# Security Organization

## Security Organization and Management Policy

### Security Roles and Responsibilities

Screendesk has an organizational structure that establishes, approves, implements, and monitors adherence to an Information Security Program through clear lines of authority and responsibilities.

#### Risk Committee

The Risk Committee has oversight responsibilities related to internal security controls.

Responsibilities include:

* Approving and monitoring adherence to this policy
* Ensuring data handling responsibilities are assigned, documented, and communicated
* Performing the annual risk assessment

The Risk Committee meets at least quarterly and maintains formal meeting minutes.

#### Personnel

The following personnel are responsible for overseeing and implementing security and data protection practices throughout Screendesk:

* CTO (Adrien Nhem, <adrien@screendesk.io>): Responsibilities include providing overall direction, leadership, and support on methods and tools for secure storage, retention, and disposal of Confidential and Sensitive data. The CTO also serves as the primary Systems Administrator.
* CEO: Assists the CTO in implementing and maintaining security practices.
* End Users (Employees, Consultants): Responsibilities include adhering to the organization's data protection policies, procedures, and practices and reporting instances of non-compliance to the CTO.
* Vendors (includes Contractors and other Third Parties): Responsibilities include all those applicable to end users. In addition, vendors, contractors, and third parties are responsible for:
  * Avoiding any measure to alter standards that protect customer data
  * Completing due diligence and ongoing monitoring assessments per the requirements set forth in the Vendor Management Policy
  * Immediately notifying Screendesk of any policy violations involving customer data

Every end user and vendor is responsible for identifying and mitigating risks associated with the protection of Confidential information and must comply with all the policies within this Information Security Policy.

### Policy Review

The CTO is responsible for reviewing Screendesk's policies and procedures on at least an annual basis to ensure they remain accurate and up-to-date with current operations and compliance requirements.

### Related Policies

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td><a href="/pages/i1s7xwkEE7xGaR6fLj12">Access Control</a></td><td>Policy related to access controls.</td><td></td></tr><tr><td><a href="/pages/sKRGfNJsxfuRjP5GXpDw">Change Management</a></td><td>Policy related to change management.</td><td></td></tr><tr><td><a href="/pages/OqhSaM3g1KgkUYBlpmob">Incident Management</a></td><td>Policy related to incident management.</td><td></td></tr><tr><td><a href="/pages/raPFgK6R8cyBHJW0abTy">Monitoring</a></td><td>Policy related to monitoring.</td><td></td></tr><tr><td><a href="/pages/5Czsv1M91F5TxlaNVgmz">Network and Systems</a></td><td>Policy related to network and systems. </td><td></td></tr><tr><td><a href="/pages/EIG5fFWDA6MxKEQoXGv0">People Security</a></td><td>Policy related to people security.</td><td></td></tr><tr><td><a href="/pages/hED92NtmnpkHrsmsZCt6">Risk Management</a></td><td>Policy related to risk management. </td><td></td></tr><tr><td><a href="/pages/CKPkvlrnzhy4GjzvG4dn">Vendor Management</a></td><td>Policy related to vendor management. </td><td></td></tr><tr><td><a href="/pages/IQ04340pCEQBqnV9Z5NJ">Vulnerability Management</a></td><td>Policy related to vulnerability management. </td><td></td></tr></tbody></table>


# Access Control

Access controls establish standards and procedures for preventing unauthorized access to information assets.

### Principle of Least Privilege

Access rights to Screendesk system components are limited to authorized personnel and are based on a user's role and responsibilities. Access rights to Screendesk system components must adhere to the concept of least privilege at all times.

The principle of least privilege grants users the bare minimum level of access to operating systems that is needed to perform their role or carry out their job responsibilities. Screendesk applies least privilege to its systems to add an additional layer of security over the data and information that a user handles and to reduce the risk of users abusing their access privileges.

### Privileged Users

Privileged users are those with elevated or superuser access to in-scope systems and system components that is granted according to business needs. At Screendesk, the CTO (Adrien Nhem) serves as the primary privileged user, responsible for ensuring that the access rights for all users (including the CEO and any future employees or contractors) are commensurate with:

* The user's role and responsibilities within Screendesk (this principle is known as role-based access control)
* The concept of least privilege and separation of rights based on job duties

### Provisioning Users

When an employee or contractor joins Screendesk, they are given the appropriate tools and access to Screendesk systems. During the process of onboarding, employees are assigned unique identifications (ID) and are sent the organization's policies. Employees must acknowledge having read and received the policies before being granted access to the information systems and networks needed to carry out their roles and responsibilities.

Users for all in-scope systems and system components are provisioned using all applicable provisioning and de-provisioning tools as necessary. This includes access to:

* Render.com (cloud provider)
* Amazon S3 (for storing recordings)
* Any other critical systems used in Screendesk's operations

### User Identifications

When a new user is onboarded, they are assigned a unique Screendesk employee ID. This ID defaults to the user's first name in lowercase text. If that ID already exists, then the ID will be the user's first and last name.

Employees are strictly prohibited from sharing IDs or from using another user's ID, regardless of whether the other user has granted permission.

### User Access

Once an ID has been assigned to a new user, a formal access request must be submitted to and approved by the CTO. When the access request is approved, the new user is given access to their Screendesk email, internal resources, and any other elevated permissions that their role requires them to have.

This same process is applied when existing employees require additional levels of access.

### Deprovisioning Users

For any modifications to or removal of access, a formal access request is required to ensure these actions are documented and completed in a timely manner. Terminated employees have access revoked within twenty-four (24) hours of termination.

### Access Review Policy

All employee access to production systems is reviewed by the CTO at least quarterly to confirm the access of each employee is appropriate and complies with the principles of least privilege and separation of duties.

The access review and any modifications to system access are formally documented and tracked.

### Identification and Authentication Policy

All users are authenticated through unique IDs and passwords or through authorized secure shell (SSH) keys in order to access Screendesk's information systems and networks.

Screendesk uses automated access control systems to restrict user access to its network and data. These automated access controls require users to authenticate before they may access any of the following:

* Screendesk's network
* Screendesk's source code
* Screendesk's and its customer data
* Other restricted data

All users must use multi-factor authentication (MFA) measures to ensure that access to in-scope system components are protected at all times.

### Password Policy

Passwords are a critical component of information security. Passwords protect user accounts and must be configured according to Screendesk's password policies. Screendesk requires users to create and use complex passwords.

Passwords must be safeguarded, and owners should not share them with other users. Passwords used by all users must meet or exceed all stated Screendesk policies for password complexity requirements.

#### Password Complexity

Screendesk requires that all passwords meet or exceed all of the following guidelines:

* Contain at least twelve (12) alphanumeric characters
* Contain both upper and lowercase letters
* Contain at least one number
* Contain at least one special character (e.g., $%^&\*()\_+|\~-=\`{}\[]:";'<>?,/).

Weak passwords are prohibited. Weak passwords have the following characteristics:

* Contain less than twelve characters
* Can be found in a dictionary, including foreign language, or exist in a language slang, dialect, or jargon
* Contain personal information such as birthdates, addresses, phone numbers, or names of family members, pets, friends, etc.
* Contain work-related information such as building names, system commands, sites, companies, hardware, or software

#### Invalid Password Lockouts

Parameters regarding account lockout policies and password resets are enforced with system settings. Only the CTO is allowed to make any changes to the password complexity rules and lockout policies.

### Remote Access to Production Systems

All access to Screendesk system components initiated outside the organization's trusted network infrastructure is considered "remote access." Remote access to production systems is restricted to authorized employees with a valid MFA token.

All users must use approved technologies, such as internet protocol security (IPSec) and/or secure socket layer (SSL) for remote access. These approved protocols are to be used along with MFA and additional supporting measures such as secure shell keys (SSH).


# Change Management

#### Pre-Implementation Testing (continued)

time. Validation efforts in this environment consist of automated functionality and security testing.

#### Approval

Screendesk seeks to produce new releases swiftly yet with the oversight necessary to promote quality and assure adequate controls:

* Before pushing a release to production, the CTO must approve changes classified as having a major impact.
* Any visible changes to end-user-facing documents and interfaces are automatically cataloged and require manual review and approval.
* All changes in implementation or configuration require approval by the other team member who did not implement the change.
* A successful execution, completed during the pre-implementation testing phase, is required for releasing a feature in production.

#### Staging Deployment

After obtaining final approval, the change is deployed to a staging environment whose configuration fully mimics the production environment. Multiple changes may be bundled automatically into a single deployment to facilitate rapid development and iteration.

Validation is achieved in this environment by a successful deployment of all requested changes, followed by automated testing that simulates user behavior. Successful completion of all staging tests automatically initiates deployment to the production environment.

#### Production Deployment and Communication

Once a staging deployment has been successful, an identical deployment is initiated in the production environment.

* If the deployment succeeds with no errors, the change request is marked as successfully merged, the Git version control system is updated to reflect the changes, and Engineering is notified of the change.
* If the deployment encounters an error, any changes are automatically rolled back and the implementer is notified of the failure. Once a defect has been repaired or a feature has been fully realized by Engineering, Product members associated with the change request are notified that the change is complete, and the system of record is updated.

#### Rollback Procedures

Screendesk's ability to execute rollback procedures depends on the change(s) that need to be rolled back. If a rollback is possible, Engineering is able to address an issue in near real time by reverting to a previous version of the product.

#### Continuous Improvement

Although the System Change Management Policy presents the change management process linearly, Screendesk accumulates feedback throughout the system development process, reviews and prioritizes requested changes, and reflects those changes as incremental improvements to the product.

### Inventory Management Policy

Screendesk's management maintains a system asset inventory that does the following:

* Accurately reflects the organization's production systems
* Includes all system components
* Does not duplicate components that appear in multiple systems
* Maintains enough information to track and report on assets – in particular, marking relevant assets as "critical" and verifying that they meet security baseline requirements
* Indicates whether assets store or access Sensitive and/or Confidential data
* Notes any approved deviations to current deployed configurations
* Assigns ownership of system components and documents assignees' acknowledgment of ownership
* Documents accountability information, including responsibility and ownership, by name, position, or role

### Change Communication

Screendesk communicates any major changes to the system to authorized internal users (e.g., feature releases). For major system changes, Screendesk follows these steps:

1. Obtains final approvals from authorized staff
2. Deploys the feature in either the organization's internal production environment or in a customer's environment (in conjunction with the customer's personnel)
3. Sends release notes that describe the functionality introduced with the release, provide examples of how to use the new functionality, note fixes to material bugs identified during prior releases, and list known limitations


# Incident Management

## Incident Management Policy

Screendesk distinguishes between security events and security incidents as follows:

* Security event: A suspicious activity that deviates from normal behavior but does not appear to compromise any system resources. Security events include phishing emails, changes in login permissions, spikes in incoming traffic, and similar situations. Events may be elevated to incidents if determined by authorized personnel.
* Security incident: A suspicious or malicious activity that compromises a system resource and is being used for unauthorized purposes. Security incidents include data breaches, a successful distributed denial-of-service (DDOS) attack, or similar situations where the incident is so large that it may involve a legal team, public disclosure, or a failure to meet contractual commitments with customers.

### Incident Management Roles and Responsibilities

The Incident Response Team (IRT) has clear roles and responsibilities for adequately preparing for and responding to any incident. The IRT follows the necessary steps, processes, and procedures to address an incident as well as to understand what actions (if any) to take with law enforcement agencies, local/federal/state agencies, the media, and any other third parties considered to be within scope.

Given Screendesk's small size, the IRT consists of both employees, with the CTO (Adrien Nhem) serving as the primary responsible party. The IRT is responsible for the following:

* Declaring a security incident
* Leading the incident response process after the incident is declared through a postmortem
* Determining what other teams or individuals are required to contribute to the response process
* Coordinating investigation and remediation efforts
* Keeping stakeholders informed
* Performing an annual test of the Incident Response program through a tabletop exercise

### Incident Response Procedures

These procedures outline the steps necessary to address security and performance related events and incidents in order to ensure the confidentiality, integrity, and availability of Screendesk's platform and supporting systems. The IRT should follow the appropriate procedure based on the incident severity ranking:

* Low: Indicates attempted suspicious activity that did not compromise the network (e.g., a port scan or a failed intrusion attempt). Low severity is treated as a security event.
* Medium: Indicates suspicious activity that deviates from normally observed behavior and, depending on the use case, may be indicative of a resource compromise. Medium severity is treated initially as a security event but may be elevated to a security incident.
* High: Indicates the resource in question (e.g., an EC2 instance or a set of IAM user credentials) is compromised and is being used for unauthorized purposes. High severity is a true security incident.

#### Medium and Low Event Procedure

1. Initial response: IRT reports incident to all internal staff
2. Investigation: Investigates the issue
3. Internal notification: Notifies all staff via appropriate communication channels

#### High Security Incident Procedure

1. Initial response: IRT reports incident to all internal staff
2. Documentation: Raises a ticket in ticketing system and update as needed
3. Investigation: Investigates the issue
4. Internal notification: Notifies all staff via appropriate communication channels
5. External notification: Determines if notification to customers and authorities is necessary and, if so, sends notification

### Business Continuity and Disaster Recovery (BC/DR) Plan Testing

Screendesk tests its business continuity (BC) capabilities on at least an annual basis.

The IRT is responsible for overseeing the execution and documentation of the annual BC/DR Plan test. Screendesk employs a tabletop exercise to simulate an unexpected service disruption to the product platform. Testing assesses the adequacy of Screendesk's BC/DR plans and associated procedures to do the following:

* Restore product accessibility
* Communicate with internal and external parties
* Recover data
* Support capacity needs for information processing, telecommunications, and environmental support in specified contingency conditions

Screendesk documents the results of the annual BC/DR Plan test through a post-simulation report that details the following:

* A description of the simulated service disruption
* A summary of Screendesk's BC response actions
* Any identified issues and findings resulting from the BC/DR Plan test, including suggested updates
* Screendesk's performance against KPIs

### Backup

Screendesk performs backups of Sensitive, Confidential, and Public data for all in-scope production systems, including infrastructure and data stores necessary to maintain service level agreements (SLA) with customers.

Screendesk configures its cloud service providers (Render.com and Amazon S3) to perform backups of all data stored in the cloud. CSP backups are performed using the CSP's automated backup tool.

Backups are stored in a secure remote location at a sufficient distance to escape damage from a disaster at the main site of processing. Data will be retained for a period determined by business needs and regulatory requirements.

Backups are tested annually by the Engineering team to ensure that they can be restored and relied upon in an emergency. As part of testing, management determines their ability to meet the company's restoration time requirements.


# Monitoring

## Monitoring Policy

### Event Monitoring Policy

Screendesk implements comprehensive auditing and monitoring controls to identify and capture the following events:

* All authentication and authorization activities by all users and their associated accounts (e.g., successful and unsuccessful login attempts)
* Any access to or creation, modification, or deletion of Sensitive or Customer data
* All actions taken by privileged users
* Malicious activity

Screendesk monitors system components to capture these events with specialized software such as File Integrity Monitoring (FIM), Host-based Intrusion Detection Systems (HIDS), and/or change detection software programs. Notifications are set up to alert the CTO if immediate action needs to be taken.

The CTO is responsible for monitoring and communicating changes and events.

### Performance and Utilization Monitoring Policy

Screendesk monitors system components (e.g., servers) for appropriate performance and utilization by taking the following measures:

* Process monitoring: Screendesk monitors all critical processes and provides alerting and notification measures when processes fail.
* Network interface monitoring: Screendesk monitors the overall health and status of the network interface.
* CPU utilization: Screendesk identifies current, real-time capacity of the central processing unit (CPU) and sends alerts and notifications if capacity is over limits and/or assets are underutilized.
* Memory utilization: Screendesk identifies current, real-time memory usage and sends alerts and notifications if memory usage is high and/or if memory availability is low.
* Disk utilization: Screendesk identifies current, real-time disk space and sends alerts and notifications if disk space is low.

### Logging and Reporting Policy

Along with capturing all necessary events described in the Event Monitoring Policy, Screendesk implements protocols to log, store, and review all required events and their associated attributes as necessary.

#### Logging

Screendesk uses capturing and forwarding protocols (e.g., Syslog) and/or specialized software applications or other technology as necessary to protect the confidentiality, integrity, and availability of audit trails and their respective log reports that are produced by monitoring activities.

#### Review

The CTO reviews all applicable user permissions and related output (e.g., log reports) to identify any issues or concerns and report them immediately to appropriate personnel.

#### Reporting

Any anomalies, such as unauthorized configuration changes in the logs, are escalated in accordance with the Incident Management Policy.


# Network and Systems

## Network and System Security Policy

### Data Handling Policy

#### Types of Data

The following types of data are stored, processed, and/or transmitted on system components that are owned, operated, maintained, and controlled by Screendesk:

* Sensitive: Applies to the most sensitive business information, to which access is strictly limited (e.g., passwords, encryption keys)
* Confidential: Applies to less sensitive business information, which is intended for use solely by Screendesk and/or its customers (e.g., screen recordings, customer support data)
* Public: Applies to all other information that does not clearly fit into the above classifications

#### Retention

Screendesk retains Sensitive and Confidential data only for as long as necessary to fulfill its purposes unless otherwise required by law or to meet legal and customer contractual obligations. To support compliance with these obligations, the CTO reviews Screendesk's data retention practices on an annual basis.

#### Disposal

Screendesk securely disposes of Sensitive and Confidential data following defined processes once it is no longer necessary for legal, regulatory, or business requirements or it has reached the end of its retention period.

The following methods are used for both hard copy and electronic data:

* Purging and deleting data from all system components using a secure wipe program in accordance with industry-accepted standards for secure deletion
* Destroying any sensitive data that is in a hard copy format (e.g., cross-shredding)

For electronic media stored on system components that are no longer in use, data is disposed of through secure deletion methods.

Instances of customer data disposal are tracked via a ticketing system to document the steps taken to complete the removal.

### Information Security Policy

Screendesk maintains reasonable technical, organizational, and physical security measures to protect the security of Sensitive and Confidential data in transit, at rest, and in storage from unauthorized access or unlawful disclosure.

Critical security controls include, but are not limited to, the following:

* Encryption in transit: Sensitive and Confidential data transfers are sent via a secure transfer system that is transport layer security (TLS) 1.2 or higher.
* Encryption at rest: All Screendesk servers, workstations, and laptops use advanced encryption standard (AES) 256 disk encryption.
* Outbound files: A secure file transfer platform is used to transfer files outside of the Screendesk network.
* Inbound files: During transfer, all files sent into the Screendesk network are verified that they are free of corruption and that the files originated from a known source.
* Database: Screendesk application databases that are externally accessible by web traffic are encrypted and provide a level of identification security using an application-specific protocol such as HTTPS. Sensitive and Confidential data in Screendesk databases is also encrypted from the customer's side before being inserted into the database.
* Data segregation: Sensitive and Confidential data remains in either the on-premises deployment of Screendesk's products or secure cloud environments (Render.com and Amazon S3).
* Data storage: Sensitive and Confidential data is only stored in approved systems, databases, and endpoints (e.g., laptops).
* Cloud storage: Secure and Confidential data is stored in a secure, dedicated cloud environment behind a firewall.
* Production and test environments: Screendesk sanitizes all production data before use in non-production environments, as applicable.
* Incident management: Screendesk maintains a process for identifying, managing, and resolving privacy incidents in accordance with the Screendesk Incident Management Policy.


# People Security

## People Security Policy

### Employee Confidentiality Agreements

All employees of Screendesk are required to read and accept the terms of a confidentiality agreement upon hire. This agreement states that they are prohibited from disclosing any company data from the systems and system components to which they have access. Screendesk ensures that these agreements comply with all applicable laws. The organization will not grant an employee access to any Screendesk assets without obtaining the employee's verified acknowledgment of the agreement.

### Background Check Policy

Screendesk uses either an approved background check vendor or defined reference checks to perform background checks on individuals prior to their start date.

### Security Awareness Training

All employees within Screendesk must undergo security awareness training within thirty (30) days of hire and at least annually thereafter.

The training accomplishes the following:

* Ensure employees are aware of significant security issues that pose a credible threat to the organization, its network infrastructure, and its supporting system resources
* Establish a comprehensive framework that effectively addresses the core components of security awareness, training, and education
* Provide subject matter directly related to the safety and security of specific system components, especially those to which all users have access
* Communicate the necessary response and resolution measures if employees suspect a security event or incident

The CTO monitors completion of security awareness training and follows up with employees who have not complied with the above requirement.

### Performance

As part of maintaining information security standards, the CEO is required to complete performance appraisals for the CTO, and vice versa, at least annually. These appraisals should include an assessment of adherence to security policies and practices.

Given Screendesk's small size (2 employees), it's crucial that both team members are fully aligned on security practices and consistently implement them in their daily operations. Regular, open communication about security matters should be maintained between the CEO and CTO.


# Risk Management

## Risk Management Policy

Screendesk has designed a risk assessment program to assess the organization's enterprise-level risk at least annually or upon significant changes to the environment.

As part of the risk assessment process, Screendesk will do the following:

1. Specify Screendesk's objectives and identify and assess risks related to these objectives.
2. Identify and assess threats to and vulnerabilities in systems and services (the latter through changes to service commitments).
3. Determine the likelihood and magnitude of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of the system relative to the information it processes, stores, or transmits.
4. Integrate risk assessment results and risk management decisions with the organization, its mission, and/or its business process perspectives via system-level risk assessments.
5. Document risk assessment results in the organization's risk registry and respond to the results in accordance with Screendesk's risk tolerance.
6. Disseminate risk assessment results to key stakeholders (both employees).
7. Update the risk assessment when there are significant changes to the system, its operating environment, or other conditions that may impact the security or privacy of the system.
8. Identify and assess potential fraud and its potential impact on the organization's objectives.
9. Ensure management selects and develops manual and technical general control activities to assist in mitigating risks.

Given Screendesk's small size and the nature of its business (enabling customer support teams to request and send screen recordings for debugging), particular attention should be paid to:

* Data privacy and protection risks associated with screen recordings
* Security risks related to the use of Render.com as the cloud provider and Amazon S3 for storing recordings
* Risks associated with the transmission and storage of potentially sensitive customer data
* Compliance risks related to SOC2 Type 2 requirements

The CTO, in collaboration with the CEO, is responsible for conducting and documenting the annual risk assessment, as well as any additional assessments triggered by significant changes in the business environment or operations.


# Vendor Management

## Vendor Management Policy

Screendesk requires vendors to maintain their own security practices and procedures and to abide by Screendesk's security policies.

### New Vendors

Using a defined process, Screendesk management assesses a potential vendor to evaluate its criticality and riskiness. Relevant assessment criteria may include but is not limited to:

* The vendor's expertise, experience, and reputation
* The nature and necessity of the service
* Whether a vendor needs access to Sensitive or Confidential data
* The vendor's security infrastructure
* The vendor's level of contact with customers

A vendor's criticality rating determines the level and intensity of initial due diligence and ongoing monitoring. It also facilitates management's ability to appropriately manage process dependencies on suppliers and quickly identify which vendors have access to Sensitive or Confidential data.

#### Criticality Rating

Possible vendor criticality ratings are defined below.

**Critical**

* Daily operations critically depend on the service.
* Service failure or significant impairments would halt business processes.
* Supplier provides a service critical to developing, supporting, and securing the company software product.

**High**

* Daily operations significantly depend on the service.
* Service failure or significant impairments would seriously disrupt business processes.
* Supplier provides a service that is significantly important to developing, supporting, and securing the company software product.

**Medium**

* Daily operations regularly use the service but do not depend on it.
* Service failure or significant impairments would impair but not seriously disrupt business processes.
* Supplier service is used for developing, supporting, and securing the company software product, but it is not a critical function.

**Low**

* Operations regularly use the service but unevenly (i.e., not every day or not every user).
* Service failure or significant impairments would present challenges to operations but would not disrupt business processes.
* Supplier service is used for developing, supporting, and securing the company software product, but it is not an essential function.

### Vendor Review

Screendesk collects and reviews a compliance report at least annually on all vendors rated critical or high risk. The review is documented and any exceptions or deviations noted in the reports are evaluated to determine their impact on the service.

For Screendesk, this includes annual reviews of:

1. Render.com (cloud service provider)
2. Amazon Web Services (S3 for data storage)

The CTO is responsible for conducting these reviews and reporting findings to the CEO. Any identified risks or concerns should be addressed promptly, and mitigation strategies should be developed and implemented as necessary.

### Vendor Security Requirements

Screendesk requires all vendors, especially those handling Sensitive or Confidential data, to adhere to the following security requirements:

1. Implement and maintain appropriate security measures to protect Screendesk's data.
2. Comply with all applicable data protection and privacy laws and regulations.
3. Notify Screendesk immediately of any security incidents that may affect Screendesk's data.
4. Allow Screendesk to conduct security assessments or audits when deemed necessary.
5. Provide documentation of their security practices and any relevant certifications upon request.
6. Ensure that any subcontractors or third parties they engage also adhere to these security requirements.

### Ongoing Monitoring

Screendesk continuously monitors its critical vendors for:

1. Changes in their security posture or practices
2. News of security incidents or breaches
3. Updates to their services that may impact Screendesk's operations or security
4. Compliance with agreed-upon service level agreements (SLAs)

The CTO is responsible for this ongoing monitoring and should report any significant findings or concerns to the CEO promptly.

### Vendor Termination

When terminating a relationship with a vendor, especially one that has had access to Sensitive or Confidential data, Screendesk follows these steps:

1. Revoke all access to Screendesk systems and data
2. Ensure the return or secure destruction of any Screendesk data held by the vendor
3. Update the vendor inventory and any relevant documentation
4. Conduct a final security assessment to ensure no residual risks remain

The CTO oversees this process and ensures its completion before finalizing the termination of any vendor relationship.


# Vulnerability Management

## Vulnerability Management Policy

Screendesk's vulnerability management program ensures the confidentiality, integrity, and availability (CIA) of the organization's information systems landscape, which includes all critical system resources.

The Screendesk vulnerability management program addresses vulnerabilities and threats through remediation and control implementation. These terms are defined as follows:

* Vulnerabilities: Software flaws or misconfigurations that may weaken the security of an organization's system
* Threats: Capabilities or methods of attack developed by malicious entities to exploit vulnerabilities and harm a computer system or network. Potential threats also include insider threats
* Remediation: Means of addressing or resolving vulnerabilities and threats
* Control implementation: The use of defined scanning and testing procedures to identify, communicate, and address vulnerabilities and threats

Chief components of the program include the following:

### Configuration Standards

Screendesk establishes a secure information security baseline by provisioning, hardening, securing, and locking down all critical system resources through continuous monitoring and security patches.

### Network Architecture

Screendesk develops secure network architecture and secure segmentation to prevent vulnerabilities.

### Network Scanning and Monitoring

Screendesk follows internal and external vulnerability scanning procedures and conducts network layer and application layer penetration tests to manage vulnerabilities.

Vulnerabilities will be categorized by severity based on the following criteria:

* Impact: The possible disruption to systems and business operations
* Likelihood: The ease in which a vulnerability may be exploited
* Compensating controls: The availability of network- or host-based methods of mitigation

The classification and prioritization of vulnerabilities are based on the Open Web Application Security Project (OWASP) Risk Rating Methodology. Separate Impact and Likelihood scores are assigned to the identified vulnerability. The combined scores result in an overall severity score for the vulnerability, indicating its prioritization for remediation.

### Network Segmentation

Screendesk segments its network to prevent direct or unauthorized connections between an external network and its information systems – and in particular between an external network and Confidential data in cloud environments. Segmentation is established through the following means:

* Demilitarized zones (DMZ) that logically separate Screendesk's systems and data from untrusted external networks
* Security tools that isolate subnetworks and security groups (e.g., customer environments) and prohibit connection except through monitored interfaces

### Vulnerability Scanning

Screendesk performs internal and/or external vulnerability scans to test in-scope systems at least quarterly. These reports are shared with the CTO.

### Vulnerability Remediation Procedure

Once an employee has identified a critical or zero-day vulnerability, they report the vulnerability immediately to the CTO, who is responsible for carrying out this procedure for each identified vulnerability.

1. Develop a vulnerability analysis. Document the following details about the vulnerability:
   * Description/Nature of the vulnerability
   * System(s) impacted
   * Risk rating based on the potential impact, the likelihood of exploitation, and any existing controls that may reduce the risk
   * Any suggested controls that may be implemented to address the vulnerability
2. Determine the remediation timeline based on the risk rating:
   * Critical: Immediately to 7 days from identification
   * High: Within 14 days of identification
   * Medium and Low: Within 30 days of identification

### Patch Management Policy

Effective patch management and system updates help ensure the confidentiality, integrity, and availability of systems from new exploits, vulnerabilities, and other security threats.

All necessary system patches and system updates to Screendesk's underlying infrastructure are obtained from the software vendor and/or other trusted third parties:

* Vendor websites and email alerts
* Vendor mailing lists, newsletters, and additional support channels for patches and security
* Third-party websites and email alerts
* Third-party mailing lists
* Approved online forums and discussion panels

All necessary system patches and system updates to Screendesk's underlying infrastructure are obtained and deployed at least monthly. The specific timeline for applying patches depends on the severity level of the vulnerability for each system component. Screendesk uses the following timelines for patch management based on severity level:

* Critical: Immediately to 7 days from identification
* High: Within 14 days of identification
* Medium and Low: Within 30 days of identification

Patches fixing highly critical or zero-day vulnerabilities are escalated and applied as soon as possible. The CTO considers the following factors to determine when to apply the patch:

* The relative importance of the vulnerable systems
* The relative severity of each vulnerability
* The operational risks of patching without first testing
* Whether there is a viable option to mitigate the vulnerability through an alternative method, at least until patches are fully deployed and operational

### Antivirus Protection Policy

Screendesk has antivirus (AV) solutions to detect malicious code and malware. AV is deployed on all applicable system components in its underlying infrastructure.

The AV meets the following criteria:

* The most current version available from the vendor
* Enabled for automatic updates
* Configured for conducting periodic scans at least monthly
* Capable of removing all known types of malicious software

All AV solutions will generate logs for monitoring and alerting IT personnel about infected machines. Because strong and comprehensive malware measures are not just limited to the use of AV, additional tools are to be employed as necessary for eliminating all other associated threats.


# Subprocessors

<table data-view="cards" data-full-width="true"><thead><tr><th>Name</th><th>Description</th><th>Data Location</th><th>DPA</th><th>Type of data processed</th><th>Data Transfers</th><th>Data Retention Duration</th></tr></thead><tbody><tr><td>Google Analytics</td><td>Google Analytics is an analytics platform that more uniquely gives us certain nice-to-have "vanity" analytics and serves as a good place for understanding where on the web our users are coming from.</td><td>United States</td><td>Yes</td><td><p></p><ul><li>Website usage data </li><li>User location data (country, city)</li><li>Device and browser information</li><li>Anonymized IP addresses</li><li>User behavior data</li></ul></td><td><p></p><ul><li>SOC 2 and SOC 3 certified</li><li>ISO 27001 certified</li><li>Encryption in transit and at rest</li><li>Access controls and authentication mechanisms</li><li>Regular security audits</li></ul></td><td>26 months for user-level and event-level data</td></tr><tr><td>Sentry</td><td>Sentry is used as our error logging platform. When you get an error, we get it too so we can better fix these bugs as soon as possible.</td><td>United States</td><td>Yes</td><td><p></p><ul><li>Application error logs and stack traces</li><li>Performance metrics</li><li>User context data related to errors (e.g., browser type, OS version)</li><li>Limited user identification data</li></ul></td><td><p></p><ul><li>SOC 2 Type II certified</li><li>GDPR compliant</li><li>Encryption in transit and at rest</li><li>Role-based access controls</li><li>Regular security audits</li></ul></td><td>90 days</td></tr><tr><td>Intercom</td><td> Intercom is our customer support ticketing system. It allows us to help track, prioritize, and solve customer support interactions.</td><td>United States</td><td>Yes</td><td><p></p><ul><li>User profile information (e.g., name, email, company)</li><li>Conversation history and content</li><li>User behavior data </li><li>Custom attributes or tags assigned to users</li></ul></td><td><p></p><ul><li>SOC 2 Type II certified</li><li>GDPR and CCPA compliant</li><li>Encryption in transit (TLS) and at rest (AES-256)</li><li>Multi-factor authentication</li><li>Regular third-party security audits</li><li>ISO 27001:2013 certified</li></ul></td><td>90 days</td></tr><tr><td>Whereby</td><td>Facilitates live video calls for real-time communication</td><td>Ireland</td><td>Yes</td><td><p></p><ul><li>Video and audio streams during live calls</li><li>Temporary storage of call recordings</li><li>User metadata necessary for call functionality (e.g., participant names, call durations)</li></ul></td><td><p></p><ul><li>End-to-end encryption for video calls</li><li>SOC 2 Type II certified</li><li>GDPR compliant</li><li>Regular security audits</li></ul></td><td>Recordings are temporarily stored and then immediately deleted after transfer to your own AWS S3 storage. No long-term data retention on Whereby's systems.</td></tr><tr><td>Render.com</td><td>Render.com is a cloud platform provider that offers hosting and deployment services for web applications, static sites, databases, and background workers. They provide infrastructure and tools to build and run applications and websites.</td><td><p>United States / Germany</p><p><br></p></td><td>Yes</td><td>Application data, user data, logs, and metadata related to hosted services</td><td>Global infrastructure with servers primarily in the US and EU Security measures: SOC 2 Type II certified, encryption in transit and at rest, regular security audits</td><td>60 days</td></tr><tr><td>AWS</td><td>Cloud storage (S3), messaging and mobile notifications (SNS), and media transcoding and processing (MediaConvert)</td><td>United States / France</td><td>Yes</td><td><p></p><ul><li>S3: Files and objects, potentially including user-generated content, backups, and application data</li><li>SNS: Message payloads, which may include notifications and alerts</li><li>MediaConvert: Video and audio files for processing and transcoding</li></ul></td><td><p></p><p>Global infrastructure with data centers worldwide; customers can choose specific geographic regions for data storage and processing Security measures:</p><ul><li>Encryption in transit and at rest</li><li>Access controls and identity management</li><li>Compliance certifications including SOC 1, 2, and 3, ISO 27001</li><li>Network security and protection against DDoS attacks</li></ul></td><td><p></p><ul><li>S3: Customizable retention policies, data stored until deliberately deleted</li><li>SNS: Messages typically retained for short periods during delivery</li><li>MediaConvert: Input and output files retained as specified by the customer</li></ul></td></tr></tbody></table>


# Data Processed

Screendesk collects the video and audio data recorded by its users. Additional information collected falls under the basic PII category such as names, usernames, IP addresses, email addresses, and company names (if given). Information regarding the data collection, processing, and purpose can be found within our Privacy Policy. We also outline our obligations regarding personal data within our Data Processing Addendum.


# User Access Management

## User Access Management Guide

### Overview

This guide outlines the user management and authentication framework for Screendesk organizations, including roles, permissions, and authentication methods.

### Organization Structure

* All users belong to an organization
* Access to features is determined by user roles
* User management is controlled by Owners and Admins

### User Roles and Permissions

#### Owner & Admin

* Full administrative access to the organization
* Can manage billing and subscription settings
* Can modify organization-wide settings
* Can manage user roles and permissions
* Can configure authentication methods

#### Editor

* Cannot access billing or organization settings
* Cannot modify user roles or permissions
* Has access to manage all recordings within the organization

#### Member

* Basic user role
* Can manage only their own recordings
* Cannot access organization settings
* Cannot access other users' recordings

### Authentication Methods

#### SAML SSO 2.0

* Enterprise-grade Single Sign-On
* Integrates with existing identity providers
* Supports automated user provisioning
* When enabled, becomes the primary authentication method
* **Important**: When SAML is enabled, only the organization owner can continue using email/password login

#### SCIM

* Automated user provisioning and deprovisioning
* Synchronizes user attributes with identity provider
* Streamlines user lifecycle management
* Supports real-time user updates

#### Email/Password + MFA

* Traditional authentication method
* Requires email verification
* Multi-Factor Authentication (MFA) required for additional security
* Available to all users when SAML is not enabled
* Only available to organization owner when SAML is enabled

### Best Practices for User Management

1. Enable SAML SSO for enterprise organizations
2. Implement SCIM for automated user management
3. Regularly audit user roles and permissions
4. Ensure MFA is enabled for all email/password accounts
5. Document role assignments within your organization
6. Regularly review access logs and user activities
7. Remove inactive users promptly


# Recordings Security

## Recordings Security Guide

### Overview

This guide details the security features and controls available for managing recordings within Screendesk, including access controls, storage options, and data retention policies.

### Recording Access Controls

#### Access Level Restrictions

* Administrators can restrict recording access to authenticated users only
* When enabled, only logged-in Screendesk users can view recordings
* Prevents unauthorized access to sensitive content

#### Role-Based Access

* Owners & Admins: Full access to all recordings
* Editors: Can manage all recordings within the organization
* Members: Can only manage their own recordings

### Data Storage and Management

#### Storage Location Options

* Administrators can select preferred storage region:
  * North America
  * Europe
* Benefits:
  * Meets data residency requirements
  * Ensures compliance with regional regulations
  * Optimizes access speed for local users

#### Automatic Data Retention

* Configurable automatic deletion rules
* Administrators can set recordings to delete after specified number of days
* Benefits:
  * Maintains data hygiene
  * Supports compliance requirements
  * Reduces storage costs
  * Automates data lifecycle management

### Security Considerations

#### Data Protection

* All recordings are stored with encryption
* Access logs are maintained for audit purposes
* Regional storage supports data sovereignty requirements

#### Compliance Support

* Automatic deletion helps maintain data minimization principles
* Storage location selection aids in regulatory compliance
* Access restrictions support data protection requirements

### Best Practices for Recording Security

1. Implement authenticated-only access for sensitive content
2. Choose storage location based on compliance requirements
3. Set up appropriate data retention policies
4. Regularly audit recording access patterns
5. Document storage and retention configurations
6. Review and update security settings periodically
   1. Train users on proper recording sharing practices


# Overview

Welcome to the technical documentation covering Screendesk's architecture and security infrastructure. This space contains detailed information about:

### Contents

* System Architecture Diagrams
* Security Protocols
* Infrastructure Overview
* Data Flow Patterns
* Security Measures & Compliance

### Documentation Access

All relevant diagrams and technical specifications will be maintained and updated in this space. For the most current architectural decisions and security implementations, please refer to the documentation sections above.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/GrcNJnWzlo6fiGVqI4sQ">Request Screen Recording</a></td><td>Architecture of the feature</td><td></td><td><a href="/pages/GrcNJnWzlo6fiGVqI4sQ">/pages/GrcNJnWzlo6fiGVqI4sQ</a></td></tr><tr><td><a href="/pages/r47L6k2zligDvGXGiQ10">Video Conferencing</a></td><td>Architecture of the feature</td><td></td><td><a href="/pages/r47L6k2zligDvGXGiQ10">/pages/r47L6k2zligDvGXGiQ10</a></td></tr></tbody></table>

### Additional Information

For detailed technical inquiries or specific security-related questions, please contact our CTO:

Adrien\
<adrien@screendesk.io>

*Note: This documentation is regularly updated to reflect the latest architectural changes and security enhancements.*


# Request Screen Recording

{% @mermaid/diagram content="flowchart TB
%% Customer Side
subgraph CustomerUsers\["Customer Users"]
CustAgent\["Support Agent"]
CustAdmin\["Workspace Admin"]
EndUser\["End Customer"]
end

```
subgraph HelpdeskIntegration["Helpdesk Integration"]
    HelpdeskApp["Screendesk App in\nCustomer Helpdesk"]
    HTTPS1["HTTPS/TLS 1.2+"]
end

subgraph RecordingFlow["Screen Recording Flow"]
    RecordLink["Short Link Generation"]
    Browser["Browser Recorder\nMediaRecorder API"]
    ScreenCapture["Screen + Audio Capture"]
end

subgraph Authentication["Authentication Layer"]
    AuthMethods["Authentication Methods"]
    SAML["SAML 2.0 Integration"]
    SCIM["SCIM User Management"]
    MFA["Multi-Factor Auth"]
end

%% Screendesk Internal Users
subgraph InternalUsers["Screendesk Internal Users"]
    SupportAdmin["Support Admin\n(Admin Dashboard Access)"]
    EngineerAdmin["Engineering Admin\n(Cloud Services Access)"]
    CTO["CTO\n(Full Infrastructure Access)"]
end

%% Application Layer
subgraph AppInfra["Application Infrastructure (Render.com)"]
    direction TB
    subgraph WebTier["Web Tier"]
        Web1["Web Server 1"]
        Web2["Web Server 2"]
        WebN["Web Server N"]
    end
    
    subgraph WorkerTier["Worker Tier"]
        Worker1["Worker 1"]
        Worker2["Worker 2"]
        WorkerN["Worker N"]
    end
    
    Redis["Redis Cache"]
    
    subgraph DBTier["Database Tier"]
        DB["PostgreSQL\nEncrypted at Rest\nPoint-in-Time Recovery"]
    end

    WAF["Web Application Firewall"]
end

%% Cloud Services
subgraph CloudServices["Cloud Services"]
    subgraph S3Storage["Screendesk S3 Storage"]
        S3["Amazon S3\nScreen & Video Recordings\nEncrypted at Rest"]
    end
    
    subgraph VideoService["Video Conferencing Service"]
        Whereby["Whereby\nReal-time Video"]
        RecordingHandler["Recording Handler"]
    end
end

%% Admin Access Controls
subgraph AdminAccess["Admin Access Security"]
    IPWhitelist["IP Whitelisting"]
    GoogleSSO["Google Workspace SSO"]
    AdminMFA["Strong MFA"]
end

%% Encryption Layer
subgraph EncryptionLayer["Security & Encryption"]
    TLS["TLS 1.2+ Encryption"]
    HTTPS2["HTTPS Only"]
end

%% Screen Recording Flow
CustAgent --> HelpdeskApp
HelpdeskApp --> RecordLink
RecordLink --> EndUser
EndUser --> Browser
Browser --> ScreenCapture
ScreenCapture --> |"Submit Recording"|WebTier

%% Standard Access Patterns
HelpdeskApp --> HTTPS1
HTTPS1 --> AuthMethods
CustAdmin --> AuthMethods
AuthMethods --> SAML
AuthMethods --> SCIM
AuthMethods --> MFA

%% Admin Access Patterns
SupportAdmin --> AdminMFA
SupportAdmin --> |"Admin Dashboard"|WebTier

EngineerAdmin --> AdminMFA
EngineerAdmin --> IPWhitelist
EngineerAdmin --> GoogleSSO
EngineerAdmin --> |"Cloud Services Access"|CloudServices

CTO --> AdminMFA
CTO --> IPWhitelist
CTO --> GoogleSSO
CTO --> |"Full Infrastructure Control"|AppInfra

%% Application Flow
WAF --> TLS
TLS --> WebTier
WebTier --> WorkerTier
WebTier --> Redis
WebTier --> DB
WorkerTier --> DB
WorkerTier --> S3

%% Video and Recording Flow
HelpdeskApp --> |"Initiate Video Call"|Whereby
Whereby --> |"Real-time Video"|EndUser
Whereby --> |"Recording"|RecordingHandler
RecordingHandler --> |"Direct Storage"|S3

%% Notes
classDef note fill:#e6f3ff,stroke:#2d5986,stroke-width:2px;

note1["Data deletion:\nHard deletes only\nMax 5 days retention"]
note2["Horizontal scaling\nfor performance"]
note3["EU/US Region Selection\nper customer"]
note4["All communications\nencrypted with HTTPS/TLS 1.2+"]
note5["Client-side recording\nNo installation needed"]
note6["Secure link generation\nand validation"]

class note1,note2,note3,note4,note5,note6 note;" %}
```

## Screendesk Technical Architecture and Flow Documentation

### Introduction

Screendesk's architecture combines secure helpdesk integration, sophisticated recording capabilities, and robust cloud infrastructure to deliver a seamless support experience. This document details the technical flows and security measures that enable secure communication and data handling throughout the platform.

### Core Recording Technologies

#### Screen Recording Workflow

At the heart of Screendesk's functionality lies a sophisticated screen recording system that operates entirely through web browsers. When a support agent initiates a recording request, the system generates a secure short link through our helpdesk integration. This link serves as a secure gateway for end customers to access the recording interface.

The recording process leverages the browser's MediaRecorder API, enabling high-quality screen and audio capture without requiring software installation. This client-side approach significantly enhances security and user adoption by eliminating the need for external applications or plugins. The captured content flows directly through encrypted channels to our web infrastructure, ensuring data security from the moment of capture.

#### Video Conferencing Integration

Parallel to screen recording, our video conferencing capabilities are powered by Whereby's real-time communication platform. The integration maintains end-to-end security while enabling direct video recordings storage to our S3 infrastructure. This architecture eliminates intermediary storage points, reducing potential security vulnerabilities and ensuring immediate availability of recorded sessions.

### Infrastructure Components

#### Web Service Layer

Our web infrastructure, hosted on Render.com, employs a horizontal scaling approach with multiple web servers operating in parallel. These servers handle incoming requests from both helpdesk integrations and direct recording submissions. A Web Application Firewall (WAF) sits in front of this tier, providing an additional security barrier against potential threats.

The web tier maintains direct connections to our Redis cache system, optimizing performance for frequent operations while ensuring session data remains secure. This caching layer plays a crucial role in managing user sessions and temporary data storage, all while operating within our encrypted environment.

#### Processing Layer

Background operations are managed by our worker tier, which consists of multiple processing servers designed to handle asynchronous tasks. These workers manage critical operations such as recording processing, storage management, and data cleanup routines. The worker tier maintains secure connections to both our database and S3 storage systems, ensuring that all data transformations occur within our secured infrastructure.

#### Data Storage Architecture

Our data storage strategy employs a multi-layered approach:

* A PostgreSQL database cluster provides our primary data store, with all data encrypted at rest and point-in-time recovery capabilities enabled
* Amazon S3 storage handles all media content, including screen recordings and video conference recordings
* Regional deployment options (EU/US) ensure compliance with data sovereignty requirements
* Redis provides temporary storage for session management and performance optimization

### Security Implementation

#### Authentication Framework

Access control begins with our comprehensive authentication layer, which supports multiple secure authentication methods:

* SAML 2.0 integration enables enterprise-grade single sign-on capabilities
* SCIM protocols facilitate automated user management
* Multi-factor authentication adds an essential security layer
* Additional security measures for administrative access include IP whitelisting and Google Workspace SSO

#### Administrative Access Control

Internal system access follows a hierarchical security model:

* Support administrators access the admin dashboard through strong MFA verification
* Engineering administrators require additional security clearance through IP whitelisting and Google Workspace SSO
* CTO-level access includes full infrastructure control with quarterly security reviews

#### Data Protection Measures

Every aspect of data handling incorporates security measures:

* All communications utilize TLS 1.2+ encryption
* HTTPS-only protocols ensure secure data transmission
* Regional data storage options respect data sovereignty requirements
* Strict data deletion policies ensure complete removal within five days
* Client-side recording eliminates the need for software installation while maintaining security

### Operational Flows

#### Helpdesk Integration Process

Integration with customer helpdesk systems occurs through our dedicated Screendesk application, which establishes secure communications via HTTPS/TLS 1.2+ protocols. This integration enables support agents to initiate recording requests and video calls directly from their familiar helpdesk environment.

#### Recording Request Flow

1. Support agents trigger recording requests through the helpdesk interface
2. Our system generates secure, validated short links
3. End customers receive and access these links
4. Browser-based recording captures screen and audio content
5. Captured content transmits directly to our web tier
6. Processing occurs in our worker tier
7. Final storage in encrypted S3 buckets

#### Administrative Operations

Administrative functions follow strictly controlled paths:

* Support operations flow through the admin dashboard
* Cloud service access requires multiple security validations
* Infrastructure modifications undergo careful access control
* All administrative actions are logged and monitored

This architecture ensures secure, efficient operation while maintaining the flexibility needed for customer support interactions. Regular security audits and continuous monitoring maintain the integrity of all system components.


# Video Conferencing

{% @mermaid/diagram content="flowchart TB
%% Customer Side
subgraph CustomerUsers\["Customer Users"]
CustAgent\["Support Agent"]
CustAdmin\["Workspace Admin"]
EndUser\["End Customer"]
end

```
subgraph HelpdeskIntegration["Helpdesk Integration"]
    HelpdeskApp["Screendesk App in\nCustomer Helpdesk"]
    HTTPS1["HTTPS/TLS 1.2+"]
end

subgraph Authentication["Authentication Layer"]
    AuthMethods["Authentication Methods"]
    SAML["SAML 2.0 Integration"]
    SCIM["SCIM User Management"]
    MFA["Multi-Factor Auth"]
end

%% Screendesk Internal Users
subgraph InternalUsers["Screendesk Internal Users"]
    SupportAdmin["Support Admin\n(Admin Dashboard Access)"]
    EngineerAdmin["Engineering Admin\n(Cloud Services Access)"]
    CTO["CTO\n(Full Infrastructure Access)"]
end

%% Application Layer
subgraph AppInfra["Application Infrastructure (Render.com)"]
    direction TB
    subgraph WebTier["Web Tier"]
        Web1["Web Server 1"]
        Web2["Web Server 2"]
        WebN["Web Server N"]
    end
    
    subgraph WorkerTier["Worker Tier"]
        Worker1["Worker 1"]
        Worker2["Worker 2"]
        WorkerN["Worker N"]
    end
    
    Redis["Redis Cache"]
    
    subgraph DBTier["Database Tier"]
        DB["PostgreSQL\nEncrypted at Rest\nPoint-in-Time Recovery"]
    end

    WAF["Web Application Firewall"]
end

%% Cloud Services
subgraph CloudServices["Cloud Services"]
    subgraph S3Storage["Screendesk S3 Storage"]
        S3["Amazon S3\nScreen & Video Recordings\nEncrypted at Rest"]
    end
    
    subgraph VideoService["Video Conferencing Service"]
        Whereby["Whereby\nReal-time Video"]
        RecordingHandler["Recording Handler"]
    end
end

%% Admin Access Controls
subgraph AdminAccess["Admin Access Security"]
    IPWhitelist["IP Whitelisting"]
    GoogleSSO["Google Workspace SSO"]
    AdminMFA["Strong MFA"]
end

%% Encryption Layer
subgraph EncryptionLayer["Security & Encryption"]
    TLS["TLS 1.2+ Encryption"]
    HTTPS2["HTTPS Only"]
end

%% Access Patterns
CustAgent --> HelpdeskApp
HelpdeskApp --> HTTPS1
HTTPS1 --> AuthMethods
CustAdmin --> AuthMethods
AuthMethods --> SAML
AuthMethods --> SCIM
AuthMethods --> MFA

%% Admin Access Patterns
SupportAdmin --> AdminMFA
SupportAdmin --> |"Admin Dashboard"|WebTier

EngineerAdmin --> AdminMFA
EngineerAdmin --> IPWhitelist
EngineerAdmin --> GoogleSSO
EngineerAdmin --> |"Cloud Services Access"|CloudServices

CTO --> AdminMFA
CTO --> IPWhitelist
CTO --> GoogleSSO
CTO --> |"Full Infrastructure Control"|AppInfra

%% Application Flow
WAF --> TLS
TLS --> WebTier
WebTier --> WorkerTier
WebTier --> Redis
WebTier --> DB
WorkerTier --> DB
WorkerTier --> S3

%% Video and Recording Flow
HelpdeskApp --> |"Initiate Video Call"|Whereby
Whereby --> |"Real-time Video"|EndUser
Whereby --> |"Recording"|RecordingHandler
RecordingHandler --> |"Direct Storage"|S3

%% Screen Recording Flow
CustAgent --> |"Screen Recording"|S3

%% Notes
classDef note fill:#e6f3ff,stroke:#2d5986,stroke-width:2px;

note1["Data deletion:\nHard deletes only\nMax 5 days retention"]
note2["Horizontal scaling\nfor performance"]
note3["EU/US Region Selection\nper customer"]
note4["All communications\nencrypted with HTTPS/TLS 1.2+"]
note5["Video recordings stored\ndirectly in Screendesk S3"]

class note1,note2,note3,note4,note5 note;" %}
```

### Overview

Screendesk's security architecture represents a sophisticated multi-layered approach to securing communications, data handling, and access control. Our system seamlessly integrates customer-facing components with internal infrastructure while maintaining rigorous security protocols at every interaction point. This documentation outlines the comprehensive security measures that protect our platform, ensuring data integrity and user privacy at all times.

### User Types and Access Management

#### Customer Users

At the customer level, Screendesk implements a carefully structured access system designed to meet diverse user needs while maintaining strict security standards. Support Agents operate through our dedicated application, which is deeply integrated within their existing helpdesk system. This integration enables them to seamlessly initiate video calls, manage screen recordings, and request additional recordings from end customers when needed. The integration layer ensures all these interactions occur within a secure, controlled environment.

Workspace Administrators hold elevated privileges within the system, accessing it through our robust authentication framework that incorporates SAML 2.0 and SCIM protocols. These administrators maintain complete control over their organization's workspace, managing configurations and user access permissions while working within our security framework. Their role is crucial in maintaining organizational security policies while ensuring smooth operation for their teams.

End Customers interact with our system through a streamlined, security-focused interface. When joining video calls through our Whereby integration or providing screen recordings, these users benefit from our end-to-end encryption and secure communication channels. Every interaction is protected by HTTPS/TLS 1.2+ protocols, ensuring data privacy and security throughout the session.

#### Internal Users and Access Controls

Internal access to Screendesk's systems follows a hierarchical structure with carefully delineated permissions and multiple security layers. Support Administrators access the system through our admin dashboard, protected by strong multi-factor authentication. Their direct connection to the web tier enables effective monitoring and support activities while maintaining system security through strictly defined access parameters.

Engineering Administrators operate under an even more rigorous security framework. Their access requires successful navigation through three distinct security layers: IP whitelisting, Google Workspace SSO, and enhanced MFA protocols. This triple-layer protection ensures that cloud service access remains secure while preventing unauthorized infrastructure modifications.

At the highest level, the CTO position holds comprehensive infrastructure control privileges. This role carries exclusive rights to modify Render.com services, with access undergoing quarterly security reviews to maintain compliance and security standards. The position's elevated access comes with additional responsibility for maintaining system integrity and overseeing security protocols.

### Technical Infrastructure

#### Application Architecture

The Screendesk application infrastructure, hosted on Render.com, employs a sophisticated multi-tier architecture designed for both security and scalability. The Web Tier comprises multiple servers operating in horizontal scaling configuration, allowing for dynamic response to load changes while maintaining consistent security. These servers maintain direct connections to our Redis cache, optimizing performance while operating behind a robust Web Application Firewall.

Our Worker Tier handles background processing through a distributed network of servers, each maintaining secure connections to both our database and S3 storage systems. This tier scales automatically based on workload demands, ensuring consistent performance without compromising security. The separation between web and worker tiers provides an additional layer of security through compartmentalization.

The Database Tier centers around a PostgreSQL implementation with comprehensive security measures. All data remains encrypted at rest, with point-in-time recovery capabilities ensuring data resilience. The database maintains secure connections exclusively with authorized application tiers, preventing unauthorized access while enabling efficient data operations.

#### Communication Flow

The integration of Screendesk into customer helpdesk systems represents a crucial security junction. Our application establishes secure communications through consistent HTTPS/TLS 1.2+ protocols, creating a trusted channel between customer systems and our authentication layer. This integration ensures seamless operation while maintaining rigorous security standards.

Video conferencing follows a carefully designed security path. When a Support Agent initiates a call, the request flows through our helpdesk integration to Whereby's secure video service. Video recordings move directly to Screendesk's S3 storage, eliminating security vulnerabilities that could arise from intermediate storage. This direct path ensures data integrity while maintaining performance.

Screen recording processes follow similarly secure paths. Transmissions flow directly to S3 storage with encryption both in transit and at rest. Our regional storage system respects customer preferences and data sovereignty requirements, storing data in either EU or US regions as specified.

### Security Implementation

#### Authentication and Encryption

Screendesk's authentication system integrates multiple secure protocols to ensure comprehensive access control. Enterprise customers benefit from SAML 2.0 integration for single sign-on capabilities, while SCIM protocols automate user management securely. Multi-factor authentication adds an essential security layer, with internal users receiving additional protection through Google Workspace SSO integration.

All communications within the system employ TLS 1.2+ encryption, ensuring data privacy during transmission. Our strict HTTPS-only policy combines with Web Application Firewall protection to create a robust security perimeter. For administrative access, IP whitelisting provides an additional security layer, restricting system access to authorized locations only.

#### Data Management and Compliance

Our data management strategy emphasizes security and sovereignty. Regional deployment options in both EU and US territories allow customers to maintain compliance with local data protection regulations. All recordings stored in our S3 system remain encrypted at rest, with access strictly controlled through our authentication layers.

The platform maintains a strict data deletion policy, implementing true hard deletes with a maximum retention period of five days. This policy ensures that when data deletion is requested, it is completely and verifiably removed from all storage layers. Our comprehensive logging and monitoring systems track all access and changes, maintaining an audit trail while enabling real-time threat detection.

Regular security reviews and quarterly access audits maintain the integrity of our security systems, while continuous WAF monitoring provides protection against emerging threats. This multi-layered approach to security and compliance ensures that Screendesk maintains the highest standards of data protection while providing essential services to our customers.


# Privacy Policy

Privacy policy of Screendesk. Read more if you want to learn how we intend to use your data.

{% hint style="info" %}
Effective: January 31, 2022
{% endhint %}

This Privacy Policy describes how Screendesk collects, uses, and shares your personal information, as well as your choices and rights with respect to your personal information.

### **Scope of this Privacy Policy**

This Privacy Policy applies to information that relates to you as an identifiable individual (often referred to as “personal information” or “personal data”) that Screendesk receives or collects when you interact with us or our services, website, and software (the “Services”).This Privacy Policy does not apply to any third-party services, websites, or software, such as third-party applications that may be integrated into our Services via API. Those services, websites, and software are subject to their own terms and privacy policies, and you should read those carefully.

### **Information We Collect**

We collect and receive the following types of information:Information You Provide to Us:

* *Account Information:* To create an account for the Services or to enable certain features, we require that you provide us with information for your account such as name, email, password, and authentication credentials. If you sign up for a paid subscription, we (or our payment processors) may need your billing details such as credit card information, banking information, and billing address.
* *Video and Other Customer Data:* In using our Services, our customers submit video recordings, seek user support, or provide other Customer Data (defined in our Terms of Service) to us. Our use of and processing of Customer Data is governed by our Terms of Service.
* *Other Information You Provide:* We receive other information from you when you choose to interact with us in other ways, such as if you sign up for one of our webinars or e-books, participate in a research study, contest, sweepstake, or event, apply for a job, or otherwise communicate with us.

Information We Collect Automatically:

* *Usage Data:* We automatically collect usage data about how you interact with our Services when you use them. For example, this could be actions you take on our platform, such as number of videos you’ve recorded or viewed, your sharing activity, or what third-party integrations you enabled.
* *Log Data:* Our servers automatically log certain types of data when you visit or use our Services, for example, when you navigate through our website. This data is stored in our log files and includes, Internet Protocol (IP) address, type of device, operating system or browser, unique device identifiers, browser settings, date and time you visited or used our Services, the referring website, URL parameters, and error and crash reporting data.
* *Information from Cookies and Similar Technologies:* A cookie is a small piece of information that is downloaded to your device by your browser when you visit a website. We use cookies or similar technologies (including third-party cookies) to remember your preferences, understand how you interact with our Services or emails that we send you, maintain the security of our Services, and administer, improve and promote our Services. You can configure your browser to prevent cookies, but please note that disabling cookies may make some features or functionality unavailable to you.&#x20;

Information We Receive from Third Parties:

* *Third-Party Integrations:* Third parties may create integrations built on Screendesk technology so that their applications can interoperate with Screendesk. If you choose to enable an integration, the third-party may share some information about you with us to make your experience more seamless, such as your name, email, or other content or information needed to facilitate the integration. Additionally, if you sign up or login to our Services using one of our single-sign-on providers (e.g., Google, Apple, etc.), we collect authentication information provided to us by the provider to allow you to log in.
* *Marketing Information:* We may receive marketing or demographic information about you from third parties or partners, for example, data about your organization or industry or other public information from sources like social media or online professional profiles. We may combine this information with other data we already have to improve your experience with our Services or inform you of Services we think may be of interest to you.

### **How We Use Your Information**

We use your information in the following ways:

* To provide and maintain our Services.
* To analyze and improve our Services.
* To keep our Services secure and protect against fraud, abuse, and intrusion.
* To provide user support, information, and services requested by you.
* To send important account or security notifications.
* To promote our Services in accordance with applicable laws and regulations. If you’d like to unsubscribe from our marketing emails, click the “unsubscribe” link at the bottom of the email. You can also update your notification preferences in your account settings.
* To comply with our legal obligations, including responding to a court order or other valid legal process.
* For other purposes with your consent.

Please keep in mind that customers control their accounts and associated Customer Data. We use Customer Data according to our customers’ instructions and our Terms of Service. Customers are able to: (1) restrict, remove, disclose, and access content and information associated with the accounts in their Workspaces; (2) grant, deny, or limit access to those accounts and Workspaces; and (3) configure the privacy settings for those accounts and Workspaces. If you create a Screendesk account with your work email and you aren’t already part of your company’s Workspace, your company may have the ability to add your account (including the content in it) to its Workspace. We’ll give you notice before that happens.If information is aggregated or de-identified so that it can no longer be reasonably associated with an identifiable person, we may use it for any lawful purpose.

### **How We Share Your Information**

We share information outside of Screendesk only as described below:

* *Trusted Third Parties:* We disclose information to our service providers or other third-parties so they can help us provide our Services and run our business. Examples include for storing Customer Data, payment processing, providing customer service, and helping us with our marketing activities. We’ll only disclose the information necessary for these parties to perform their services for us, and they’ll be bound by contractual obligations to protect your personal information.
* *Other Users*: When you collaborate with others, we display your basic account or profile information for context. For example, if you share a Screendesk recording with another user, we’ll let them know that it was you who shared it. Also, when users interact with a video or other content on our Services, we make certain usage information visible to the video owner and viewers, such as who viewed a video (if the viewer is logged in at the time of viewing) or how many times a video was viewed.
* *Administrators:* If you join a Workspace owned by another person or entity, the administrator of that Workspace has the right to access the content in it. Customers and their authorized users may choose to share and disclose information according to their own policies. Also, if you sign up for Screendesk with an email domain that is owned or managed by your employer or organization, we may share the fact that you have an account with us and some basic account information with your employer or organization.
* *Change in Business Structure:* If Screendesk is involved in a merger, acquisition, public offering, asset sale, insolvency, bankruptcy, or similar change in our business structure, we may need to disclose your information to those involved in the transaction, subject to confidentiality requirements.
* *For Legal Reasons*: We may release your information if we believe it is necessary to comply with the law, regulation, valid legal process, an enforceable government request, to prevent fraud or a security breach, enforce our policies or agreements, or protect our or others’ rights, property, or safety.
* *With Your Consent:* We’ll otherwise share your information only with your consent.For example, if you choose to enable a third-party integration, we may share account information and/or content from your account, but only as authorized by you when you enable or use the integration.

### **How We Protect Your Information**

We are committed to protecting your information from unauthorized access, use, disclosure, and loss. We use industry-standard security practices to keep your information secure, such as encryption, access controls, physical security measures, and internal reviews of data collection, use, and storage. However, data transmissions over the internet cannot be guaranteed to be 100% secure or safe from intrusion by others. Be sure to use secure internet connections, protect your login credentials, and create strong passwords for your account. Learn more about our security and compliance efforts on our [Security](https://screendesk.io/security) page.

### **Data Retention**

We’ll retain information you store on our Services for as long as your account exists or as long as we need it to provide you Services. If you delete your account or your content from Screendesk, we’ll permanently delete your account or content within 30 days, unless we need to retain any information to comply with our legal obligations, resolve disputes, or enforce our agreements. For any other information we may receive or collect from you, we’ll retain that information for only as long as is necessary for the purposes described in this Privacy Policy.

### **Data Transfers**

To provide our Services, we transmit, process, and store data in the United States and other locations around the world. For example, if you access our Services from a foreign country, data may be stored locally on the device you use to access the Services.We perform data transfers in accordance with applicable data protection law, using the following safeguards:

* *Standard Contractual Clauses:* Where required, we use standard contractual clauses to meet the data transfer requirements for processing personal data that is subject to the data protection laws of the European Economic Area (EEA), Switzerland, and UK and for other international transfers of Customer Data to the extent required by applicable law. Our Data Processing Addendum incorporates the standard contractual clauses.
* *Other Valid Transfers:* We will otherwise only transfer personal data to a country that the European Commission or UK authorities have determined provides an adequate level of protection for personal data or pursuant to another legally valid personal data transfer mechanism.
* *Privacy Shield:* While Screendesk remains self-certified under the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks and is committed to applying the Privacy Shield Principles to personal data received from the EU or Switzerland, we do not rely on those frameworks as a legal basis for personal data transfers. With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, Screendesk is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission. We are responsible for personal data we receive under the Privacy Shield, including onward transfers to third party agents acting on our behalf. Screendesk commits to cooperate with EU data protection authorities and comply with the advice given by those authorities with regard to human resources data transferred from the EU in the context of the employment relationship. Please send any questions or complaints regarding our Privacy Shield compliance to <privacy@Screendesk.com> or for unresolved complaints you may invoke binding arbitration, at no cost to you, from [JAMS](https://www.jamsadr.com/file-an-eu-us-privacy-shield-claim), which is an independent dispute resolution body in the United States. Competent EU and Swiss data protection authorities (or a panel established by those authorities) may also address complaints and provide appropriate recourse free of charge with respect to our Privacy Shield compliance. You can view Screendesk’s Privacy Shield certification on the [Privacy Shield website](https://www.privacyshield.gov/list).

### **Your Rights**

When it comes to your personal information, you have the right to (subject to certain exemptions by law):

* Access your personal information.
* Delete your personal information.
* Correct or update your personal information.
* Transmit your personal information elsewhere.
* Object to or restrict the processing of your personal information.

You can exercise most of these rights through your Screendesk account. For example, if you wish to delete your personal information from Screendesk, you may permanently delete your account. You can also access and update your account information via your account settings page. If you are unable to exercise your rights through your Screendesk account, please contact the administrator of your Workspace, or otherwise you can [send us your request](mailto:support@screendesk.io).

### **Age Requirement**

If you are under 13 years old (or the age of digital consent in your country), you may not sign up for Screendesk, and please do not send any personal information about yourself to Screendesk. If you believe that someone under 13 or the applicable age of digital consent has provided us with personal information in violation of this Privacy Policy, please [contact us](mailto:support@screendesk.io), and we will take steps to delete the information.

### **For EEA, Switzerland, and UK Data Subjects**

In general, Screendesk is a processor of Customer Data. This means that we process Customer Data only according to our customers’ instructions in accordance with our Terms of Service. For a list of our subprocessors, please visit our [Privacy for Humans](https://privacy.screendesk.io/privacy-for-humans) page. Screendesk acts as a controller for other types of personal data where Screendesk determines the purposes and means of processing of that data, such as personal data used for marketing or research purposes.Where Screendesk acts as a controller of personal data, our lawful bases for processing include:

* Our legitimate interests (for example, to send you information about new features or upcoming product launches). You have the right to object to our use of your personal data for direct marketing at any time.
* As needed to comply with our contractual obligations (for example, if you sign up for a contest or promotion, we’ll process your personal data as needed for us to perform our obligations under the contest or promotion terms).
* To comply with legal obligations (for example, to respond to a law enforcement request or enforce or defend our legal rights).
* With your consent (for example, if you opt into receiving email marketing from us). You have the right to withdraw your consent at any time.

You may [email us](mailto:support@screendesk.io) or contact if you have questions or issues relating to your personal data:

### **For California Residents**

The California Consumer Privacy Act (CCPA) grants additional privacy rights to California consumers, such as the right to:

* Request to know about the categories or specific pieces of their personal information we collect, use, and disclose (including why we collect the information, where we get it from, and who we share it with).
* Request to delete their personal information.
* Not receive discriminatory treatment for exercise of their CCPA privacy rights.

If you [send us a request](mailto:support@screendesk.io), we will first validate your request by verifying your identity using your account information or other form of valid identification. An authorized agent may also make a request on a consumer’s behalf. Please note that, if you use Screendesk as an employee or agent of a business, we may not be required to grant your request to access/know or delete personal information, and we may ask that you contact your account administrator.CCPA also requires specific disclosures for California consumers:

* We explain the categories of personal information we have collected in the preceding 12 months and sources of that information above under “Information We Collect.”
* We explain the business or commercial purposes for collecting personal information above under “How We Use Your Information.”
* We explain the categories of personal information that we have disclosed to third parties in the preceding 12 months above under “How We Share Your Information.”

We do not sell personal information.

### **Updates to this Privacy Policy**

We may update this Privacy Policy by posting the updates to our website. If an update materially impacts your rights or how we use your personal information, we will notify you either by email or other direct communication at least 30 days before the updates take effect. Any other revisions will become effective on the date the updates are posted by Screendesk.

### **Questions?**

Email us questions at <support@screendesk.io>.


# Privacy for Humans

At Screendesk, our users’ privacy is at the core of our decision making. We provide a service that changes the way we work and allows us to be more expressive and informative in our daily work communication. Sensitive information may pass through our systems, and we don’t take that lightly.We have created this page to show you how our systems use your data. For more information about how we use personal data, please view our [Privacy Policy](https://privacy.screendesk.io/).

### **Where does my data go within Screendesk?**

#### **Text-based Data**

Your text-based data is comprised of things like your name, notifications, password, linked accounts like Google and Slack, video names, comments, transcripts, and so on. The majority of this data is stored on an encrypted database at *both* rest and in-transit within AWS.

#### **Image and Video Data**

This includes your avatars, videos and thumbnails. These files are stored on our encrypted S3 buckets, which can only be accessed by certain robots and engineers within our organization who have special access.

### **Where does my data go outside of Screendesk?**

We only send data to trusted third-party systems that are subject to strict privacy and security controls. We think it’s important you understand not only what these systems are but also why we send your data to these systems. If you don’t agree with or understand our reasoning, please email us at <support@screendesk.io>. If you do not agree with your data going to a specific system, deleting your Screendesk account will permanently delete all of your data from all our systems. If you participate in a Screendesk paid account, only the Screendesk account administrator at your organization can delete your data. For folks coming to figure out GDPR compliance, the following third-party services act as data processors for us. When we work with these service providers in our capacity as a data processor for our customers' personal data, the General Data Protection Regulation (GDPR) calls these third-party service providers a sub-processor. A subprocessor is a third party data processor engaged by Screendesk who may have access to or process personal data: (i) on behalf of Screendesk customers; (ii) in accordance with customer instructions as communicated by Screendesk; and (iii) in accordance with the terms of a written contract between Screendesk and the subprocessor.

#### **📞 Whereby**

Location: United States

Nature of Processing: Video API platform

What: Provides the infrastructure to power our Instant Meet feature.

Why: Our core competency at Screendesk is ensuring async and sync support communication happens more effectively. Whereby is the easiest way to add video chat to our platform.&#x20;

#### **💭 Intercom**

Location: United States

Nature of Processing: Customer support service

What: [Intercom](https://docs.intercom.com/pricing-privacy-and-terms/data-protection/how-were-preparing-for-gdpr) is a messaging and marketing platform that allows us to do customer success better. This is where you’re able to chat with us from that little bubble in the bottom-right of our web pages.

Why: Intercom has drastically increased our ability to address bugs and handle requests from our users (that’s you!) over when we used to primarily use email. As a part of being able to maintain your relationship with us on this platform, we have to know who you are. We only know this once you’ve created an account, but we use this information for various debugging purposes and to send you product updates and announcements.

#### **📈 Amplitude**

Location: United States

Nature of Processing: User analytics service

What: [Amplitude](https://amplitude.com/blog/2018/01/18/amplitudes-commitment-privacy-gdpr/) is our main analytics platform. It allows us to track whether a feature or product is successful in delivering impact to our users, and it lets us discover new (anonymized) trends of usage via conversion funnels, event segmentation, data pathways, retention charts, and cohort analysis.

Why: If we are going to be a platform that delivers immense value to our users, we have to constantly be innovating.&#x20;

#### **☎️ Help Scout**

Location: United States

Nature of Processing: Customer support service

What: Help Scout is our customer support ticketing system. It allows us to help track, prioritize, and solve customer support interactions.

Why: Help Scout has helped us nurture customer relationships with personalized, responsive support. It also allows us to have tool which centralizes customer support request and inquiries to ensure our customers receive the best response.

#### **📊 Google Analytics**

Location: United States

Nature of Processing: Data analytics service

What: [Google Analytics](https://blog.littledata.io/2017/10/19/is-google-analytics-compliant-with-gdpr/) is an analytics platform that more uniquely gives us certain nice-to-have "vanity" analytics and serves as a good place for understanding where on the web our users are coming from.

Why: It’s good to know where our users are finding us so we can promote our product more with those partners and channels or figure out whether there are tangential products that should be introduced to our platform.

#### **🐦 Honeybadger**

Location: United States

Nature of Processing: Error logging service

What: Honeybadger is used as our error logging platform. When you get an error, we get it too so we can better fix these bugs as soon as possible.

Why: No one likes bugs! Data sent to Honeybadger includes IP address and your Screendesk ID and no other personal information. We grab your IP to get a general location the error is happening in and potentially pin-down bugs that have to do with timezones. We send your user ID so we can more quickly search and diagnose issues surfaced by our users in our customer support panel (Help Scout). Your user ID does not reveal any other personal information to the engineer investigating the issue.

#### 🔐 WorkOs

Location: United States

Nature of Processing: authentication and authorization process for our SaaS application and ensure that only authorized users have access to our product. (Enterprise customers only).&#x20;

Why: This helps us meet compliance requirements, reduce the risk of security breaches, and provide a seamless user experience for our enterprise customers. Additionally, WorkOS allows us to centralize the management of user identities and permissions, simplifying the process of onboarding and offboarding users. By relying on WorkOS for identity management, we can focus on delivering value to our customers while leaving the complex identity management tasks to the experts.

