Remote Support and Access Policy

Last updated: 24 July 2026

This Remote Support and Access Policy explains how SETUPROS LTD, trading as SetuprosTech, provides remote technical support and how access to customer devices, systems, accounts and data is authorised, controlled and protected.

Remote access can create security and privacy risks if it is not properly controlled. UK security guidance recommends limiting remote access to authorised users, applying appropriate authentication and granting only the access necessary for the task.

1. Company Information

Legal company name: SETUPROS LTD
Trading name: SetuprosTech
Company number: 17327322
Registered in: England and Wales
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Website: setuprostech.com
Email: info@setuprostech.com

In this policy:

  • “SetuprosTech”, “we”, “us” and “our” mean SETUPROS LTD.
  • “Customer”, “you” and “your” mean the person or organisation requesting remote support.
  • “Remote support” means technical assistance provided through an internet connection without a SetuprosTech representative being physically present at the customer’s location.
  • “Remote access tool” means software or a platform used to view or control an authorised device or system remotely.

2. Scope of This Policy

This policy applies where SetuprosTech remotely assists with:

  • Computers and laptops;
  • Servers;
  • Mobile devices;
  • Microsoft 365;
  • Microsoft Azure;
  • Exchange Online;
  • Microsoft Teams;
  • Email and domain configuration;
  • User accounts and permissions;
  • Networks and Wi-Fi;
  • Cloud systems;
  • Software installation and configuration;
  • Data migration;
  • Security and backup configuration;
  • Troubleshooting;
  • Device and application setup; and
  • Other agreed technology services.

This policy should be read together with our:

  • Privacy Policy;
  • Terms of Service;
  • Service Cancellation and Refund Policy; and
  • Acceptable Use Policy.

3. Customer Authorisation

SetuprosTech will only access a device, account or system where the customer has given permission.

Authorisation may be provided through:

  • Written email confirmation;
  • Acceptance of a quotation or service order;
  • A support-ticket instruction;
  • A remote-session access code;
  • Verbal confirmation during an arranged support session; or
  • Another clear and recorded instruction.

By authorising remote support, the customer confirms that they:

  • Own or lawfully control the relevant device, account or system;
  • Have authority to permit remote access;
  • Are authorised to act for the relevant organisation;
  • Have informed affected users where necessary;
  • Have obtained any internal approval required; and
  • Consent to SetuprosTech performing the agreed support work.

SetuprosTech may refuse access where the requesting person’s identity or authority cannot be reasonably verified.

4. Access Limited to the Agreed Purpose

Remote access will be limited to the work reasonably necessary to address the agreed requirement.

SetuprosTech will not intentionally:

  • Access unrelated files;
  • Search personal information unrelated to the support request;
  • Review communications that are not relevant to the task;
  • Copy customer data without a legitimate service reason;
  • Change unrelated settings;
  • Install unapproved software; or
  • Continue accessing a system after authorisation has ended.

Access rights should follow the principle of least privilege, meaning access is limited to the minimum information and functionality necessary for the authorised task.

5. Approved Remote Access Methods

Remote support may be provided through:

  • A recognised remote-support application;
  • A secure browser-based support tool;
  • Microsoft-approved administration portals;
  • A customer-provided VPN;
  • A managed remote-monitoring platform;
  • Screen-sharing software;
  • Cloud administration tools; or
  • Another agreed access method.

The specific tool may vary depending on:

  • Customer requirements;
  • Device type;
  • Security settings;
  • Technical compatibility;
  • Existing customer systems; and
  • The nature of the support requested.

SetuprosTech will not ask a customer to disable important security protections unless this is necessary, explained and approved.

6. Session-Based Access

Where possible, remote support should use temporary or session-based access.

This may include:

  • A one-time support code;
  • A temporary password;
  • A time-limited invitation;
  • Customer approval before connection;
  • Customer confirmation before control is granted; or
  • Automatic termination when the session closes.

The customer should not provide permanent credentials where temporary access can reasonably be used.

7. Unattended Access

Unattended remote access means SetuprosTech can connect without the customer manually approving every session.

Unattended access will only be configured where:

  • It is necessary for an ongoing service;
  • The customer expressly authorises it;
  • The scope and duration are agreed;
  • Access is restricted to authorised personnel;
  • Appropriate authentication is applied;
  • The customer understands how to disable it; and
  • The access remains reasonably necessary.

Examples may include:

  • Managed IT support;
  • Server maintenance;
  • Agreed monitoring;
  • Scheduled updates;
  • Backup administration; or
  • Ongoing technical maintenance.

Unattended access should be removed or disabled when the related service ends.

8. Authentication and Account Security

SetuprosTech may require security controls including:

  • Strong passwords;
  • Multi-factor authentication;
  • Unique user accounts;
  • Temporary access codes;
  • Device approval;
  • Role-based access;
  • Session expiry;
  • Login alerts; and
  • Access logging.

The NCSC recommends additional authentication, including multi-factor authentication, for remote access to important systems.

Customers should not share:

  • Passwords through public contact forms;
  • Authentication codes with unauthorised persons;
  • Permanent administrator credentials unnecessarily; or
  • Credentials through insecure channels where a safer method is available.

9. Customer Responsibilities Before a Session

Before remote support begins, the customer should:

  • Save open work;
  • Back up important data;
  • Close unrelated confidential files;
  • Close personal communications not relevant to the task;
  • Inform other users who may be affected;
  • Ensure the device has a stable internet connection;
  • Confirm that the device is connected to power where appropriate;
  • Provide accurate information about the issue;
  • Make administrator access available where required; and
  • Remain available during the session if requested.

The customer remains responsible for ensuring that they are authorised to disclose any information visible during the session.

10. Backups

Unless backup creation is expressly included in the agreed service, the customer remains responsible for maintaining current and recoverable backups.

Technical work may involve risks including:

  • Data corruption;
  • Interrupted updates;
  • Software incompatibility;
  • Device failure;
  • Migration failure;
  • Existing malware;
  • Account lockout; and
  • Loss of unsaved work.

SetuprosTech may recommend that work be postponed if suitable backups are not available.

The NCSC advises organisations to maintain appropriate backups and secure devices and accounts as part of basic cyber resilience.

11. Customer Supervision

For ordinary support sessions, the customer may be asked to remain present or available while work is performed.

The customer may:

  • Observe the session;
  • Ask what actions are being taken;
  • Withdraw permission;
  • Pause the session;
  • End the connection; or
  • Refuse a proposed change.

Ending a session may prevent completion of the work and may still result in charges for time already spent.

12. Access to Personal and Confidential Information

During remote support, personal or confidential information may become visible incidentally.

SetuprosTech will take reasonable steps to:

  • Avoid opening unrelated files;
  • Minimise access to personal information;
  • Use information only for the agreed service;
  • Maintain confidentiality;
  • Restrict access to authorised personnel; and
  • Handle personal information according to our Privacy Policy.

The ICO advises organisations to use appropriate security measures for remote access and remote handling of personal information.

13. Credentials

Where credentials are required, SetuprosTech may request:

  • A temporary password;
  • A delegated administrator account;
  • A customer-created support account;
  • A time-limited access link;
  • A one-time authentication code; or
  • Customer-assisted login.

Permanent passwords should be avoided where possible.

After the support work is completed, the customer may be advised to:

  • Change passwords;
  • Revoke temporary access;
  • Remove the support account;
  • Review administrator permissions;
  • Sign out active sessions; and
  • confirm that multi-factor authentication remains enabled.

14. Administrator Access

Some tasks require elevated or administrator access.

Administrator access will only be requested where reasonably necessary for activities such as:

  • Installing software;
  • Changing system settings;
  • Configuring Microsoft services;
  • Creating or modifying user accounts;
  • Applying security settings;
  • Connecting domains;
  • Managing networks; or
  • Performing migration work.

The customer must confirm that they are authorised to grant that level of access.

15. Remote Support Tools

Remote-support software may collect limited technical information, such as:

  • Device name;
  • Operating system;
  • Internet Protocol address;
  • Session time;
  • Connection status;
  • Tool version;
  • Support operator details; and
  • Diagnostic information.

