This article documents what data the Addigy Agent and the Addigy platform collect, who can see it, and how long it is kept. Use it when you need to answer a GDPR data audit question, respond to a data subject request, or review Addigy's role in your data processing chain.
Overview
Under GDPR terminology, Addigy customers are the Data Controllers and Addigy is the Data Processor. Addigy processes data from Data Controllers who sign up for Addigy Services.
- What is collected: The Addigy Agent collects the device data required to perform Remote Monitoring and Management services, such as IP address, MAC address, device name, and username.
- Where it can be installed: Data Controllers can install the Addigy Agent on macOS, iOS, and tvOS devices only.
- Who it's for: IT departments and service companies managing Apple devices, and the compliance or privacy teams who support them.
Data Controllers can also enable functionality that collects additional data. For example, a Controller can create custom scripting to retrieve other types of information beyond the default set.
Device-Specific Data in Addigy
The Addigy Agent maintains specific information about the device in order to perform its required tasks, for as long as the Addigy Agent is installed on that device.
Personally identifiable device information includes:
- Ethernet MAC Address
- Device Name
- Mac UUID
- LocalHost Name
- TeamViewer Client ID
- Serial Number
- Splashtop ID
- Local IP
- Admin Users
Note: This device information is restricted and available only to the Data Controller. Addigy, as a Data Processor, does not record or maintain a log of this type of information. Once it is updated or deleted, Addigy cannot confirm the previous status of the device or devices.
In addition to the device attributes above, the following is collected by the Addigy Agent and the Addigy platform and maintained by the Data Controller:
- Event Actions performed in the Addigy Console by Owner, Admin, and User level roles are maintained for 90 days (3 months).
This data can be exported via Reports or as a CSV for data portability and data visibility.
User-Specific Data in Addigy
Separate from device data, Addigy holds information about the people who sign in to the Addigy console.
- An Addigy user is created by an Organization Administrator, or the Administrator of the Organization creates the Addigy account. In either case, the Full Name, User Name, and Phone Number are required. This level of personal information is required to access the Addigy interface.
- Support ticket creation references this user information on submission, so that tickets can be tied back to the Addigy user.
- Addigy Multi-Factor Authentication can use the phone number of the Addigy user to validate the secure login.
Note: To change user-level information, contact your Data Controller.
Device Facts and MDM Facts
For a full list of the default Device Facts collected by the Addigy Agent, along with a description of each, see Device Facts Overview.
MDM Facts are also collected. These facts are defined by Apple and documented at the following links: