
Support ticket content, attachments, and any email correspondence you send us.
Hostname, system manufacturer / model / serial, CPU and RAM specs, drive list and free space, Windows edition / build, time-zone, domain-join status, current CPU and memory utilization, primary MAC address, last-reported public IP, agent version, and DPAPI-protected device-token reference.
Per-session summary written at end-of-session: start/end timestamps, the path that connected (LAN-direct / direct over WAN / relay), bytes transmitted on each path, and the operator's public IP. Screen content is never stored. Session recordings are not implemented.
Warning-level and above application logs forwarded from the Agent for centralized troubleshooting. No personal data is included.
As a company that may process data outside the EEA, we ensure that any international transfers of personal data comply with GDPR requirements through:
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy:
The technical measures we currently apply:
X-Device-Token bound to the device's identity and subscription state.In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with your local data protection supervisory authority.
We encourage you to contact us first at support@pronovatech.com so we can address your concerns directly.
For any GDPR-related inquiries or to exercise your rights, please contact us: