LegalNaytto
Data Processing Addendum
This addendum forms part of the Terms of Service between Relyt Works LLC, 1925 Lovett Avenue, STE 7 278, Bismarck, North Dakota 58504, United States ("Naytto", processor) and a customer that uses Naytto for an organization ("Customer", controller). It applies when Naytto processes personal data on the Customer's behalf under the GDPR, the UK GDPR, the Swiss FADP or the CCPA/CPRA.
1. Processing details
- Subject matter and duration: providing Naytto for the term of the agreement, plus the deletion periods in section 7.
- Nature and purpose: account sign-in, adding and managing computers, connecting browser sessions to them, relaying encrypted connections, account activity and usage limits.
- Data subjects: the Customer's users and anyone named in computer names.
- Personal data: as listed in the Privacy Policy: email addresses, IP addresses, browser user agents, computer names and status, activity and usage records. Session content (screen, input, clipboard, files) is encrypted between the browser and the computer and does not pass through Naytto's servers; Naytto does not store it.
- Special category data: none intended. The Customer should not put special category data in computer names.
2. Naytto's obligations
Naytto will:
- Process personal data only on the Customer's documented instructions. These terms and the Customer's use of the product are those instructions. Naytto will tell the Customer if it believes an instruction breaks the law.
- Ensure that anyone authorized to process the data is bound by confidentiality.
- Maintain the security measures in section 5.
- Use subprocessors only as set out in section 6.
- Help the Customer respond to data subject requests. The self-service export and deletion on the Account page are the primary means.
- Help the Customer with security, breach notification, impact assessments and prior consultation, as far as Naytto's processing allows.
- Delete personal data at the end of the service, as set out in section 7.
- Make available the information needed to demonstrate compliance, and allow audits by the Customer or its auditor, at most once a year with 30 days' notice, or by providing independent reports where they exist.
3. CCPA/CPRA
Naytto is a service provider. It will not sell or share personal information, or retain, use or disclose it outside the direct business relationship or for any purpose other than providing the service. It will not combine it with personal information from other sources except as the law permits, and it will tell the Customer if it can no longer meet these obligations.
4. Breach notification
Naytto will notify the Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting the Customer's data. The notice will include what is known about its nature, likely consequences and the measures taken.
5. Security measures
- Passkey-first sign-in, email codes limited in time and attempts, optional TOTP, a strong recent sign-in for sensitive actions, and security notices by email.
- Every record is scoped to one account, with automated cross-account isolation tests. Each computer has its own revocable credential, stored as a hash.
- Traffic is encrypted in transit (TLS). Session media and data are encrypted between the browser and the computer (DTLS-SRTP and DTLS), relayed with per-session credentials that are revoked when the session ends. The service identifies the computer for the browser.
- Access to production is limited to the founder, and changes are deployed through reviewed CI.
- Retention is enforced automatically (see the Privacy Policy). Point-in-time recovery lasts 30 days.
6. Subprocessors
The Customer authorizes the subprocessors listed here. Naytto will give at least 30 days' notice of a new or replacement subprocessor through that page and by email to customers who ask for notice. The Customer may object on reasonable data protection grounds. If the parties cannot resolve the objection, the Customer may end the affected service. Naytto binds each subprocessor to data protection terms at least as protective as this addendum and remains responsible for it.
7. Deletion
When the Customer deletes a user's account or the whole account, Naytto deletes the associated personal data immediately, except as follows. Activity records are kept 90 days after deletion, and abuse reports up to 365 days, to investigate unauthorized access. Service logs expire within 7 days, email delivery records within 31 days and backups within 30 days.
8. International transfers
Naytto processes data in the United States and on Cloudflare's global network. Where a transfer requires it, the parties agree to the EU Standard Contractual Clauses (Module 2, controller to processor), which are incorporated by reference. For UK data they are supplemented by the UK International Data Transfer Addendum, and for Swiss data by the Swiss adaptation. Onward transfers to Cloudflare and Google rely on their data processing terms and their EU-US Data Privacy Framework certifications. Section 1 completes Annex I of the Clauses and section 5 completes Annex II. The competent supervisory authority is the one for the Customer's establishment or representative in the EU. The Clauses are governed by Irish law, and disputes under them go to the courts of Ireland.
Last updated: 2026-09-25.