Robovue
How it works Features Pricing FAQ
Sign in

Data Processing Agreement

This agreement forms part of the Terms of Service between Robovue's operator, named in those terms ("Robovue", the processor), and the customer (the controller). It covers personal data in Customer Data that Robovue processes for the customer, and it meets Article 28 of the UK GDPR.

1. Details of the processing

  • Subject matter: monitoring the customer's automation bots.
  • Duration: the subscription, plus the deletion periods in section 9.
  • Nature and purpose: receiving, storing and displaying bot run reports; sending alerts; and reporting.
  • Data subjects: whoever appears in the customer's run data. That's usually the customer's staff, and may include the customer's own customers or suppliers if a bot handles their records.
  • Categories of data: whatever the customer's bots send. This includes:
    • bot and machine names;
    • run status and times;
    • error messages;
    • free-form payloads, up to 64 KB per report;
    • if the customer turns them on, one screenshot or text file per failed run, up to 5 MB;
    • raw event data from connected platforms (UiPath webhook events and Automation Anywhere activity records), which can include robot and user names.
  • Special-category data: none intended. The Terms of Service don't allow it to be sent.

2. Robovue's obligations

Robovue will:

  1. process personal data only on the customer's documented instructions. Those instructions are these terms, plus how the customer uses and configures the service. The exception is where the law requires otherwise; then Robovue will tell the customer first, unless the law forbids that;
  2. make sure everyone authorised to process the data is bound by confidentiality;
  3. apply the security measures in Annex A;
  4. use subprocessors only as section 7 allows;
  5. help the customer respond to data subject requests, as far as the nature of the processing allows. The dashboard lets the customer view, export and delete run data itself;
  6. help the customer with security, breach notification, data protection impact assessments and consultation with the ICO, as far as they relate to this processing;
  7. delete or return the data at the end of the service, as section 9 describes;
  8. make available the information needed to show it complies with this agreement, and allow audits under section 8.

Robovue will tell the customer promptly if it believes an instruction breaks data protection law.

3. The customer's obligations

The customer is responsible for:

  • having a lawful basis for the personal data its bots send;
  • giving its data subjects any notice they need;
  • not sending data the Terms of Service prohibit.

Screenshot attachments are off by default, and turning them on is the customer's decision.

4. Personal data breaches

Robovue will notify the customer without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting Customer Data. The notice will describe what is known at the time:

  • the nature of the breach;
  • its likely consequences;
  • the measures taken.

Robovue will update the notice as it learns more.

5. International transfers

Customer Data is stored in the UK, in AWS's London region (eu-west-2). If a subprocessor processes it outside the UK, Robovue will make sure the transfer is protected by UK adequacy regulations or by appropriate safeguards under the UK GDPR.

6. Confidentiality

Robovue treats Customer Data as confidential. It accesses Customer Data only to provide the service, to support the customer at the customer's request, or to investigate a security issue or a failure.

7. Subprocessors

  • The customer gives general authorisation for the subprocessors listed on our subprocessors page.
  • Robovue will give at least 30 days' notice before adding a new one, by updating that page and emailing workspace Admins.
  • If the customer objects on reasonable data protection grounds and we can't resolve it together, the customer may cancel and get a refund of prepaid fees for the unused period.
  • Robovue requires each subprocessor to agree to data protection terms at least as protective as these, and remains responsible for their work.

8. Audits

Robovue will answer reasonable written security questionnaires once a year and share the relevant documentation. If that isn't enough to show compliance, or a regulator requires it, the customer may carry out an audit, no more than once a year, on these conditions:

  • at least 30 days' notice;
  • at the customer's own cost;
  • during business hours;
  • under confidentiality.

9. Deletion

  • During the subscription:
    • run history is deleted once it's older than the plan's retention window: 30 days on Free, 90 days on Team, and no limit on Business;
    • attachments are deleted after 30 days;
    • delivery-log entries are deleted after 7 days at most.
  • Deleting a bot permanently removes its runs and attachments.
  • Deleting the workspace removes all Customer Data from the live service immediately, and from backups within 7 days. An Admin can do this themselves.

Annex A: Security measures

Hosting and network

  • Hosted on AWS in the London region.
  • Application containers run in private subnets and have no public address.
  • The database isn't publicly accessible, and accepts connections only from the application.
  • The load balancer accepts only HTTPS, and only from Cloudflare's network. Cloudflare provides DDoS protection in front of it.

Encryption

  • In transit:
    • HTTPS only from the internet to Cloudflare, then TLS 1.2 or higher from Cloudflare to the load balancer;
    • HSTS on the app;
    • the attachment store refuses unencrypted requests;
    • the database connection requires TLS.
  • At rest: database storage, backups and attachment storage are encrypted with AWS-managed keys. Application secrets are held in AWS SSM Parameter Store as encrypted values.

Access control

  • Customers sign in through AWS Cognito. Passwords must be at least 8 characters, with upper-case, lower-case and numeric characters.
  • Every request is scoped to the signed-in user's workspace, so one workspace can't read another's data.
  • Bots authenticate with either a per-workspace API key or a request signed with HMAC-SHA256 and a 5-minute replay window. Both are checked in constant time.
  • Keys can be rotated from the dashboard, with an overlap period so bots keep working while they switch over.
  • Access to infrastructure uses least-privilege IAM roles.
  • Deployments run from CI with short-lived credentials. There are no long-lived deploy keys.

Resilience

  • Automated daily database backups, kept for 7 days. Restores have been tested.
  • Uptime is monitored externally every 5 minutes, with a public status page.

Application

  • Every response carries a Content Security Policy, frame denial, no-sniff, a referrer policy and a permissions policy.
  • The app loads no third-party scripts.
  • Ingestion, the management API, attachment uploads and feedback are rate limited.

Last updated: 2026-09-30.

Robovue

Robovue — RPA bot-fleet monitoring for teams running more than one platform.

Product

  • How it works
  • Features
  • Pricing
  • FAQ

Trust

  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Subprocessors
  • Accessibility Statement
  • Contact us
© 2026 Robovue, a trading name of Ryan Spike.