Privacy Policy
This policy explains what personal data RDP Protector collects, why, on what legal basis, who we share it with and how long we keep it. It covers the website, the control panel and the Windows agent.
1. Who is responsible
The controller is File Master LLC, Serena app., office C13, Golden Sands, Varna 9007, Bulgaria, VAT 180842207. Because we are established in the EU, the General Data Protection Regulation (GDPR) applies to our processing.
For data about your own end users that may reach us through your use of the service, you are the controller and we act as processor — see the Data Processing Addendum.
2. Account and organisation data
When you create an account we store:
- your email address;
- a hash of your password (never the password itself), using a modern slow hashing algorithm;
- your multi-factor authentication secret, if you enable MFA;
- your interface language;
- the organisations you belong to, their names, and your role in each;
- an audit log of administrative actions in your organisation: who did what, to which object, with what parameters, and when.
If you sign in with Google or GitHub, we receive your email address and the provider's user identifier from that provider. We do not receive your password there, and we do not post anything on your behalf.
3. Data your servers report
Each installed agent reports, about the machine it runs on:
- hostname, and any display name you set;
- operating system version and CPU architecture;
- the server's public IP address;
- which ports the protected services (RDP, FTP, MS SQL) are listening on;
- agent version and configuration hash;
- a machine fingerprint, used to detect an agent key being reused on a different host;
- last-seen timestamp and health status.
Where your servers are individual people's machines rather than infrastructure, this data can be personal data. It is processed to deliver the service you asked for.
4. Attack data and third-party IP addresses
The agent reads the host's own Windows Security event log for failed authentication events and reports, for each banned source:
- the source IP address or the subnet (CIDR) it belongs to;
- the autonomous system number and operator name for that network;
- the country the address is registered to, on a best-effort basis;
- which service was targeted (RDP, FTP, MS SQL);
- timestamps and the number of attempts.
Under the GDPR, an IP address can be personal data even when it belongs to someone attacking a server. We process it on the basis of legitimate interest in network and information security — the interest that Recital 49 of the GDPR describes explicitly. We have assessed that the interest in preventing unauthorised access to our customers' servers outweighs the limited privacy impact on the source of that traffic, and we minimise what is collected: no payloads, no attempted usernames beyond what is needed for detection, and no content of any kind.
To resolve an address to its network and country we use ipinfo.io. Results are cached so the same address is not looked up repeatedly.
5. Shared threat intelligence
On paid plans, addresses and subnets that attacked one customer can be blocked pre-emptively for other customers. What is shared across the customer base is the attacking network's address, its network metadata, the targeted service and timing — never the identity of the customer that was attacked, never their server names or addresses, and never any content.
You cannot opt out of contributing attack metadata while using a plan that includes shared reputation, because the feature is reciprocal by design. You can use the Free plan, which relies on local detection only.
6. Billing data
We do not receive or store payment card numbers. Payments are processed by PayPro Global (international), YooKassa (Russian Federation) or a cryptocurrency channel. From them we receive confirmation of payment, the subscription state, and the billing identifiers needed to reconcile an account.
Where a provider acts as merchant of record, it is an independent controller for the payment data it collects from you, under its own privacy policy.
7. Website, cookies and analytics
Strictly necessary cookies
- a refresh-token cookie, set after sign-in, which keeps you signed in. It is HTTP-only, restricted to the authentication path, and cleared when you sign out;
- a short-lived OAuth nonce cookie during a Google or GitHub sign-in, used to prevent request forgery, and deleted immediately afterwards.
These are required for the service to function and are set on the basis of legitimate interest.
Analytics
The public marketing pages load Google Analytics 4 (measurement ID G-RJYLKQ92ZQ) to understand which pages are read and how visitors arrive. This is used for aggregate statistics, not to identify you. Google Analytics sets its own cookies and processes data under Google's terms; you can prevent it entirely with any standard browser tracking protection or ad blocker, and the site works fully without it.
We do not use advertising cookies, cross-site tracking pixels, or third-party marketing tags.
8. Support correspondence
When you open a support ticket or email us, we store the message, your email address and the thread history, so that we can answer and so that a later question can be understood in context.
If you enable Telegram alerts, we send notification messages to the Telegram chat you nominate through Telegram's Bot API. Those messages contain the alert content — for example, a banned address and the server it was banned on. Telegram processes them under its own policy.