### **Who has access to what within Screendesk?**

Our non-technical team members have access to Intercom, which allows every person at Screendesk to be able to do customer support. Over time, this will become more restricted as we scale up the team to only be customer support individuals. Our technical team *can be granted temporary access* to our servers, video and thumbnail storage layers. This is only for debugging or development purposes. Each engineer has a unique key that identifies them within our systems. All actions are logged for 6 years. If their key is compromised, we have an instantaneous way of expiring that key, checking if their key was used by an outsider, and processes to remedy such situations and alert the affected user base. So far, this has never happened in Screendesk's history, and we’re very proud of that.

### **How can I export my data?**

Videos: You can export all of your video data by downloading each individual video. Text-based Data: Your user information, folders and video metadata can be exported by emailing us. If you ever want to delete your data, deleting your account will permanently delete all of your data off our systems.

### **Useful Vocabulary**

#### **🔒 Encrypted**

Encryption is a process where data is scrambled with a specific secret that only a select few have. If this data is stolen, it cannot be understood unless the stealer has the proper secret. All of your personally-identifiable data (videos, images and text) are encrypted at-rest and in-transit across all systems.

#### **🏃 In-transit**

Your data is being sent from one location to another (usually one server/computer to another)

#### **🛌🏾 At-rest**

Your data is physically being stored on a device (usually a server)

#### **🕳️ S3 Bucket**

This is where we store larger (usually media) files such as images and videos

#### **🤝 Database**

This is a server that stores data that relates to one another. In other words, this is where we can query to answer questions like: "what is a user?", "does a user own one or many videos?"

#### **🤖 AWS**

Short for Amazon Web Services. This is the cloud provider we use at Screendesk that allows us to rent storage and compute capacity from their data centers. If you have any questions about privacy at Screendesk, we are here to help. Email us at <support@screendesk.io>.


# Data Processing Addendum

This Data Processing Addendum (“DPA”) supplements and is incorporated into Screendesk's Terms of Service or other agreement between Customer and Screendesk governing Customer’s use of and access to the Services (“Agreement”). Capitalized terms used below that are not otherwise defined have the meanings given to them in the Agreement.

### **1. Scope**

1.1 Scope of DPA. This DPA applies to Screendesk’s processing of Personal Data to provide the Services to Customer pursuant to the Agreement.

1.2 Processor. The parties agree that Screendesk acts as a processor under Data Protection Law and/or service provider under CCPA for Customer in providing the Services to Customer.

1.3 Processing Activities. The subject matter and duration of the processing, the nature and purpose of the processing, the type of Personal Data, and categories of data subjects are described in Exhibit A.

### **2. Processing of Personal Data**

2.1 Screendesk Obligations. Screendesk will:

(a) process Personal Data only on documented instructions from Customer, including transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law to which Screendesk is subject, in which a case Screendesk will inform Customer of the legal requirement before processing, unless prohibited by law;

(b) ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

(c) implement appropriate technical and organizational measures, including Screendesk's Security Measures, designed to protect Personal Data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored or otherwise processed and to ensure a level of security appropriate to the risk;

(d) respect the conditions for engaging other processors as required by applicable Data Protection Law and set forth in Section 4 below;

(e) taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, to the extent possible, to enable Customer to fulfill its legal obligations as a controller to respond to requests for exercising data subject rights pursuant to applicable Data Protection Law;

(f) taking into account the nature of processing and the information available to Screendesk, assist Customer in ensuring compliance with its legal obligations pursuant to applicable Data Protection Law regarding (i) security of processing, (ii) notification of and communication of Security Incidents, (iii) data protection impact assessments, and (iv) prior consultation with the applicable supervisory authority;

(g) at Customer’s choice, delete or return all Personal Data to Customer after the end of the provision of the Services, and delete existing copies unless applicable law requires storage of Personal Data;

(h) make available to Customer all information necessary to demonstrate compliance with its obligations under applicable Data Protection Law and allow for and assist with audits in accordance with Section 6 below, in each case at Customer’s expense; and(i) inform Customer if, in its opinion, an instruction infringes applicable Data Protection Law.

2.2 Customer Instructions. Customer instructs Screendesk to process Personal Data as documented in this DPA and the Agreement, and as otherwise necessary to provide the Services to Customer. Customer’s instructions to Screendesk for the processing of Personal Data will comply with all applicable laws, including Data Protection Laws.

2.3 Controller Authorization. If Customer is a processor, Customer warrants to Screendesk that Customer’s instructions and actions with respect to Personal Data, including its appointment of Screendesk as a subprocessor, have been authorized by the relevant controller.

### **3. Data Transfers**

3.1 Customer Authorization. Customer authorizes Screendesk to perform Data Transfers:&#x20;

(a) to any country subject to an adequacy determination by the European Commission;&#x20;

(b) pursuant to the Standard Contractual Clauses; or&#x20;

(c) any other legally valid data transfer mechanism. The Standard Contractual Clauses will only apply for Data Transfers to a country not recognized as having an adequate level of data protection if there is no other legally valid data transfer mechanism.

3.2 Standard Contractual Clauses. For Data Transfers out of the European Economic Area, Switzerland, or the United Kingdom pursuant to the Standard Contractual Clauses:&#x20;

(a) the Controller-to-Processor Clauses will apply where Customer acts as a controller of Personal Data; and&#x20;

(b) the Processor-to-Processor Clauses will apply where Customer acts as a processor of Personal Data, and Customer will fulfill any obligations Screendesk may have to Customer’s controller(s) as a processor.

### **4. Subprocessors**

4.1 General Authorization. Customer hereby grants Screendesk general authorization to engage Subprocessors, subject to the terms of this DPA and the Agreement. Screendesk uses the Subprocessors listed at [privacy.screendesk.io](https://privacy.screendesk.io) to provide the Services and will notify Customer of any intended changes concerning the addition or replacement of a Subprocessor via the mechanism listed on that page. If Customer provides a reasonable written objection to a new Subprocessor within 10 days of receiving notice, and Screendesk chooses not to suggest an alternative, Customer may terminate the Agreement after 30 days’ notice to Screendesk.

4.2 Subprocessor Requirements. Prior to the engagement of a Subprocessor, Screendesk will enter into a written agreement with the Subprocessor containing at least the same data protection obligations as those set out in this DPA, including providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of applicable Data Protection Law. If a Subprocessor fails to fulfill its data protection obligations, Screendesk will be liable to Customer for the performance of that Subprocessor’s obligations.

### **5. Security Incidents**

5.1 Security Incident Notification. Upon becoming aware of a Security Incident, Screendesk will notify Customer without undue delay and promptly take reasonable steps to minimize harm and secure Personal Data.

5.2 Notification Description. To the extent possible, notification to Customer will describe the nature of the Security Incident, the likely consequences of the Security Incident, and the measures taken or proposed to be taken to address the Security Incident. Screendesk’s notification of or response to a Security Incident will not be construed as an acknowledgement by Screendesk of any fault or liability with respect to the incident.

### **6. Audits**

6.1 Customer Audit. Upon Customer’s prior written request and subject to the confidentiality obligations, Screendesk will allow Customer or an independent third-party auditor that is not a competitor of Screendesk to access information or inspect Screendesk’s procedures relevant to the protection of Customer Data in order to audit Screendesk’s compliance with this DPA.

6.2 Process for Inspections. Inspections may be conducted no more than once per year and only in a manner that does not interfere with Screendesk’s normal business operations. Customer and Screendesk will mutually agree upon the scope, timing, and duration of the inspection, and Customer will reimburse Screendesk for reasonable fees associated with time spent on the inspection. Any deficiencies or reports created based on such access or inspection must be promptly shared with Screendesk and will be Screendesk’s Confidential Information.

### **7. CCPA Certification**

Screendesk will not:

(a) sell Customer personal information;

(b) retain, use, or disclose any Customer personal information for any purpose other than for the specific purpose of providing the Services, including retaining, using, or disclosing Customer personal information for a commercial purpose other than providing the Service; or

(c) retain, use, or disclose Customer personal information outside of the direct business relationship between Customer and Screendesk.

### **8. General**

This DPA is subject to the terms of the Agreement, including without limitation, those regarding dispute resolution, limitation of liability, and termination. If any of the provisions of this DPA conflict with the provisions of the Agreement, the provisions of this DPA will prevail.

### **9. Definitions**

“CCPA” means the California Consumer Privacy Act of 2018 and any legislation or regulation that amends, replaces, or re-enacts it.“Controller-to-Processor Clauses” means the standard contractual clauses between controllers and processors approved by the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

“Data Protection Law” means&#x20;

(a) the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data effective 25 May 2018 (the General Data Protection Regulation) and any legislation or regulation that amends, replaces, or re-enacts it; and&#x20;

(b) any other applicable data protection law or regulation of the European Union or the European Economic Area and their member states, Switzerland, and the United Kingdom.

“Data Transfer” means any transfer or onward transfer of Customer Personal Data out of the European Economic Area, Switzerland, or the United Kingdom to another country.“Personal Data” means personal data contained in Customer Data that is subject to applicable Data Protection Law or the CCPA.

“Security Incident” means a breach of Screendesk’s Security Measures causing the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by Screendesk;

“Standard Contractual Clauses” means the Controller-to-Processor Clauses or the Processor-to-Processor Clauses, as applicable and as may be updated from time to time to the extent required by Data Protection Law.

“Subprocessor” means a third party engaged by Screendesk to processes Personal Data in order to provide parts of the Services under the Agreement.

The terms “controller”, “processor”, “data subject”, “personal data,” “processing" and “appropriate technical and organizational measures” have the meanings provided in applicable Data Protection Laws.The terms “business”, “commercial purpose”, “service provider”, “sell” and “personal information” have the meanings provided in the CCPA.

### **Exhibit A**

**Subject Matter of Processing**

The subject matter of the processing is the Personal Data submitted to the Services by Customer pursuant to the Agreement.

**Duration of Processing**

The processing will continue until the expiration or termination of the Agreement, or as otherwise determined by Customer by deleting Personal Data from its account.

**Nature and Purpose of Processing**

Processing by Screendesk to provide the Services to Customer pursuant to the Agreement.

**Types of Personal Data**

Personal Data provided to Screendesk by Customer or its Authorized Users, including:

* Name, email address, and other account data;
* Video, audio, transcript data, and comments containing Personal Data;
* Transaction logs for transactions conducted by users using the Service;
* Information about the hardware and software used to access the Service;
* Information and analytics about use of the Service;
* Employee authentication information, such as user ID and department information;
* Other Personal Data uploaded or submitted by Customer or Authorized Users to the Services.

**Categories of Data Subjects**

Employees and other Authorized Users of Customer and any other individual whose Personal Data is uploaded or submitted by Customer or Authorized Users to the Services.


# Terms of Service

{% hint style="info" %}
Last updated: July 18, 2022
{% endhint %}

When we say “Company”, “we”, “our”, or “us” in this document, we are referring to Screendesk.

When we say “Services”, we mean any product created and maintained by Screendesk.

When we say “You” or “your”, we are referring to the people or organizations that own an account with one or more of our Services. We have specific ownership policies for our products: Screendesk.

We may update these Terms of Service in the future. These changes have been to clarify some of these terms by linking to an expanded related policy. Whenever we make a significant change to our policies, we will refresh the date at the top of this page and take any other appropriate steps to notify account holders.

When you use our Services, now or in the future, you are agreeing to the latest Terms of Service. That’s true for any of our existing and future products and all features that we add to our Services over time. There may be times where we do not exercise or enforce any right or provision of the Terms of Service; in doing so, we are not waiving that right or provision. These terms do contain a limitation of our liability.

If you violate any of the terms, we may terminate your account. That’s a broad statement and it means you need to place a lot of trust in us.

### Account Terms

1. You are responsible for maintaining the security of your account and password. The Company cannot and will not be liable for any loss or damage from your failure to comply with this security obligation. We recommend users set up two-factor authentication for added security. In some of our Services, we may require it.
2. You may not use the Services for any purpose outlined in our [Use Restrictions policy.](https://privacy.screendesk.io/use-restrictions)
3. You are responsible for all content posted and activity that occurs under your account. That includes content posted by others who either: (a) have access to your login credentials; or (b) have their own logins under your account.
4. You must be a human. Accounts registered by “bots” or other automated methods are not permitted.