The relevant software provider may process this information under its own privacy terms.

SetuprosTech will use reputable tools appropriate to the support task and will review access settings where reasonably practical.

16. Session Logging

SetuprosTech may keep basic service records, including:

  • Date and time of support;
  • Customer name;
  • Device or account supported;
  • General issue reported;
  • Actions performed;
  • Outcome of the session;
  • Technician or authorised user involved; and
  • Follow-up requirements.

These records may be used for:

  • Service administration;
  • Security;
  • Customer support;
  • Billing;
  • Dispute handling;
  • Quality control; and
  • Legal or regulatory compliance.

Session records will be retained according to our Privacy Policy.

17. Session Recording

Remote sessions will not normally be audio-recorded or video-recorded.

Where recording is considered necessary, SetuprosTech will:

  • Explain the reason;
  • Obtain appropriate permission;
  • State what will be recorded;
  • Limit access to the recording;
  • Protect the recording; and
  • Retain it only for an appropriate period.

Screen-sharing or remote-support tools may generate technical logs without creating a full video recording.

18. File Transfer

Files will only be transferred where reasonably necessary for the agreed service.

This may include:

  • Diagnostic logs;
  • Approved software;
  • Configuration files;
  • Migration data;
  • Support documentation; or
  • Customer-authorised files.

SetuprosTech will not intentionally copy unrelated customer files.

Where practical, transferred files will be:

  • Limited to the minimum necessary;
  • Stored securely;
  • Shared only with authorised persons; and
  • Deleted when no longer required.

19. Software Installation

SetuprosTech may install software where:

  • It is required for the agreed service;
  • The customer has authorised the installation;
  • The software is legitimate;
  • Licensing requirements are satisfied; and
  • The installation does not involve prohibited or unlawful activity.

Software may include:

  • Remote-support tools;
  • Security software;
  • Microsoft applications;
  • Drivers;
  • Updates;
  • Backup tools;
  • Network utilities; and
  • Diagnostic applications.

The customer remains responsible for third-party licence terms and subscription fees unless otherwise agreed.

20. Security Incidents and Malware

Where SetuprosTech identifies suspected:

  • Malware;
  • Unauthorised access;
  • Credential compromise;
  • Data exposure;
  • Phishing;
  • Ransomware;
  • Suspicious administrator accounts; or
  • Other security risks,

we may:

  • Pause the support session;
  • Inform the customer;
  • Recommend immediate security action;
  • Disconnect affected systems;
  • Advise password changes;
  • Recommend specialist incident response; or
  • Decline to continue where the risk is outside the agreed scope.

Incorrectly configured remote-access services can create serious security risks, including ransomware exposure.

SetuprosTech does not guarantee that every threat can be identified, removed or prevented.

21. Prohibited Requests

SetuprosTech will not provide remote access or assistance for:

  • Unauthorised access to another person’s device or account;
  • Password theft;
  • Credential interception;
  • Security bypassing without lawful authority;
  • Malware creation or deployment;
  • Illegal surveillance;
  • Fraud;
  • Software piracy;
  • Counterfeit licensing;
  • Unlawful data extraction;
  • Destruction of data without authority;
  • Spam activity; or
  • Any other unlawful or abusive purpose.

A session may be ended immediately if unlawful or unauthorised activity is suspected.

22. Support for Employer-Owned Devices

Where support is requested for an employer-owned device, the person requesting assistance confirms that:

  • They are authorised by the employer;
  • The device may be accessed for the requested purpose;
  • Relevant workplace policies have been followed;
  • The employer has approved any required software installation; and
  • The person has authority to disclose information visible during the session.

SetuprosTech may request confirmation from an authorised company representative.

23. Support for Personal Devices

Where a personal device is used for business purposes, the customer should consider that:

  • Business and personal information may be stored together;
  • Other household members may have access;
  • Personal applications may be visible;
  • Employer policies may restrict support access; and
  • Additional security measures may be needed.

ICO guidance notes that personal devices used for work can create increased privacy and security risks, including access by unauthorised household members.

24. Remote Network and Server Access

Remote access to servers, business networks and administrative systems may require stronger controls.

These may include:

  • VPN access;
  • Approved gateways;
  • Multi-factor authentication;
  • Restricted source addresses;
  • Role-based permissions;
  • Logging;
  • Temporary administrator accounts;
  • Secure connection protocols; and
  • Customer security approval.

Remote access solutions should be correctly configured and kept updated. Internet-facing VPN and remote-access services form part of an organisation’s security exposure and should receive timely security updates.

25. Ending a Remote Session

A remote session will end when:

  • The agreed work is completed;
  • The customer withdraws permission;
  • The connection is no longer required;
  • A security concern arises;
  • The support period expires;
  • The customer fails to cooperate;
  • Payment or authorisation requirements are not met; or
  • Continuing the work may create an unreasonable risk.

After the session, SetuprosTech may:

  • Disconnect the remote tool;
  • Remove temporary files;
  • Disable temporary accounts;
  • Provide a summary;
  • Recommend follow-up steps; or
  • Request confirmation that the issue has been resolved.

26. Removal of Remote Access

Customers may request the removal of SetuprosTech remote access at any time.

Depending on the tool, removal may involve:

  • Uninstalling the remote-support application;
  • Revoking an invitation;
  • Removing a delegated administrator relationship;
  • Deleting a support account;
  • Changing credentials;
  • Disabling unattended access;
  • Revoking active sessions; or
  • Removing device permissions.

Where ongoing remote access forms part of a managed service, removing access may limit or prevent SetuprosTech from providing that service.

27. No Guaranteed Outcome

SetuprosTech will use reasonable skill and care but does not guarantee that remote support will:

  • Resolve every technical issue;
  • Recover all data;
  • Remove every security threat;
  • Restore unsupported software;
  • Repair defective hardware;
  • Prevent future incidents;
  • Resolve a third-party outage; or
  • Work where access, connectivity or permissions are insufficient.

Where remote support is unsuitable, we may recommend:

  • On-site support;
  • Hardware repair;
  • Vendor escalation;
  • Data-recovery specialists;
  • Cybersecurity specialists; or
  • Replacement of unsupported equipment.

28. Charges

Remote support charges may be based on:

  • A fixed quotation;
  • Hourly time;
  • A support package;
  • A monthly agreement;
  • A project fee; or
  • Another agreed arrangement.

Charges may apply for:

  • Assessment time;
  • Connection and diagnosis;
  • Work completed;
  • Waiting time caused by unavailable access;
  • Additional work outside scope; and
  • Follow-up support.

Cancellation and refund rules are explained in our Service Cancellation and Refund Policy.

29. Liability

Nothing in this policy excludes liability where it would be unlawful to do so.

Subject to applicable law and the Terms of Service, SetuprosTech is not responsible for losses caused by:

  • Inaccurate customer instructions;
  • Lack of backups;
  • Pre-existing damage;
  • Existing malware;
  • Unsupported hardware or software;
  • Customer interruption of the session;
  • Third-party service failure;
  • Customer disclosure of credentials;
  • Unauthorised customer actions; or
  • Changes made after the support session.

This section does not remove mandatory consumer rights.

30. Privacy and Data Protection

Personal information processed during remote support will be handled according to our Privacy Policy.

Depending on the service, SetuprosTech may act as:

  • A controller for customer, billing and support-administration information; or
  • A processor where it handles personal information only on the customer organisation’s documented instructions.

A separate data-processing agreement may be required where SetuprosTech processes personal information on behalf of a business customer.

31. Changes to This Policy

We may update this policy to reflect:

  • Changes to remote-support tools;
  • Changes to our services;
  • New security requirements;
  • Changes to privacy law;
  • Changes to third-party platforms; or
  • Changes to our business procedures.

The latest version will be published with a revised “Last updated” date.

32. Contact Us

Questions about remote support or access should be sent to:

SETUPROS LTD, trading as SetuprosTech
Email: info@setuprostech.com
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Company number: 17327322
Registered in: England and Wales