9. What we do not collect
The agent reads its own host's security event log and writes firewall rules. It does not read your files, your databases, your application data, your users' documents, your keystrokes or your screen. It has no remote-execution capability, does not scan other machines, and opens no inbound connection of its own — it communicates outbound over HTTPS only.
We do not sell personal data, we do not share it for advertising, and we do not perform automated decision-making that produces legal effects for you.
10. Legal bases
| Processing | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the panel and the agent to you | Performance of a contract, Art. 6(1)(b) |
| Billing and accounting records | Contract, and legal obligation Art. 6(1)(c) |
| Detecting and blocking attacks; shared threat intelligence | Legitimate interest, Art. 6(1)(f) — network and information security |
| Security and audit logging | Legitimate interest, Art. 6(1)(f) |
| Transactional email (security, billing, account notices) | Performance of a contract, Art. 6(1)(b) |
| Website analytics | Consent where required by local law, otherwise legitimate interest |
| Support correspondence | Performance of a contract, Art. 6(1)(b) |
11. Sub-processors and recipients
| Recipient | Purpose | Data involved |
|---|---|---|
| PayPro Global | International payment processing | Billing details you give them; we receive only subscription state |
| YooKassa | Payment processing in the Russian Federation | As above |
| Google (OAuth) | Optional "sign in with Google" | Email address, provider user ID |
| GitHub (OAuth) | Optional "sign in with GitHub" | Email address, provider user ID |
| Google Analytics | Aggregate website statistics | Usage events, IP address (as processed by Google) |
| ipinfo.io | Resolving an IP to its network, operator and country | The attacking IP address only |
| Telegram | Optional alert delivery | Alert content, your chat identifier |
| Email delivery provider (SMTP) | Transactional email | Your email address, message content |
| Hosting provider | Running the panel and databases | All service data, at rest and in transit |
We may also disclose data where legally required, or where necessary to establish, exercise or defend legal claims. We will tell you unless legally prohibited.
We give at least 30 days' notice by email before adding a new sub-processor that handles customer personal data. Business customers may object under the DPA.
12. International transfers
Service data is hosted in the European Union. Some sub-processors listed above are established outside the EEA. Where that involves a transfer of personal data, it is made under an adequacy decision where one applies, or otherwise under the European Commission's Standard Contractual Clauses together with supplementary measures where required.
13. Retention
| Data | Kept for |
|---|---|
| Attack history visible in the panel | Set by your plan: 24 hours (Free), 90 days (Solo), 365 days (Pro and Enterprise) |
| Account, organisation and server records | Until you delete the account |
| Administrative audit log | Retained with the organisation, deleted with it |
| Shared threat-intelligence records | While the address remains operationally relevant; entries age out as they stop being observed |
| Support correspondence | 3 years after the ticket is closed |
| Invoices and accounting records | As required by Bulgarian tax law, currently 10 years |
| Website analytics | As configured in Google Analytics, currently 14 months |
When you delete your account, account and organisation data is erased. Threat-intelligence records about attacking networks are not tied to your identity and remain in the database; accounting records are retained where the law requires.
14. Security
- All traffic between the agent, your browser and the panel is encrypted with TLS.
- Passwords are stored only as slow hashes; we cannot recover them.
- Agent credentials are stored hashed and can be revoked centrally at any time.
- The panel supports multi-factor authentication, and we recommend enabling it.
- Access to production systems is restricted to personnel who need it.
- Administrative actions are recorded in an append-only audit log.
If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Bulgarian supervisory authority within 72 hours and inform you without undue delay where the regulation requires it.
15. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- have inaccurate data corrected;
- have your data erased, where no legal obligation requires us to keep it;
- restrict or object to processing carried out on the basis of legitimate interest;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, where processing is based on consent.
Write to tech.support@recoverytoolbox.com. We answer within one month. You may also complain to the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни, cpdp.bg), or to the supervisory authority where you live.
If you are the source of a blocked address and believe it was blocked in error, write to the same address with the IP or subnet. We will review the observations behind the entry and remove it if it is not justified.
16. Changes
We may update this policy. Material changes are announced by email to account holders at least 30 days in advance, and the version and effective date at the top of this page are updated.
17. Contact
File Master LLC
Serena app., office C13, Golden Sands, Varna 9007, Bulgaria
VAT: 180842207
Email: tech.support@recoverytoolbox.com
Phone: +359 88 2253194
RDP Protector