Remote support terms

How we access your devices remotely, with what safeguards, and how that access ends. Last updated: 29 September 2026. This translation is provided for convenience; the French version prevails.

1. Principle

Support is provided remotely by default. Phronesis IT never accesses a device without the client's authorisation. These terms supplement the terms and conditions.

2. Access mandate

At the start of the relationship, the client signs an access mandate specifying the devices, accounts and services concerned and the scope of authorised actions. The client may change or revoke it at any time in writing.

3. How a session works

One-off intervention

The session is opened by the client or with their explicit consent, using a single-use code. It is visible on screen throughout, and the client can end it at any time.

Monitoring (subscriptions and business contracts)

With the client's written consent, a monitoring agent is installed to watch backups, updates and security alerts. It gives no access to file contents. Any remote control remains subject to the client's consent, except scheduled maintenance provided for in a business contract.

4. Tools

Remote control software: RustDesk, open-source software. Sessions are end-to-end encrypted; they pass through RustDesk's connection infrastructure or a connection server operated by Phronesis IT, and neither can read their content. Monitoring tool: [tool name]. Any change of tools is notified to the client.

5. Credentials

Credentials entrusted to us are stored in an encrypted password manager protected by two-factor authentication. They are never sent in clear text by email or messaging. Personal accounts are used wherever possible.

6. Traceability

Each session is logged (date, duration, device, actions taken) and summarised in the written report provided after the intervention. The client may request the log at any time.

7. Data and professional secrecy

Phronesis IT does not open the client's documents, client or patient files, or messages, unless the intervention requires it and the client agrees. No copy of the data is kept. Data is processed under the data processing agreement compliant with the GDPR and the Swiss FADP.

8. Revoking access

At the end of each one-off intervention, temporary access is removed, and Phronesis IT recommends that the client change any passwords shared with us. When the contract ends, the monitoring agent is uninstalled, credentials are deleted from the password manager, and written confirmation is provided on request.

9. Client commitments

Before a session, the client closes confidential documents unrelated to the intervention and remains reachable throughout. The client reports without delay any access they did not authorise.