### Payment, Refunds, and Plan Changes

1. If you are using a free version of one of our Services, it is really free: we do not ask you for your credit card and — just like for customers who pay for our Services — we do not sell your data.
2. For paid Services that offer a free trial, we explain the length of trial when you sign up. After the trial period, you need to pay in advance to keep using the Service. If you do not pay, we will freeze your account and it will be inaccessible until you make payment. If your account has been frozen for a while, we will queue it up for auto-cancellation.
3. If you are upgrading from a free plan to a paid plan, we will charge your card immediately and your billing cycle starts on the day of upgrade. For other upgrades or downgrades in plan level, the new rate starts from the next billing cycle.
4. All fees are exclusive of all taxes, levies, or duties imposed by taxing authorities. Where required, we will collect those taxes on behalf of the taxing authority and remit those taxes to taxing authorities. Otherwise, you are responsible for payment of all taxes, levies, or duties.
5. We process refunds according to our Fair Refund policy.

### Cancellation and Termination

1. You are solely responsible for properly canceling your account. Within each of our Services, we provide a simple no-questions-asked cancellation link. You can find instructions for how to cancel your account in our Cancellation policy. An email or phone request to cancel your account is not automatically considered cancellation. If you need help cancelling your account, you can always [contact our Support team](mailto:support@screendesk.io).
2. All of your content will be inaccessible from the Services immediately upon account cancellation. Within 30 days, all content will be permanently deleted from active systems and logs. Within 60 days, all content will be permanently deleted from our backups. We cannot recover this information once it has been permanently deleted. If you want to export any data before your account is cancelled, [we‘ve provided instructions to do so](https://privacy.screendesk.io/privacy-for-humans#how-can-i-export-my-data).
3. If you cancel the Service before the end of your current paid up month, your cancellation will take effect immediately, and you will not be charged again. We do not automatically prorate unused time in the last billing cycle.&#x20;
4. We have the right to suspend or terminate your account and refuse any and all current or future use of our Services for any reason at any time. Suspension means you and any other users on your account will not be able to access the account or any content in the account. Termination will furthermore result in the deletion of your account or your access to your account, and the forfeiture and relinquishment of all content in your account. We also reserve the right to refuse the use of the Services to anyone for any reason at any time. We have this clause because statistically speaking, out of the hundreds of thousands of accounts on our Services, there is at least one doing something nefarious. There are some things we staunchly stand against and this clause is how we exercise that stance. For more details, see our[ Use Restrictions policy.](/screendesk-privacy/use-restrictions)
5. Verbal, physical, written or other abuse (including threats of abuse or retribution) of Company employee or officer will result in immediate account termination.

### Modifications to the Service and Prices

1. We make a promise to our customers to support our Services until the end of the Internet. That means when it comes to security, privacy, and customer support, we will continue to maintain any legacy Services. Sometimes it becomes technically impossible to continue a feature or we redesign a part of our Services because we think it could be better or we decide to close new signups of a product. We reserve the right at any time to modify or discontinue, temporarily or permanently, any part of our Services with or without notice.
2. Sometimes we change the pricing structure for our products. When we do that, we tend to exempt existing customers from those changes. However, we may choose to change the prices for existing customers. If we do so, we will give at least 30 days notice and will notify you via the email address on record. We may also post a notice about changes on our websites or the affected Services themselves.

### Uptime, Security, and Privacy

1. Your use of the Services is at your sole risk. We provide these Services on an “as is” and “as available” basis. We do not offer service-level agreements for most of our Services — but do take uptime of our applications seriously. Visit <https://status.screendesk.io/> to see the status of our Services.
2. We reserve the right to temporarily disable your account if your usage significantly exceeds the average usage of other customers of the Services. Of course, we’ll reach out to the account owner before taking any action except in rare cases where the level of use may negatively impact the performance of the Service for other customers.
3. We take many measures to protect and secure your data through backups, redundancies, and encryption. We enforce encryption for data transmission from the public Internet.
4. When you use our Services, you entrust us with your data. We take that trust to heart. You agree that Screendesk may process your data as described in our Privacy Policy and for no other purpose. We as humans can access your data for the following reasons:
   1. To help you with support requests you make. We’ll ask for express consent before accessing your account.
   2. On the rare occasions when an error occurs that stops an automated process partway through. We get automated alerts when such errors occur. When we can fix the issue and restart automated processing without looking at any personal data, we do. In rare cases, we have to look at a minimum amount of personal data to fix the issue. In these rare cases, we aim to fix the root cause as much as possible to avoid the errors from reoccurring.
   3. To safeguard Screendesk. We’ll look at logs and metadata as part of our work to ensure the security of your data and the Services as a whole. If necessary, we may also access accounts as part of an abuse report investigation.
   4. To the extent required by applicable law.
5. We use third party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to run the Services. You can see a list of all subprocessors who handle personal data in our [Privacy Policy](/screendesk-privacy).
6. Under the California Consumer Privacy Act (“CCPA”), Screendesk is a “service provider”, not a “business” or “third party”, with respect to your use of the Services. That means we process any data you share with us only for the purpose you signed up for and as described in these Terms of Service and Privacy Policy. We do not retain, use, disclose, or sell any of that information for any other commercial purposes unless we have your explicit permission. And on the flip-side, you agree to comply with your requirements under the CCPA and not use Screendesk’s Services in a way that violates the regulations.
7. These Service Terms incorporate the Screendesk Data Processing Addendum (“DPA”), when the General Data Protection regulation (“GDPR”) applies to your use of Screendesk Services to process Customer Data as defined in the DPA. The DPA is effective as of September 28, 2021 and replaces and supersedes any previously agreed data processing addendum between you and Screendesk relating to the GDPR. If you prefer to have an executed copy of the Data Processing Addendum, you may sign a copy online. Regardless of whether you execute or not, we protect and secure your data to the high standards set out in the addendum.

### Copyright and Content Ownership

1. All content posted on the Services must comply with U.S. copyright law.&#x20;
2. We claim no intellectual property rights over the material you provide to the Services. All materials uploaded remain yours.
3. We do not pre-screen content, but reserve the right (but not the obligation) in our sole discretion to refuse or remove any content that is available via the Service.
4. The names, look, and feel of the Services are copyright© to the Company. All rights reserved. You may not duplicate, copy, or reuse any portion of the HTML, CSS, JavaScript, or visual design elements without express written permission from the Company. You must request permission to use the Company’s logo or any Service logos for promotional purposes. Please email us requests to use logos at <support@screendesk.io>. We reserve the right to rescind this permission if you violate these Terms of Service.
5. You agree not to reproduce, duplicate, copy, sell, resell or exploit any portion of the Services, use of the Services, or access to the Services without the express written permission by the Company.
6. You must not modify another website so as to falsely imply that it is associated with the Services or the Company.

### Features and Bugs

We design our Services with care, based on our own experience and the experiences of customers who share their time and feedback. However, there is no such thing as a service that pleases everybody. We make no guarantees that our Services will meet your specific requirements or expectations.

We also test all of our features extensively before shipping them. As with any software, our Services inevitably have some bugs. We track the bugs reported to us and work through priority ones, especially any related to security or privacy. Not all reported bugs will get fixed and we don’t guarantee completely error-free Services.

### Services Adaptations and API Terms

We offer Application Program Interfaces (“API”s) for some of our Services. Any use of the API, including through a third-party product that accesses the Services, is bound by the terms of this agreement plus the following specific terms:

1. You expressly understand and agree that we are not liable for any damages or losses resulting from your use of the API or third-party products that access data via the API.
2. Third parties may not access and employ the API if the functionality is part of an application that remotely records, monitors, or reports a Service user’s activity other than time tracking, both inside and outside the applications. The Company, in its sole discretion, will determine if an integration service violates this bylaw. A third party that has built and deployed an integration for the purpose of remote user surveillance will be required to remove that integration.
3. Abuse or excessively frequent requests to the Services via the API may result in the temporary or permanent suspension of your account’s access to the API. The Company, in its sole discretion, will determine abuse or excessive usage of the API. If we need to suspend your account’s access, we will attempt to warn the account owner first. If your API usage could or has caused downtime, we may cut off access without prior notice. Some third-party providers have created integrations between our Services and theirs. We are not liable or accountable for any of these third-party integrations.

### Liability

We mention liability throughout these Terms but to put it all in one section:

You expressly understand and agree that the Company shall not be liable, in law or in equity, to you or to any third party for any direct, indirect, incidental, lost profits, special, consequential, punitive or exemplary damages, including, but not limited to, damages for loss of profits, goodwill, use, data or other intangible losses (even if the Company has been advised of the possibility of such damages), resulting from: (i) the use or the inability to use the Services; (ii) the cost of procurement of substitute goods and services resulting from any goods, data, information or services purchased or obtained or messages received or transactions entered into through or from the Services; (iii) unauthorized access to or alteration of your transmissions or data; (iv) statements or conduct of any third party on the service; (v) or any other matter relating to this Terms of Service or the Services, whether as a breach of contract, tort (including negligence whether active or passive), or any other theory of liability.

In other words: choosing to use our Services does mean you are making a bet on us. If the bet does not work out, that’s on you, not us. We do our darnedest to be as safe a bet as possible through careful management of the business; investments in security, infrastructure, and talent; and in general giving a damn. If you choose to use our Services, thank you for betting on us.

If you have a question about any of the Terms of Service, please <support@screendesk.io>.


# Use Restrictions

{% hint style="info" %}
*Last updated: March 4, 2021*
{% endhint %}

We also recognize that however good the maker’s intentions, technology can amplify the ability to cause great harm. That’s why we’ve established this policy. We feel an ethical obligation to counter such harm: both in terms of dealing with instances where Screendesk is used (and abused) to further such harm, and to state unequivocally that the products we make at Screendesk are not safe havens for people who wish to commit such harm. If you have an account with any of our products, you can’t use them for any of the restricted purposes listed below. If we find out you are, we will take action.

### Restricted purposes

* **Violence, or threats thereof**: If an activity qualifies as violent crime in the United States or where you live, you may not use Screendesk products to plan, perpetrate, or threaten that activity.
* **Child exploitation, sexualization, or abuse**: We don’t tolerate any activities that create, disseminate, or otherwise cause child abuse. Keep away and stop. Just stop.
* **Hate speech**: You cannot use our products to advocate for the extermination, domination, or oppression of people.
* **Harassment**: Intimidating or targeting people or groups through repeated communication, including using racial slurs or dehumanizing language, is not welcome at Screendesk.
* **Doxing**: If you are using Screendesk products to share other peoples’ private personal information for the purposes of harassment, we don’t want anything to do with you.
* **Malware or spyware**: Code for good, not evil. If you are using our products to make or distribute anything that qualifies as malware or spyware — including remote user surveillance — begone.
* **Phishing or otherwise attempting fraud**: It is not okay to lie about who you are or who you affiliate with to steal from, extort, or otherwise harm others.
* **Spamming**: No one wants unsolicited commercial emails. We don’t tolerate folks (including their bots) using Screendesk products for spamming purposes. If your emails don’t pass muster with [CAN-SPAM](https://www.ftc.gov/tips-advice/business-center/guidance/can-spam-act-compliance-guide-business) or any other anti-spam law, it’s not allowed.
* **Cybersquatting**: We don’t like username extortionists. If you purchase a Screendesk product account in someone else’s name and then try to sell that account to them, you are [cybersquatting](https://www.law.cornell.edu/uscode/text/15/1125). Cybersquatting accounts are subject to immediate cancellation.
* **Infringing on intellectual property**: You can’t use Screendesk products to make or disseminate work that uses the intellectual property of others beyond the bounds of [fair use](https://www.copyright.gov/fair-use/more-info.html).

While our use restrictions are comprehensive, they can’t be exhaustive — it’s possible an offense could defy categorization, present for the first time, or illuminate a moral quandary we hadn’t yet considered. That said, we hope the overarching spirit is clear: Screendesk is not to be harnessed for harm, whether mental, physical, personal or civic. Different points of view — philosophical, religious, and political — are welcome, but ideologies like white nationalism, or hate-fueled movements anchored by oppression, violence, abuse, extermination, or domination of one group over another, will not be accepted here.

### How to report abuse

For cases of suspected malware, spyware, phishing, spamming, and cybersquatting, please alert us at <support@screendesk.io>.

For all other cases, please let us know by emailing <support@screendesk.io>. If you’re not 100% sure if something rises to the level of our use restrictions policy, report it anyway.

Please share as much as you are comfortable with about the account, the content or behavior you are reporting, and how you found it. Sending us a URL or screenshots is super helpful. If you need a secure file transfer, let us know and we will send you a link. We will not disclose your identity to anyone associated with the reported account.&#x20;

Someone on our team will respond within one business day to let you know we’ve begun investigating.

\**This policy and process applies to any product created and owned by Screendesk.*


